1) Executive summary (what’s “new” about this wave)
Payments infrastructure is entering a fresh modernization wave because three foundational layers are shifting at once: (1) rails (real-time/always-on clearing and settlement), (2) data standards (ISO 20022 becoming the common payment “language”), and (3) operating model + risk (24/7 availability expectations colliding with stricter resilience, fraud, and security regimes).
This wave is not a simple “upgrade.” It is a re-platforming moment where core interbank systems, cross-border messaging, and the surrounding control plane (fraud, sanctions, resilience, observability) are being redesigned to work continuously, with richer data, and under higher regulatory scrutiny.
Two timelines illustrate the compression: SWIFT’s CBPR+ coexistence ended on 22 November 2025 (pushing cross-border institutions into ISO 20022 operational reality), while Europe’s Instant Payments Regulation introduced phased obligations starting 9 January 2025 for euro-area PSPs, accelerating instant payments rollout and related controls like verification of payee.
Meanwhile, the business layer is evolving: tokenization is becoming a default security pattern in cards (e.g., Visa reporting “nearly 50%” of global e-commerce transactions tokenized), while payments economics increasingly hinge on value-added services (reconciliation, data-driven risk, treasury automation) built on top of modern rails rather than tolls inside them.
2) What we mean by “payments infrastructure modernization”
Payments infrastructure includes:
- Clearing & settlement rails (instant payment systems, ACH, RTGS, card networks). [ecb.europa.eu], [pwc.com], [europeanpa…council.eu]
- Messaging, directories, and interoperability layers (ISO 20022 message schemas, routing, participant directories, payment tracking). [frbservices.org], [swift.com], [swift.com]
- Control plane (fraud/AML/sanctions screening, liquidity, exception handling, resilience/BCP, security compliance). [eiopa.europa.eu], [osborneclarke.com], [swift.com]
Modernization, in this wave, means moving from:
- batch + business-hours processing → 24/7/365 execution and monitoring (with real-time risk and liquidity controls). [europeanpa…council.eu], [finextra.com], [pwc.com]
- unstructured or legacy message formats → ISO 20022 rich, structured data that can support automation and analytics. [frbservices.org], [bankofengland.co.uk], [fsb.org]
- siloed national schemes and bilateral links → platform-like interoperability (e.g., standards-based cross-border interlinking of instant systems). [bis.org], [bis.org], [fsb.org]
3) The drivers: why this wave is happening now
Driver A — Real-time becomes “table stakes,” not a premium feature
Instant payments are shifting expectations: settlement in seconds, continuous availability, and immediate confirmation.
Regulation is now forcing the issue in some regions; the EU IPR explicitly sets deadlines for receiving and sending instant credit transfers and adds obligations like verification of payee and sanctions-list checks. [europeanpa…council.eu], [pwc.com], [frbservices.org] [osborneclarke.com], [finextra.com], [finance.ec.europa.eu]
Driver B — ISO 20022 is becoming the “operating system” for payment data
ISO 20022 is positioned as a structured, data-rich common language that supports a move from batch file processing toward real-time processing and enables enhanced analytics and operational efficiencies.
Central infrastructures have already migrated or are deep into migration: the Bank of England moved CHAPS/RTGS to ISO 20022 on 19 June 2023, and SWIFT ended CBPR+ coexistence on 22 November 2025. [frbservices.org], [fsb.org], [bankofengland.co.uk] [bankofengland.co.uk], [swift.com], [fsb.org]
Driver C — Cross-border payments are under coordinated global pressure
The G20/FSB roadmap frames cross-border payments as still too costly/slow/opaque, pushing priority work on interoperability, ISO 20022 harmonization, API harmonization, and linking fast payment systems.
