- Merchant onboarding speed is not locked to your processor. A dedicated underwriting software layer can cut sub-merchant approval from days to under five minutes by automating KYB checks, risk scoring, and provisioning in sequence.
- The vendor category splits into three distinct types: orchestration platforms (Alloy, Middesk), purpose-built payfac onboarding tools (Finix, NMI Merchant Central, Agreement Express), and embedded underwriting APIs (Unit21, Persona, Sift).
- The workflow bottleneck is almost always the gap between data collection and risk decision, not the payment rails themselves. Fix that gap first.
- PayFacs and ISVs face different constraints: PayFacs own the underwriting liability, so they need automated risk scoring and real-time decisioning. ISVs routing through a processor need boarding tools that integrate with that processor’s boarding API.
- Pricing across this category is almost entirely custom or quote-based. Any vendor promising a flat monthly rate without knowing your monthly merchant volume is quoting a loss leader.
The best merchant onboarding software for PayFacs and ISVs automates the full workflow from KYB data collection through risk scoring to payment provisioning, cutting sub-merchant approval from days to under five minutes. The leading platforms include Alloy, Finix, NMI Merchant Central, Agreement Express, Middesk, Unit21, Persona, and Sift, each covering different parts of the stack depending on whether you own underwriting liability or route through a processor.
Why Merchant Onboarding Speed Is an Underwriting Problem, Not a Processor Problem
Most PayFac and ISV teams blame slow merchant activation on their processor. The processor is rarely the bottleneck. The delay almost always sits in the manual handoffs between document collection, identity verification, business verification, risk scoring, and account provisioning.
A sub-merchant application that arrives clean, verified, and scored can hit payment rails in minutes. One that requires a human to pull a Secretary of State filing, cross-reference a watchlist, and estimate transaction risk can sit in a queue for three days. The processor is waiting on you, not the other way around.
This is the core diagnostic that shapes every vendor recommendation in this article: merchant onboarding is an underwriting problem, not a processor problem. The software that matters sits between your onboarding form and your payment processor’s boarding API. It is distinct from the PayFac model itself (covered in our guide to PayFac-as-a-Service providers for vertical SaaS) and from standalone KYB data vendors (covered separately in our KYB providers comparison). What lives here is the orchestration layer that connects those pieces into a decision.
How Does the Merchant Onboarding Workflow Actually Run?
Every functional merchant onboarding system runs through three sequential stages. FintechSpecs refers to this as the Collect → Score → Provision framework throughout this analysis. Problems compound when any stage lacks automation or passes work to a human queue.
Stage 1: Collect
The merchant submits business identity, ownership, and banking information. Modern tools use pre-filled forms, API-driven data retrieval (pulling state registration data, EIN confirmation, UCC filings), and document upload with automated extraction. Manual data collection is the most common source of application abandonment.
Stage 2: Score
The platform runs the submitted data against KYB verification, KYC on beneficial owners, AML watchlist screening, MCC risk classification, and estimated transaction volume analysis. Risk scoring engines assign a decision tier: auto-approve, manual review, or decline. The best systems handle 70 to 85% of applications in the auto-approve tier.
Stage 3: Provision
Approved merchants get credentials pushed to the processor’s boarding API. This is where integration depth matters. A platform that can POST approval data directly to Worldpay, Fiserv, or Stripe Connect eliminates the manual rekeying step that adds 24 to 48 hours to activation.
| Stage | Key Actions | Common Bottleneck | Automation Target |
|---|---|---|---|
| Collect | KYB form, document upload, EIN/SSN match | Missing fields, manual doc review | Pre-fill APIs, OCR extraction |
| Score | KYB check, KYC on owners, AML screen, MCC risk | Manual analyst queue for mid-risk apps | Rules engine + ML risk tier |
| Provision | Processor API push, MID assignment, fee schedule | Manual rekeying into processor portal | Direct boarding API integration |
The FintechSpecs Onboarding Stack Audit: Four Checks Before You Buy
Before evaluating any vendor, run these four checks against your current workflow. They identify which stage of the Collect → Score → Provision chain is broken and which vendor category actually fits your situation.
Check 1: Where do applications stall? Pull your last 90 days of merchant applications and find the median time between submission and first decision. If that number exceeds four hours, the Score stage is the problem. If the time between decision and provisioning exceeds 24 hours, the Provision stage and its processor integration are the problem.
Check 2: What is your auto-approve rate? If you cannot answer this, you do not have a risk scoring system. You have a review queue. Target 70% auto-approve on clean applications; anything below 50% means your rules engine is either missing data inputs or has thresholds set for a risk appetite you no longer hold.
Check 3: Who owns underwriting liability? PayFacs own it. ISVs typically do not. This determines whether you need a full risk decisioning platform (Alloy, Agreement Express) or a boarding integration tool (NMI Merchant Central, Finix). Buying a full underwriting platform when you do not own the liability adds cost with no corresponding risk protection.
Check 4: Which processors do you board to? Every vendor on this list has a different set of native processor integrations. Check the exact processor list before shortlisting. A platform with strong Stripe Connect and Adyen integrations may have no native Worldpay or First Data path.
8 Best Merchant Onboarding and Underwriting Software Platforms
1. Alloy

Alloy is an identity decisioning platform that many PayFacs use as their underwriting orchestration layer. It connects to dozens of KYB and KYC data sources (Middesk, LexisNexis, Experian, Socure, and others) and lets risk teams build decision workflows without custom code. The core value is that you can change which data sources feed a decision, adjust risk thresholds, and create manual review queues in a no-code workflow builder.
For PayFacs running high sub-merchant volumes, Alloy’s ability to run parallel data checks and return a single decision verdict reduces per-application latency from minutes to seconds. It does not handle payment provisioning natively, so you still need a processor boarding integration alongside it. Pricing is not publicly disclosed; Alloy quotes based on decision volume. We covered the Alloy vs Middesk comparison in depth in our Alloy vs Middesk KYB platform analysis.
Best for: PayFacs that want to own their underwriting logic and swap data vendors without rebuilding integrations.
2. Finix

Finix positions itself as a merchant onboarding and payment facilitation platform that covers both the boarding workflow and the payment processing rails. According to Finix’s public documentation, the platform handles sub-merchant onboarding, risk monitoring, settlement, and reporting in a single API. For ISVs that want to become PayFacs without building processor relationships from scratch, Finix provides a faster path than pursuing direct acquiring agreements.
The practical advantage is that the boarding API and the payment API share a data model, which eliminates the integration gap between approval and provisioning. The trade-off: you are committing to Finix as your processor as well as your onboarding layer, which reduces portability if you want to switch rails later. Pricing is quote-based and varies by processing volume.
Best for: ISVs in vertical markets (healthcare, legal, field services) that want to move to a full PayFac model without multiple vendor relationships.
3. NMI Merchant Central

NMI’s Merchant Central product targets payment service providers and ISOs that need to accelerate merchant sign-up and activation. According to NMI’s public product page, Merchant Central uses automated web forms, eSignatures, and direct boarding to reduce the time from application to processing. The platform integrates with NMI’s payment gateway, which means provisioning is native rather than requiring a separate API call to a processor.
Merchant Central is pragmatic rather than elegant. It covers the basics well: digital applications, document collection, automated approval workflows, and activation triggers. Risk scoring capability is lighter than Alloy or Agreement Express. It fits ISOs and ISVs already operating on NMI’s gateway who want to modernize their boarding process without migrating their processing stack.
Best for: ISOs and ISVs on NMI’s gateway that want faster merchant activation without a platform migration.
4. Agreement Express
Agreement Express (now part of the Paysign/Payroc ecosystem) is one of the longer-standing purpose-built merchant boarding platforms in North America. It digitizes the full merchant application, runs automated KYB and compliance checks, and pushes approved merchants directly to acquiring processors. The platform covers multi-processor boarding, which means a single application can be routed to different acquiring relationships based on risk profile or vertical.
The underwriting workflow in Agreement Express is configurable: risk teams can set decision rules, create tiered approval paths, and build custom questionnaires for high-risk MCCs. For large ISOs and PayFacs with multi-acquiring setups, the multi-processor routing is the feature that competitors rarely match at this level of configurability. Pricing is enterprise and not publicly disclosed.
Best for: Large ISOs, PayFacs, and acquirers with multiple processor relationships that need centralized boarding and decision logic.
5. Middesk

Middesk focuses specifically on business identity verification, making it a strong data layer for any PayFac that is building or upgrading its KYB workflow. It verifies business registration, beneficial ownership, address history, tax ID, and watchlist status. Where Middesk differentiates from broader identity platforms is in the depth of its business data coverage: Secretary of State records, UCC filings, and business health signals that inform underwriting decisions beyond a basic EIN match.
