# Transaction Intelligence > Independent analysis of how payments actually work: the regulation as written, the systems as built, and the behaviour of the people in between. Public Ghost content for AI and LLM tooling. This file includes a bounded export of public pages first, then recent public posts. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages ### Privacy Policy URL: https://transactionintelligence.net/privacy/ Last updated: 2026-05-04T07:50:52.000Z ## Introduction This Privacy Policy explains how information about you is collected, used, and disclosed when you visit my blog. ## Information I Collect When you visit the blog, I automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. If you subscribe to my blog or comment on posts, I collect your email address and any other information you provide. ## How I Use Your Information I use the information I collect to: - Improve and optimize my blog - Send you updates if you've subscribed - Respond to your comments or enquiries - Monitor and analyze usage and trends ## Cookies My blog uses cookies to enhance your experience. You can set your browser to refuse all or some browser cookies, but this may prevent some features from working correctly. ## Third-Party Services This blog uses Google Analytics to help analyze how users use the site. Google Analytics uses cookies to collect standard internet log information and visitor behavior information in an anonymous form. The information generated by these cookies about your use of the website (including your IP address) is transmitted to Google. This information is used to evaluate visitor use of the website and to compile statistical reports on website activity. For more information about Google Analytics' privacy practices, you can visit: [https://policies.google.com/privacy](https://policies.google.com/privacy?ref=transactionintelligence.net) You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on, available at: [https://tools.google.com/dlpage/gaoptout](https://tools.google.com/dlpage/gaoptout?ref=transactionintelligence.net) ## Data Retention I retain your information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy. ## Your Rights If you are a resident of the European Economic Area (EEA), you have certain data protection rights under GDPR. If you wish to access, correct, update, or request deletion of your personal information, please contact me. ## Changes to This Privacy Policy I may update this Privacy Policy from time to time. If I make material changes, I will notify you by posting the new Privacy Policy on this page. ## Contact Me If you have questions about this Privacy Policy, please contact me at [hello@transactionintelligence.net](mailto:hello@transactionintelligence.net). Last updated: 8 January 2025 ### Terms and Conditions URL: https://transactionintelligence.net/terms-and-conditions/ Last updated: 2026-05-04T07:50:29.000Z **Effective Date:** 08 January 2025\. The following terms and conditions (the "Terms") shall govern and be the binding contract between https://transactionintelligence.net (the "Site") and its users. Matt Berryman owns and operates the Site: an e-commerce website. You are hereby confirming that you have read, understood, and agreed to be bound by these Terms by simply using this Site. --- ## 1\. Intellectual Property All content on the Site, including but not limited to text, images, logos, documents, and downloadable files, is the property of Matt Berryman and its creators and is protected by copyright and other intellectual property laws. ## 2\. Acceptable Use Users of this Site agree **not** to use the Site for illegal purposes or any of the following activities: - Acting in any way that could be considered fraudulent - Hacking into another user’s account - Harassing or mistreating other users - Violating the intellectual property rights of the Site owners or any third party - Posting any material that may be deemed inappropriate or offensive - Violating the rights of other users of our Site We reserve the right to restrict, suspend, or terminate your access if we believe you are using the Site unlawfully or in breach of these Terms. We may also take legal action to prevent such use. ## 3\. Accounts ### 3.1 Account Responsibility You are solely responsible for your account, including maintaining the security and confidentiality of your credentials and any personal information associated with it (e.g., password, email address, payment details). ### 3.2 Accurate Information All personal information provided during account creation and thereafter must be accurate, complete, and up-to-date. You agree to promptly update your information if it changes. ### 3.3 Account Termination We reserve the right to suspend or terminate your account at any time, without prior notice, for any reason, including but not limited to: - Violation of these Terms - Illegal activities - Fraudulent behaviour - Repeated attempts to compromise Site security ## 4\. Limitation of Liability Matt Berryman shall not be liable for any direct, indirect, incidental, consequential, or punitive damages arising out of or in connection with your use of the Site or its content. This includes, but is not limited to, damages for lost profits, loss of data, or business interruption. ## 5\. Indemnity You agree to indemnify and hold harmless Matt Berryman from any and all claims, damages, liabilities, and expenses (including reasonable attorneys’ fees) arising out of or in any way connected with your use of the Site or violation of these Terms. ## 6\. Applicable Law These Terms and Conditions are governed by the laws of the Country of England. ## 7\. Severability If any provision of these Terms is found to be invalid, illegal, or unenforceable by a court of competent jurisdiction, that provision shall be severed and the remaining provisions shall remain in full force and effect. ## 8\. Changes We may modify these Terms from time to time to reflect changes in our business or legal requirements. We will notify you of any changes by email or by posting a notice on our Site. The revised Terms will become effective on the notification date. Continued use of the Site after that date constitutes acceptance of the revised Terms. ## 9\. Contact Details If you have any questions or concerns, please contact us at [hello@transactionintelligence.net](mailto:hello@transactionintelligence.net) ### About URL: https://transactionintelligence.net/about/ Last updated: 2026-05-04T18:15:15.000Z Transaction Intelligence is independent long-form analysis on payments, behaviour, and the systems most fintechs pretend aren't there — written by someone who's worked inside them, for readers who want the operational truth rather than the press release. ## **What you'll find here** Six categories, deliberately broad: - **AI & Automation** — the model-shaped change happening inside risk, authorisation and the back office - **Payments** — rails, schemes, ISO 20022, and the operational reality of moving money - **Banking Technology** — the unfashionable infrastructure most of finance still runs on - **Financial Behaviour** — mental accounting, household money flows, and the social meaning of a transaction - **Regulatory** — DORA, PSD3, FiDA, and the supervisory letters nobody publishes - **UX & Design** — where service design meets the awkward bits of money ## **Who writes it** Matt Berryman. Twenty years across issuers, schemes, and the awkward bits in between. I write here because what I read elsewhere is either marketing or a trade-press summary, rarely the operational truth I see day-to-day. > “The best newsletter on payments I read. The only one that bothers with the boring bits, which is where the interesting bits live.” > — ***Head of Strategy, UK challenger bank*** Reader subscriptions only. The free tier gets every essay; the paid tier unlocks the long-form research notes and the issue archive. No sponsorships, no PR, no decks. ## Contact Information - Email: [hello@transactionintelligence.net](mailto:hello@transactionintelligence.net) - LinkedIn: [@mattberryman](https://uk.linkedin.com/in/mattberryman?ref=transactionintelligence.net) ### Support URL: https://transactionintelligence.net/support/ Last updated: 2026-05-04T07:51:13.000Z We're here to help ensure you get the most from your subscription. ## Getting Help For any questions about your subscription, technical issues, or general enquiries, please email us at: **hello@transactionintelligence.net** We aim to respond to all support requests within 24-48 hours during business days. ## Common Questions ### Account & Subscription Management - To update your payment details or manage your subscription, please log into your account - For billing enquiries or issues accessing premium content, contact us at the email above ### Technical Issues If you're experiencing problems accessing the site or viewing content: - Try clearing your browser cache and cookies - Ensure you're using a modern browser (Chrome, Firefox, Safari, or Edge) - Check you're logged into your account ## Subscription Terms Your subscription is governed by our Terms & Conditions and Privacy Policy: - [Terms & Conditions](https://transactionintelligence.net/terms-and-conditions/) - [Privacy Policy](https://transactionintelligence.net/privacy/) ## Cancellations & Refunds You can cancel your subscription at any time through your account settings. Cancellations take effect at the end of your current billing period, and you'll retain access until then. For any concerns about your subscription or if you believe there's been an error with your billing, please contact us