AfricaNenda

Reference Guide for Inclusive Instant Payment Scheme Rules

A comprehensive framework for developing scheme rules, offering legal, operational, and governance foundations to build secure and accessible IPS across Africa.

Version 1.0

5. Core Components of Scheme Rules

83 min read92 sections16,497 wordsIPS Reference Guide v1.0
On this page

1. Scheme Manager Responsibilities:

  • Define business rules, technical standards, and Scheme policies.
  • Set eligibility criteria and participation requirements.
  • Determine funding and cost allocation mechanisms.
  • Manage onboarding and certification of Participants.
  • Resolve escalated disputes through expert determination.
  • Establish the long-term strategic roadmap for the Scheme.
  • Own Scheme-related intellectual property, where applicable.


2. System Operator Responsibilities:

  • Building and maintaining the payment infrastructure in line with Scheme specifications.
  • Ensuring high availability and meeting performance benchmarks.
  • Implementing strong cybersecurity and data protection measures.
  • Coordinating updates and upgrades with the Scheme Manager.
  • Providing monitoring, incident response, and participant support.
  • Maintaining disaster recovery and continuity plans.
  • Supplying performance data and incident reports to the Scheme Manager and relevant stakeholders.
  • Conducting first-line investigation of disputes.

2. Governance composition

1) Governing Board

The Governing Board should the highest decision-making body of the instant payment system, responsible for setting strategic direction, approving Scheme rules, and overseeing system operations.

  • The board composition should balance representation across different participant categories while ensuring appropriate expertise in payment systems, risk management, technology, and regulatory compliance.
  • Clear eligibility criteria should establish qualification requirements for board membership, including professional expertise, institutional representation, and absence of conflicts of interest.
  • The board's authority and responsibilities should be formally documented, including decision-making procedures, reserved powers, and delegation frameworks for operational matters.

As part of sound governance practices, the terms of reference for the Governing Board (PFMIs, Principle 2) should be clearly stipulated in the Articles of Association of the Institution Managing the Schemes.

The Board's composition should ensure a balanced representation across different participant categories, while also providing appropriate expertise in payment systems, risk management, technology, and regulatory compliance. Clear eligibility criteria must be established for board membership, including professional qualifications, institutional representation, and the absence of conflicts of interest.

To ensure focused oversight of Scheme governance, the Board should establish a dedicated Governance Committee, in addition to standard committees such as the Audit Committee and the Risk Management Committee.

The Board may delegate specific responsibilities to Management as appropriate, while retaining ultimate authority and oversight.

2) Advisory Forums

Advisory Forums serve as structured platforms for engaging Scheme participants and other key stakeholders in the governance process. These forums provide input on rule development, operational improvements, market needs, and emerging risks. While they do not hold decision-making power, their insights help ensure that the Scheme remains aligned with user expectations, industry trends, and practical realities. Two key types of forums include:

  • Participants Forums, composed of direct Scheme participants such as banks, non-bank financial institutions, and payment service providers. These forums provide operational feedback, raise implementation challenges, and suggest enhancements based on real-world use.
  • End User Forums, which represent consumer and business perspectives. They focus on user experience, accessibility, trust, and service quality.

Even within a Bank Led model, it is critical to ensure inclusive governance. A notable example is the Central Bank of Brazil, which established a permanent advisory body (Pix Forum). This forum plays a key role in supporting the Central Bank by contributing to the development of rules and procedures that govern the Pix system. By incorporating a wide range of stakeholder perspectives, the Pix Forum helps ensure that decision-making is transparent, participatory, and reflective of the broader ecosystem’s needs.[^7]

3) Working Groups

To strengthen operational collaboration and ensure that the Scheme remains responsive to participant needs, instant payment systems should establish dedicated Participant Working Groups. These groups offer structured platforms for participants to contribute expertise on technical, operational, legal, and business issues. They foster coordination among participants and address cross-cutting challenges that affect inter-participant operations and participant–customer interactions. The core objectives of these working groups include:

  • Facilitating knowledge-sharing and collaboration among participants.
  • Identifying and resolving technical, legal, and operational challenges.
  • Advising on enhancements to the Scheme and addressing emerging issues.
  • Escalating material concerns and actionable recommendations to the governing body.

The number and scope of working groups may depend on the size, complexity, and maturity of the Scheme, as well as the specific issues and priorities faced at a given time. Example of working groups:

  • Business Working Group: Focuses on product design, pricing models, and marketing strategies to support adoption and customer engagement.
  • Operational Working Group: Covers operations, technology, and information security, including incident handling, performance monitoring, and interoperability issues.
  • Legal Working Group: Addresses legal, risk, compliance, and data protection matters, helping ensure alignment with applicable regulations and Scheme policies.
  • Ad Hoc Working Groups : May be formed as needed to address specific topics or temporary issues requiring focused attention.

These groups should operate under clear terms of reference and maintain regular communication with the Scheme's Management to ensure their input informs decision-making and continuous improvement.

3. Principles for an effective management

To ensure effective execution of strategic decisions and strong operational management, instant payment Schemes should adopt a clear and accountable management framework. Key principles include:

1) Leadership Structure and Accountability: The Scheme should have a well-defined leadership structure with clear accountability lines. The executive team should report directly to the governing board to ensure alignment with strategic objectives.

2) Segregation of Duties: In integrated models, it is crucial to maintain a clear separation between governance functions and operational responsibilities to prevent conflicts of interest and safeguard the integrity of the Scheme.

3) Performance Management: A performance management framework should be in place to monitor the effectiveness of the Management Team, using KPIs aligned with the Scheme’s objectives and stakeholder expectations.

4) Clear Decision-Making Processes: The Scheme should establish well-defined decision-making processes at all levels to ensure accountability and that decisions are made in the best interest of the Scheme.

5) Risk Management Framework: A comprehensive framework for identifying, assessing, and managing various risks (operational, legal, financial, and reputational) must be implemented, including crisis management procedures.

6) Cross-Functional Collaboration: The Scheme should encourage collaboration among different functions (leadership, operations, legal, technical, compliance) to ensure that all perspectives are considered in decision-making.

7) Stakeholder Engagement: Regular communication with stakeholders, including participants, regulators, and consumers, is essential to ensure their needs and concerns are considered in strategic decisions.

8) Continuous Improvement and Innovation: The Scheme should foster a culture of innovation and continuous improvement, responding to technological advancements and evolving market conditions.

9) Internal and External Auditing: Both internal and external auditing processes should be implemented to ensure compliance, identify inefficiencies, and assess the overall performance of the Scheme.

10) Succession Planning: A well-defined succession plan for leadership roles and technical experts is crucial for the Scheme's continuity and stability.

This structure ensures both operational efficiency and governance integrity, particularly in models where the Scheme and system operator roles are

4. Decision-Making Frameworks

1) Voting Mechanisms

Effective governance requires clear voting mechanisms that balance stakeholder interests and establish transparent decision procedures. Different voting models may be appropriate for different decisions:

  • simple majority voting for routine operational matters, qualified majority (e.g., two-thirds) for significant rule changes, and consensus approaches for fundamental system changes.
  • Voting rights allocation should be carefully designed to prevent domination by larger participants while ensuring representation proportionate to participation levels and risk exposure. This may involve tiered voting rights, participant category representation requirements, or voting caps for individual institutions.

2) Rule Change Procedures

A Structured rule change process enables the Scheme to evolve in response to market needs, technological developments, and emerging risks. This process should balance the need for stability and predictability with the importance of continuous improvement and adaptation.

To ensure transparency, consistency, and operational stability, all rule changes within the instant payment Scheme should be classified and managed based on both impact level and subject matter category.

1) Classification by Impact

  • Major Changes: Substantial modifications that may significantly affect system functionality, participant obligations, risk management, or user experience. These changes typically require broad consultation, formal approval processes, and sufficient notice prior to implementation.
  • Minor Changes: Limited adjustments with minimal operational or compliance impact, such as editorial corrections, clarifications, or routine updates. These changes may follow a simplified approval and notification process.

2) Categorization by Subject Matter

  • Technical Enhancements: Updates to technical standards, message formats, system interfaces, or integration protocols that affect how participants connect and interact with the system.
  • Operational Adjustments: Modifications to operational procedures, service levels, processing schedules, or performance expectations that govern day-to-day activities.
  • Risk and Security Updates: Changes related to fraud prevention, cybersecurity requirements, business continuity, or other risk mitigation controls critical to the Scheme’s integrity.
  • Governance Modifications: Adjustments to governance structures, such as decision-making procedures, voting mechanisms, representation rights, or participation categories.
  • Emergency Changes: Urgent modifications required to address immediate threats, system failures, or regulatory demands. These changes may be fast-tracked but should still be subject to post-implementation review and communication.

3) Change Management Process

A formalized change management process ensures that all rule changes are evaluated, approved, and implemented in a transparent, consistent, and timely manner. The process includes the following key stages:

  • Initiation: Rule changes may be proposed by the Scheme Manager, the System Operator participants, or regulators. Each proposal must include a clear rationale, expected impact, and supporting documentation. Proposals are logged in a centralized Change Request Register maintained by the Scheme Manager.
  • Preliminary Assessment: The Scheme Manager conducts an initial assessment to:
  • Classify the change by impact level (major or minor);
  • Categorize it by subject matter (technical, operational, risk, governance, or emergency);
  • Determine whether immediate action is required (for emergency changes).

The outcome of this assessment determines the required pathway for consultation and approval.

  • Stakeholder Consultation: For major changes, the Scheme Manager initiates a formal consultation with affected stakeholders, including participants, the System Operator, and relevant regulators. Draft changes may be circulated for written feedback over a defined period (e.g., 2 to 4 weeks). Where relevant, technical or operational impact assessments may be conducted.
  • Review and Approval: A designated Scheme Change Advisory Committee or governance body reviews the proposed change, stakeholder input, and supporting analysis. Approval follows a formal voting or consensus-based decision-making process. In urgent situations, emergency changes may be fast-tracked for immediate implementation. However, these changes must subsequently undergo formal review and approval by the appropriate governance body to ensure proper oversight and accountability
  • Notification and Publication: Once approved, the final rule change is documented and published through official Scheme communication channels. Participants are provided with implementation timelines, technical specifications (if applicable), and any relevant training or guidance.
  • Implementation: Participants implement the approved change within the agreed timeframe. The System Operator supports implementation for system-level or technical changes. The Scheme Manager monitors readiness and compliance across the ecosystem.
  • Post-Implementation Review: Following implementation, the Scheme Manager conducts a review to:
  • Assess whether the change achieved its intended objectives;
  • Identify any implementation issues or unintended consequences;
  • Gather feedback from participants and stakeholders;
  • Recommend any follow-up actions or additional clarifications.

3. Scheme Participation Framework

1. Core principles

Instant payment Schemes should adopt a clear set of core principles that serve as the foundation for defining participation, who is eligible to join, under what conditions, and with what responsibilities. These principles promote open and fair access (PFMIs, Principle 18) while supporting the development of inclusive, secure, and high-performing payment ecosystems. The recommended core principles are:

  • Balance: Achieving the right equilibrium between broad access and effective risk management, ensuring that increased participation does not compromise system stability.
  • Security: Safeguarding the integrity, confidentiality, and resilience of the payment system through strong data protection and cybersecurity measures.
  • Accessibility: Enabling participation by a diverse range of financial service providers, including banks, fintechs, and other regulated entities, to promote innovation and financial inclusion (see Annex 4 for related metrics).
  • Fairness: Ensuring all participants are treated equitably through transparent rules and non-discriminatory access to system functionalities.
  • Efficiency: Designing participation processes and operational workflows that minimize complexity, reduce costs, and support the seamless flow of transactions.

2. Participant Classification

Instant payment systems generally define multiple categories of participants, each with distinct rights, obligations, and levels of system access. These classifications help ensure that the system remains both inclusive and operationally sound. The main participant categories typically include:

1) Core Participation Types

  • Direct Participants: These entities establish a direct technical connection to the instant payment system and participate directly or indirectly in the settlement process. Direct participants are fully responsible for meeting all technical, operational, and compliance requirements defined by the Scheme.

