Two creator platforms can look almost identical from the outside — same kinds of creators, same payout flows, same product categories — and carry completely different amounts of compliance risk. The difference usually comes down to one architectural choice: whether the platform is the Merchant of Record for its creators, or passes each creator through to the processor as their own merchant. That choice determines who the processor holds responsible, and therefore who actually carries the liability.
The Merchant of Record model
The Merchant of Record is the legal entity responsible for a transaction in the eyes of the payment processor and the card networks. It holds the processor relationship, handles chargebacks, remits tax where applicable, and answers to the processor for compliance.
When a platform operates as the Merchant of Record on behalf of its creators, it takes on all of that. Creators get a smooth experience — they do not need their own processor accounts, they just get paid — but the platform becomes the single party the processor looks to for everything. Every creator's activity is, in compliance terms, the platform's activity. If a creator sells something prohibited, it is the platform's Merchant of Record status that carries the violation.
This model concentrates risk. It is also extremely common in the creator economy, precisely because it makes the creator experience frictionless. Print-on-demand platforms, digital product storefronts, and many patronage platforms operate this way. The convenience for creators is real, and so is the liability it centralizes on the platform.
The pass-through model
The alternative is pass-through, where each creator onboards directly onto the processor and becomes their own merchant of record. The platform facilitates the connection but is not the responsible party for the creator's transactions in the same way. Compliance responsibility shifts substantially toward the individual creator and their own processor relationship.
Pass-through reduces the platform's direct Merchant of Record liability. If a creator who is their own merchant violates processor policy, the primary exposure sits with that creator's account rather than being concentrated on the platform. For a platform worried about carrying every creator's risk, this looks appealing, and it is one reason some platforms have moved toward it.
But pass-through is not a clean exit from compliance concern. A platform that facilitates onboarding still has reputational and, depending on structure, operational exposure to what its creators do. And moving to pass-through changes the platform's business model and its relationship to creators in ways that go well beyond compliance. It is a strategic choice, not just a risk-reduction lever.
Why the distinction is the starting point for everything
The reason this matters so much is that a platform cannot reason about its processor exposure at all without first knowing which model it operates. The same non-compliant creator produces a very different liability picture depending on whether the platform is the Merchant of Record or merely a facilitator of a pass-through relationship.
For a Merchant of Record platform, every payout is the platform's own compliance surface. Vetting creators before payout is not optional risk management; it is protecting the platform's own processor account, because there is no separation between the creator's violation and the platform's liability. This is where payout compliance is most existential.
For a pass-through platform, the calculus is different but not absent. The platform carries less direct liability, but it still has an interest in the integrity of its ecosystem and, depending on how the arrangement is structured, may retain meaningful exposure. The durable compliance surface is smaller, but reasoning about it still starts with an honest account of where responsibility actually sits.
The practical question to ask
Any platform assessing its processor risk should begin with a single question: when a creator we pay violates a processor's policy, whose account carries the violation? If the answer is "ours," the platform is operating as Merchant of Record and its exposure is concentrated and direct. If the answer is "the creator's own," the platform has pushed liability outward, with all the strategic trade-offs that entails.
Most of the hardest payout-compliance problems live in the Merchant of Record world, because that is where a single non-compliant creator maps directly onto the platform's own standing with its processor. Knowing which world you are in is the prerequisite for every other compliance decision.
This article is provided for general educational purposes and is not legal, tax, or compliance advice. The structure of Merchant of Record and pass-through arrangements varies, and platforms should consult qualified counsel about their specific situation. Tumban provides advisory risk guidance and does not guarantee compliance outcomes.
Payout Compliance
7 min read
Merchant of Record vs Pass-Through: Who Actually Carries Processor Liability
Whether a platform is the Merchant of Record or passes creators through to the processor decides who carries the compliance liability. It is the single most important question for understanding a platform's real processor exposure.
Mahesh Premachandran
Founder, Tumban
Two creator platforms can look almost identical from the outside — same kinds of creators, same payout flows, same product categories — and carry completely different amounts of compliance risk. The difference usually comes down to one architectural choice: whether the platform is the Merchant of Record for its creators, or passes each creator through to the processor as their own merchant. That choice determines who the processor holds responsible, and therefore who actually carries the liability.
The Merchant of Record model
The Merchant of Record is the legal entity responsible for a transaction in the eyes of the payment processor and the card networks. It holds the processor relationship, handles chargebacks, remits tax where applicable, and answers to the processor for compliance.
When a platform operates as the Merchant of Record on behalf of its creators, it takes on all of that. Creators get a smooth experience — they do not need their own processor accounts, they just get paid — but the platform becomes the single party the processor looks to for everything. Every creator's activity is, in compliance terms, the platform's activity. If a creator sells something prohibited, it is the platform's Merchant of Record status that carries the violation.
This model concentrates risk. It is also extremely common in the creator economy, precisely because it makes the creator experience frictionless. Print-on-demand platforms, digital product storefronts, and many patronage platforms operate this way. The convenience for creators is real, and so is the liability it centralizes on the platform.
The pass-through model
The alternative is pass-through, where each creator onboards directly onto the processor and becomes their own merchant of record. The platform facilitates the connection but is not the responsible party for the creator's transactions in the same way. Compliance responsibility shifts substantially toward the individual creator and their own processor relationship.
Pass-through reduces the platform's direct Merchant of Record liability. If a creator who is their own merchant violates processor policy, the primary exposure sits with that creator's account rather than being concentrated on the platform. For a platform worried about carrying every creator's risk, this looks appealing, and it is one reason some platforms have moved toward it.
But pass-through is not a clean exit from compliance concern. A platform that facilitates onboarding still has reputational and, depending on structure, operational exposure to what its creators do. And moving to pass-through changes the platform's business model and its relationship to creators in ways that go well beyond compliance. It is a strategic choice, not just a risk-reduction lever.
Why the distinction is the starting point for everything
The reason this matters so much is that a platform cannot reason about its processor exposure at all without first knowing which model it operates. The same non-compliant creator produces a very different liability picture depending on whether the platform is the Merchant of Record or merely a facilitator of a pass-through relationship.
For a Merchant of Record platform, every payout is the platform's own compliance surface. Vetting creators before payout is not optional risk management; it is protecting the platform's own processor account, because there is no separation between the creator's violation and the platform's liability. This is where payout compliance is most existential.
For a pass-through platform, the calculus is different but not absent. The platform carries less direct liability, but it still has an interest in the integrity of its ecosystem and, depending on how the arrangement is structured, may retain meaningful exposure. The durable compliance surface is smaller, but reasoning about it still starts with an honest account of where responsibility actually sits.
The practical question to ask
Any platform assessing its processor risk should begin with a single question: when a creator we pay violates a processor's policy, whose account carries the violation? If the answer is "ours," the platform is operating as Merchant of Record and its exposure is concentrated and direct. If the answer is "the creator's own," the platform has pushed liability outward, with all the strategic trade-offs that entails.
Most of the hardest payout-compliance problems live in the Merchant of Record world, because that is where a single non-compliant creator maps directly onto the platform's own standing with its processor. Knowing which world you are in is the prerequisite for every other compliance decision.
This article is provided for general educational purposes and is not legal, tax, or compliance advice. The structure of Merchant of Record and pass-through arrangements varies, and platforms should consult qualified counsel about their specific situation. Tumban provides advisory risk guidance and does not guarantee compliance outcomes.