How to improve payment security for treasury & finance teams

This article is written by Nomentia

Most larger companies process hundreds, if not thousands, of outgoing payments every day. These payments are crucial for the business and must be handled accurately and punctually. Yet, as the number of payments increases, their management can become challenging. Particularly when dealing with tens or even hundreds of bank accounts. Oftentimes, treasury and finance teams have to deal with a layer of complexity when they need to improve payment processes. To protect themselves against payment errors, fraud, or making payments to sanctioned beneficiaries. Which often requires implementing payment security process controls and other security measures.


In this article, we’ll talk about why it’s critical to have secure payment processes in place. What threats could your organization be facing. And how treasury and finance can tackle payment security within their own scope of work. While keeping processes as efficient as possible. As a bonus, we’ll provide a fraud risk management framework that can make dealing with process improvements less overwhelming.

Join the treasury forum at Treasurymastermind

Why are payment security and controls more relevant than ever before?

Financial scams are often directed towards treasury and finance teams, making these teams important stakeholders in payment security projects. In collaboration with IT and security professionals, they play a crucial role in ensuring payment security. Trustpair, SAP, and Accenture, payment did a survey that showed payment security is a top priority for finance and treasury professionals. With the increase in incidents of fraud and cyberattacks, companies can no longer ignore payment security. As a result, most teams are now actively reviewing their organizational processes to enhance safety. The survey also revealed that 56% of US-based companies fell prey to payment fraud in 2022.

IN 2022, 56% OF US COMPANIES HAD STILL FALLEN PREY TO PAYMENT FRAUD.

TREASURY & RISK SURVEY COMMISSIONED BY TRUSTPAIR & GIACT

The research study revealed that treasurers expect banks and system providers to take active role fighting against fraud attempts. To meet this growing demand, many advanced payment and TMS vendors have developed solutions to enhance payment security.

Differentiating between the types of payment issues that can occur

Even though some solutions provide the full suite of technical features for tackling payment errors, sanctions, and fraud. It is still important to differentiate between the security threats treasury and finance face because they require different approaches. Let’s consider some of the most common threats that can occur:

  • Erroneous payments: are typos, wrong amounts, double payments, or other errors that can occur while making payments.
  • Sanctioned beneficiaries: are usually payments processed to sanctioned beneficiaries that should not be allowed.
  • Internal fraud: could be employees with payment permissions who make fraudulent payments on purpose.
  • External fraud: some of the major trends include phishing, wire transfer scams, and invoice fraud where criminals trick employees into paying them.
  • Account takeovers: usually a hostile account takeover where an unwanted person can access a company’s payment systems to transfer money.
Payment issues overview

What belongs to payment security from a treasury and finance perspective, and how can you tackle it?

The question remains: what is really included in payment security from a treasury and finance perspective? And which threats can actually be fought by them? This can vary greatly, depending on the organization. The experience of teams, and the policies treasurers have established regarding security, among other factors. Different treasury professionals may have different opinions on what payment security entails. However, we have noticed some common themes that treasurers at our clients focus on from a technological standpoint:

Avoiding erroneous payments

Manual processes are susceptible to errors, particularly when they are performed repeatedly, leading to handler fatigue. This commonly results in erroneous payments through typos, outdated vendor master data, or mixing up beneficiaries, for example. These errors can be compounded over time. Resulting in time-consuming efforts to correct them, such as liaising with all involved stakeholders or seeking assistance from banks.

“MASTER DATA IS CRITICAL FOR PROCESS CONTINUITY. DATA ARE ASSETS, AND IF WE TALK ABOUT MASTER DATA, THAT IS REALLY A KEY ASSET, AND YOU NEED TO MANAGE MASTER DATA LIKE YOU MANAGE OTHER KEY ASSETS.”

MARK ROELANDS, RISK & COMPLIANCE CONSULTANT, GRC CONSULTING

An automated payment system, connected between your ERP and banks, can keep your master data automatically updated. And also, avoid outdated information. You can also avoid errors by setting up rule-based process controls. Or automated matching processes for reconciling financial records with bank statements. For larger single payment sums, double verification by a second person can be helpful in preventing errors.

Ensuring payments aren’t sent to any sanctioned beneficiaries

To comply with regulations and ensure security, most companies must check their payments against unwanted beneficiary lists. This can be achieved by verifying payments against public lists like OFAC’s, EU’s, and other institutions. As well as private blocklists or allow lists. As world politics continue to shift, these lists keep evolving, and hence, they need to be updated regularly.

