3 questions from the package
From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.
1. Does your product report approval rates separately for authorizations sent with a network token and authorizations sent with the card number?
Why it matters. Without this split, the buyer cannot tell whether network tokens raise approvals on its own card mix. Tokenization then cannot be tuned or justified with data.
Good answer
- Approval report can be filtered by credential type (network token versus card number)
- The split can be broken out further by card brand and issuer country
- The transaction-level export carries a field showing which credential type was sent
Red flags
- Only a blended approval rate is available
- Token use is described but not exposed per transaction
- Approval-lift figures come only from the vendor's whole portfolio, not from the merchant's own traffic
2. Which EMV 3-D Secure protocol versions does your product support for browser-based and in-app authentication?
Why it matters. Issuers and card networks support different protocol versions, and newer versions carry more data for frictionless decisions. If the product cannot run a version the issuer supports, the transaction falls back to a challenge or loses authentication entirely.
3. For each of [markets], name the acquiring legal entity that would process our card transactions and the country in which it is licensed.
Why it matters. Transactions acquired from outside the issuing market are processed as cross-border. Cross-border processing can add scheme fees, and issuers may decline cross-border transactions more often than domestic ones.
Capability areas
Authorization & Acceptance Optimization (13)
Measuring and raising approval rates: network tokens and account updater as approval levers, stored-credential (customer- and merchant-initiated) transaction flags, retry and decline-recovery logic, issuer-data enrichment including Level 2 and Level 3 data, debit and local-scheme routing, and decline-code reporting by brand, BIN, issuer country and method. 3DS/SCA authentication and cross-provider routing are covered in their own areas.
Strong Customer Authentication & 3-D Secure (10)
Authentication flows and exemption handling: 3DS versions and data elements, PSD2 SCA exemption requests (low value, TRA, merchant-initiated, recurring), frictionless rates, step-up fallback and liability-shift outcomes per transaction. Fraud scoring models are covered under Fraud & Risk Screening.
Global Coverage & Local Payment Methods (13)
Local acquiring footprint by country, domestic versus cross-border processing, presentment and settlement currencies, and coverage of wallets, BNPL, vouchers, local card schemes and other alternative methods in our markets. Real-time and account-to-account rails are covered separately.
Real-Time & Account-to-Account Payments (8)
Acceptance and payout over instant and bank-based rails such as FedNow, RTP, SEPA Instant and pay-by-bank: payer flow, confirmation finality, refunds, returns and failure handling on these rails. Card acceptance and card-based local methods are out of scope.
Orchestration, Routing & Failover (12)
Routing across multiple acquirers or PSPs: rule definition (least-cost, geo-local, BIN-based, performance-based), automatic failover and cascading retries, adding or removing a downstream provider, and reporting that compares providers on the same traffic. Vendor-side disaster recovery of its own infrastructure is covered by the business-continuity module.
Vaulting, Tokenization & Credential Portability (10)
Card and payment-credential storage: hosted fields and vault options that reduce our PCI DSS scope, network token provisioning and lifecycle, PSP-agnostic tokens, inbound migration of stored credentials from an incumbent, outbound credential export to another provider, and preservation of network tokens and stored-credential transaction IDs across migrations. General contract-exit terms are covered by the migration-exit module.
Fraud & Risk Screening (11)
Native transaction fraud screening and integration with third-party fraud tools: rule authoring, risk scores and the signals behind them, manual review queues, false-positive measurement, and the effect of fraud decisions on approval rates. Dispute handling after a chargeback is covered under Chargebacks & Disputes.
Chargebacks & Dispute Management (9)
The dispute lifecycle: network alerts and pre-dispute resolution, chargeback notification, reason-code mapping, evidence assembly and representment, win-rate reporting, and liability tracking. Fraud prevention before authorization is out of scope.
Platform & Marketplace Payments (12)
Payments for sub-merchants or sellers on a platform: KYC/KYB onboarding flows, split payments and payout scheduling, sub-merchant risk monitoring, negative-balance and reserve handling, and seller-facing reporting. Not relevant to buyers who only accept payments for themselves.
Settlement, Reconciliation & Financial Reporting (12)
How money and data reach finance: settlement timing and batching, reserve and holdback visibility, transaction-level fee breakdown (interchange, scheme fees, markup, FX), reconciliation of payouts to orders and refunds, and report formats for month-end close. Pricing levels and contract terms are covered by the commercial module.
Payment Integration & Developer Tooling (9)
Payment-specific integration behavior: idempotency on payment calls, webhook event coverage for the payment lifecycle, sandbox simulation of specific decline codes, 3DS challenges and disputes, hosted checkout components and versioning. Generic API availability, SSO and connectors are covered by the integration module.
Omnichannel & In-Person Acceptance (9)
Card-present acceptance and its link to online payments: terminal options and management, offline and store-and-forward processing, cross-channel shopper identification and refunds, and unified reporting across channels. Not relevant to online-only buyers.
Questions about this package
How many Enterprise Payments & FinTech Infrastructure RFP questions are there?
128 solution questions in 12 capability areas: 28 for the RFI, 64 for the RFP and 36 deep-dive questions for the finalists. The workbook adds 90 due-diligence questions on security, integration, implementation and exit.
What comes with each question?
Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.
Can I edit the questions?
Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.
Which license do I need?
The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.