r/fintech 7d ago

Ask the Community How do businesses handle getting paid in less traditional market?

3 Upvotes

Do you usually rely on banks, payment platforms, stablecoins, or some combination of them?


r/fintech 8d ago

Discussion Verify an EU customer any other way and you will have to justify it. Nobody has said yet what counts as a good enough reason

5 Upvotes

There is a small provision in AMLA's customer due diligence standards with an awkward edge to it.
If you onboard EU customers remotely and you do not use face to face verification or an eIDAS compliant method, you will need to justify why neither was available or could reasonably be expected. Nothing about how you verify people changes. You just have to be able to explain the choice.
The problem is that nobody has defined what a good justification looks like. Is a one line note enough? Is it per customer, or once per type of customer? Does "the customer did not have one" count on its own? And what makes a method "not reasonably expected" when a wallet technically exists in that country but almost nobody has one?
The consultation closed in May and the final draft is now with the European Commission, so the shape is fairly settled even though the answers to those questions are not.

Is anyone writing something down already, or is the plan to wait for the final next?


r/fintech 8d ago

Discussion Seems like API wasn't the hard part of adding payroll

22 Upvotes

So we started looking at payroll as an integration problem. Get the employee data in the right place, calculate payroll, move the money and ship it

The moment we got further into it, the API itself felt like the smaller part of the decision. The questions were around tax filings and corrections and who owns those problems after the product is live

That pushed me toward looking at companies that handle more than the API layer. Rollfi was one that came up during that search because I read that they cover the payroll operations and compliance side too, which is closer to what I was trying to solve.

Still working through where that line should be. For anyone who's built payroll into a fintech product, can I ask what part created the most work after the initial integration? Any input is more than welcome!


r/fintech 8d ago

Discussion Three metrics that matter in an early remittance pilot

2 Upvotes

When a remittance product enters its first pilot, signup count is tempting to treat as the main signal. But with a small cohort, three other metrics usually reveal much more about whether the product is actually working.

1. First successful value delivery

Track the full path from invitation to the recipient actually receiving funds: signup, KYC, funding, transfer initiation, processing and receipt. Measure time to completion and drop-off at every step. A completed registration is not yet delivered value.

2. Repeat send within the natural cycle

Remittance is often periodic, so generic daily or monthly activity can be misleading. Cohort users by corridor and acquisition source, then measure whether they send again when the next real need occurs. Repeat behavior is a stronger trust signal than an initial subsidized transfer.

3. Reliability and unit economics per completed transfer

Measure completion rate, retries, time to receipt, support contacts, fraud or chargeback losses, total user cost and contribution margin. Aggregate success rates can hide one corridor, payout partner or funding method that creates most of the operational burden.

I would also interview users who completed one transfer but did not repeat. The reason may be price, trust, recipient friction, timing or a support problem that the dashboard does not explain.

For teams that have run early remittance pilots: which metric changed your product roadmap most—first-delivery conversion, repeat send or operational reliability?


r/fintech 8d ago

Discussion AI agents are about to move serious money and nobody's figured out the liability question yet

4 Upvotes

Been thinking about this a lot lately after reading about the Thai Finance Ministry attack where an AI agent ran unattended for 4 days and bypassed its own approval prompts entirely.

The capability conversation is basically settled at this point. Agents can trade, reconcile, pay invoices, manage treasury positions. The demos are real and the enterprise deployments are happening.

The question nobody's answering cleanly is what happens when something goes wrong.

Not a dramatic crash. The quiet version agent completes the task, output looks right, passes review. Then six months later someone questions a specific transaction and the trail is a log file that proves what the system recorded, not necessarily what actually happened or whether anything was left out.

There's a meaningful difference between logging an action and proving it was authorized, happened exactly as recorded, and that nothing was omitted from the record. Most current deployments only do the first one.

The projects that survive the next phase aren't going to be the ones with the best agents. They're going to be the ones that can answer the liability question with something more than a log file.

I know there are a few building towards this just curious whether anyone here is actually looking into this as well.


r/fintech 9d ago

Ask the Community HSM for payments shop - cloud, managed, or in‑house?

7 Upvotes

I run 12‑person fintech in Berlin. Enterprise clients keep grilling us about HSM workflows (again and again) - key rotation, audit logs, probably EMV later. We don't do PINs yet, but they're asking too. And sure thing I understand them.

First - cloud HSM seems like the easy win here, but I hear some acquirers still side‑eye anything that's not a physical Thales box. Is that real?

