The Anatomy of a Stalled Deal: Navigating Enterprise Procurement and Regulatory Friction

  • A stalled enterprise deal is often a risk-resolution problem, not a sales problem.
  • Procurement friction is usually created months before procurement formally enters.
  • Outsourcing does not transfer regulatory accountability. The buyer remains responsible for the risks of its third-party relationships.
  • Regulatory, contractual, security and operational blockers should be identified before the formal procurement stage.
  • Executive sponsorship helps, but it doesn’t remove institutional control requirements.
  • Discounting rarely solves a risk objection. Better evidence often does.
  • The goal is not to “get procurement out of the way.” It is to make the procurement decision defensible.

Executive Summary

A stalled deal in enterprise payments rarely stalls for one reason. The sales team blames procurement. Procurement is waiting for legal. Legal is waiting for compliance. Compliance wants evidence on licensing, data flows or transaction monitoring. Technology is questioning integration effort, and finance is challenging the economics. Above all of them, an executive sponsor still believes the project matters, but not enough to override unresolved risk. In regulated financial services, procurement is not simply a buying process. It is part of the institution’s risk-control architecture. That is why a deal with a compelling business case can still stop moving.

When a deal enters procurement, the question is no longer “Does the client want this?” It becomes: “Can the client defend buying this from us?” That is a much harder question. It means regulatory evidence, contractual protections, operational resilience, information security, data handling, licensing, subcontracting, implementation ownership and exit arrangements can matter as much as product capability and price. The strongest commercial teams understand this early. They don’t wait for procurement to discover the risks. They design the deal so that procurement, legal, risk and compliance can explain why the institution is comfortable proceeding.



Procurement Is Not an Event

A common mistake in enterprise sales is treating procurement as an event. It is the point at which questions that were always there become formal. During discovery, everyone talks about the business problem. The bank wants lower operating cost. The fintech wants new corridors. The technology team wants to replace ageing infrastructure. The sponsor wants to go live before the next planning cycle. Those conversations create momentum.

Then procurement arrives, and the questions change:

  • Where is the data hosted?
  • Which legal entity contracts, and which one actually provides the service?
  • Who are the subcontractors?
  • What happens if a critical service fails, and what are the recovery commitments?
  • Can the bank audit the provider?
  • What happens on termination, on acquisition, or if a key processor disappears?

None of this means the client has lost interest. It means the client has moved from commercial enthusiasm to institutional accountability. That is a different phase of the sale.


Why Regulated Buyers Behave Differently

Difficult procurement questions often signal more interest, not less. The institution is serious enough to test whether the relationship can survive scrutiny. This matters especially in payments. A vendor selling an internal workflow tool and a provider supporting payment processing, transaction routing, reconciliation or fraud controls are both “vendors,” but their risk profiles are not comparable.

Regulators have formalized these expectations. The 2023 US Interagency Guidance on Third-Party Relationships describes a lifecycle covering planning, due diligence, contract negotiation, ongoing monitoring and termination. It is explicit that using a third party does not remove a bank’s responsibility to comply with applicable laws. The regime is also evolving. In September 2026, the US federal banking agencies proposed replacing that guidance with a more principles-based approach that ties oversight to the actual risk each relationship poses. For vendors, that raises the stakes of positioning. A provider that can show clearly where it sits on the risk spectrum makes the buyer’s classification decision easier. One that can’t will be reviewed as high-risk by default.

So the buyer isn’t merely asking “Is this vendor good?” It is asking “Can we demonstrate that using this vendor fits our risk appetite, controls and regulatory obligations?” That explains why a deal that looked 90% complete can suddenly feel like it has gone backwards. It hasn’t. The definition of “complete” has changed.


The Five Friction Points

Most stalled enterprise deals break down into a few interconnected friction points.

