How to choose a loyalty platform vendor: the RFP checklist for Indian brands
A channel loyalty platform decision locks in your trade experience for years — the scan that works or doesn't at a dusty counter in Bhiwandi, the UPI payout that lands in seconds or sits pending for a week, the fraud that leaks 1% of budget or 15%. Yet most RFPs are written for generic software and miss what actually breaks in Indian trade programs. Here is the build-vs-buy decision, a 40-point checklist grouped by capability, the red flags, the pricing models, and the pilot-first contracting structure that de-risks the whole choice. Ground the requirements in how a QR scan-to-earn program actually operates before you write yours.
Build vs buy: the honest arithmetic
Every large brand's IT team believes it can build "a scan-and-points app" in a quarter. What the app description hides is the operating system underneath: serialised code generation at printing-press volumes, scan validation under fraud attack from your own channel, UPI payout rails with reconciliation and retries, per-PAN benefit aggregation for Section 194R TDS (10% once benefits cross ₹20,000/FY), vernacular WhatsApp journeys, and a rules-plus-ML fraud engine that has already seen the bulk-scanning tricks your dealers will invent in week three. In practice an in-house build runs 9–12 months and ₹1–3 Cr before the first live scan, then needs a permanent team — because fraud patterns, payment rails and tax rules keep moving. The build option is rational only when loyalty infrastructure is your product. For everyone else the question is not build vs buy but which vendor — and that is what the RFP must answer.
The 40-point RFP checklist, grouped
Serialisation & factory integration (7 points)
(1) Unique, non-sequential, non-guessable code generation at your annual unit volume. (2) Support for labels, inline variable-data printing and concealed/scratch formats, with named print-vendor integrations. (3) Batch and plant-level mapping so a scan traces to line, batch and dispatch — the backbone of traceability and recall handling. (4) Dual-code designs (outer authentication + inner reward). (5) Code-status lifecycle: generated, printed, activated, scanned, blocked. (6) Wastage and reprint handling without duplicate-payout risk. (7) Evidence: which brands, what volumes, ask for the print-run documentation.
Payout rails & compliance (7 points)
(8) Instant UPI payout with stated success rate (demand >98% first-attempt) and automatic retries. (9) Alternatives: bank transfer, vouchers, catalogue via a rewards catalogue. (10) Penny-drop verification and UPI-name-to-PAN matching. (11) Per-PAN benefit aggregation across cash, points, gifts and trips, with automatic 194R deduction or gross-up at the ₹20,000 threshold. (12) Quarterly TDS return extracts for finance. (13) PAN-mismatch handling that doesn't silently freeze money. (14) Reconciliation reports your finance team can audit against the bank statement line by line.
Vernacular & WhatsApp experience (6 points)
(15) Full user journey — enrolment, scan, balance, redemption, support — on WhatsApp, not just notification blasts. (16) 8+ Indian languages across UI, messages and support, switchable by the user. (17) Assisted-enrolment mode for the field force. (18) Low-end Android and patchy-network tolerance: offline scan queuing, small APK or no-app-needed flows. (19) AI chat support in vernacular for the 70% of queries that are balance and payout status. (20) Proof: ask for language-wise active-user splits from a live program — a vendor who cannot produce them has never run one.
Fraud engine (6 points)
(21) Rules layer: geo-fencing, per-device and per-user velocity caps, time-of-day and location-cluster anomalies. (22) Pattern layer: dealer bulk-scanning signatures, code-harvesting detection, mule-UPI networks, related-account graphs. (23) Configurable actions — hold, review, block, clawback — with an audit trail. (24) A review queue with SLAs, not a monthly Excel export. (25) Reporting of flag rate and confirmed leakage as standard KPIs (healthy: 2–5% flagged, <1% of spend lost). (26) War stories: make the vendor narrate three real fraud patterns they caught and what changed after. Vendors without war stories haven't been attacked yet — you'll be their training data.
Analytics & program operations (6 points)
(27) The full KPI ladder out of the box — enrolment, activation cohorts, 30-day active %, scan frequency, redemption/breakage, fraud, payback — as covered in our KPI guide. (28) Role-cut dashboards: CXO, trade marketing, RSM/field territory views. (29) Matched-control incrementality measurement, or at minimum cohort comparison tooling. (30) Self-serve scheme configuration: point values, slabs, boosters with effective dates and automatic sunsets — no change requests to the vendor's dev team. (31) Campaign and segment messaging. (32) Raw data export / API access so your analytics team is never held hostage.
DMS / ERP integration & data (4 points)
(33) SKU master, price list and dealer-hierarchy sync from SAP/Tally/your DMS, scheduled not manual. (34) Primary-vs-scan reconciliation — the report that catches channel stuffing and code leakage in one view. (35) Invoice OCR for invoice-based incentives where units can't carry QR. (36) Data ownership and exit clauses: participant data, scan history and PAN records are yours, exportable in full, contractually.