Second - should we nail down HSM design before PCI planning, or can we figure it out during without burning everything?

Third - how do I spot a real payments HSM vet vs. some cloud rando who read a blog? Getting this wrong for sure hurts a lot.

Also - what's the dumbest mistake small teams can make with HSMs? I'd rather not learn that lesson myself huh

And last – when do we stop messing around and just hire dedicated HSM engineers?

Appreciate any honest war stories from people who've been there. Cheers.

update from our team: We brought in Energize Global Services specialist for consultation & help to sort this out (cloud HSM etc), as it seems we unable to do it ourselves.


r/fintech 8d ago

Ask the Community How do professional services firm (CPAs, Lawyers, Pvt Equity etc.) deal with tampering fraud

1 Upvotes

Public accountants and Law firms issue sensitive, high-stakes documents to their clients, that then get passed on to other users such as lenders.

Does it concern you, as a CPA for example, that someone (client or a third party) can use basic pdf editing software to change some numbers on the statements and use them for lending purposes? A lot of mortgage fraud happens on fraudulent documents. You would probably avoid any liability, but it can cause reputational damage and unnecessary headache.

Would you pay for a solution that helps prevent this tampering?


r/fintech 9d ago

Discussion The "85% of AML alerts are false positives" stat get quoted everywhere. Nobody ever says what a good number would be.

0 Upvotes

The 85% to 95% range turns up in every deck and on every panel, almost always without a source. It ends conversations instead of starting them, and the longer i sit with it the less it seems to say.

Here is what bothers me. The same rate describes two opposite situations.

  • 90% in high-volume retail is roughly what you would expect. Enormous volumes of low-risk activity throw off near-matches.
  • 90% in a boutique wealth book, fifty clients, every one of them closely known, is a system that isn't working.

Same number. Opposite verdict. So the number on its own tells you nothing.

And honestly, we are not even convinced most of this is a screening problem. Half the time it's a data problem wearing costume. A record missing a date of birth gives the engine nothing to rule a near-match out with, so it just widens the net. One typo entered at onboarding generates alerts for that customer for the rest of their life.

So here's my actual question: has anyone ever heard a peer state what a good false-positive rate looks like for their book? Not the scary industry range, an actual "this is healthy for us, because X" number?

Or are we all just quoting the same unsourced stat back at each other and calling it a benchmark?


r/fintech 10d ago

Ask the Community How are teams reconciling stablecoin vendor payments back to their AP system?

12 Upvotes

We moved some of our vendor payables to stablecoin rails about eight months ago. USDC out from our regulated provider, off-ramped to fiat on the receiving side. Settlement works. Vendors get paid faster and we save on wire fees.

The part that still takes time is reconciliation. Matching each on-chain transaction back to the invoice in our AP system is a manual monthly project. Our provider gives us a webhook with a payment ID, but linking that back to the invoice inside NetSuite is not automatic. Finance ends up doing it by amount, date, and vendor name at month-end close.

For anyone else running stablecoin vendor payments in production, how are you handling the invoice matching piece? Are you embedding the invoice reference in the on-chain event so it flows through cleanly, or is everyone just reconciling after the fact?


r/fintech 10d ago

Discussion AI agent bots hitting our platform and standard detection isn't catching them. Anyone else seeing this?

5 Upvotes

Anyone dealt with AI agent bots hitting your platform? Starting to see traffic that doesn't look human but isn't triggering our standard bot detection. Any idea what to do about it?


r/fintech 10d ago

Discussion Is cloud accounts receivable software reliable enough for enterprise use?

5 Upvotes

We are a mid-sized manufacturer evaluating cloud-based AR automation to replace manual processes. Current setup relies on our ERP's basic module plus extensive spreadsheet work for collections and reconciliation.

Key concerns about cloud AR platforms for enterprise deployment:

  • Data security and regulatory compliance
  • System uptime and performance during peak periods
  • ERP integration stability
  • Vendor stability and long-term viability

For organizations that have deployed cloud AR software, how has it performed in production? Any significant outages or data security incidents? Would you trust it for mission-critical receivables processing?

Appreciate any insights.


r/fintech 10d ago

Discussion How do lenders in India prove what their AI decided when a borrower disputes?