Middesk is not a full onboarding platform. It does not handle document collection, merchant applications, or processor provisioning. It is the KYB engine that a PayFac would plug into an orchestration layer like Alloy, or directly into a custom boarding workflow. Teams that want pre-built onboarding workflow software should pair Middesk with a boarding platform. Teams building custom underwriting infrastructure often use Middesk as a standalone API call within their own decisioning engine.
Best for: PayFacs building custom underwriting logic that need accurate, deep business verification data via API.
6. Unit21

Unit21 is a risk and compliance infrastructure platform covering transaction monitoring, case management, and rules-based alerting. In the merchant onboarding context, Unit21 is most relevant for PayFacs that need ongoing sub-merchant monitoring after initial approval. Onboarding a sub-merchant is a one-time event; monitoring that merchant for changes in transaction behavior, chargeback rates, or suspicious patterns is continuous.
Many PayFacs discover that their onboarding tooling handles initial approval well but have no systematic way to catch a merchant whose risk profile deteriorates after activation. Unit21 fills that gap with real-time transaction monitoring rules and investigation workflows. It integrates with onboarding platforms rather than replacing them. See also our overview of transaction monitoring tools for early-stage fintech companies for how Unit21 compares in the broader monitoring category.
Best for: PayFacs that already have boarding tooling and need to close the monitoring gap in their post-approval risk program.
7. Persona

Persona is an identity verification platform that handles both KYC (individual owner verification) and KYB (business entity verification) within a configurable flow builder. For merchant onboarding, Persona’s strength is the UX layer: it handles the end-merchant’s verification experience with branded flows, automated document checks, selfie liveness detection, and database lookups. The output is a verification decision that feeds back into an upstream decisioning platform.
Persona is not an underwriting engine and does not handle processor provisioning. Its value in the onboarding stack is reducing friction and fraud at the identity collection stage so that the risk scoring layer receives cleaner, verified inputs. Persona publishes pricing on its website, with costs varying by verification type and volume. Teams focused purely on the KYC layer of their onboarding flow will find Persona’s workflow customization more flexible than most alternatives.
Best for: PayFacs and ISVs that want a configurable, branded identity verification experience for sub-merchant owners without building it in-house.
8. Sift

Sift applies machine learning to account and transaction fraud detection, and its Account Defense and Payment Protection products cover merchant onboarding fraud specifically. In payfac contexts, onboarding fraud includes shell merchant accounts set up to process fraudulent transactions, bust-out fraud where a merchant loads chargebacks before disappearing, and synthetic identity fraud in the beneficial ownership data.
Sift scores onboarding applications in real time based on device signals, behavioral patterns, and network connections between applicant data points. It is not a KYB verification tool and does not return business registration data. Its output is a fraud score that a risk team uses alongside KYB verification in their decisioning engine. Sift is most relevant for PayFacs processing in consumer-facing verticals (food delivery, ticketing, e-commerce) where onboarding fraud rates are materially higher than B2B verticals. Pricing is custom and volume-based.
Best for: PayFacs in consumer-facing verticals with elevated exposure to synthetic identity and bust-out merchant fraud.
Vendor Comparison: Which Tool Covers Which Workflow Stage?
| Platform | Collect | KYB/KYC Verification | Score | Provision | Post-Approval Monitoring | Best Fit |
|---|---|---|---|---|---|---|
| Alloy | Partial (via API) | Yes (multi-source orchestration) | Yes | No (requires separate integration) | Partial | PayFacs needing configurable underwriting |
| Finix | Yes | Yes (built-in) | Yes | Yes (native) | Yes | ISVs moving to full PayFac model |
| NMI Merchant Central | Yes | Partial | Basic | Yes (NMI gateway) | No | ISOs/ISVs on NMI gateway |
| Agreement Express | Yes | Yes | Yes (configurable) | Yes (multi-processor) | Partial | Large ISOs, multi-acquiring PayFacs |
| Middesk | No | Yes (KYB only) | No | No | No | Custom KYB data layer within own stack |
| Unit21 | No | No | Partial (post-approval) | No | Yes | PayFacs needing sub-merchant monitoring |
| Persona | Yes (identity UX) | Yes (KYC + KYB) | No | No | No | Branded identity verification flow |
| Sift | No | No | Yes (fraud scoring) | No | Yes (transaction fraud) | Consumer-facing PayFacs with fraud exposure |
What Does Automated Merchant Underwriting Actually Cost?