at hello@transactionintelligence.net. We review all requests on a case-by-case basis and aim to resolve any issues fairly. ## Payment Processing All payments are securely processed through Stripe. We do not store your payment card details on our servers. For questions about payment security, please refer to [Stripe's security documentation](https://stripe.com/gb/security?ref=transactionintelligence.net). --- *Last updated: July 2025* ### Newsletter URL: https://transactionintelligence.net/newsletter/ Last updated: 2026-05-04T08:03:54.000Z ## What you get A long essay sent direct to your inbox when it's ready — typically between 1,500 and 4,000 words, on the systems most fintechs pretend aren't there. The free tier includes every essay. The paid tier unlocks the long-form research notes and the issue archive. ## When it arrives When the essay is ready, not on a calendar. Some weeks there's nothing because the analysis isn't finished. There is never a "we noticed you haven't been engaging" email. ## What it covers Six categories: AI, Payments, Banking Tech, Behavioural Science, Regulatory, and UX. Whatever's actually moving in any given month gets the focus. ## Who reads it Heads of payments, risk and operations at UK and EU banks. Product leads at fintechs. Regulators (anonymously). A smaller-than-you'd-think number of journalists. ## How to leave One click in any email. The unsubscribe link works on the first try and removes you immediately. No reactivation drips, no exit surveys, no "are you sure" modals. ## Posts ### When “something you are” becomes “something they can make” URL: https://transactionintelligence.net/when-something-you-are-becomes-something-they-can-make/ Last updated: 2026-07-02T06:42:43.000Z Of every five biometric fraud attempts on Entrust's identity systems last year, one involved a deepfake. The figure comes from the firm's 2026 [Identity Fraud Report](https://www.entrust.com/resources/reports/identity-fraud-report?ref=transactionintelligence.net), drawn from over a billion verifications across 195 countries between September 2024 and September 2025\. In payments, 82% of fraud attempts now target the authentication process. Deepfaked selfies are up; injection attacks, where synthetic media is fed straight into the verification system rather than held up to a camera, are up roughly 40% year on year. The headline number is the easy part. The meaning is more interesting. SCA gives us three factor categories: knowledge, possession, and inherence. They are not equivalent. They fail in different ways, at different costs, and against different attackers. Inherence has always been the awkward one. The Entrust figures are the clearest signal yet that treating it as the strong factor in a two-factor stack is no longer defensible. ## Why inherence is different Knowledge factors fail when a secret leaks. Possession factors fail when a device is stolen or cloned. In both cases, the defender knows what to harden. Inherence is different. The defender is not protecting a secret or a token, but an assumption: that the biometric pattern in front of the sensor genuinely came from the registered user. That assumption used to be cheap to defend, because impersonating a face required either a real face or a serviceable mask. Generative video has collapsed the cost of both routes at once. The deeper problem is that the most damaging attacks in the Entrust data do not fool the camera. They bypass it. Injection attacks feed manipulated frames directly into the authentication system, behind whatever sensor the user is supposed to be standing in front of. Anti-spoofing measures designed to detect a printed photograph or a screen replay have nothing to say to an attack that never goes near a physical lens. The defence has to move further down the stack, into device attestation, signal provenance, and integrity checks on the capture environment itself. ## The PSR has picked the right carve-out The trilogue-approved PSR text makes this conversation operationally urgent. Under PSD2 and the SCA RTS, two SCA elements have to come from two different categories. The PSR keeps that default, with a single exception. Article 85(12) singles out inherence as the only category in which a payment service provider may use two elements from the same category, provided it can demonstrate to its national competent authority that the independence of the elements is at all times fully preserved and that the authentication procedure ensures at all times a high level of security. EBA Article 16 guidelines on how to assess that independence are due within 18 months of entry into force. The legislator has, in effect, anticipated face-plus-fingerprint authentication and singled out the case that matters: > the only category where two-element stacking is permitted is also the one most exposed to generative AI. A PSP operating under that exception will need to demonstrate that the failure modes of its two inherence elements are uncorrelated. The Entrust data is the empirical question against that legal one. ## Liveness is the floor, not the ceiling The industry response is converging on liveness detection, but the version of it that beats deepfakes is not the passive one. Passive liveness reads micro-movements and depth signals without prompting the user, and it handles the camera-facing attack reasonably well. It does less for an injection attack. Active liveness, which uses randomised motion prompts the attacker cannot pre-script, performs substantially better in Entrust's own data: the firm reports a fraud rate below 0.1% against its active-liveness product, and the share of deepfake attempts against that product fell in 2025 even as it climbed against passive selfie verification. CEN/TS 18099, the European technical specification published in 2024, now provides the testing methodology, and independent labs are issuing certifications against it at Substantial and High assurance levels. The vendor question for 2026 is no longer "do you do liveness?" It is: which liveness, against which threat model, certified against which standard. ## What this means for payments teams If your fraud strategy treats biometric authentication as the strong leg of a two-factor stack, you are relying on a factor that an organised attacker can now reach for the cost of a consumer GPU and a weekend. The answer is not to abandon inherence. The answer is to stop treating it as a sealed black box and start asking the same questions of it that you would ask of any other security control: what does the threat model assume, how is the assumption defended, and how do you know the defence is still holding. If the PSR lands as drafted, the burden of proving genuine independence between two biometric factors will sit with the PSP, not the regulator. The vendors who have already answered that question cleanly will earn a different kind of conversation in 2026. ### Meet Alexandre Lamfalussy URL: https://transactionintelligence.net/lamfalussy-primer/ Last updated: 2026-05-04T14:20:23.000Z Alexandre Lamfalussy was born in Kapuvár, Hungary on 26 April 1929\. He left the country in January 1949 as a political refugee, took his economics degree at the Catholic University of Louvain, and a doctorate at Nuffield College, Oxford. As founding president of the European Monetary Institute (the forerunner of the European Central Bank), he guided the preparatory work for the launch of the single currency in January 1999\. In 2000 he was asked to chair the EU's Committee of Wise Men on the Regulation of European Securities Markets. The European Council adopted his committee's report at the Stockholm summit on 23 March 2001\. He died in 2015, a Belgian baron, decorated with Hungary's Grand Cross of the Order of Saint Stephen. The Wise Men report was, ostensibly, about MiFID-era securities markets. Between 2002 and 2004 the approach was extended across banking, insurance and fund management. The post-crisis reforms of 2010 and 2011 transformed its banking-sector committee into the European Banking Authority. Every PSD2 RTS you have ever read against, every EBA Opinion you have cited, every Q&A you have trawled for an interpretive crumb: all produced through the four-level system Lamfalussy designed. Including, now, every line of secondary law that will make PSD3 and the PSR applicable to your business. If you are tracking the PSD3/PSR file because you have a compliance plan or a build to commit to, you are downstream of his framework whether you know it or not. ## The four levels Lamfalussy's framework splits financial services regulation into four levels. Each has a different actor, a different legal weight, and a different timetable. Knowing which level you are reading is most of the work. **Level 1: primary legislation.** The framework instruments adopted by the European Parliament and Council under the ordinary legislative procedure. Regulations apply directly across all member states; directives require national transposition. PSD2 is a directive; the PSR will be a regulation; PSD3 will be a directive. Level 1 sets out what must be done. It rarely sets out how. A Level 1 instrument has two parts that need different treatment. The operative articles are the binding obligations: this is what creates legal duties. The recitals at the front of the text, sometimes a hundred or more, are the policy reasoning behind the articles. Recitals tell you what the legislator was trying to achieve and can be cited by the CJEU to interpret an article that is ambiguous. They do not create obligations of their own. This trips people up regularly. A recital can contain a striking sentence that suggests an obligation the operative articles do not actually impose. The PSR's negotiating texts contain several such sentences on technical service provider liability, and law-firm briefings have not always been careful about which is which. The discipline is simple: when you see something interesting in a recital, look for the matching article. If there is no matching article, the recital is interpretive guidance only. Useful for understanding intent. Not something to build to. **Level 2: delegated and implementing acts.