﻿WEBVTT

1
00:00:09.520 --> 00:00:10.900
<v 0>Hi everyone. Thanks for joining.</v>

2
00:00:11.380 --> 00:00:13.720
I'm Sarah Rende and I lead risk strategy here at Stripe.

3
00:00:14.860 --> 00:00:18.560
For many fast-growing SaaS platforms, risk is a big unknown.

4
00:00:18.920 --> 00:00:21.900
It sits on the back burner while you're busy shipping for customers,

5
00:00:22.160 --> 00:00:25.840
working off your product roadmap and focused on your everyday business until

6
00:00:25.900 --> 00:00:30.100
something happens that's too big to ignore. In many cases,

7
00:00:30.600 --> 00:00:34.300
if an account on your platform goes bankrupt or something happens,

8
00:00:34.620 --> 00:00:38.780
you're financially responsible. This happened recently to a platform on Stripe.

9
00:00:40.560 --> 00:00:43.760
A cardholder used a stolen credit card to make three transactions.

10
00:00:44.120 --> 00:00:47.500
They were completely normal transactions, average typical order size,

11
00:00:48.000 --> 00:00:48.980
nothing out of the ordinary.

12
00:00:49.860 --> 00:00:52.680
The money was paid out to the legitimate merchant on their platform,

13
00:00:53.140 --> 00:00:58.140
business as usual. But then the charges were later disputed as fraudulent,

14
00:00:58.600 --> 00:01:02.560
and this left the platform on the hook for $23,000 their merchant could not

15
00:01:02.600 --> 00:01:07.460
cover. Now, when this happens, the first instinct is naturally to hit the brake,

16
00:01:07.760 --> 00:01:09.900
slow things down, add some friction,

17
00:01:10.360 --> 00:01:14.380
try to regain a sense of control. And you're right to be cautious,

18
00:01:14.880 --> 00:01:18.580
but we've also learned that this approach can end up costing you way more than

19
00:01:18.600 --> 00:01:19.500
the fraud ever did.

20
00:01:22.620 --> 00:01:24.440
After more than a decade of doing this at Stripe,

21
00:01:24.660 --> 00:01:26.400
we now think about risk a bit differently.

22
00:01:27.120 --> 00:01:30.640
We're thinking about risk as a growth accelerator rather than a platform,

23
00:01:31.240 --> 00:01:33.120
rather than a brake, excuse me.

24
00:01:33.200 --> 00:01:36.720
Having the right risk infrastructure can give you the confidence to continue to

25
00:01:36.860 --> 00:01:40.500
move quickly and grow your business. Today,

26
00:01:40.560 --> 00:01:42.920
we're going to walk through three things. First,

27
00:01:43.040 --> 00:01:46.460
considerations for scaling your business across three stages of the merchant

28
00:01:46.480 --> 00:01:48.320
lifecycle. Next,

29
00:01:48.380 --> 00:01:52.380
we'll talk about making a strategic choice on the right approach to risk

30
00:01:52.440 --> 00:01:55.800
management for your platform and the questions you should be asking yourself to

31
00:01:55.840 --> 00:01:57.860
make a good decision. And finally,

32
00:01:57.920 --> 00:02:01.240
you'll hear from Jobber on how they're using risk as a competitive edge.

33
00:02:02.680 --> 00:02:04.160
Now to walk through the first two sections,

34
00:02:04.500 --> 00:02:07.140
I'd like to invite my colleague to the stage, Connor Mullen.

35
00:02:07.700 --> 00:02:09.360
Connor leads risk product here at Stripe,

36
00:02:09.760 --> 00:02:12.880
and he spent the last few years building the risk infrastructure we're about to

37
00:02:12.920 --> 00:02:14.020
cover. Welcome, Connor.

38
00:02:19.320 --> 00:02:21.500
<v 1>Thanks, Sarah. All right, let's get into it.</v>

39
00:02:22.100 --> 00:02:26.460
Scaling safely starts with moving away from the idea that risk is a one-time

40
00:02:26.480 --> 00:02:30.840
check you perform at sign-up. Risk evolves with your business.

41
00:02:31.520 --> 00:02:33.580
As you bring more business onto your platform,

42
00:02:34.060 --> 00:02:38.460
your risk doesn't just grow-it changes shape. Let's take an example.

43
00:02:38.960 --> 00:02:43.060
Say you onboard a new business and they pass all of your risk checks on day one.

44
00:02:43.580 --> 00:02:45.280
Six months later, they've really scaled,

45
00:02:45.340 --> 00:02:46.960
they're processing more volume than ever,

46
00:02:47.360 --> 00:02:48.960
and they start to have supply chain issues.

47
00:02:49.540 --> 00:02:52.860
Those supply chain issues means they're not able to fulfill orders,

48
00:02:53.520 --> 00:02:58.440
and once they can't fulfill orders, disputes start coming in. As a platform,

49
00:02:58.500 --> 00:02:59.540
this could be your problem.

50
00:03:01.840 --> 00:03:04.960
And this is why we think you need to move away from onboarding as your only

51
00:03:05.020 --> 00:03:09.740
protection, and to a full lifecycle of risk management.

52
00:03:10.520 --> 00:03:13.420
Many platforms today put so much emphasis on onboarding,

53
00:03:13.500 --> 00:03:16.180
trying to stop any bad activity at the gate.

54
00:03:16.840 --> 00:03:19.160
But when you have monitoring and mitigation in place,

55
00:03:19.620 --> 00:03:22.220
you can lower those barriers and keep yourself safe.

56
00:03:23.940 --> 00:03:26.080
Legitimate businesses can get started faster

57
00:03:28.020 --> 00:03:30.620
because you have the systems to catch problems down the road.

58
00:03:31.440 --> 00:03:35.240
And this turns risk management from a growth inhibitor to an accelerator.

59
00:03:36.860 --> 00:03:40.340
So let's get started with the first step: onboarding. To unlock growth,

60
00:03:40.540 --> 00:03:43.540
your priority should be reducing friction at the front door.

61
00:03:44.220 --> 00:03:48.500
You want legitimate businesses getting up and running fast while stopping the

62
00:03:48.600 --> 00:03:52.760
obviously bad ones from getting in too. But right now,

63
00:03:52.840 --> 00:03:55.220
many platforms treat every new sign-up like a stranger.

64
00:03:55.920 --> 00:03:59.520
They don't have data on these businesses, so in order to onboard them,

65
00:03:59.880 --> 00:04:02.800
they collect more information, they ask for more documents,

66
00:04:02.860 --> 00:04:04.780
they go back and forth.

67
00:04:04.780 --> 00:04:08.520
And the result of this is that only 18% of platforms are

68
00:04:08.580 --> 00:04:11.800
able to successfully onboard a business in less than 24 hours.

69
00:04:12.080 --> 00:04:13.320
That's across the whole industry.

70
00:04:15.780 --> 00:04:17.680
Every day legitimate business is waiting,

71
00:04:18.120 --> 00:04:20.620
is the day they're not active on your platform. Or worse,

72
00:04:20.720 --> 00:04:24.060
this friction at onboarding could cause them to just go somewhere else entirely.

73
00:04:25.860 --> 00:04:29.200
So to scale, you need to stop treating every new sign-up like a stranger.

74
00:04:30.400 --> 00:04:32.600
You need signals, automated processes,

75
00:04:32.660 --> 00:04:36.380
and product experiences that allow you to distinguish the good from the bad.

76
00:04:38.660 --> 00:04:41.200
And this really starts with recognizing the good up front.

77
00:04:42.540 --> 00:04:46.460
So one in six businesses globally are already known to the Stripe network.

78
00:04:47.620 --> 00:04:50.580
What that means is when one of these businesses comes to your platform,

79
00:04:51.000 --> 00:04:54.640
they can grant access to their data and get onboarded instantly.

80
00:04:55.260 --> 00:04:58.980
No back and forth, no documents. They're ready to go right away.

81
00:05:01.060 --> 00:05:03.080
And the impact of this is massive.

82
00:05:04.460 --> 00:05:08.400
86% of platforms on Stripe successfully onboard a business in the first 24

83
00:05:08.560 --> 00:05:11.720
hours. That's five times higher than the industry average.

84
00:05:13.860 --> 00:05:17.380
Take Phorest. So they are a platform for nail salons,

85
00:05:18.120 --> 00:05:21.580
and they use Stripe to launch in 10 countries and completely automate their

86
00:05:21.680 --> 00:05:25.580
onboarding and verification process. By using Stripe onboarding,

87
00:05:26.100 --> 00:05:29.940
they've made it so that it takes less than two minutes for a salon to onboard.

88
00:05:30.940 --> 00:05:33.480
And that speed is key to their go-to-market strategy,

89
00:05:33.960 --> 00:05:38.080
because they serve very busy small businesses who just want to get up and

90
00:05:38.100 --> 00:05:41.960
running fast. But you can only do this.

91
00:05:42.040 --> 00:05:45.920
You can only afford to move with that speed if you also have the confidence to

92
00:05:46.140 --> 00:05:50.640
catch bad actors. Instead of investigating every new sign-up,

93
00:05:51.140 --> 00:05:55.300
you can use signals from Stripe's risk intelligence to quickly identify

94
00:05:55.360 --> 00:05:59.380
fraudsters out the gate before they've even processed a dollar.

95
00:06:00.620 --> 00:06:03.660
And that totally changes your team's role and how you think about risk

96
00:06:03.720 --> 00:06:06.560
management. Instead of investigating every single account,

97
00:06:06.840 --> 00:06:10.020
you're able to rely on automated, scalable processes.

98
00:06:11.800 --> 00:06:15.140
Look at FreshBooks. By relying on Stripe's risk signals,

99
00:06:15.980 --> 00:06:19.660
they blocked 300 fraudsters from onboarding in just three months.

100
00:06:21.060 --> 00:06:23.720
And this wasn't just about stopping the bad stuff from happening.

101
00:06:23.940 --> 00:06:27.920
This allowed them to open up the funnel and let more business in without

102
00:06:27.980 --> 00:06:28.820
increasing their risk.

103
00:06:31.440 --> 00:06:33.600
But if we're going to say yes more at the front door,

104
00:06:34.300 --> 00:06:36.540
then you need to have the confidence that down the road,

105
00:06:36.600 --> 00:06:38.520
you're going to catch bad activity when it happens.

106
00:06:39.200 --> 00:06:40.940
And this is why monitoring is so important.

107
00:06:42.340 --> 00:06:46.040
What we see is that historically risk management has been reactive to the actual

108
00:06:46.100 --> 00:06:47.040
bad stuff happening.