Every platform on this list uses custom pricing tied to merchant application volume, decision complexity, and integration depth. None of them publish a flat monthly rate that scales predictably with sub-merchant growth, so any comparison of sticker prices is incomplete.
The cost structure that matters more than platform fees is the cost per decision. Consider a PayFac processing 500 new sub-merchant applications per month. If manual review costs an analyst 20 minutes per application at a fully loaded cost of $60 per hour, that is $100,000 in annual analyst time on applications alone, before counting errors and rework. Dropping manual review from 50% of applications to 15% through automation pays for most mid-market platform contracts within the first year.
The hidden cost that operators miss is the cost of a wrong approval. A sub-merchant that generates $40,000 in fraudulent chargebacks before being flagged will erase months of platform savings. Fraud losses make onboarding speed and onboarding accuracy complementary goals, not competing ones. For a detailed treatment of where these costs compound, see our analysis of hidden costs killing fintech SaaS margins and our piece on fraud prevention vs user experience trade-offs in fintech.
PayFac vs ISV: Which Onboarding Tools Apply to Each Model?
PayFacs and ISVs have different regulatory and operational relationships to sub-merchant underwriting, which changes which tools are appropriate.
A PayFac is the merchant of record for its sub-merchants with the card networks. It owns the underwriting liability, the chargeback exposure, and the compliance obligation. That means it needs a full underwriting stack covering all three stages: Collect, Score, and Provision, plus ongoing monitoring. Skimp on any stage and the liability lands directly on the PayFac’s acquiring agreement. Alloy, Agreement Express, and Finix are all built for this profile.
An ISV routes transactions through a processor or PayFac-as-a-service provider and typically does not own the underwriting liability. Its boarding tooling needs to collect application data and pass it to the upstream acquirer’s boarding API, but the risk decision lives elsewhere. NMI Merchant Central and Finix both serve this model. The risk of over-engineering here is real: an ISV that builds out a full underwriting stack for risk it does not own is paying for infrastructure without corresponding protection. For a deeper look at how payments embedding models differ, our piece on how to embed payments in SaaS breaks down the PayFac, ISV, and Merchant of Record decision tree.
Time-to-Approve Benchmarks: What Good Looks Like
There is no single industry standard for sub-merchant approval times, but operational benchmarks from public case studies and vendor documentation give a workable frame:
| Application Type | Manual Process | Partially Automated | Fully Automated |
|---|---|---|---|
| Low-risk MCC, clean KYB data | 1 to 3 days | 2 to 4 hours | Under 5 minutes |
| Mid-risk MCC, standard verification | 3 to 7 days | 4 to 24 hours | 15 to 60 minutes |
| High-risk MCC or complex ownership | 7 to 21 days | 1 to 3 days | Manual review required |
Fully automated approval at under five minutes is achievable for clean, low-risk applications. It requires pre-filled data retrieval, real-time KYB verification (not batch), instant watchlist checks, and direct processor boarding API integration. Any gap in that chain reintroduces human latency. Most PayFacs with well-configured tooling still have 15 to 25% of applications fall into manual review, and that number reflects both their data quality and their risk appetite, not a platform failure.
What Should a PayFac Look for in Merchant Risk Scoring Software?
Risk scoring for merchant underwriting differs from consumer credit scoring in one important way: the risk profile of a sub-merchant is dynamic. A restaurant that generates clean transactions for six months can pivot to processing card-not-present transactions for a third party in month seven. Static approval decisions are not sufficient.
When evaluating risk scoring tools, the criteria that separate strong from adequate are: the ability to set rules by MCC, the ability to layer machine learning signals on top of rules, the availability of real-time data feeds (not daily batch), and the presence of a case management interface for manual review analysts. A risk scoring engine without a usable investigation interface creates a different operational failure: fast decisions that analysts cannot efficiently audit or override.
For PayFacs that want to build their own scoring logic on top of verified data, the combination of Middesk (for business verification) plus Alloy (for decisioning workflow) plus Unit21 (for post-approval monitoring) is the most commonly assembled custom stack in the mid-market. Finix and Agreement Express offer more vertically integrated alternatives that trade configurability for speed of deployment. Our fraud detection and risk tools overview covers how several of these vendors compare across the broader risk category.
Frequently Asked Questions
What is merchant onboarding software?
