Payments regulation is now one of the most consequential and fastest-moving areas of financial policy. The shift from batch-processed transactions to real-time, API-driven, multi-actor ecosystems is outpacing the frameworks built to govern them. Regulators updating or designing payments regimes today face a different set of trade-offs than their predecessors did even a decade ago.
Proportionality over uniformity
Modern payments ecosystems include global card networks, domestic instant payment schemes, licensed e-money institutions, unlicensed technical service providers, and increasingly, non-bank orchestrators sitting between all of them. Applying a single regulatory weight class to these differing actors can either strangle innovation at the margins or leave systemic risk under-supervised at the core.
The more durable approach is activity-based and risk-tiered regulation. Obligations should scale with the actual risk an entity introduces for example value held, transaction volume, criticality to national payment infrastructure, for example. The EU’s shift from PSD2 to PSD3/PSR reflects this logic, folding e-money institutions into the payment institution framework while sharpening obligations for fraud liability and access to payment systems.
Technology neutrality
“Technology neutral” is a frequently cited regulatory ambition, but one that is often applied haphazardly. A rule that is neutral on paper can still create de facto winners if it assumes a particular architecture, for example, assuming synchronous API calls where a market still runs on file-based batch settlement, or assuming a single centralised ledger where a jurisdiction is moving towards tokenised or DLT-based settlement rails.
Genuine neutrality means specifying regulatory outcomes (data integrity, finality, auditability, consumer redress) rather than mandating the technical means of achieving them. This is harder to draft and harder to supervise, but it avoids locking a jurisdiction into infrastructure choices that age poorly.
Operational resilience
As payment chains lengthen single points of failure multiply even as no single actor appears individually systemic. The EU’s DORA and the UK’s critical third-party regime for cloud and other CTPs both reflect a recognition that resilience regulation can no longer stop at regulated entities’ own walls.
Regulators need supervisory visibility into concentration risk among unregulated infrastructure providers (cloud, core banking vendors, API gateway providers) that sit underneath many licensed entities simultaneously. This is a challenging regulatory perimeter as extending direct supervision to technology vendors raises jurisdictional and resourcing issues. However, treating it as out of scope simply moves the risk.
Financial inclusion and competition
In emerging markets, mobile money and agent-banking models have done more for financial inclusion than most bank-led initiatives. Regulation designed primarily around bank-centric models can inadvertently disadvantage these models. For example, by imposing capital or governance requirements calibrated for deposit-taking institutions onto e-money issuers with materially different risk profiles.
At the same time, dominant mobile money or super-app operators can themselves become gatekeepers, and interoperability mandates (agent interoperability, wallet-to-wallet, wallet-to-bank) are often the difference between an inclusive ecosystem and a series of walled gardens. Regulators need to understand both realities at once – proportionate treatment for lower-risk non-bank models, alongside interoperability and access requirements once any single actor reaches enough scale to present competition issues.
Consumer protection
Fraud typologies in instant, irrevocable payment environments, authorised push payment (APP) fraud for example, are structurally different from card-present or batch-settled fraud. Liability frameworks built around card chargeback logic do not map cleanly onto instant credit transfers, where finality is near-immediate and reversal is a real challenge.
The UK’s mandatory APP fraud reimbursement regime for Faster Payments is one answer to this, shifting liability toward the sending and receiving PSPs rather than leaving it entirely with the consumer. Whether or not other regulators adopt that specific model, the underlying question of who internalises the cost of fraud in an irrevocable, real-time system needs an answer.
Cross-border coherence without full harmonisation
Few regulators can realistically harmonise fully with every corridor partner, but incoherence carries real costs. Correspondent banks de-risking out of corridors with unclear AML expectations, PSPs unable to scale regionally because licensing regimes are mutually unrecognised, and remittance costs staying high are realities. Regional initiatives such as PAPSS in Africa and ASEAN’s payment connectivity work show that pragmatic, corridor-specific interoperability arrangements can deliver much of harmonisation’s benefit without requiring full regulatory convergence.