109
00:06:47.620 --> 00:06:51.980
You wait for disputes to come in or an account's balance to go negative and then

110
00:06:52.040 --> 00:06:56.620
you start acting. The data on Stripe actually shows this.

111
00:06:57.140 --> 00:06:58.320
So on average,

112
00:06:58.380 --> 00:07:03.180
it takes 40 days for a platform to detect a bad actor after that

113
00:07:03.280 --> 00:07:08.140
original sign of suspicious behavior starts. And by then it's too late.

114
00:07:08.380 --> 00:07:10.700
The funds are gone, the money is out of your platform.

115
00:07:12.300 --> 00:07:17.100
This 40-day window is what we think leads platforms to put so much emphasis on

116
00:07:17.240 --> 00:07:21.440
onboarding and increase friction because it's scary to be in this window of

117
00:07:21.500 --> 00:07:24.740
uncertainty. So to solve this,

118
00:07:25.060 --> 00:07:28.100
we think you need to move to continuous automated monitoring:

119
00:07:28.920 --> 00:07:33.080
adjusting your strategy in real time based on the signals of how a business is

120
00:07:33.120 --> 00:07:38.040
performing-and relying on these automated signals before

121
00:07:38.100 --> 00:07:41.980
there's an issue, before a dispute comes in, before an account goes negative.

122
00:07:42.940 --> 00:07:47.600
And this shifts from like a one-time pass/fail check at onboarding to more

123
00:07:47.640 --> 00:07:49.780
dynamic and ongoing risk management.

124
00:07:52.240 --> 00:07:53.540
To do this with confidence,

125
00:07:54.080 --> 00:07:58.400
you really need to rely on data that doesn't just exist in your platform,

126
00:07:59.540 --> 00:08:02.160
and that's why using signals from Stripe is so powerful.

127
00:08:03.200 --> 00:08:07.410
We process $1.9 trillion in annual volume across 16,000 platforms,

128
00:08:08.640 --> 00:08:13.200
and that data is what feeds our signals-taking your local context as a

129
00:08:13.280 --> 00:08:17.640
platform and combining it with the signals from Stripe so that you can monitor

130
00:08:18.120 --> 00:08:21.680
and prevent bad things from happening before they affect your platform.

131
00:08:25.190 --> 00:08:29.960
Platforms using our automated fraud signals see over five times lower

132
00:08:30.200 --> 00:08:31.960
exposure with these signals,

133
00:08:32.680 --> 00:08:37.360
because we do things like detect fraudulent activity across the Stripe

134
00:08:37.400 --> 00:08:40.840
network and let you know when one of those businesses is on your platform.

135
00:08:41.240 --> 00:08:43.800
And that's the difference that continuous monitoring can make.

136
00:08:46.360 --> 00:08:48.160
We saw this in action with FreshBooks.

137
00:08:48.440 --> 00:08:52.280
By using our automated flags to catch high-risk accounts,

138
00:08:52.480 --> 00:08:56.200
they cut their detection time from 30 days to less than four days.

139
00:08:56.560 --> 00:08:59.360
That's 80% reduction in time to detect fraud.

140
00:09:01.800 --> 00:09:04.720
They even use our signals to detect merchant liquidity issues.

141
00:09:05.000 --> 00:09:08.040
So if a business has signs of trouble, might be going bankrupt,

142
00:09:08.560 --> 00:09:13.240
they can detect that early before it's too late. As FreshBooks put it:

143
00:09:13.680 --> 00:09:15.360
"By leveraging Stripe's data network,

144
00:09:15.520 --> 00:09:19.520
we've eliminated risk exposure blind spots that were invisible in isolation,

145
00:09:20.000 --> 00:09:21.640
allowing us to accelerate growth."

146
00:09:24.180 --> 00:09:26.160
By moving to this continuous life cycle,

147
00:09:26.550 --> 00:09:30.620
Freshbook was able to stop playing catch-up and start getting ahead of issues.

148
00:09:31.040 --> 00:09:35.200
They gained the visibility to confidently keep onboarding barriers low,

149
00:09:36.580 --> 00:09:38.940
knowing that they can detect issues down the road because of monitoring.

150
00:09:41.520 --> 00:09:45.600
But detecting risk is only valuable if you have a precise way to act on it,

151
00:09:46.240 --> 00:09:49.840
and that's why your mitigation strategy is so important.

152
00:09:49.960 --> 00:09:54.720
What we see is that historically platforms rely on blunt tools and heuristics.

153
00:09:56.000 --> 00:09:59.440
For example, flag every single transaction over $5K,

154
00:09:59.800 --> 00:10:03.520
pause the account while we review. But that's just too blunt.

155
00:10:03.640 --> 00:10:07.760
It treats every single user the same. Take an example.

156
00:10:07.820 --> 00:10:11.200
Let's say you're a telehealth platform. You've got provider A and provider B.

157
00:10:12.040 --> 00:10:14.600
Provider A has been active on your platform for three years.

158
00:10:15.240 --> 00:10:16.620
They have near zero disputes.

159
00:10:17.060 --> 00:10:20.040
You verify their online presence and a bunch of information about their

160
00:10:20.080 --> 00:10:24.360
business. And then provider B, who's new to you. They just joined yesterday.

