PaymentsJournal

PaymentsJournal

Payments Content, Expert Insights and Timely News

  1. 4d ago

    Ownership Authentication: Fighting Fraud Losses and First-Party Risk

    Fraudsters no longer need to reinvent their tactics from scratch. With artificial intelligence and increasingly sophisticated access to consumer data, they can test new approaches quickly, learn what works, and adapt before financial institutions have time to catch up. That speed is forcing banks and other financial institutions to rethink how they authenticate customers. One approach gaining traction is ownership authentication, a process that looks beyond whether an application’s information matches a particular account. During a PaymentsJournal Podcast, John Gordon, CEO of ValidiFi, and Suzanne Sando, Lead Analyst of Fraud Management at Javelin Strategy & Research, explored how this approach can help financial institutions connect seemingly minor signals, identify emerging risks, and stay ahead of the adaptive fraud schemes. A New Generation of Fraud Artificial intelligence has made it possible for criminals to create new schemes and fraudulent identities in a matter of minutes. AI has fueled the rise of several types of scams, including account takeovers and bank impersonation. Some fraudsters use AI to submit account applications across multiple institutions, while others use it to gather information about existing customers, allowing them to mimic typical behavior and evade detection. One way financial institutions are responding to those evolving threats is through ownership authentication. Rather than focusing solely on a new account or one that appears to be involved in fraud, this approach seeks to understand the consumer across their broader financial relationships. It incorporates factors such as ownership, payment history, account stability, and behavioral changes that can reveal emerging risk. Verified accounts generally outperform better than the broader population in terms of fraud outcomes, but those results can improve further when institutions add an additional layer of authentication. Simply verifying that account details match the person opening the account is no longer enough. “Just because an account is open and valid and it belongs to a particular consumer, there are still aspects that drive different decisions for the financial services provider based on fraud and risk connotations,” said Gordon. “If an account is open, valid and belongs to the applicant, if that applicant has an email address that’s less than 30 days old, the increase in risk is skyrocketing.” Taking the Holistic View It’s no longer enough to examine a single aspect of a consumer’s identity or behavior. Matching personally identifiable information (PII) to an account at a single point in time doesn’t provide a complete picture. Financial institutions increasingly need to take a holistic view of the consumer and assess whether the information provided remains consistent over time. “Taken individually, you may miss the signals of a brand new email address or phone number—all these things that maybe don’t seem that that risky on the surface,” said Sando. “When you put them all together, it becomes a serious risk factor for this particular consumer. Fraudsters are bypassing a lot of checks that they normally wouldn’t have in the past because they have AI enabling them.” Fraudsters, for example, may begin an account takeover with seemingly innocuous changes, such as updating a marital status or utility information. On their own, these changes may not raise an alarm. Over time, however, those changes can be combined with a new credit card, a new debit card, and a utility bill to make the activity appear legitimate. Individually, each signal may seem insignificant. Together, they can reveal a much stronger pattern of potential fraud—one that can be missed when institutions examine each signal in isolation. Facing Up to First-Party Fraud Ownership authentication can also play a role in addressing fraud associated with buy now, pay later plans. As these options have become a prominent part of the consumer economy, they have made it easier for people to spread payments over time for purchases they may not be able to afford upfront. For some consumers, even extended payment schedules can become difficult to manage. And as a result, first-party fraud may become a more deliberate strategy for consumers who are unable or unwilling to repay what they owe. “All of those consumers are providing bank account and routing numbers at application, and we have the ability to access all of that data,” said Gordon. “When you look at that information together, you can see the status of the most recent transactions tied to those accounts. Is there a history of stop payments, frozen accounts, or other first-party fraud indicators? By evaluating those factors collectively, you give yourself much greater protection.” “For those of us a certain age, that brings back a lot of connotations from 2008 where the consumer pressures were increasing and increasing,” he said. “And as a result, saying they felt like their best option was bankruptcy.” Convenience as a Risk Consumers often care less about who provides a financial service than whether the experience is convenient. But that emphasis on convenience can create risk, particularly when providers are reluctant to introduce anything that could add friction to a transaction. As research has shown, many consumers will abandon a payment process when they encounter unwanted friction. But merchants and payment processors are increasingly learning that friction doesn’t have to be all-or-nothing. It can be targeted and managed based on the level of risk. For example, if an applicant attempts to open a bank account using information associated with more than four Social Security numbers, that should trigger additional scrutiny. Similarly, if an applicant uses a relatively new or undeliverable email address, the institution may require a higher level of authentication. Consumers may be frustrated by these additional steps, but they are also becoming aware that friction is sometimes necessary to protect their accounts and financial information. The challenge is finding the right balance between a seamless experience and appropriate security. “We’re actually finding now that 50% of consumers are prioritizing the security of their PII that they’ve entered into that application,” said Sando. “If they don’t find that to be secure, they’re going to drop out of that process and you’re going to have abandonment issues.” Key Takeaways Ownership authentication falls under the broader category of “smarter friction.” It means understanding the customer experience, centering the end user, and providing safeguards that consumers can understand and recognize as necessary. Most importantly, it recognizes that every account applicant is different. “There is no one-size-fits-all,” said Gordon. “You’ve got to have the ability to tailor solutions to the application. How well-known is that consumer to you? That should drive a lot of the defense that you stand up.” “You validate what’s happening on that end. You marry that with the risk that you could potentially be facing. And that’s where you get that smarter friction.” Read ValidiFI’s latest intelligence report

