May 20th, 2020
FedNow Forwarding Faster Payments, First Data’s Dirty Deals, Always Available API's
TL;DR
Jason and Hayden discuss how FedNow fits into the broader real-time payments ecosystem and why smaller financial institutions were eager for broader access to faster bank-to-bank payment capabilities. They also unpack First Data’s FTC settlement as another reminder that acquiring banks and payment processors cannot rely on blind faith when monitoring high-risk merchants and third-party partners. The episode closes with a practical discussion of open banking, API reliability, high availability, load testing, penetration testing, and why ISVs need payments technology partners that can keep up with modern payment methods and production-level demand.
Faster Payments Need More Than Speed
This episode of Cents Chat starts with FedNow, but the bigger theme is infrastructure accountability.
Real-time payments sound simple from the outside. Money moves faster. Customers are happier. Banks modernize. Everyone wins. But Jason and Hayden dig into the messier version of that story: faster payments also create more channels, more risk, more interoperability questions, and more pressure on the systems that sit underneath the experience.
FedNow was still in development at the time of this episode, and Jason frames it as another major real-time payments rail alongside The Clearing House’s RTP network. That mattered especially for smaller banks, which often lacked direct access to existing real-time payment infrastructure without relying on third-party processors. FedNow promised broader access and a more inclusive path into instant payments.
Real-Time Payments Make the Ecosystem More Complicated
Jason’s point is not that FedNow is bad for the industry. Quite the opposite. He sees it as exciting and necessary.
But the payments ecosystem was already getting more fragmented. Cards, ACH, RTP, FedNow, Zelle, Venmo, Square Cash, and other alternative payment methods were all pushing toward broader acceptance. The more payment options merchants accept, the more banks, ISVs, and processors have to understand cross-channel risk.
Faster payments are not just a product feature. They change how money moves, how fraud happens, how disputes are handled, and how merchants expect software platforms to behave.
First Data Shows Why Oversight Cannot Be Outsourced
The second topic moves from faster payments to the First Data FTC settlement. The allegations centered on First Data knowingly processing, laundering, or assisting the laundering of card transactions for scams that harmed consumers.
Jason treats this as another warning flare for the acquiring ecosystem. The issue was not that the industry lacks rules. Visa and Mastercard have risk management and acquirer oversight expectations. The problem is that too many acquiring banks and processors rely on reporting produced by the very third parties they are supposed to monitor.
That is not oversight. That is trust with a PDF attached.
Jason’s takeaway is that banks need automated, independent, meaningful monitoring of their third-party payment providers. Audits should not be viewed as punishment. If the program is healthy, audits are a second set of eyes that help identify gaps before regulators, card brands, or consumers do it for you.
APIs Have to Survive Production Reality
The final segment turns to open banking and API reliability.
Jason points out that the U.S. does not have a PSD2-style mandate forcing banks to open APIs, but fintech innovation was moving the industry in that direction anyway. That makes API performance and resilience critical.
An API that works in a demo but falls apart under production load is not good enough. ISVs and merchants depend on these systems to authorize transactions, move money, reconcile activity, and support customers. Downtime means lost sales, angry merchants, angry consumers, and potential chargeback exposure.
The practical standard is clear: APIs need simple integration, strong developer support, broad functionality in one place, current upstream features, high availability, load testing, monitoring, and penetration testing.
If your API breaks when it matters, the market will not care how elegant the documentation looked.
Featuring

Jason
The Nerd

Hayden
Guest Speaker
Transcript
Hayden: Welcome to this episode of Cents Chat with Jason and Hayden. Let's jump right in to make payments make sense. Jason, glad to be with you for another Wednesday recording session. And although, by the looks of that beard, it seems like you haven't left the office since last week's recording session. Come to think of it, regardless of the time of day, when I log on to Slack, you're online working.
Jason: Yeah, Hayden, the dev team and I have been working very hard on finalizing our first release of a really cool technology product that we're super excited about. We have totally been embracing the quarantine lifestyle and spending way too much time in the office.
Hayden: Yeah, I've seen you do a few demos, and everybody has been pretty excited. Let's jump into today's stories. FedNow forwarding faster payments: another flavor in the real-time payments ecosystem. Next, First Data’s dirty deals: another FTC story about lack of oversight. And last, always available APIs and the key to API services that do not suck. Now let's jump right into our first story. The FedNow service is at the top of the priority list for the Federal Reserve and is currently in active development. They are working through the pandemic and expect to have it available in 2023 or 2024. Industry engagement is a key component of the new FedNow service development plan, and they are working on developing industry-wide collaboration on service and design.