161
00:10:24.980 --> 00:10:27.020
You haven't verified everything about them yet,

162
00:10:27.520 --> 00:10:29.760
and they went from $0 to $50K in just one hour.

163
00:10:31.920 --> 00:10:35.980
If you use a blunt instrument, like a rule that flags every account at $5K,

164
00:10:36.900 --> 00:10:38.580
you could really damage trust with provider A.

165
00:10:39.540 --> 00:10:41.280
You're restricting access to their funds.

166
00:10:41.480 --> 00:10:43.540
They've been a good customer with you for a long time,

167
00:10:45.160 --> 00:10:48.620
and it is more than just damaging their cash flow.

168
00:10:49.600 --> 00:10:51.380
It could make you lose the customer altogether.

169
00:10:53.360 --> 00:10:55.720
So instead of relying on isolated volume triggers,

170
00:10:56.060 --> 00:11:00.540
you need to take context from your entire relationship with the customer and use

171
00:11:00.560 --> 00:11:05.280
that in your mitigation strategy. For provider A,

172
00:11:05.880 --> 00:11:09.460
you don't take any action at all because you know who they are and you trust

173
00:11:09.500 --> 00:11:13.920
them. And then for provider B, instead of just pausing them altogether,

174
00:11:14.340 --> 00:11:16.460
you can use a more precise tool like a reserve.

175
00:11:16.880 --> 00:11:20.900
Setting aside the funds that they're processing while allowing them to still run

176
00:11:20.920 --> 00:11:23.340
their business, they could be your next huge customer.

177
00:11:24.200 --> 00:11:25.920
But with that reserve in place,

178
00:11:25.980 --> 00:11:28.260
you're still protecting yourself should something go wrong.

179
00:11:31.140 --> 00:11:34.300
With Stripe, everything that I just described is built in.

180
00:11:34.760 --> 00:11:39.180
You've got this control plane that allows you to take the right mitigation

181
00:11:39.300 --> 00:11:43.080
actions like restricting payouts, placing reserves, triggering identity checks,

182
00:11:43.540 --> 00:11:47.140
or rejecting accounts if you have to. And as you take these actions,

183
00:11:47.220 --> 00:11:52.120
Stripe gets better itself and more attuned to your product and your platform.

184
00:11:54.480 --> 00:11:57.700
But monitoring and mitigation is not just about stopping bad things from

185
00:11:57.780 --> 00:12:00.960
happening: it's also about learning who you should trust more.

186
00:12:02.000 --> 00:12:06.280
The same signals that allow you to detect that provider A was a good customer

187
00:12:06.820 --> 00:12:10.000
also allow you to extend more trust to them.

188
00:12:11.420 --> 00:12:14.520
When you have that level of certainty, you don't just not take action.

189
00:12:14.800 --> 00:12:18.620
You can give them faster access after they've processed that $5K transaction.

190
00:12:19.020 --> 00:12:21.960
You give them something like Instant Payouts that lets them get that money in

191
00:12:21.980 --> 00:12:25.260
their bank account quickly and keep growing their business on your

192
00:12:25.280 --> 00:12:27.580
platform.

193
00:12:27.580 --> 00:12:31.860
This turns your risk team from a growth inhibitor to a growth

194
00:12:31.880 --> 00:12:35.240
accelerant. So ultimately,

195
00:12:35.340 --> 00:12:39.440
scaling safety safely is not just about a one-time check at sign-up.

196
00:12:39.840 --> 00:12:44.440
It's about managing risk across the entire lifecycle from reducing friction at

197
00:12:44.530 --> 00:12:47.510
onboarding so legitimate businesses can get up and running fast,

198
00:12:48.550 --> 00:12:52.410
to continuous monitoring, to identify threats after they've signed up,

199
00:12:53.800 --> 00:12:55.350
and mitigating with precision,

200
00:12:56.330 --> 00:13:00.490
including moving beyond just stopping bad actors to identifying who to trust

201
00:13:00.590 --> 00:13:02.990
more. And together,

202
00:13:03.110 --> 00:13:07.090
full lifecycle risk management enables you to move risk from a brake to an

203
00:13:07.110 --> 00:13:11.170
accelerator. But knowing what to do is only half the equation.

204
00:13:11.630 --> 00:13:15.130
The other question is who builds it? Sarah's going to walk us through that.

205
00:13:15.470 --> 00:13:16.303
Sarah, back to you.

206
00:13:24.990 --> 00:13:27.110
<v 0>Every platform eventually reaches a crossroads.</v>

207
00:13:27.830 --> 00:13:31.270
Do we want to make risk management a core internal priority that we're going to

208
00:13:31.330 --> 00:13:34.210
invest in, or do we need to look to leverage a partner?

209
00:13:35.650 --> 00:13:40.180
To help you decide, here's three things to consider. First,

210
00:13:40.530 --> 00:13:43.150
your resource allocation. This is really important.

211
00:13:44.050 --> 00:13:46.710
There's only so many resources. Resources are finite.

212
00:13:47.150 --> 00:13:51.570
Is risk management going to be the priority area and the best allocation of your

213
00:13:51.850 --> 00:13:53.590
limited product and engineering resources?

214
00:13:54.110 --> 00:13:57.230
If you're going to bring risk in-house, you'll need to hire and staff a team,

215
00:13:57.670 --> 00:14:01.070
build custom workflows, maintain internal tools and datasets.