Manual sanctions screening, i.e., uploading and downloading spreadsheets against sanction databases,. Or manually searching lists each time a payment batch is processed, can take a lot of time. Therefore, our customers have found that sanctions screening is most suitable as an automated step of a payment process flow in a payments hub every time payments are executed.

Preventing fraudulent payments

Fraud is a recurring topic for many companies and is challenging to spot when hundreds of daily payments go out to various stakeholders. However, preventing fraud is critical, as the losses can affect cash flow and liquidity planning. Organizations must tackle multiple types of fraud, each requiring a slightly different approach. 

Some of the most common frauds are wire transfer scams, phishing, and fake invoicing. On the one hand, most of these derive from human vulnerabilities; hence, you should educate employees to identify such fraud. On the other hand, intelligent payment technologies can recognize some of these irregularities as they stand out from ordinary payments. By scanning vendor master data automatically, for example. And, of course, larger payment sums should always be verified by several people. So that the financial loss is not too significant.

To avoid internal fraud, users should be given limited rights in payment processes. There should always be several people checking payments regularly. And the consequences of fraud should be made clear in Treasury policies to avoid any ambiguity.

Ensuring that payment processes are standardized and creating company-wide visibility

Most companies we help have many local payment operations worldwide, where processes and systems can differ per location. This usually leads to a lack of transparency over processes and security, even the cash flow, on a group level.

In some cases, our customers want to centralize payments to a group-wide level. And have global processes enforced. In other cases, local entities still have more responsibilities. In most cases, companies want to use the same payment technology to tackle global payments, and the solution is rolled out country by country until all entities use the same system. A single system provides transparency into all payment-related cash flow, allows processes to be easily enforced, and allows users to be optimally managed. An additional benefit is that you can leverage payment technologies to streamline intercompany payments and payments in various currencies to minimize the associated costs.

Basic system security like SSO and MFA

One of the most crucial aspects of payment processing is controlling who can access your bank accounts or payment systems, how safe it are, and their rights to execute payments. Basic functionalities like multi-factor authentication (MFA) and single sign-on (SSO) are considered essential by treasury professionals to keep their data safe and prevent unwanted logins. Typically, we see that companies require this for logging into payment technologies, and sometimes verification codes are even used when executing larger payment batches or sums.

User management and audit trail

One excellent control mechanism for security is user management. Once your treasury and finance teams expand, with multiple entities and bank accounts, it becomes hard to have a bird’s-eye view of which users are managing what processes and what they should be allowed access to. Not to mention all the new joiners and people quitting the organization, which needs to be kept track of. Without central user management, it can quickly become overwhelming and time-consuming.

That’s the reason why most companies look at tools for central user management, even integrated with HR systems, to keep track of newcomers and leavers. A TMS, for example, allows admin users to easily assign roles or user rights to specific teams or individuals without giving them too few or too many permissions. For instance, group treasury can set permissions so that a local entity can access its own cash flows and execute local payments, but cannot access the data or payments of other entities or groups.

“TO ENSURE SAFE PRACTICES, THE PRINCIPLE OF LEAST PRIVILEGE IS A GOOD RULE OF THUMB: NEVER GIVE MORE RIGHTS TO PEOPLE IN THE SYSTEM THAN THE TASKS THEY ARE ACTUALLY PERFORMING ACCORDING TO THEIR ROLE.”

TAPANI OKSALA, HEAD OF PARTNERS, NOMENTIA

On top of that, there’s often a demand by the treasury and finance for audit trails. This means that organizations can see exactly what users do in systems in case something goes wrong (incidentally or on purpose) and review the logs afterward. This helps while planning any follow-up actions.

4 or 6-eye principles

A simple yet efficient way to ensure that something isn’t wrong with a payment or payment batch is by including 4 or 6 eye principles into a payment process, for example, when a payment is about to be made. This way, a second or even third pair of eyes must verify the details of the payments being made to ensure they are correct. In payment hubs, you can set rules for when these principles should be applied, and the second reviewer will automatically receive a notification once their attention is requested.

