GoCardless

UK · gocardless.com · 32 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 32 sub-vendors.

Insights

Last updated 2026-08-11 · revision 2

32 direct vendors, 242 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

GoCardless exhibits high migration readiness primarily due to its highly modern and cloud-native internal tech stack. The use of AWS and GCP, coupled with containerization (Kubernetes, Docker) and infrastructure-as-code (Terraform), signifies an architecture that is inherently flexible, portable, and well-suited for migrations or platform shifts. The presence of a robust REST API and support for various programming languages further indicates a modular and API-driven approach, simplifying integration and potential re-platforming efforts. The existing focus on PSD2/Open Banking Compliance and ISO 27001 suggests well-defined processes that can aid in navigating regulatory aspects during a migration. If external vendors are involved, their geographic diversity across 8 countries could offer flexibility in choosing alternative solutions during a migration. The assessment is hampered by the lack of specific data on data residency requirements, which could introduce significant complexity and cost if strict regulations apply to their operations. Similar to resilience, the absence of financial stability data (revenue concentration, growth history) makes it impossible to gauge the company's financial capacity to fund a large-scale migration. The "Total Vendors: 0" data point, despite other vendor information, creates ambiguity around vendor lock-in. If taken literally, it implies minimal vendor lock-in, which would be a significant strength. However, if external vendors provide the 43 services, the number of distinct vendors is unknown, making it challenging to precisely quantify the vendor lock-in risk. "Vendor Lock-in Risk: Unknown" was explicitly stated in the data.

Compliance

11 in-scope frameworks identified; showing 3.

SOC 2 (source) — Compliant

GoCardless is a cloud-based payment services provider handling sensitive financial data for 100,000+ businesses. SOC 2 is a de facto standard for cloud service providers in the financial sector, and enterprise customers routinely require SOC 2 reports as part of vendor due diligence. GoCardless's security page references security certifications and the company's scale and enterprise customer base make SOC 2 compliance highly likely. Risk is Low because GoCardless appears to maintain active compliance, and the framework is well-suited to their cloud-native architecture.

Evidence: https://gocardless.com/security

FinCEN — Compliant

GoCardless Inc. is a FinCEN-registered Money Services Business (MSB) and licensed money transmitter in certain US states, creating significant AML/BSA compliance obligations. Non-compliance with BSA/AML requirements can result in substantial civil and criminal penalties. Risk is Medium because GoCardless has demonstrated compliance through FinCEN registration and state money transmitter licensing, but ongoing AML program maintenance, suspicious activity reporting (SARs), and state-by-state licensing requirements create continuous compliance obligations.

Evidence: https://gocardless.com/en-us/legal/usa-licenses, https://www.fincen.gov/msb-registrant-search, https://www.nmlsconsumeraccess.org/

ISO 27001 (source) — Compliant

ISO 27001 certification is standard for payment processors and financial services companies of GoCardless's scale. The company processes sensitive financial data (bank account numbers, payment data) for 100,000+ businesses globally, making robust information security management essential. GoCardless's security page and enterprise customer requirements strongly indicate ISO 27001 certification. Risk is Low because the framework is well-established and GoCardless's business model necessitates strong information security controls.

Evidence: https://gocardless.com/security, https://gocardless.com/legal

Financials

Three-year financials

Financial Resilience Score: 6/10

GoCardless demonstrates strong financial momentum with two consecutive years of ~38% revenue growth and a significant narrowing of net losses in FY24 (from £78.0m to £35.1m, a 55% reduction). The company processed £39.6bn in payments in FY24 and serves 94,000+ customers, providing meaningful scale and recurring revenue stability from its subscription billing base. Management has articulated a 'clear path to profitability,' supported by cost discipline following a ~15% workforce reduction in mid-2023. The company is well-capitalized, having raised over US$500m in equity including a US$312m Series G in 2022 at a ~US$2.1bn valuation, with backing from top-tier investors including Alphabet's CapitalG, Bain Capital Ventures, Accel, Balderton, and Salesforce Ventures. Diversification is improving, with 24% of revenue now international and North America growing 51% YoY in FY24. However, GoCardless remains loss-making at the group level with cumulative losses continuing to accrue, and profitability has no firm date. The UK filing excludes GoCardless Inc. (US) and GoCardless SIA (Latvia), so group-wide economics may differ. There is also down-round risk given the frothy 2021-22 valuation environment, competitive intensity from Stripe, Adyen, TrueLayer, Modulr and others, and a modest tailwind from interest income on client balances that could reverse if rates fall.

Key strengths: Two consecutive years of ~38% revenue growth, Net loss narrowed 55% in FY24 to £35.1m, £39.6bn payment volume processed in FY24, +28% YoY, 94,000+ customers with largely recurring subscription billing, Well-funded with US$500m+ raised, including Series G at US$2.1bn valuation, Strong investor base: CapitalG, Bain Capital Ventures, Accel, Balderton, Permira, BlackRock, International revenue reached 24% of total; North America grew 51% YoY, Strategic M&A: Nordigen (open banking) and Nuapay/Sentenial (send-money capability)

Risk factors: Still loss-making at group level with growing cumulative deficit, No firm profitability date disclosed, UK filing excludes US and Latvian subsidiaries, obscuring full group economics, Down-round risk from 2022 peak valuation of US$2.1bn, Intense competition from Stripe, Adyen, TrueLayer, Modulr, Trustly, Volt, Regulatory exposure across UK FCA, US MSB, and evolving open banking frameworks, Interest income (part of £132.8m total income) is rate-dependent and could shrink, Executed ~15% workforce reduction in mid-2023 indicating prior cost pressures

Revenue by geography

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report