That said, regulators should take an “interoperability by design” approach when designing regulation and subsequent technical standards, and this should be a continual mindset rather than a one-off exercise.
Messaging standards as a driver of policy objectives
The global shift to ISO 20022 is usually discussed as an operational project for banks and market infrastructures. For regulators, it is also a policy opportunity. ISO 20022’s structured data fields materially improve the quality of information available for sanctions screening, AML transaction monitoring, and fraud analytics but only if regulators actively require the richer data to be used and passed through the chain, rather than allowing truncation to legacy MT-message limits in the payment journey.
Regulators overseeing cross-border corridors should treat ISO 20022 adoption timelines, data truncation practices, and interoperability with CPMI-IOSCO’s PFMI expectations as supervisory issues, not purely technical ones. A jurisdiction that migrates its RTGS to ISO 20022 without corresponding rules on data completeness gets the compliance cost of migration without benefits it was meant to unlock.
Additionally, regulators should look at ISO 20022 as an industrial investment that can be used beyond payments. At the heart of ISO 20022 is a data dictionary the industry has invested in over decades. This data dictionary should continue to be built on to support initiatives and new innovations such as open banking and blockchain.
Open banking and open finance as Infrastructure
Open banking regimes are frequently framed around a single question: can a third-party access account data with consent? That framing is now too narrow. The more consequential regulatory decisions concern the plumbing underneath the access right:
- API standardisation. Fragmented, bank-specific API implementations (the UK’s early experience, and much of the EU’s under PSD2) impose real integration costs on TPPs. Mandating or strongly incentivising a common technical standard as the UK did through OBIE/Open Banking Limited, Banco Central do Brasil in Brazil, and as FiDA is attempting to do for open finance more broadly through Financial Data Sharing Schemes reduces this friction but requires an institutional body with the authority and neutrality to govern the standard over time.
- Liability allocation When a payment initiated through a TPP fails or is fraudulent, who bears the loss, the ASPSP, the TPP, or the customer? Regulators often leave a lot of ambiguity in this regard, but this can often lead to reduction in risk appetite.
- Premium APIs and commercial models. Regulators need a view on whether banks can monetise API access beyond the regulatory minimum, and how that interacts with competition policy. FiDA’s permission dashboards and compensation mechanisms are one attempt to formalise this; other jurisdictions are still treating it as a private commercial matter, which can tend to favour incumbents.
For emerging markets, the sequencing question is often more pressing than the design question. Building open banking rules before core payment infrastructure (real-time gross settlement, a functioning national ID scheme, or working data protection regulation) is mature tends to produce frameworks that may look sound but are too challenging to implement.
New forms of money
Central bank digital currencies, stablecoins and other crypto-assets used for payments are no longer speculative cases for regulators, they are policy questions with direct implications for sovereignty and financial stability.
Whether a CBDC is wholesale-only or extends to retail use, account-based or token-based, and how much of the distribution chain runs through commercial banks, all must be determined through the lens of disintermediation risk to bank balance sheets and the degree of privacy afforded to end users. Regulators and central banks need to be explicit about which policy objective CBDC is meant to serve e.g. financial inclusion, resilience against private stablecoin displacement or cross-border settlement efficiency for example, as the design that best serves one objective often trades off against another. A retail CBDC built for inclusion in a market with limited connectivity may look different from a wholesale CBDC built to modernise interbank settlement.
A CBDC or stablecoin that cannot settle against existing bank accounts, card rails, or instant payment schemes will struggle to move beyond niche use regardless of its technical merit. Regulators should treat interoperability standards for new forms of money as a critical component, as infrastructure decisions often determine adoption.
The underlying discipline
The future of payments regulation is about building regulatory frameworks that can absorb continuous change – new intermediaries, new rails, new fraud vectors, without rewriting regulations every few years. That means regulating outcomes and risk rather than specific architectures, building institutional capacity to govern technical standards over time rather than treating standard-setting as a one-off, and being explicit about the trade-offs between inclusion, competition, and resilience.
The jurisdictions getting this right tend to share one common trait in that they treat payments regulation as an ongoing function, not a static exercise.