Detect and respond notifications

Treasury and finance departments have a lot of tasks and processes to manage simultaneously. It can be hard to determine where their attention is needed most urgently. However, when attention is required, it is usually quite urgent. The same goes for payment security – if there is an issue, it is important that the relevant person be notified immediately. Although banks can notify users when there is a problem with a payment, this is only after the payment has been processed. Payment technologies can automatically identify almost any step in the payment process that requires attention and send notifications to the right user based on different sets of rules. This eliminates the need for emails to be sent back and forth between colleagues and other stakeholders. And if a payment somehow slips through, a hub can be integrated with the bank to ensure that the bank’s feedback is shown.

Payment matching or reconciliation

One of the most effective ways to prevent payment errors and fraud is by reconciling transactions with bank statements or invoices to ensure that all payments match payables. This is especially important when dealing with a large number of suppliers and payments. By using a system that can connect to your banks and ERP system, you can make sure that all necessary payment data is accurate and not missed. Such setups will greatly reduce errors related to manually going through each invoice and settling them.

However, payment security involves more than just technical solutions that are mentioned above. Other important topics that our partners and clients usually address include:

Employee awareness training

A big challenge for many companies is that fraud, errors, or scams start with an email or message to an employee via different channels. One important way to tackle this is to train employees, not just in treasury but in all teams, to identify scams. Most organizations do so through security awareness training that is usually initiated by IT and Security teams. Suppose something unwanted happens anyway; it’s best to have the proper incident response procedures in place to tackle it immediately.

“SAFE AND SECURE CULTURE IS NOT BEING CREATED BY STORING PDF DOCUMENTS WITH INSTRUCTIONS ON A SHAREPOINT, IT NEEDS FOLLOW-UP AND TRAINING. ALSO, THE COMPANY CULTURE NEEDS TO BE FOSTERED IN SUCH A WAY THAT PEOPLE FEEL COMFORTABLE STEPPING FORWARD AND POINT OUT THINGS THAT AREN’T IN ORDER.”

MARK ROELANDS, RISK & COMPLIANCE CONSULTANT, GRC CONSULTING

Treasury policies

One way to influence your payment security is by establishing the right payment-related policies that can be enforced company-wide. If they are easy to understand and can easily be followed without making processes inefficient, they can help ensure more secure practices.

Invoice approval procedures

Your invoice and vendor authenticity are important to maintain the integrity of your payables. One way to avoid fraud, especially with invoicing scams posing a threat to organizations, is to ascertain that your invoicing procedures allow you to identify fraud quickly. Irregular payments, such as those outside of approved countries, to new bank accounts, or irregular amounts, should always raise suspicion and be verified. In addition, you should encourage your team to ensure safety by cross-referencing vendor information when irregularities occur.

Incorporating these technical layers into the payment process is critical to efficient security against threats. On top of all technical security implementations, the human risk element should be tackled, which is sometimes an even bigger challenge as cyber threats and other scams continue to evolve and keep getting more challenging to identify for employees. Careful employee guidance and training should be a great first step in tackling that.

Where do start with payment security processes?

While facing the dual demands of optimizing payment processes cost-effectively and keeping security measures to mitigate financial losses from fraud and cybercrime efficient, organizations can find an effective solution in a payment factory. It’s an approach that offers a combination of automation and process security, tackling both challenges simultaneously.

Still, it can be daunting for some to initiate implementing a new system, such as a payment hub, to address payment security concerns. Therefore, we advise to begin by examining your current processes and identifying areas that can be improved. If you discover that your current methods can only scale to a certain extent, it may be worthwhile to investigate the various technologies available on the market. 

How a response framework can help in dealing with incidences 

As your treasury and finance organization continues to work with payment security, it usually keeps identifying additional improvements. When dealing with multiple treasury processes, it can be difficult to determine which ones to focus on first. To simplify matters, you can follow a process framework like the fraud risk management cycle developed by the European Court of Auditors (ECA). It shows the need for establishing the right processes and policies, and running risk assessments, after which the right controls can be developed to improve your current processes. As it is a continuous process, the process repeats itself constantly.

Fraud risk management framework

In addition, we always recommend you spar with your payment system to improve processes, be it a bank, ERP, TMS, or payment hub. Most of them have the necessary tools to help you fight payment threats better and more efficiently.