In some jurisdictions[^8], direct participants may be further categorized as:

  • *Directly Connected Settling Participants (DCSPs)* – with direct access to both the payment system and the settlement mechanism.
  • *Directly Connected Non-Settling Participants (DCNSPs)* – with direct technical access but relying on a third party for settlement services.
  • Indirect Participants: Indirect participants connect to the instant payment system through a direct participant, leveraging that relationship for both technical access and, potentially, settlement. While they are still subject to relevant rules and obligations, they typically face less demanding technical requirements.

2) Specialized Participation Roles

In addition to core participant types, instant payment Schemes may recognize specialized roles that contribute to the ecosystem's functionality and innovation. These include:

  • Third-Party Payment Providers (TPPs): These entities provide services such as payment initiation or account information access (as defined in Payment Service Directive 2[^9]) to end-users, without necessarily holding or settling customer funds. TPPs play a key role in enabling innovative services and expanding the use cases of the instant payment system.
  • Technical Service Providers (TSPs): TSPs offer technology infrastructure, integration services, or operational support to other participants. Although they do not process payments directly, they enhance system accessibility, particularly for smaller institutions, by offering shared technical platforms and reducing the complexity and cost of system participation.

3. Eligibility Criteria for Participation

1) Direct Participants

Eligibility for direct participation typically includes several categories of requirements.

1. Legal status requirements generally mandate that participants be licensed financial institutions or regulated payment service providers authorized to provide payment services in the relevant jurisdiction.

2. Financial requirements include minimum capital standards, liquidity capacity relative to expected transaction volumes, and financial guarantee mechanisms where applicable.

3. Operational requirements typically include minimum technical capability standards, business continuity provisions, and customer service capabilities.

4. Compliance capabilities should include appropriate risk management systems, AML/CFT programs, and data protection measures.

Direct participants generally must also demonstrate the ability to meet the system's security standards and performance requirements.

2) Indirect Participants

Indirect participation criteria typically focus on ensuring appropriate relationships with direct participants while maintaining system integrity.

  • Legal status requirements usually parallel those for direct participants, requiring appropriate regulatory authorization to provide payment services.
  • Indirect participants must establish contractual relationships with direct participants that clearly allocate responsibilities and liabilities.
  • While technical requirements may be less stringent than for direct participants, indirect participants still must maintain appropriate security controls and operational capabilities relative to their transaction volumes.
  • Compliance obligations generally include maintaining appropriate AML/CFT programs and data protection measures, though implementation may differ from direct participant requirements.

4. Participant Onboarding Process

The participant onboarding process should be transparent, objective, and efficient, ensuring that only qualified entities gain access to the instant payment system. A well-defined onboarding framework safeguards the integrity, security, and operational reliability of the system. The process should include the following components:

1) Application and Eligibility Requirements: New applicants must submit all required documentation, which may include:

  • License certificate
  • Financial statements and evidence of solvency;
  • Proof of operational readiness and internal capacity;
  • Details of risk management, fraud prevention, and compliance programs.

The application process should be standardized, with published forms, instructions, and eligibility criteria.

2) Assessment and Evaluation: The Scheme Manager should apply a consistent and objective methodology to evaluate applications. Evaluation criteria may include:

  • Legal and regulatory standing;
  • Financial health and institutional soundness;
  • Technical and operational capabilities.

Clear timelines should be established for the assessment process to ensure predictability and fairness.

3) Technical Certification: Applicants must demonstrate their ability to interface with the system by completing a technical certification process that covers:

  • Conformance to message formats and protocols.
  • Security architecture and authentication capabilities.
  • Ability to send, receive, and reconcile payment messages accurately.

4) Testing and Validation: Before going live, applicants must undergo rigorous testing, including:

  • End-to-end transaction simulations.
  • Performance and stress testing.
  • Validation of security and data protection controls.

A successful testing phase is a prerequisite for production access.

5) Implementation and Go-Live Readiness: An implementation plan must be developed in coordination with the System Operator, covering:

  • Transition and cutover planning;
  • Staff training and operational readiness;
  • Communication strategies for customer awareness and support.

6) Ongoing Compliance and Reassessment: After onboarding, participants remain subject to ongoing compliance monitoring.

  • Periodic reassessments should verify continued eligibility and operational conformity.
  • Any material changes in the participant’s business model, technical infrastructure, or risk posture must be reported and may trigger a revalidation process.

5. General Rights and Obligations

A well-functioning Instant Payment Scheme requires clear allocation of rights and obligations among the System Operator and Scheme Participants. These guidelines provide a generic framework that can be adapted to different institutional, regulatory, and market contexts.

1) System Manager/Operator

The System Manager/Operator is tasked with the management, operation, and oversight of the IPS infrastructure, playing a critical role in ensuring the system's stability, security, and equitable access for all participants.


3. Key Obligations of the System Operator/Manager include:

  • Operate and maintain the IPS in a secure, efficient, and reliable manner, aligned with the Scheme rules and agreed service levels.
  • Ensure fair and transparent access to all eligible participants without discrimination.
  • Coordinate governance structures, including working groups and consultative forums.
  • Provide technical support and operational assistance, including issue resolution.
  • Communicate proactively, including advance notice of maintenance, upgrades, or rule changes.
  • Monitor compliance, address violations in line with Scheme procedures, and safeguard participant and customer confidentiality.
  • Publish periodic system performance reports in anonymized form to inform participants.
  • Exercise discretion under the Scheme rules fairly, reasonably, and in line with the Scheme’s objectives.


4. The main Rights of the System Operator/Manager include:

  • Set and review participation fees, following consultation with participants.
  • Share performance data with regulators and advisors for supervisory and policy purposes, while preventing commercial misuse of such data.
  • Notify participants of material or repeated non-compliance, ensuring such communication is limited to the concerned party and preserves confidentiality.
  • Limit liability for any loss or damage arising from actions or omissions made in good faith and within the framework of the Scheme rules.

2) Participants

Participants' rights and obligations may vary based on their participation model (e.g., direct or indirect), but all are expected to uphold the rules and principles of the Scheme.


5. Rights of Participants:


6. Operational Rights:

  • Submit transactions in accordance with the Scheme rules and established parameters.
  • Receive timely settlement for valid and properly submitted transactions.
  • Access technical support, issue resolution services, and operational guidance.
  • Receive advance notification of planned system changes or maintenance.
  • Be treated equitably in transaction processing without preference or bias.


7. Governance Rights

  • Participate in consultations related to rule changes and system enhancements.
  • Be represented in governance structures as defined by participation category.
  • Appeal decisions that significantly affect participation status or operational rights.
  • Receive transparent information on system performance, incidents, and developments.


8. Commercial Rights:

  • Offer instant payment services under their own branding.
  • Define and implement pricing strategies for customer-facing services, in line with applicable regulations.
  • Develop and provide value-added services based on IPS infrastructure.


9. Obligations of Participants:


10. Financial Obligations:

  • Maintain sufficient settlement funding to support expected transaction volumes.
  • Provide required collateral or guarantees, where applicable.
  • Contribute to loss-sharing or guarantee mechanisms if required by the Scheme.
  • Pay all Scheme fees and charges in a timely manner.


11. Operational Obligations:

  • Maintain system connectivity and performance according to agreed service levels.
  • Process transactions promptly and in compliance with Scheme rules.
  • Implement robust security measures and fraud prevention controls.
  • Promptly report incidents and participate in collaborative resolution efforts.
  • Participate in required testing, certification, and system upgrades.


12. Compliance Obligations:

  • Comply with all applicable Scheme rules, technical standards, and procedures.
  • Adhere to legal and regulatory requirements relevant to their role in the IPS.
  • Implement customer protection measures consistent with Scheme and regulatory expectations.
  • Cooperate with compliance reviews, audits, and data reporting obligations.
  • Ensure that any sponsored institutions or third-party providers adhere to relevant rules and obligations.

3) Sponsoring agent

The relationship between sponsoring direct participants and their sponsored indirect participants is vital to the success of tiered participation models. Clear rules help ensure fair treatment, effective risk management, and service continuity.


13. Contractual Framework:


14. Technical and Operational Support:


15. Risk Management and Oversight:

4) Technical Service Provider (TSP)

TSPs are essential to the integration, scalability, and operation of instant payment systems. They provide infrastructure, connectivity, and services that help participants, especially smaller or indirect ones, access the system. Clear rules should define their roles, responsibilities, and oversight to ensure resilience and security.


16. Roles and responsibilities

  • Translation Services: The Scheme should include provisions for services that facilitate translation between different message formats or standards, ensuring interoperability across various systems and platforms.
  • Aggregation Services: To support smaller participants, the Scheme should offer aggregation services that allow groups of smaller entities to pool their resources, thereby enhancing their ability to participate effectively in the instant payment network.
  • Value-Added Services: The Scheme should allow for the provision of value-added services, such as fraud prevention, compliance checking, and data analytics, to enhance security, regulatory compliance, and operational efficiency within the payment ecosystem.


17. Technical and Operational Requirements

  • Higher availability requirements reflecting their position as potential single points of failure.
  • Robust security standards for handling transactions across multiple systems.
  • Comprehensive monitoring and reporting capabilities across connected networks.
  • Clear procedures for managing incidents that affect multiple connected systems.


18. Governance and Oversight:

  • Certification processes verifying ISP capabilities and compliance with standards.
  • Regular assessment of operational performance and risk management
  • Clear allocation of responsibilities between ISPs and the participants they serve
  • Transparency requirements regarding fees, service levels, and connected networks.

6. Participation suspension and termination

Clear suspension and termination conditions define the circumstances and procedures under which a participant’s rights within the instant payment Scheme may be temporarily restricted or permanently revoked, ensuring transparency, consistency, and fairness in the application of such measures

1) Suspension conditions

The Scheme should define different types or levels of suspension based on the nature and severity of the underlying issues. This may include partial suspensions affecting only certain transaction types or volumes, monitored operations with enhanced oversight, or full suspensions preventing all transaction processing.


19. Grounds for Suspension:

  • Financial Distress: Significant deterioration in financial condition creating settlement risk, including breaches of capital requirements, liquidity constraints, or pending insolvency proceedings
  • Operational Failures: Persistent or severe operational issues compromising the participant's ability to fulfil obligations, including extended outages, critical system failures, or repeated performance standard violations
  • Security Breaches: Significant security incidents affecting the participant's systems that create risk for the broader ecosystem, including data breaches, cyber-attacks, or compromised infrastructure
  • Compliance Violations: Material or repeated non-compliance with Scheme rules, technical standards, or regulatory requirements.
  • Regulatory Actions: Supervisory measures imposed by regulatory authorities that affect the participant's ability to provide payment services.


20. Suspension Process:

  • Initial identification and assessment of potential suspension conditions
  • Appropriate escalation within the Scheme governance structure
  • Communication with the affected participant, including opportunity to respond where circumstances permit
  • Formal decision through authorized governance bodies
  • Implementation of suspension measures with appropriate technical and operational adjustments
  • Notification to other participants and relevant authorities as required


21. Remediation and Restoration Procedures:

  • Remediation Plan Development: The suspended participant, in collaboration with the Scheme operator, must develop a comprehensive remediation plan addressing the specific issues that led to suspension. This plan should include concrete actions, timelines, resource allocations, and success measures.
  • Scheme Approval and Monitoring: The remediation plan must be formally approved by the Scheme through designated governance channels. Once approved, the Scheme will establish monitoring mechanisms to track progress against plan milestones.
  • Implementation and Validation: The participant implements the remediation measures with regular progress reporting to the Scheme. The Scheme may require independent validation of key improvements, particularly for technical or security-related remediation.
  • Testing and Certification: Before full restoration, the participant must complete appropriate testing and certification processes to demonstrate that remediated systems and processes meet Scheme requirements.
  • Phased Restoration: Restoration of participation privileges may follow a phased approach, starting with limited transaction types or volumes and gradually expanding to full participation as confidence in the remediation is established.