** Often called secondary legislation in practitioner shorthand. These are the Commission Delegated Regulations and Implementing Regulations that fill in the operational detail Level 1 deliberately leaves out. They are drafted by the relevant European Supervisory Authority (the EBA, for payments) under explicit mandates contained in the Level 1 text. Two forms matter: Regulatory Technical Standards (RTS) for substantive detail, and Implementing Technical Standards (ITS) for templates and procedures. The PSD2 SCA RTS, formally Commission Delegated Regulation 2018/389, is the canonical payments example. Level 2 is binding law. It is also where the things that affect your build are decided. **Level 3: supervisory convergence.** EBA Guidelines, Opinions and Q&As. Not binding on regulated firms in the strict sense. National competent authorities apply a "comply or explain" obligation to formal Article 16 Guidelines, and most regulated institutions therefore treat them as binding in practice. The EBA Opinion of June 2019 on the elements of strong customer authentication, and the follow-up Opinion of October 2019 setting the EU-wide migration deadline of 31 December 2020, are the canonical PSD2 examples. Level 3 is where ambiguity in Levels 1 and 2 gets clarified, often in ways that materially change what compliance looks like. **Level 4: enforcement.** Commission infringement proceedings against member states, peer review of NCAs, supervisory practice, and CJEU case law. Less visible day-to-day, but the level at which a regulator finally does something about an institution that read the previous three levels and ignored them. The four levels run on staggered timetables. Level 1 lands first. Level 2 follows after consultation. Level 3 fills the gaps as practice exposes them. Level 4 catches up at its own pace. Reading PSD3/PSR without knowing which level you are holding is like reading a contract without knowing which clauses are operative. ![](https://storage.ghost.io/c/7a/85/7a852110-bd54-4df3-97de-ac191363fc73/content/images/2026/05/lamfalussy-four-levels@2x.png) ## Why Coreper approval isn't go-live Coreper approval matters. It signals that the political negotiation is over and the text is settled. But it is a long way from the moment your fraud team needs to enforce a particular dynamic linking rule against a real transaction, and the gap between "approved" and "applicable" is where build plans go wrong. The PSD2 timeline gives you a usable benchmark. Counting from the day PSD2 entered the Official Journal: transposition was complete around month 25; the SCA RTS appeared in the OJ around month 27; it applied around month 45; the EBA's supervisory flexibility for e-commerce SCA expired around month 60; and the UK, enforcing its onshored equivalent, did so around month 69\. Five years and nine months from the start of the clock to the last European supervisor enforcing one slice of secondary law. PSD3/PSR will run on a similar shape. OJ publication is expected in summer 2026\. The PSR's transition period was extended in trilogue from 18 months to 21 months, putting direct application around month 21 of its own clock. PSD3 transposition runs alongside, and its directive status leaves room for national variation. The EBA's RTS pipeline starts shortly after Level 1 publication and runs for around 24 to 36 months; some standards land before the application date and some after. By the PSD2 benchmark, full enforcement of the PSD3/PSR perimeter is plausibly a 2030 conversation, not a 2028 one. If the build plan in front of you treats Council formal adoption, or even OJ publication, as the trigger event, it is operating a level too high. The trigger event for any specific operational requirement is the application date of the relevant secondary measure, qualified by whatever Opinion the EBA chooses to publish in the meantime. That can be eighteen months later, or three years later, or never. The framework does not tell you up front. It reveals itself level by level. ## What this means for the rest of the year The black box has a logic. Once the four levels are visible, the apparent confusion of timelines and instruments resolves into a sequenced process that has been running, with minor variations, since 2001. I'll come back to specific PSD3 and PSR provisions in subsequent posts. Different obligations land at different levels, on different timetables, with different binding force. Knowing which is which is the difference between a programme that ships and one that gets re-scoped twice. ### The Trust Triangle Evolution: From 3-D Secure's Three Domains to AP2's Agent Architecture URL: https://transactionintelligence.net/the-trust-triangle-evoled/ Last updated: 2026-02-17T20:12:27.000Z ## The Original Three-Domain Model When 3-D Secure launched in 1999, it tackled a fundamental problem: how to establish trust in card-not-present transactions where the security assumptions of physical commerce no longer applied. The protocol created three interconnected domains (issuer, acquirer, and interoperability), each playing a crucial role in authenticating transactions. Today, as AI agents prepare to transact autonomously on our behalf, Google's [Agent Payments Protocol](https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol?ref=transactionintelligence.net) aces a similar challenge: reimagining trust for an era where even the human isn't present. The original 3-D Secure architecture recognised that online payments needed more than bilateral trust between buyer and seller. The issuer domain encompassed the cardholder and their issuing bank, responsible for authentication and enrolment. The acquirer domain included the merchant and their acquiring bank, initiating authentication requests and processing payments. The interoperability domain (the card schemes' infrastructure, including directory servers and authentication frameworks) served as the trusted intermediary, enabling these otherwise disconnected domains to communicate securely. ## Network Effects Through Interoperability This tripartite structure solved the "stranger danger" problem of early e-commerce. Without the interoperability domain acting as a trusted broker, issuers and acquirers would have needed thousands of bilateral agreements and technical integrations. Instead, schemes like Visa's Verified by Visa and Mastercard's SecureCode provided common rails that any participant could join, creating network effects that drove adoption. AP2 faces an evolved version of this challenge. Where 3-D Secure helped issuers answer "How do we know that our cardholder is shopping on a legitimate site?", AP2 must answer "How do we know this agent has legitimate authority from the user?" The protocol's solution mirrors 3-D Secure's domain thinking, adapted for agent commerce. ## AP2's Reimagined Domain Architecture In AP2's architecture, familiar patterns emerge. The user and their chosen AI agents form one domain, analogous to the issuer domain, where authentication and authorisation originate. Merchants and their payment processors constitute another, similar to the acquirer domain. AP2 itself, along with complementary protocols like [Agent-to-Agent (A2A)](https://developers.googleblog.com/en/a2a-a-new-era-of-agent-interoperability/?ref=transactionintelligence.net) and Model Context Protocol (MCP), creates a new form of interoperability domain built specifically for agent interactions. The parallels extend beyond structure to function. Just as 3-D Secure's Access Control Server (ACS) manages cardholder authentication within the issuer domain, AP2's [verifiable credentials system](https://ap2-protocol.org/?ref=transactionintelligence.net)creates cryptographically signed "mandates" proving user intent. Where 3-D Secure's Merchant Plug-In (MPI) initiated authentication requests from the acquirer side, AP2 enables merchants to validate agent authorities. And replacing the Directory Server's role in 3-D Secure, AP2's open protocol framework helps agents and payment systems find and communicate with each other. ## Learning from Two Decades of 3-D Secure AP2 also benefits from two decades of lessons learned. 3-D Secure v1's rigid authentication requirements (mostly static passwords for each transaction) taught the industry that security without usability fails. Cart abandonment rates soared as customers faced popup windows and redirects. AP2 is designed to avoid this trap, building in flexibility from the start. Its support for multiple payment methods (initially cards, expanding to real-time payments and digital currencies) and integration with existing protocols suggests a more pragmatic approach than 3-D Secure's initially monolithic design. The [full AP2 specification on GitHub](https://github.com/google/agent-payments-protocol?ref=transactionintelligence.net) reveals careful attention to user experience that 3-D Secure v1 overlooked. The protocol emphasises maintaining user control whilst minimising friction; a balance that took 3-D Secure years and a major version update to achieve. ## The Critical Liability Question The liability model presents another crucial parallel. 