Example engagement ยท Fintech: B2B payments and accounts payable automation
AEO audit for a B2B payments and AP automation company
A hypothetical B2B payments and AP automation company, used to show how AEO HQ's audit would run in fintech: buyer prompts, crawler checks, a register of regulated claims, and the report. No results.
An example engagement for a hypothetical company, showing how the audit runs and what it delivers. It is not a client result.
Industry guide: SEO, AEO, and GEO for fintech and financial services
The company
| Item | Profile (hypothetical) |
|---|---|
| Product | AP software and payments: invoice capture, approval routing, sync with enterprise resource planning (ERP) systems, and payment by ACH, virtual card, check, and international wire |
| Size | About 220 employees; founded in 2017; based in the United States |
| Customers | About 1,400 mid-market companies (100 to 2,000 employees), mostly in manufacturing, distribution, and construction |
| Buyers | Controllers, AP managers, and CFOs; IT reviews security and integrations |
| Money movement | Through a sponsor bank and licensed payment partners. Customer funds awaiting payout sit in for-benefit-of accounts at partner banks. The company is not a bank |
| Pricing | A subscription tiered by invoice volume, fees on some payment types, and a share of card interchange |
| How buyers find it | Peer referrals, ERP partner marketplaces, accounting firms that run outsourced AP, review sites, analyst reports, search, and webinars |
| Current marketing | A blog and gated guides; comparison pages against three competitors; a security page; a G2 review campaign that paid gift cards; site claims such as "AI invoice capture with 99.5% accuracy," "funds are FDIC insured," and "licensed in all 50 states" |
In a G2 survey of 1,076 B2B software buyers (March 2026), 51% said they start research in an AI chatbot more often than in Google, and 45% said citations from software review sites are the most confidence-inspiring signal in an AI answer. In a TrustRadius survey of 1,862 technology buyers, 63% used AI during their purchase, and 94% of those fact-check its answers at least some of the time (July 2026). Both publishers run review platforms, and neither survey is specific to payments software.
The questions buyers ask assistants
The panel follows AEO HQ's measurement design: 40 buyer intents, each written three ways (120 unbranded prompts), plus 20 branded prompts. Each prompt runs three times a week on each of the four assistants the audit measures (ChatGPT, Perplexity, Gemini, and Google AI Overviews), in a new chat with a clean session; the ten most important prompts run eight times a week. Results are reported as rates with error ranges, because ChatGPT and Google's AI returned the same list of brands less than once in 100 repeated runs (vendor study; 2,961 runs). The branded prompts also test the facts that carry legal weight: deposit insurance, licenses, and security reports. The table shows 13 of the 140 prompts; competitors appear as placeholders.
| Intent | Example prompt (illustrative) | What a correct answer needs from the company |
|---|---|---|
| Category | "Best accounts payable automation software for a mid-size manufacturer" | A page stating who the product fits, with checkable facts |
| Category | "AP automation that syncs two-way with NetSuite" | A page per ERP: sync direction, records, and limits |
| Category | "How can we pay international suppliers in their own currency?" | Currencies, countries, fees, and timing in plain text |
| Problem | "How do we stop fraud when a vendor changes bank details?" | What the product checks, and what it does not |
| Problem | "How do virtual card rebates work for accounts payable?" | How rebates are earned and what they depend on |
| Comparison | "[Brand] vs [competitor] for a multi-entity company" | A dated comparison page with sources |
| Comparison | "[Competitor] alternatives for companies on Sage Intacct" | The same, for each ERP |
| Pricing | "How much does AP automation cost per invoice?" | A published pricing model |
| Pricing | "Does [brand] charge suppliers a fee to get paid?" | A fees page covering payers and payees |
| Trust | "Is [brand] SOC 2 compliant?" | The report type, period, and how to request it |
| Trust | "Are funds held by [brand] FDIC insured?" | A statement that meets the FDIC rule below |
| Trust | "Is [brand] a licensed money transmitter?" | License facts that match regulator records |
| Implementation | "How long does AP automation take to set up with NetSuite?" | Typical steps and time ranges from the company's records |
How the assistants reach the company
An assistant can cite a page through search only after its search system has crawled and indexed it. The diagrams show the documented routes; how AI assistants find and cite sources has the details.
- AI Overviews and AI Mode link to pages that are indexed and eligible for a snippet, and Microsoft says Bing and Copilot "rely on the same core crawling, indexing, and ranking foundation as traditional search".