  2. Sep 24

    Physical Cards Reimagined—More Than a Payment Tool

    The payment card was supposed to disappear. As digital wallets, embedded payments, and mobile-first experiences reshaped commerce, the physical card seemed destined to follow the path of other outdated tools. Instead, it has found a new role—not just as a simple way to pay, but as a platform of identity, access, rewards, and deeper customer engagement.  According to the Federal Reserve’s 2025 Diary of Consumer Payment Choice, credit cards accounted for 35% of U.S. consumer transactions in 2024, with debit cards adding another 30%—making cards, combined, the dominant way Americans pay. That dominance holds even as mobile wallets grow, since most mobile payments are still funded by an underlying credit or debit card rather than replacing one. Their staying power comes from their ability to deliver experiences that extend well beyond the transaction itself. In a PaymentsJournal podcast, Michael Hughes, General Manager of Arculus by CompoSecure, and James Wester, Co-Head of Payments at Javelin Strategy & Research, explored why the physical card remains relevant and how innovative brands are transforming it into a powerful tool for building loyalty, creating new consumer touchpoints, and strengthening relationships between issuers and the people they serve. Consumers Still Value the Physical Card Predictions that digital wallets and virtual payment methods would make physical cards obsolete have not materialized. Much like the continued appeal of tangible products in an increasingly digital world, consumers still value the physical experience of a payment card—particularly as cards have evolved into more premium formats, such as metal designs and customized offerings.  When consumers hold metal cards and drop them on the table, Hughes said, they like the sound and the way they feel, along with a real sense of pride the cards carry. That lines up with consumer research: a global study from Capuchin Behavioural Science found that 72% of consumers would use their payment card more often if it were made of metal instead of plastic. However, the future of the physical card depends on its ability to deliver more than payment functionality. The greatest risk isn’t digital replacement, but becoming a commodity that serves only a single purpose. To remain relevant, cards must continue evolving in ways that create value for both consumers and issuers. Today, cards are already expanding into new roles, including venue access, authentication, loyalty, and rewards. This is creating an opportunity for the card to become a central point of engagement that helps brands build stronger and more meaningful connections with customers. Hughes sees an opportunity to redefine what a payment card can be. “Every issuer wants its card to be top of wallet,” he said. “Traditionally, that just meant being the card a customer reaches for at checkout. Hughes describes a much broader version of top of wallet: issuers can drive additional engagement through the card issuer’s app, prompting cardholders to tap their card to earn rewards, verify their identity, or otherwise interact with the brand. That’s a level of engagement traditional payment cards were never built to deliver. Building Engagement Through Data Advances in data collection and analytics have allowed issuers and brands to better understand customer behavior and create more personalized experiences. A co-branded card with a team such as the New York Yankees, for example, can reveal more than spending patterns—it can provide insight into fan interactions, including visits to Yankee Stadium and other brand touchpoints. “Banks have traditionally issued credit cards to earn fees”, Hughes said. “But viewed from another angle, a card can become an engagement tool—combining programs an issuer would already be offering, like loyalty, rewards, or event access, into a single experience. That shifts the value from simply earning points and interchange fees on payments to delivering customer engagement and the revenue that engagement generates.” Wester added: “We tend to think of use cases in terms of financial or quasi-financial transactions, whether it’s rewards or points or tokens. But ultimately it’s about identifying that person and saying, OK, you are who we want to be interacting with. And now you can take the data from that interaction later and say, we’re going to do things with that.” Authentication Without Added Friction As authentication increasingly moves into software-based solutions, consumers are often required to leave a transaction, retrieve a verification code, and return to complete the purchase. While these processes provide security, they interrupt the user experience and create opportunities for frustration or cart abandonment. “If I can take my branded card and allow [the customer] to validate who they are just by tapping [the card] to the phone, the engagement remains constant,” said Hughes. Physical cards offer another avenue for simplifying authentication while maintaining security. Reducing friction can improve both customer engagement and protection, as overly complicated security processes may discourage users from completing necessary steps to safeguard their accounts. “The weakest link in security is always the person,” Wester said. “The less friction in the process, the better it is for consumers.” Expanding the Role of the Card Because payment cards have been part of consumers’ financial routines for decades, issuers often overlook their potential as a broader engagement tool. A multifunction card can support dozens of new use cases, from loyalty and access to authentication and personalized experiences. Hughes advises picking the two or three use cases specific to whatever customer segment an issuer is targeting, and nailing them. That’s an area he believes Arculus is especially good at helping organizations diagnose—it’s not just about the concept, but about designing the application so it’s simple and easy to engage with, not confusing. Issuers only get a couple of chances before a frustrated customer decides they’re done. The key to unlocking the card’s full potential is creating functionality that improves the user experience while driving greater usage. As engagement grows, the resulting data can help issuers and brands continue refining experiences and building stronger relationships with customers. Hughes’s takeaway for issuers is to align incentives and metrics across product, finance, and merchant teams, then ask a simple question: what value can this card bring customers, and how will you measure it? That discipline, he said, is what separates programs built for the short-term versus the ones that last.  Physical cards were never at risk of disappearing, only of becoming irrelevant. The ones that evolve from solely a payment instrument to an active engagement platform are the ones with a strong future.