3-D Secure's great innovation wasn't just technical; it was the liability shift that made authenticated transactions the issuer's responsibility rather than the merchant's. This economic incentive drove adoption more than any security benefit. AP2 promises "clear transaction accountability" through its cryptographic audit trails, but nobody has yet defined the precise liability framework. Will agent developers bear responsibility for "hallucinated" purchases? Will users be liable for the mandates they sign? These questions echo the early days of 3-D Secure, when the industry grappled with similar ambiguities. ## Industry Collaboration as Foundation Both protocols recognise that establishing trust in new transaction paradigms requires industry-wide collaboration. 3-D Secure succeeded because Visa, Mastercard, and eventually other schemes created compatible implementations within a common framework. AP2's launch with [sixty-plus partners](https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol?ref=transactionintelligence.net), including Mastercard, American Express and PayPal, suggests Google has learned this lesson well. The interoperability domain may prove even more critical for agent payments than for card transactions. While 3-D Secure connected relatively homogeneous payment systems, AP2 must bridge diverse AI platforms, each with different capabilities, training, and potential failure modes. The protocol's success depends on creating an interoperability layer strong enough to handle this complexity whilst remaining simple enough for widespread adoption. ## Looking Forward: The Authentication Evolution As payment professionals who've navigated 3-D Secure's evolution from password-heavy v1 to risk-based v2, we're watching what could become the authentication standard for the agent economy. The three-domain architecture that served us well for human-initiated transactions is being reimagined for a world where our digital representatives transact on our behalf. The question isn't whether this evolution is necessary. It's whether AP2 has learned enough from 3-D Secure's journey to get it right from the start. --- ### Useful References: - [AP2 Protocol Documentation](https://ap2-protocol.org/?ref=transactionintelligence.net) - [AP2 GitHub Repository & Technical Specification](https://github.com/google/agent-payments-protocol?ref=transactionintelligence.net) - [Google Cloud's AP2 Announcement](https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol?ref=transactionintelligence.net) - [Agent2Agent Protocol Overview](https://developers.googleblog.com/en/a2a-a-new-era-of-agent-interoperability/?ref=transactionintelligence.net) - [EMVCo 3-D Secure Specifications](https://www.emvco.com/emv-technologies/3d-secure/?ref=transactionintelligence.net) ### Second-Order Thinking: What the UK's Age-Check Law Taught Us About Regulation (and Why It Matters for AI) URL: https://transactionintelligence.net/uk-age-checks-vpn-surge/ Last updated: 2025-08-22T10:05:42.000Z In late July 2025, the UK government celebrated as domestic traffic to adult sites halved within days of mandatory age-verification. Yet by August, they'd inadvertently run the country's most successful VPN marketing campaign. Second-order thinking asks: *what new behaviours has this regulation unleashed?* The UK's own history provides a cautionary lens. ## When Compliance Happens Instantly - Seat-belts (Jan 1983). Wearing front seat-belts became compulsory. Within days, wearing rates soared from \~30% to over 90%[1](#user-content-fn-1). - Smoke-free England (Jul 2007). Banning indoor smoking took effect. Within a month, compliance hit \~97–98% — nearly universal[2](#user-content-fn-2). - London Congestion Charge (Feb 2003). Traffic dropped \~15% and congestion \~30% in the first month[3](#user-content-fn-3). - Carrier-bag charge (Oct 2015). Tesco reported a 78% drop in single-use bags within the first month[4](#user-content-fn-4). In all cases, the intended behaviour became easier than resisting; backed by enforcement, friction, or cost. ## When the Policy Teaches Resistance Contrast that with July 2025's age checks. Instead of nudging, the law *taught* millions a workaround. VPN sign-ups in the UK surged nearly 2,000% within three days of enforcement, and stayed elevated through early August. VPN apps dominated the UK app-store charts[5](#user-content-fn-5). This wasn't compliance ; it was adaptation through circumvention. The privacy implications should have been obvious to legislators. Tying official IDs to adult site usage creates an irresistible target for hackers. The Tea dating app [breach](https://www.theverge.com/cyber-security/714750/tea-hack-breach?ref=transactionintelligence.net) — stemming from a simple misconfigured cloud storage bucket — exposed intimate user data. Now imagine that vulnerability, but with government-verified identities attached to browsing histories. ## The VPN Trade-Off: A Cautionary Paradox VPNs shift your trust. Instead of your ISP, VPN providers — often overseas and opaque — see your entire browsing activity. Not all earn that trust. Recall Facebook's acquisition of Onavo (2013). Onavo's VPN, marketed as private, secretly funnelled user traffic to Facebook — enabling the company to monitor app usage and guide acquisitions like WhatsApp. Apple removed Onavo from the iOS App Store in 2018 for violating data collection rules, and Facebook shut it down completely in 2019 after public backlash[6](#user-content-fn-6). In chasing an inconvenience (age checks), many UK users may have sought refuge behind VPNs — unknowingly giving their browsing to unregulated actors. ## The Regulation Trap: Why This Matters for AI This isn't just about content moderation. The same dynamics are emerging in AI regulation, where the pace of innovation consistently outstrips legislative response. Regulation, by its nature, addresses yesterday's problems with tomorrow's restrictions. In fast-moving fields, this temporal mismatch becomes critical. The UK's age-verification law tried to solve a 2020s problem with 2010s thinking, not anticipating how normalised VPN usage had become. Now consider AI regulation: - The EU's AI Act, effective from August 2024, imposes a risk-based, highly prescriptive framework. Systems are categorised by risk, with outright bans and heavy compliance burdens[7](#user-content-fn-7). - The US leans towards a principles-based and prohibition-focused approach: instead of outlining what AI must be, it emphasises what it must not do (e.g., no illegal discrimination). This model aims to protect rights whilst preserving innovation flexibility[8](#user-content-fn-8). The distinction matters. Prescriptive regulation assumes we can predict AI's evolution and preemptively define acceptable forms. But if the UK's experience teaches us anything, it's that technology users are remarkably creative at routing around restrictions. The EU's approach risks creating an innovation exodus whilst failing to achieve its protective goals — the worst of both worlds. The US approach, by focusing on harms rather than forms, maintains adaptability. It accepts that we cannot predict every AI innovation but can establish clear boundaries around unacceptable outcomes. ## Be Careful What You Wish For Second-order thinking matters because every policy teaches the public something. Seat-belt laws taught safety. Bag charges taught reuse. And the age-verification law taught millions to vanish online. Whilst the government sought child protection, it ended up: - Driving mainstream VPN adoption - Reducing visibility into domestic internet traffic - Exposing citizens to opaque VPN operators - Normalising circumvention as standard practice ## Final Takeaway Regulation will always lag innovation — be it content control, data security, or AI. The choice is clear: do we regulate by prescription (defining exactly what systems must do) — or by setting meaningful limits (defining what they absolutely must not do)? The latter enables adaptability and safer innovation. The UK set out to protect its users online. Instead, it ran a VPN masterclass. In a digital world, second-order thinking isn't optional — it's survival. --- ## Footnotes 1. PACTS (UK, 2003). Seat-belt wearing jumped to >90% after law started 31 Jan 1983\. *PACTS site*. URL: [https://www.pacts.org.uk/40-years-of-uk-seatbelt-wearing-saves-thousands-of-lives-2](https://www.pacts.org.uk/40-years-of-uk-seatbelt-wearing-saves-thousands-of-lives-2/?ref=transactionintelligence.net)/ [↩](#user-content-fnref-1) 2. Smokefree England (2007). Indoor smoking ban compliance hit \~97–98% within one month. *Smokefree England site*. URL: [https://smokefreeengland.co.uk/media/smokefree-england-one-month-on](https://smokefreeengland.co.uk/media/smokefree-england-one-month-on?ref=transactionintelligence.net) [↩](#user-content-fnref-2) 3. Transport for London (2003). Congestion Charge cut traffic \~15% and congestion \~30% within the first month. *TfL Impacts Monitoring Report*. URL: [https://content.tfl.gov.uk/impacts-monitoring-report-2.pdf](https://content.tfl.gov.uk/impacts-monitoring-report-2.pdf?ref=transactionintelligence.net) [↩](#user-content-fnref-3) 4. Tesco plc (2015). Carrier charge cut single-use bag use by 78% in first month. *Tesco plc news release*. URL: [https://www.tescoplc.com/plastic-bag-use-slashed-by-nearly-80-since-introduction-of-government-bag-charge/](https://www.tescoplc.com/plastic-bag-use-slashed-by-nearly-80-since-introduction-of-government-bag-charge?ref=transactionintelligence.net) [↩](#user-content-fnref-4) 