216
00:14:01.670 --> 00:14:03.750
It's a big investment. Alternatively,

217
00:14:03.990 --> 00:14:07.230
you might decide that's not the best use of your product resources and instead

218
00:14:07.290 --> 00:14:11.550
want to leverage a partner. Second, your data strategy.

219
00:14:12.110 --> 00:14:15.450
Do you have the right data to actually manage risk? Do you have enough data?

220
00:14:16.250 --> 00:14:16.680
If not,

221
00:14:16.680 --> 00:14:19.390
do you have someone you can partner with who's seen these types of threats

222
00:14:19.430 --> 00:14:24.050
before to augment your own data?
Can you use your proprietary data or are you

223
00:14:24.150 --> 00:14:28.370
already using it to augment the risk decisions for your product and your

224
00:14:28.410 --> 00:14:32.910
customers? And finally, liability management. This is a big one.

225
00:14:33.630 --> 00:14:36.150
You have to remember that as you're scaling your platform,

226
00:14:36.510 --> 00:14:39.990
you're also expanding your financial risk to struggling or fraudulent

227
00:14:40.030 --> 00:14:41.770
businesses. And with that,

228
00:14:41.830 --> 00:14:45.170
you need to think about how much financial risk can your business actually carry

229
00:14:45.530 --> 00:14:47.810
and how much do you want to carry. Effectively,

230
00:14:47.870 --> 00:14:51.030
you're co-signing for every merchant that signs onto your platform.

231
00:14:51.730 --> 00:14:53.250
And depending on your business model,

232
00:14:53.690 --> 00:14:56.790
you may be comfortable with that financial uncertainty or you may decide that

233
00:14:56.810 --> 00:14:58.090
you want to off-load it to a partner.

234
00:14:59.870 --> 00:15:04.490
To hear how a high-growth platform leverages all of these areas to make good

235
00:15:04.510 --> 00:15:06.050
decisions on their risk management approach,

236
00:15:06.450 --> 00:15:08.030
I'd like to invite you to hear from Jobber.

237
00:15:08.710 --> 00:15:12.470
Jobber is a platform for professional services that's optimizing everything from

238
00:15:12.590 --> 00:15:15.950
scheduling appointments to sending customer invoices.

239
00:15:15.950 --> 00:15:18.630
Please join me in welcoming Jobber's Head of Risk, Barnard Steyn.

240
00:15:26.870 --> 00:15:27.790
Thank you for joining us.

241
00:15:28.050 --> 00:15:28.883
<v 2>Thank you for having me.</v>

242
00:15:29.030 --> 00:15:29.863
<v 0>Great to have you.</v>

243
00:15:30.250 --> 00:15:34.690
So we talked a lot today about areas that platforms should consider when they're

244
00:15:35.090 --> 00:15:37.290
deciding on the right risk management approach for their platform.

245
00:15:37.690 --> 00:15:42.290
I'd love to hear if those resonate for you and how you think about whether to

246
00:15:42.370 --> 00:15:43.203
outsource risk.

247
00:15:43.690 --> 00:15:48.210
<v 2>Yeah, thank you. When thinking about outsourcing risk management,</v>

248
00:15:48.750 --> 00:15:50.950
I think there are two things which really come to mind.

249
00:15:51.430 --> 00:15:56.170
The one is the stage of growth your business is in and how closely tied your

250
00:15:56.390 --> 00:15:59.290
growth and revenue is to risk management.

251
00:15:59.710 --> 00:16:01.530
If you're a younger business and you're just starting,

252
00:16:01.690 --> 00:16:03.810
you're really focused on product market fit,

253
00:16:04.370 --> 00:16:07.350
you focused on gaining financial momentum.

254
00:16:07.950 --> 00:16:10.870
You don't really have much choice but to outsource risk management.

255
00:16:11.590 --> 00:16:13.790
As you start scaling and start growing,

256
00:16:13.990 --> 00:16:16.710
it becomes important for a executive team to then decide,

257
00:16:17.190 --> 00:16:19.510
is risk management in- house important for the business?

258
00:16:20.070 --> 00:16:21.350
And if the answer is yes,

259
00:16:21.730 --> 00:16:24.690
then it makes sense to start bringing in pieces of it bit by bit.

260
00:16:25.570 --> 00:16:28.570
I've seen very large successful SaaS companies,

261
00:16:28.950 --> 00:16:30.370
mostly outsource risk management,

262
00:16:30.570 --> 00:16:32.950
because they had a simple portfolio or a simple product.

263
00:16:33.650 --> 00:16:37.590
I've also seen much smaller organizations have to bring in risk management much

264
00:16:37.670 --> 00:16:41.350
earlier in their journeys, simply because of the nature of their product.

265
00:16:41.350 --> 00:16:43.430
It really isn't a one-size-fits-all approach,

266
00:16:43.950 --> 00:16:47.610
and it's something that executive team has to decide on as the business grows.

267
00:16:48.670 --> 00:16:49.503
<v 0>Great, thank you for sharing that.</v>

268
00:16:49.850 --> 00:16:53.650
I think just the nature of the business is a big factor in determining what's

269
00:16:53.670 --> 00:16:57.030
the right path and how complicated it is, seems like a big dimension.

