How merchant of record reduces your legal and compliance risk

Selling globally makes you liable for VAT, chargebacks, PCI scope and consumer protection. How a merchant of record moves that liability, and what stays put.

BY SANDRO ZWEIG

Summarize with AI

No headings found on page

Summarize with AI

No headings found on page

When you sell software to customers in other countries, you take on a set of legal obligations most founders never budgeted for. Tax registration in Germany. GST filings in Australia. Sales tax nexus across dozens of US states. OIDAR rules in India. Data residency requirements under GDPR. Consumer protection statutes that vary by jurisdiction.

Most teams discover this exposure after the fact: an audit notice, a chargeback they did not know how to handle, or an invoice that fails local formatting requirements. By the time compliance becomes urgent, the risk is already sitting on your balance sheet.

A Merchant of Record shifts that risk to a different legal entity. It transfers who is legally responsible for meeting the obligations.

What a merchant of record actually is

A Merchant of Record (MoR) is the legal entity that processes transactions, assumes tax and compliance responsibility, and manages refunds and liabilities for every sale made on your behalf. In practice, that means the MoR's name sits on the invoice. Their legal entity files the tax returns. When a customer disputes a charge, the chargeback lands with the MoR, not with you.

The mechanism is a licence rather than a sale. You appoint the MoR as a non-exclusive reseller with the right to sell your product in its own name. It then sells to the end customer. Two transactions happen at once: one between you and the MoR, one between the MoR and your customer. Nothing about your product changes hands, and nothing about the customer experience changes either.

Two terms get used interchangeably here and they should not be. The seller of record is the entity legally selling the product, responsible for commercial terms: warranties, returns, consumer protection. The merchant of record is the entity that processes the payment and carries the financial and tax liability attached to it. A full MoR provider usually wears both hats, which is what makes the model useful, but the scope of what you have transferred depends on the contract rather than on the label. Read it carefully before assuming a given obligation has moved.

The six compliance risks a merchant of record takes off your plate

1. Consumption tax liability

This is the most immediately consequential risk for most SaaS companies. When you sell to a customer in the EU, someone has to register for VAT, calculate the right rate, collect it from the customer, and remit it to the correct tax authority. The same logic applies to UK VAT post-Brexit, GST in Australia for digital services, GST in Canada and New Zealand, India's OIDAR regime, Japan's JCT, and US state sales tax under the economic nexus rules established by South Dakota v. Wayfair in 2018.

If you sell direct, that 'someone' is you. And the registration requirements, filing deadlines, and currency-denominated remittances are different in every jurisdiction.

A Merchant of Record absorbs this entirely. The MoR is registered in each supported jurisdiction, calculates tax at the point of sale, collects it, and remits it directly to the relevant authority. Your business is insulated from VAT audits, underpayment penalties, and the compliance overhead of maintaining registrations across markets.

2. Invoicing and documentation obligations

Tax-compliant invoicing is not optional in most markets. The EU requires invoices to include the supplier's VAT number, the customer's VAT number for B2B transactions, the applicable tax rate, and the gross and net amounts separately stated. India requires GST invoices with specific fields. Brazil's nota fiscal requirements are famously complex.

If your invoices do not meet local requirements, the tax authority may reject them. That creates exposure for the buyer and, depending on the jurisdiction, liability for you.

When a Merchant of Record handles the transaction, it issues the compliant invoice under its own legal identity. The invoice reflects the MoR's tax registration, formatted to meet the requirements of the customer's jurisdiction. This removes a low-profile but genuine source of compliance risk that compounds as you add markets.

3. Chargeback and dispute liability

Under card network rules, the merchant of record on the transaction is responsible for chargeback disputes. That means absorbing the disputed amount during the investigation period, defending the case with the card network, and accepting the outcome.

