Join our Newsletter — 33% off our NHI Course

Indonesia payments compliance is changing fast, what should teams do?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Indonesia’s payments market is growing at a 17.74% CAGR from 2026 to 2031, driven by BI-FAST, mobile wallets, and QRIS, while compliance still relies on fragmented tools and manual point-in-time checks, according to SumSub. The gap is now operational, not theoretical: payments teams need continuous, technology-enabled governance rather than periodic review cycles.

Editorial analysis by NHI Mgmt Group, based on content published by SumSub: “From entity to activity-based regulation: What payment providers in Indonesia need to know”.

By the numbers:

  • Indonesia's growth is being driven by a CAGR of 17.74% from 2026 to 2031.
  • Indonesia has a population of 282 million spread across 17,500 islands.

Key questions

Q: What breaks when payments compliance is still run as point-in-time review?

A: Point-in-time review breaks when payment flows, merchant onboarding, and transaction risk change faster than the review cycle can capture them.

Q: Why do real-time payment rails increase compliance risk?

A: Real-time rails compress the time available to detect, approve, and record control decisions.

Q: What are the signs that payment governance is falling behind?

A: Common signs include conflicting records across tools, delayed approvals for new payment methods, manual evidence collection at audit time, and control owners who cannot explain where a change was first approved.

Practitioner guidance

  • Shift from periodic to continuous review Rebuild compliance oversight so control checks are triggered by operational events, not only by calendar cycles.
  • Map fragmented control ownership Document where onboarding, monitoring, fraud review, and audit evidence are owned today, then identify gaps where no team can prove end-to-end control effectiveness.
  • Tie governance to payment change events Define policy triggers for new rails, wallet integrations, QR-based acceptance changes, and exception handling so compliance can follow the pace of the business.

Bottom line: Indonesia's payment growth is creating a governance mismatch because compliance processes built for slower environments cannot keep pace with real-time rails and fast-changing merchant flows.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Continuous compliance is now the baseline expectation in real-time payment markets. Point-in-time assurance was designed for slower operating models where risk could be reviewed after the fact. That assumption fails when payment flows, wallet activity, and merchant acceptance are changing continuously, because compliance state can go stale before a review cycle finishes. Practitioners should treat compliance as an always-on control function, not a scheduled audit exercise.

A few things that frame the scale:

  • Companies are dedicating an average of 32.4% of their security budgets to secrets management and code security, with US organisations leading at 40.8%, according to The State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.

A question worth separating out:

Q: How can organisations tell whether continuous compliance is working?

A: They should look for shorter exception resolution times, fewer unresolved control breaches, and evidence that compliance status updates automatically when payment activity changes. If reporting still depends on manual compilation, the process is not yet continuous. Good governance is visible in the speed and completeness of response, not just in documentation.

👉 Read our full editorial: Indonesia’s payment growth is outpacing compliance controls



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Continuous compliance becomes a payments operating model, not a reporting cycle. When a market moves at real-time speed, periodic compliance checks cannot establish whether current controls match current behaviour. The issue is not that point-in-time review is useless, but that it is too slow to govern payment environments where business logic changes continuously. Practitioners should treat compliance as an operational control plane rather than a retrospective assurance exercise.

A question worth separating out:

Q: Should teams keep manual checks for payments or move to technology-enabled compliance?

A: Manual checks still have a role, but they should not be the primary control when payment ecosystems change continuously. Technology-enabled compliance is the better default when organisations need timely evidence, consistent exception handling, and faster policy enforcement across fragmented tools. The decision is less about automation for its own sake and more about control latency.

👉 Read our full editorial: Indonesia’s payment growth is outpacing compliance controls


This post was modified 3 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.