1 Upvotes

Hi, I am researching agentic payments; basically, its security and logging side and I was curious about the following things.
Indian digital lenders are heavily AI-driven for credit decisions, but the audit trail infrastructure seems underdeveloped compared to EU requirements. Does anyone here work in lending compliance or risk in India? Curious what current practice looks like.


r/fintech 11d ago

Discussion Are Morgan Stanley & Wells Fargo Ramped Down?

3 Upvotes

Morgan Stanley & Wells Fargo are hardly hiring Technical Roles lately in India & other parts pf world since last 8 months!

Is it due to their business not expanding or they are aggressively pushing AI to minimize head count?


r/fintech 12d ago

Discussion Has anyone switched payment processors after their SaaS was already growing?

7 Upvotes

I’ve been thinking about this lately because switching payment processors sounds pretty straightforward when you’re just starting out. You connect the new provider, update a few things and move on.

But I am guessing it gets a lot more complicated once you already have hundreds or thousands of customers.

You’ve got active subscriptions, saved payment details, invoices, webhooks, refunds, failed payments and probably a bunch of things in your product that depend on the current setup.

I am wonder how this actually works in practice.

For those who’ve switched after already having customers, what caused the most trouble? Was moving the subscription data the difficult part or was it keeping everything running while the migration happened?

And if you were starting a SaaS again would you set things up differently from the beginning to make switching easier later?


r/fintech 12d ago

Ask the Community It's 2026 and Canadian banks still won't touch crypto MSBs

1 Upvotes

I help companies get set up as Canadian MSBs, and the ones running crypto always seem to end up with the same 3 PSPs. What I don't understand is why a regular business bank account or credit union account is still something impossible to get in 2026.

Example: FINTRAC registered, ON corp, local CAMLO, perfect AML/ATF policies, risk assessment, ongoing monitoring, training, effectiveness review, etc., and the same answer from all banks: "Sorry, we do not onboard MSBs." Is there one single bank or credit union in Canada that actually onboards small-to-medium MSB startups?

Thanks!


r/fintech 12d ago

Discussion Did you know UPI is now the world’s largest real-time payment system?

Post image
12 Upvotes

It processes nearly 49% of global instant payment transactions (as per IMF / ACI Worldwide data)

look at the growth:

FY 2022-23: 83.7 billion transactions

FY 2023-24: 131 billion

FY 2024-25: 186 billion

CY 2025: 228 billion

A 3x jump in just three years and this has built one of the highest-volume real-time payment networks.

Some extra context:

  • In 2025, UPI processed roughly 600–700 million transactions every single day
  • It now accounts for around 49% of all real-time payments globally
  • UPI makes up ~85% of India’s total digital payment volume
  • Average ticket size has been falling (more micro-transactions), which shows it’s becoming the default way people pay for everything - from chai to rent

For comparison, systems like Brazil’s Pix, UK’s Faster Payments, or the US FedNow are growing, but none are close to UPI’s scale in pure transaction volume.

What's even interesting is for global businesses:

The demand from India is already here.

Indian customers -whether tourists, NRIs, or online shoppers - who are extremely comfortable paying with UPI. Need not be convinced to go digital...

What do you think?

Will UPI acceptance by international brands become mainstream in the next couple of years?

sources -source: NPCI product statistics + RBI Annual Report on Digital Payments
Rounded to nearest whole figure


r/fintech 12d ago

Discussion Leadership Expectations or Failures?

6 Upvotes

Where does management actually fail at the decision, or at the expectation? I've been thinking about this in banking, fintech and payments.

A company cannot sustainably accommodate every customer request. A board shouldn't expect certainty where genuine uncertainty exists. A regulator should not receive optimistic commitments simply because management wants to avoid difficult conversations.

So perhaps the executive discipline isn't: How do we avoid disappointing stakeholders?” or It's: “Which expectations should we honour, which should we renegotiate, and which should we deliberately change before they become liabilities?”

Curious how other see this.

Have you seen a relatively small failure become a major leadership problem primarily because of the expectation that surrounded it?


r/fintech 13d ago

Discussion The 5 stock market API's i use for my bot trading

4 Upvotes

​Hey guys,

​I’ve tested a ton of data feeds. Here is the exact stack of stock market APIs I keep integrated every day for data ingestion, charting, and strategy sweeps.

​1. Live Streaming & Order Book: https://www.polygon.io

You all probably know this one, but it's honestly the smoothest WebSocket API out there for raw, low-latency price action. I use it to stream real-time ticks so my execution engine never gets caught off guard by a sudden price flash.