Projects like BIS Project Nexus aim to standardize how domestic instant payment systems connect so cross-border payments can reach recipients within ~60 seconds in most cases. [fsb.org], [bis.org], [fsb.org] [bis.org], [fsb.org], [bis.org]
Driver D — Resilience and security requirements are tightening as complexity rises
The EU’s Digital Operational Resilience Act (DORA) applies from 17 January 2025, creating harmonized expectations for ICT risk management, incident reporting, and third-party risk oversight across financial entities and key ICT providers.
For cards and e-commerce ecosystems, PCI DSS is also evolving: PCI DSS v3.2.1 retired on 31 March 2024, and PCI DSS v4.0 requirements become mandatory by 31 March 2025, reinforcing modern controls in a more hostile threat landscape. [eiopa.europa.eu], [finextra.com], [fsb.org] [docs.tenable.com], [pcisecurit…ndards.org], [corporate.visa.com]
Driver E — The form factor of “money” is diversifying (tokenization + regulated digital assets)
Tokenization is scaling as a systemic security shift: Visa highlights near-50% tokenization share in global e-commerce and notes fraud reduction and authorization uplift associated with token-based transactions.
In parallel, Europe implemented the Markets in Crypto-Assets Regulation (MiCA) framework (entered into force June 2023; with further measures and registers), with stablecoin-related provisions applying from mid-2024 in practice and broader regime elements fully applicable from late 2024. [corporate.visa.com], [mckinsey.com], [pwc.com] [esma.europa.eu], [regular.eu], [mckinsey.com]
4) Evidence of the wave in motion: rails are upgrading at scale
4.1 United States — Real-time rails scaling (FedNow) + ISO foundations
The Federal Reserve describes ISO 20022 as “vital to instant payments,” emphasizing structured data as foundational for moving from batch to real-time processing and enabling remittance-rich straight-through processing.
FedNow volumes show rapid growth: 2025 recorded 8,413,402 settled payments with $853,411,108,511 value, up from 1,505,250 payments and $38,196,907,431 value in 2024. [frbservices.org], [pwc.com], [kpmg.com] [frbservices.org], [federalreserve.gov], [frbservices.org]
Interpretation: the U.S. is building a two-rail instant environment (FedNow + RTP), which increases reach but also introduces routing and operational complexity—a key modernization pressure on payment hubs and fraud systems. [pwc.com], [frbservices.org], [mckinsey.com]
4.2 Europe — Regulation-driven instant-by-default behavior
The EU Instant Payments Regulation entered into force 8 April 2024, with initial obligations for PSPs starting 9 January 2025, forcing infrastructure upgrades, real-time sanctions controls, and verification-of-payee capabilities on a compressed schedule.
The EPC’s SCT Inst scheme targets funds availability in <10 seconds, and rulebook updates align address-structure changes with broader ISO 20022 release cycles. [finance.ec.europa.eu], [osborneclarke.com], [finextra.com] [europeanpa…council.eu], [finextra.com], [fsb.org]
Interpretation: Europe’s modernization is not only technical; it is also economic and behavioral (e.g., equal charges requirements), pushing banks to treat instant processing as a default mode rather than a premium channel. [osborneclarke.com], [finextra.com], [mckinsey.com]
4.3 UK — A pivot from “big-bang replacement” to modular renewal
In the UK, Pay.UK cites a consensus need for central infrastructure renewal and explicitly shifts toward a modular, phased strategy—notably cancelling the prior NPA procurement and emphasizing future-proofing and integration with new channels (including open banking-initiated payments).
The Payment Systems Regulator confirms the NPA work was renamed Interbank Infrastructure Renewal (IIR) after cancellation of procurement, aligning with the National Payments Vision’s call for a more agile approach. [wearepay.uk], [psr.org.uk], [bankofengland.co.uk] [psr.org.uk], [wearepay.uk], [gov.uk]
Interpretation: the UK case shows a broader modernization lesson: infrastructure programs often shift from monolithic replacement to incremental composability when delivery risk, cost, and governance complexity mount. [psr.org.uk], [wearepay.uk], [mckinsey.com]
4.4 High-value settlement — RTGS modernization + ISO as baseline
The Bank of England migrated CHAPS and RTGS to ISO 20022 on 19 June 2023, positioning ISO as a “single common language” and highlighting enhanced data fields (structured addresses, purpose codes, LEIs) as a pathway to automation and resilience (e.g., rerouting).