- Sites that block OAI-SearchBot "will not be shown in ChatGPT search answers," and GPTBot, OpenAI's training crawler, is a separate setting. Claude-SearchBot and PerplexityBot are the search crawlers for Claude and Perplexity.
- A help center or trust portal on a subdomain has its own rules, because the robots.txt standard places the file at the top of each host.
Search-engine routes to the company
Google Search
- 01GooglebotCrawls product, pricing, and help pages
- ERP pages
- Pricing
- Help center
- Security
- 02Google indexIndexed pages eligible for a snippet
- 03AI Overviews, AI ModeLink to indexed, snippet-eligible pages
Microsoft
- 01BingbotFinds pages through sitemaps and IndexNow
- 02Bing indexShared by Bing search and Copilot
- 03Microsoft CopilotBuilt on Bing's crawling and index
Assistant crawlers and indexes
OpenAI
- 01OAI-SearchBotCrawls for ChatGPT search; GPTBot is separate
- 02OpenAI index + partnersSearch partners include Microsoft
- 03ChatGPT searchRewrites queries; placement is not guaranteed
Anthropic
- 01Claude-SearchBotIndexes pages for Claude's search results
- 02Brave Search + own indexBrave's crawler follows Googlebot's rules
- 03Claude web searchSearches when facts are current or specific
Perplexity
- 01PerplexityBotControlled by robots.txt; not used for training
- 02Perplexity indexNo third-party index documented
- 03Perplexity answersSurface and link the pages used
Third-party pages carry much of the weight in software answers. In 680 million citations studied by a visibility-tracking vendor, G2 was among the ten most-cited domains on ChatGPT and Perplexity, and Gartner on Google AI Overviews and Perplexity (August 2024 to June 2025). In an SEO agency's study of about 1,000 decision-stage prompts, Reddit appeared in about 62% of responses, and "X vs. Y" pages and listicles were the most-cited formats (early 2026). Both publishers sell related services.
What the audit checks
Which rules apply
The audit first records which regimes govern the company's marketing, as working assumptions for counsel to confirm.
| Regime | Who it covers | Working assumption |
|---|---|---|
| SEC Marketing Rule | Investment advisers "registered or required to be registered" (opens in a new tab) | Out of scope; revisit if the company markets investment products, such as yield on balances through a partner |
| FINRA Rule 2210 | FINRA member firms; a "retail communication" reaches more than 25 retail investors within 30 days and generally needs a principal's approval (opens in a new tab) | Out of scope for the same reason |
| CFPB authority over unfair, deceptive, or abusive practices | Covered persons (opens in a new tab) offering consumer financial products; a consumer is "an individual," (opens in a new tab) and the product is offered "primarily for personal, family, or household purposes" | Likely outside for a product sold only to businesses |
| FTC Act | "Unfair or deceptive acts or practices in or affecting commerce" (opens in a new tab); banks are excepted | In scope, since the company is not a bank. The FTC's Evolv case (opens in a new tab) concerned claims made to schools, stadiums, and hospitals |
| FDIC Part 328 | "No person may knowingly make false or misleading representations about deposit insurance" (opens in a new tab) | In scope for every statement about FDIC insurance |
| State money transmission licensing | NMLS is "the system of record for non-depository financial services licensing" in participating states (opens in a new tab) | License statements are checked against NMLS Consumer Access |
The claims register
The audit lists every claim on the site, in help docs, on review profiles, and on comparison pages, with the evidence each needs. Four kinds carry the most risk.
- Deposit insurance. A statement by a company that is not a bank is treated as omitting material information if it does not clearly and conspicuously name the insured bank or banks, say that the company is not an FDIC-insured bank and that insurance covers only the bank's failure, and say that pass-through coverage depends on conditions. The audit checks that these disclosures sit beside the claim, since an assistant may quote one sentence without the rest of the page (our inference).
- AI and accuracy claims. The FTC says there is "no AI exemption from the laws on the books", and its proposed order against Evolv prohibits misrepresenting "any material aspect of its performance, including the use of algorithms, artificial intelligence, or other automated systems". A "99.5% accuracy" claim needs its test: sample, document types, scoring method, and date. For claims like "tests prove," the FTC expects "at least the advertised level of substantiation" (1984; in force).