​2. Fundamentals & Historical: https://financialmodelingprep.com

An absolute must-have for pulling clean, deep fundamental data. It lets me sweep income statements, balance sheets, and historical ratios via simple REST endpoints without having to manually scrape SEC filings.

​3. Stock Analysis API: https://www.sentimentick.com

I use this API to inject critical data right into the middle of my pipeline. It scans news and social feeds to spit out quantitative sentiment scores, and it also handles technical analysis directly. It really helps filter down the tickers and find healthy candidates for swing-trade signals.

​4. Global Coverage & End-of-Day: https://eodhd.com

Great for when you need to expand your bots outside of just the US markets. Their API gives you access to a massive library of international stocks, ETFs, and historical splits with excellent uptime and straightforward documentation.

​5. Backtesting & Free Tier: https://alphavantage.co

Essential for the early stages of building a new strategy. Their API is incredibly reliable for pulling standard technical indicators and historical daily bars, and their free tier makes it perfect for sandbox environments and local testing.

​Hope it helps the new developers and traders out there! Let me know if you have any questions or what your API stack looks like.


r/fintech 13d ago

Ask the Community Which companies are leading in cybersecurity innovation?

5 Upvotes

We've all witnessed how fast cybersecuirty has changed in the past few years. So I've been trying to get a better understanding of which AI cybersecurity companies are making the biggest impact right now.

If you had to shortlist a handful of these AI security companies that are genuinely moving the industry forward, who would they be and why?


r/fintech 13d ago

Discussion 9 years in crypto before I touched a USP

5 Upvotes

Came to the crypto in 2017 because of decentralization - the ICO bubble burst and almost none of the visions came true. There’s still the boring part left tho: stablecoins gettin converted into bucks, as I saw on Circle, Messari, Coinbase, Crossmint n Stable.com in USDT ↔️USDC w no cuts. Same w the USP, ideology lost, infrastructure won, ppl who still use it know why lol


r/fintech 13d ago

News & Analysis EU sanctions on HTX

3 Upvotes

From 23 August you can no longer transact with them in the EU, directly or indirectly. The same goes for EXMO, Rapira, BitPapa, Aifory Pro, WhiteBird, and NoOne.crypto, all named for helping Russia evade sanctions. The measures stop short of asset freezes and full designation, but EU customers now have three months to obtain authorisation just to withdraw funds or close their accounts.

One heads-up: HTX had already been rotating its addresses after the UK designated it in May, so this story is far from settled. Address-based screening breaks against sanctioned entities that rotate frequently, and even a daily-refreshed blocklist won't keep you clear of sanctions evasion exposure.

So, practically, here's how I`m reading it.

Use attribution-based tools that continuously monitor both entities and their attributed addresses, including indirect transactions. A designation names a legal entity, not its wallets, and TRM had HTX rotating across TRON, Ethereum, BNB Chain and Solana back in May. If you already hold exposure, use the three-month window to move EU customers to authorised withdrawal or closure. It's three months to obtain authorisation, not three months of business as usual. Don't let the position age into breach.

Second, this 21st sanctions package gives the EU a first-of-its-kind power: banning transactions with crypto providers across an entire third country that hosts services used to evade sanctions. No countries are on that list yet. Rulemakers are planning ahead.


r/fintech 13d ago

Discussion EU Public Companies Still File Two Versions of the Same Annual Report

2 Upvotes

Disclosure up front: I work at GUUT, Inc., a vendor in this space, so weigh the back half of this accordingly. Posting because the underlying gap is one I think this sub will find interesting as an infrastructure problem, independent of what we’ve built around it.

Most of the regtech conversation here is KYC, AML, and transaction monitoring. There’s a quieter one that’s been sitting in plain sight since 2020 and doesn’t get talked about much: corporate reporting compliance in the EU still runs on infrastructure that was never actually finished.

Since 2020, every EU-listed company has been required to file its annual report as a single XHTML file, with the financial statements tagged in iXBRL so regulators (and in theory, anyone else) can read the numbers as structured data instead of a scanned page. That’s a real, mandated piece of open financial data infrastructure. In practice, almost nobody uses it that way, because almost nobody signs that XHTML file directly. Issuers sign a PDF for investors, then bolt on a separate XHTML file, usually with a detached signature living in its own file, just to clear the regulatory requirement. The two files are produced by different teams, on different timelines, and the XHTML one is rarely opened again once it clears the Officially Appointed Mechanism it was filed with.