  3. Sep 23

    Delegation with Limits: What Merchants Want from Agentic Commerce

    There is a growing disparity between hype and reality when it comes to agentic commerce. This is not so much a critique of AI agents’ capabilities, or the infrastructure that has rapidly emerged to support them, as it is an indication that this model is still in its early stages. Many merchants still associate the term “agent” with independent sales organization (ISO) reseller agents, rather than artificial intelligence. In a recent PaymentsJournal podcast, Hilla Peled, SVP of AI & Data Science at Nuvei, and Don Apgar, Director of Merchant Payments at Javelin Strategy & Research, discussed agentic commerce from the merchant perspective, where the primary concern is how businesses can earn customer trust as this emerging model evolves. Although questions remain around the model, that does not mean the progression toward agentic commerce is slowing. On the contrary, now is the time for merchants and providers to develop strategies and prepare for widespread AI agent interactions. Preparing for the Agentic Revolution Despite the apprehension surrounding agentic commerce, there is little debate that AI now plays a significant role in consumers’ lives. It has become a go-to resource for a wide range of tasks, and commerce is no exception. Shoppers are already using AI to compare prices and discover products, and autonomous agentic personal shoppers represent a natural extension of this trend. Most merchants are eager to support this shift, but not if it requires compromising funds or expanding PCI scope. “Merchants aren’t saying, ‘give me a shopping agent,’ but they want to be prepared to the extent that their customers show up with shopping agents,” Apgar said. “Largely, they’re trying to figure out what this means, which standard will prevail, and how they should look at their architecture and their position in agentic commerce.” Many businesses are closely examining how the technical details will be resolved, including how transactions will settle and which standards will govern interactions. One of the most important questions is agent ownership, whether an agent is acting on behalf of the consumer, the merchant, or the AI company that developed it. Establishing this responsibility will influence how all parties approach agentic payments. The ultimate objective is to create trust in the process by ensuring that an agent reliably executes its assigned tasks and delivers an outcome that meets customer expectations. This is no small feat, given the range of fraud and security concerns, including the potential for bad actors to manipulate agents, consumers, or merchants for malicious purposes. The answers to many of these questions remain unclear, meaning the space will likely experience uncertainty and adjustment as it matures. “One of the biggest things that we observe is the gap between what customers are doing when adopting the public agents versus what the PSPs and acquirers are willing to take on,” Peled said. “Everyone is now just preparing themselves to the point where agentic commerce will become much wider.” “We know that 1.5% of purchases in the U.S. have been agentic, which is huge when you think of the current state of agentic commerce,” she said. “At the same time, both customers and merchants and any business across e-commerce today is wondering, ‘What is the next thing they need to do in order to be ready when agentic commerce will explode?’” Volume Follows Trust To better understand the current state of agentic commerce, Nuvei conducted a study examining consumer attitudes and behaviors. The study found that only around 1% of respondents wanted fully automated AI purchasing, while 56% said they would never allow an AI platform to spend without their approval, regardless of the amount. While these findings may appear to challenge the future of agentic commerce, previous technology shifts have demonstrated that consumer preferences can evolve rapidly. “If you remember in 1995, almost nobody wanted to put a card number online, but we know where we are at today” Peled said. “The demand isn’t for autonomy, it’s for the trust trails that make delegation safe. In payments, volume has always followed trust and the infrastructure decisions are being made now, years ahead of the volume.” There are clear parallels between the growth of e-commerce three decades ago and the emergence of agentic commerce today. Along with initial concerns about security and fraud, many believed certain products could never be successfully sold online. For example, some experts argued that online clothing and footwear sales would struggle because consumers preferred trying items on before making a purchase. Agentic commerce may encounter and overcome similar barriers, but potentially at a much faster pace. “Javelin research picked out a few categories—including travel, B2B and commodity purchases—that we think will be the first to earn shoppers’ trust using an agent, but it’s not going to take 30 years like it did for e-commerce to evolve,” Apgar said. “The tech is moving so much faster that it will reach a maturity point and a tipping point for agentic commerce much sooner than it took e-commerce.” A Fundamental Shift in Commerce The accelerated pace of innovation and adoption has already been demonstrated by generative AI. “The AI space has been around for 17 years and the pace that AI has evolved in the last 12 to 18 months is just unprecedented,” Peled said. “There was always evolution, but what we see now with the capabilities and with the actual adoption shows that the hype about agentic commerce is not just hype. People are adopting agents because they understand their power and agents are becoming stronger and more capable very quickly.” This means organizations should prepare for change sooner rather than later, especially businesses serving younger or more tech-savvy customers. However, merchants should recognize that agentic commerce is not simply a gateway to new markets. Instead, it represents a fundamental shift in how commerce operates. “The reality is that this is existing purchase volume. AI doesn’t magically give people more money to spend,” Apgar said. “These are existing purchases that are going to go from whatever channel they’re being made in today—whether it’s retail, e-commerce, or mobile—and be converted to agentic.” “Where is the early impact of that going to be? Which merchants will be impacted the most? Early adopters have the ability to pick up market share from lagging competitors,” he added. A Trust Problem, not an AI Problem The potential for early adoption is why many merchants are closely monitoring the evolution of agentic commerce and attempting to identify the point at which it reaches mainstream adoption. “They understand that at some point, others will eat their lunch if they’re not adopting early,” Peled said. For merchants determining how to move forward, there are practical steps they can take. The first is to audit existing infrastructure and assess whether it can support orchestration without custody. Next, merchants should build first-party capabilities so they are not forced to reintegrate solutions later. Retailers should also stay dialed into market developments and regularly reevaluate their roadmaps. Given the pace of change, this process should occur every few months rather than every 12 to 18 months. This will help ensure that merchants’ technology stacks are prepared as agentic commerce becomes more widespread. To stay ahead of the curve, Nuvei recently completed a live agentic commerce proof of concept. In collaboration with Visa, Arvato Systems, and fashion brand Kings and Priests, the initiative demonstrated an agentic transaction executed through a unified workflow, all within shopper-defined parameters like spending limits and approved categories. “We launched a live Visa transaction where an AI agent purchased, paid inside the merchant’s own experience and cleared across multiple European issuers,” Peled said. “The hard part was never teaching an agent to buy; that’s what agents know how to do. It was giving issuers and schemes across markets a reason to approve a purchase that no human initiated. That is a trust problem, not an AI problem.”