ALSO READ

Check our other blogs

This article is written by our partner, FIS

Key takeaways

  • Recent events illustrate that receivables finance remains vulnerable to fraud risks, such as invoice fabrication and double pledging, particularly when relying on manual processes and weak governance.
  • Advanced technology mitigates risk through real-time data integration, automated anomaly detection and shadow ledgers, reducing reliance on manual reporting and creating a single source of truth.
  • The most resilient frameworks combine digital efficiency with human oversight, ensuring automated alerts are reviewed by experienced professionals who understand the nuances of complex transactions.

Receivables finance (RF) has long been a cornerstone of corporate finance, enabling businesses to convert outstanding invoices into immediate liquidity. By selling their receivables to a funder, companies may access cost-effective funding and reduce risk, while investors may gain exposure to short-duration, diversified assets at a competitive return.

However, as recent events surrounding First Brands Group illustrate, this structure remains vulnerable to risks beyond credit, such as fraud. These vulnerabilities highlight the need for greater scrutiny and the adoption of new technologies.

How does fraud occur in RF transactions?

Fraud in RF transactions typically manifests through misrepresentation of receivables quality, double pledging of assets and fabrication of invoices. These risks arise because RF relies heavily on the integrity of the originator’s reporting and servicing processes. If invoices are falsified or pledged to multiple financiers, the asset base becomes compromised, exposing investors and lenders to significant losses.

The First Brands case underscores these vulnerabilities. The U.S. auto parts supplier, which filed for Chapter 11 reorganization in September 2025, allegedly engaged in widespread financial misconduct, including doctoring invoices and double-counting receivables to secure billions of dollars in financing.

What makes RF vulnerable to fraud?

Several market features of RF contribute to fraud risk:

  1. Information asymmetry: Investors and lenders may rely on originator-provided data without analyzing historical data and internal credit and operational processes.
  2. Servicer dependence: Given the usually heavy operational workload, originators may continue servicing receivables post-sale, creating opportunities for manipulation if internal controls are weak.
  3. Origination through fintech platforms: Many funders want access to this space, interested in the return relative to the short-term nature of the asset. However, by delegating the responsibility of originating and structuring, they may not receive detailed transaction information – exposing them to risk, given that such platforms do not normally have skin in the game.

These factors can make RF particularly vulnerable when governance fails or liquidity pressures incentivize aggressive accounting.

How can technology help detect fraud in RF?

The First Brands saga has accelerated calls for digital transformation in RF oversight. Advanced technology and reporting platforms can reduce fraud risk through:

  1. Real-time data integration and monitoring: Cloud-based platforms enable continuous monitoring of receivables performance across geographies. By aggregating item-level data from ERP systems and payment gateways, these solutions can provide a single source of truth, reducing reliance on manual reporting.
  2. Elimination of manual processes: When files are provided manually, there is no barrier to manipulating the asset file while moving from ERP to funder. With an automated solution, a fraudulent actor would have to manipulate the ERP on a recurrent basis, as opposed to changing a simple spreadsheet.
  3. Creation of a shadow ledger: An automated reporting tool can monitor each invoice in a relevant pool of assets. If properly implemented, a funder can track asset performance across the entire range of seller entities and ERPs. This helps to detect unusual performance patterns such as reappearing invoices, duplicates, or amount and due date changes.
  4. Automated checks and anomaly detection: Certain advanced digital tools now enable continuous scrutiny of receivables portfolios, automatically flagging inconsistencies such as atypical aging profiles and deviations from established dilution trends. By utilizing such technology, funders and investors can be better equipped to identify and address potential risks before they escalate.
  5. Transparent and detailed reporting frameworks: Industry initiatives promoting simple, transparent and standardized structures, coupled with automated waterfall calculations and trigger monitoring, may enhance investor confidence and regulatory compliance. This can be absent when investing through fintech platforms where information provided by the corporate is shared in an aggregated format with limited scrutiny.

What will shape the future of RF?

The collapse of First Brands is a cautionary tale for all stakeholders in the RF ecosystem. While RF remains a powerful liquidity tool, its resilience depends on effective governance and technological safeguards. Platforms that deliver real-time transparency, automated controls and immutable records are no longer optional: They are essential to maintaining trust and confidence in this asset.

In essence, resilient frameworks are often built on digital efficiency and the irreplaceable insight of experienced practitioners.

As institutional investors continue to seek exposure to trade finance assets and corporates aim to unlock working capital, the combination of advanced technology and human expertise within complex RF structures will help to shape the market’s future.