2) Termination


22. conditions and procedures

Termination of participation in the instant payment Scheme may be either voluntary or involuntary. Clear and well-defined conditions for both suspension and termination help ensure that a participant’s rights can be temporarily restricted or permanently revoked in a fair, transparent, and consistent manner.


23. Grounds for Involuntary Termination:

  • Failure to remediate issues leading to suspension within established timeframes.
  • Repeated suspensions demonstrating persistent inability to meet participation requirements.
  • Critical financial failure such as insolvency, bankruptcy, or license revocation
  • Severe or deliberate violations of Scheme rules that fundamentally undermine trust.
  • Prolonged inactivity or failure to maintain minimum participation requirements.


24. Termination Decision Process:

  • Formal recommendation from operational management based on documented evidence.
  • Review by relevant governance committees with appropriate participant representation.
  • Opportunity for the affected participant to present its case (except in extreme circumstances)
  • Final decision by authorized governance body according to established voting procedures.
  • Documentation of decision rationale and compliance with termination standards.


25. Voluntary Withdrawal Process

  • Formal notification requirements with minimum notice periods.
  • Wind-down planning to manage the transition for customers and counterparties
  • Final settlement and reconciliation processes
  • Return of collateral or guarantee fund contributions according to established timelines.


26. Managing Systemic Impact of Participant Exit:

  • Transaction Wind-Down Management: The Scheme should define clear and comprehensive processes to manage in-flight transactions and ongoing payment relationships during a participant’s exit—whether voluntary or involuntary. These processes should include:
  • Completion of Pending Transactions: Procedures for identifying and appropriately handling transactions that are in progress at the time of exit.
  • Management of Recurring Payment Arrangements: Protocols for terminating or transferring recurring payments and standing instructions to ensure continuity of service for end-users.
  • Customer Notification Requirements: Guidelines to ensure timely and effective communication to affected customers regarding service changes, alternative options, or disruptions.
  • Continuity for Sponsored Participants: For direct participants that sponsor indirect participants, the Scheme must ensure a smooth transition by facilitating the re-assignment of sponsored entities to new sponsors and minimizing service disruptions.
  • Customer Protection Measures: management procedures should incorporate specific customer protection elements, potentially including:
  • Standardized customer communication templates explaining the situation and next steps.
  • Minimum notice periods for service discontinuation where circumstances permit.
  • Facilitated processes for transferring payment relationships to other participants.
  • Special handling for vulnerable customers or critical payment services.
  • Systemic Risk Mitigation: For the exit of significant participants, the Scheme should establish coordinated risk management approaches with relevant authorities. This may include:
  • enhanced monitoring of other participants for potential contagion effects,
  • temporary liquidity support mechanisms, or adjusted settlement procedures during the transition period.
  • Contingency arrangements should be developed for scenarios involving the simultaneous exit of multiple participants during periods of market stress.

4. # Operational Rules

1. Instant Payment Product

1) The Concept of Instant Payment

Across jurisdictions, a range of terms is used to describe what is commonly referred to as instant payment, including real-time payment, immediate payment, and faster payment.

According to the Bank for International Settlements (BIS), Faster Payments are defined as: *“A payment in which the transmission of the payment message and the availability of final funds to the payee occur in real time or near-real time on a 24-hour and seven-day (24/7) basis as possible.”[^10]*

This definition emphasizes the speed of the clearing message and availability of funds to the payee, without necessarily requiring real-time interbank settlement. This Reference Guide adopts the BIS definition to guide the development of the instant payment ecosystem, with a focus on uninterrupted service, immediate funds availability, and user-centric functionality.

2) Key Features of Instant Payment

Instant payments offer a distinctive set of features designed to address modern market needs and provide a competitive edge over traditional instruments:

  • Speed: Transactions are processed and confirmed within seconds.
  • 24/7/365 Availability: Payments can be initiated and received at any time, including weekends and public holidays.
  • Credit Push Model: The payer initiates the transaction, offering enhanced control and reducing the risk of fraud.
  • Verification of Payee: Allows confirmation of the recipient’s identity before execution.
  • Positive Confirmation: Both payer and payee receive immediate notifications, enhancing trust and transparency.
  • Availability of Funds: Funds are irrevocably available to the payee once the payment is confirmed.
  • Proxy Services: Enable payments using simplified identifiers such as mobile numbers, email addresses, or national IDs.
  • Value-Added Services: Overlay services like Request to Pay and Payment Initiation Requests enhance flexibility and enable more complex use cases.

Instant payment schemes should ensure these features are embedded in their design to offer a tangible advantage over legacy payment systems.

3) Use Cases

Instant payment systems are versatile and support a wide range of transaction types across individuals, businesses, and government entities. Recognizing the distinct roles and requirements of each use case, dedicated operational guidelines should be established for each to ensure efficiency, security, and regulatory compliance.

  • Person-to-Person (P2P): P2P payments represent one of the most common use cases for instant payment systems, allowing individuals to transfer funds directly to one another. The following aspects should be considered for P2P:
  • Account Setup and Management: Effective account setup and management processes are critical to the security, compliance, and user experience of P2P payment services. Payment system operators must establish comprehensive guidelines for financial institutions and payment service providers to follow when onboarding users and managing their accounts throughout the customer lifecycle.
  • User Identification: Implement multiple options for recipient identification, including phone numbers, email addresses, and usernames, with appropriate privacy controls. Consider proxy addressing systems (refer to the section on proxy directory service for more details) that mask actual account details while enabling seamless transfers.
  • Transaction Limits: Establish daily, weekly, and monthly transaction limits based on user verification level. Consider implementing dynamic limits that adjust based on user behaviour patterns and risk scoring to balance security with convenience.

*

  • Person-to-Business (P2B): Person-to-Business (P2B) payments represent a critical use case for instant payment systems, enabling consumers to pay merchants to pay merchants or service providers instantly via QR codes, mobile POS, or e-commerce platforms, reducing cash dependence and improving merchant liquidity. P2B payments require special attention to merchant onboarding, verification, and management processes. The following aspects should be considered in the operational guidelines:
  • Merchant Onboarding: Operational guidelines must establish comprehensive procedures for the merchant verification process with risk-based due diligence and automated KYB checks, technical integration, and account setup while balancing security, compliance, and user experience considerations.
  • Merchant Management: Operational guidelines must establish comprehensive frameworks for ongoing merchant relationship management, performance monitoring, problem resolution, and commercial management throughout the merchant lifecycle.
  • Payment Acceptance: Multiple integration options including QR codes, USSD, mobile application, and POS systems.
  • Consumer Experience: Operational guidelines must establish frameworks that ensure consistency, security, and convenience throughout the consumer journey while accommodating the diverse contexts in which P2B payments occur.
  • Transaction Reporting: Comprehensive merchant dashboards with real-time sales data and analytics.
  • Settlement Process: Flexible settlement options with same-day availability and automated reconciliation.
  • Bill Payments: Facilitates timely and transparent payment of utilities, school fees, subscriptions, and more, with immediate posting and confirmation. Bill payment functionality requires integration with a wide range of billers including utilities, government agencies, educational institutions, and service providers. The following aspects should considered in the operational rules:
  • Biller Onboarding: Operational guidelines must establish comprehensive procedures for biller verification, technical integration, and account setup that address the unique characteristics of billers compared to traditional merchants.
  • Transaction Processing: Bill payment transaction processing within instant payment systems requires specialized operational procedures that address the unique characteristics of billing transactions. Unlike standard P2P or P2B payments, bill payments often involve additional data elements, validation requirements, and processing models that must be accommodated in the operational framework.
  • Recurring Payment Management: Recurring bill payment functionality represents an important capability within instant payment systems, allowing consumers to automate regular payments while giving billers greater certainty about revenue collection. Operational guidelines must establish comprehensive frameworks for managing the unique lifecycle and risk considerations associated with recurring payments.

*

  • Cash-In and Cash-Out Transactions: Cash-in and cash-out transactions represent critical bridge functionality between physical currency and digital payment systems, particularly important in markets with significant cash usage or limited banking infrastructure.

The instant payment context adds significant value to traditional cash-in/cash-out models by enabling real-time transaction settlement, immediate agent rebalancing, enhanced transaction verification, and improved liquidity management. When combined with Request to Pay functionality, instant payments can optimize the cash-out process by allowing agents to initiate payment requests to consumers, streamlining the interaction and reducing manual steps and potential errors.

The following key aspects should be considered in the Operational guidelines:

  • Agent Onboarding and Management: Operational guidelines must establish comprehensive frameworks for agent selection, verification, training, monitoring, and ongoing relationship management that address the unique risks and operational considerations associated with cash handling.
  • Transaction Processing: Cash transaction processing within instant payment systems requires specialized operational procedures that address the unique characteristics of physical currency handling combined with digital payment processing. Operational guidelines must establish comprehensive frameworks for the end-to-end transaction lifecycle while ensuring security, compliance, and positive customer experience.
  • Risk Management: Cash transaction risk management within instant payment systems requires specialized approaches that address the unique risks associated with physical currency handling combined with digital transaction processing. Operational guidelines must establish comprehensive frameworks for identifying, assessing, mitigating, and monitoring these compound risks while maintaining service accessibility and efficiency.
  • Agent Network Management: Effective agent network management is essential for building a sustainable, accessible, and efficient cash transaction ecosystem within instant payment systems. Operational guidelines must establish comprehensive frameworks for network planning, performance management, incentive structures, and continuous improvement that support both business objectives and financial inclusion goals.
  • Cross-border payment: Cross-border instant payments represent a significant evolution in the global financial ecosystem, enabling the rapid transfer of funds across international boundaries. Key operational considerations that Instant Payment System Operators, financial institutions, payment service providers, and regulatory bodies must address to implement effective cross-border instant payment systems:
  • Technical infrastructure: The foundation of any cross-border instant payment system is a robust technical infrastructure. It should support the ISO 20022 messaging standard, offer secure and scalable API connectivity, and enable seamless integration with key external systems, including but not limited to foreign exchange platforms, compliance and sanctions screening tools, and real-time fraud detection mechanisms.
  • Regulatory Compliance and Legal Frameworks: Cross-border: instant payments operate within a complex web of international and domestic regulations that vary significantly across jurisdictions. Financial institutions must navigate this regulatory landscape while ensuring compliance with anti-money laundering (AML) and counter-terrorism financing (CTF) requirements in all relevant countries.
  • Settlement Mechanisms and Liquidity Management: Effective settlement mechanisms are crucial for cross-border instant payments, as they ensure the finality of transactions and manage the financial risk between participating institutions.
  • Foreign Exchange and Currency Conversion: Currency conversion represents one of the most complex operational aspects of cross-border instant payments. Financial institutions must develop strategies to manage FX risk during off-market hours while still providing competitive exchange rates to customers.

2. Messaging Standards

Standardized messaging formats and protocols are fundamental to ensuring interoperability, efficiency, and future-proofing of instant payment Schemes. The Scheme should adopt internationally recognized message format standards where feasible, while considering local market requirements and existing infrastructure.

The globally recommended standard for financial messaging, offering rich data capabilities, extensibility, and future-proofing. ISO 20022 enables enhanced remittance information, structured addressing, and integration with other payment systems.

While ISO 20022 implementation may present initial complexity, particularly for institutions with legacy systems, its adoption aligns with global trends and supports future interoperability with regional and international payment systems.

1) Message Types:

The Scheme should define a comprehensive set of message types covering all aspects of transaction processing and Scheme operations, including:

Payments Initiation (pain): Messages that support the initiation of a payment from the ordering customer to a financial institution that services a cash account and reporting its status.

Payments Clearing and Settlement (pacs): Messages that support the clearing and settlement processes for payment transactions between financial institutions.

Cash Management (camt): Messages that support the reporting and advising of the cash side of any financial transactions, including cash movements, transactions and balances, plus any exceptions and investigations related to cash transactions.

Account Management (acmt): Messages that support the management of account related activities, such as the opening and maintenance of an account.