  4. Sep 22

    From Data to Action: How Automated Intelligence Is Changing Collections

    Most businesses have no shortage of customer data. They know who their customers are, how they pay, when they tend to pay and, in many cases, exactly when a payment goes wrong. The harder question is what to do with all that information—particularly when a customer falls behind. That makes collections less of a data problem than an action problem. Automated intelligence can bridge that gap, using customer information to determine what should happen next and creating a more effective, individualized approach to collecting payments. In a PaymentsJournal Podcast, Robyn Burkinshaw, CEO and Founder of Blytz, and Christopher Miller, Lead Analyst of Emerging Payments at Javelin Strategy & Research, discussed how incorporating AI into actionable reminders can enhance the payment experience for customers and businesses alike. Moving Up from Basic Automation In payment collections, basic automation typically follows a fixed set of rules: send a reminder on a certain day, make a call when an account becomes past due or retry a payment at a predetermined time. Automated intelligence takes a different approach. Rather than simply following a schedule, it looks at what is happening with the customer and uses the data a business already has to determine the next best action. That could mean choosing the right message, channel, timing, tone, or payment option for a particular customer or account. Instead of leaving customer data sitting in a database, automated intelligence turns that information into an active workflow. The result is a more differentiated experience. Higher-risk accounts can receive a more thoughtful, targeted path to payment, while lower-risk customers can move through a faster, more streamlined self-service experience.  In both cases, the approach better reflects what the individual customer actually needs “It’s different when you’re talking to a customer who’s a day late than when you’re talking to a customer who hasn’t responded in three months,” said Burkinshaw. “Intelligence is going to pick up on those nuances to make the experience better for the customer, and thus make the experience better for the merchant.” Differentiating Customer Experiences Consider a customer with variable income. Another generic past-due reminder may not help them make a payment. What they may need instead is flexibility: the ability to pay part today and the rest later, use a different card, pay by ACH, or set a Promise to Pay without having to call during business hours.  “The notion of differentiated and customized experience is commonplace at the high end of the market,” said Miller. “It is what financial services companies talk about all the time in terms of surfacing offers for well-qualified consumers, or analyzing their transactions to see what next thing might be useful to sell them. The same set of technical capabilities should be applied to this particular use case in a way that drives not just incremental gains, but substantial gains in productivity.” The idea behind the 90/10 rule is that roughly 90% of customers will do what the business wants them to do—make their payments regularly and on time. The remaining 10% are more likely to require additional attention. Automated intelligence can help businesses keep the 90% moving through a streamlined process while focusing resources on the 10% who need more support. Just as importantly, it can help identify which accounts actually require that attention. A customer who pays late every Friday but has never missed a payment should be approached differently from someone who has ignored every outreach attempt for three months. Those distinctions are easy to overlook when every account follows the same rules. Automated intelligence can identify those patterns and use them to shape the next best action. “That’s the shift,” said Burkinshaw. “The future isn’t more reminders, it’s more relevant reminders, and it’s the ability to take immediate action from that reminder.” Preventing Payments from Becoming Collection Events A declined payment should not automatically become a collections event. The customer’s card may have expired. Their payday may have shifted. They may simply need to pay part of the balance today and the rest on Friday. Automated intelligence can help identify what is behind a failed payment and offer the most immediate, realistic path forward. Instead of treating every payment failure as delinquency, it can help businesses distinguish between a temporary obstacle and an account that genuinely requires collections intervention. “We don’t just throw it over the wall and expect our collectors to dial for dollars,” said Burkinshaw. “We’re giving them prescriptive data that makes them more able to make surgical decisions about the problem that needs resolving.” That changes the experience on both sides. For the payer, the experience becomes less punitive and more focused on finding a workable solution. For the business, it can mean better use of collector time and resources, with human attention focused on the accounts where it can make the biggest difference. “We continue to see use cases where people are sent to the principal’s office,” said Miller. “Nobody thinks that we should have a padded chair where you wait in the hall outside—it’s a wooden bench. It’s uncomfortable. But that’s not how you actually resolve the issue in a way that’s favorable to all the participants.” Key Takeaways Traditional automation gives every account essentially the same set of marching orders, regardless of the circumstances. Automated intelligence goes a step further, using the information already available to determine what action makes the most sense for each situation. That makes AI less of an abstract concept and more of a practical tool. Its value doesn’t necessarily come from putting AI front and center. In fact, some of its most useful applications may be the ones customers barely notice. “Over the next five years, AI is going to disappear,” said Miller. “You won’t even know when you’re using it.” As AI becomes increasingly embedded in the business environment, automated intelligence offers a practical way to put it to work. Artificial intelligence may operate behind the scenes, but it can make the automation itself more responsive, helping businesses determine when, how, and where to engage customers in order to collect payments as efficiently and effectively as possible. “The next chapter of payments isn’t about offering more ways to pay,” said Burkinshaw. “It is about knowing which option matters the most in the moment. What we’re building around automated intelligence gives merchants the ability to truly meet customers with the right message at the right time, with the right payment path, before friction becomes failure.” “Let’s not automate failure,” she said. “Let’s automate success. Give customers the ability to succeed before we punish them for failure. This is the future of payments. Be in front of it. Don’t be behind it.”

