From what I've seen, the key is finding a partner who actually understands your existing architecture rather than trying to sell you their standard package. You want someone who can work with your tech stack, not against it. The regulatory side is crucial too - make sure whoever you work with has experience with PSD2, GDPR, and whatever specific requirements your target markets have. API-first solutions tend to be more flexible, but you need solid documentation and support during integration. Don't rush the decision, this is your core infrastructure we're talking about.