In the eurozone, the Eurosystem’s T2 (launched March 2023, replacing TARGET2) uses ISO 20022 and shares features across TARGET services to improve liquidity management and efficiency. [bankofengland.co.uk], [fsb.org], [bankofengland.co.uk] [ecb.europa.eu], [fsb.org], [bis.org]
5) The cross-border layer: modernization is becoming a control-plane problem
Cross-border payments are modernizing along two tracks:
- Message & data standardization (ISO 20022) across SWIFT and market infrastructures. [swift.com], [fsb.org], [bankofengland.co.uk]
- Operational transparency + exception automation, because the “last mile” of cross-border failures often sits in investigations, recalls, and compliance stops. [swift.com], [fsb.org], [mckinsey.com]
SWIFT’s documentation confirms CBPR+ coexistence ended on 22 November 2025, and strongly recommends full ISO adoption to minimize operational and financial impacts, while also indicating post-2025 charges and migration momentum mechanisms.
SWIFT’s Case Management describes a shift to structured, ISO 20022-enabled exception handling (data pre-population, smart routing, end-to-end tracking) with mandatory milestones (e.g., November 2026/2027 for certain message flows). [swift.com], [fsb.org], [bis.org] [swift.com], [swift.com], [fsb.org]
Why this matters: when payments become faster, the “pain point” moves from settlement speed to error resolution and risk gating—meaning modernization must include the workflow layer (case orchestration) and not only the payment instruction layer. [swift.com], [finextra.com], [mckinsey.com]
6) The architecture shift: from monolith rails to modular “payment stacks”
A useful way to understand the modernization wave is to view payments as a stack:
Layer 1 — Rail connectivity (multi-rail, multi-scheme)
Institutions increasingly connect to multiple rails (instant systems, ACH equivalents, RTGS, cards), requiring routing and normalization. [mckinsey.com], [pwc.com], [europeanpa…council.eu]
Layer 2 — Message + data normalization (ISO 20022 as the “canonical model”)
ISO 20022’s structured fields enable straight-through processing, richer remittance, and better analytics—if institutions remediate and standardize upstream data quality. [frbservices.org], [bankofengland.co.uk], [kpmg.com]
Layer 3 — Orchestration (rules, routing, idempotency, reconciliation)
With multiple rails, orchestration becomes a differentiator: choosing rail by SLA, cost, risk score, customer preference, transaction type, and liquidity position. [mckinsey.com], [fsb.org], [pwc.com]
Layer 4 — Risk and compliance at real-time speed (fraud, sanctions, authentication)
The EU IPR’s daily sanctions-list verification approach reflects the reality that instant payments compress screening windows; “real-time” requires redesigned controls and customer-facing safety mechanisms (e.g., verification of payee). [osborneclarke.com], [finextra.com], [eiopa.europa.eu]
Layer 5 — Resilience, observability, third-party risk (always-on operations)
DORA’s focus on ICT risk, incident reporting, and third-party oversight aligns with the operational reality that payment uptime is now a systemic risk issue—not merely an IT KPI. [eiopa.europa.eu], [finextra.com], [mckinsey.com]
7) Where value shifts: from “moving money” to “making money move well”
As rails commoditize speed, value migrates to:
- Data-enhanced services (invoice-to-pay reconciliation, cash forecasting, remittance enrichment, analytics). [frbservices.org], [kpmg.com], [mckinsey.com]
- Risk-reducing services (tokenized credentials, better fraud detection, verification of payee, resilience engineering). [corporate.visa.com], [osborneclarke.com], [eiopa.europa.eu]
- Operational excellence (exception automation, lower investigation cost, better tracking and transparency). [swift.com], [swift.com], [fsb.org]
McKinsey frames a broader industry “turning point,” highlighting multirail competition, contested standards, and increasing emphasis on agility, architecture, and trust as investment priorities. [mckinsey.com], [mckinsey.com], [fsb.org]
KPMG’s research similarly describes ISO 20022 and instant payments as catalysts pushing banks toward 24x7x365 capabilities and positioning modernization as a strategic growth enabler rather than pure compliance. [kpmg.com], [frbservices.org], [pwc.com]
8) Tokenization and “safer payments by default”
Tokenization is a practical modernization story because it changes the security perimeter: rather than protecting PANs everywhere, networks replace sensitive credentials with tokens and cryptograms, reducing replay value and lowering fraud rates in digital commerce. [corporate.visa.com], [mastercard.com], [docs.tenable.com]
Visa reports that tokenized transactions can reduce online fraud versus PAN-based transactions and improve authorization performance, positioning tokens as both security and revenue levers (fewer false declines).