Merchant onboarding software automates the process by which PayFacs, ISOs, and ISVs sign up, verify, and activate businesses to accept payments. It covers digital application collection, KYB and KYC identity verification, automated risk scoring, and provisioning approved merchants to payment processing rails. The goal is to reduce time-to-approval from days to minutes while maintaining underwriting accuracy.
What is the difference between KYB for merchant acquiring and standard KYB?
Standard KYB confirms that a business is legally registered and matches stated ownership. KYB for merchant acquiring goes further: it evaluates the business’s MCC classification, estimated transaction volume, chargeback risk, and whether the business model is consistent with the payment network’s permitted use policies. Acquiring KYB is an underwriting decision, not just a compliance check. Platforms like Middesk and Alloy serve the compliance layer; the underwriting interpretation layer requires additional risk scoring logic specific to payment facilitation.
Can an ISV build sub-merchant onboarding without becoming a PayFac?
Yes. An ISV can build a boarding flow that collects merchant application data and passes it to an upstream PayFac-as-a-service provider (like Stripe Connect, Adyen for Platforms, or Finix) that owns the underwriting. The ISV controls the user experience and captures a revenue share on payment volume without taking on acquiring liability. The limitation is that the upstream PayFac’s risk policies govern what the ISV can approve, and those policies are not fully customizable by the ISV.
How does automated merchant onboarding reduce fraud losses?
Automation reduces fraud by eliminating the inconsistency of manual review. Human analysts applying inconsistent risk thresholds across high application volumes miss patterns that a rules engine catches systematically. Automated KYB verification catches shell entities and mismatched ownership earlier in the process. Fraud scoring tools like Sift add behavioral signals (device fingerprinting, velocity patterns) that no document review process can replicate. The combination of consistent rules and real-time signals outperforms manual review for high-volume PayFac operations.
What processor integrations should I check before choosing a boarding platform?
Confirm native boarding API support for your exact processor relationships before shortlisting any vendor. Key names to check: Worldpay, Fiserv (First Data), Global Payments, Stripe Connect, Adyen for Platforms, and TSYS. “Integration available” in a vendor’s materials sometimes means a CSV export and a manual upload, not a real-time API push. Ask specifically whether the integration uses the processor’s live boarding API and whether provisioning triggers automatically on approval or requires a manual step.
What is the typical auto-approve rate for automated sub-merchant onboarding?
Auto-approve rates vary significantly by industry vertical, merchant risk profile, and how aggressively a PayFac has tuned its risk rules. For low-risk MCCs with clean application data, well-configured platforms can auto-approve 70 to 85% of applications. Platforms with sparse data inputs or overly conservative default rules often run below 50%, which means the majority of the speed benefit from automation is lost to a manual review queue that is larger than necessary.
Do merchant onboarding platforms handle ongoing sub-merchant monitoring?
Most boarding-focused platforms (NMI Merchant Central, Agreement Express) handle initial approval but have limited post-approval monitoring. Finix includes ongoing risk monitoring as part of its PayFac infrastructure. For dedicated monitoring, Unit21 and Sift cover real-time transaction pattern analysis and behavioral risk signals after activation. PayFacs with significant sub-merchant portfolios typically need both a boarding platform and a monitoring layer, and those are often different vendors.
The Onboarding Stack Is a Risk Program, Not a Form Builder
The most persistent misunderstanding about merchant onboarding software is that it is a front-end problem: better forms, faster uploads, digital signatures. Those improvements matter at the margins. The material gain comes from treating onboarding as the first stage of a continuous risk program. The decision made at the point of approval determines the fraud and chargeback exposure a PayFac carries for the entire life of that sub-merchant relationship.
That framing changes which vendor you buy. A form-builder mindset leads to NMI Merchant Central or a light boarding module. A risk-program mindset leads to Alloy or Agreement Express paired with Unit21 for monitoring, because the goal is not just fast approval but defensible approval. The difference shows up in chargeback ratios and card network audits, not in approval time benchmarks. For a broader view of how compliance and operations intersect in payment infrastructure, the fintech product and compliance readiness checklist covers the program-level requirements PayFacs need to satisfy.
PayFacs that have automated the full Collect → Score → Provision workflow report meaningful reductions in analyst headcount, faster merchant activation, and lower fraud losses, but only when data quality, risk rules, and processor integrations are treated as a single system. Buying one piece and leaving the others manual produces marginal results. The bottleneck always moves to the next unmated stage.