270
00:16:57.330 --> 00:16:57.690
<v 2>Yeah.</v>

271
00:16:57.690 --> 00:17:00.550
<v 0>How high on the priority list do you think risk management should be for</v>

272
00:17:00.970 --> 00:17:02.550
platforms as they're thinking about scaling?

273
00:17:03.690 --> 00:17:05.350
<v 2>My view is that risk management should be high.</v>

274
00:17:06.210 --> 00:17:08.750
Risk management has changed very much in the last decade.

275
00:17:09.110 --> 00:17:10.130
If you think about risk teams,

276
00:17:10.250 --> 00:17:12.590
they used to be somewhat of a compliance function.

277
00:17:12.710 --> 00:17:14.510
They'd be in a corner of the organization.

278
00:17:14.770 --> 00:17:17.730
There'd be a team you'd go to to normally get the answer, "No,

279
00:17:17.870 --> 00:17:20.910
you're not doing that." That has evolved tremendously.

280
00:17:21.670 --> 00:17:25.550
And by having risk management and risk management teams higher up on the

281
00:17:25.590 --> 00:17:26.423
executive agenda,

282
00:17:26.590 --> 00:17:31.150
they get the time and the attention and the resources needed to perform a

283
00:17:31.210 --> 00:17:35.850
function which helps unlock growth and identify new revenue opportunities.

284
00:17:36.710 --> 00:17:36.930
<v 0>Yep.</v>

285
00:17:36.930 --> 00:17:41.030
I think that's so important that there's the company backing and decision that

286
00:17:41.050 --> 00:17:42.590
this is an area we're going to invest in,

287
00:17:43.490 --> 00:17:46.210
and then that really sets up the function for success. Absolutely.

288
00:17:46.770 --> 00:17:50.250
And what was the specific inflection point for Jobber on the decision to bring

289
00:17:50.530 --> 00:17:51.570
risk management in-house?

290
00:17:52.530 --> 00:17:54.390
<v 2>Yeah. So as a reminder, Sarah already mentioned this,</v>

291
00:17:54.450 --> 00:17:58.710
we're a CRM platform with embedded fintech and we serve the trades industry.

292
00:17:58.850 --> 00:18:02.430
So we have plumbers, roof technicians, construction companies,

293
00:18:02.490 --> 00:18:03.970
a very wide variety of businesses.

294
00:18:04.810 --> 00:18:07.870
And the inflection point for us where we realized risk management was better

295
00:18:07.910 --> 00:18:12.450
managed in- house was when we saw how complex our risk world is.

296
00:18:13.050 --> 00:18:16.130
And I'll offer an example. Imagine a lawn care business.

297
00:18:16.190 --> 00:18:19.350
They have many customers. They have many small transactions.

298
00:18:19.610 --> 00:18:22.730
If one customer goes bad or one transaction charges back,

299
00:18:23.090 --> 00:18:25.030
it generally doesn't matter. The business keeps going.

300
00:18:25.710 --> 00:18:29.390
But now imagine a construction business. They have very large transactions,

301
00:18:29.770 --> 00:18:30.690
not many customers.

302
00:18:31.330 --> 00:18:34.570
And if one of those transactions or just one customer goes bad,

303
00:18:35.170 --> 00:18:39.250
it often has enough financial momentum to seriously jeopardize that business's

304
00:18:39.290 --> 00:18:43.310
financial health. With that kind of complexity in the risk environment,

305
00:18:43.410 --> 00:18:44.370
we had to insource.

306
00:18:44.790 --> 00:18:47.610
And we felt that our outsource strategy simply would not be able to deal with

307
00:18:47.630 --> 00:18:49.810
the extreme nuances we see across our portfolio.

308
00:18:51.370 --> 00:18:52.203
<v 0>That makes a lot of sense.</v>

309
00:18:52.790 --> 00:18:55.620
I think just understanding the magnitude there of a different...

310
00:18:55.810 --> 00:18:57.530
A transaction is not a transaction.

311
00:18:57.710 --> 00:19:02.590
Depends on all these other factors of size and the stage of the business

312
00:19:02.650 --> 00:19:03.970
and all of these things like the industry.

313
00:19:04.510 --> 00:19:06.950
<v 2>Absolutely. And if there's concentration risk, it really changes things.</v>

314
00:19:07.130 --> 00:19:07.963
<v 0>Definitely.</v>

315
00:19:08.210 --> 00:19:12.570
And how has your risk strategy affected how you decide where to expand or how to

316
00:19:12.610 --> 00:19:13.443
grow?

317
00:19:13.970 --> 00:19:15.610
<v 2>At Jobber, we have a bit of an inside joke,</v>

318
00:19:15.750 --> 00:19:17.650
and it was coined by our GM of fintech,

319
00:19:17.810 --> 00:19:20.590
is that we want to do things without blowing off our fingers.

320
00:19:21.270 --> 00:19:23.930
So whenever we're going to move into a new product or a new feature,

321
00:19:24.050 --> 00:19:26.090
we spend a lot of energy doing the due diligence,

322
00:19:26.470 --> 00:19:28.430
looking at the upside and downside risks.

323
00:19:29.590 --> 00:19:31.790
We've been processing card payments for a long time.

324
00:19:31.870 --> 00:19:33.750
We understand that risk as an example.

325
00:19:34.430 --> 00:19:36.930
We recently want to expand our ACH portfolio.