Mastercard describes tokenization at scale (including monthly tokenized transaction volume and strategic targets), reinforcing that tokens are becoming a mainstream network primitive. [corporate.visa.com], [mckinsey.com], [pwc.com] [mastercard.com], [mastercard.com], [paymentsdive.com]
Why this belongs in “payments infrastructure modernization”: security primitives (tokens, stronger auth, script integrity, etc.) are now embedded into network-level behavior, not bolted on at the edge. [docs.tenable.com], [pcisecurit…ndards.org], [corporate.visa.com]
9) A modernization roadmap: what institutions actually have to do
A realistic modernization program (bank, PSP, processor) now spans technology + data + operations:
Step 1 — Build a canonical payment data model (ISO 20022-native)
- Treat ISO 20022 not as a “translation project,” but as the canonical representation across channels and rails. [frbservices.org], [bankofengland.co.uk], [swift.com]
- Prioritize data remediation (names/addresses/LEIs/purpose codes/remittance), because structured fields only help if populated reliably. [bankofengland.co.uk], [fsb.org], [kpmg.com]
Step 2 — Modernize the processing core for 24/7 operations
- Ensure continuous posting/reconciliation and eliminate “end-of-day” fragility in downstream systems that can’t tolerate instant settlement patterns. [finextra.com], [pwc.com], [europeanpa…council.eu]
- Design for resilience and third-party failure (DORA-style controls, incident reporting readiness, vendor exit strategies). [eiopa.europa.eu], [wearepay.uk], [mckinsey.com]
Step 3 — Implement orchestration + routing + liquidity controls
- Multi-rail environments require policy-driven routing and liquidity forecasting across rails, especially when transaction caps and use cases expand. [mckinsey.com], [ecb.europa.eu], [pwc.com]
Step 4 — Rebuild risk controls for real-time
- Verification-of-payee, adaptive fraud analytics, and sanctions approaches must be redesigned for compressed time windows. [osborneclarke.com], [finextra.com], [eiopa.europa.eu]
Step 5 — Modernize exception handling (the hidden cost center)
- Adopt structured case management and standardized recall/investigation flows; SWIFT’s plan formalizes this as a mandatory migration path. [swift.com], [swift.com], [fsb.org]
10) Key risks and failure modes (what can go wrong)
- “ISO compliance” without data quality creates a false sense of modernization; you still get investigations and failed STP if upstream systems keep generating dirty identifiers and addresses. [frbservices.org], [bankofengland.co.uk], [fsb.org]
- Always-on rails on not-always-on cores can produce operational hazards: instant payments stress liquidity, reconciliation, support, and monitoring, especially on weekends and holidays. [finextra.com], [europeanpa…council.eu], [pwc.com]
- Fragmentation risk rises with multirail ecosystems; without orchestration, standards alignment, and interoperability projects, complexity can increase costs and reduce transparency. [mckinsey.com], [fsb.org], [bis.org]
- Third-party concentration and operational risk grows as payment stacks depend on clouds, SaaS, and specialized providers—exactly why DORA expands oversight and expects stronger third-party risk management. [eiopa.europa.eu], [wearepay.uk], [mckinsey.com]
- Security lag becomes existential: PCI DSS v4.0’s mandatory requirements (by March 2025) reflect a world where payment pages and identity controls must be hardened against modern fraud and injection attacks. [docs.tenable.com], [pcisecurit…ndards.org], [corporate.visa.com]
11) Outlook (2026–2029): what to watch next
A) Interoperability becomes the next battleground
The FSB and CPMI emphasize interoperability and extension (including APIs and fast-payment linking) as central to achieving 2027 cross-border targets, suggesting modernization will increasingly focus on networks between networks.
