Written by: Luke Sobieraj, Founder & COO, Digital Colliers
The Advent-Stripe consortium reportedly walked from a $50B pursuit of PayPal in late 2025. The deal not closing is almost beside the point. The fact that a consortium of that shape got that close means the payments layer is consolidating, and the buy-side conversation about who owns the rails is now a boardroom question, not a strategy-deck question.
If you sit inside a mid-market bank or a regional payments provider, the takeaway isn't about Stripe or PayPal specifically. It's about what happens to your stack when three or four counterparties end up owning the flow you depend on. Most banks I talk to can't produce a clean inventory of that flow on demand. That's the risk.
The deal is a signal, not the story
The pursuit tells you two things. First, private capital thinks the payments layer still has room to consolidate. Second, the acquirers who can write that cheque are the same names already sitting inside your acquiring, orchestration, and BNPL flows. When one of your vendors buys another one of your vendors, your concentration risk shifts overnight and nobody sends you a memo.
DORA has been in force since 17 January 2025, and it explicitly puts ICT third-party concentration on the board's plate for EU-regulated financial entities. If your firm is in scope and you can't map your critical payments dependencies down to the sub-processor, you're already behind on an obligation that has teeth.
What a real payments vendor inventory looks like
Most banks have a vendor list. That's not an inventory. An inventory is a data model, and the fields that matter are the ones nobody fills in. At minimum you want:
- Every acquirer, PSP, orchestrator, tokenisation vendor, and 3DS provider, with the merchant categories and geographies each one actually carries today
- The fallback rail for every primary route, and the last date that failover was actually tested end to end
- Every dormant integration that's still authenticated against a live API key, including the ones nobody has logged into in eighteen months
- Chargeback and dispute flows mapped by network, including which team owns the response window and where the evidence lives
- Sub-processor chains for each vendor, refreshed on a cadence you can defend to a regulator
The gap between "we have a vendor list in a SharePoint" and "we have this data model kept current" is the entire risk surface.
The three things mid-market banks almost always miss
The pattern is consistent. Fallback rails are declared but not drilled. Ask when the last live failover from primary to secondary acquirer happened and you often get a blank look. Second, dormant integrations pile up. A pilot from 2022 leaves behind credentials, webhooks, and a reconciliation job that still runs quietly against a ledger nobody reviews. Third, chargeback flows are only partly mapped. The happy path is documented. The exceptions, cross-border disputes, network-specific evidence rules, representment timing, live in tribal knowledge on two or three people's laptops.
All three of these get worse when a vendor is acquired. Contracts change, sub-processors change, and the integration you never documented is suddenly running against a new legal entity.
Why this compounds with the AI work already on your roadmap
Most banks are also standing up AI for AML triage, fraud scoring, and dispute automation on top of these same payment flows. That's fine in principle. In practice, AML transaction-monitoring false-positive rates already run 85 to 95% at typical mid-market banks, so any model you deploy is being trained and evaluated against a very noisy label set. If the underlying vendor topology shifts under you mid-project, the model drifts and nobody notices until an audit.
Around 95% of enterprise AI projects fail to reach production or ROI, and the ones I've seen die in financial services usually die because the data model underneath was never clean. The payments inventory is that data model for anything you want to build on the transaction flow.
What the operators getting this right are doing
They treat the payments inventory as a live system, not a document. It has an owner, a schema, a review cadence, and an API that fraud, AML, treasury, and vendor risk all read from. When a consortium walks toward one of their vendors, they can answer the concentration question in an afternoon. When it walks away, same thing. That's the position you want to be in before the next $50B rumour lands, because there will be one.