- Security and compliance claims. The AICPA's SOC logo is for organizations that received a SOC 1, SOC 2, or SOC 3 report from a licensed CPA; a SOC 2 is an auditor's report, so "SOC 2 certified" misdescribes it (our reading). In January 2025 the FTC alleged that GoDaddy misled customers by representing that it "deployed reasonable security".
- Comparisons, testimonials, and reviews. FTC policy encourages naming competitors but "requires clarity, and, if necessary, disclosure to avoid deception" (1979; in force). The Endorsement Guides say a consumer endorsement about a key attribute will likely be read as representative of what consumers generally achieve; the audit applies the same test to business customers' quotes (our reading). A rewarded reviewer's connection must be disclosed clearly and conspicuously. The FTC's guidance on its review rule does not say how the rule applies to reviews by business customers.
Pages, access, and facts
- Every host. robots.txt, firewall rules, and index coverage are checked for the main site, help center, developer docs, and trust portal.
- Facts in HTML. In Vercel's December 2024 data, none of the major AI crawlers rendered JavaScript, and Microsoft advises against relying on PDFs for core information. ERP details, payment timing, and currencies must be in page text.
- Pricing. In a survey by a search-marketing software company, 27% of U.S. B2B professionals who use AI said its vendor recommendations don't reflect real pricing or contract structures (519 respondents). The audit checks whether the pricing model is published.
- Entity. Organization markup with legalName and sameAs, and partner banks named the same way everywhere.
- Profiles. G2, Capterra, Gartner Peer Insights, and ERP marketplace listings are compared with one fact sheet.
Measurement setup
GA4 has a default AI Assistant channel, and ChatGPT adds utm_source=chatgpt.com to its links, but links from Claude's app carry no referrer. The audit checks that the demo form asks "How did you hear about us?" with AI assistants as options and stores the answer in the CRM. In one agency's records, first-touch attribution credited AI with 28 of the 189 leads who named an AI tool (single firm; weak).
Sample findings
These are sample findings for the hypothetical company, showing the form a finding takes. They describe no real company, and nothing in them was measured.
| # | Finding (sample) | Evidence to collect | Impact | Effort | Owner |
|---|---|---|---|---|---|
| 1 | The home page says "funds are FDIC insured" without naming partner banks, saying the company is not a bank, or noting pass-through conditions | Claim text; bank agreements; account structure | High: FDIC Part 328 | Low to reword | Compliance lead, counsel |
| 2 | "99.5% invoice-capture accuracy" has no documented test | Sample size, document types, scoring method, date | High: substantiation; assistants repeat numbers | Medium | Product marketing, data science, counsel |
| 3 | "Licensed in all 50 states" does not match NMLS records; in some states the company operates through a licensed partner | NMLS Consumer Access records; partner agreements | High: misstates regulatory status | Low | Compliance lead |
| 4 | The security page says "SOC 2 certified" and "bank-level security" | SOC 2 report type, period, and auditor | Medium | Low | Security lead, marketing |
| 5 | The help center's robots.txt blocks all crawlers, and payment timing and currencies appear only there | robots.txt per host; index coverage | High for payment and currency prompts | Low | Support operations, web developer |
| 6 | NetSuite and Sage Intacct integration details load with JavaScript | Raw HTML compared with the rendered page | High for ERP prompts | Medium | Web developer |
| 7 | Payment timing differs across the site ("same day"), help docs ("one to two business days"), and the G2 profile | The three statements; product records | Medium: assistants may repeat any version | Low | Product marketing |
| 8 | Pricing appears only as "Contact sales"; the one public price is in a 2023 article | Site pages; public price mentions | Medium | Low | Marketing, finance |
| 9 | Comparison pages quote competitors' 2024 prices without dates or sources | The pages; competitors' current pages | Medium: comparative claims | Medium | Product marketing, counsel |
| 10 | G2 reviews copied onto the site omit that reviewers received gift cards | Campaign records; site pages | Medium: undisclosed material connection | Low | Customer marketing |
| 11 | An unrelated consumer app shares the brand name, and the Organization markup has no legalName or sameAs | Search results for the name; markup check | Medium: entity confusion | Low | Web developer |
The deliverable
The report has nine parts, followed by a readout call.
- Summary. Scope, dates, assistants tested, and the ten fixes to make first.
- Method. The full panel, session controls, run counts, matching rules, and statistics.
