Parties & Authority
Clear legal names, entity types, and signatory authority; specify whether affiliates may act and how delegated authority is documented and revoked.
A well-drafted Legal ISO Agreement clarifies roles, reduces operational risk, and documents compliance responsibilities including PCI and data privacy. It makes dispute resolution and liability allocation explicit and supports auditability for regulators and partners under ESIGN/UETA frameworks.
The Legal ISO Agreement is used by commercial parties that manage merchant acquiring and payment services.
Use this agreement when onboarding merchants, delegating underwriting, or establishing a reseller relationship that involves cardholder data or payment processing.
Typically a bank or processor that signs to accept merchants and delegates defined duties to the ISO. Their review focuses on underwriting standards, settlement flows, and regulatory compliance clauses.
An authorized officer of the ISO who signs to accept responsibilities such as merchant onboarding, KYC, PCI controls, chargeback handling, and indemnity obligations; ensure authority appears on corporate records.
Clear legal names, entity types, and signatory authority; specify whether affiliates may act and how delegated authority is documented and revoked.
Detailed description of merchant acquisition activities, underwriting limits, transaction routing, settlement responsibilities, and any technology platform or API use.
Precise fee schedules, chargeback responsibility, timing of remittances, reserve requirements, and methods for adjusting rates or withholding funds.
PCI-DSS obligations, data breach notice timing, PHI handling if applicable, and requirements for audits and certifications.
Mutual indemnities for third-party claims, caps on liability where negotiated, and carve-outs for willful misconduct or fraud.
Initial term, renewal mechanics, termination for cause or convenience, transition assistance, and post-termination data retention obligations.
| Field | Configuration |
|---|---|
| Signer Order | Sequential or parallel routing |
| Authentication | Email link, SMS code, or KBA |
| Conditional Fields | Show fields based on selections |
| Notifications | Email reminders and completion alerts |
Choose a platform that supports secure uploads, robust audit trails, and industry integrations to maintain operational continuity.
Verify the platform supports required compliance (e.g., HIPAA BAA if PHI is present), audit trails for ESIGN/UETA, and administrative controls for retention and access.
Date obligations begin; affects liabilities and enforcement.
Time required for termination or contract changes.
Period for automatic or negotiated renewal.
Settlement schedule for fees and reserve adjustments.
When retention clock begins for compliance purposes.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes | Yes | Yes | Yes | Limited |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |
Tim Martin needed rapid execution to onboard property-management merchants
BIS prioritized compliance and auditability for merchant agreements
Prepare and approve the final contract language before sending to parties.
Confirm signers and required attachments are present prior to sending.
All parties sign and dates are recorded with audit evidence.
Provide copies to operations, finance, and compliance teams for onboarding.