Fraud and compliance exposure grows faster than your team.
I help you get ahead of it.

Fraud prevention, risk operations & compliance consulting for SaaS companies and ISVs scaling embedded payment programs.

I'm David. Over 15+ years I've built fraud operations from the ground up at hypergrowth fintech and embedded-payments companies, and directed global risk protecting over $1B in annual payment volume.

Request a Risk Review
Processors & gateways
Stripe Adyen
Bank rails & frameworks
ACH NACHA Plaid
Who I Work With

Built for SaaS Companies Running Payments

ISVs & Embedded Payment Platforms

When you embed payments into your software, you inherit fraud and compliance liability for every transaction your merchants run. Most ISVs don't have the in-house risk function to manage it.

  • Sub-merchant underwriting & onboarding risk
  • Processor compliance obligations (PCI, AML)
  • Liability exposure from merchant fraud losses

SaaS Marketplaces & Multi-Merchant Platforms

Operating a marketplace means managing fraud risk at scale, across hundreds or thousands of sellers. A single bad actor can trigger processor account reviews and damage your entire portfolio standing.

  • Portfolio-level fraud monitoring & alerting
  • Chargeback liability and dispute management
  • KYC flow design for high-volume merchant onboarding

What breaks when volume spikes

Scaling revenue often breaks default payment configurations.

Account Reviews & Holds

If risk flags trigger, processors can pause payouts fast. I align your risk logic with processor risk models to keep cash flowing.

Card Testing Attacks

Thousands of small authorizations from bots trigger risk flags and drive up processing costs ($0.30/attempt adds up fast).

Hidden Liability & KYC Risks

Onboarding the wrong merchant can create losses, processor scrutiny, and portfolio risk. I build defensible KYC and underwriting flows that catch problems before they scale.

How I secure your growth

01

Audit & Architecture

Deep dive into your payment stack. I map out leaks, high-risk vectors, and friction points in your user journey.

02

Remediation & Ops

I deploy custom fraud rules across your payment stack, monitoring dashboards, and dispute defense SOPs.

03

Fractional Leadership

I stay embedded with your team, managing incidents, processor relationships, and risk as volume scales.

What I Build

Adaptive Fraud Rule Architecture

I architect custom fraud logic that blocks attacks without killing conversion. Processor-agnostic expertise across Stripe Radar, Adyen RevenueProtect, Checkout.com Risk, and custom internal tooling.

  • Platform-agnostic rule sets (Stripe, Adyen, Checkout.com, and others)
  • Card security strategies (3DS, AVS, CVC)
  • Precision allowlist/blocklist management
BLOCK IF :block_level: = 'high'
AND :ip_country: != :card_country:
AND :amount_in_usd: > 500.00

REVIEW IF :cvc_check: != 'pass'

Merchant Risk Monitoring

For marketplaces and platforms, I build monitoring logic that tracks sub-merchant health across your portfolio and flags risk before it becomes liability.

  • SQL queries for real-time risk dashboards
  • Slack integrations for instant fraud alerts
  • Underwriting criteria & KYC flow optimization
SELECT merchant_id, COUNT(*) as disputes
FROM payments
WHERE status = 'disputed'
GROUP BY merchant_id
HAVING disputes > 5;

Operational Playbooks & Incident Response

Without documented protocols, every fraud incident becomes improvised. I build clear operating playbooks for incident response, disputes, and decisioning so your team can move quickly without making risk worse.

  • Actionable Incident Response Plans for attacks
  • High-win-rate Dispute Evidence templates
  • Decision trees for Refund vs. Chargeback logic
[ALERT] BIN Attack Detected
├── 1. Activate "High Friction" Rule Set
├── 2. Isolate BIN prefix: 411111
└── 3. ACTION: Batch Refund (< 6 hrs)

Compliance & Regulatory Readiness

Embedding payments triggers real regulatory obligations. I build the compliance infrastructure, policies, frameworks, and documentation, so you stay audit-ready and processor-approved as you scale.

  • PCI DSS scope reduction & audit readiness
  • AML/BSA program design and policy review
  • KYC compliance frameworks & merchant onboarding documentation
  • Regulatory risk assessment for new payment markets
PCI DSS SAQ-D: Scope Reduced
AML Policy: Reviewed & Signed
KYC Flow: Documented
Merchant TOS: Needs Update
BSA Program: Not Implemented

// 2 items require immediate action
Case Studies

What the work actually looks like

Representative examples based on real work. Company details have been anonymized.

Series A Creator Payments Platform

Standing Up a Compliant Payments Program From Zero

A Series A creator payments platform needed to launch payment acceptance and payouts but had no compliance foundation and no sponsor bank relationship in place.

I worked directly with their sponsor bank to build the payment acceptance program from the ground up, and project-managed the full onboarding, aligning the platform, the bank, and the processor through a process most early-stage teams underestimate. I authored the complete compliance stack: policies and procedures, the KYC and onboarding framework, and the operational documentation the bank required for approval.

To validate the program against NACHA Third-Party Sender requirements, I brought in an independent firm to audit everything I had built. The program passed, and I trained their staff on proper payment and risk procedures so it could run without me in the room.

The platform launched on schedule and processed over $100M in its first year, on compliance infrastructure built to scale with it.

$100M+

Processed in year one

0 to 1

Payments program built from scratch

NACHA

Third-Party Sender audit passed

Series C EdTech Platform

From Processor Flag to Clear Standing

A Series C EdTech platform came to me after a $200,000 fraud event and rising processor pressure.

They were onboarding sub-merchants to process tuition payments, but their underwriting was thin and inconsistently enforced. Bad actors slipped through onboarding, ran chargebacks the platform was fully liable for, and pushed their chargeback ratio past the threshold that triggers a processor review. They had no internal risk function, no playbook, and no one who owned it.

In 30 days, I built that function.

I designed a sub-merchant underwriting and KYC framework their onboarding team now enforces on every applicant, stood up a real-time risk monitoring dashboard their ops team uses daily, and trained their team on dispute response and chargeback defense. I stayed on as their fractional Head of Risk to own incidents, the processor relationship, and ongoing monitoring.

The flag was cleared, the losses stopped, and they now have the infrastructure to scale without repeating it.

$200k+

Fraudulent losses stopped

30 days

Processor flag cleared

0 to 1

Risk function built from scratch

How I Engage

Two ways to work with me, depending on your stage, team, and risk exposure.

Ready to secure your growth?

Tell me your processor, payment volume, and where risk is showing up.

Request a Risk Review