  1. Commercial approval exists, but institutional approval does not.
    • The sponsor says, “We have internal approval.” Approval from whom, and for what? Budget, business case, procurement, risk, technology, legal and committee approvals are not interchangeable.
    • A senior sponsor can genuinely want the deal and still lack authority to commit the institution. The result is phantom momentum. The pipeline shows a late-stage opportunity while the organisation is still solving for approval.
  2. Procurement is asked to solve problems sales should have anticipated.
    • A vendor spends six months selling value, then expects procurement to work through the risk architecture in three weeks. It rarely works.
    • If the solution touches regulated activity, customer data, transaction processing or cross-border flows, most of the questions are predictable. The sales team doesn’t need to answer all of them itself, but it must know they are coming. Regulatory guidance places due diligence before the relationship begins, covering legal and compliance requirements, data security, financial condition and service levels. If you wait for procurement to raise these, you are already late.
  3. The vendor sells a product; the buyer evaluates a dependency.
    • The sales deck shows: API → integration → transaction → reporting.
    • The buyer is thinking: vendor → data → customers → operations → regulators → audit → incident → contingency → exit.
    • That second picture raises questions a demo never answers. Who has privileged access? How fast must incidents be notified? What happens when a subcontractor changes? Can the bank migrate away without disruption? From the buyer’s perspective, these are part of the product.
  4. Regulatory ambiguity creates commercial hesitation.
    • “We support corridor X” can hide a dozen separate questions:
      • Which entity performs the regulated activity, and which holds the licence?
      • Who controls customer funds?
      • Who performs KYC and transaction monitoring?
      • Where does the data move?
      • Which local partners are involved, and which rules apply to each component?
    • A vendor that cannot explain its own operating model forces the buyer to reconstruct it. Ambiguity becomes risk, risk becomes review, and review becomes delay. That is how an attractive deal stalls without anyone ever saying “no.”
  5. Legal turns sales language into obligations.
    • “Secure,” “resilient,” “compliant,” “real-time,” “highly available.” These words work in a presentation and become liabilities in a contract. The moment a claim becomes an obligation, someone must define it. What is the SLA? What counts as an incident? What are the audit rights, the liability cap, and the treatment of data at termination? Legal asking these questions isn’t the problem. Sales never having considered the answers is.

An Illustrative Scenario:

Consider a typical pattern. A payments provider wins strong sponsorship from a bank’s head of transaction banking. The business case is approved, pricing is agreed, and the deal is forecast to close within the quarter. Then the bank’s third-party risk team classifies the provider as critical. It requests evidence of where settlement data is stored, the identity of a sub-processor in a second jurisdiction, and incident-notification commitments. None of this had been discussed.

The sales team offers a further discount. Nothing moves, because price was never the blocker. The deal closes two quarters late, after the provider assembles the evidence it could have prepared at discovery.

The sponsor was real. The value was real. The deal was simply built for commercial approval, not institutional approval.


Procurement Friction Is Often a Symptom of Earlier Sales Design

Sales organizations often misdiagnose this. Procurement is usually exposing weaknesses that were there all along:

  • Weak qualification: the economic buyer was qualified, the risk stakeholders were not.
  • Weak discovery: the business case was understood, the approval architecture was not.
  • Weak stakeholder mapping: the vendor knew the sponsor, not the people who could stop the deal.
  • Weak solution design: the product was demonstrated, the operating model was not explained.
  • Weak documentation: technical material was supplied, risk-review evidence was not.
  • Weak commercial architecture: pricing was agreed before the contracting structure was clear.
  • Weak regulatory positioning: the vendor said what it could technically do, not what it could legally and operationally support.

By the time procurement appears, these weaknesses are expensive to fix. The team is retrofitting institutional confidence into a deal built on commercial enthusiasm.


The Executive Sponsor Is Necessary, But Not Sufficient.

A strong sponsor resolves prioritization, allocates resources and sustains momentum. But sponsorship is not authority. The sponsor says, “We need this.” Procurement asks under what terms. Risk asks what happens if it fails. Compliance asks how it fits the institution’s obligations. Technology asks how it will operate. Finance asks about total economic impact. Legal asks what exactly is being agreed.

Wanting the project doesn’t answer any of those. Alignment has to run across functions, not just up the hierarchy. The goal isn’t one excited senior person. It is enough institutional agreement for the transaction to survive scrutiny.