326
00:19:37.290 --> 00:19:40.390
It is a payment rail that makes a lot of sense for us and our businesses.

327
00:19:40.870 --> 00:19:42.010
So before we invested there,

328
00:19:42.330 --> 00:19:46.010
we spent a lot of time digging into it and understanding how this works,

329
00:19:46.810 --> 00:19:50.190
and it led us to decide to invest heavily in open banking data.

330
00:19:51.190 --> 00:19:52.710
Looking back on this decision now,

331
00:19:52.830 --> 00:19:56.510
I'm so glad we did that because we've been able to successfully scale the

332
00:19:56.530 --> 00:20:00.810
business without major changes to our exposure. And it's this attitude of,

333
00:20:01.230 --> 00:20:04.370
"Don't blow off your fingers," which leads our product thinking from a risk

334
00:20:04.390 --> 00:20:05.223
perspective.

335
00:20:05.730 --> 00:20:08.990
<v 0>It's always good to have a good catchphrase internally, a strong internal brand.</v>

336
00:20:09.410 --> 00:20:10.130
<v 2>And 10 fingers.</v>

337
00:20:10.130 --> 00:20:12.630
<v 0>I like it. Yes. And 10 fingers. Very important. Yes. Great.</v>

338
00:20:13.490 --> 00:20:14.323
Thank you for sharing that.

339
00:20:14.410 --> 00:20:19.310
I'd love to hear how you're using proprietary data from inside of Jobber and

340
00:20:19.350 --> 00:20:22.410
connecting that with Stripe's payment data to make better decisions.

341
00:20:22.930 --> 00:20:26.390
<v 2>Yeah. We've been a user of Stripe data and Stripe products for a long time,</v>

342
00:20:26.930 --> 00:20:31.430
and we trust it as high-quality data. And without getting technical,

343
00:20:31.490 --> 00:20:36.270
the precision recall is very well-balanced. And our approach is to layer data.

344
00:20:36.450 --> 00:20:40.730
And one of these layers is Stripe data. We obsess about false positives.

345
00:20:40.790 --> 00:20:43.130
And for those in the audience that don't know what a false positive it is,

346
00:20:43.650 --> 00:20:46.630
it's essentially a risk action against a good customer which should have never

347
00:20:46.690 --> 00:20:49.070
happened in the first place. It is a high-friction event.

348
00:20:49.370 --> 00:20:51.590
It's bad for your customer. It's bad for your platform.

349
00:20:52.190 --> 00:20:54.670
And we've seen time and again, by layering data,

350
00:20:55.130 --> 00:20:58.790
you can drive down false positives. It's a key point to our strategy.

351
00:21:00.150 --> 00:21:02.630
<v 0>Yeah. I think sometimes there's not just one answer, right? It's like,</v>

352
00:21:02.710 --> 00:21:05.370
how can we take the best combination of signals to make the best overall

353
00:21:05.390 --> 00:21:06.223
decision.

354
00:21:06.930 --> 00:21:10.790
And then I'd love to hear how you're using automated signals from Radar today.

355
00:21:11.490 --> 00:21:13.850
<v 2>Yeah. Also, we've been using Radar for a very long time.</v>

356
00:21:14.970 --> 00:21:17.230
I've probably used the product for almost a decade now, I think.

357
00:21:17.790 --> 00:21:21.890
And what we've seen is on the spectrum of risk scoring that Radar offers,

358
00:21:22.310 --> 00:21:25.130
on the high end and the low end, the signals are very reliable.

359
00:21:25.210 --> 00:21:28.630
So we've built a lot of automation there. We've kept humans in the loop,

360
00:21:28.830 --> 00:21:30.970
in the sort of the middle of the risk spectrum.

361
00:21:31.890 --> 00:21:36.670
And what this has allowed us to do is to scale the business without having to

362
00:21:36.750 --> 00:21:38.510
scale head count in a linear fashion.

363
00:21:38.990 --> 00:21:42.210
And this additional free time we've gotten back from people and the team,

364
00:21:42.550 --> 00:21:46.270
we've dedicated to other more value-adding risk activities. Also,

365
00:21:46.330 --> 00:21:47.710
it's a key part to our data strategy.

366
00:21:48.410 --> 00:21:50.330
<v 0>Absolutely. I think there's a ton of efficiency there.</v>

367
00:21:50.410 --> 00:21:55.070
And obviously the big theme of this event is around AI and automation.

368
00:21:55.150 --> 00:21:58.930
And I think finding ways to be more efficient with the resources we don't have

369
00:21:58.950 --> 00:22:01.530
to scale head count and overhead is always top of mind,

370
00:22:01.690 --> 00:22:04.590
especially for scaling platforms and growing businesses.

371
00:22:05.890 --> 00:22:08.790
What's the next risk problem that Jobber is tackling?

372
00:22:09.510 --> 00:22:12.550
<v 2>Yeah, I feel like the list of risk problems never ends,</v>

373
00:22:12.990 --> 00:22:17.990
but the things I think about the most is-and some of them might be a bit cliché

374
00:22:18.050 --> 00:22:23.050
and obvious at this point-but the one is the AI arms race between bad actors

375
00:22:23.090 --> 00:22:24.210
and platforms at the moment.

376
00:22:24.670 --> 00:22:28.990
We work really hard to stay a step ahead or catch up really quickly,

377
00:22:30.250 --> 00:22:32.090
and we invest heavily in AI technology.