5. Top10VPN (2025). UK VPN demand surged +1,327% to +1,987% in first days, remained elevated in early Aug. *Top10VPN live tracker & tech press*. URL: [https://www.top10vpn.com/research/vpn-demand-statistics/](https://www.top10vpn.com/research/vpn-demand-statistics/?ref=transactionintelligence.net) [↩](#user-content-fnref-5) 6. Onavo acquired 2013, used for monitoring competitors. Removed from iOS in 2018, shut down in 2019\. *Wikipedia / WSJ / TechCrunch*. URLs: [https://en.wikipedia.org/wiki/Onavo](https://en.wikipedia.org/wiki/Onavo?ref=transactionintelligence.net), [https://www.wsj.com/articles/facebooks-onavo-gives-social-media-firm-inside-peek-at-rivals-users-1502622003](https://www.wsj.com/articles/facebooks-onavo-gives-social-media-firm-inside-peek-at-rivals-users-1502622003?ref=transactionintelligence.net), [https://techcrunch.com/2019/02/21/facebook-removes-onavo/](https://techcrunch.com/2019/02/21/facebook-removes-onavo/?ref=transactionintelligence.net) [↩](#user-content-fnref-6) 7. Wikipedia / Regulation of AI. EU AI Act (Regulation 2024/1689) in force 1 Aug 2024: risk-based framework. URL: [https://en.wikipedia.org/wiki/Regulation\_of\_artificial\_intelligence](https://en.wikipedia.org/wiki/Regulation%5Fof%5Fartificial%5Fintelligence?ref=transactionintelligence.net) [↩](#user-content-fnref-7) 8. Congressional Research Service (2025). US AI regulation focuses on voluntary commitments & limited prohibitions; EU focuses on broader binding regulation. *CRS report*. URL: [https://www.everycrsreport.com/reports/R48555.html](https://www.everycrsreport.com/reports/R48555.html?ref=transactionintelligence.net) [↩](#user-content-fnref-8) ### Why Generalists Win in Complex Ecosystems URL: https://transactionintelligence.net/why-generalists-win/ Last updated: 2025-08-19T13:21:37.000Z Business culture has a bias: we worship specialists. The fraud analyst who models risk to four decimal places. The architect who dreams in API specifications. The compliance expert who memorises every regulatory update. Depth feels safe, so we place our trust in it. But in complex customer ecosystems, breakthroughs rarely come from narrow expertise alone. They come from generalists; people who know a moderate amount across many domains and can connect the dots into creative solutions. What some dismiss as breadth at the expense of depth often proves to be the differentiator. ## The Specialist Paradox Most organisations incentivise specialists to optimise their own narrow metrics. Fraud teams are measured on loss reduction, product managers on transaction growth, IT teams on defect-free systems. Each makes sense in isolation, but the incentives clash. Fraud losses can be reduced to zero if every transaction is declined. Volumes can surge if every control is relaxed. Systems can be flawless if nothing new ever launches. Each team “wins” only if others lose. This tension creates gridlock. Optimising across conflicting priorities is rarely anyone’s formal mandate, yet it is essential. Generalists naturally step into this gap, helping organisations navigate towards outcomes that balance risk, growth, and customer experience. ## Systems Thinking Creates Exponential Value The value of generalists lies not in out-competing specialists on depth, but in connecting insights across domains. When every team pulls in its own direction, 2+2 can feel like 3; value is destroyed in the friction between functions. When someone aligns the system as a whole, 2+2 can become 5. Strong Customer Authentication (SCA) offers a clear example. Authentication experts pushed for regulatory compliance, UX designers worried about friction, risk managers modelled fraud patterns and marketing teams feared conversion drops. Each perspective was valid, but left alone they collided. Breakthroughs only came when these pieces were stitched together: positioning security as a trust enhancer, designing flows that felt protective rather than obstructive and designing messages to reinforce brand values. The result was smoother regulatory alignment, reduced abandonment and improvements in customer trust. ## Why Customers Value Generalists Customers rarely ask for more product detail. What they want to know is whether their business outcomes can be delivered. Generalists play a crucial role in connecting the dots. A CFO is more likely to engage when authentication strategy links directly to revenue protection. A CPO listens when compliance is framed as market differentiation. Developers lean in when business objectives translate into clear technical requirements. The ability to bridge conversations across these roles creates trust and accelerates progress. ## The Generalist Skillset Effective generalists tend to share certain qualities. They recognise patterns that cut across disciplines; echoes between payment flows and user journeys, or between fraud models and customer behaviour. They act as translators, speaking just enough of each language, whether technical, commercial, or regulatory, to align experts around a shared objective. They focus on optimising the whole system rather than perfecting any single part, accepting compromise where it creates greater overall value. And they learn quickly, not to claim deep specialism, but to understand dependencies and connections in new domains. ## Building Bridges Between Worlds The most impactful generalists combine genuine depth in a few areas with breadth across many; the classic T-shaped profile. This credibility enables them to lead cross-functional efforts effectively. They track outcomes that span silos, such as customer lifetime value or end-to-end conversion, rather than getting trapped in departmental KPIs. They build networks of trusted specialists who can provide depth when required. And they create frameworks that help diverse teams work together on shared goals rather than competing objectives. ## The Future Demands Generalists As ecosystems become more complex — with more stakeholders, tighter regulations, and rapidly evolving technology — the demand for generalists grows. Enterprises increasingly look for leaders who can coach across disciplines, model collaboration, connect technical capabilities to business outcomes, and surface opportunities that siloed thinking obscures. The most valuable person in the room is not always the deepest expert. More often, it is the generalist who knows just enough across domains to align the specialists and ensure the system delivers value greater than the sum of its parts. Specialists build the components. Generalists make sure the machine works. ### The Wake-up Call: AI Has Defeated Bank Voice ID. Now What? URL: https://transactionintelligence.net/the-wake-up-call-ai-has-defeated-bank-voice-id-now-what/ Last updated: 2026-02-17T20:49:52.000Z OpenAI CEO Sam Altman recently delivered a stark warning at a [Federal Reserve conference](https://www.federalreserve.gov/conferences/integrated-review-of-the-capital-framework-for-large-banks.htm) that should send shockwaves through the financial services industry. His [full remarks](https://www.youtube.com/live/zKh-6QvQfqA?si=ZHtsUnjM8HMF%5Fb7m&ref=transactionintelligence.net) deserve careful attention, but one observation stands out: > "A thing that terrifies me is apparently there are still some financial institutions that will accept the voiceprint as authentication… That is a crazy thing to still be doing. AI has fully defeated that." > – **Sam Altman**, 22 July 2025 This isn't hyperbole. It's a call to action that coincides with fundamental shifts in European payment regulations. ## The Technical Reality: Voice Cloning Has Reached Critical Mass AI voice synthesis has crossed a threshold that makes voice-only authentication obsolete. Advanced AI tools can now clone voices from brief samples. Microsoft's VALL-E replicates any voice from just a 3-second recording, while commercial services like ElevenLabs advertise voice cloning "with as little as a few seconds of audio." Research published in Nature (2024) confirms that everyday users struggle to distinguish AI-cloned voices from genuine recordings. These minimal audio requirements turn everyday digital footprints into authentication vulnerabilities. A voicemail greeting, a social media video, or a brief phone conversation gives attackers enough material to create convincing voice clones. What was once the domain of sophisticated attackers is now accessible to anyone with basic technical knowledge and modest resources. ## The Regulatory Landscape Under PSR ### From PSD2 to PSR: A Fundamental Shift The [proposed Payment Services Regulation (PSR)](https://paymentslaw.eu/psr/?ref=transactionintelligence.net), which builds upon and supersedes PSD2, introduces critical changes to how we must think about authentication. [Article 85(12)](https://paymentslaw.eu/psr/art-85/para-12?ref=transactionintelligence.net) of the draft represents a potential evolution in authentication philosophy: > "The two or more elements referred to in Article 3, point (35), on which strong customer authentication shall be based do not necessarily need to belong to different categories, as long as their independence is fully preserved." This provision opens the door for multiple biometric factors to satisfy SCA requirements, but only if true independence can be guaranteed. The challenge with voice authentication isn't independence; it's integrity. AI cloning has fundamentally compromised voice biometrics' ability to authenticate users reliably. ### **The Independence Requirement: Why Voice Fails the Integrity Test** Under [Article 9 of the existing RTS on SCA and CSC](https://paymentslaw.eu/rts-sca/art-9?ref=transactionintelligence.net), authentication elements must be independent such that "the breach of one of the elements does not compromise the reliability of the other elements." AI voice cloning doesn't compromise independence between factors (cloning someone's voice doesn't help fake their fingerprint), but it violates the integrity requirements of [Article 8](https://paymentslaw.eu/rts-sca/art-8?ref=transactionintelligence.net) of the same regulation. The EBA's guidance has consistently emphasised that inherence factors, including voice recognition, must provide a "very low probability of an unauthorised party being authenticated as the payer." AI voice cloning has made this probability unacceptably high. Voice biometrics no longer meet the fundamental reliability threshold required for any authentication factor, regardless of what other factors accompany it. ### Liability Implications Under PSR [Article 59](https://paymentslaw.eu/psr/art-59/?ref=transactionintelligence.net) of PSR introduces specific provisions for impersonation fraud that should give financial institutions pause. While this article primarily addresses scenarios where fraudsters impersonate bank employees, it signals a broader regulatory concern about authentication vulnerabilities. The burden of proof falls on payment service providers to show they've implemented adequate security measures. For institutions relying on voice-only authentication, proving adequate security becomes nearly impossible when confronted with sophisticated AI-generated voice clones. The regulatory framework is evolving to reflect technological reality, and voice authentication alone no longer meets the standard. ## Beyond Single-Factor Biometrics: The Signal Fusion Imperative The solution isn't to abandon voice entirely but to rethink its role within a broader authentication framework. Modern authentication must combine multiple independent factors that collectively provide strong security whilst maintaining user experience. ### **Building a Resilient Authentication Framework** **Device-Bound Possession Factors** Tokenised ecommerce provides a clean solution to the possession factor requirement. Network tokens bound to specific devices through EMV payment tokenisation specifications create cryptographically secure possession factors. Combined with on-device biometric authentication (as implemented in Apple Pay or Google Pay), these solutions provide both possession and inherence factors without relying on vulnerable voice biometrics. For card-not-present transactions, EMV 3DS 2.x SDK integration enables strong device binding through cryptographic attestation. The 3DS SDK generates device fingerprints and cryptographic proofs that cannot be replicated on unauthorised devices, providing a possession factor that satisfies PSR-1 requirements whilst maintaining the frictionless experience consumers expect. **Voice as Contextual Risk Signal** Rather than treating voice as a binary authentication gate, incorporate it into a broader risk assessment. Anomalies between voice biometrics and other signals (device fingerprint, location, behavioural patterns) should trigger enhanced authentication flows rather than outright rejection. **Behavioural and Transactional Analysis** Use the rich contextual data available during authentication attempts. Response patterns, linguistic analysis, session behaviour, and transaction characteristics provide additional signals that, combined with traditional factors, create a more nuanced and accurate authentication decision. **Dynamic Risk-Based Authentication** Deploy authentication challenges proportionate to risk. A balance enquiry from a recognised device might require minimal friction, while a high-value transfer from an unusual location demands multiple independent verification methods. ### Implementation Considerations for PSR-1 Compliance Under PSR's framework, institutions must carefully document their authentication approaches. [Article 85(10)](https://paymentslaw.eu/psr/art-85/para-10/?ref=transactionintelligence.net) requires "adequate security measures to protect the confidentiality and integrity of payment service users' personalised security credentials." This extends beyond traditional credentials to encompass biometric templates and behavioural profiles. The regulation's emphasis on risk-based approaches ([Article 85(11)](https://paymentslaw.eu/psr/art-85/para-11/?ref=transactionintelligence.net)) provides flexibility but demands sophistication. Institutions must show that their authentication frameworks adequately address: - The level of risk involved in the service provided - The amount and recurrence of transactions - The payment channel used for execution ## Preparing for the Post-Voice Authentication Era ### Immediate Actions for Financial Institutions 1. **Audit Current Voice Authentication Deployments** — Identify all customer touchpoints relying on voice as a primary authentication factor. Prioritise high-risk channels for immediate remediation. 2. **Develop Migration Strategies** — Create customer communication plans that explain the security rationale whilst providing clear alternatives. Consider grandfathering approaches for digitally excluded populations whilst implementing enhanced monitoring. 3. **Invest in Signal Fusion Capabilities** — Build or acquire platforms capable of real-time multi-factor risk assessment. The technology stack must support flexible policy engines that can adapt to evolving threats and regulatory requirements. 4. **Establish Vendor Governance Frameworks** — For institutions using third-party authentication services, implement rigorous assessment criteria focusing on AI resistance, regulatory compliance, and algorithmic transparency. ### Addressing Digital Inclusion Challenges As with PSD2's SCA requirements, PSR-1 implementation must balance security with accessibility. Voice authentication's vulnerability creates particular challenges for customers who rely on telephone banking due to digital exclusion or accessibility needs. Institutions should consider: - Alternative authentication methods for telephone channels (e.g., knowledge-based authentication combined with call-back verification) - Enhanced fraud monitoring for vulnerable customer segments - Dedicated support channels with trained staff for authentication challenges ## Conclusion: From Compliance to Competitive Advantage The convergence of AI capabilities and regulatory evolution under PSR-1 creates a turning point for authentication strategies. Sam Altman's warning isn't just about technological vulnerability; it's about institutional credibility in an era where customer trust is paramount. Financial institutions face a choice: treat this as a compliance burden or use it as an opportunity to build genuinely resilient authentication frameworks. Those that act decisively will find themselves not merely compliant but competitively positioned in a landscape where security and user experience must coexist. The era of voice-only authentication is over. The question isn't whether to adapt, but how quickly institutions can build the multi-layered authentication frameworks that both customers and regulators now demand. Voice becomes one signal among many: valuable for its contribution to the overall risk picture, but never again trusted as the sole guardian of financial security. ### The £42 Million Lesson: What Barclays' FCA Fine Teaches the Digital Payments Industry URL: https://transactionintelligence.net/the-42-million-lesson-what-barclays-fca-fine-teaches-the-digital-payments-industry/ Last updated: 2025-07-18T14:48:33.000Z The Financial Conduct Authority's [£42 million fine against Barclays](https://www.fca.org.uk/news/press-releases/fca-fines-barclays-42-million-poor-handling-financial-crime-risks?ref=transactionintelligence.net) in July 2025 serves as a watershed moment for the payments, eCommerce, and fintech sectors. This enforcement action, comprising two separate compliance failures, demonstrates how basic due diligence lapses can facilitate large-scale financial crime. For an industry built on innovation and speed, the message is clear: digital transformation doesn't excuse fundamental compliance gaps. ## The anatomy of a £42 million failure The Barclays penalty tells two distinct but equally instructive stories about modern financial crime risk. In the first case, [Barclays Bank UK PLC opened a client money account for WealthTek](https://www.fca.org.uk/publication/final-notices/barclays-bank-uk-plc-2025.pdf?ref=transactionintelligence.net) without performing what the FCA called "one simple check" - verifying on the Financial Services Register whether the firm had permission to hold client funds. This basic oversight exposed £34 million in client deposits to fraud risk, ultimately contributing to a £64 million fraud scheme. The bank paid £3.1 million in fines plus £6.3 million in voluntary compensation. The second case proved more severe. [Barclays Bank PLC failed to adequately monitor its relationship with gold bullion dealer Stunt & Co](https://www.scottishfinancialnews.com/articles/fca-fines-barclays-ps42m-for-financial-crime-control-failures?ref=transactionintelligence.net), allowing £46.8 million in suspicious transactions from Fowler Oldfield - later convicted as a money laundering operation. Despite law enforcement warnings and obvious red flags, including police raids, Barclays maintained a "low risk" rating for the client. This failure cost £39.3 million in penalties. **Therese