Administration (admi): Generic messages, ie, system event notifications, generic rejections, etc…

The SWIFT Instant Payments Plus (IP+)[^11] Working Group has developed comprehensive implementation guidelines that serve as a valuable resource for schemes adopting the ISO 20022 messaging standard. These guidelines provide best practices and technical specifications, helping payment schemes to successfully integrate instant payment solutions while ensuring compatibility with the global ISO 20022 framework.

2) Message Security and Validation:

Comprehensive message security standards must be established, including encryption requirements, digital signature standards, and message authentication controls. Detailed message validation rules should be defined, with clear procedures for handling message validation failures.

3) Instant Payment Processing

The processing of instant payments must ensure speed, security, and reliability across all transactions. The following illustrates key considerations that schemes should account for in defining their operational and technical rules. This list is not exhaustive and may evolve as the ecosystem matures:

  • Message Validation: All messages must conform to ISO 20022 and scheme-defined rules.
  • Payment Controls and Limits: Transaction caps and daily limits to manage risk and ensure compliance.
  • Transaction Timeouts: Payments must be completed within set timeframes; otherwise, they are treated as failed.
  • End-User Notification: Real-time confirmation or failure alerts must be sent to both payer and payee.
  • Finality of Payment: Once confirmed, payments are irrevocable and must be immediately settled.
  • Strong Authentication and Beneficiary Verification: Secure login and confirmation of recipient identity before execution.
  • Erroneous and Unauthorized Payments: Clear protocols must address dispute resolution and error handling.
  • Receiver Response Time: Receiving institutions must respond promptly to maintain real-time integrity.
  • Immediate Fund Availability: Funds must be credited and available to the payee instantly.

These considerations form the foundation for robust instant payment operations and support a consistent user experience across participants.

3. Proxy Directory Service

1) Functions

Proxy directory services represent a fundamental advancement in payment systems, enabling users to initiate and receive payments using familiar identifiers such as mobile numbers, email addresses, or national IDs instead of complex account numbers. This capability significantly enhances user experience, reduces payment friction, and drives adoption of digital payment solutions across various demographics.

The core function of a proxy directory is to maintain secure mappings between these user-friendly identifiers (proxies) and actual payment account information. When a user initiates a payment to a proxy, the system resolves this identifier to the corresponding account details, enabling the transaction to proceed through the payment infrastructure. This resolution process must occur in real-time, with high availability and robust security measures.

2) Key considerations


27. Types of Proxies and Standardization:

The system must support a clearly defined set of proxy identifiers that can be linked to payment accounts.

- These proxies should include common identifiers such as mobile phone numbers, email addresses, national IDs, and business identifiers.

- These identifiers must be familiar to users, widely available, and capable of uniquely identifying individuals or entities within the payment ecosystem.

- Each proxy type must undergo standardization to ensure consistency across the payment ecosystem, including defining format specifications, validation rules, and lifecycle management procedures.

- Furthermore, the scheme should establish clear guidelines for handling special cases such as recycled mobile numbers, expired IDs, or business closures to prevent misdirected payments or unauthorized access.


28. Registration and Deregistration Processes:

To maintain the integrity of a proxy directory service, secure, transparent, and auditable processes for managing the full lifecycle of proxy registrations must be established. This includes:

  • Registration:
  • Ensuring that only legitimate proxy-account mappings are created and maintained.
  • The registration process should capture explicit, informed customer consent before creating any proxy-account mapping, including, Identity verification, Account ownership validation
  • Clear disclosure of how the proxy will be used
  • Registration interfaces must present terms in plain language, with appropriate record-keeping of consent timestamps and channels.
  • Before activation, the system must verify both proxy ownership and account access rights through mechanisms such as One-time passwords or Account validation checks
  • Modification:
  • Users should be able to update their proxy-account mappings through secure channels, with Appropriate notifications and re-authentication to prevent unauthorized changes.
  • Deregistration:
  • The system must support immediate deregistration upon customer request, suspected fraud, account closure, or regulatory requirement, with Confirmation mechanisms, Cooling-off periods where necessary and Appropriate notifications


29. Proxy Resolution and Payment Generation:

Proxy resolution forms the core technical functionality of the directory service, converting user-friendly proxies into the payment account information needed to initiate transactions. This process must be reliable, fast, and precise to meet the demands of instant payment systems. The resolution process must incorporate error-handling capabilities to manage issues such as inactive proxies, deregistered proxies, or technical failures.


30. Proxy–Payment Account Relationship Models:

The relationship between proxies and payment accounts is a key design consideration with implications for user experience, system complexity, and risk management. Two primary models:

  • One-to-One Relationship: Each proxy identifier is linked to exactly one payment account. This model simplifies resolution logic, reduces ambiguity, minimizes routing errors, and ensures clear ownership of proxies.
  • Many-to-One Relationship: Multiple proxy identifiers may be linked to a single payment account, enabling users to register several proxies (e.g., personal and work email addresses) or businesses to create multiple entry points for payments.


31. Proxy Database Architecture:

  • A centralized proxy database consolidates all proxy-account mappings into a single logical database, operated by a scheme authority or designated service provider. This architecture ensures consistency, operational efficiency, and robust governance.
  • A decentralized proxy database distributes proxy-account mappings across participating institutions, offering benefits such as enhanced data sovereignty, reduced central infrastructure costs, and greater resilience against single-point failures. However, the decentralized model comes with challenges in data synchronization and ensuring consistent data quality across the ecosystem.


32. Information Exchange and Communication Standards:

All message exchanges within the proxy directory ecosystem must conform to standardized formats and structures, ideally aligned with the ISO 20022 messaging standard.

The message suite should include specialized formats for various functions, including proxy registration, modification, and deregistration requests, resolution queries and responses, error notifications, administrative commands, and reconciliation and audit verification messages.

The scheme should publish message definitions in formal schema repositories, with clear versioning and change management processes.



34. Settlement Model Options

  • Real-Time Gross Settlement (RTGS): Each transaction is settled individually and immediately on a gross basis, typically through the central bank RTGS system. This model eliminates settlement risk but requires 24/7 availability of the RTGS system, which may not be feasible in all African contexts. Key considerations include:
  • Maximum security with no settlement risk
  • High liquidity requirements for participants
  • Potential need for pre-positioning of funds if RTGS is not 24/7
  • Dependency on RTGS operating hours
  • Deferred Net Settlement (DNS): Transactions are accumulated over a defined period, with net positions settled periodically. This model is more liquidity-efficient but introduces settlement risk between settlement cycles. Key considerations include:
  • More efficient liquidity utilization
  • Settlement risk exposure between cycles
  • Need for risk mitigation measures (collateral, limits)
  • Easier implementation with existing infrastructure
  • Flexibility in settlement frequency (e.g., hourly, several times daily)
  • Hybrid Models: Some instant payment Schemes have implemented hybrid models combining elements of RTGS and DNS approaches:
  • Pre-funded Settlement Model: Participants maintain a dedicated settlement pool with prefunded balances. Transactions are settled continuously from this pool, with periodic replenishment.
  • Liquidity-Saving Mechanisms: Transactions are queued and settled in optimized batches when liquidity is available, reducing liquidity requirements while minimizing settlement delays.
  • Tiered Settlement: Different transaction types or value bands follow different settlement approaches, with high-value or high-risk transactions potentially settled in real-time while others use deferred settlement.


35. Settlement Institution:

The selected settlement model should balance risk management with practical implementation considerations, potentially evolving over time as infrastructure capabilities develop.

2) Settlement Cycles and Timing:

settlement timing and cycles are essential for managing liquidity and risk within the instant payment ecosystem. The approaches for settlement timing in instant payment Schemes are the following:


36. Settlement Cycle Definition

  • Frequency: Settlement cycles should be frequent enough to manage settlement risk while aligning with operational capabilities. Common approaches include hourly settlement during business hours, with less frequent cycles (e.g., every 3-4 hours) during nights and weekends.
  • Schedule: Fixed settlement schedules should be established, with precise timing of key settlement events including position calculation, settlement initiation, and completion confirmation.
  • Failure Handling: Clear procedures should be defined for handling settlement cycle failures, including retry attempts, escalation protocols, and contingency arrangements.


37. Settlement Windows:


38. Calendar Management

  • Regular business days and hours in all relevant jurisdictions
  • Official holidays and non-processing days
  • Scheduled maintenance periods for settlement systems
  • Modified settlement schedules for specific calendar events

This calendar should be published to all participants well in advance, with mechanisms for communicating changes or exceptional circumstances.


39. Position Reporting

  • Current net position relative to available liquidity
  • Projected positions based on pending transactions
  • Historical settlement patterns and peak positions
  • Notifications when positions approach defined thresholds

Settlement timings should be designed to balance risk management with operational efficiency, recognizing the infrastructure realities in different markets

3) Prefunding and Collateral

Robust prefunding and collateral arrangements are essential for managing settlement risk in instant payment Schemes, particularly those using deferred net settlement models. The recommended approaches for instant payment contexts.


40. Prefunding Requirements:

  • Prefunding Calculation: The methodology for determining minimum prefunding requirements should be clearly defined, potentially based on:
  • Historical net debit positions with appropriate multipliers
  • Statistical analysis of peak positions and volatility
  • Participant-specific risk factors and transaction patterns
  • Projected volume growth and seasonal variations
  • Funding Maintenance: Participants must maintain required prefunding levels throughout operating hours, with:
  • Real-time monitoring of available funds against requirements
  • Automatic alerts when positions approach thresholds
  • Clear procedures for topping up prefunding when needed
  • Consequences for failing to maintain required levels
  • Funding Adjustments: Processes for reviewing and adjusting prefunding requirements should be established.
  • Regular scheduled reviews (typically monthly or quarterly)
  • Event-triggered reviews following significant volume changes
  • Temporary adjustments for seasonal variations or special events
  • Appeal procedures for participants to request reconsideration.


41. Collateral Arrangements:

  • Eligible Collateral: Clearly defined criteria for acceptable collateral types, typically focusing on high-quality liquid assets such as government securities or central bank-eligible instruments.
  • Valuation Methodology: Transparent approaches for valuing collateral, including application of appropriate haircuts reflecting liquidity and market risk.
  • Collateral Management: Procedures for pledging, holding, and releasing collateral, potentially leveraging existing central bank collateral management systems.
  • Collateral Mobilization: Clear processes for accessing or liquidating collateral in the event of participant default, including legal frameworks ensuring timely execution.


42. Settlement Caps :

  • Net debit caps limit maximum exposure relative to available prefunding or collateral.
  • Transaction value limits for individual payments to manage concentration risk
  • Sender limits controlling total outgoing value within defined timeframes
  • Receiver limits controlling total income from specific counterparties

Prefunding and collateral requirements should be calibrated to balance risk management with liquidity efficiency, recognizing that excessive requirements may create barriers to participation or increase costs for end-users.

4) Liquidity Management Tools

Effective liquidity management is critical for participants in instant payment Schemes, enabling them to meet settlement obligations efficiently while optimizing funding costs. This section outlines recommended liquidity management tools and approaches for instant payment contexts.


43. Liquidity Forecasting

  • Historical Analytics: Detailed data on historical settlement patterns, peak positions, and cyclical variations to support trend analysis and forecasting
  • Projected Positions: Near-real-time projections of upcoming settlement positions based on in-flight transactions and historical patterns.
  • Early Warning Indicators: Alerts and notifications for unusual transaction patterns or emerging liquidity pressures.
  • Stress Testing Tools: Capabilities for simulating liquidity requirements under various stress scenarios


44. Intraday Liquidity Facilities:

  • Automated Liquidity Provision: Automated mechanisms for transferring liquidity between participant accounts, potentially including:
  • Automated sweeps between settlement and operational accounts.
  • Scheduled liquidity transfers aligned with settlement cycles
  • Threshold-triggered liquidity injections when positions approach defined limits.
  • Emergency Liquidity Support: Arrangements for addressing unexpected liquidity shortfalls, potentially including
  • Intraday credit facilities from the central bank
  • Collateralized liquidity lines between participants
  • Emergency liquidity pools funded by scheme participants
  • Procedure for requesting temporary cap increases or extensions


45. Participant Liquidity Management Interface:

  • Monitor current and projected settlement positions in real-time
  • View detailed breakdowns of incoming and outgoing payment flows
  • Configure automated liquidity management tools and alerts
  • Execute manual liquidity transfers when needed

Liquidity management tools should be designed with consideration for the diverse capabilities of African financial institutions, providing both sophisticated options for advanced participants and simpler tools for institutions with more limited resources.

