Buy-vs-build isn't a gut call or a cost spreadsheet. It's the same four questions every time. The interesting part: run two honest decisions through the same rubric and they can come out opposite. That's the rubric working, not failing.
The rubric
Four questions, every time
01
Differentiator or infrastructure?
Will customers ever choose us because of this? Or is it table stakes everyone needs and no one rewards?
02
What's the true cost of ownership?
Not the build, the forever: maintenance, the roadmap tax, the eng time quietly spent keeping it alive.
03
How much regulatory surface?
Every line we own in a regulated path is a line we have to defend, audit and keep compliant as rules change.
04
How fast do I need to be right?
If speed-to-correct matters more than control, that pulls toward partnering. If the learning is the point, build.
Same rubric, opposite answers
Verification (KYB/KYC)The PLG demo
โ Build in-houseBuy / partner โ
Differentiation
Cost of ownership
Regulatory surface
Speed to be right
Verification scores toward buy on every axis; the demo scores toward build. The dots cluster on opposite sides, which is exactly why both calls were right.
Worked example ยท 1
Verdict ยท BuyKYB verification
Our KYB checks ran through a home-grown backoffice that couldn't scale: slow processing, manual workarounds, analyst errors, and a compliance treadmill every time regulation moved. Running it through the rubric:
1
Differentiator or infrastructure? โ Infrastructure.
No customer ever chose us for prettier sanctions screening. Identification, PEP checks, registry data, UBO verification: table stakes every competitor needs and no buyer rewards.
2
True cost of ownership? โ Brutal, and forever.
Not the build, the maintenance: registry integrations per market, data sources that change, checks that must track every regulatory update. Our backoffice was already showing the bill: workarounds, error rates, engineering time bleeding away from the roadmap.
3
Regulatory surface? โ Maximal.
Every line of owned verification code is a line we must defend to a regulator as rules evolve. Vendors carry that update burden across jurisdictions as their core business; we'd carry it as a distraction.
4
Speed to be right? โ Vendor-fast.
New markets couldn't wait quarters for hand-built checks. Pre-built automations meant new checks became configuration, not engineering projects.
All four questions pointed the same way: buy. But the rubric also drew the line precisely: the case management, how our analysts work and how our risk logic evolves, scored as differentiation, so that we built. Roughly 75% bought automations, one custom workbench. The nuance is the point: the rubric works per-capability, not per-vendor-contract. Full case โ
Worked example ยท 2
Verdict ยท BuildThe PLG demo platform
Same rubric, opposite reality. We already had a bought solution, a guided-tour vendor, and it was failing in live deals. Running the questions:
1
Differentiator or infrastructure? โ The differentiator itself.
In a product-led motion, the demo is the pitch. Prospects deciding whether to buy the product were judging us on a vendor's click-through of screenshots of a product that no longer existed. Demo drift wasn't a tooling annoyance; it was misrepresentation risk.
2
True cost of ownership? โ Lower than it looked.
The real cost driver isn't building the demo. It's keeping demo data current as the product ships. That only works wired into our own development process (demo data as part of Definition of Done). No vendor can own our release cycle; the maintenance cost of buying was actually higher.
3
Regulatory surface? โ Light.
Mock data, no real money movement, guarded flows. The compliance argument for buying simply didn't apply here.
4
Speed to be right? โ Building was the only path to right.
The vendor was faster to something, but its architecture is built for curated walkthroughs and can't do real-app exploration at all. And AI-assisted development collapsed the build premium: ground-up to launched v1 in two months.
Verification failed the differentiation test, so we bought it. The demo was the differentiation, so we built it as the real product, guarded and seeded, so it can never drift from reality. Full case โ
"Buy the infrastructure. Build the thing that only you can."