Mekorma
United States · www.mekorma.com · 13 vendors
Resilience scores
- Digital Sovereignty: 62
- Digital Resilience: 6
- Financial Resilience: 7
Technology vendors
- Continia Software — Technology — Denmark
- Google LLC — Technology — United States
- Netlify, Inc. — Technology — United States
- and 10 more
Services catalogue
3 services in catalogue across 2 categories; runs on 13 sub-vendors.
- Payment Hub
- Shared Services - Multi-Entity
- Vendor Validation
Insights
Last updated 2026-08-15 · revision 3
13 direct vendors, 170 subvendors
Direct vendors by controlling owner country (sample)
- United States: 8
- Canada: 2
- United Kingdom: 2
Subvendors by controlling owner country (sample)
- Unknown: 1
- Germany: 6
- Norway: 3
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Mekorma demonstrates a good level of migration readiness. Its internal technology stack is predominantly modern and cloud-native, utilizing Microsoft Azure and Dynamics 365 Business Central, along with AL Language for development. This foundation is highly conducive to future migrations, offering flexibility and scalability. The absence of specified data residency requirements further simplifies potential migration efforts. Vendor relationships indicate geographic diversity across 4 countries, which can help mitigate complexity associated with vendor concentration during migration. However, a significant challenge and unknown factor is the 'Vendor Lock-in Risk,' which is not specified. High vendor lock-in could substantially complicate and increase the cost of migration. Additionally, financial stability (revenue concentration, growth) and regulatory environment details are not available, which are crucial for assessing the company's ability to fund and navigate a migration project. While their products support legacy ERPs like Dynamics GP, their internal systems appear to be more modern, which is a positive for their own migration.
Compliance
7 in-scope frameworks identified; showing 3.
FinCEN — Assessment Required
The Bank Secrecy Act (BSA) and FinCEN regulations apply to 'money services businesses' (MSBs) and financial institutions. Mekorma's Remote Payment Services facilitates B2B vendor payments via ACH, EFT, and virtual card. If Mekorma is classified as a money transmitter or payment processor under FinCEN regulations, it would be subject to BSA/AML requirements including registration, customer due diligence, suspicious activity reporting (SARs), and recordkeeping. However, Mekorma appears to act as a software intermediary rather than a direct money transmitter — the actual fund movement is handled by Corpay and Priority Commerce. Risk is Medium because the regulatory boundary between software vendors and money transmitters in payment facilitation is complex and fact-specific.
Evidence: https://www.mekorma.com/solutions/remote-payment-services, https://www.fincen.gov/money-services-business-msb-information-center, https://www.mekorma.com/solutions/vendor-validation
PCI DSS (source) — Partially Compliant
Mekorma's Privacy Policy explicitly states: 'We also comply with payment card industry data security standards during the processing of credit and debit card transactions.' This self-declaration indicates PCI-DSS awareness and claimed compliance. However, Mekorma's Remote Payment Services includes virtual credit card payments to vendors, and the Payment Hub processes payment transactions within ERP environments. PCI-DSS compliance is critical for any entity that stores, processes, or transmits cardholder data. Risk is High because: (1) payment card data is among the most sensitive financial data; (2) non-compliance can result in significant fines from card brands (Visa, Mastercard) and potential loss of ability to process card payments; (3) the self-declaration in the Privacy Policy is not supported by a publicly disclosed PCI-DSS attestation of compliance (AOC) or Report on Compliance (ROC); (4) virtual card payments through Remote Payment Services involve cardholder data flows that require rigorous PCI-DSS controls.
Evidence: https://www.mekorma.com/linked-webpages/terms-of-use-privacy, https://www.mekorma.com/solutions/remote-payment-services, https://www.pcisecuritystandards.org/
NACHA Operating Rules — Assessment Required
Mekorma's Remote Payment Services explicitly supports ACH (Automated Clearing House) and EFT payments to vendors. NACHA Operating Rules govern all ACH transactions in the United States and impose obligations on Originators, Third-Party Senders, and Third-Party Service Providers. If Mekorma acts as a Third-Party Service Provider (TPSP) or Third-Party Sender (TPS) in the ACH network — by initiating or facilitating ACH entries on behalf of its customers — it is subject to NACHA Operating Rules including: data security requirements (WEB Debit Account Validation, data encryption), risk management, audit requirements, and registration obligations. Risk is High because: (1) ACH fraud and unauthorized transactions carry significant financial and reputational risk; (2) NACHA violations can result in fines and suspension from the ACH network; (3) the exact role of Mekorma vs. its payment partners (Corpay, Priority Commerce) in the ACH origination chain is unclear.
Evidence: https://www.mekorma.com/solutions/remote-payment-services, https://www.nacha.org/rules/third-party-sender-registration, https://www.nacha.org/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Mekorma is a privately held, founder-owned US software company with a 35-year operating history in the AP automation and B2B payments niche. Although no audited financials, revenue figures, EBIT, or equity data are publicly disclosed, several qualitative signals suggest a stable and resilient business. The company has a large installed base of 5,000+ customers, a recurring revenue model based on subscriptions and transaction-based Remote Payment Services, and deep entrenchment in the Microsoft Dynamics ERP ecosystem, which creates high switching costs. Founder-led continuity under Ora Goldman since 1990, absence of private-equity buyouts, and the presence of a professionalized finance function (dedicated CFO Carol Wood) support the view of a stable, bootstrapped ISV. Industry tailwinds in AP automation and B2B payments further support the resilience profile. However, the company faces meaningful concentration risk from its dependence on the Microsoft Dynamics platform family, especially given Microsoft's planned sunset of Dynamics GP (mainstream support ending 2028). The strategic transition to Dynamics 365 Business Central and Acumatica is a critical execution risk. Competitive pressure from larger, better-capitalized AP automation vendors (Bill.com, AvidXchange, Tipalti, Stampli) targeting the same SMB/mid-market segment is another key risk. Regulatory and payments compliance risk related to ACH and virtual card handling under NACHA rules also warrants consideration. Overall, resilience appears solid but cannot be fully verified without access to private financial data.
Key strengths: 35-year continuous operating history since 1990, Founder-led with stable private ownership (no PE buyout), 5,000+ customer base with high switching costs, Recurring subscription and transaction-based revenue model, Deep entrenchment in Microsoft Dynamics ecosystem (Certified Microsoft Solutions Partner), Dedicated CFO indicating professionalized finance function, Industry tailwind in AP automation and B2B payments, Expansion into Dynamics 365 Business Central and Acumatica platforms
Risk factors: Platform concentration risk with Microsoft Dynamics dependency, Microsoft Dynamics GP sunset (mainstream support ends 2028), Competitive pressure from larger vendors (Bill.com, AvidXchange, Tipalti, Stampli), Private-company opacity limits external risk verification, SMB and mid-market customer segment concentration, Regulatory and payments compliance risk (NACHA, banking partners), Execution risk in transition from Dynamics GP to Business Central
Revenue by geography
- United States and Canada: 0%
Revenue by product/service
- Vendor Validation: 0%
- Payment Hub (subscriptions): 0%
- Shared Services / Multi-Entity: 0%
- Remote Payment Services (ACH/EFT/Virtual Card): 0%
Workforce by country
- United States: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.