5) Default Handling

Clear procedures for handling participant defaults are essential for maintaining settlement certainty and system stability. This section outlines recommended default management frameworks for instant payment Schemes.


46. Default Definition and Declaration

  • Failure to meet settlement obligations by specified deadlines
  • Regulatory intervention affecting participant's ability to operate
  • Insolvency or resolution proceedings against the participant
  • Expulsion from the Scheme due to rule violations or risk concerns

Formal procedures for default declaration must be established, specifying authority for making default determinations, required evidence, notification protocols, and appeal mechanisms where appropriate.


47. Immediate Response Measures:

  • Transaction Suspension: Immediate suspension of the defaulting participant's ability to submit new transactions to the system.
  • Position Calculation: Prompt calculation of the defaulter's final net position, including all accepted but unsettled transactions.
  • Resource Assessment: Evaluation of available resources to cover the defaulter's obligations, including prefunding, collateral, and guarantee arrangements.
  • Stakeholder Notification: Communication to other participants, regulatory authorities, and critical service providers regarding the default event.


48. Settlement Completion:

  • Prefunding Utilization: Application of the defaulter's prefunded balance toward outstanding obligations.
  • Collateral Liquidation: Execution of procedures to liquidate or apply available collateral if prefunding is insufficient.
  • Guarantee Fund Access: Utilization of any collective guarantee fund if established as part of the Scheme design.
  • Loss Allocation: Implementation of defined loss allocation mechanisms if prefunding, collateral, and guarantees are insufficient.


49. Operational Continuity:

  • Transfer of customer payment services to alternative providers
  • Special operating procedures for processing payments during transition period
  • Customer communication templates and channels for providing guidance

Default management procedures should be tested regularly through simulation exercises involving all relevant stakeholders, ensuring operational readiness for actual default scenarios.

5. Consumer Protection and Dispute Resolution

1) Core Principles

Robust consumer protection is fundamental to building trust in instant payment systems and driving adoption. This section outlines core consumer protection principles for instant payment Schemes.


50. Foundational Consumer Protection Principles:

  • Transparency: Consumers must receive clear, accessible information about instant payment services, including fees, processing times, and potential risks. Information should be provided in simple language appropriate for varying literacy levels, potentially in multiple languages for diverse markets.
  • Redress: Effective mechanisms must be available for resolving disputes and addressing errors. Procedures should be accessible to all consumers regardless of location or socioeconomic status.
  • Security: Robust security measures must protect consumers from unauthorized transactions and fraud. Security controls should be proportionate to risks while remaining usable for consumers with varying technical capabilities.
  • Privacy: Personal and financial data must be protected with clear limitations on collection, use, and sharing. Consumers should maintain appropriate control over their information while enabling necessary processing for service delivery.


51. Consumer Protection Policy Framework:

  • Minimum Standards: Clearly defined baseline protection requirements that all participants must implement, covering security controls, disclosure practices, complaint handling, and fraud management.
  • Participant Obligations: Specific responsibilities for protecting consumers at different stages of the payment journey, with clear allocation of accountability between originating and receiving institutions.
  • Scheme Monitoring: Mechanisms for assessing participant compliance with consumer protection requirements, potentially including customer experience metrics, complaint analysis, and targeted reviews.
  • Evolution Process: Structured approach for enhancing consumer protection measures based on emerging risks, incident patterns, customer feedback, and regulatory developments.
  • Minimum Standards: Clearly defined baseline protection requirements that all participants must implement, covering security controls, disclosure practices, complaint handling, and fraud management.

2) Transaction Transparency

Clear and accessible transaction information is essential for enabling consumers to make informed decisions and monitor their payment activities. This section outlines transaction transparency requirements for instant payment Schemes.


52. Pre-Transaction Disclosure:

  • Transaction Details: Clear presentation of essential transaction elements including recipient identity, amount, and purpose.
  • Fees and Charges: Transparent disclosure of all applicable fees, presented in absolute amounts rather than percentages where possible.
  • Execution Timeframe: Clear indication of when the funds will be available to the recipient.
  • Transaction Finality: Explicit notification about the irrevocable nature of instant payments once authorized.
  • Security Information: Contextual security guidance relevant to the specific transaction type or amount.


53. Transaction Confirmation:

ElementRequirement
Transaction ReferenceUnique identifier for the transaction that can be used for future inquiries or disputes
Transaction StatusClear indication of whether the transaction was completed successfully
Amount detailsConfirmation of the transaction amount, any fees deducted, and total amount debited
Recipient InformationConfirmation of the recipient's identity in a recognizable format
TimestampDate and time when the transaction was processed
Available BalanceRemaining account balance after the transaction (where applicable)

54. Transaction History:

  • Complete record of all instant payment transactions, accessible for at least a minimum period to be defined by the Scheme.
  • Multiple access channels, including mobile applications, online platforms, and statements.
  • Search and filtering capabilities to help locate specific transactions

3) Authentication Standards

Robust yet usable authentication standards are essential for ensuring that instant payments are authorized by legitimate users while maintaining accessibility.


55. Authentication Principles:

  • Risk-Based Approach: Authentication strength should be proportionate to transaction risk, considering factors such as amount, recipient, channel, and historical patterns.
  • Security-Usability Balance: Authentication mechanisms should provide meaningful security while remaining usable across different customer segments and device types.
  • Multi-Factor Authentication: High-risk transactions should require multiple authentication factors from different categories (knowledge, possession, inherence).
  • Inclusive Design: Authentication options should accommodate varying levels of technical capability, literacy, and device access.


56. Authentication Requirements

  • Base Authentication: Minimum requirements for standard transactions:
  • Unique identifier (username, phone number)
  • Secret knowledge factor (PIN, password)
  • Account lockout after failed attempts
  • Session management controls
  • Enhanced Authentication
  • Enhanced Authentication: Additional requirements for higher-risk transactions
  • Secondary verification (OTP, push notification)
  • Transaction verification details
  • Biometric verification where available
  • Device binding/recognition

4) Complaint Handling

Effective complaint handling procedures are essential for maintaining customer trust and resolving issues efficiently.


57. Complaint Handling Principles:

  • Timeliness: Complaints should be acknowledged and resolved within clearly defined timeframes appropriate to their nature and complexity.
  • Transparency: Customers should receive clear information about complaint procedures, progress updates, and rationale for decisions.
  • Accessibility: Complaint channels should be accessible to all customers regardless of location, technical capability, or literacy level.
  • Fairness: Complaint assessment should be objective and consistent, with equitable outcomes based on established principles.


58. Participant Requirements:

  • Multiple Access Channels: Provision of various complaint submission methods, including in-person, phone, digital, and potentially USSD for feature phone users.
  • First Response Timelines: Maximum timeframes for initial acknowledgment (typically 24-48 hours) and provisional assessment of complaints
  • Investigation Standards: Structured approach to complaint investigation, including evidence collection, transaction tracing, and root cause analysis
  • Resolution Timeframes: Maximum periods for completing investigations and providing final responses (typically 5-15 days for standard complaints).
  • Documentation Requirements: Standards for recording complaint details, investigation steps, and resolution outcomes.

iii. Dispute Management and Escalation Framework: In addition to participant-level complaint handling mechanisms, the Scheme should establish a structured framework for escalating unresolved disputes. This ensures timely and fair resolution of issues that may arise between participants, between a participant and a customer, or between a participant and the Scheme Manager.

The escalation process should follow a progressive, tiered approach designed to resolve issues at the lowest appropriate level while ensuring fairness and transparency for more complex cases.

The table below presents an illustrative escalation pathway that Scheme Managers and participants may adapt based on institutional arrangements, regulatory requirements, and the specific nature of the dispute.

Escalation LevelResponsible PartyExample Use CasesIllustrative TimeframeTypical Resolution Mechanism
Level 1 – Participant ResolutionCustomer support or operations team of the initiating or receiving participantEnd-user complaints, transaction errors, failed payment reversalsWithin 2 business daysResolved through the institution’s standard complaint process
Level 2 – Bilateral CoordinationDesignated focal points of involved participantsDisputes between participants (e.g., misrouted payments, unmatched transactions)Within 5 business daysJoint investigation and resolution using scheme-aligned procedures
Level 3 – Scheme-Level FacilitationScheme Manager or designated dispute unitEscalated disputes, repeated failures, or non-compliance with agreed proceduresWithin 7–10 business daysMediation or guided facilitation by the Scheme Manager, with documented decisions
Level 4 – Independent DeterminationAppointed expert or neutral panelComplex, high-value, or sensitive disputes not resolved at scheme levelWithin 20 business daysIndependent review and binding recommendation based on scheme rules and documentation
Level 5 – Regulatory Referral (if applicable)Relevant financial regulator or consumer protection authorityRegulatory breaches, systemic non-compliance, or unresolved customer protection issuesPer regulatory guidelinesEscalated to competent authority under national legal or supervisory frameworks

5) Fraud Protection and Liability

Clear frameworks for fraud protection and liability allocation are essential given the immediate and irrevocable nature of instant payments.


59. Customer Fraud Protection Measures:

  • Preventive Controls: Measures to prevent fraudulent transactions:
  • Risk-based transaction screening
  • Payee confirmation requirements
  • New beneficiary cooling periods
  • Transaction value limits
  • Unusual activity detection
  • Customer Empowerment: Tools enabling customers to control their security:
  • Customizable transaction limits
  • Real-time transaction notifications
  • Temporary service freezes
  • Customer Education: The Scheme should establish requirements for customer education on fraud risks:
  • Clear information about common fraud scenarios and warning signs
  • Contextual security messages at key transaction points
  • Regular fraud awareness updates through appropriate channels
  • Targeted education for vulnerable customer segments
  • Practical guidance on security measures customers can implement.


60. Liability Framework:

Table 6: Liability scenarios

ScenarioTypical Liability Approach
Unauthorized Transactions (Account Compromise)Participant liability unless customer negligence can be demonstrated (burden of proof on participant
Authorized Push Payment Fraud (Social Engineering)More complex determination based on whether the participant provided adequate warnings and whether the customer followed security guidance.
Technical Error or System VulnerabilityLiability typically rests with the participant or Scheme responsible for the compromised system.
Merchant Fraud (Non-Delivery of Goods/Services)Typically outside the liability framework of the payment system, though consumer guidance should be provided.

61. Fraud Recovery Processes:

  • Rapid response protocols when fraud is reported, including immediate recipient bank notification
  • Processes for freezing funds in recipient accounts when legally permissible
  • Standardized information sharing protocols for fraud investigations
  • Coordination mechanisms with law enforcement agencies

Fraud protection and liability frameworks should balance consumer protection with practical implementation considerations in African markets, recognizing variations in regulatory requirements, technical capabilities, and customer awareness levels.

6) Data Protection:

Strong data protection frameworks are essential for maintaining customer trust and complying with evolving privacy regulations.


62. Data Protection Principles:

  • Purpose Limitation: Personal data should only be collected and processed for specified, explicit, and legitimate purposes related to payment processing and associated services. Secondary uses should require specific consent or other legal basis.
  • Data Minimization: Only data necessary for the specific purpose should be collected and retained. Payment systems should avoid collecting excessive information not required for transaction processing or risk management.
  • Transparency: Customers should receive clear information about how their data is collected, used, shared, and protected, with appropriate consent mechanisms for discretionary processing activities.
  • Security: Appropriate technical and organizational measures must protect personal and financial data against unauthorized access, loss, or alteration throughout the data lifecycle.


