Vendor Selection (Operator Field Manual)
TL;DR
- Start with the fraud tools your processor already gives you (Stripe Radar, Adyen RevenueProtect). Only pay for a dedicated vendor once false positives or fraud losses cost more than the vendor does
- Write down the problem before you take a single demo. "Get chargebacks from 0.8% to under 0.5%" can be evaluated. "Improve fraud" can't
- Run a scoped A/B pilot with a clean control before you commit. A vendor's case studies were written about someone else's traffic
- Contract for the exit: data export, token portability, sane notice periods. That's what protects you when the tool underperforms or the company gets acquired
Pick tools by problem and volume tier, not by brand fame. Start with what's built in, then add only what you can measure, because a tool you can't measure is a tool you'll never be able to cancel.
Looking for Fraud Vendors Specifically?
For fraud-specific vendor evaluation, see the Fraud Vendor Selection Guide. This page covers general vendor selection across all payment services.
What Matters
- Define the problem first. Fraud guarantees, IDV, alerts and chargeback ops are four different purchases.
- Match the tool model to your volume. Guarantees suit a team with no capacity; rules and decisioning suit a team that wants control.
- Start with processor-native tools and tune them properly. Most merchants never need more.
- Pilot on a clean A/B split. Measure auth rate, fraud, chargebacks and support tickets together, because a tool that fixes one and wrecks another isn't a win.
- Contract for exit: data export, token portability, notice periods.
Minimum Viable Stack by Volume
- Under $100k/mo: your processor's fraud tools (Radar, RevenueProtect, whatever yours is called), AVS and CVV checks, 3DS on high-risk orders only, and enrichment through Order Insight or Consumer Clarity. You don't need anything else yet.
- $100k-$1M/mo: add alerts (RDR plus Ethoca or CDRN). Consider piloting a guarantee vendor on one segment. Start IDV on your highest-risk flows.
- Over $1M/mo: a dedicated fraud tool with rules and ML, automated alert handling, IDV orchestration, and a dispute vendor if your volume warrants one.
Tool Categories and When to Use
- Fraud guarantees (Signifyd, Forter, Riskified). Buy these when you haven't got the headcount and you want the liability off your desk. Watch what they do to your approval rate, because that's how they manage their own losses.
- Rules and decisioning (Sift, Kount, decision APIs). Buy these when you want control and you've got an analyst to spend on tuning. Without that person, you've bought a dashboard.
- Processor-native rules (Stripe Radar, Adyen RevenueProtect, Braintree). Use these first and tune them before you buy anything else.
- IDV and KYC (Persona, Sardine, Alloy). For account creation and account takeover problems. These do nothing for card-present fraud.
- Alerts and enrichment (Verifi RDR and CDRN, Ethoca, Order Insight, Consumer Clarity). For deflecting chargebacks and making your statement line readable.
- Chargeback management vendors. For high dispute volume. Make them show you win rate broken out by reason code, and confirm they handle Visa Compelling Evidence 3.0.
Pilot Plan
Give it two to four weeks. Less than that and you're reading noise.
- Scope: one segment, whether that's a country, a payment method or a traffic slice. Keep a clean control group.
- Metrics: auth rate, fraud rate, chargeback rate, false positives, customer support tickets.
- Success: net revenue lift, meaning approved-good revenue minus fraud and fees, with customer experience holding steady (tickets flat or down).
- Exit: a documented rollback, with your original routing ready to switch back on.
Ask Before You Buy
- "How is this priced? Per transaction, percent of GMV, or percent of what you approve or cover? Are there minimums?"
- "Can we export our decisions, scores and device data? All of it?"
- "How do we turn this off, and how fast? What does it cost us to leave?"
- "Which brands and regions do you cover? Do you support 3DS? Do you support CE3.0 evidence?"
- "What are your uptime, response latency and support SLAs, in writing?"
Where This Breaks
- No control group. You can't prove lift, so you'll renew forever on vibes.
- Blended traffic in a "pilot." It hides false positives, which is usually the point.
- Guarantee vendors quietly tightening. Lower approvals reduce their liability, not yours.
- Overlapping tools. Processor rules plus vendor rules means good orders get blocked twice, and neither dashboard shows you the other one's declines.
Next Steps
Picking your first vendor?
- Check minimum stack by volume - What you actually need
- Understand tool categories - Guarantees vs rules vs alerts
- Plan your pilot - Scoped test with control
Evaluating a specific tool?
- Ask before you buy - Pricing, data, portability
- Watch for pitfalls - No control group, double-blocking
- Run clean A/B - Measure auth, fraud, chargebacks
Need detailed evaluation?
- Review selection guide - Full process
- Explore vendor landscape - Market overview
- Set up experimentation - Testing framework
Related
- Processor Rules Configuration - Native fraud tools
- Vendor Selection Guide - Detailed selection criteria
- Vendor Landscape - Market overview
- Chargeback Alerts - RDR, Ethoca, CDRN
- Processor Reporting Checklist - Data requirements
- Risk Scoring - Score-based decisioning
- Identity Verification - IDV tools
- Buying Payments - Processor selection
- Processor Management - Ongoing relationships
- Rules vs. ML - Detection approaches
- Benchmarks - Performance targets
- Experimentation - Pilot testing