AboutPricing

Mass Payments Are Not Compliance: What AP Still Owns After the Batch File Leaves

September 6, 2026

|

8

minutes to read

Mass Payments Are Not Compliance: What AP Still Owns After the Batch File Leaves
Mário Sérgio Rodrigues

Mário Sérgio Rodrigues

View author profile

Share

76% of US organizations experienced attempted or actual payments fraud in 2025, and 74% were hit by business email compromise, according to the 2026 AFP Payments Fraud and Control Survey released in April 2026. 

In most of those cases the file went out and the money moved exactly as instructed, and the problems started after.

Gigapay is the Merchant of Record for creator payouts: the one vendor solution that pays your creators on your behalf by taking on the compliance, payouts, and support so you don't have to. Payment rails and AP tools move money and generate paperwork, and that distinction is exactly what this article is about.

Mass payments products have trained finance teams to believe the hard part of paying hundreds of people is the sending. PayPal Mass Pay, bank batch files, and every "upload a CSV" button in the market solve one problem: many credits, one click. Sending was never the hard part. After the batch file leaves, accounts payable still owns onboarding, tax documentation, invoicing, payment support, fraud controls, and the question no batch file answers: who is the legal buyer of the work you just paid for?

This article breaks down what mass payments actually solve, what stays on AP's desk after the file leaves, what that ownership costs in hours and penalties, and how a Merchant of Record changes what your spreadsheet means.

Key Takeaways

  • Mass payments solve sending. Onboarding, tax, invoicing, support, and fraud stay with you.
  • A batch file is a payment instruction, not a control environment.
  • DAC7 fines run per seller. Germany's reach €50,000. Sweden's run SEK 2,500 to 12,500.
  • 76% of US organizations faced payments fraud in 2025, per the 2026 AFP survey.
  • A Merchant of Record becomes the legal buyer. A mass pay button never does.
Mass Payments Are Not Compliance

What Mass Payments Are and Where They Came From

Mass payments, also called mass payouts or batch payments, let a business send many payments in a single operation instead of initiating each transfer by hand. The mechanics are decades old. A finance team assembles a file with recipient details and amounts, uploads it to a bank portal or a payment service provider, and the system executes hundreds or thousands of credits from one funding source.

The product category grew in three waves. Banks offered batch file uploads for payroll and supplier runs, usually in formats like SEPA XML, BACS, or NACHA. Then PayPal launched Mass Pay (later rebranded PayPal Payouts), which let any business pay up to thousands of recipients from a CSV or an API call. Then a generation of payout platforms turned the same idea into a polished dashboard: upload a spreadsheet, click send, watch the status column turn green.

Every wave sold the same promise. Paying many people should be as easy as paying one. On the narrow question of execution, the promise is true. On everything surrounding the payment, the promise is silent.

Why Finance Teams Reach for Mass Payments

The demand is real. A brand running creator campaigns at scale can easily process 300 to 600 individual payments per year, and affiliate networks and marketplaces process far more. Initiating those transfers one by one is a full-time job nobody wants. Mass payments compress that job into minutes.

The trap is what the compression hides. When the operational pain of clicking "send" 400 times disappears, teams conclude the payment problem is solved. The payment problem was never just the sending. It was everything the sending assumes has already happened: verified identities, collected tax forms, confirmed eligibility, agreed invoices, and a plan for the payments that fail.

Why Every Creator Payment Is Now a Compliance Event

The creator economy professionalized faster than the payment infrastructure behind it. Europe alone has 8.6 million creators earning income, and creator marketing budgets have compounded at roughly 26% per year, yet in most companies the money still moves the way it did in 2015: a spreadsheet, a batch file, and hope.

Regulators noticed. The last three years turned creator payments from a marketing line item into a reporting obligation with named forms, filing deadlines, and per-seller penalties.

