A community bank CEO told me recently, “We’re instant-enabled.”
Send was live. The fraud controls had been tested. The board had signed off. She said it the way senior leaders describe a project that has closed.
Technically, she was right.
Strategically, the harder work was just beginning.
Going live on instant payments Send is not the finish line of modernization. It is the point where the institution has to prove it can absorb the next capability without rebuilding its governance from scratch.
That next capability may be a new Send use case. It may be tokenized deposits, participation in a stablecoin network, richer ISO 20022 data, or an AI agent initiating a treasury payment.
Whatever comes next, the question is the same:
Can your institution evaluate it through a governance model that already exists, or will it reopen the same debate all over again?
Many financial institutions still treat each new capability as a separate project.
A new working group is formed for stablecoins. A fresh risk assessment begins for tokenized deposits. Treasury, fraud, legal, operations, and technology return to the table for AI-authorized payments. A new vendor conversation starts. Another board deck is built.
Then the same questions surface:
Who or what is authorized to move the money?
How do we know the actor, account, and purpose are legitimate?
What controls must operate before, during, and after the transaction?
What happens when a payment is mistaken, manipulated, or fraudulent?
What is the economic case, and does it justify the operating burden?
Those are the right questions. The problem is not that institutions ask them. The problem is that they keep answering them as though no prior work exists.
(Ask your team where the answers from the last three modernization initiatives live. In a standing policy? A shared risk register? A control architecture? in an old presentation? a lessons-learned document? the memory of two people who may not be in the room next time?)
That gap is where confidence breaks down.
Confidence is not optimism. It is not the absence of risk. And it is not the belief that your technology team can solve whatever appears next.
Institutional confidence means senior leaders can answer five questions without starting a research project:
What risks are we willing to accept?
What controls are non-negotiable across every rail and instrument?
Who has the authority to approve, reject, or stage a capability?
How will we measure value, exposure, and operational strain?
What evidence would cause us to expand, pause, or change course?
The strongest institutions I have seen are not always the largest or best funded. They are the ones that have converted prior implementation work into a reusable operating model.
This is not a new problem introduced by stablecoins or tokenized deposits. The same pattern played out across the banking-as-a-service boom. Between 2019 and 2023, a wave of banks signed one fintech partnership after another, embedded lending, neobank accounts, card programs, evaluating each one on its own instead of carrying a standing framework forward from the last approval. By 2023 and 2024, the FDIC and the Federal Reserve had entered consent orders and enforcement actions against several of those banks, Cross River Bank and Evolve Bank & Trust among them, for failing to build a risk management framework that could keep pace with the number of partners they had taken on. The remediation regulators required looks almost exactly like what a reusable governance framework contains: board approval before onboarding any new partner, a standing list of every partner and product under review, and defined ownership for identifying and reporting risk. Regulators did not invent a new requirement. They formalized the discipline that should have existed from the first partnership.
The financial institutions that get this right never needed a consent order to find out.
Their fraud decisions are not trapped inside one instant payments project. Their 24/7 liquidity assumptions do not have to be rediscovered for every use case. Their customer-authentication requirements do not change because a vendor uses the word “tokenized.” Their board does not have to relearn the same risk vocabulary every quarter.
They have built a standing governance framework that can evaluate a new rail, instrument, use case, or authorization method consistently.
Confidence is a “tested posture”, not a “feeling”. Share with a leader that would benefit from seeing this.
That is what confidence looks like in practice.
A repeatable modernization framework doesn’t have to be complex.
At minimum, it should contain four elements.
A shared risk baseline. Fraud, identity, settlement, liquidity, compliance, data, resilience, third-party dependency, and reputational exposure should be assessed through the same institutional lens, regardless of the capability being proposed.
A common decision model. Every proposal should be evaluated against the same criteria: customer or business need, strategic value, revenue or retention potential, control readiness, operating impact, technology dependency, and time to evidence.
Defined decision rights. Payments, treasury, risk, compliance, technology, and operations should know what they own, where they have veto authority, and what can be staged rather than rejected.
A learning rhythm. New capabilities should produce evidence that improves the next decision. Fraud performance, liquidity usage, exception volumes, customer adoption, and operational friction should feed back into the governance model.
This is the discipline behind the SAFE™ to SEND™ framework I developed while advising financial institutions. It gives leadership teams a common way to evaluate settlement, authentication, fraud, exceptions, regulatory exposure, data, resilience, and reputation before turning on a capability.
Applied consistently, that framework creates something more valuable than a completed risk assessment: a modernization posture the institution can reuse.
This is also the through-line connecting the last two issues, “Stablecoins Won’t Replace Instant Payments” and “They’re Already on the Next Layer.”
The instruments are changing. Your institution should not have to reinvent the foundation beneath them.
Once that framework is embedded and the posture is established, the institution changes how it experiences innovation.
A stablecoin consortium is no longer treated as an entirely new universe. It becomes another settlement and distribution model to test against existing questions about funding, customer ownership, third-party risk, compliance, and economics.
A tokenized deposit product is not evaluated because it sounds innovative. It is assessed according to whether it protects the deposit relationship, solves a customer problem, fits the institution’s control environment, and creates enough value to justify the build or partnership.
An AI agent initiating a treasury sweep is not simply approved or rejected because “AI is risky.” The institution examines identity, authority, transaction limits, explainability, exception handling, and human override through controls it already understands.
The board conversation changes, too.
Instead of asking for months to determine whether the institution should care, senior leaders can explain what is new, which existing guardrails apply, where the gaps are, and what staged decision is being requested.
Moving quickly is not recklessness. It is governed velocity.
The institution moves faster because it is no longer renegotiating its principles every time the market introduces a new capability.
A confident instant-enabled financial institution is not one that has adopted every available rail or instrument.
It is one whose leaders know how to decide.
They can distinguish a strategic option from a distraction. They can move forward without bypassing risk. They can say “not yet” without signaling “we have no idea.” And they can build on what their organization has already learned instead of reopening the same project under a different name.
That is the posture this newsletter has been building toward across instant payments, stablecoins, tokenized deposits, ISO 20022, and AI-enabled money movement.
Not speed for its own sake. Not adoption for its own sake.
Governed velocity: the ability to move with greater confidence because the governance underneath each decision is stable, reusable, and trusted.
Here is the question worth taking to your board this quarter: When the next capability arrives, will your leadership team be relitigating governance, or applying it?
If your leadership team is trying to turn a crowded modernization roadmap into a defensible sequence, I’d welcome the conversation.
If your leadership team would benefit from this perspective in the room, I’d welcome the conversation.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.