Most vendor pitches answer the questions nobody asked. The ones that predict a bad outsourcing decision are rare unless you bring them yourself.
A vendor's sales deck tells you what their platform does, not who's accountable when it breaks. In software payments, a vendor's code doesn't sit beside your product, it runs inside it.
That's the question that separates a smooth integration from a compliance headache six months in.
TL;DR
Compliance can be delegated, accountability can't,
Integration questions matter as much as security ones,
AI vendor tools need their own line of questioning,
Every good vendor question ends with a name, not a policy.
What compliance questions should you ask a payments vendor?
Just under 90% of large and midsize US commercial banking clients work with a fintech vendor for payments or cash management, per Datos Insights' 2026 Fintech 50 report.
Vendor relationships are the default now in software payments, so screening an outsourcing payments partner matters more. Dennis Overbeeke, CTO at New10, runs every vendor through a Change Risk Assessment.
"If we want to use a new vendor, we do a Change Risk Assessment. It tells you we have requirements for each third party we want to work with." — Dennis Overbeeke, CTO at New10
Requirements split into two categories. Encryption sits on the tech side. Subcontractors and processes sit on the business side. Ask a vendor to name specific subcontractors. If they can't produce that list on the spot, that's a signal.
Should you build, buy, or outsource this piece?
Before evaluating any vendor, Overbeeke frames a prior question. Does this even belong outside your walls?
"You have to decide whether to make something, buy it, or outsource it." — Dennis Overbeeke, CTO at New10
Compliance work tests this hardest. You can hand pieces to SaaS tools or specialists, but accountability stays with you.
“You could outsource certain aspects of compliance, but it's you who's going to be held accountable. You can't outsource accountability." — Dennis Overbeeke, CTO at New10
Ask this inside your own team. If this vendor's output turns out wrong, who signs off on catching it? If nobody in particular, the outsourcing payments development decision needs a rethink, compliance or integrated payments solutions alike.
What should you ask about a vendor's integration approach?
Security and compliance dominate most vendor checklists, but integration architecture deserves its own questions. Boyko Karadzhov, Co-founder and CTO at Payhawk, learned this over years of payment gateway development, switching providers more than once.
"We don't like external code in our code base. When I see a provider's name in our code, it's usually a red flag." — Boyko Karadzhov, Co-founder and CTO at Payhawk
Payhawk isolates every external integration behind a single adapter that translates the vendor's data into a format the product understands.
Ask a prospective payment orchestration provider about the depth of their integration into your code.
"It's very strategic for us to have a single, named point of contact per integration. It helps to have one person in-house orchestrate the project." — Boyko Karadzhov, Co-founder and CTO at Payhawk
TSH saw a version of this while building Cleeng's Adyen payment integration: custom integration logic acting as a bridge between Cleeng's frontend and Adyen's platform, built to strict security and scalability requirements from day one.
What questions are specific to AI vendor tools?
AI-powered vendor tools add a layer most checklists weren't built for, and the same gap shows up in payment orchestration software routing decisions across providers. Marilyn McDonald, CTO at Thredd, treats third-party risk management for AI as harder than the standard case.
"Vendor models are the harder part of this. Which vendor tools are in play, what data each one can access, and how they are trained and governed." — Marilyn McDonald, CTO at Thredd
The problem is asymmetry. It's hard to produce internal evidence of someone else's system, so McDonald's team controls what data goes in and out, rather than auditing the model. She doesn't rule out external vendors for governance tooling, but draws a firm line. Accountability-critical work stays in-house.
"A tool or control built for a regulator needs to be owned by someone inside the firm." — Marilyn McDonald, CTO at Thredd
A few questions worth carrying into any AI vendor conversation:
What data can this tool access?
Who can produce an audit trail if a regulator asks?
Who stays accountable once the vendor is live?
Signing a contract isn't the end of it. It's closer to the middle. Overbeeke's CRA and McDonald's paved-path governance both assume ongoing checks, not a one-time approval.
McDonald keeps her ratio of employees to contractors around 70:30, so accountability-critical roles stay staffed in-house.
"You can surround that core with external vendors, but the named accountable individual sits inside your organization." — Marilyn McDonald, CTO at Thredd
Put a direct question to them. What's the name of the person who owns this once it ships? A question without a name isn't answered.
What's the one question that predicts a good vendor relationship?
Three vendor relationships share one instinct. Push past what a vendor demonstrates and ask what it can only answer in part.
Ask for subcontractor names and encryption specifics, not general assurances,
Check the depth of a vendor's code within your own before you sign,
Keep a named, internal owner for anything a regulator could ask about later.
The vendors worth working with tend to welcome these questions. The ones who can't give a clear answer are telling you something too.
The original conversations with Dennis Overbeeke, Boyko Karadzhov, and Marilyn McDonald go deeper into these decisions.
The interview with Dennis Overbeeke, CTO, New10.
The interview with Boyko Karadzhov, Co-founder and CTO, Payhawk.
The interview with Marilyn McDonald, CTO, Thredd.
Authors

Adrian Senecki
Copywriter and budding fiction writer, interested in (but not limited to) the business side of software development. Likes acquiring new skills and foretelling the future.

Andrzej Wysoczański
Frontend developer with 10 years of experience. With The Software House for almost 7 years, going from a regular dev to the Head of Frontend. He loves keeping tabs on the latest frontend technologies, especially React-related. Regular of the Taby & Spacje podcast (tsh.io/taby-vs-spacje) for Polish speaking programmers.
