The traditional batch processing model gave banks time to perform scans for suspicious activity at multiple levels before payments were settled.
This buffer prompted the creation of a risk management regimen of systemic checks and back-office reviews, many of which were performed as a matter of course. However, as payments have become faster and more technology-driven, this set-it-and-forget-it approach is no longer optimal.
As Matthew Gaughan, Tech & Infrastructure Analyst at Javelin Strategy & Research, detailed in the Embedded Risk: Risk Management Finds a Home in the Tech Stack report, multiple forces have transformed risk management from a supporting function into a key component of every operation.
Namely, to match the speed of modern payments, risk management tools must operate continuously, respond dynamically, and function transparently—a feat which can only be accomplished effectively when risk controls are embedded across the enterprise.
Concluding the Processes of the Past
Although risk has been, and will always be, a part of the payments process, a convergence of trends is reshaping how organizations approach it.
For one, real-time payments have become a widely available and attractive alternative across a growing number of use cases. However, these instant and frequently irrevocable payments have drastically reduced the window for detecting and neutralizing fraud.
Financial services have also become both more deeply embedded and more externally interconnected than ever. Open banking has continued to supplant the traditional banking model, while embedded finance has fostered the expectation that payments can be made from virtually anywhere.
On top of these marked shifts, technologies like artificial intelligence and cloud computing are reshaping how payments can be personalized, streamlined, and delivered.
“In modern payments, everything is fast and complicated, and even more with things like agentic commerce coming into play and having these situations where there might not even be a human present in a transaction,” Gaughan said. “There are all these moving parts and the processes of the past—where it was separate from the payment flow and its own thing—don’t meet the needs of the current technological landscape.”
An Asynchronous Day and Age
As a result of these changes, many banks are moving away from centralized systems and manual review processes. Instead, they are embracing modular risk services that can be embedded directly into payment workflows.
This approach incorporates risk tools into nearly every aspect of the institution, from establishing customer identity to managing orchestration to creating event logs. This is to say nothing of longstanding risk management functions such as sanctions screening and anti-money laundering checks.
This level of integration has become imperative given the complexities of payment rails, geographies, fraud prevention, and compliance. A modular, embedded risk framework also allows institutions to adapt rapidly to evolving technologies, which is something conventional systems increasingly struggle to accomplish.
“If you try to bolt on that type of infrastructure on top of legacy architecture that isn’t built for it, it puts an extra strain on the system,” Gaughan said. “Now, payments, data flows, and the things that come with it are more asynchronous than they ever were. In the past, it was done in batches; it was predictable; it had a cadence to it.”
“It’s not like those systems weren’t powerful, they had mainframes that handled massive amounts of payments, but the mainframes of the past are too rigid for the asynchronous payment flow that is becoming increasingly common in this day and age.”
Moving Risk Management Upstream
Despite the forces prompting this change, many financial institutions have been hesitant to invest in modernizing their risk management infrastructure. This is partly because these functions have become entrenched in organizations’ systems and partly because institutions often prioritize other areas of the business.
However, the risks present in today’s financial services environment could rapidly permeate every aspect of an enterprise’s operations if they are not managed properly.
“First and foremost, it’s important that banks begin to treat risk as part of the full platform, given how much things have changed,” Gaughan said. “It’s crucial that they get it right because if they don’t, things break a little bit. Customers aren’t going to be happy; the bank will lose out on transactions, and customers might go elsewhere where they feel they’re being treated better.”
This underscores an opportunity for financial institutions. Although risk management is often treated as a defensive necessity, it can also serve as an integral part of an organization’s payments strategy.
More effective embedded risk controls can help banks support new use cases, streamline orchestration, optimize onboarding, and respond to regulatory and compliance shifts. However, in many cases, this will require institutions to break with established approaches to risk management.
“To move the risk function more upstream into the payment flow, you’re going to need to break out what that risk application is into discrete and composable parts, where things like fraud and identity can then be orchestrated properly within the broader modular architecture of a modern payment stack,” Gaughan said.
“Once you do that, then it becomes second nature, embedding it into how these risk functions are handled in real time,” he said. “But it’s going to be even more important as increasingly there are less reversible payments out there.”
Solidifying the Functions
While the speed of modern payments is one of the most important factors reshaping risk management, it is just one force in a broader transformation.
More importantly, banks that can integrate compliance, identity, authorization, and monitoring—all facets of risk management—into their payment architecture will be better positioned to navigate the financial services landscape of the future.
“It sounds simple, but payments in general are a risk product, and it’s important to keep that in mind when making these decisions,” Gaughan said. “All of these questions that have been associated with payments for time immemorial now are becoming more important because of real-time and asynchronous payments. These functions need to be solid.”