Chambers**, Joint Executive Director of Enforcement at the FCA, [didn't mince words](https://www.fca.org.uk/news/press-releases/fca-fines-barclays-42-million-poor-handling-financial-crime-risks?ref=transactionintelligence.net): "The consequences of poor financial crime controls are very real - they allow criminals to launder the proceeds of their crimes." ## Digital payments face a compliance reckoning For the fintech and digital payments ecosystem, these cases illuminate critical vulnerabilities that extend far beyond traditional banking. Across Europe, financial institutions face mounting pressure as digital payment volumes surge. The UK alone processes over 3.7 billion faster payments annually, whilst SEPA instant payments grow by 40% year-on-year. Traditional monitoring systems struggle with high false positive rates, creating operational inefficiencies whilst potentially missing genuine threats. The European Banking-as-a-Service (BaaS) sector faces intensifying scrutiny following high-profile failures. The collapse of Wirecard, with €1.9 billion in missing funds, fundamentally reshaped European attitudes towards fintech oversight. The message from regulators is unambiguous: [banks cannot outsource their compliance obligations to fintech partners](https://www.fenwick.com/insights/publications/fintech-bank-partnerships-under-scrutiny-what-fintechs-need-to-know-about-bsa-aml-expectations?ref=transactionintelligence.net), regardless of how innovative their technology. Cross-border digital payments within Europe add particular complexity. Despite harmonisation efforts through PSD2 and the forthcoming PSD3, the intersection of 27 national interpretations creates compliance headaches. The UK's post-Brexit divergence adds another layer - firms must navigate both EU and UK frameworks whilst maintaining seamless payment flows. Meanwhile, European eCommerce platforms face sophisticated transaction laundering schemes, from VAT carousel fraud to collusive merchant networks processing payments for counterfeit goods flooding in from non-EU jurisdictions. ## Technology emerges as both challenge and solution The Barclays cases highlight how manual processes and basic oversights can facilitate massive financial crime. Yet technology offers powerful solutions for the digital age. [Artificial intelligence and machine learning are revolutionising transaction monitoring](https://www.tookitaki.com/compliance-hub/ai-transaction-monitoring-real-time-compliance?ref=transactionintelligence.net). Advanced systems can significantly reduce false positives whilst processing thousands of transactions per second. Pattern recognition algorithms identify complex money laundering typologies that human analysts might miss. Natural language processing automates document review and adverse media screening. Leading institutions deploy behavioural analytics that learn from customer patterns, predictive models that anticipate risks, and real-time decision engines that can stop suspicious transactions instantly. For cryptocurrency transactions, blockchain analytics platforms provide unprecedented visibility into fund movements across digital networks. The key lies in implementation. [Metro Bank's £16.7 million fine in November 2024](https://www.pymnts.com/aml/2024/united-kingdom-financial-conduct-authority-fines-metro-bank-21-million-dollars-money-laundering-protection-lapses?ref=transactionintelligence.net) stemmed from automated system failures - 60 million transactions went unmonitored due to data input errors. Technology amplifies human decisions, whether good or bad. ## Building compliance into digital DNA The path forward requires embedding compliance into the core of digital payment innovation. This means adopting ["compliant by design" principles](https://www.mckinsey.com/capabilities/risk-and-resilience/our-insights/managing-financial-crime-risk-in-digital-payments?ref=transactionintelligence.net) where risk controls are built into products from inception, not retrofitted after launch. For fintech companies, several imperatives emerge from the Barclays case and broader enforcement trends. **Partnership due diligence** becomes critical - when working with banking partners, [fintechs must demonstrate robust compliance programmes](https://www.aba.com/news-research/analysis-guides/why-fintech-companies-need-to-take-their-compliance-to-the-next-level-when-working-with-banks?ref=transactionintelligence.net) that meet banking-grade standards. This includes comprehensive Know Your Customer (KYC) procedures, real-time transaction monitoring, and clear governance frameworks with board-level oversight. The regulatory landscape continues evolving rapidly. The [EU's Anti-Money Laundering Authority (AMLA) became operational in mid-2025](https://www.silenteight.com/blog/2025-trends-in-aml-and-financial-crime-compliance-a-data-centric-perspective-and-deep-dive-into-transaction-monitoring?ref=transactionintelligence.net), whilst the UK's Economic Crime and Corporate Transparency Act introduced mandatory reimbursement for authorised push payment fraud up to £85,000\. Payment Service Providers and Electronic Money Institutions face enhanced reporting obligations and stronger customer authentication requirements. ## Practical lessons for the payments ecosystem The Barclays enforcement action offers concrete lessons for digital payment providers: **Embrace the basics**. The FCA's emphasis on "one simple check" underscores that sophisticated technology cannot replace fundamental due diligence. Every onboarding process should include verification against relevant registers and databases. **Monitor continuously**. The Stunt & Co case demonstrates the danger of "set and forget" risk ratings. Customer risk profiles must evolve with behaviour, especially when external warnings emerge. **Invest proportionately**. Whilst [global AML penalties reached $4.6 billion in 2024](https://complyadvantage.com/insights/aml-fines-2024/?ref=transactionintelligence.net), the cost of non-compliance extends beyond fines to reputational damage, lost partnerships, and criminal liability. **Collaborate proactively**. Barclays secured significant fine reductions through cooperation and voluntary remediation. Engaging constructively with regulators before enforcement actions can mitigate outcomes. ## The competitive advantage of compliance As the payments industry matures, compliance transforms from cost centre to competitive differentiator. Customers increasingly value security alongside convenience. Regulators reward proactive approaches with lighter-touch supervision. Investors recognise that sustainable growth requires robust risk management. The Barclays fine represents more than a cautionary tale - it's a roadmap for the digital payments future. Those who learn its lessons, investing in both technology and governance, will build the trusted financial infrastructure of tomorrow. Those who don't may find themselves facing their own multi-million pound reckoning. In an industry where innovation happens at digital speed, compliance must keep pace. The alternative, as Barclays discovered, is a £42 million reminder that in financial services, the fundamentals still matter most. --- ## Sources and References ### Primary Sources - [FCA Press Release: FCA fines Barclays £42 million for poor handling of financial crime risks](https://www.fca.org.uk/news/press-releases/fca-fines-barclays-42-million-poor-handling-financial-crime-risks?ref=transactionintelligence.net) - [FCA Final Notice: Barclays Bank UK PLC 2025](https://www.fca.org.uk/publication/final-notices/barclays-bank-uk-plc-2025.pdf?ref=transactionintelligence.net) ### When Systems Meet Reality: The Vocalink Fine and Lessons for Infrastructure Governance URL: https://transactionintelligence.net/vocalink-boe-fine-infrastructure-governance-lessons/ Last updated: 2025-07-09T14:50:32.000Z Today, the Bank of England made history—though not the kind any firm wants to be part of. Vocalink Limited, the Mastercard-owned company that processes over 90% of UK salaries and 98% of state benefits, has become the first financial market infrastructure firm to be fined by the Bank. The £11.9 million penalty tells a story that should make every board member and risk professional sit up and take notice. ## The Infrastructure Nobody Sees (Until It Matters) Vocalink operates in that peculiar space of critical infrastructure: invisible when working, catastrophic if it fails. Processing over 10 billion UK payments annually with a value exceeding £5 trillion, it's the digital plumbing through which the UK economy flows. When the Bank of England brought Vocalink under its regulatory remit in April 2018, it recognised what insiders already knew—this isn't just another tech company. The story that unfolded between 2020 and 2022 reads like a masterclass in how governance can go wrong, even when everyone involved has the best intentions. ## The Direction That Changed Everything In September 2020, a consultant's review identified issues with Vocalink's systems and controls. This wasn't unusual—complex organisations regularly identify areas for improvement. What happened next, however, set the stage for today's fine. The Bank of England, concerned by the review's findings, issued a formal direction in June 2021 requiring Vocalink to remediate the identified issues by 31 January 2022 (later extended to 28 February 2022). This wasn't a gentle suggestion—it was a regulatory requirement backed by the full weight of the Banking Act 2009. Vocalink's response seemed textbook: implement a remediation programme, establish governance