While digitalization may stand as the frontline defense against fraud, it’s equally vital to maintain effective human oversight by having seasoned professionals conduct independent reviews and engage in regular dialog with originators and funders.

This interplay between technological innovation and expert judgment helps ensure that not only are anomalies flagged automatically, but also the nuances of complex transactions are properly understood and addressed. In essence, resilient frameworks are often built on digital efficiency and the irreplaceable insight of experienced practitioners.

Join our Treasury Community

Treasury Masterminds is a community of professionals working in treasury management or those interested in learning more about various topics related to treasury management, including cash management, foreign exchange management, and payments. To register and connect with Treasury professionals, click the button below.

This article is written by Nomentia

Why are manual treasury processes expensive?

Manual treasury processes become expensive because they require recurring effort to collect balances, prepare payment files, update forecasts, check approvals, and reconcile data. Even when each task seems manageable, the combined impact can reduce efficiency, slow down decision-making, and increase operational risk.

Treasury teams are used to making imperfect systems work.

A spreadsheet here. A bank portal there. A local ERP export from one entity, a payment file from another, and a cash forecast that still depends on email updates from the business. None of these workarounds may look dramatic on their own. In many organisations, they are even seen as normal.

The problem is that “normal” can become expensive.

Manual treasury operations rarely create one large, visible cost line. Instead, they create a pattern of hidden costs: time spent collecting data, delays in decision-making, duplicated effort, payment exceptions, outdated forecasts, missed visibility, and control gaps that only become urgent when something goes wrong.

That is why treasury automation ROI should not only be discussed as a technology question. It is also an operating model question. How much time does treasury spend managing the process instead of managing cash, liquidity, payments, and risk?

Why manual treasury work is difficult to measure

The cost of manual work is often underestimated because it is distributed across people, entities, systems, and routines.

A treasury analyst may spend hours preparing a daily cash position. A regional finance team may manually upload payment files. Another person may validate bank data, check approvals, update forecasts, or investigate why one bank statement does not match the expected format.

Each task may be manageable. Combined, they create a significant operational burden.

This is also why many teams struggle to build a cash forecasting business case. The value of better forecasting is not limited to “faster reporting”. It is the value of better decisions: knowing earlier where liquidity is needed, reducing dependency on outdated data, improving confidence in funding decisions, and giving leadership a clearer view of what may happen next.

External research points in the same direction. PwC’s 2025 Global Treasury Survey notes that treasury teams are under pressure to improve cash visibility, cost efficiency, and risk management, while leading organisations increasingly adopt real-time liquidity tools, AI-enhanced forecasting, and centralised payment models. HSBC also highlights that cash flow forecasting has remained a key treasury priority, reflecting the need for precise and timely forecasts in a volatile environment.

In other words, manual treasury processes are not only inefficient. They can slow down the organisation’s ability to respond.

The cost of fragmented cash visibility

Cash visibility is one of the clearest examples of hidden treasury cost.

When balances are collected manually across banks, accounts, currencies, and entities, treasury may technically have the data, but not necessarily in time to act on it. The team may know yesterday’s position, but not today’s. It may have a consolidated view, but only after several people have updated files, checked bank portals, and reconciled different formats.

That delay matters.

Without timely visibility, companies may keep too much cash idle in one place while borrowing elsewhere. They may struggle to identify trapped cash. They may make liquidity decisions based on incomplete information. They may also spend valuable time explaining numbers instead of improving them.

Nomentia positions its Smart Treasury Suite around visibility, control, and predictability across payments, cash, liquidity, and risk, integrating with ERPs, banks, and other systems. For companies operating across multiple banks and entities, that integration layer is not just technical infrastructure. It is the foundation for turning fragmented data into usable treasury insight.

The cost of manual payments

Payments are another area where manual processes can appear cheaper than they really are.

At first glance, uploading files through bank portals or managing payments across local workflows may seem acceptable. The team knows the process. The banks are connected somehow. Payments are executed. Work continues.

But payment operations carry a high cost when they depend on scattered portals, inconsistent approvals, manual file handling, and local exceptions.

The hidden costs include time spent preparing and checking payment files, resolving format issues, validating approvals, tracking payment statuses, and answering questions from subsidiaries, AP teams, banks, and auditors. More importantly, weak payment control can increase exposure to duplicate payments, missed cut-offs, fraud attempts, and compliance issues.