Jason: Yeah, Hayden, this is a super exciting initiative in the payments ecosystem, and we are certainly looking forward to contributing to the FedNow community. There has been so much innovation in real-time payments in the last couple of years, and FedNow is yet another flavor of real-time payments. Many people do not know this, but here in the U.S., there are actually two main clearinghouses for bank-to-bank transactions. There is the Federal Reserve Bank and The Clearing House, which launched its own real-time payments product called RTP in 2017. The Clearing House is actually owned by the world's largest commercial banks, and smaller banks do not have direct access to RTP without using a third-party processor, thus increasing their costs. So most of the smaller banks are very excited about the FedNow initiative, which will give all banks access to online real-time payment capabilities.
Hayden: Jason, I know being a certified APRP, you have a ton of experience in how money moves between banks. And I understand the goal is for nationwide coverage through interoperability, where somebody can make a payment and have it seamlessly make it to the receiver, regardless of the service operator.
Jason: Conceptually, FedNow and RTP will operate very similarly to the ACH solutions, where regardless of what clearinghouse a bank is using, they will communicate between each other so that the payment ultimately lands where it needs to land. Even smaller banks today that do not have direct connections to one of the clearinghouses rely on correspondent banks, and there are various third-party service providers that create vertically specialized solutions. But ultimately, I think the picture is going to get more complex.
Historically in this country, we have had two types of primary payment networks: card and debit networks, and then the ACH networks. And they have always played very nicely together. I think with the trend of these real-time payment solutions, and you have to look beyond just the FedNow solution and RTP, I think you also have to include Zelle, Venmo, Square Cash, and a lot of these third-party applications that have been created that today are strictly peer-to-peer payment solutions, but ultimately want to break into consumer-to-business type solutions.
What we are seeing is the transformation of the U.S. payment supply chain to look very similar to many international countries where card payments or bank-to-bank transfers are not the primary means of conducting transactions. And I think the picture here is going to continue to get more and more convoluted as all of these different players are making a drive to have merchants accept their form of payment. It is going to create new challenges for merchants, ISVs, and banks that are going to have to monitor and deal with all of these cross-channel risk type scenarios.
Hayden: Jason, on the topic of risks, it looks like yet another FTC settlement has been reached. This time, First Data LLC and a former executive will pay over $40.2 million to settle Federal Trade Commission charges. The charges state that First Data knowingly processed payments and laundered, or assisted laundering, of credit card transactions for scams that targeted hundreds of thousands of customers. They allegedly looked the other way when repeatedly warned by employees, banks, and others that one of their independent sales agents, Chi “Vincent” Ko, was laundering money and that First Data was facilitating the laundering of payments for companies that were operating unlawfully for years. And it turns out they actually hired the agent as a First Data executive.
Jason: Hayden, this is going to be my hot topic of the year, and we are going to keep talking about this until this supply chain gets it under control. The fact that this continues to happen is simply a lack of due diligence and oversight. There are so many protocols that should be in place at every bank that has an acquiring program to protect against this type of activity. Visa has their Global Acquirer Risk Standards. Mastercard has its global risk management programs. Both of these programs outline the level of due diligence that an acquiring bank should be doing on its third-party payment providers and their subsidiaries.
The problem is that most of these acquiring banks do not have systems in place to inspect what they expect from their third-party payment processors, and they are just operating on blind faith. They are relying on the third-party payment processors to generate the reports that they then, in turn, use to audit them, which is a recipe for disaster. I think what a lot of acquiring banks do not appreciate is how well-defined the risk standards are and how easy it is to actually put compliance programs in place that generate these reports in an automated fashion and make overseeing their third-party payment processors a significantly easier task.
Hayden: Well, according to the FTC, from 2012 to 2014, Ko used false names to open accounts, provided Wells Fargo with misleading information to open the accounts, and ignored evidence that his clients were committing acts of fraud. The money to be paid will go toward refunding consumers harmed in these scams, and the company will be required to screen and monitor certain high-risk merchant clients, as well as establish and implement an oversight program to monitor its independent sales agents. And on top of that, for the next three years, First Data is required to hire an independent assessor to oversee the company's compliance with the settlement’s oversight program.
Jason: Hayden, outside of the fine, what is sad is that the penalties being imposed are things that the acquiring bank, in this case Wells Fargo, should have been demanding from First Data in the first place. Banks undergo a series of audits every year from regulators, and those in the acquiring space from the card networks as well. I do not understand why they should expect anything different from their third-party payment processors.