63. Data Protection Requirements:

  • Privacy Notices: Clear, accessible information about data processing activities, presented in understandable language appropriate for varied literacy levels.
  • Consent Management: Mechanisms for obtaining and recording valid consent for discretionary processing, with appropriate options for consent withdrawal.
  • Data Security: Comprehensive controls protecting data during transmission, processing, and storage, including encryption, access controls, and monitoring systems.
  • Data Retention: Clear policies defining retention periods for different data types, with secure deletion or anonymization at the end of necessary retention.
  • Data Subject Rights: Procedures for handling access requests, correction requirements, and other data subject rights under applicable regulations.


64. Data Sharing Governance:

  • Inter-Participant Sharing: Clear rules for data sharing between participants for transaction processing, risk management, and dispute resolution.
  • Third-Party Processing: Requirements for participant agreements with service providers who process customer data, ensuring equivalent protection levels.
  • Regulatory Disclosure: Protocols for sharing data with regulatory authorities for compliance, oversight, and financial intelligence purposes.
  • Cross-Border Transfers: Safeguards for transferring data across national borders, particularly relevant for regional payment systems.


65. Data Breach Management:

  • Clear definition of what constitutes a reportable data breach
  • Notification requirements and timelines for participants to report breaches to the Scheme
  • Procedures for notifying affected customers and relevant authorities
  • Requirements for breach investigation and remediation

Data protection frameworks should align with relevant data protection regulations while recognizing practical implementation challenges in diverse markets.

6. Technical Infrastructure and Security

1) System Architecture

A robust, secure, and scalable technical architecture is the foundation of any successful instant payment Scheme.


66. Architectural Principles:

  • Performance: Architecture designed to deliver consistent low-latency transaction processing under varying load conditions.
  • Security: Security-by-design approach with defense-in-depth and principle of least privilege embedded at all levels.
  • Scalability: Capacity to scale horizontally and vertically to accommodate growing transaction volumes and participant numbers.
  • Resilience: Ability to maintain operations despite component failures, with no single points of failure in critical paths.


67. Core System Components:

  • Switching Infrastructure: Central processing hub responsible for routing transactions between participants, applying Scheme rules, and coordinating the end-to-end transaction lifecycle should include redundant processing capabilities with load balancing and automatic failover.
  • Settlement Engine: System component managing the settlement process, including calculation of positions, management of settlement windows, and interaction with the settlement institution must maintain absolute data integrity with comprehensive reconciliation capabilities.
  • Participant Interfaces: Communication gateways enabling participant connectivity to the central infrastructure, supporting defined message formats and security protocols should accommodate varying participant technical capabilities.
  • Support Systems: Auxiliary components providing essential functions such as participant management, fraud monitoring, reporting, billing, and administrative interfaces must integrate seamlessly with core processing components.


68. Deployment Models

  • On-Premises Deployment: Traditional approach with dedicated physical infrastructure in controlled data centers, offering maximum control but requiring significant capital investment and specialized operational expertise.
  • Private Cloud: Virtualized infrastructure deployed on dedicated resources, providing greater flexibility and resource optimization while maintaining strong control over the environment.
  • Hybrid Models: Combination of on-premises critical components with cloud-based supporting systems, potentially offering an optimal balance for many African contexts.
  • Public Cloud: Leveraging third-party cloud infrastructure for rapid deployment and cost-efficiency, though requiring careful security assessment and potential regulatory approval.

The chosen architecture should balance international best practices with practical considerations relevant to African markets, including infrastructure reliability, skills availability, and regulatory requirements.

2) Connectivity and Integration

Reliable, secure connectivity between participants and the central system is critical for instant payment Scheme operation.


69. Connectivity Models:

  • Primary Connectivity: Main connectivity channel for transaction processing:
  • Dedicated private network connections offering maximum security and reliability
  • MPLS ((Multiprotocol Label Switching) ) or similar managed network services with guaranteed quality of service.
  • Secure VPN tunnels over public internet where dedicated connections are not feasible.
  • End-to-end encryption regardless of underlying network infrastructure.
  • Backup Connectivity: Redundant channels for business continuity:
  • Independent secondary connections using different technologies and providers.
  • Automatic failover mechanisms with minimal switching time
  • Regular testing of backup channels to ensure readiness
  • Alternative routing arrangements for critical transaction types
  • Dedicated private network connections offering maximum security and reliability.


70. Network Architecture:

  • Network Segmentation: Logical separation of different functional domains with controlled interfaces between segments.
  • Defense in Depth: Multiple security controls at different network layers, including firewalls, intrusion detection/prevention systems, and traffic filtering.
  • Secure Access Management: Strictly controlled network entry points with comprehensive authentication, authorization, and audit mechanisms.
  • Traffic Monitoring: Real-time monitoring of network traffic patterns with anomaly detection and alerting capabilities.


71. Integration Approaches:

  • Direct API Integration: API-based integration using standardized interfaces, enabling flexible, efficient system-to-system communication with comprehensive security controls.
  • Middleware Solutions: Integration adapters or middleware components that translate between the Scheme's messaging standards and participants' internal systems, simplifying integration for institutions with legacy systems.
  • Web Portal Access: Web-based interfaces for smaller participants or those with limited technical capabilities, offering essential functionality through secure browser-based access.


72. Integration Standards:

  • Detailed API specifications with complete documentation, reference implementations, and test environments.
  • Consistent error handling and status reporting conventions across all interfaces.
  • Version management procedures for managing API evolution while maintaining backward compatibility.
  • Performance requirements, including response times, throughput capabilities, and availability expectations.

Connectivity and integration approaches should recognize the varying technical maturity of African financial institutions, providing accessible options for less sophisticated participants while enabling efficient integration for advanced institutions.

3) Processing Capacity and Performance

Adequate processing capacity and consistent performance are essential for reliable instant payment services.


73. Capacity Planning

  • Baseline Capacity: Initial capacity should accommodate projected transaction volumes with substantial headroom (e.g. 200-300% of expected peak volumes) to address unexpected growth and usage spikes.
  • Growth Projections: Capacity planning should incorporate detailed growth projections considering factors such as participant onboarding, new use cases, seasonal variations, and market development initiatives.
  • Stress Testing: Regular stress testing should validate system performance under extreme conditions, including sustained high volumes and sudden traffic spikes.
  • Scalability Planning: Clear roadmaps for horizontal and vertical scaling should be established, with defined triggers for capacity expansions based on utilization thresholds and growth rates.


74. Performance Requirements:


75. Performance Optimization:

  • Efficient Architecture: System design optimized for high-throughput transaction processing, with efficient data flows and minimal processing overhead.
  • Resource Allocation: Appropriate allocation and tuning of computing resources across different system components based on operational patterns.
  • Caching Strategies: Intelligent use of caching for frequently accessed data to reduce database load and improve response times.
  • Database Optimization: Database design and tuning focused on transaction processing efficiency, with appropriate indexing, partitioning, and query optimization.
  • Database Optimization: Database design and tuning focused on transaction processing efficiency, with appropriate indexing, partitioning, and query optimization.


76. Performance Monitoring:

  • Real-time monitoring of key performance indicators across all system components.
  • Historical performance analysis to identify trends and patterns.
  • Automated alerting when performance metrics approach defined thresholds.
  • End-to-end transaction tracing to identify performance bottlenecks.
  • Regular performance reporting with detailed metrics and improvement recommendations.

4) Data Management

Effective data management is critical for maintaining transaction integrity, supporting operational needs, and meeting regulatory requirements.


77. Data Architecture:

  • Data Models: Clearly defined data models for all critical information domains, with standardized structures, relationships, and validation rules.
  • Data Classification: Structured classification of data based on sensitivity, criticality, and regulatory requirements, with appropriate handling requirements for each category.
  • Data Lifecycle: Defined policies for data creation, storage, retention, archiving, and destruction aligned with business needs and regulatory requirements.
  • Data Integration: Coherent approach to data sharing and synchronization between different system components and external interfaces.


78. Database Management:

  • Database Technology: Selection of appropriate database technologies optimized for transaction processing, considering requirements for throughput, consistency, and availability.
  • High Availability: Database architecture ensuring continuous operation despite component failures, potentially including clustering, replication, and automated failover.
  • Data Integrity: Comprehensive mechanisms for maintaining data accuracy and consistency, including constraint enforcement, transaction management, and verification procedures.


79. Data Security:

  • Access Controls: Granular data access management:
  • Role-based access control;
  • Principle of least privilege;
  • Segregation of duties;
  • Privileged access management;
  • Regular access reviews.
  • Data Protection: Protective measures for data:
  • Encryption for data at rest;
  • Encryption for data in transit;
  • Secure key management;
  • Data masking for sensitive fields;
  • Secure disposal procedures.
  • Data Retention and Archiving: Clear policies for data lifecycle management:
  • Retention periods defined for different data types based on operational needs and regulatory requirements.
  • Structured archiving processes for data that must be retained but not frequently accessed.
  • Secure, verifiable data destruction when retention periods expire.
  • Data retrieval capabilities for archived information when needed for investigations or compliance.

Data management approaches should balance international best practices with practical considerations relevant to African markets, including infrastructure limitations, skills availability, and specific regional regulatory requirements.

5) Security Requirements

Comprehensive security controls are essential for protecting instant payment systems against evolving threats. This section outlines security requirements for Instant Payment Scheme.


80. Security Governance:

  • Security Policy Framework: Comprehensive policies covering all aspects of information security, aligned with international standards (e.g., ISO 27001) and adapted to payment system requirements
  • Security Organization: Clearly defined security roles and responsibilities, with appropriate segregation of duties and independent security oversight
  • Risk Assessment: Structured security risk assessment processes, including threat modeling, vulnerability assessment, and risk treatment planning
  • Security Metrics: Defined security performance indicators (see annex 3) with regular measurement and reporting to governance bodies.


81. Technical Security Controls:

  • Perimeter Security: Network boundaries protected by multiple defense layers
  • Network Security: Secure network design with segmentation and traffic control
  • System Security: Hardened infrastructure with minimal attack surface
  • Application Security: Secure development practices and runtime protection
  • Data Security: Protection for sensitive information at all stages


82. Cryptographic Requirements:

  • Encryption Standards: Use of industry-standard encryption algorithms and appropriate key lengths for different security contexts.
  • Key Management: Secure processes for cryptographic key generation, distribution, storage, rotation, and revocation.
  • Digital Signatures: Implementation of non-repudiation mechanisms for critical transactions using digital signature technologies.
  • Secure Storage: Protection of cryptographic materials using hardware security modules or equivalent controls.


83. Security Monitoring and Incident Response:

  • Security Monitoring: Real-time monitoring of security events across network, system, and application layers, with correlation and analytics to identify potential threats.
  • Threat Intelligence: Integration of threat intelligence to enhance detection capabilities for emerging attack patterns.
  • Incident Management: Structured processes for security incident handling, including detection, classification, containment, eradication, recovery, and post-incident analysis.
  • Incident Management: Structured processes for security incident handling, including detection, classification, containment, eradication, recovery, and post-incident analysis.

6) Disaster Recovery

Robust disaster recovery capabilities are essential for ensuring business continuity in the face of significant disruptions. This section outlines disaster recovery frameworks for instant payment Schemes:


84. Disaster Recovery Strategy:

  • Risk Assessment: Structured assessment of potential disaster scenarios that could impact system operations, including natural disasters, infrastructure failures, cyber attacks, and other major disruptions. The assessment should consider the specific risk landscape in relevant African regions.
  • Recovery Strategy: Overall approach to recovery, determining whether to implement hot, warm, or cold recovery sites, considering factors such as cost, complexity, and recovery time requirements. Given the critical nature of payment systems, hot or warm standby approaches are typically required.
  • Recovery Objectives: Clearly defined recovery targets including Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for different system components. Critical payment functions typically require RTOs of less than 30 minutes and RPOs approaching zero data loss.
  • Recovery Priorities: Defined sequence for system recovery, identifying the most critical functions that must be restored first, typically focusing on core transaction processing and settlement functions before administrative capabilities.


85. Disaster Recovery Infrastructure:

  • Recovery Sites: Geographically distributed alternative processing locations with sufficient separation to mitigate regional disasters yet close enough to manage effectively.
  • Data Replication: Mechanisms for maintaining synchronized data between primary and recovery environments, with appropriate replication frequency based on RPO requirements.
  • Network Redundancy: Diverse network paths connecting to the recovery site, potentially using different carriers and technologies.
  • Infrastructure Equivalence: Recovery environment with processing capabilities equivalent to the primary environment, or at minimum sufficient to handle critical functions.