If you process payments directly, your business carries this liability on every transaction, and the monitoring regime has tightened. Visa's Acquirer Monitoring Program now combines fraud reports and disputes into a single ratio with no early-warning tier. As of April 2026 the excessive merchant threshold is 1.5% across the US, Canada, the EU, Asia-Pacific and Latin America, down from 2.2%, with fees of 8 dollars per dispute once you cross it. Mastercard runs a separate program that triggers at 100 chargebacks in a month combined with a 1.5% ratio. Sustained breaches escalate to acquirer remediation demands and, at the far end, loss of card acceptance.

A Merchant of Record steps in as the transacting entity and takes on chargeback liability in its place. The MoR manages the dispute process with card networks directly. Your business is not the defendant in those proceedings. You still bear commercial responsibility for the product experience, but the legal and financial exposure from fraudulent chargebacks sits with the MoR.

4. KYC and fraud screening

Payment regulations in most jurisdictions require Know Your Customer checks at some level, particularly for high-value transactions or markets with elevated fraud risk. The requirements vary: some are identity-focused, some are risk-based, some apply only above certain transaction thresholds.

When a Merchant of Record processes the transaction, it conducts KYC and fraud screening on its own behalf. The MoR holds the relationships with card networks and acquiring banks, so the regulatory requirements flow to it. You benefit from the MoR's fraud detection infrastructure without building or maintaining it yourself.

5. PCI DSS and data privacy scope

If your business directly processes card payments, you are subject to the Payment Card Industry Data Security Standard. PCI DSS compliance requires quarterly vulnerability scans, annual assessments at higher merchant levels, and ongoing security controls around cardholder data. Failures lead to fines, remediation costs, and potential loss of card acceptance rights.

A Merchant of Record owns the payment infrastructure and holds PCI compliance on your behalf. Cardholder data is never stored or processed on your systems. Your PCI scope drops significantly, often to SAQ A, the lightest validation tier.

It does not drop to nothing, and that is the part teams get wrong. Under PCI DSS v4.0.1, the current version, the Council removed the payment page script requirements from SAQ A in 2025 and replaced them with an eligibility criterion: you must be able to confirm that your site is not susceptible to script-based attacks affecting your e-commerce systems. That criterion covers your whole website, not just the checkout. Outsourcing the payment page moves the cardholder data out of your environment. It does not move responsibility for what runs on your own pages.

The same logic applies partially to data privacy. The MoR processes customer payment data under its own privacy policy and data handling framework. This does not eliminate your GDPR obligations for data you collect directly, but it reduces the surface area of sensitive payment data flowing through your systems.

6. Consumer protection and refund rules

Consumer protection law varies significantly by market. Australia's consumer law has its own mandatory guarantees. Some jurisdictions restrict automatic subscription renewals without explicit re-consent. And the EU rules on withdrawal rights just moved.

The EU gives consumers a 14-day right of withdrawal on distance contracts. Traders have long relied on an exception that lets them exclude it for digital content, provided the customer expressly consents to immediate supply and acknowledges losing the right. In July 2026 the Court of Justice narrowed that route sharply. In Sky Österreich Fernsehen, the court held that an offering which updates dynamically and adapts to individual user behaviour is a digital service, not digital content, and the digital-content exception does not apply to it. The court also said the exception must be read strictly, and that where there is doubt, the rules for services apply.

That reasoning covers a large share of SaaS. If your product ships updates and personalises what the user sees, the consent-and-waiver checkbox in your signup flow may no longer extinguish the withdrawal right. Consumers who withdraw after asking you to start can be charged proportionate compensation for use, but that is a different position from having no cancellation exposure at all.

If you sell directly, working out which of these applies to you is your problem. Miss it, and you face refund disputes, regulatory complaints, and potential fines.

A Merchant of Record absorbs these obligations as the legal seller. It operates under its own terms of service with the end customer, designed to meet the consumer protection requirements of each jurisdiction. The refund rules, withdrawal rights, and renewal disclosure requirements are its problem, not yours.

What a merchant of record does not cover

The category is sometimes oversold.

A Merchant of Record covers consumption taxes: VAT, GST, and sales tax on the transactions it processes. It does not cover your corporate income tax, your home jurisdiction tax filings, transfer pricing arrangements if you operate multiple entities, or 1099 reporting obligations to your own contractors and suppliers.