This is where payment automation benefits become easier to explain. Automation is not only about faster payment execution. It is about standardising the process, improving traceability, reducing manual intervention, and making payment control easier to prove.

The cost of unreliable forecasting

Forecasting is often where manual treasury processes become most visible to leadership.

The CFO does not necessarily see how many files were collected, how many emails were sent, or how many adjustments treasury made before the forecast was ready. But the CFO does see when the forecast is late, when confidence is low, or when the numbers change without a clear explanation.

A manual cash forecast can still be useful. Many experienced treasury teams are excellent at working around incomplete data. But as the business grows, expands into new markets, adds banks, or inherits systems through acquisitions, the limits become harder to ignore.

Forecasting depends on data quality, timing, ownership, and repeatability. If treasury spends too much time gathering inputs, it has less time to analyse drivers, challenge assumptions, and model scenarios. A forecast that takes days to prepare may already be outdated when it reaches decision-makers.

This is why the business case for treasury automation should include both time savings and decision quality. Faster data collection is valuable. But the larger value often comes from giving treasury more time to interpret what the numbers mean.

The cost of controls that rely on people remembering the process

Manual controls are often built around expertise. The team knows which approvals are needed, which files need checking, which bank deadlines matter, and which exceptions require escalation.

That works until complexity increases.

As more entities, banks, users, and payment types are added, control becomes harder to manage consistently. Processes may differ across countries. Approval rules sit outside the system. Audit trails may require manual reconstruction. Exceptions depend on individual knowledge rather than embedded workflows.

In a stable environment, this may go unnoticed. During growth, restructuring, audit, staff changes, or periods of financial pressure, it becomes a risk.

The Nomentia Treasury Trends Report 2026 describes treasury teams facing pressure to deliver real-time insights, stronger controls, and more strategic input, often while dealing with fragmented systems and limited IT support. The report is based on 384 treasury and finance leaders across the Nordics, DACH, Benelux, and the UK.

That is the reality many treasury teams recognise: expectations are rising faster than operational capacity.

How to think about treasury automation ROI

A strong treasury automation ROI discussion should not begin with software features. It should begin with operational impact.

  • Where is treasury losing time today?
  • Which manual tasks are repeated every day, week, or month?
  • Where do payment processes create avoidable risk?
  • How much effort goes into collecting and validating data?
  • Which decisions are delayed because cash visibility or forecasts are not ready?

From there, TMS cost savings become easier to frame. The value may come from fewer manual hours, lower operational risk, more efficient payment execution, improved cash visibility, reduced dependency on spreadsheets, or stronger audit readiness.

The most useful business case is not a generic promise that automation saves money. It is a structured estimate of where the organisation currently loses time and where better treasury processes could create measurable improvement.

Also Read

Join our Treasury Community

Treasury Masterminds is a community of professionals working in treasury management or those interested in learning more about various topics related to treasury management, including cash management, foreign exchange management, and payments. To register and connect with Treasury professionals, click the button below.

This article is written by Cobase

For an industry built on numbers, banking has always struggled with something more basic: speaking the same language.

Ask any treasury team trying to connect to banks globally and you’ll hear a familiar frustration. The expectation is simple – money is digital, banks are global, so connectivity should be straightforward. In reality, it rarely is. What looks like a plumbing issue is something deeper: a system that was never designed to be unified in the first place.

Modern banking didn’t emerge as a coordinated network. It grew in fragments. National systems were built to serve domestic economies, shaped by local regulation, infrastructure, and political priorities. Payment schemes evolved independently. Messaging formats were defined in isolation. Even basic concepts like how to confirm a payment or report a balance took different forms depending on where you looked.

The result is not just variation, but incompatibility.

SWIFT is often held up as the closest thing to a global standard. And in one sense, it is. It created a common messaging layer that banks across the world could use. But it never standardised what happens after the message is sent. Two banks can receive the same SWIFT instruction and process it in entirely different ways – different cut-off times, different validations, different interpretations.

This is where the idea of “bank connectivity” begins to unravel. The challenge is not just reaching a bank, but dealing with how each bank behaves once you do.

Over the years, the industry has made repeated attempts to smooth this out. None have fully succeeded. Not because the technology wasn’t good enough, but because the incentives never aligned. Banks compete. Regulators don’t coordinate globally. And legacy systems – often decades old – continue to run critical infrastructure that no one is willing to replace lightly.

