Selling Payments Software Through Compliance, Not Around It
In most software categories, the champion signs off and the deal moves to legal. In fintech and embedded finance, the champion's enthusiasm barely matters until risk, compliance, and often a partner bank have all cleared the integration. A rep who treats that review the way they would treat ordinary legal redlines will watch a quarter disappear waiting on a team that was never mentioned in the first three calls.
MEDDIC, in its MEDDPICC form, is built for exactly this kind of gate: it makes a rep name the Paper Process early and test whether the champion can actually move it forward. Challenger solves a separate problem: getting a risk-averse buyer to take the first meeting at all, when their current processor or in-house build already technically works.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Step One: How do you map the paper process before the pilot?
Before scoping a proof of concept, ask the champion directly which teams have to sign off on a new payments or embedded finance vendor: information security, compliance, sometimes a sponsor bank's own risk team. Get a rough timeline for the last vendor review that went through the same path. A champion who cannot answer this has not actually cleared it internally yet, no matter how ready they sound.
Document the Paper Process owner as a required field before the opportunity is allowed to progress. In Salesforce, a stage-gate rule that blocks advancement without a named compliance or risk contact catches the deals that look qualified on the surface but have never touched the team that will ultimately decide.
Step Two: How do you test the champion with a real ask?
The standard MEDDIC champion test applies here with extra weight: ask the champion to set up an introduction to whoever owns risk sign-off, or to share the internal criteria compliance will use to evaluate the integration. In payments, this ask often reveals whether the champion has actual standing or is a product-side advocate with no visibility into the risk process at all.
Gong-style call review is useful here specifically because compliance and security conversations tend to happen off the main sales call, in side threads a rep may never surface in a deal review. Listening back for whether a rep actually asked the champion about the internal review path, rather than assuming it would sort itself out, separates qualified pipeline from hopeful pipeline.
Step Three: Earn the First Meeting With a Cost the Buyer Missed
Most fintech and payments buyers are not comparing vendors, they are comparing your platform to a processor relationship or an internal build they consider good enough. Challenger's Commercial Teaching works by naming a cost the buyer has not connected to their current setup, such as reconciliation hours, chargeback handling, or the operational drag of maintaining custom code against a partner bank's changing requirements, before ever describing the product.
A rep who leads with feature comparisons in this category tends to get compared on price. A rep who leads with a specific, provable cost of the status quo tends to get a second meeting with someone who was not originally on the call.
Step Four: Keep Both Sides of the Deal Warm
Fintech deals routinely run two parallel tracks, the commercial conversation with the buyer's product or finance lead, and the technical and compliance conversation with risk and engineering. New-business software deals average 91 days to close against 52 for expansion business, and in this category the gap tends to run longer still because the compliance track moves on its own schedule1. Salesloft-style cadences that keep both threads active on a defined schedule stop the compliance conversation from going quiet while the commercial one moves ahead.
Because win rates in a compliance-heavy category run lower than a simple software sale, plan pipeline coverage above the general 3x to 4x baseline, closer to the 4x to 7x range used for enterprise deals with lower win rates2.
Step Five: Protect Attainment and Burn Together
Only 51 percent of SaaS account executives hit quota, and in fintech the reps who miss are disproportionately the ones who let a compliance-heavy deal sit unqualified for a full quarter rather than pushing for the risk contact early3. Because payments and embedded finance companies often carry heavier compliance and infrastructure cost than a typical SaaS business, keep an eye on burn multiple by revenue stage as sales headcount grows, since a compliance-heavy sales motion can quietly extend payback if qualification discipline slips4.
Say a rep closes a deal that looked qualified but stalls for three extra months in a compliance review nobody scoped upfront. That single deal now drags down average cycle time for the whole team's forecast, and it makes the next quarter's pipeline coverage math look worse than the underlying business actually is. Treating the compliance review as a tracked stage with its own expected duration, rather than an unpredictable black box, keeps one slow deal from distorting the whole team's numbers.
Run the same moves in this order on every compliance heavy deal:
- Map the Paper Process first by asking the champion which teams must approve the vendor and how long the last comparable review took.
- Test the champion by asking for an introduction to whoever owns risk sign-off, or for the internal criteria compliance will use.
- Earn the first meeting by naming a cost the buyer has not connected to the current setup, such as reconciliation hours or chargeback handling.
- Keep the commercial track and the compliance track moving in parallel, since the compliance review runs on its own schedule.
- Protect attainment by pushing for the risk contact early instead of letting a compliance heavy deal sit unqualified for a full quarter.
What Good Looks Like
A disciplined fintech sales process names the compliance or risk sign-off contact and gets a realistic review timeline before a pilot is scoped, so the deal's real clock is known from the start rather than discovered mid-quarter.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Listen back for whether a rep actually asked about the compliance or risk review path, since that detail often surfaces in a side conversation rather than the main call.
Require a named compliance or risk contact before an opportunity can advance to a late stage, catching deals that look qualified but have never touched the real reviewer.
Run a structured cadence across both the commercial and compliance threads so the risk conversation does not go quiet while the product conversation moves ahead.
Frequently Asked Questions
Who actually approves a new payments vendor at a fintech company?
It is rarely the product lead who requested the demo. Look for whoever owns risk or compliance sign-off, and in platforms with a sponsor bank relationship, ask whether the bank's own risk team has a say. Treat that person as the real Economic Buyer until proven otherwise.
Does Challenger work on a buyer who is worried about compliance risk?
Yes, but the insight has to be about risk or operational cost, not growth or efficiency in the abstract. A reframe that names a specific compliance or reconciliation cost the buyer's current setup creates lands better than a generic growth pitch in a category this risk-aware.
How early should a rep ask about the security or compliance review process?
As early as the second call. Waiting until a proof of concept is already scoped means discovering the review timeline after engineering hours are already committed, which is exactly the slippage MEDDPICC's Paper Process step exists to prevent.
Sources
Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.
- Average B2B sales cycle length. Ebsta x Pavilion 2025 GTM Benchmarks Report, 2025.
- Pipeline coverage ratio norms. Clari — Pipeline Coverage Ratio best practices, 2025.
- Percent of SaaS AEs hitting quota (Bridge Group). The Bridge Group 2024 SaaS AE Metrics & Compensation Report, 2024.
- Burn multiple guidance bands by ARR (net burn / net new ARR). a16z Growth burn multiple framework (Kahl & George, 'A Framework for Navigating Down Markets', May 2022), table transcribed by Kruze Consulting, 2022.
Related Guides
Commission Software for Usage-Based Fintech Sales Teams
Embedded finance revenue is a moving take rate, not a fixed price. Here is how QuotaPath and CaptivateIQ handle that, and which fits your team.
ZoomInfo vs Cognism for Fintech Sales Teams
Fintech sales teams answer to legal before they answer to a quota. Here is how contact data provenance should decide ZoomInfo vs Cognism.
Fathom vs Fireflies for Fintech and Payments Sales Teams
A checklist for fintech and embedded finance sales teams weighing Fathom against Fireflies, with the compliance questions most guides skip.
Apollo vs ZoomInfo for Fintech Sales: The Timing Problem
Fintech deals move fast once a buyer decides to act. Here's how to weigh Apollo against ZoomInfo, and where Outreach fits, for that kind of timing problem.
Onboarding Fintech Clients Without Skipping a Compliance Step
A compliance-first checklist for onboarding fintech and embedded finance platform clients, and where GuideCX earns its structure over Arrows.
Highspot vs Seismic for Fintech Compliance Review
Highspot vs Seismic for fintech and embedded finance sales teams, judged by how each handles compliance review of settlement and fraud claims.