A merchant account is what allows a business to accept card payments. It is provided by an acquiring bank or a payment service provider, and the application is a credit and risk assessment rather than a simple account opening — because the acquirer carries the exposure if you fail to deliver what customers paid for.
Understanding that is what explains the requirements. The acquirer is underwriting your ability to fulfil orders, and everything it asks for goes to that risk.
Business Requirements at a Glance
An application to an acquirer or payment service provider typically requires the following.
- A registered legal entity, with CIPC documents, or a registered sole proprietorship
- A business bank account in the entity’s name for settlement
- FICA verification of the business, its directors and its beneficial owners
- A valid SARS tax compliance status
- Description of the business, its products and its trading model
- Trading history and turnover figures, or projections for a new business
- For online merchants: a website meeting the acquirer’s and card scheme requirements
- Compliance with PCI DSS at the level appropriate to your transaction volume
- Acceptance of the merchant agreement, including chargeback and reserve provisions
Registration and Legal Requirements
Risk assessment drives the outcome. Acquirers classify businesses by risk based on the product, the delivery model and the chargeback profile of the sector. Businesses selling goods delivered immediately are low risk; businesses taking payment for future delivery — travel, events, subscriptions, pre-orders, custom manufacture — are higher risk, because the acquirer is exposed if the business fails before delivering.
High-risk classification does not mean refusal. It means a rolling reserve, higher fees, or a delayed settlement cycle. Understand which applies before signing.
Chargebacks are the exposure that surprises merchants. A cardholder disputing a transaction can have it reversed, and the merchant bears the amount plus a fee. Excessive chargeback ratios lead to penalties and, ultimately, termination and listing on card scheme databases that make obtaining another merchant account difficult.
PCI DSS compliance is a card scheme requirement, not optional. The level of validation depends on transaction volume, and most small merchants can satisfy it through a self-assessment questionnaire — particularly if they use a hosted payment page so that card data never touches their systems.
Using a hosted payment page or a tokenising gateway is the single most effective way for a small merchant to reduce PCI scope, cost and risk. Storing card data yourself is almost never worth it.
Documents and Ownership Information Required
The documents an acquirer or payment service provider will ask for.
- CIPC registration documents, company profile and memorandum of incorporation
- Certified identity documents and proof of address for directors and beneficial owners
- Beneficial ownership information as filed with the CIPC
- Business bank account confirmation letter for settlement
- SARS tax compliance status PIN
- Recent bank statements, commonly three to six months
- Financial statements or management accounts, for established businesses
- Website address, terms and conditions, refund policy, delivery policy and privacy notice
- Proof of business address
- Details of any previous merchant account and its termination, if applicable
- Completed merchant application and signed merchant agreement
Tax, Licence and Compliance Requirements
Consumer protection law shapes what your website must say. The Consumer Protection Act 68 of 2008 and the Electronic Communications and Transactions Act 25 of 2002 require online sellers to disclose specified information — identity, contact details, full price, delivery arrangements, and the cooling-off and returns position. Acquirers check for this because missing disclosures generate disputes.
The ECT Act gives consumers a cooling-off right for certain electronic transactions, and the CPA gives return rights in defined circumstances. Your refund policy must reflect the law rather than contradict it, and a policy purporting to refuse all refunds is unenforceable.
POPIA applies to the customer data you collect. A privacy notice, a lawful basis for processing, and appropriate security are required, and payment data attracts particular care.
Settlement timing matters commercially. Acquirers settle on a cycle, and a rolling reserve holds back a percentage for a period against chargebacks. For a business with thin margins, that timing is the difference between working and not, and it should be negotiated and understood before signing.
Read the termination and reserve clauses. Acquirers can suspend settlement and hold funds where risk indicators change. That is contractual, and merchants who have not read those clauses discover them at the worst moment.
Compare providers. Traditional acquiring banks, payment service providers and aggregators offer different pricing, settlement and onboarding models. Aggregators onboard faster with less documentation but generally cost more per transaction and can be quicker to suspend.
Process, Deadlines and Ongoing Obligations
Prepare the website and policies before applying. A significant share of online merchant applications are delayed because the site lacks the disclosures the law and the acquirer require.
Then apply to more than one provider and compare the full picture — transaction fees, monthly fees, settlement cycle, reserve, chargeback fees and termination terms — rather than the headline rate.
- Prepare CIPC, FICA and tax compliance documents before applying
- Get the website disclosures, terms, refund and privacy policies right first
- Use a hosted payment page to minimise PCI scope
- Understand your risk classification and any rolling reserve before signing
- Read the chargeback, reserve and termination clauses carefully
- Compare acquirers, payment service providers and aggregators on the full cost
- Keep chargeback ratios low — excessive ratios lead to termination
- Confirm current requirements with the acquirer or provider directly
Frequently Asked Questions
Why is a merchant application a credit assessment?
Because the acquirer is exposed if you take payment and fail to deliver. Everything it asks for goes to that risk.
What is a rolling reserve?
A percentage of your settlements held back for a period against potential chargebacks. It applies commonly to higher-risk businesses and materially affects cash flow.
Do I need PCI DSS compliance?
Yes, at the level appropriate to your volume. Most small merchants satisfy it through a self-assessment questionnaire, particularly when using a hosted payment page.
What does my website need?
The disclosures required by the Consumer Protection Act and the ECT Act — identity, contact details, full price, delivery, cooling-off and returns — plus a POPIA-compliant privacy notice.
Onboarding requirements, risk classifications, fees and settlement terms are set by each acquirer or payment service provider and by the card schemes, and they change. Confirm current requirements with the provider before applying.