  5. Sep 17

    Why Fraudsters Look Trustworthy and Good Customers Look Suspicious

    Criminals are increasingly aware of the signals banks use to identify “good customers”—and they are using that knowledge to evade detection. At the same time, legitimate customers are adopting behaviors that were once considered tried-and-true risk signals. Data breaches and privacy concerns, for example, have spurred many consumers to use VPNs, a behavior that was once viewed as a reliable fraud red flag. The result is a growing inversion of traditional fraud signals: legitimate customers can look suspicious, while sophisticated criminals can appear trustworthy. In a recent PaymentsJournal podcast, Diarmuid Thoma, Head of Fraud and Data Strategy at AtData, Jose Pallares, Senior Director of Product Management at Experian, and Jennifer Pitt, Senior Fraud Management Analyst at Javelin Strategy & Research, discussed the convergence of these patterns and how they are reshaping the fraud landscape. This ambiguity has created an environment in which bad actors are thriving and consumers are losing confidence in financial institutions. To combat this threat, financial institutions must adopt methods that are both broader and more granular to accurately identify fraud. The Rise of Manufactured Trust Technology has accelerated this shift, but the underlying challenge is familiar. Whenever fraud systems learn to identify certain behaviors, criminals adapt to avoid them. “Back when I was doing fraud review 20 years ago, if somebody was on a mobile device or a mobile number, that was slightly riskier because landlines were safer statistically,” Thoma said. “Whereas now if you gave a landline, that’s kind of a weird thing. There’s a natural part to that, and people have to keep that in mind, there are these shifts and profiles evolve.” In the past, the prevailing fraud prevention philosophy was to build models capable of detecting abnormalities and inconsistencies. However, criminals are all too aware of this strategy, and it has instead become a blueprint for avoiding detection. Artificial intelligence has also allowed bad actors to deploy these tactics at scale. With a few prompts, even technologically unsophisticated criminals can generate multiple synthetic profiles and manage them at scale. They are also becoming more patient and strategic in how they carry out illicit activities. “Once they had an account, they used to run up the account quickly, do a bust-out, and then run away,” Pitt said. “They don’t do that as much anymore. What they do is they make the account look legitimate over time. To skirt the detection on the forefront, they’re building up that identity with non-financial accounts. They might open up an email account, and once that identity becomes legitimized and verified at one organization, other organizations see it as more legitimate. It’s building that credit profile.” These capabilities have allowed bad actors to manufacture trust at a time when it is more difficult than ever to discern an individual’s intentions. This is partly because consumers have also rapidly adopted technologies like AI and social media, especially among younger and more digitally native generations. “The behavior profile of a good consumer is completely different than it was even five years ago,” Pallares said. “Fraudsters now think or look like good consumers, and consumers—from a fraud systems angle—look completely messy and risky. So how do we level up our existing fraud systems to catch and look at those things differently?” The Compounding Effects of Misclassification Beyond potential fraud losses, gaps in fraud infrastructure often cause legitimate customer activity to be misclassified as fraudulent. As a result, the customer experience suffers. These errors often occur at a time when organizations’ relationships with customers are most tenuous. “There are a lot who from early account set up are coming in and they’re spending a lot,” Thoma said. “They’re doing exactly what you’d be worried about from a commercial point of view, somebody comes in and spends a lot very fast and that’s concerning.” This exemplifies one of the main drivers of false positives: verification often hinges on a single transaction, point in time, or identity element. This short-sighted view can create significant issues for all customers, particularly high-value users. Their behaviors may raise numerous flags, as they may travel frequently, use multiple devices, and leverage a variety of payment methods. “I’ve seen from a bank perspective that good customers were off-boarded because there were signals that they thought were fraud, and it was essentially a false positive where identity elements were flagged as fraud that really weren’t,” Pitt said. “And I’ve seen bad customers get on-boarded because of the same thing. Basically, the decision was wrong, and I’ve seen that a lot.” Left unaddressed, these issues can lead to friction, abandonment, and reduced lifetime value, creating a compounding effect on operations and, ultimately, revenue. This revenue drain can go unnoticed by financial institutions. While many institutions have processes in place to measure fraud, there is often no ready gauge for fraud misclassification. “I think it’s probably a lot bigger than what we think because we just can’t measure it with any degree of accuracy,” Pallares said. “To compound the problem, there are fraud models that are being fed data, and these edge cases that result in false positives don’t make it into the fraud models for behavior. What you’re being measured on doesn’t allow for these edge cases to reduce the risk on those types of consumers.” Trust Is Not Binary The answer is not to abandon fraud signals, but to put them in context. A single transaction, device, or identity element can raise a question, but it shouldn’t determine whether a customer is trustworthy. Financial institutions should take a longitudinal approach to fraud identification, looking at how a customer’s behavior develops over time. Consistent identity markers, such as a longtime email address, established device, or history of legitimate activity can provide valuable context that an isolated anomaly can’t. This also requires fraud models that can adapt as consumer behavior changes. A behavior that once indicated risk may become commonplace, while new patterns may emerge as technology and consumer habits evolve. “Trust is not binary, it’s built,” Pallares said. “You have to look across your different consumer touchpoints and what a consumer is doing, instead of saying, ‘I verify them at account opening, go wild.’ And trust can be revoked. Anytime something looks out of the ordinary and it’s not verified, there’s certain lightweight controls that people can put in place to make sure that once-verified is not always-verified.” That broader view can’t always be found with a single institution. Fraud, payments, and customers experience teams need to share data and intelligence so that decisions are based on a more complete understanding of the customer. Extending that approach across institutions can provide an even stronger defense, particularly as fraudsters move between organizations and manufacture identities across multiple accounts. “When we talk about siloes, it’s within organizations, but it’s also across organizations and across different industries that we need to be sharing,” Pitt said. “Have they been flagged before at another organization? Wouldn’t that help your organization to know if it’s been flagged before, because you wouldn’t onboard that identity? Right now, the exact same synthetic might be used at 100 different banks because fraudsters know that banks aren’t talking.” The challenge is determining which signals represent legitimate complexity and which indicate coordinated fraud. A consumer with little financial history may simple be new to the system, while someone who rapidly establishes connections across multiple organizations may warrant greater scrutiny. The goal, then, is not to find customers who look perfect on paper. It’s to identify customers whose identities and behaviors have been earned over time. Trust Has to Be Earned In a fraud environment where appearances can be manufactured, history becomes one of the most valuable indicators of trust. Financial institutions need the technology, data, and partners to uncover that history and distinguish between customers who look trustworthy and those whose identities and behaviors have earned that trust over time. “When you’re selecting them, it has to be an uncorruptible history because now AI can create history in certain fields,” Thoma said. “In your vendor selection, you look for stuff that can give you the history that is isolated from that, that cannot be replicated, that cannot be created within a week or two and generated. It’s earned history, and that’s really important.”