Project Nexus is a concrete model: one connection to a shared platform rather than custom bilateral connections, designed for scalable cross-border instant payments. [fsb.org], [bis.org], [fsb.org] [bis.org], [bis.org], [fsb.org]
B) Exception automation becomes mandatory infrastructure
SWIFT’s roadmap makes E&I modernization a structural requirement with dated milestones, signaling that “payment completion” is increasingly judged by resolution speed as much as settlement speed. [swift.com], [swift.com], [paymentsjournal.com]
C) Trust engineering will define winners
McKinsey’s “agility, architecture, and trust” framing aligns with the direction of regulation (DORA), security standards (PCI DSS), and consumer protections (verification of payee). [mckinsey.com], [eiopa.europa.eu], [osborneclarke.com]
12) Practical conclusion: a new modernization wave, not a single project
This modernization wave is best understood as a system-wide reset where:
- Rails get faster and always-on (instant payments scaling; RTGS modernization). [europeanpa…council.eu], [ecb.europa.eu], [frbservices.org]
- Data becomes structured and standardized (ISO 20022 as common language across domestic and cross-border contexts). [frbservices.org], [bankofengland.co.uk], [swift.com]
- Operations and control planes are redesigned for real-time risk, exceptions, and resilience under tighter regulatory regimes. [eiopa.europa.eu], [swift.com], [osborneclarke.com]
The institutions that “win” will treat modernization as:
- a platform shift (canonical ISO-native model, modular architecture), [frbservices.org], [wearepay.uk], [mckinsey.com]
- an operational shift (24/7 execution + observability + third-party resilience), [eiopa.europa.eu], [finextra.com], [pwc.com]
- a product shift (monetizing services built on rich data and lower-friction money movement). [kpmg.com], [mckinsey.com], [corporate.visa.com]
Selected source list (for deeper reading)
- Federal Reserve Financial Services: “What is ISO 20022 and why does it matter?” FedNow & ISO 20022
- Federal Reserve Financial Services: FedNow Volume & Value Statistics
- SWIFT: ISO 20022 implementation FAQs (CBPR+ end of coexistence)
- SWIFT: Case Management (Exceptions & Investigations transformation plan)
- Financial Stability Board: G20 Roadmap consolidated progress report (2024)
- BIS Innovation Hub: Project Nexus overview
- Bank of England: CHAPS/RTGS ISO 20022 migration
- European Commission (DG FISMA): Instant Payments Regulation clarifications
- Osborne Clarke: Instant Payments Regulation obligations & timelines
- EIOPA: DORA overview (applies 17 Jan 2025)
- PCI SSC: PCI SSC Document Library
- Tenable: PCI DSS v4.0 timeline summary
- Visa: Tokenization deep dive
- Mastercard: Tokenization overview
- ECB: T2 overview (replaced TARGET2 in March 2023; ISO 20022)
- McKinsey: Global Payments Report (2025)
- Pay.UK: Response to National Payments Vision (modular renewal)
- PSR: Interbank Infrastructure Renewal (IIR)