The Regulatory Calendar AP Now Answers To

  1. DAC7 (EU): Platform operators must collect and verify seller information and report income data to tax authorities annually. Sweden fines SEK 2,500 to 12,500 per unreported seller. Germany's DAC7 penalties reach €50,000. The fines multiply by recipient count, which is exactly the dimension mass payments scale.
  2. Germany: The Künstlersozialkasse levy hit 4.9% in 2026 on payments for commissioned creative work above €1,000, and it applies even when the creator sits abroad. On top of that, §50a withholding of 15.825% applies to certain payments to foreign creators, with the paying company liable if it fails to deduct. North Rhine-Westphalia investigators are running criminal probes into roughly €300 million in suspected evasion tied to influencer income, and Hamburg's tax office is auditing 140 influencers.
  3. United Kingdom: Joint and several liability rules for umbrella arrangements went live on 6 April 2026, and HMRC has been sending platform-data nudge letters to creators. HMRC recovered more than £41 billion in FY2024, with employment status a stated priority.
  4. Spain: IRPF withholding at 15% (or 7% for new professionals) plus Modelo 111 and 190 filings, plus Modelo 238 platform reporting, plus self-billing rules under RD 1619/2012.
  5. United States: The Form 1099-K reporting threshold dropped to $600 for 2026, which multiplies reporting obligations for anyone paying US-based recipients through third-party networks.

None of these obligations attach to the payment rail. All of them attach to the party commissioning and paying for the work. Read that sentence again before your next batch run, because it decides who gets the audit letter.

What Mass Payments Actually Solve

Credit where it is due. A mass payments product solves execution, and it solves it well.

  • One operation, many credits: A single file or API call replaces hundreds of manual transfers.
  • Fewer keying errors: Structured data beats retyping IBANs at 6 p.m.
  • Status visibility: Sent, pending, failed, all in one screen.
  • Funding consolidation: One debit from your account instead of hundreds.

That is a genuine improvement over manual initiation, and no serious finance team should go back. The mistake is treating execution as the whole job. In the payment lifecycle, execution is one step out of roughly seven, and it happens to be the easiest one to automate.

Mass Payments Are Not Compliance

What AP Still Owns After the Batch File Leaves

Here is the honest inventory. Each of these stays with your team after any mass payments run, whether the file went through a bank, PayPal Payouts, or a payout dashboard.

Recipient Onboarding and Identity Verification

Who are these people? A batch file contains a name, an account number, and an amount. It does not confirm the person exists, that the account belongs to them, or that they are who your marketing team believes they are. KYC on payees, verifying tax IDs, and screening against sanctions lists remain your controls to design and run. 

The 2026 AFP survey's finding that 74% of organizations faced business email compromise matters here, because a compromised email chain that swaps one IBAN in a 400-row file produces a payment your mass payments tool will execute flawlessly.

Eligibility: Whether You May Pay Them at All

Some recipients cannot legally be paid the way your file assumes. 

  • A Serbian company paying a Serbian individual directly triggers a statutory withholding obligation under Article 101 of the Serbian PIT law, on every payment, at the time of payment. 
  • A German company paying a foreign creator may owe §50a withholding before the money leaves. 
  • A Spanish payer owes IRPF withholding. 

The batch file does not check any of this. Your AP team is expected to know it, per country, per recipient type, before clicking send.

Tax Documentation: The Form You Needed Before Paying

W-9 and W-8 collection for US-connected recipients, tax residency certificates for treaty relief, VAT status checks, self-employment status confirmation in markets where it decides the withholding treatment. Every one of these documents needed to exist before the payment, and the mass payments product will not stop you if they don't. The gap only surfaces months later, usually in January.

The January Problem: What You Will File

DAC7 reports. 1099s. KU14 in Sweden. Modelo 238 in Spain. The filing season converts every row of every batch file from the past year into a reporting line, and the data quality of those filings depends entirely on the documentation you collected at onboarding. Teams that skipped step three discover it at step four, with per-seller fines attached.

Invoicing: Who Is on the Paper

A payment without a matching invoice is an accounting problem waiting for an auditor. When you mass pay 400 creators, you need 400 invoices or a compliant self-billing arrangement, and self-billing rules differ by country. Spain regulates it under RD 1619/2012. The Bahamas does not permit it at all. 

Your mass payments tool generated a payment confirmation, which is not an invoice, and your books know the difference.

Support: Who They Call When It Fails

Payments fail. Wrong account numbers, closed accounts, intermediary bank rejections, name mismatches. In a 400-row file, even a 3% failure rate means a dozen creators messaging your campaign manager asking where their money is. That support load lands on marketing and AP, it arrives at the worst time, and it directly damages the creator relationships the campaign was built on.