  6. Sep 16

    10 Years Running, Same Day ACH Continues to Break New Ground

    When Same Day ACH launched a decade ago, the primary use case was for exceptions—such as in emergency payroll transactions, time-sensitive bill payments, and other situations where traditional ACH settlement timelines were too restrictive. Those use cases remain relevant, but they represent only a fraction of how Same Day ACH is used today. As organizations have gained greater familiarity with the option and recognized the value of faster settlement, adoption has expanded dramatically. In a recent PaymentsJournal podcast, Devon Marsh, Managing Director of ACH Network Rules and Risk Management at Nacha, and Ben Danner, Senior Debit Analyst at Javelin Strategy & Research, discussed the evolution of Same Day ACH, the forces driving its growth, and the opportunities that could shape the next phase of faster payments. The broader lesson from the past decade is that payment speed is not simply a question of getting funds from one account to another as quickly as possible. For many transactions, the important consideration is finding the right balance among speed, predictability, risk management, and operational efficiency. Same Day ACH has emerged as an important part of that equation, providing faster settlement while preserving the reach and established processes of the ACH Network. A Microcosm of the ACH Network Same Day ACH began with transaction volumes in the millions. A decade later, it is used for nearly 1.5 billion transactions annually. In many respects, Same Day ACH has become a microcosm of the broader ACH Network. The average dollar value of a Same Day transaction is now nearly equivalent to the average value of transactions processed across the ACH Network overall. That convergence is significant: it suggests that Same Day ACH is no longer confined to a narrow set of specialized use cases, but it is increasingly being incorporated across the same range of payment activities served by traditional ACH. “In the decade since its launch, Same Day ACH has evolved from a credit-only transaction capped at $25,000 to a robust, mature fast rail transacting both debits and credits up to $1 million,” Marsh said. “Now, after the early introduction of debit transactions and after two increases to the per-transaction limit—with another slated for September of 2027—Same Day ACH serves every use case in the ACH Network except for international transactions.” The growth is equally striking from a dollar value perspective. Same Day ACH moved roughly $20 billion in its first year, compared with approximately $4 trillion in 2025, with the ACH Network on track to process even greater value this year. That evolution reflects more than simply increased adoption. The capabilities of Same Day ACH have expanded as well. The first phase supported credit-only transactions, while subsequent changes broadened functionality and increased transaction limits, giving organizations more flexibility in determining when faster ACH settlement makes sense. “The majority of the volume now is on debit, but the majority of the value is on ACH credit,” Danner said. “ACH credits are used for earned wage access, payroll, gig economy transfers and payouts, as well as business payments. So lots of use cases which have expanded beyond where it was initially. Thinking about debit, that’s where you’ve got the originator pulling the funds—bill payments, loan payment, subscriptions, and taxes—where all of that use has been growing as well.” Building on Existing Infrastructure One of the most important drivers of Same Day ACH adoption is something that can be easy to overlook in discussions about faster payments: the strength and ubiquity of the existing ACH infrastructure. Businesses, consumers and government agencies rely on ACH payments for payroll, bill payments, account funding, vendor payments, and other recurring or high-volume transactions. Organizations and consumers are familiar with the payment method, and financial institutions have established systems and processes for supporting it to scale. Same Day ACH builds on that foundation rather than requiring the market to adopt an entirely new payment rail. “Ease of adoption has driven the growth of Same Day ACH,” Marsh said. “Same day transactions are processed on existing infrastructure, they use existing formats, and they’re subject to the same familiar processes as future-dated ACH transactions. And they can reach virtually every deposit account in the U.S. with both debits and credits.” Danner added: “Both consumers and businesses want choice and flexibility.  Same Day is fine in many use cases or perhaps even the standard ACH transaction. The key is having that choice of speed and that flexibility to choose.” Finding the Right Speed for the Payment There are now more payment choices than ever, including instant or near-real-time options which have emerged in recent years. However, real-time payments also bring their share of considerations. Instant payments are often irrevocable and lack a debit capability. Both of these factors figure into one’s choice of payment. Although there are use cases where these payments make sense, Same Day ACH can often provide a balance of speed, efficiency, reach, and predictability—particularly for payments where immediate settlement is not essential. “We recognize that some payments travel faster than Same Day ACH, and some travel slower,” Marsh said. “Different payment scenarios have different needs based on the timing, the value, and the business processes involved.” “For a vast number of situations, we believe that Same Day ACH optimizes many of these considerations,” he said. “It provides the benefit of speed as well as the efficiency of batch processing. It enables businesses and consumers to complete payments in urgent situations.” One of the key aspects of this efficiency is that the structure and schedule of Same Day ACH transactions allow organizations time to plan and leverage these payments strategically, which can maximize the value of the payment for both payor and payee. From an accounts payable perspective, most businesses aim to hold on to funds as long as possible to optimize cash flow and liquidity. This also allows for greater accuracy within accounting metrics such as days payable outstanding and gives organizations more effective insights into their operations. Same Day ACH can provide these benefits while accelerating settlement, making it an important option between instant payments and traditional ACH. “Payments that benefit from that faster settlement time include payroll and contractor payments and transfers,” Danner said. “If you think about Same Day ACH credits, that is going to be primarily about accelerating disbursements, letting businesses get money into the account faster.” “If you think about ACH debits on the other side, it’s about accelerating the collections,” he said. “The benefit there is that the biller or that merchant can pull the funds sooner and reduce that time between the initial payment initiation and receiving those funds in their account, which has cash flow benefits.” The Next Phase of Growth From the early days of Same Day ACH, demand has been driven by a broader shift in expectations around payment speed, especially in commercial payments. That demand is likely to become even more consequential as the range of transactions eligible for Same Day ACH continues to expand. In September 2027, the Same Day ACH per-transaction limit is scheduled to increase to $10 million. The change represents one of the most significant expansions of the payment type since its introduction and could broaden the range of transactions for which Same Day ACH is economically and operationally viable. While transactions above the current $1 million per payment threshold represent a relatively small share of overall payment volume, they can represent substantial value and operational importance. Raising the limit has the potential to bring new categories of payments—and new groups of originators—into the Same Day ACH ecosystem. For some organizations, the higher threshold could also simplify payment operations by making Same Day ACH viable across a greater share of their ACH activity rather than requiring them to use different payment methods based on transaction size. “It’s about extending those capabilities and one of those being that per-payment limit, which is certainly going to expand use cases,” Danner said. “I’m thinking about use cases, and it’s things like high-value commercial real estate transactions or large enterprises needing to transfer money between accounts that need that speed. You could certainly cross that threshold into $10 million.” Commercial real estate provides one example of the opportunity. Although certain jurisdictions or transaction requirements may call for a wire transfer to execute a closing itself, Same Day ACH can potentially support other high-value activities surrounding the transaction, including commission payments and escrow funds. The first decade of Same Day ACH demonstrated that organizations value the ability to move money faster without abandoning the reach and infrastructure of ACH. The next decade could be defined by a broader question: not simply whether a payment can move faster, but how organizations can use different speeds and payment methods strategically across the operations. “Same Day ACH will continue to gain momentum as more receivers recognize its benefits,” Marsh said. “Businesses, in particular, that receive Same Day ACH transactions will begin to originate Same Day for their own payments. Originators will convert more future-dated activity to same day because their customers want it and because it’s easy to adopt.” “An increased dollar limit, demand, and ease of use will be the things that drive Same Day ACH growth in the comin

