Back to the library
Risk & Compliance
2026-08-30 10 min read

Third Party Agent Registration: Who Has to Register

Your gateway or billing vendor probably needs registering with Visa before it does any work, and the registration is tied to one acquirer, not to the vendor.

JA

By Jeffrey Anderson

third party agentTPA registrationcompliancepayment gatewaysVisa rules
Third Party Agent Registration: Who Has to Register
Key takeaways
  • A third party agent is any entity providing payment-related services directly or indirectly to a member or its merchants. That covers gateways, billing platforms, fraud tools and chargeback vendors, and your acquirer decides, not you.
  • Registration must be completed before the performance of any contracted services or transaction activity, so it gates pilots and integrations, not just go-live.
  • Visa may deny or reject a registration at any time, with or without cause. Signing and building before registration completes is a risk the rules openly reserve.
  • Registration is specific to each acquirer. A vendor registered under one acquirer must be registered again by another, which puts agent re-registration on the critical path of any processor migration.
  • From 24 October 2026 in the US and Canada, members must disclose the numeric IDs, issuing and acquiring identifiers, BINs and account ranges their agents use, and review that information annually.
  • Losses from a third party agent can be collected from the members using that agent, which is why acquirers gate the stack so carefully.

Third party agent registration is the compliance step most merchants have never heard of, right up until it delays their launch. If a vendor touches your payments, your acquirer has to register it with Visa before that vendor does any work at all.

The rules sit in section 1.9.8 of the Visa Core Rules and Visa Product and Service Rules (18 April 2026). They're short, and they catch a lot of businesses off guard.

The Definition Is Broader Than You'd Guess

Start with what Visa means by the term, because most people picture a processor and stop there.

A Third Party Agent is "an entity, not defined as a VisaNet Processor or Visa Scheme Processor, that provides payment-related services, directly or indirectly, to a Member and/or its Merchants or Sponsored Merchants or their agents" (ID# 0025921).

Two words in that sentence do a lot of work. "Indirectly" means a vendor you hired, who never speaks to your bank, can still be in scope. And "payment-related services" is not a short list. Your gateway, your subscription billing platform, your chargeback representment provider, your fraud screening tool, your CRM if it stores cards, your fulfillment partner if it triggers captures. Any of them can qualify.

You don't get to decide. Your acquirer does, and Visa can disagree with your acquirer.

Registration Comes Before The Work, Not After

This is the part that bites schedules.

A member must register a third party agent with Visa using the Program Request Management application and the appropriate regional forms. Then comes the sentence to plan around: "Registration must be completed before the performance of any contracted services or Transaction activity" (ID# 0025893).

Not before you go live. Before the vendor performs any contracted services. A pilot, a test migration, a sandbox integration that touches real transaction data, all of it sits behind the registration.

For a vendor engaged by a merchant rather than by the bank, the obligation lands the same way. An acquirer must register a third party agent engaged by any of its merchants before the performance of any contracted services on the merchant's behalf (ID# 0025894).

Visa Can Refuse, With Or Without Cause

Worth quoting exactly, because it changes how you should sequence a vendor decision.

"Visa may deny or reject a Third Party Agent's registration at any time with or without cause" (ID# 0025893).

There's no appeal described, no criteria published, and no obligation to explain. If you've signed a contract with a vendor, paid an implementation fee, and built against their API before registration completes, you've taken a risk the rules openly reserve the right to realise.

Ask your acquirer whether a vendor is already registered with them before you sign anything. It's a two minute question that occasionally saves a quarter.

Registration Is Per Acquirer, Not Per Vendor

Here's the detail that surprises people who've done this before.

Registration of a third party agent is specific to each acquirer, and requires a separate registration by each acquirer for any third party agent that either uses its acquiring identifier or provides contracted services on behalf of the acquirer or its merchants (ID# 0025894).

So "our gateway is already registered with Visa" is not a meaningful statement on its own. It's registered with a particular acquirer. Move to a new acquirer and the same vendor needs registering again, by the new one.

That has a direct consequence if you're switching processors. Your migration timeline isn't just your own underwriting. It's also re-registering every agent in your stack under the new acquirer, and that work belongs on the plan from day one rather than being discovered in week three.

The Contract Has To Be Direct

Short rule, easy to breach without noticing. A third party agent must have a direct written contract with a member to perform services on behalf of the member (ID# 0025892).

A chain of subcontracts where your vendor quietly uses somebody else's infrastructure doesn't satisfy that. If your provider is reselling another platform, ask who actually holds the contract with the bank.