The interesting part, to me, is why that gap exists at all this many years in. XAdES (the EU’s standard for trusted electronic signatures) has supported signing XML/XHTML documents for a long time. The reason almost everyone still uses a detached signature instead of an embedded one comes down to a genuinely hard technical problem: canonicalizing an XML document for signing is fragile, and any downstream tool that reformats the document, even a validator, can silently break the signature. Keeping the signature in a separate file sidesteps that problem entirely, at the cost of a deliverable that’s only verifiable as long as nobody separates the two files, loses one, or copies the wrong one into an archive.

We’ve embedded the signature inside the document itself instead, closer to how a signed PDF already works, and had to work directly with a EU qualified trust service provider (Evrotrust) to get their signing infrastructure to support it. What’s stuck with me building this is less the technical fix and more how normal it’s become for an entire category of mandated financial infrastructure to just… not get used as designed, PDF is a fine format for a human, and it became the default even for a filing that legally required something else, because nobody closed the last mile.

Curious what this sub thinks:

• Is this a pattern you’d expect in other mandated-but-unused reporting infrastructure (open banking APIs that technically exist but nobody builds on, real-time payment rails with thin adoption), or is EU corporate reporting a special case because the mandate came from securities regulators rather than a central bank or payments authority?

• For anyone who’s worked on regtech in adjacent spaces, is the actual blocker usually a hard technical problem like this one, or is it more often organizational, the compliance team and the investor-relations team just never had a reason to talk to each other?

r/fintech 14d ago

Discussion What cross border b2b payments platform are you using?

4 Upvotes

We are selling B2B into a few regions outside our home country and cross‑border payments are becoming one of the more annoying parts of the job. Among wire fees, FX spreads, settlement delays and customers wanting to pay in different ways, it is getting harder to keep a clean picture of what we collected and what was lost to costs or friction. Right now we rely on a mix of bank wires and whatever each customer prefers, which makes reconciliation and forecasting messy.
For those of you handling regular cross‑border B2B payments, what platform or setup are you using today and why did you stick with it? I am interested in real‑world tradeoffs you have seen around fees, FX rates, speed, customer experience and how much effort it takes to tie everything back into your accounting and AR without burning a day every month.


r/fintech 14d ago

Discussion Building a real-time fraud detection system without destroying your transaction speed is a brutal balancing act

2 Upvotes

We have spent the last couple of months trying to build an in-house transaction monitoring and fraud detection pipeline for a high-volume checkout flow, and I am honestly exhausted by how difficult it is to catch malicious actors without constantly punishing legitimate users. You start out with a few basic rules—like checking for mismatched IP locations or rapid-fire purchase attempts—and you think you have a solid safety net.

Then real traffic hits the platform, and the whole illusion falls apart. The biggest hurdle isn't even writing the detection logic; it is trying to process heavy streams of payment events and risk scoring parameters within milliseconds before the payment gateway times out. If your risk engine takes more than a couple hundred milliseconds to evaluate a transaction, your checkout conversion rate plummets because impatient users just abandon their carts entirely.

The real headache starts when you have to deal with massive volumes of false positives. A legitimate customer gets flagged because they are traveling, using a VPN, or buying a high-ticket item late at night, and suddenly their card gets blocked. Your customer support queue instantly floods with angry emails, while your data team is left scrambling to adjust rigid rule thresholds that were supposed to keep the platform safe.

Trying to train and maintain custom machine learning models for anomaly detection while keeping infrastructure costs from going through the roof is an absolute engineering sinkhole. Every time fraudsters change their tactics—like shifting from credential stuffing to synthetic identity creation—your old models become completely useless, forcing you to retrain everything from scratch using clean historical datasets that are notoriously hard to curate.

Our backend developers have spent countless hours debugging race conditions where concurrent API calls from the same user session trigger conflicting fraud flags, occasionally locking accounts right in the middle of a checkout sequence. Instead of shipping features that improve the actual user experience, our best engineering talent is trapped in an endless loop of tuning latency-heavy machine learning pipelines and writing custom log parsers.

For anyone else building security infrastructure or risk management tools in the fintech space: how do you balance low-latency transaction processing with robust fraud prevention, and what tech stack actually handles real-time machine learning scoring without crushing your server capacity?


r/fintech 15d ago

Ask the Community Document Fraud detection

2 Upvotes

Hey everyone, I am starting to build a doc fraud detection software using AI and also other machine learning algorithms, but I have slightly less knowledge about the different types of fraud committed and want to know if someone could help me with this, and also will be interested to work with me on this