  7. Sep 10

    Nacha’s Upcoming Rules Refresh Is All About Improving Clarity

    ACH may be one of the payments industry’s most established networks, but it’s far from standing still. With new Rules taking effect this September—and another significant change already slated for 2028—financial institutions are facing a steady stream of adjustments that could affect how they process transactions, make funds available, and manage compliance. Earlier this year, Nacha implemented Rules aimed at bolstering financial institutions’ automated push payment fraud protections and cultivating a risk-based approach to fraud detection. This September, additional changes are coming down the pike, geared toward optimizing rules for International ACH Transactions (IATs) and funds availability for non-Same Day ACH transactions. In a recent PaymentsJournal podcast, Devon Marsh. Managing Director of ACH Network Rules and Risk Management at Nacha, and Ben Danner, Senior Debit Analyst at Javelin Strategy & Research, discussed the reasoning behind the Rules and how financial institutions should adapt to new processes and strategies. Understanding these Rules is critical, not just to maintain compliance, but also to increase efficiency and prepare for the next evolution of ACH. Calibrating Cross-Border Payments When a payment crosses a border, even if only part of the transaction does, the Rules governing it can become considerably more complicated. That is part of what Nacha is addressing with its definition of an International ACH Transaction. One of the most significant imminent changes is that the definition of IATs will be recalibrated, not replaced. “When people hear there’s a new definition, they think the definition has changed,” Marsh said. “The revision sought to provide clarity, so there is really no conceptual change in what type of transaction should be called an International ACH Transaction. What changed in the definition was the way it was worded—hopefully, it’s a more accessible definition now and Originators can understand better what they need to code as an IAT when they create an ACH entry.” When approaching the new definition, the first step for any ACH Network participant that facilitates IAT entries—including Originators, Originating Depository Financial Institutions (ODFIs), and Receiving Depository Financial Institutions (RDFIs)—is to study the definition and compare it against the types of transactions they currently process. In this process, some organizations that currently create IATs may discover that transactions they have historically considered IATs will not fall under the updated definition. Others may find that transactions previously treated as domestic payments actually meet the definition of an IAT. Once institutions have ascertained how to appropriately apply the definition, the next step is to educate personnel and begin classifying transactions accordingly. This will make the process more streamlined and better suited to the growing global economy. “It’s about clarity, which determines the obligations attached to the transaction,” Danner said. “Clarifying definitions around International ACH helps for more accurate compliance screening. It’s better, more accurate data to assess risk for all institutions across the [ACH] Network.” “Part of a larger trend is that cross-border is growing,” he said. “According to Nacha data, over 121 million IATs were processed in 2024. This shift in thinking about screening and risk monitoring and definitional clarity is even more important as cross-border volume grows.” But classification is only one part of the equation. For customers, one of the most tangible effects of a Nacha Rule change is much simpler—when can they actually use their money? The Interest of Making Funds Available That question sits at the center of another important change this September. The updated Rules around funds availability for non-Same Day ACH credit entries will change when RDFIs must make funds available—and remove a condition that has been in place for years. For many years, the Nacha Rules have stated that an RDFI that receives next-day credit entries by 5 p.m. must make those entries available to receivers by 9 a.m. local time on the settlement date. One component of the updated Rules will remove the 5 p.m. condition. Beginning Sept. 18, funds must be made available by 9 a.m. on the settlement date, regardless of when the file was received. For example, if an RDFI receives a file in a 6 a.m. file distribution from its ACH Network Operator, the institution will be expected to make the credit entries with that settlement date available by 9 a.m. “Most RDFIs that we talked with in developing this Rule already did that as a matter of practice,” Marsh said. “That 5 p.m. condition was a requirement, but posting transactions received after that wasn’t a violation. It didn’t say if you receive after 5 p.m. you can’t post; it was saying if you receive before 5 p.m., you must post.” “Most RDFIs, in the interest of making funds available to their receivers, would receive files well after 5 p.m. and make those available by 9 a.m. on the settlement date,” he said. “So, most of the RDFIs probably didn’t have a change to implement, they just had to ensure they were complying with this new Rule.” At first glance, that may sound like a relatively narrow operational adjustment. But the change illustrates a broader point: even seemingly small changes to Nacha Rules can force institutions to rethink how their systems, teams, and processes work together. And Nacha has accounted for the fact that not every institution operates on the same clock. In exploring the removal of the 5 p.m. condition, Nacha considered that there are several financial institutions located significantly east of the Atlantic Time Zone and west of the international date line. For example, there are financial institutions in the U.S. territory Guam. These institutions may receive files that are not even available to them before 9 a.m. local time on the settlement date. This is why Nacha established an exception—a carve-out for institutions that are not logically or physically capable of complying with the Rule. While these changes may cause a short-term shift for financial institutions, they can have substantial impacts for customers, including potentially earlier access to payroll, benefits, refunds, and other ACH credits. “If you think about what non-Same Day ACH credits are used for, it’s things like payroll benefits, government benefits, refunds, and invoice payments,” Danner said. “Perhaps with this change in window, it could be those payments could be available earlier, which could improve cash flow or reduce wait times—all the benefits of receiving a faster payment, particularly for these time-sensitive payments.” Streamlining Return Codes By the time the new return reason code R90 takes effect in March 2028, institutions will have plenty of time to prepare. The question is whether they will use it. “The reason we developed the new code R90 is because R16 paired two return reasons that were not necessarily logically connected,” Marsh said. “There’s returning due to sanctions obligations that the new code will take on, and R16 will remain the return reason code for account frozen.” “The best explanation for why we need to separate those out is because once the ODFI and the Originator receive a return back, they may need to do different things based on what the actual reason was,” he said. Splitting these return reasons into two separate codes is designed both to provide clarity on the origination side and to offer the RDFI a discrete code for returns related specifically to sanctions compliance obligations. There is another important difference with R90: when the clock starts. Under the usual return process, institutions generally have two banking days to return an entry, with the clock tied to the settlement date. R90 works differently. The two-day window begins when an RDFI determines that the payment has triggered its sanctions compliance obligations. In practice, this gives institutions more time to investigate a payment before the return deadline begins. For example, an RDFI might initially accept an entry but flag it for further review. If that review later determines that the payment has triggered its sanctions obligation, the two-day window starts at that point—not when the payment originally settled. “This isn’t unprecedented,” Marsh said. “There is a return reason code R23 that is used when an RDFI is notified by a Receiver that the Receiver has declined a credit entry, and that’s when the clock starts. This is similar in that respect: the clock is still two banking days, but it starts at a specific point in time.” A Long Lead Time The R90 change exemplifies Nacha’s efforts to make the ACH Network more efficient and secure for banks and their customers—but banks must still do their share. That is precisely why 2028 may deserve attention now. “It’s back to the theme of providing more accurate data,” Danner said. “It gives Originators better, clear information about what actions they’re going to need to take when a payment’s returned. This can affect the screening workflows and exceptions handling and communication and compliance procedures for OFAC compliance and risk monitoring. It’s important for ACH Operators and FIs to prepare to implement this new code.” The temptation may be to focus on the September changes and worry about R90 later. But the institutions that wait until 2028 is around the corner may find that the hardest part was never the code itself; it was everything that had to change around it. “The reason they need to start paying attention to it now is that developing a new return reason code requires programming and it requires technical development—and that could have a long lead time,” Marsh sa

