CIOPages
All RFP packages

RFP Package · Enterprise Applications

Enterprise Payments & FinTech Infrastructure RFP questions and template

128 questions, 10 demo scenarios and a five-vendor scorecard for choosing Enterprise Payments & FinTech Infrastructure software, in one Excel workbook.

What this package is for

Use it to run a Enterprise Payments & FinTech Infrastructure software selection, from the first long list to the final scorecard.

What the category covers. Software and services that accept, route, secure and settle payments: authorization optimization, 3-D Secure and SCA exemptions, local and real-time payment methods, multi-provider routing and failover, vaulting and credential portability, fraud, disputes, platform payouts, reconciliation and in-store acceptance. Bought by payments, finance, ecommerce and IT leaders choosing a full-stack provider, an orchestration layer or an enterprise acquirer.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 28 questions screen out products that lack something you need.
  • RFP, to the shortlist. 64 questions ask how each product does the work.
  • Deep dive, to the finalists. 36 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 90 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Does your product report approval rates separately for authorizations sent with a network token and authorizations sent with the card number?

Why it matters. Without this split, the buyer cannot tell whether network tokens raise approvals on its own card mix. Tokenization then cannot be tuned or justified with data.

Good answer
  • Approval report can be filtered by credential type (network token versus card number)
  • The split can be broken out further by card brand and issuer country
  • The transaction-level export carries a field showing which credential type was sent
Red flags
  • Only a blended approval rate is available
  • Token use is described but not exposed per transaction
  • Approval-lift figures come only from the vendor's whole portfolio, not from the merchant's own traffic

2. Which EMV 3-D Secure protocol versions does your product support for browser-based and in-app authentication?

Why it matters. Issuers and card networks support different protocol versions, and newer versions carry more data for frictionless decisions. If the product cannot run a version the issuer supports, the transaction falls back to a challenge or loses authentication entirely.

3. For each of [markets], name the acquiring legal entity that would process our card transactions and the country in which it is licensed.

Why it matters. Transactions acquired from outside the issuing market are processed as cross-border. Cross-border processing can add scheme fees, and issuers may decline cross-border transactions more often than domestic ones.

Capability areas

Authorization & Acceptance Optimization (13)

Measuring and raising approval rates: network tokens and account updater as approval levers, stored-credential (customer- and merchant-initiated) transaction flags, retry and decline-recovery logic, issuer-data enrichment including Level 2 and Level 3 data, debit and local-scheme routing, and decline-code reporting by brand, BIN, issuer country and method. 3DS/SCA authentication and cross-provider routing are covered in their own areas.

Strong Customer Authentication & 3-D Secure (10)

Authentication flows and exemption handling: 3DS versions and data elements, PSD2 SCA exemption requests (low value, TRA, merchant-initiated, recurring), frictionless rates, step-up fallback and liability-shift outcomes per transaction. Fraud scoring models are covered under Fraud & Risk Screening.

Global Coverage & Local Payment Methods (13)

Local acquiring footprint by country, domestic versus cross-border processing, presentment and settlement currencies, and coverage of wallets, BNPL, vouchers, local card schemes and other alternative methods in our markets. Real-time and account-to-account rails are covered separately.

Real-Time & Account-to-Account Payments (8)

Acceptance and payout over instant and bank-based rails such as FedNow, RTP, SEPA Instant and pay-by-bank: payer flow, confirmation finality, refunds, returns and failure handling on these rails. Card acceptance and card-based local methods are out of scope.

Orchestration, Routing & Failover (12)

Routing across multiple acquirers or PSPs: rule definition (least-cost, geo-local, BIN-based, performance-based), automatic failover and cascading retries, adding or removing a downstream provider, and reporting that compares providers on the same traffic. Vendor-side disaster recovery of its own infrastructure is covered by the business-continuity module.

Vaulting, Tokenization & Credential Portability (10)

Card and payment-credential storage: hosted fields and vault options that reduce our PCI DSS scope, network token provisioning and lifecycle, PSP-agnostic tokens, inbound migration of stored credentials from an incumbent, outbound credential export to another provider, and preservation of network tokens and stored-credential transaction IDs across migrations. General contract-exit terms are covered by the migration-exit module.

Fraud & Risk Screening (11)

Native transaction fraud screening and integration with third-party fraud tools: rule authoring, risk scores and the signals behind them, manual review queues, false-positive measurement, and the effect of fraud decisions on approval rates. Dispute handling after a chargeback is covered under Chargebacks & Disputes.

Chargebacks & Dispute Management (9)

The dispute lifecycle: network alerts and pre-dispute resolution, chargeback notification, reason-code mapping, evidence assembly and representment, win-rate reporting, and liability tracking. Fraud prevention before authorization is out of scope.

Platform & Marketplace Payments (12)

Payments for sub-merchants or sellers on a platform: KYC/KYB onboarding flows, split payments and payout scheduling, sub-merchant risk monitoring, negative-balance and reserve handling, and seller-facing reporting. Not relevant to buyers who only accept payments for themselves.

Settlement, Reconciliation & Financial Reporting (12)

How money and data reach finance: settlement timing and batching, reserve and holdback visibility, transaction-level fee breakdown (interchange, scheme fees, markup, FX), reconciliation of payouts to orders and refunds, and report formats for month-end close. Pricing levels and contract terms are covered by the commercial module.

Payment Integration & Developer Tooling (9)

Payment-specific integration behavior: idempotency on payment calls, webhook event coverage for the payment lifecycle, sandbox simulation of specific decline codes, 3DS challenges and disputes, hosted checkout components and versioning. Generic API availability, SSO and connectors are covered by the integration module.

Omnichannel & In-Person Acceptance (9)

Card-present acceptance and its link to online payments: terminal options and management, offline and store-and-forward processing, cross-channel shopper identification and refunds, and unified reporting across channels. Not relevant to online-only buyers.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. Recover a declined subscription renewal
  2. European checkout with exemption and issuer challenge
  3. Primary acquirer fails during checkout
  4. Launch card and local payments in a new country
  5. Pay-by-bank payment with refund and failure
  6. Onboard a seller and recover a negative balance
  7. Work a chargeback from alert to outcome
  8. Reconcile one payout to orders and fees
  9. Migrate stored cards in and back out
  10. Buy online and return in store

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Enterprise Payments & FinTech Infrastructure RFP questions are there?

128 solution questions in 12 capability areas: 28 for the RFI, 64 for the RFP and 36 deep-dive questions for the finalists. The workbook adds 90 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Enterprise Payments & FinTech Infrastructure

For the business side of the same change: