Legacy system integration
Many financial institutions still operate on older systems. Many of these systems have been in play for decades; they were never designed for instant settlements, so upgrades are expensive and time-consuming.
Moving legacy systems over to ISO 20022 standards, for example, takes over a year for vast financial institutions.
You're at risk not only for integrated systems working with new core systems but for supporting interfaces too - reporting and reconciliation engines all need periodic testing to ensure continuity.
Upgrades can cause downtime, and any errors that reach customers hurt trust quickly.
Some organisations take a phased approach instead, running the old and new systems in parallel until the new one catches up. This avoids major interruptions, though it adds short-term complexity. For a closer look at reducing that risk, see payment infrastructure migration.
Security and fraud risks
Because an instant payment cannot be reversed once it settles, every check has to happen before the money leaves the account, not after. This is the opposite of how card payments and batch transfers work, where a chargeback or recall is still possible for days.
The main threat is authorised push payment fraud, where a scammer tricks the account holder into approving a payment themselves rather than stealing their credentials.
Because the payment is genuinely authorised, standard fraud rules do not catch it; only name-matching checks like Verification of Payee in the EU and Confirmation of Payee in the UK, which confirm that the account name matches the payee before the transfer is sent, are effective against it.
Sanctions and anti-money laundering (AML) screening also have to run in real time, 24/7, against the relevant lists for each region: OFAC in the US, EU financial sanctions lists, and the UK's OFSI list.
There is no overnight batch window left to catch a flagged payment after the fact.
Machine learning models help by flagging transactions that break a customer's normal pattern, such as a payment sent to a new payee for an unusually large amount.
The challenge is keeping false positives low: a legitimate payment that gets blocked or delayed undermines the instant experience the customer is paying for.
Regulatory compliance requirements
Each region enforces real-time payments through its own rules, and the requirements are becoming more specific rather than less.
In the EU, the Instant Payments Regulation (Regulation (EU) 2024/886) obliges euro-area providers to receive instant transfers, send them, and run Verification of Payee, all at no extra cost to the customer compared with a standard transfer.
Strong Customer Authentication continues to apply to instant payments alongside these newer obligations; see the DECTA payment infrastructure guide for a full explanation of Strong Customer Authentication.
In the UK, the Payment Systems Regulator's mandatory reimbursement rules put the cost of authorised push payment fraud directly on the sending and receiving banks, which is a strong incentive to invest in Confirmation of Payee and other pre-transfer checks rather than absorb losses after the fact.
In the US, the Bank Secrecy Act requires continuous transaction monitoring and reporting, which applies to real-time payments in the same way it applies to any other transfer.