86. Recovery Procedures: Detailed recovery procedures must be established:

  • Disaster Declaration: Criteria and authority for formally declaring a disaster and invoking recovery procedures, with clear decision-making protocols.
  • Failover Execution: Step-by-step procedures for activating the recovery environment, including technical operations and communication activities.
  • Operational Transfer: Processes for transferring operations to the recovery site, including staff relocation or remote access arrangements.
  • Verification: Procedures for confirming successful recovery, including system integrity checks and functional testing.

7) AI-Driven Fraud Management for Instant Payment Systems


87. Background

As instant payment systems (IPS) become increasingly embedded in daily financial activity, the need for advanced, real-time fraud detection is more critical than ever. The irrevocable nature and speed of instant payments heighten the risk exposure, making early detection and rapid response essential.

Traditionally, fraud detection relied on static rules, manual reviews, and post-transaction analysis. While effective in certain contexts, these legacy systems struggle to detect complex fraud patterns or adapt to evolving tactics such as social engineering and authorized push payment (APP) fraud.

The emergence of Artificial Intelligence (AI) and Machine Learning (ML) has revolutionized the fight against financial fraud. AI-powered systems can process large volumes of transaction data in real time, detect anomalies, learn from new fraud patterns, and enable predictive threat identification all at the speed IPS demands.

While this reference guide remains technologically neutral, allowing implementers the flexibility to choose solutions suited to their context, the recommendation of AI-driven fraud management solutions is motivated by the unique challenges of instant payments, particularly their speed, irrevocability, and exposure to sophisticated fraud schemes.

As IPS expand to serve a broader, more inclusive user base, including previously underserved populations, fraud vectors such as social engineering, synthetic identity fraud, and coordinated network abuse are on the rise. These challenges necessitate more adaptive and intelligent approaches to fraud detection, beyond what traditional systems can offer.


88. Use Cases of AI in Fraud Detection for IPS

AI can be applied across the entire transaction lifecycle in IPS to detect and prevent various types of fraud. Key use cases include:

  • Real-time transaction scoring: Assigning risk scores to each transaction based on behavioral, contextual, and historical data.
  • Anomaly detection: Identifying out-of-pattern transactions that deviate from a user’s typical behavior.
  • APP (Authorized Push Payment) fraud prevention: Detecting indicators of manipulation, coercion, or unusual behavioral changes that may precede APP fraud.
  • Account takeover detection: Monitoring access and authentication patterns to flag suspicious logins or device changes.
  • Synthetic identity and impersonation fraud: Using AI to detect fake accounts and bot-driven attacks.
  • Merchant and agent fraud: Monitoring for unusual behavior such as abnormal settlement frequency, split transactions, or excessive refunds.
  • Network-level fraud detection: Correlating fraud signals across participants to detect coordinated attacks or mule account networks.


89. Why AI is Better Suited for Instant Payment Fraud Detection:

  • Limitations of the Traditional Rule-Based Fraud Detection?

Traditional fraud detection systems in payment ecosystems have primarily relied on *rule-based* mechanisms, predefined sets of conditions that trigger alerts or block transactions (e.g., transaction amount exceeding a threshold, activity from blacklisted IP addresses, or unusually high frequency within a short timeframe). While these systems have played an essential role in early fraud management, they present significant limitations in the context of real-time and increasingly sophisticated fraud typologies targeting IPS.

Key Limitations of Traditional Rule-Based Approaches:

  • Static and Reactive: Rule-based systems rely on known fraud patterns and predefined thresholds. They are inherently reactive and struggle to detect novel or evolving fraud tactics such as synthetic identity fraud or socially engineered APPs.
  • High False Positives: Because rules are often broad to ensure caution, many legitimate transactions get flagged unnecessarily. This leads to user frustration, operational inefficiencies, and reputational risk for providers.
  • Maintenance Burden: Updating and fine-tuning rule sets requires constant human intervention and expert input. This leads to increased operational costs and slow adaptation to emerging threats.
  • Lack of Contextual Understanding: Rule engines typically evaluate transactions in isolation. They are unable to consider complex patterns over time, behavioral profiles, or relationships across entities.
  • Scalability Challenges: As transaction volumes grow, rule systems become harder to manage without introducing inefficiencies, redundancy, or system latency.
  • Capability of the AI-driven fraud management platform

AI-driven solutions offer a *proactive, dynamic, and scalable* alternative that aligns with the real-time, high-volume, and trust-dependent nature of IPS. The key advantages include:

  • Behavioral Risk Modeling: AI evaluates transactions in the context of a user's historical behavior, enabling personalized risk assessment that rules cannot deliver.
  • Adaptive Learning: AI models continuously learn from new data and feedback (fraud labels, customer disputes, transaction outcomes), enabling quicker adaptation to emerging fraud tactics.
  • Multidimensional Analysis: AI can simultaneously assess hundreds of features such as device metadata, transaction velocity, geolocation patterns, and peer-to-peer relationships within milliseconds.
  • Lower False Positives, Higher Detection Rates: By identifying subtle, nonlinear patterns, AI significantly reduces false positives while improving true fraud detection accuracy.
  • Real-Time Scalability: AI platforms are built to operate at massive scale without degrading performance, making them suitable for national IPS platforms with high throughput demands.

It is important to note that AI does not necessarily replace rules-based systems. In practice, hybrid models are often adopted, where AI models score transactions, and business rules guide final decisions, especially for regulatory compliance, alert prioritization, or specific risk policies.


90. Solution Architecture Overview

An AI-driven fraud detection platform for IPS typically includes the following components:

  • Data Ingestion Layer: Aggregates transaction data, device metadata, behavioral signals, and third-party risk indicators in real-time.
  • Feature Engineering Engine: Transforms raw data into meaningful attributes for modeling, such as transaction velocity, geo-location anomalies, and device fingerprinting.
  • Model Scoring Engine: Applies trained AI/ML models to assess transaction risk in milliseconds.
  • Decision Engine: Uses model outputs and business rules to determine actions, e.g., approve, hold, or decline transactions.
  • Alert & Investigation Module: Generates alerts for flagged transactions and provides explainability for analysts.
  • Feedback & Learning Loop: Continuously updates models with outcomes to improve detection accuracy.

The platform may be hosted centrally by the IPS operator (e.g., scheme-level AI fraud service) or deployed within participants’ environments with data-sharing arrangements under a federated model.


91. Success Factors for Implementing AI-Driven Fraud Solutions

The successful deployment of AI-driven fraud detection in Instant Payment Systems depends not only on technical capabilities but also on ecosystem readiness, governance maturity, and data stewardship. The following prerequisites and success factors should be considered by scheme managers, system operators, and participants before or during implementation:

Success FactorDescription
Data Quality & AvailabilityAI models require large volumes of accurate, timely, and well-structured data for effective training, scoring, and learning
Data Sharing and Interoperability FrameworksEffective fraud detection often requires real-time data sharing among participants. Secure APIs, shared intelligence layers, and data anonymization techniques support this.
Skilled Human CapitalSpecialized skills are needed in data science, fraud analytics, compliance, and AI model management. Institutions should invest in continuous capacity-building and cross-functional collaboration.
Model Governance and Regulatory ComplianceInstitutions must adopt model risk management frameworks covering validation, explainability, fairness, and compliance with data protection laws.
Real-Time Integration and System ReadinessAI fraud systems must be seamlessly integrated with the IPS transaction flow, supporting real-time decisioning without degrading user experience or performance.
Risk Appetite and Threshold CalibrationParticipants must define acceptable risk levels and set transaction blocking, alerting, or escalation thresholds accordingly.
Ongoing Learning and Feedback LoopsEffective fraud detection depends on continuous learning from confirmed fraud cases, false positives, and user feedback to improve model accuracy.

92. Scheme Rule Considerations

To ensure the effective and coordinated implementation of AI-based fraud detection solutions across all participants, the Instant Payment Scheme Rules should incorporate clear provisions addressing governance, obligations, data sharing, accountability, and technical standards. These provisions help drive consistent fraud responses, ecosystem-wide learning, and alignment with regulatory and ethical expectations.

Key considerations include:

  • Minimum Fraud Management Standards: Define baseline capabilities expected of participants, such as real-time screening, use of adaptive fraud detection tools, and periodic updates of detection models based on emerging threats.
  • Roles and Responsibilities: Clarify the responsibilities of the Scheme Manager, System Operator, and Participants in fraud detection, investigation, model updates, and response coordination.
  • Real-Time Screening Requirements: Mandate or recommend that participants implement real-time fraud screening mechanisms, enabling timely flagging and blocking of suspicious transactions.
  • Data Sharing and Privacy: Specify categories of permissible data (e.g., behavioral, transactional, device-based) for fraud analytics and outline secure data-sharing protocols across participants. Provisions must align with applicable privacy and data protection laws, enabling cross-institutional intelligence without compromising user rights.
  • Model Governance: Require documentation of model architecture, logic, thresholds, validation procedures, and periodic performance reviews. Models must be explainable and auditable to ensure fairness, prevent discriminatory outcomes, and support regulatory oversight.
  • Fraud Reporting and Escalation: Mandate standardized reporting of fraud incidents, including timeliness, format, and content. Define escalation procedures for high-impact or systemic fraud cases requiring centralized coordination.
  • SLAs for Fraud Flagging and Blocking: Establish minimum performance benchmarks for fraud detection and mitigation actions—such as latency limits for scoring and blocking suspicious transactions within milliseconds to preserve the real-time nature of the system.
  • Liability Framework: Define how liability is allocated in cases of fraud-related losses, especially distinguishing between centralized fraud management models (operated by the scheme or central system) and participant-level models. This includes clarity on false positives, detection gaps, and user redress processes.
  • Incentives and Sanctions: Provide mechanisms for rewarding institutions that demonstrate strong fraud control performance (e.g., fewer incidents, effective model management) and penalizing those failing to meet minimum standards or compliance obligations.
  • Hybrid Decisioning Approaches: Recognize that AI models may be best used in combination with rule-based systems, particularly for regulatory compliance, exception handling, or policy enforcement. Scheme rules may recommend this hybrid architecture as a best practice.
  • Capacity Building and Certification: Promote regular training and professional development for fraud analysts, AI model developers, and risk teams. Where applicable, require certification or qualification standards for operating AI-based fraud detection systems.
  • Collaboration and Feedback Loops: Encourage mechanisms for participant collaboration, including joint intelligence platforms, fraud typology sharing, and structured feedback loops to retrain AI models and improve system-wide fraud resilience.

5. User experience guideline

The Scheme should issue a User Experience (UX) Guideline that provides foundational standards for Participants developing user-facing applications and services within the Instant Payment ecosystem. Adhering to these principles and obligations will ensure a consistent, secure, and user-friendly experience, thereby fostering user trust and accelerating adoption across the ecosystem.

1. Foundational Principles

User-facing applications and services within the Instant Payment Scheme should be built upon the following core principles:

  • User-Centricity: Design decisions must prioritize understanding and solving real user needs and pain points related to instant payments. User research and feedback should inform all stages of development.
  • Accessibility: Payment services must be designed to be usable by individuals with diverse abilities and in various contexts (e.g., varying levels of digital literacy, different device capabilities, and environmental conditions).
  • Usability: Interfaces must be intuitive, easy to navigate, and require minimal learning. Clear information architecture, consistent design patterns, and user-friendly workflows are essential.
  • Usefulness: Features and functionalities offered must meet genuine user needs and provide tangible value in the context of instant payments. Avoid implementing features that are technically complex but offer limited practical benefit.
  • Credibility and Desirability: User interfaces and communication must build trust through reliable information, transparent processes, and an appealing design that aligns with the Scheme's brand and values.
  • Consistency: A coherent and predictable user experience must be maintained across all touchpoints, including different devices, channels, and applications offered by Participants. Consistent design language, terminology, and workflows are crucial.