Fraud Controls

Treasury departments discovered 83% of attempted fraud in 2025, per the AFP survey. Mass payments concentrate risk: one manipulated file moves hundreds of payments at once. Dual approval, out-of-band verification of bank detail changes, and anomaly review before release are your controls. The product ships none of them as obligations, only as options you must remember to configure and enforce.

The Legal Buyer Problem

This is the one nobody prices in. When your company pays a creator directly, your company is the buyer of that creative service. Your name goes in the contractual chain, the withholding obligations attach to you, the platform reporting duties can attach to you, and the vendor record sits in your ERP. 

Multiply by 400 recipients across 20 countries and your vendor master becomes a liability register. Mass payments tools do not touch this question. They cannot, because they are payment instructions, and the buyer of record is a legal position, not a payment field.

The Sentence to Put in Your Payments Policy

If your AP policy needs one line to prevent the category error, use this one:

A batch file is a payment instruction. It is not a control environment.

Everything in the previous section follows from that sentence. Instructions execute. Control environments verify, document, withhold, report, invoice, and answer the phone. When a team says "we already do mass payments," they are describing an instruction pipeline, and the correct follow-up question is who owns the control environment around it. In most companies the honest answer is "AP, informally, with spreadsheets."

Mass Payments Are Not Compliance

What the Control Environment Costs When AP Owns It

The ownership described above has a price, and it is measurable.

  • Hours: Gigapay's analysis of a brand running 600 creator collaborations per year puts the manual administration burden at roughly 840 hours annually: vendor setup, document collection, invoice matching, failure handling, and reporting prep. That is 40% of a full-time role spent on work no one was hired to do.
  • Cost per payment: The all-in cost of a "free" manual creator payment runs approximately €40 to €60 once you count the AP time, the error cycles, and the reporting overhead. On 600 payments, the manual process costs around €139,590 per year against roughly €46,350 with the administration removed.
  • Penalties: The exposure is retroactive. DAC7 fines apply per seller per year. German KSK audits reach back five years. Swedish F-skatt withholding traps surface in reviews long after the payments are cleared. A team that ran clean-looking batch files for three years can inherit three years of accumulated filing gaps in a single audit letter.
  • Vendor sprawl: Onboarding 300 creators as individual vendors means 300 vendor records, 300 sets of banking details to maintain, and 300 entries your procurement team must eventually rationalize. Finance leaders describe the alternative simply: one counterparty in the vendor master instead of a thousand micro-vendors and a tax exposure you can't see.

How a Merchant of Record Changes What Your Spreadsheet Means

Here is the part that surprises teams comparing options. Gigapay also accepts a spreadsheet. Name, email, amount. Upload it and hundreds of creators get paid, instantly when the account is pre-funded, across 65+ countries and 50+ currencies.

The difference is not the file. The difference is what stands behind the file.

When you upload a CSV to a mass payments button, the file is the entire product. When you upload a CSV to Gigapay, the file is only the instruction, and the control environment already exists behind it:

  • Onboarding is done before payment: Creators verify identity through KYC, confirm their tax status, and can be paid as individuals without a registered company. Your file references people the system already knows.
  • The legal buyer changes: Gigapay purchases the creator's deliverable and resells it to you, becoming the formal counterparty. You pay one B2B invoice to one vendor of record instead of holding 400 direct payee relationships.
  • Reporting is filed, not exported: DAC7 reporting, KU14 in Sweden, and KSK handling in Germany run as part of the service rather than as a January project on your side.
  • Invoicing collapses: Consolidated invoicing and automated self-billing cut invoice volume by around 80%. One invoice per campaign instead of hundreds.
  • Support moves: When a payment fails or a creator has a question, they contact Gigapay's support team, which holds a creator NPS of 88. Your campaign managers stay out of banking troubleshooting.
  • Creators keep what they earn: On all new plans, the client covers the fees.

The comparison to a PSP mass-pay button is therefore not a feature race. Both accept a spreadsheet. One executes it. The other absorbs the ownership inventory this article just walked through. For platforms and high-volume brands that have outgrown spreadsheets entirely, the same control environment is available through an API with a typical integration time of two to five days.