Over my career, I have had the absolute pleasure, and I actually mean that, of working with several great auditors. I would be remiss if I did not give a shoutout to David Press from Mastercard, who, outside of being a Miami Dolphins fan, is one of the most knowledgeable people that I have ever worked with. We will have to get him on an episode of Cents Chat to not just talk audits, but maybe a little AFC East. Here is what I can tell you: if you are playing by the rules, an audit should not be something you are scared of. It is a second set of eyes to help you find and identify gaps. No matter how great your policies are, times change, fraud profiles change, people come up with new scams. And that is why, as financial institutions and as third-party payment providers, you should embrace these audits and work with the auditors to develop solutions that are going to protect the integrity of this supply chain.
Hayden: Well, Jason, now that Brady is out of New England, maybe your Buffalo Bills will have a chance this season. Anyways, moving forward, let's talk about a gap that seems to be closing very quickly. As we are slowly moving toward a coronavirus-free world, the role of an open banking API is growing, and we definitely expect to see a rise of open banking and digital-first financial services.
Jason: Yeah, Hayden, it absolutely boggles my mind how many checks we still write. Or in the case of the CARES Act, how many checks the government had to write, and how many people had to rely on the Postal Service to deliver those payments. The fact that so many merchants still rely on outdated accounts receivable and accounts payable systems that do not have direct banking integration is mind-boggling.
How can anyone run a business based on Excel spreadsheets these days? What is funny is that the U.S. does not have a PSD2 payment service directive like the European Union does, which mandates that banks open their APIs and enhance consumer authentication, something known as SCA, or strong customer authentication. But that is not stopping rapid innovation in the U.S. thanks to our strong fintech space. One of the biggest challenges with the payments and banking system is that much of it is still based on legacy technology. Many of the modern solutions overlay 50-year-old mainframe technology that still powers much of the ecosystem.
Hayden: Yeah, well, the resiliency of technology is a key factor in a bank's dependency on an API, but monitoring API performance is just as important as deploying them in the first place. Service providers must make sure to monitor their API's performance to ensure functionality and accessibility, and to avoid downtime or technical issues that can otherwise lead to the loss of transactions.
Jason: Hayden, this is actually one of the biggest topics that I talk to ISVs about: unreliable APIs. And I will tell you, it absolutely drives them and their merchants nuts because it results in the loss of sales, angry merchants, angry consumers, and potential chargebacks. And the industry trend is that everybody blames somebody else.
If you are going to be producing APIs, you really need to understand high availability. Too many people are building solutions that work great in a small environment with a limited amount of data, but when you move it into a production environment and beat on it, it falls apart.
It is more critical than ever for somebody who is playing in the financial services space, be it payment processing or banking, to have multiple data centers, perform extreme load testing, and have monitoring solutions in place so that you are not finding out you have a problem with your system when one of your customers is calling you. And equally as important is testing all of these different solutions. Do not just have multiple data centers. Do not just do load testing. Do not just put a monitoring solution in place. Actually test to make sure these things are effective when something does go wrong, because it will.
Hayden: Jason, I know you, for one, have been working on several technology initiatives focused on this exact topic. So, in your professional opinion, what do you see as the key differentiators?
Jason: Well, Hayden, we have touched on this topic in a few episodes now, but we will recap some of the key items. I think the first one is that it has to be easy to integrate to, and you have to have a development support team that is going to work in real time with those who are integrating to your solution.
Secondly, a single API that exposes all of the different services that you offer. Do not have multiple versions of different flavors of APIs that you are forcing your customers to integrate to. You have to stay up to date with the latest functionality from upstream vendors. I can tell you horror stories of people who built APIs that, at the time they built them, were cutting edge, but two years later were so far behind the industry standards it was mind-boggling. In fact, there are still gateways out there today that have not implemented Visa mandates from two years ago, and it has a massive impact on authorization rates. We will cover that in another episode.
Next, high availability and penetration testing. We live in this development world where everything is rapid development, rapid deployment. And as you are building solutions and getting them out the door as quickly as possible, do not forget to load test and penetration test those new features and functionality so that you are ensuring you are not setting yourself up for a compromise.
Hayden: Based on previous topics, I know data security is not something to compromise on. Alrighty, Jason, the moment our listeners have been waiting for. How about those takeaways?
Jason: ISVs, make sure your payments technology partners are paying attention to domestic alternative payment methods, or you will leave your merchants wanting more. Banks, do not rely on your third-party payment providers to produce reporting you use to audit them. It is a recipe for disaster. Technology service providers, if you are not building APIs that are fault-tolerant and highly available, it is your fault when it breaks.