2. Guidance to Participants

Participants developing user-facing applications and services for the Instant Payment Scheme should adhere to the following obligations:

1) Application Design and Navigation: A well-designed application interface is essential for delivering a seamless and inclusive user experience. Participants must ensure that their digital channels are intuitive, coherent, and accessible across all user devices. The following principles should be applied:

  • Intuitive Navigation: Applications must provide clear and consistent navigation pathways, allowing users to easily locate and access core functionalities such as initiating payments, viewing transaction history, and managing account details.
  • Clarity and Simplicity: Information must be presented using simple language and a concise format. Technical jargon should be avoided or clearly explained to promote understanding across a broad user base, including those with limited financial or digital literacy.
  • Responsive Design: User interfaces must adapt seamlessly to a range of devices and screen sizes (e.g., smartphones, tablets, desktops), ensuring consistency and usability across platforms.
  • Visual Coherence and Branding: The application’s visual design should be clean and uncluttered. Participants should align with the Scheme's branding and accessibility guidelines to promote familiarity and trust.
  • Guided User Flow and Feedback: Clear visual cues (e.g., progress indicators, confirmation messages, error highlights) must guide users through the payment journey, from initiation to completion. Feedback mechanisms should be immediate and informative, helping users understand system responses or required actions.
  • Inclusivity Considerations: Participants must ensure that application design, communication channels, and service delivery approaches are inclusive of underserved populations, particularly women and users in rural or remote areas. To this end:
  • Usability testing should incorporate gender and rural representation to ensure solutions are practical for all demographics;
  • Interfaces and communications should support local languages and reflect cultural contexts;
  • Agent networks or assisted digital channels should be leveraged to increase physical reach;
  • Digital skills training or simplified user modes should be considered to support users with limited digital proficiency.

2) Payment Initiation Methods: Participants' applications must offer users multiple methods for initiating instant payments to cater to diverse user preferences and scenarios, including:

  • Account Number Input: Allowing users to manually enter the recipient's account number. Clear guidance on the required format should be provided.
  • Proxy Lookup and Selection: Seamless integration with the Scheme's proxy directory service, enabling users to search and select recipients using their registered aliases (mobile number, email, national ID, etc.). Clear display of the recipient's verified name (where available) is required.
  • QR Code Scanning: Functionality to scan QR codes generated by recipients for payment initiation. Clear visual cues and instructions for scanning should be provided.

3) User Communication Standards: All user-facing communication related to instant payments must adhere to the following standards:

  • Success, Error, and Guidance Messages:
  • Provide clear and concise messages confirming successful transactions.
  • Display informative and actionable error messages that help users understand and resolve issues. Avoid technical error codes.
  • Offer contextual guidance and tips to assist users throughout the payment process.
  • Mandatory Nomenclature: Participants must use the standard terminology defined by the Instant Payment Scheme for key actions, statuses, and features to ensure consistency across the ecosystem.
  • Notification of Suspicious Transactions: Implement clear and timely mechanisms to notify users of potentially suspicious transactions and guide them on necessary actions (e.g., verification, reporting).
  • Credit Usage Notifications (if applicable): If a Participant supports credit-based instant payments, clear and timely notifications regarding credit usage, limits, and repayment terms must be provided.

4) Transaction Notifications: To ensure transparency and keep users informed, participants must implement robust notification mechanisms for all instant payment activities:

  • Users must receive timely notifications for all initiated and received instant payment transactions.
  • Notifications should include essential details such as the counterparty (name/proxy), amount, date and time, and transaction status.
  • Participants should offer users customizable notification preferences (e.g., push notifications, SMS, email).
  • Notifications should be clear, concise, and easily understandable.

5) Proxy-Based Payments: To improve user convenience and minimize the need for account numbers, Participants should be required to fully integrate with the Scheme's proxy directory service, enabling comprehensive proxy functionality:

  • Seamless integration for user registration, management, and utilization of preferred proxies for sending and receiving payments.
  • An intuitive proxy registration process that mandates explicit user consent.
  • Clear communication to users regarding the advantages and security features of proxy usage.
  • User-friendly tools for viewing, modifying, and deregistering their linked proxies.

6) Recipient Verification: To minimize misdirected payments and build user trust, participants must implement effective recipient verification mechanisms during the payment process:

  • Verified Name Display: Show the verified name associated with a proxy (where available) during proxy-based transactions to confirm recipient identity.
  • Confirmation Screens: Provide users with a clear summary of recipient details (e.g., name, proxy/account number) before authorizing a payment.
  • Risk Warnings: Clearly alert users about the risks of sending payments to unverified recipients, especially in cases where proxy validation is unavailable.

7) QR Code Payments: QR code functionality enables seamless face-to-face or remote transactions. Applications must ensure a smooth and secure QR experience by adhering to the following:

  • Provide a reliable and intuitive interface for scanning QR codes to initiate payments.
  • Include clear, step-by-step instructions on how to scan and complete QR-initiated transactions.
  • Before confirming the transaction, display critical details such as the recipient name and amount (if pre-encoded in the QR).
  • Allow users to generate their own QR codes for receiving payments, with options to encode fixed or editable amounts and descriptions.

8) Transaction Receipts and History: Comprehensive payment records are essential for transparency and issue resolution. Participants must:

  • Provide a searchable, easy-to-navigate transaction history, accessible within the application.
  • Include key transaction details: date, time, amount, recipient (name/proxy/account), status, and a unique reference number.
  • Offer options for users to generate and share transaction receipts (e.g., PDF download, email sharing).
  • Ensure long-term access to historical data within reasonable retention limits.

9) Customer Support and Issue Resolution: Responsive customer support is critical for maintaining user trust. Participants are required to:

  • Ensure support is easily accessible within the app via FAQs, help sections, chat, contact forms, or phone support.
  • Clearly display support response time expectations and escalation processes.
  • Establish transparent dispute resolution mechanisms for failed or incorrect transactions, and communicate these to users.
  • Provide multilingual support where applicable to accommodate local user bases.

10) Security and Authentication: Security is a cornerstone of user confidence. Participants must implement strong, proportional safeguards:

  • Proportional Security Measures: Tailor security levels to transaction risk (e.g., higher-value transactions may require stronger authentication).
  • Fraud Detection and Prevention: Utilize real-time monitoring and AI-driven analytics to detect and prevent fraudulent behavior.
  • Transaction Cancellation During Review: Allow users to cancel payments that are flagged and placed under review, where supported by Scheme rules.
  • Authentication Methods: Implement secure yet user-friendly authentication options (e.g., PIN, biometric, password, OTP, or MFA).
  • Transaction Limits: Communicate applicable transaction limits clearly and allow users to manage limits where allowed.

11) Multi-Channel Consistency: For participants offering services across different platforms (mobile, web, USSD, etc.), the user experience must remain consistent:

  • Use unified design language, terminology, and workflows across all channels to reduce user confusion.
  • Where differences are unavoidable (e.g., limited features on USSD), these must be clearly explained to users.
  • Ensure feature parity across channels to the extent possible and appropriate.

6. Branding guidelines

To build a trusted, recognisable, and inclusive brand identity for Instant Payment System, each Scheme should adopt a unified branding approach grounded in clear principles. The following are high-level branding guidelines that every IPS should integrate into its governance, operations, and participant communications.

1) Brand Value and Identity: The Scheme should mandate that the IPS brand embodies four core values: Instant, Available, Affordable, and Easy. These values must be clearly communicated through all visual, verbal, and experiential touchpoints of the system. They reflect the essence of instant payments and are critical to fostering public trust and widespread adoption. The Scheme should ensure that this brand personality resonates with all users, individuals, businesses, and public institutions, and promotes the system as a secure, modern, and inclusive financial service.

2) Brand Mark: The Scheme should provide a complete and standardised brand mark, composed of a distinctive symbol representing technology and financial transactions, a custom logotype designed exclusively for the system, and a message identifying the authority backing the scheme (e.g., a central bank or national regulator). It should mandate three permissible formats for applying the brand: (1) the full version with symbol, logotype, and message, (2) a digital-friendly version combining the symbol and logotype, and (3) a compact version featuring the symbol only, reserved for mobile icons and constrained interfaces. Use of the logotype alone should be prohibited to preserve the brand’s recognisability and integrity.

3) Proportions: To maintain consistent visual presentation across media and platforms, the Scheme should provide exact specifications for proportions, layout, minimum sizes, and clear space requirements. These rules ensure that the brand remains legible and professional in both print and digital formats. The Scheme should mandate the use of official brand files only and prohibit participants from redrawing, modifying, or distorting the brand elements in any way.

4) Colour Palette: The Scheme should also establish a primary colour palette that visually communicates trust, innovation, and accessibility. This palette must include a main brand colour, a complementary tone, and a neutral base, all culturally appropriate and distinctive within the African context.

5) Brand Coexistence and Partner Usage: When the IPS brand is presented alongside other payment methods in signage or promotional materials, the Scheme should mandate equal prominence and visual alignment. The IPS brand must be displayed at the same size and frequency as other payment options, following strict alignment rules, both horizontal and vertical, to avoid visual crowding or misrepresentation. This ensures that the IPS is always recognised as a legitimate and universal payment option.

6) Derivative Branding: For systems offering derivative services such as QR-based payments or agent cash-out the Scheme should establish clear branding rules. All derivative brands must maintain visual coherence with the primary brand while using distinct colours and labels for each function. Typography and proportions must follow a consistent design system. The Scheme should centralise the creation and approval of derivative brands, explicitly prohibiting participants from developing their own sub-brands.

7) Brand Name Usage and Messaging: The IPS brand name must be used correctly in all written and spoken contexts. The Scheme should provide a set of approved public-facing key messages (e.g., “Make a payment”, “Pay anytime, any day, in seconds”) to support consistent communications across all stakeholders.

8) Communication and Education Standards: To preserve brand integrity, the Scheme should prohibit any form of advertising or messaging that confuses the public or implies that the IPS is exclusive to a single institution. All participants must clearly convey that the payment system is a shared, public-good infrastructure. The Scheme should also provide recommended terminology tailored for different audiences: simple, user-friendly terms for the public; operational terms for merchants; and more technical language for specialist audiences.

9) Brand Governance and Licensing: The Scheme should establish the IPS brand as the exclusive property of the Scheme Manager, granting participants a limited, revocable license for use. It must mandate brand presence in all physical and digital media related to the payment system and require that branding be installed in high-visibility locations. Any deteriorated physical assets (e.g., signage) must be replaced promptly. These measures help safeguard the brand’s reputation and reinforce its role as a symbol of safe, accessible, and reliable digital finance for all.

7. Compliance Monitoring Framework

An effective compliance monitoring framework ensures that participants maintain adherence to Scheme rules and requirements throughout their participation lifecycle. This framework helps identify and address compliance issues before they create significant risks to the system or other participants.

1) Monitoring Approaches:

  • Self-Certification: Regular attestations from participants regarding their continued compliance with key requirements (see annex ).
  • Data Analysis: Review of operational metrics, transaction patterns, and performance data to identify potential compliance issues
  • Targeted Reviews: Focused assessments of specific compliance areas based on risk indicators or scheduled review cycles.
  • Comprehensive Audits: Periodic in-depth evaluations of overall compliance status, potentially involving on-site visits or third-party assessors

2) Monitoring Dimensions

The monitoring framework should address all key aspects of participant obligations, including:

  • Financial requirements and settlement performance
  • Operational reliability and service level adherence
  • Technical standards compliance and security controls
  • Risk management effectiveness
  • Regulatory compliance and customer protection

The intensity and frequency of monitoring activities should follow a risk-based approach, with greater scrutiny applied to higher-risk participants or those with previous compliance issues. The framework should include clear escalation procedures for addressing identified concerns, ranging from informal guidance for minor issues to formal remediation plans for significant deficiencies.

The Scheme should maintain transparent documentation of monitoring approaches, evaluation criteria, and potential consequences of non-compliance. Regular reporting on aggregate compliance trends and anonymized case studies can help all participants better understand expectations and improve their own compliance practices.