The expectation of a unified system persists. But it’s built on a false premise.

Banking isn’t fragmented because something went wrong. It’s fragmented because that’s how it was built.

The API promise, and its limits

Few ideas in banking have generated as much optimism in recent years as APIs.

They arrived with the promise of simplicity. Clean, modern interfaces. Real-time data. Standardised access. Compared to the heavy, file-based integrations of the past, APIs looked like a reset moment, a chance to finally make bank connectivity behave like the rest of the digital world.

And in some ways, they delivered.

Large banks began exposing endpoints for payments and reporting. Developers could interact with bank systems without navigating layers of legacy protocols. In controlled environments, things worked exactly as advertised.

But step outside those environments, and the picture changes.

APIs in banking are not a single standard. They are dozens, sometimes hundreds, of individual implementations. Each bank defines its own structure, its own authentication methods, its own limits. Even when two banks claim to follow the same framework, the differences show up quickly – in edge cases, in error handling, in performance under load.

The regulatory push behind open banking added momentum, but also confusion. PSD2 created a baseline, but it was never designed for corporate treasury. It focused on retail use cases, with limited scope for bulk payments, complex approval flows, or multi-entity structures. For large organisations, it solved a small part of a much bigger problem.

Meanwhile, neo-banks and aggregators entered the picture, offering simplified access and faster onboarding. They improved the experience at the edges, particularly for account opening and basic transactions. But they didn’t remove the need to engage with traditional banks. In many cases, they simply added another layer to manage.

The result is a familiar pattern in financial infrastructure. New technology doesn’t replace the old – it accumulates around it.

APIs didn’t eliminate fragmentation. They made it more dynamic.

Inside the hidden work of making banks “just work”

From the outside, bank connectivity looks deceptively simple. Payments go out, balances come in, and everything appears to move through a single system.

What’s less visible is the machinery underneath.

For companies operating across multiple countries, connectivity is not one connection, it’s dozens. Each bank brings its own requirements. File formats differ. Security models vary. Some require certificates, others tokens. One bank processes payments in batches, another in real time. Cut-off times shift by region, sometimes by product.

Even within the same bank, behaviour can change depending on the channel used. An API might support one set of payment types, while host-to-host supports another. Documentation doesn’t always reflect reality. Test environments behave differently from production. Exceptions are handled inconsistently.

None of this is unusual. It’s the normal state of the system.

This is why, despite all the talk of innovation, older methods remain firmly in place. Host-to-host connectivity – direct, file-based integration – continues to handle a large share of corporate payments. It’s not elegant, but it’s predictable. It does what it’s supposed to do, at scale, without surprises.

In certain markets, local standards dominate. EBICS, for example, is deeply embedded in parts of Europe. It works not because it’s globally relevant, but because it reflects the specific needs of those markets. In those contexts, it often outperforms more “modern” approaches simply by being consistent.

And then there’s SWIFT, still acting as the global fallback. When no direct connection is available, SWIFT is usually there. Not perfect, not always efficient, but broadly accepted.

Put all of this together, and a pattern emerges. There is no single best way to connect to banks. There is only a set of trade-offs.

The real work is not choosing one method, but managing all of them at once, and making them behave as if they were one.

That work increasingly sits in a layer most corporates never set out to build, but inevitably do: an orchestration layer that absorbs differences between banks, channels, and formats, and presents something coherent on top.

This is where platforms like Cobase operate.

Rather than trying to standardise banks themselves, Cobase standardises the interaction with them. It connects across SWIFT, EBICS, APIs, and host-to-host channels, translating between formats, normalising data, and embedding bank-specific behaviour into a central system. A payment instruction created once can be converted automatically into whatever each bank requires. Data coming back – balances, statuses, confirmations – is aligned into a consistent structure.

The complexity doesn’t disappear. It is relocated.

Instead of sitting in day-to-day treasury operations spread across teams, spreadsheets, and manual fixes, it is contained within a controlled layer designed to handle it.

Because in the end, the hardest part of bank connectivity is not building connections.

It’s making them invisible.

Also Read


Join our Treasury Community

Treasury Masterminds is a community of professionals working in treasury management or those interested in learning more about various topics related to treasury management, including cash management, foreign exchange management, and payments. To register and connect with Treasury professionals, click the button below.