The Evidence Gap

The vendor says, “We can do it.” The buyer says, “Show us.” That is reasonable. Depending on the relationship, the evidence may include:

  • security assessments, audit reports and certifications
  • penetration-testing results
  • business-continuity and disaster-recovery arrangements
  • incident procedures and data-flow diagrams
  • subcontractor details and financial information
  • licensing documentation and compliance policies
  • transaction-monitoring controls
  • service-level definitions

This is not a US-only concern. The Financial Stability Board’s December 2023 third-party risk toolkit reflects the same global trend. Institutions depend increasingly on external providers for critical services, and supervisors expect those dependencies to be understood and managed. The lesson for sales leadership is simple. Your due-diligence package is part of your sales infrastructure. It should exist before the client sends a 200-question questionnaire, not be assembled after.


The Contract is part of the Product.

This is uncomfortable for product-led organizations, but it holds in regulated enterprise sales. If a bank cannot obtain appropriate audit rights, reporting, service commitments, security obligations, incident notification or termination provisions, the product may be commercially unusable, however good the technology. Commercial, legal, compliance, security and product teams therefore need to align before final negotiation. Not every deal needs a committee. But the buyer is purchasing an operating relationship, and the contract defines much of it.


The Discount Trap

When a deal stalls, the reflex is to discount. Sometimes price really is the problem. Often it isn’t. A 15% discount doesn’t remove regulatory exposure. Lower implementation fees don’t solve data residency. Better pricing doesn’t create subcontractor visibility. Discounting creates an illusion of progress. The buyer says, “Improve the terms and we can move forward.” The terms improve, the deal doesn’t move, and the vendor now has less margin while the original blocker remains.

The better question is: “What specifically prevents you from signing?” Keep asking until the answer is concrete. “Legal,” “risk” and “procurement” are departments, not blockers. The blocker is the unresolved decision underneath the department.


Find the Named Blocker

When a deal stalls, stop talking about functions and start talking about decisions.

Instead of…Ask…
“Legal is reviewing the contract.”Which clause?
“Compliance has concerns.”Which requirement?
“Procurement wants more information.”Which information, and who approves it?
“Technology is assessing integration.”Which dependency is unresolved?
“The regulator may have concerns.”Which interpretation or approval is needed?

A vague stalled deal becomes a finite list of decisions, and that is manageable.


Run the Final Mile as Parallel Workstreams

Procurement should be a parallel workstream, not the last step. Once an opportunity is strategically serious, five tracks should run together:

  1. Commercial: what is being bought, why now, the economic case, budget ownership.
  2. Regulatory and compliance: which regulated activities are involved, which entities perform them, which licences apply, which controls must be evidenced.
  3. Technology and security: which systems connect, what data moves and where it is stored, what security and resilience requirements apply.
  4. Legal and procurement: who contracts, which obligations are material, the liability, audit, termination and service terms, which deviations need executive approval.
  5. Implementation: who owns delivery, which dependencies sit with each party, which third parties are involved, what must happen before go-live.

This is not bureaucracy. It is deal architecture.

Ask the Better Question Earlier. Don’t ask “When can you sign?” Ask: “What would have to be true inside your organisation for you to be able to sign?”

If the buyer says compliance approval is needed, ask what compliance needs to see. If the technology risk team must approve the architecture, ask for their decision criteria. If procurement requires an approved vendor, ask what that takes.

Each answer becomes a workstream. You are no longer chasing a signature. You are mapping the decision system.


Not All Friction Should Be Removed

Some friction exists for good reason. A bank’s need to understand its third-party dependencies, data handling and operational resilience is not bureaucracy. The commercial skill is to distinguish necessary control from avoidable process friction. The first requires evidence and risk resolution. The second may require executive intervention or process redesign. A team that treats both as “procurement being difficult” can solve neither. As oversight becomes more proportionate to actual risk, vendors that help buyers tell the two apart will move faster than those that don’t.


Cross-Border Payments Amplify Everything

A domestic deal may involve one client, one vendor and one legal framework. A cross-border proposition can involve:

  • multiple entities and jurisdictions
  • correspondent banks and local payment systems
  • FX and settlement arrangements
  • sanctions screening and transaction monitoring
  • data transfers and local licensing
  • outsourcing and subcontractors

The commercial proposition may be simple. The operating model is not. Teams with deep corridor knowledge have an advantage here, if they use it. Move from “We support this corridor” to: “Here is how the transaction moves, which entities participate, what each does, where the controls sit, and which parts depend on third parties.” That is a credible enterprise conversation.