  8. Sep 9

    Why Haven’t More Financial Institutions Adopted Instant Payments?

    Instant payments have quickly shifted from an emerging capability to a competitive expectation. Yet many financial institutions still struggle to justify the investment required to support them. With implementation costs, operational changes, and fraud concerns to address, it’s fair to ask: Are instant payments simply a customer convenience, or can they deliver meaningful business value? In a PaymentsJournal Podcast, Shankar Jayaraman, Director of Product Management, Real-Time Payments at Fiserv, Rusiru Gunasena, Head of Business Development for Service Providers at The Clearing House, and Ben Danner, Senior Analyst of Debit at Javelin Strategy & Research, explored why that question may already have an answer. As consumers and commercial use cases continue to expand, the decision facing financial institutions is becoming less about whether to offer instant payments and more about how soon they can. Clearing the Concerns Despite the fact that more than 1,500 financial institutions now offer instant payments through either The Clearing House’s RTP network or the Federal Reserve’s FedNow Service, more than 8,000 still do not. For many of these organizations, the barriers to adoption remain significant. One key factor is the challenge of making a bank’s payments and processes available 24/7. In addition to meeting customer expectations for around-the-clock service, financial institutions must establish prefunding requirements and ensure the proper risk controls are in place. Since instant payments are generally irrevocable, fraud prevention is a critical concern that must be fully addressed before transactions begin. For legacy banks, older, multi-tier technology stacks may not be capable of supporting instant payments. Overhauling these systems can be daunting, especially when the same payment processes have been in place for decades. Fortunately, financial institutions don’t have to navigate the transition alone. Experienced third-party service providers can handle operations such as transaction monitoring, error handling, risk mitigation, and fraud prevention, serving as a critical first line of defense. “If you are the financial institution, you’re not the first one,” said Jayaraman. “There is already someone who has cracked the problem. And there are many solution providers out there who are there to help you solve the problem.” Benefits of Joining the Network Whatever the concerns about adopting instant payments, the benefits often outweigh the risks. Most financial institutions that implement instant payments find that the customer experience improves immediately. “When a financial institution goes live on RTP, their customers discover that they can go and pull their funds sitting in a digital wallet into the institution account immediately,” said Gunasena. “They were even willing to pay to get those funds, because now they have liquid funds in their financial institution.” Instant payments also help strengthen the customer relationship by bringing it back to the financial institution. In addition, they provide rich, structured data that supports analytics and more informed decision-making. Both sending and receiving financial institutions can gain better visibility into payment activity and can make more accurate risk assessments. Some banks have even identified new revenue opportunities by offering instant payment services. “U.S. Bank launched an enhanced payment service for small businesses,” said Danner. “They’re charging to send those instant payments at a reduced rate through a subscription model to their small business service. As an issuer, this is a value add and a potential transaction revenue stream as well.” The commercial banking sector stands to benefit as well. Corporate treasuries can receive guaranteed, liquid funds immediately, improving cash flow and financial flexibility. Key Use Cases Emerge New use cases continue to emerge. The federal government has begun using instant payments for services like tax refunds, emergency payments, and other disbursements. Gig economy workers can now receive their earnings the same day, enabling them to cover immediate expenses, such as fuel, and get back to work without delay. Major issuers such as TD Bank and U.S. Bank have also rolled out instant payment capabilities for their auto dealer clients. Also on the horizon is Request for Payment, which has the potential to be a game changer by putting customers in control of authorizing the payment. “Instead of ACH debit coming and swiping your funds out of the account, now the biller will send a Request for Payment through the secure banking channels,” said Jayaraman. “You are bringing your customer back into your digital banking experience, where the customer can validate that payment—who is requesting it, for how much, what’s the purpose. Then they can agree to or deny that payment.” Making the Decision Financial institutions that are still evaluating instant payments can ease into adoption by taking a phased approach. Start by identifying the most common and pressing customer pain points, then prioritize use cases based on those needs.   Many banks have found it effective to begin with receive-only payments. However, they shouldn’t stop there—customers will eventually expect to send instant payments as well. “We should not read receive-only as the finish line, because receive is really how you get started,” said Gunasena. “To differentiate the customer experience, that’s where send comes in.” Finally, choosing an experienced partner can help create a smooth path to implementation. There are many considerations that banks and credit unions may not anticipate, but a knowledgeable partner can help identify both potential challenges and new and opportunities. Instant payments are becoming an inevitability, not only because of the speed they offer, but also because of the certainty, transparency, and enhanced customer experience they provide. Both organizations and consumers are discovering compelling new use cases across the network, transforming instant payments from a differentiating feature into an expected capability. As adoption continues to grow, instant payments are rapidly becoming a competitive differentiator. “Your customers might not be asking for it, but it is a core capability you need to have as a financial institution to service your customers for their needs in your platform,” said Jayaraman. “Otherwise, they’re going to go somewhere else and get it done as well.”

About

Payments Content, Expert Insights and Timely News

You Might Also Like