7 September 2026

What questions should I ask a vendor before outsourcing payments development?

Adrian Senecki

Andrzej Wysoczański

4 min read

Most vendor pitches answer the questions nobody asked. The ones that predict a bad outsourcing decision are rare unless you bring them yourself.

A vendor's sales deck tells you what their platform does, not who's accountable when it breaks. In software payments, a vendor's code doesn't sit beside your product, it runs inside it.

That's the question that separates a smooth integration from a compliance headache six months in.

TL;DR

  • Compliance can be delegated, accountability can't,

  • Integration questions matter as much as security ones,

  • AI vendor tools need their own line of questioning,

  • Every good vendor question ends with a name, not a policy.

What compliance questions should you ask a payments vendor?


Just under 90% of large and midsize US commercial banking clients work with a fintech vendor for payments or cash management, per Datos Insights' 2026 Fintech 50 report.

Vendor relationships are the default now in software payments, so screening an outsourcing payments partner matters more. Dennis Overbeeke, CTO at New10, runs every vendor through a Change Risk Assessment.

"If we want to use a new vendor, we do a Change Risk Assessment. It tells you we have requirements for each third party we want to work with." — Dennis Overbeeke, CTO at New10

Requirements split into two categories. Encryption sits on the tech side. Subcontractors and processes sit on the business side. Ask a vendor to name specific subcontractors. If they can't produce that list on the spot, that's a signal.

Should you build, buy, or outsource this piece?


Before evaluating any vendor, Overbeeke frames a prior question. Does this even belong outside your walls?

"You have to decide whether to make something, buy it, or outsource it." — Dennis Overbeeke, CTO at New10

Compliance work tests this hardest. You can hand pieces to SaaS tools or specialists, but accountability stays with you.

“You could outsource certain aspects of compliance, but it's you who's going to be held accountable. You can't outsource accountability." — Dennis Overbeeke, CTO at New10

Ask this inside your own team. If this vendor's output turns out wrong, who signs off on catching it? If nobody in particular, the outsourcing payments development decision needs a rethink, compliance or integrated payments solutions alike.

What should you ask about a vendor's integration approach?


Security and compliance dominate most vendor checklists, but integration architecture deserves its own questions. Boyko Karadzhov, Co-founder and CTO at Payhawk, learned this over years of payment gateway development, switching providers more than once.

"We don't like external code in our code base. When I see a provider's name in our code, it's usually a red flag." — Boyko Karadzhov, Co-founder and CTO at Payhawk

Payhawk isolates every external integration behind a single adapter that translates the vendor's data into a format the product understands.

Ask a prospective payment orchestration provider about the depth of their integration into your code.

"It's very strategic for us to have a single, named point of contact per integration. It helps to have one person in-house orchestrate the project." — Boyko Karadzhov, Co-founder and CTO at Payhawk

TSH saw a version of this while building Cleeng's Adyen payment integration: custom integration logic acting as a bridge between Cleeng's frontend and Adyen's platform, built to strict security and scalability requirements from day one.

What questions are specific to AI vendor tools?


AI-powered vendor tools add a layer most checklists weren't built for, and the same gap shows up in payment orchestration software routing decisions across providers. Marilyn McDonald, CTO at Thredd, treats third-party risk management for AI as harder than the standard case.

"Vendor models are the harder part of this. Which vendor tools are in play, what data each one can access, and how they are trained and governed." — Marilyn McDonald, CTO at Thredd

The problem is asymmetry. It's hard to produce internal evidence of someone else's system, so McDonald's team controls what data goes in and out, rather than auditing the model. She doesn't rule out external vendors for governance tooling, but draws a firm line. Accountability-critical work stays in-house.

"A tool or control built for a regulator needs to be owned by someone inside the firm." — Marilyn McDonald, CTO at Thredd

A few questions worth carrying into any AI vendor conversation:

  • What data can this tool access?

  • Who can produce an audit trail if a regulator asks?

Who stays accountable once the vendor is live?


Signing a contract isn't the end of it. It's closer to the middle. Overbeeke's CRA and McDonald's paved-path governance both assume ongoing checks, not a one-time approval.

McDonald keeps her ratio of employees to contractors around 70:30, so accountability-critical roles stay staffed in-house.

"You can surround that core with external vendors, but the named accountable individual sits inside your organization." — Marilyn McDonald, CTO at Thredd

Put a direct question to them. What's the name of the person who owns this once it ships? A question without a name isn't answered.

What's the one question that predicts a good vendor relationship?


Three vendor relationships share one instinct. Push past what a vendor demonstrates and ask what it can only answer in part.

  • Ask for subcontractor names and encryption specifics, not general assurances,

  • Check the depth of a vendor's code within your own before you sign,

  • Keep a named, internal owner for anything a regulator could ask about later.

The vendors worth working with tend to welcome these questions. The ones who can't give a clear answer are telling you something too.

The original conversations with Dennis Overbeeke, Boyko Karadzhov, and Marilyn McDonald go deeper into these decisions.

Authors

  • Adrian Senecki

    Copywriter and budding fiction writer, interested in (but not limited to) the business side of software development. Likes acquiring new skills and foretelling the future.

  • Andrzej Wysoczański

    Frontend developer with 10 years of experience. With The Software House for almost 7 years, going from a regular dev to the Head of Frontend. He loves keeping tabs on the latest frontend technologies, especially React-related. Regular of the Taby & Spacje podcast (tsh.io/taby-vs-spacje) for Polish speaking programmers.

Bring experience to your agentic payments project

AGENTIC PAYMENTS

We delivered in five months for a real fintech client

One chat interface. KYC isolated. Anti-hallucination guardrails. Explicit approval before every transfer. Zero data breaches. 95% user satisfaction.

Book consultation

Fintech success stories

See how we help customers drive build fintech products and infrastructure faster

See how we help customers drive build fintech products and infrastructure faster

Go to cases
Questions before outsourcing payments development