The Data Behind the Payment
Improving Transaction Monitoring Through Better Payment Information
📅 September 30, 2026
📅 September 30, 2026
Transaction monitoring systems at retail banks sift through high volumes, spotting anomalies across millions of small transactions. Corporate banking works the other way around. Payments are fewer, larger, and more complex, often involving several parties, trade documents, and FX conversions in a single instruction. Yet many corporate banks still rely on monitoring designed for volume, which leaves them with queues of large but legitimate alerts while real risk slips through in payments that look routine. Much of the fix lies in the payment message itself.
A well-formed cross-border payment carries useful context including who sent the money and who received it, and through ISO 20022’s ultimate debtor and ultimate creditor fields, it can also show who the payment was really made for, which matters in corporate groups, treasury centers, and supplier networks. The chain of banks shows how the money travelled, purpose codes explain why it moved, and structured remittance information can tie it to specific invoices.
Each of these details answers a question a monitoring team should be asking:
When the data is complete, these checks can run at scale. When it isn’t, analysts end up piecing the story together by hand, usually after the money has moved.
In cross-border payments, information often disappears along the way. Payments made through affiliates, shared service centers, or agents can hide the party with the real interest, especially when the ultimate party fields are left empty. Long correspondent chains and format conversions have historically cut off names and reduced addresses to free text, making screening less reliable. Large wires often carry vague purpose descriptions or none at all, while the invoices that explain them sit in trade documents the monitoring system never sees.
These gaps map directly to the risks corporate banks worry about most:
In each case, weak payment data turns a detectable pattern into an undetectable one.
Two changes have raised the bar on what banks can expect to see in a payment. The first is ISO 20022, now the dominant standard for cross-border payments, with Swift reporting that more than 98% of payment instructions are now sent in this format. It offers dedicated fields for ultimate parties, structured addresses, purpose codes, and remittance details that older MT messages handled poorly.
The second is FATF’s revised Recommendation 16, agreed in June 2025, which clarifies who in the payment chain must include payment information and keep it intact, and calls for tools to protect against fraud and error. Countries are expected to be ready to implement the changes by the end of 2030, and FATF is currently consulting on implementation guidance.
Progress has been uneven. Swift had planned to stop accepting unstructured addresses in cross-border messages on 14 November 2026, but in late August it deferred all payments-related changes, with a new timetable expected by December. As of April, around 61% of payments were still carrying unstructured addresses.
Banks shouldn’t treat the delay as breathing room as, while the deadline has moved, the direction and supervisors’ expectations haven’t. Banks that already receive structured data can benefit from it today, while those waiting for the next deadline will be monitoring with weaker data for another year or more.
Better data lets corporate banks move beyond threshold rules toward monitoring built around each client’s profile. Instead of asking whether a payment is large, the system can ask whether it fits the client’s usual counterparties, markets, currencies, and trade patterns. A payment to a new beneficiary in an unexpected country, for a purpose that doesn’t match the client’s business, is a much stronger signal than a large payment to a long-standing supplier.
Ultimate party fields reveal payments made on behalf of others, a common way to layer funds through corporate accounts. Purpose codes and remittance data let banks check a payment’s stated reason against the client’s profile. Structured names, addresses, and Legal Entity Identifiers improve screening and help connect entities within a corporate group, cutting time spent on false matches. Clean, consistent data is also what allows analytics and machine learning to produce useful results rather than more noise.
The problem is that many banks have adopted ISO 20022 without changing what their monitoring systems actually receive. Internal systems often convert messages back into older formats, dropping ultimate party fields, turning structured remittance into free text, or ignoring purpose codes. The bank pays for the migration but gets little of the benefit.
Payment data sits across several teams: operations handles the messages, technology moves the data between systems, and compliance owns the monitoring results. That makes data quality a leadership issue, and it should be treated as a monitoring control with a clear owner and clear standards.
A practical first step is to trace what happens to key payment fields between the incoming message and the monitoring system, and find where information is cut, changed, or lost. Most banks that do this uncover gaps they didn’t know about. Those findings should then shape how scenarios and models are designed, so they use the data that now arrives.
Leaders should also link client due diligence to live payment data, so that the expected activity recorded at onboarding can be checked against real counterparties, purposes, and destinations. The same expectation should extend to corporate clients who pay through third parties and to correspondents who pass on incomplete information.
Finally, teams need to know what the data is telling them. Analysts, investigators, and relationship managers should be able to read a payment message as a picture of a business relationship, and judge whether that picture holds together. Without that skill, better data just produces better-formatted alerts.
For corporate banks, every high-value wire raises the same question, does this payment fit the business behind it? For years, the payment message offered only part of the answer. That is changing, and supervisors will expect banks to use the information available well before any deadline requires them to. Banks that act now will clear fewer false alerts, catch more of the risk hidden in commercial flows, and stand behind their monitoring decisions with confidence.

Richer payment data only improves outcomes when your teams know how to interpret it. IFI’s payments course on DOLFIN® gives compliance, operations, and relationship teams a solid grounding in how payments work and where financial crime risk arises across the payment chain. For institutions that need training built around their own products, clients, and risk profile, IFI also designs custom programs, starting with a needs assessment to identify where your teams need the most support.










This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies.
Accept settingsHide notification onlySettingsWe may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.
Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.
These cookies are strictly necessary to provide you with services available through our website and to use some of its features.
Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.
We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.
We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.
These cookies collect information that is used either in aggregate form to help us understand how our website is being used or how effective our marketing campaigns are, or to help us customize our website and application for you in order to enhance your experience.
If you do not want that we track your visit to our site you can disable tracking in your browser here:
We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.
Google Webfont Settings:
Google Map Settings:
Google reCaptcha Settings:
Vimeo and Youtube video embeds:
You can read about our cookies and privacy settings in detail on our Privacy Policy Page.
Privacy Policy