What Changes On 24 October 2026

This is new, it's specific to the US and Canada, and almost nobody is writing about it.

From 24 October 2026, as part of the registration process, members must disclose to Visa the Numeric IDs associated with their third party agent. They must also disclose the issuing identifiers, acquiring identifiers, all BINs, and any applicable account ranges the agent uses to perform contracted services on the member's behalf, including in connection with end-consumer or merchant-facing programs.

The member is then responsible for maintaining accurate, complete and current information for each agent, and for reviewing and updating that information annually, after any change, or whenever Visa asks (ID# 0025893).

Read that as a direction of travel. Visa is building a much more precise map of who touches transactions and under which identifiers. Vendors with murky infrastructure, or acquirers with stale registration records, have a year to tidy up before that becomes visible.

Who Is Exempt

One exemption exists, and it's narrow.

A third party agent is exempt if it only provides services on behalf of its affiliates, including parents and subsidiaries, that are members owning and controlling at least 25% of the agent.

That exemption does not apply to Business Payment Service Providers, Consumer Bill Payment Service Providers, Marketplaces, Payment Facilitators, or Digital Wallet Operators that operate staged digital wallets. Those register regardless.

Why Your Acquirer Cares So Much

Because the money lands on them.

For losses resulting from unauthorised use, Visa may collect from the member that caused the loss, or from members using the third party agent that caused the loss (ID# 0025888). And where a member fails to meet its responsibilities regarding third party agents, liability is assigned in a defined order that starts with the member whose performance or nonperformance the loss arose from, then its sponsor, then BIN or acquiring identifier licensees (ID# 0025904).

Your vendor's failure is your acquirer's bill. That's the whole reason the registration gate exists, and it's why an acquirer that seems fussy about your stack is usually just reading its own exposure correctly.

What To Actually Do

Four things, in order.

Inventory every vendor that touches a transaction, a card number, or a billing decision. Be generous about what counts, since "indirectly" is in the definition.

Ask your acquirer which of them are already registered under its acquiring identifier. Not registered generally. Registered with them.

Sequence registration before implementation on anything new, and treat a signed vendor contract before registration as a risk you've chosen to take.

If you're changing acquirers, put agent re-registration on the migration plan at the start. It's not automatic and it's not fast.

Frequently Asked Questions

Is my payment gateway a third party agent?

Very likely. The definition covers any entity providing payment-related services directly or indirectly to a member or its merchants, which is broad enough to include gateways, billing platforms, fraud tools, and chargeback vendors. Your acquirer makes the determination.

Do I register the vendor myself?

No. Registration is the member's obligation. Your acquirer registers agents engaged by its merchants, using Visa's Program Request Management application.

Can I start integrating while registration is pending?

The rules say registration must be completed before the performance of any contracted services or transaction activity. Ask your acquirer what it will allow, and get the answer in writing.

My vendor says it's already registered with Visa. Is that enough?

Not on its own. Registration is specific to each acquirer, so a vendor registered under one acquirer needs registering again by another. Ask which acquirer.

What happens if Visa rejects the registration?

Visa may deny or reject a registration at any time, with or without cause. There's no published criteria or appeal, which is the argument for confirming registration before you commit contractually.

What's changing in October 2026?

In the US and Canada, members will have to disclose the numeric IDs, issuing and acquiring identifiers, BINs, and account ranges their agents use, and keep that information current with an annual review.

Not sure which of your vendors your acquirer treats as a registrable agent? Apply free or talk to a specialist and we'll map your stack against what actually needs registering before it costs you a launch date.

JA

Jeffrey Anderson, Merchant Placement Specialist

Merchant placement specialist at Gray Merchants. Jeffrey works directly with acquiring-bank underwriting teams across the firm’s 70+ banking relationships to place high-risk and hard-to-place businesses, structure multi-MID accounts, and keep flagged merchants processing. His writing draws on the placement files he works every week: what underwriters ask for, why accounts get declined, and what keeps an approved account open.

Talk to a specialist

Tell us about your business

Share a few details and a specialist reviews your industry, volume, and processing history, then comes back with the right path. No obligation.

  • Underwriting decision in 24 to 48 hours
  • $0 setup fee, dedicated MID
  • Specialist replies within 4 business hours
  • Every term disclosed in writing before you sign

Request a call from a specialist

Are you currently processing?

No obligation. A specialist replies within 4 business hours, Mon to Fri, 9:00 to 18:00 EST.

Third Party Agent Registration: Who Has to Register | Gray Merchants