What a Healthy Late-Stage Deal Looks Like?

A healthy late-stage deal doesn’t have zero open questions. It has known questions with named owners and defined paths to resolution. Sales leaders should be able to answer them.

  • Which approvals remain, and who owns each?
  • What evidence is still required?
  • Which contract issues are negotiable, and which are risk constraints?
  • Which issues need executive escalation?
  • What are the implementation and regulatory dependencies?
  • What happens if an issue cannot be accepted?

That last question matters most. A real deal plan needs a failure path. Otherwise the forecast is optimism disguised as process.


The Forecasting Consequence

A deal shouldn’t move from “late stage” to “commit” because the sponsor likes the solution. Once institutional approval is the gating factor, the forecast must reflect decision completion, not emotional confidence.

Deals that slip at this point rarely fail for lack of belief. They fail because nobody established what had to happen before the deal could happen. That isn’t a late-cycle forecasting problem. It is a qualification problem that started much earlier.


What I Would Change in the Sales Process?

If I were rebuilding an enterprise payments sales process today, I would make one structural change i.e move procurement and regulatory discovery forward. Not negotiation and Discovery. Before a deal becomes a forecasted commitment, the account team should understand:

  1. The legal entities involved
  2. The regulated activities involved
  3. The client’s third-party risk classification
  4. The likely security and technology review
  5. The client’s procurement process
  6. The contracting entity
  7. The evidence required
  8. The key contractual constraints
  9. The approval committee or governance structure
  10. Who the executive sponsor is, and who holds actual decision authority

This doesn’t mean dragging procurement into early calls. It means the sales organisation needs enough institutional intelligence to know what’s coming.


The Real Skill: Designing Deals That Survive Scrutiny

The deeper skill isn’t navigating procurement. It is designing a deal that can survive institutional scrutiny. That takes:

  • commercial judgment
  • regulatory literacy
  • an understanding of technology risk
  • knowledge of how banks actually decide
  • the discipline to know when to push, and when to say, “We cannot give you that.”

Saying no feels uncomfortable, but credibility compounds. A promise made in the sales cycle that legal, compliance or technology can’t support later is momentum borrowed from the future, and the debt always comes due. It follows that the best deal isn’t the one that moves fastest. A deal that moves quickly because nobody asked hard questions may simply be under-qualified. In regulated financial services, the goal isn’t zero friction. It is predictable friction like knowing which questions will be asked, by whom, what evidence answers them, what is negotiable, and where executive intervention is genuinely needed.

The deals that close tend to share a pattern. The commercial case is clear. The operating model is understandable and the regulatory position defensible. Risk questions have owners, the evidence exists, and the contract reflects reality. The sponsor understands the approval architecture, and the sales team knows what it doesn’t control.

Sales can’t dictate a bank’s risk appetite, a regulator’s interpretation or legal’s liability position. What it can do is reduce avoidable uncertainty. That is where commercial leadership has real leverage.


Final Thought: Stop Chasing the Signature

A stalled deal triggers a familiar reaction. The quarter approaches, leadership asks for updates, calls increase, another concession is offered, and someone says, “We just need to get this over the line.” A transaction doesn’t become healthier because we want the signature more urgently.

The better question is: What institutional decision has not yet been made, and what evidence is required to make it? It is less exciting than “How do we close this?” It is also far more useful. Enterprise payments are not sold through persuasion alone. They are sold through confidence: the buyer’s ability to defend the decision to procurement, legal, risk, technology, compliance, finance and, ultimately, the people accountable for the institution. Seen that way, procurement stops being the enemy at the end of the cycle. It becomes a mirror, showing whether the deal was built well enough to close.


Disclaimer: This article reflects insights and perspectives developed through experience in enterprise payments, cross-border financial services, banking technology and regulated markets. Requirements vary by institution, product, jurisdiction and regulatory perimeter; organizations should obtain appropriate legal, compliance and regulatory advice for their specific circumstances.

Leave a Comment