Commercials & company (4 points)
(37) Pricing model fit (see below) with worked totals at your Year-1 and Year-3 volumes — insist on the same spreadsheet across vendors. (38) Implementation fees, support SLAs and named success manager. (39) Reference calls with two brands at comparable scan volumes — talk to the program manager, not procurement. (40) Financial and team stability: a loyalty platform holds your channel's money-in-flight and your trade's PAN data; a vendor that folds mid-program is a trade-relations crisis, not just an IT migration.
Pricing models — and how they behave at scale
Per-scan / per-transaction. You pay when the program works — good alignment for QR-heavy programs, and easy to model: 6 million scans at ₹1.5–3 per scan is ₹90 lakh–1.8 Cr, so negotiate volume slabs early. Watch for minimum commitments that quietly convert it into a licence. Per-active-user. Predictable for engagement-led programs; the entire negotiation is the definition of "user" — insist on monthly active, never enrolled, or you will pay for the 40% of your base that registered once and vanished. Platform licence + implementation. Lowest marginal cost at national scale, highest commitment risk up front; best entered after a pilot has proven fit. Most enterprise deals blend a base licence with usage fees. In every model, reward money and payout gateway charges are pass-through on top — budget them separately using our budgeting guide and the cost calculator.
Red flags that end evaluations early
- No live scan-to-UPI demo in the room. If the money can't move in the demo, it won't move in Bhiwandi. This single test eliminates more vendors than the other 39 points combined.
- "Fraud is handled by manual review." At 20,000 scans a day, manual review is a euphemism for no review.
- No answer for 194R. A vendor who says TDS is "the brand's problem" is transferring compliance risk to you along with the audit findings.
- WhatsApp = broadcast messages. Ask to complete an enrolment and a redemption entirely inside a chat thread, in Hindi, during the demo.
- Serialisation references that don't survive a phone call. Printing 10,000 codes for a pilot and 10 million for a national wire brand are different businesses.
- Quarter-long pilot timelines. A configurable platform should sandbox your channel in days and go live in a pilot within 4–6 weeks including print lead time; quarters mean custom development wearing a platform badge.
- Resistance to pilot-first contracting or data-exit clauses. Both signal how the relationship will feel in year two.
Pilot-first contracting: buy the proof, not the promise
The strongest de-risking structure is to contract the pilot, not the platform. Shape: a paid 8–12 week pilot in 2–3 districts, with success criteria written into the agreement — activation above an agreed threshold, payout success >98%, fraud queue SLAs met, support response times honoured — and national pricing pre-agreed so that success flows straight into rollout without a second negotiation (which is where vendors claw back margin). The brand risks one district's budget instead of a three-year national commitment; the vendor is incentivised to prove the program, not close the deal. Design the pilot itself — district selection, control counters, decision gates — using our pilot design guide, and treat the vendor's behaviour during the pilot as the final RFP question: the war-room responsiveness you see in week two of a pilot is the service level you will live with for years.
Frequently asked questions
Should a brand build its own loyalty platform or buy one?
Buy, in almost every case. An in-house build of serialisation, scan validation, fraud detection, UPI payout rails and 194R compliance typically takes 9–12 months and ₹1–3 Cr before the first live scan, and then needs a permanent engineering team to chase fraud patterns and payment-rail changes. Building makes sense only when loyalty infrastructure is itself the company's product, not a supporting function.
What pricing models do loyalty platforms use in India?
Three dominate: per-scan or per-transaction fees (costs scale with success, good for QR-heavy programs), per-active-user fees (predictable for engagement-led programs, but check whether 'user' means enrolled or active), and annual platform licences with implementation fees (lowest marginal cost at scale). Most enterprise contracts blend a base licence with usage fees; reward money and payout gateway charges are always pass-through on top.
What are the biggest red flags when evaluating loyalty vendors?
A demo that cannot show a live scan-to-UPI payout in the room; no named brands doing serialised QR at your volume; fraud handled as 'manual review' rather than a rules-plus-ML engine; no answer for 194R TDS aggregation per PAN; WhatsApp flows that are really just notification blasts; per-user pricing on enrolled rather than active users; and reluctance to contract a paid pilot with exit rights.
How should TDS compliance appear in a loyalty RFP?
Ask vendors to demonstrate per-PAN benefit aggregation across cash, points, gifts and trips; automatic 10% deduction or gross-up once the ₹20,000 annual threshold is crossed under Section 194R; quarterly TDS return extracts for finance; and handling of PAN mismatches without silently freezing payouts. Vendors who treat TDS as 'the brand's problem' are transferring compliance risk to you.
What is pilot-first contracting?
Instead of signing a 3-year national contract off a demo, contract a paid 8–12 week pilot in 2–3 districts with success criteria written into the agreement — activation rate, payout success, fraud-flag handling, support SLAs — and pre-agreed national pricing that activates on success. The brand risks a district's budget instead of a national commitment, and the vendor's incentives align with proving the program rather than closing the deal.
How long should a vendor take to configure a pilot?
For a configurable platform, a working sandbox mirroring your channel structure should exist within days and a live pilot within 4–6 weeks including QR printing lead time. Timelines quoted in quarters for a pilot usually mean the 'platform' involves substantial custom development, which is the build option wearing a vendor's badge.