One honest boundary, because precision matters in this category: as Merchant of Record, Gigapay takes over most administrative and legal responsibilities connected to the purchase of the creative's deliverable, and each party remains responsible for complying with its own tax obligations under applicable law. That is a materially different position from a payment rail, and it is also not a magic shield, so treat any vendor who promises one with suspicion.

The Question to Ask Before Your Next Batch Run

Teams evaluating this space tend to ask about rails, currencies, and fees. Those questions matter less than one that takes ten seconds:

Who is the legal buyer of the services in this file?

If the answer is your company, then every control in this article is yours: the onboarding, the withholding analysis per country, the documentation, the January filings, the invoices, the failure support, and the fraud review. Your mass payments tool executed the instruction and left the ownership exactly where it found it.

If the answer is a Merchant of Record, the spreadsheet stays, the speed stays, and the ownership moves.

A second diagnostic works almost as well: Ask your AP team what they will file in January for the recipients in last quarter's batch runs, and in which countries. If the answer requires a meeting, the control environment does not exist yet.

Mass Payments Are Not Compliance

Conclusion

Gigapay is the Merchant of Record for creator payouts, the one vendor solution that pays your creators on your behalf by taking on the compliance, payouts, and support so you don't have to, while payment rails and AP tools move money and generate paperwork.

Mass payments earned their place in the finance stack by solving execution, and nothing in this article argues against them. The argument is about scope. 

Sending is one step in a lifecycle that includes verifying who you are paying, confirming you may pay them, collecting the forms the payment requires, filing what regulators expect, matching invoices, answering failed-payment messages, and standing behind the transaction as its legal buyer. 

A batch file is a payment instruction, and after it leaves, AP owns everything the instruction assumed. With per-seller DAC7 fines, German audits reaching back five years, and 76% of organizations facing payment fraud attempts, that ownership now carries a price tag that makes the "we already do mass payments" position expensive to hold.

Keep your CSV, move the ownership: book a demo with Gigapay and run your next campaign with one vendor of record behind the file.

Read Next:

FAQs:

1. What is the difference between mass payments and a Merchant of Record? 

The difference between mass payments and a Merchant of Record is scope of ownership: mass payments execute many credits from one file, while a Merchant of Record like Gigapay becomes the legal buyer of the creator's service and takes on the compliance, payouts, and support surrounding the payment.

2. Is Gigapay a mass payments tool like PayPal Mass Pay? 

Gigapay is not a mass payments tool like PayPal Mass Pay; it is mass payouts plus Merchant of Record, meaning it accepts the same spreadsheet but also becomes the vendor of record, handles creator onboarding and tax reporting such as DAC7, and provides creator support.

3. Can our finance team keep using a CSV for mass payments with Gigapay? 

Your finance team can keep using a CSV for mass payments with Gigapay, because the CSV remains the payment instruction with name, email, and amount, while Gigapay provides the control environment behind it: onboarding, compliance, invoicing, and support.

4. What does AP still own after sending a mass payments batch file? 

After sending a mass payments batch file, AP still owns recipient onboarding and KYC, per-country withholding analysis, tax form collection, January filings like DAC7 and 1099s, invoice matching, failed-payment support, and fraud controls, unless a Merchant of Record has taken them on.

5. Does Gigapay offer an API for high-volume mass payments? 

Gigapay offers an API for high-volume mass payments, built for platforms and high-volume brands, with a typical integration time of two to five days and the same Merchant of Record structure behind every payout in 65+ countries.

KYC and KYB for Vendor Onboarding: What AP Should Collect Before a Payee Hits the Master File

September 5, 2026

KYC and KYB for Vendor Onboarding: What AP Should Collect Before a Payee Hits the Master File

IR35 in 2026: What Finance Still Owns When You Pay UK Limited-Company Contractors at Scale

September 4, 2026

IR35 in 2026: What Finance Still Owns When You Pay UK Limited-Company Contractors at Scale

W-9, W-8BEN, and 1042-S: The Foreign-Vendor File AP Must Have Before the First Payment

August 31, 2026

W-9, W-8BEN, and 1042-S: The Foreign-Vendor File AP Must Have Before the First Payment