378
00:22:33.190 --> 00:22:36.690
The second thing that I think about a lot is how AI is going to change the

379
00:22:36.750 --> 00:22:40.670
efficiency for risk teams. It is already having an effect,

380
00:22:41.210 --> 00:22:43.090
and it feels like we're just starting.

381
00:22:43.610 --> 00:22:47.170
I think we're heading for a future where we're going to have extremely efficient

382
00:22:47.210 --> 00:22:52.130
teams because of AI being able to do things which were previously impossible to

383
00:22:52.170 --> 00:22:53.003
do.

384
00:22:53.350 --> 00:22:57.630
I think the third thing which I'm most excited about is how AI is going to help

385
00:22:57.710 --> 00:22:58.810
us, in my view,

386
00:22:59.310 --> 00:23:03.450
develop bespoke risk management strategies.
Today with any kind of risk

387
00:23:03.470 --> 00:23:06.870
management, you segment the risk, you develop a strategy for each segment,

388
00:23:07.230 --> 00:23:11.510
but they are diminishing margins of return for how granular each of these

389
00:23:11.530 --> 00:23:15.550
strategies become. We have an opinion that with AI,

390
00:23:15.610 --> 00:23:19.330
we are going to be able to build strategies at a per merchant level.

391
00:23:20.150 --> 00:23:22.630
Not only is this going to protect the platform, we believe,

392
00:23:23.170 --> 00:23:26.510
it's also going to unlock new revenue opportunities which previously simply were

393
00:23:26.590 --> 00:23:29.210
not accessible. And I think that's what I'm the most excited about.

394
00:23:29.950 --> 00:23:30.783
<v 0>Yeah, I think that's amazing.</v>

395
00:23:30.950 --> 00:23:34.410
I think we feel very similarly just the opportunities here are tremendous,

396
00:23:34.670 --> 00:23:39.090
and for much more customized and personalized risk treatments that feel very

397
00:23:39.250 --> 00:23:43.190
appropriate and targeted, nuanced to individual users. So,

398
00:23:43.590 --> 00:23:45.950
look forward to working on that together. And maybe lastly,

399
00:23:46.030 --> 00:23:50.410
just any words of advice you would give to a head of risk or risk leader who's

400
00:23:50.430 --> 00:23:54.030
in the audience today thinking about evolving their strategy from maybe a more

401
00:23:54.290 --> 00:23:57.290
defensive sort of reactive posture. What advice would you give?

402
00:23:58.310 --> 00:24:03.190
<v 2>My guidance would be that risk management in today's age is</v>

403
00:24:03.270 --> 00:24:07.210
really... Risk management and revenue are two sides of the same coin,

404
00:24:07.410 --> 00:24:11.430
and you have to see them as working in partnership. If you do not do that,

405
00:24:11.570 --> 00:24:13.950
you're surely leaving opportunities on the table.

406
00:24:14.050 --> 00:24:15.150
You're leaving money on the table.

407
00:24:16.410 --> 00:24:20.690
Once you adopt that viewpoint that revenue and growth and risk management go

408
00:24:20.890 --> 00:24:21.723
hand in hand,

409
00:24:22.170 --> 00:24:25.630
you can start applying product management philosophies and start thinking about

410
00:24:25.750 --> 00:24:30.250
risk as a product. It's something we've long driven within Jobber,

411
00:24:30.370 --> 00:24:31.630
and we've had a lot of success with it.

412
00:24:32.450 --> 00:24:36.030
And the ultimate goal for us is not to have zero risk at all.

413
00:24:36.290 --> 00:24:39.330
If you have zero risk, you probably don't have a business. Risk is a good thing,

414
00:24:40.190 --> 00:24:42.490
but to have predictable, controllable risk,

415
00:24:42.770 --> 00:24:44.150
and I think that's the advice I would offer.

416
00:24:45.330 --> 00:24:45.790
<v 0>Sounds good to me.</v>

417
00:24:45.790 --> 00:24:48.830
"Predictable" and "controllable" are nice words to hear in the risk management

418
00:24:48.850 --> 00:24:52.310
field. Thank you so much for joining us. We really appreciate it.

419
00:24:53.190 --> 00:24:56.910
I hope all of you learned something today and heard a little bit more about how

420
00:24:56.970 --> 00:25:00.850
risk can be used as a growth lever and not just as a brake.

421
00:25:01.770 --> 00:25:06.710
Whether you're deciding to invest heavily in building your own risk management

422
00:25:06.790 --> 00:25:11.110
and looking at ways to use our modular tools to empower your teams or

423
00:25:12.130 --> 00:25:15.830
looking for a partner to be able to off-load some of that complexity,

424
00:25:16.090 --> 00:25:18.650
Stripe can help you with that. Wherever you're at on the journey,

425
00:25:18.790 --> 00:25:23.030
we're happy and eager to work with you as partners to find the right solution

426
00:25:23.110 --> 00:25:23.943
for your business.

427
00:25:24.130 --> 00:25:26.990
Please do feel free to join us in the expo at the fraud and risk booth,

428
00:25:27.050 --> 00:25:30.490
and we'll be happy to talk about our strategies and how to help you. Thank you.

429
00:25:30.520 --> 00:25:30.840
<v 2>Thank you.</v>

