Guillermo LizasoainPayments Delivery Executive & Operator

For private equity, growth equity, and strategic acquirers

What the diligence deck won't tell you about a payments platform.

I assess payments, PSP, payment-facilitator, and embedded-payments assets for investors — before the deal, and inside the portfolio company after it. Twenty-five years building the systems I now evaluate.

The problem you are actually underwriting

Payments companies are easy to diligence above the line and hard below it.

Volume and take rate are legible. What is not legible from the data room: whether settlement reconciles without manual adjustment, how many processor integrations are genuinely productized versus held together by one person's exception handling, whether the underwriting policy exists as a written rule or as an analyst's judgment, and how much of the codebase can safely be touched by anyone still employed there.

These are the things that do not appear in a quality-of-earnings report and do appear in year two — as an integration that costs three times the estimate, or a platform migration that quietly consumes the value-creation plan.

I have built those systems. I know where they are hidden and what it costs to unwind them.

What I assess

Four places where the value-creation plan usually breaks.

Transaction and settlement integrity

Whether a single transaction can be reconstructed end to end — authorization through settlement to the merchant deposit — without asking three systems the same question.

Example outputs

  • Settlement and reconciliation accuracy, including manual-adjustment dependency
  • Residual and revenue-share calculation integrity
  • Reporting lineage and auditability
  • Exception volume and where it is absorbed

Integration reality

Which gateway, processor, and acquiring integrations are productized, which are bespoke, and which depend on a single person who could resign.

Example outputs

  • Integration inventory with productization and key-person risk rating
  • Realistic migration cost and timeline against legacy and modern processor stacks
  • Certification and compliance exposure
  • Hardware and terminal estate dependencies where relevant

Underwriting and risk operations

Whether risk policy is written and executable, or resident in individual judgment — and what genuine automation would actually require.

Example outputs

  • Pend rate, cycle time, and automation headroom
  • Policy explicitness and testability assessment
  • Sequenced automation path, with AI decisioning placed after stable rules rather than instead of them
  • Operational headcount sensitivity to volume growth

Platform, data, and team

The honest cost of change: what the codebase, the data pipelines, and the people in place can actually absorb.

Example outputs

  • Codebase health and realistic cost of change
  • Data pipeline auditability and repeatability
  • Observability coverage across the transaction lifecycle
  • Whether the technology leadership in place can execute the plan being underwritten

How I work with investors

Four ways in, depending on where you are in the deal.

Pre-LOI technical screen

1 week

A fast read on architecture, integration and key-person risk, and the red flags worth repricing or walking on.

Full technical due diligence

2–3 weeks

Platform, integrations, settlement, underwriting, data, scalability, security posture, and roadmap credibility. Written findings and an investment-committee readout included.

Post-close 100-day plan

3–4 weeks

Findings converted into a sequenced remediation and investment plan the management team can actually run.

Embedded portfolio leadership

Ongoing

Two to three days a week inside a portfolio company as a fractional technology and product executive — for the asset that needs an operator, not another report.

An operator who does diligence, not a diligence firm.

The findings come with a view on what to do about them, and I am willing to stay and execute. That is the difference between a report that gets filed and a plan that gets run.

Evidence

Problems I have already been on the other side of.

Settlement and reporting, rebuilt

Replaced a hand-built settlement and reporting layer with pipelines that reconcile deterministically and can be re-run and audited on demand. The rewrite retired the large majority of a legacy processing codebase and let further processor integrations land without another bespoke exception path.

Underwriting moved from judgment to policy

A merchant onboarding queue sending the overwhelming majority of applications to manual review, cut back by making an implicit risk policy explicit, testable and executable — with AI decisioning sequenced after the rule surface was stable rather than in place of it. The result was a risk function that could be inspected rather than described.

Global acquiring and processor integration

Platform work spanning gateways, processors, acquiring banks, terminals, settlement, and reporting across a multi-acquirer, multi-processor environment — including the country-level implementation blockers, such as national identification-number requirements, that never appear in a vendor's documentation.

Client and employer specifics, and the underlying figures, are available in conversation.

Sectors I know cold

If the asset moves money and the thesis depends on the platform scaling, that is the conversation.

  • Merchant acquiring and ISO economics
  • Payment facilitators and embedded payments in vertical software
  • PSPs and payment orchestration platforms
  • Cross-border payouts and stablecoin rails
  • Terminal and hardware estates
  • Underwriting and risk operations

Bring me in before you sign, or before you fix it.

Most of the platform problems I have spent my career fixing were visible at diligence and priced as if they were not. If you have a live payments deal, or a portfolio company where the platform has become the constraint, that is a short conversation worth having.