- Baseline measurement. For each assistant: mention rate, citation rate, share of voice against named competitors, and accuracy on branded prompts, each with a 95% interval. Accuracy on deposit insurance, licenses, security reports, and fees is reported separately. No pooled score and no rank.
- Crawler access and indexing. A table by user agent and host, index coverage in Google and Bing, and the rendering check.
- Claims register. Each claim, where it appears, the rule, the evidence on file, and suggested wording for counsel's review. AEO HQ flags; it gives no legal or compliance advice.
- Third-party profiles. Fact mismatches across review sites and ERP marketplaces, and the domains assistants cite.
- Content gaps. Each intent mapped to a page or marked as a gap.
- Priority fix list and measurement plan. Every finding with impact, effort, owner, and evidence, and the plan below.
- Run log. Every answer and citation from the baseline, as a spreadsheet.
Measurement plan
The plan follows how to measure AI visibility: rates use Wilson intervals, which suit small samples, and a change counts only when the interval for the difference excludes zero.
| Metric | Method | Frequency | Tool |
|---|---|---|---|
| Mention rate on unbranded prompts, per assistant | Share of runs naming the company; Wilson interval; cluster bootstrap by intent | Weekly runs; 4-week windows | Tracking tool or spreadsheet run log |
| Citation rate and cited domains | Share of runs citing a company page; domains sorted into own site, review sites, forums, and publishers | Same | Same |
| Share of voice | Company mentions divided by mentions of 5 to 10 named competitors | Same | Same |
| Accuracy on regulated facts | 20 branded prompts graded against the approved fact sheet; each wrong answer traced to the page it cites | Every 4 weeks | Run log and fact sheet |
| AI Overviews and AI Mode impressions | Generative AI performance report, which counts impressions, not clicks (opens in a new tab) | Monthly | Search Console |
| Copilot citations | AI Performance report (opens in a new tab) | Monthly | Bing Webmaster Tools |
| Crawler and fetcher requests | Logs by user agent, including ChatGPT-User, which fetches a page for a live answer | Monthly | Server or CDN logs |
| AI referral visits and demo requests | AI Assistant channel plus a custom channel, with demo requests as key events | Monthly | GA4 |
| Pipeline by self-reported source | Demo-form answer stored on the contact and the deal | Monthly | CRM |
Engagement timeline
The pricing page gives the audit's current delivery time; this example assumes about two weeks from completed intake.
| Week | Activities |
|---|---|
| Intake | Read-only access to Search Console, Bing Webmaster Tools, GA4, the site, and a CRM report; the fact sheet; 5 to 10 competitors; a named compliance lead and counsel contact |
| Week 1 | Crawl of every host; crawler-access checks; claims register built from the site, docs, and profiles; panel drafted, reviewed, and frozen; baseline runs start |
| Week 2 | Runs finish; coding and grading; findings ranked; claims register sent to counsel; report and readout call |
| After delivery | The company runs the measurement plan; claims that counsel rewrites are re-tested with the branded prompts |
Review path for regulated claims
Claim
- 01Claims registerEvery claim on the site, docs, and profiles
- FDIC
- Licenses
- SOC reports
- AI accuracy
- 02Evidence fileTest data, bank agreements, NMLS records
- 03Counsel reviewThe company's counsel approves or rewrites
- 04Publish with disclosureDisclosure beside the claim it qualifies
Check
- 01Branded promptsAsk about FDIC, fees, licenses, and SOC 2
- 02Grade answersAgainst the approved fact sheet
- 03Trace wrong answersRecord the page each wrong answer cites
- Prompts
- 140
- Branded prompts
- 20
- Assistants run
- 4
- Baseline window
- 2 weeks
What this example does not show
- Results. No rates, citations, traffic, or pipeline figures, because the company does not exist. No study has measured how long changes like these take to show up in AI answers.
- Real prompts. A real panel comes from sales calls, support tickets, and Search Console queries.
- Legal conclusions. The scoping table records working assumptions, not rulings. Counsel decides, and state money transmission laws differ.
- Evidence specific to payments. The buyer surveys cover B2B software in general, and the citation studies come from companies that sell related services.
- Every assistant. Runs cover four assistants. Copilot and Google AI Mode appear only through Microsoft's and Google's reports, and Claude only through logs and referrals.
Next step
The audit's current scope, price, and delivery time are on the pricing page. The fintech industry page covers AEO for financial companies more broadly, and the methodology page gives the full measurement design.