Join our Newsletter — 33% off our NHI Course

Activity-based regulation in Indonesia: what payment teams must change

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Indonesia's payment infrastructure is forecast to grow from US$110.69 billion in 2025 to US$294.85 billion by 2031, while Sumsub says the country is the second least protected against fraud out of 112 nations, making continuous, activity-based compliance a regulatory necessity. Point-in-time checks no longer match the scale or fraud dynamics of modern payment ecosystems.

Editorial analysis by NHI Mgmt Group, based on content published by SumSub: “Sumsub Calls for Continuous Compliance as Indonesia's Payment Sector Shifts to Activity-Based Regulation”.

Key questions

Q: What breaks when payment compliance is still organised around legacy entity licences?

A: Controls become misaligned with the regulated activity, so a provider may appear compliant at the corporate level while failing activity-specific requirements for e-money, gateway services, or fund transfers.

Q: Why do continuous verification and transaction monitoring belong in the same control loop?

A: Because onboarding decisions age quickly in payment ecosystems.

Q: How can payment teams tell whether activity-based compliance is actually working?

A: Look for evidence that controls re-evaluate risk as activity changes, not just at onboarding or periodic review.

Practitioner guidance

  • Map controls to payment activities, not only entities Build a control inventory that ties onboarding, monitoring, and AML requirements to each regulated activity such as e-money issuance, gateway operation, or fund transfer facilitation.
  • Unify identity and transaction monitoring Connect verification, device behaviour, and transaction monitoring so risk scoring updates as customer behaviour changes across the lifecycle.
  • Replace periodic review with event-driven re-screening Trigger AML and fraud checks when behavioural thresholds, network patterns, or transaction sequences change instead of waiting for a fixed review cycle.

Bottom line: Indonesia's move to activity-based regulation changes the control boundary from company licence to regulated payment activity.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Activity-based regulation is an identity governance problem, not only a compliance update. Once obligations attach to the action being performed, the control model has to understand transaction context, customer lifecycle state, and ongoing risk changes. That pushes payment teams into a governance pattern closer to continuous assurance than to periodic certification, and it is strongest when identity, fraud, and AML teams operate from the same evidence model. Practitioners should treat activity scope as the new unit of control.

A few things that frame the scale:

  • 68% of organisations do not know how to fully address NHI risks, according to Ultimate Guide to NHIs.
  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing how slowly remediation can lag exposure.

A question worth separating out:

Q: Who is accountable when a payment activity is non-compliant under activity-based regulation?

A: Accountability shifts to the provider responsible for that activity, even if the service sits inside a larger corporate group or platform ecosystem. The key test is whether the organisation can prove the correct controls were operating for the exact activity at the time it occurred.

👉 Read our full editorial: Activity-based payments compliance is reshaping Indonesia's risk model



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Activity-based compliance is really control scoping by behaviour, not by organisation. That shift matters because payment risk now follows what a service does, not merely who owns it. When one identity or workflow can span multiple services, the governance model has to bind controls to activity state and not just legal entity state. Practitioners should treat service-level control mapping as the new baseline for regulated payments.

A question worth separating out:

Q: What should teams prioritise first when moving to activity-based regulation?

A: Start by mapping each regulated payment activity to its required controls and evidence trail. Once the activity boundary is clear, teams can align identity verification, monitoring, and AML screening to the right risk level instead of applying a one-size-fits-all compliance model.

👉 Read our full editorial: Activity-based payments compliance is reshaping Indonesia's risk model


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.