It also does not eliminate your obligations around data you collect independently of payments: product usage data, analytics, or user profiles governed by GDPR or CCPA still fall on you.

It is also worth knowing that the model sits in a grey area rather than a settled one. Merchant of record is not expressly recognised in card brand rules, and regulators have taken an interest in arrangements where a third party runs another company's charges through its own merchant accounts. The FTC has brought an action on those grounds. This is not an argument against the model, which is used at scale by reputable providers. It is an argument for choosing a provider that discloses its role clearly at checkout and can explain its licensing position, rather than one that treats the structure as a black box.

The MoR is a transaction-layer risk transfer. It handles the compliance surface that typically consumes the most time for early-stage SaaS companies selling globally. But it works alongside your tax advisor and legal counsel, not instead of them.

When the MoR model makes sense

The MoR model tends to make sense earlier than most founders expect.

If you are selling to customers in more than two or three countries, the administrative overhead of managing tax registrations directly starts to compound quickly. If your product is fully digital and delivered online, you typically trigger tax obligations in every market where you have customers, even without a physical presence.

The tipping point for most teams is one of three moments: they close their first enterprise customer who needs a properly formatted VAT invoice, they get an inquiry from a tax authority in a country where they did not know they had an obligation, or a chargeback dispute triggers a review of their merchant account.

At each of those moments, the MoR model resolves the problem at the infrastructure level rather than forcing you to solve it market by market as the issues surface.

Where MoR fits inside your broader stack

For SaaS and AI companies, Merchant of Record is rarely the only infrastructure question on the table. Authentication, billing, customer data, and analytics all have to work together, and the integration overhead between separate tools adds up fast.

Tiun includes Merchant of Record as a native part of its backend platform for SaaS and AI companies, alongside authentication, payments, customer database, and analytics. Teams using Tiun do not configure MoR as a separate vendor relationship: it is already part of the system handling their transactions. Automated invoicing, subscription payments, and monthly payouts are built into the same platform. Whether that is the right fit depends on where you are in your stack decisions, but it is worth knowing the option exists before defaulting to a standalone MoR provider that leaves the rest of the backend fragmented.

Frequently asked questions

Is a Merchant of Record the same as a payment processor?

No. A payment processor moves money between the customer's account and yours and stops there. You remain the legal seller, which means you retain all tax, invoicing, and dispute obligations. A Merchant of Record is the legal entity that processes transactions, assumes tax and compliance responsibility, and manages refunds and liabilities for every sale made on your behalf. Its name sits on the invoice and its legal entity files the tax returns. The distinction matters most when tax authorities or card networks have questions, because those conversations go to the MoR, not to your business.

Does using a Merchant of Record mean I do not need to register for VAT anywhere?

In the jurisdictions where the MoR operates and processes your transactions, the MoR holds the tax registrations and remits the tax on your behalf. You are not the seller on those transactions, so you do not have the registration obligation for them. If you also sell direct in some markets, or have a physical presence that creates a separate tax nexus, you may still have obligations in those contexts. A tax advisor can confirm what applies to your specific setup.

Who is legally responsible if the Merchant of Record makes a tax error?

The Merchant of Record. Because it is the legal seller on the transaction, it holds the obligation and the liability. If it miscalculates VAT and the tax authority raises an assessment, that assessment is directed at the MoR, not at your business. The qualification worth reading for is in your contract. MoR agreements typically include representations about the product data you supply, including classification and the markets you sell into, and indemnities that can push liability back to you if that data was wrong. The seller-of-record substitution is real protection. It is not unconditional.

What happens to my chargeback rate when I use a Merchant of Record?

Chargebacks on transactions processed by the MoR attach to the MoR's merchant account, not yours. Your chargeback rate as a direct merchant is unaffected by those disputes. This matters because network monitoring programs have tightened, with Visa's excessive merchant threshold dropping to 1.5% in April 2026 and per-dispute fees attached, and insulating your own merchant account from the volume reduces your exposure to those thresholds.

Summarize with AI