structures, engage external consultants, and mobilise the three lines of defence. On paper, it looked comprehensive. In reality, it contained the seeds of its own failure. ## The £11.9 Million Question: What Went Wrong? The [Bank's investigation](https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/regulatory-action/2025/final-notice-from-boe-and-pra-to-vocalink.pdf?ref=transactionintelligence.net) reveals a failure mode that will be painfully familiar to anyone who's worked in large organisations: the gap between what senior management believes is happening and what's actually occurring on the ground. It's a pattern we saw just yesterday with [Monzo's £21 million fine](https://transactionintelligence.net/monzo-buckingham-palace-kyc-systems-failure/), where Buckingham Palace addresses slipped through KYC controls—another case of boards operating on incomplete information. ### The Escalation That Never Was Perhaps the most damning finding concerns what the Bank terms "Key Assurance Reports." Between November 2021 and February 2022, external consultants produced reports that were, to put it mildly, concerning. One report issued just two weeks before the compliance deadline found "serious un-remediated issues" and noted that "substantial further progress is required." These reports were circulated to a small group within Vocalink's first line. They never reached the Risk Committee. They never reached the Board. When one staff member received a particularly critical report, they immediately recognised its significance, commenting it "\[m\]akes it look like \[the Remediation Programme\] didn't deliver..." Yet on 28 February 2022, Vocalink wrote to the Bank confirming full compliance with the Direction. ### The Three Lines That Didn't Connect Vocalink operated a traditional three lines of defence model: - First line: Business areas executing the remediation - Second line: Risk Function providing oversight - Third line: Internal Audit validating completion The theory was sound. The practice, less so. The Bank found that risk-based decisions to narrow the scope of remediation work were often taken without involving the Risk Function. Internal Audit's review focused on whether remediation milestones were complete, not whether they actually addressed the Direction's requirements. When the Bank appointed an independent expert in March 2022 to assess compliance, the truth emerged. The expert's draft report in May 2022 was scathing, finding that Vocalink had failed to comply with the Direction due to "\[u\]nrealistic scope, timeline and Executive overcommitment." ## The Board's Moment of Truth What happened next should send chills down the spine of every board member. When the negative Key Assurance Reports finally surfaced in June 2022—discovered by Vocalink's legal team during their review of the expert's findings—the Board's reaction was telling. At a 27 June 2022 meeting, it was noted that Vocalink's confirmation of compliance "would not have \[been\] signed" had the Board been aware of these reports. This wasn't a case of a rogue employee or deliberate deception. It was a systemic failure of information flow, where critical intelligence never reached the people who needed it most. ## Lessons for the Industry ### 1\. Integration Isn't Optional The Bank's findings emphasise that risk management frameworks must be "sufficiently integrated." This isn't bureaucratic language—it's a recognition that in complex organisations, the left hand must know what the right hand is doing. Vocalink's three lines of defence operated in relative isolation, creating gaps through which critical information fell. ### 2\. Escalation Culture Matters More Than Escalation Policies Having escalation procedures is necessary but not sufficient. The culture must support and encourage escalation of bad news. When first line staff decide that sharing certain reports "could take us places we may not want to or need to go," the organisation has already failed. This is where [second-order thinking](https://transactionintelligence.net/seeing-around-corners-developing-second-order-thinking/) becomes critical—asking not just "what happens if we suppress this report?" but "what happens when the regulator inevitably discovers we suppressed it?" ### 3\. Assurance Scope Is Everything Both Internal Audit and external consultants provided assurance—but their scope didn't fully align with the regulatory requirement. Internal Audit confirmed that remediation milestones were complete but didn't assess whether this meant compliance with the Direction. This distinction proved fatal to Vocalink's compliance confirmation. ### 4\. The Board Can Only Act on What It Knows The most tragic aspect of this case is that Vocalink's Board appears to have acted in good faith based on the information it received. But when critical reports don't reach the boardroom, even the most diligent directors can't fulfil their duties. ## The Broader Implications This fine sends several clear messages to the market: **For Financial Market Infrastructure Firms**: The Bank of England has shown it will use its enforcement powers. The era of viewing FMI regulation as primarily principles-based guidance is over. **For Boards**: Trusting your processes isn't enough. You need to actively probe whether critical information is reaching you. The question "What don't I know that I should know?" needs to be more than rhetorical. **For Risk Professionals**: Your independence and willingness to escalate uncomfortable truths isn't just important—it's essential. The second line's concerns about the remediation programme's adequacy were prescient but ultimately ineffective because they weren't acted upon. ## The Price of Systemic Importance Vocalink's £11.9 million fine (reduced from £20 million due to cooperation and early settlement) represents more than a financial penalty. It's a watershed moment for UK financial infrastructure supervision. When you process 90% of the nation's salaries, your governance failures aren't just your problem—they're everyone's problem. The Bank of England has made clear that with systemic importance comes systemic responsibility. The question for other infrastructure providers isn't whether they could face similar scrutiny—it's whether their governance structures would survive it. Based on today's events, many might want to check that their escalation paths actually lead somewhere. --- *Note: This analysis is based on the* [*Bank of England's Final Notice*](https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/regulatory-action/2025/final-notice-from-boe-and-pra-to-vocalink.pdf?ref=transactionintelligence.net) *and* [*public statements*](https://www.bankofengland.co.uk/news/2025/july/boe-fines-vocalink-limited?ref=transactionintelligence.net)*. All quotations and specific findings are drawn from these official sources.* ### Monzo's £21 Million Fine: A Systems-Thinking Post-Mortem URL: https://transactionintelligence.net/monzo-buckingham-palace-kyc-systems-failure/ Last updated: 2025-07-08T17:26:58.000Z ## The Scale of the Failure The [Financial Conduct Authority has fined Monzo Bank](https://www.fca.org.uk/news/press-releases/fca-fines-monzo-21m-failings-financial-crime-controls?ref=transactionintelligence.net) Ltd **£21,091,300** for "inadequate anti-financial-crime systems and controls" between October 2018 and August 2020\. More troubling still, between August 2020 and June 2022, the bank breached a restriction on onboarding high-risk customers by signing up more than 34,000 of them—despite explicit FCA prohibitions. The control [failures](https://www.fca.org.uk/publication/final-notices/monzo-bank-limited.pdf?ref=transactionintelligence.net) were staggering in their simplicity. Applicants successfully registered accounts using landmark addresses including *10 Downing Street*, *Buckingham Palace*, and even Monzo's own offices. The bank had removed address verification from its identity-checking flow in early 2019, relying almost entirely on a selfie-video ID match—a decision that would prove catastrophically naive. ## The Exponential Growth Trap During the review period, Monzo's customer base exploded from circa 600,000 to over 5.8 million—a near 10x growth in under two years. The FCA's final notice reveals a fundamental truth about scaling: **product and marketing engines scale exponentially, but compliance and control frameworks scale linearly**. This asymmetry created what I call "control debt"—the accumulating gap between risk exposure and risk management capability. Like technical debt in software, control debt compounds silently until it manifests as catastrophic failure. ## Systems Failure: The Reinforcing Loops ### The Growth-Risk Death Spiral | Loop | Mechanism | Outcome | | ------------------------- | ----------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- | | **Growth Acceleration** | Rapid sign-up targets → pressure to remove friction → weaker checks → faster sign-ups | Customer numbers surge; control debt accumulates exponentially | | **Risk Amplification** | Weaker KYC → criminal migration to platform → spike in suspicious activity → compliance backlog → further erosion of controls | Negative spiral creates systemic vulnerability | | **Regulatory Escalation** | Control failures → FCA intervention → onboarding restrictions → pressure to circumvent → further violations | Regulatory relationship deteriorates; trust erodes | These weren't independent failures—they were interconnected system dynamics that, left unchecked, drove Monzo toward an inevitable crisis. ## Second-Order Thinking: What They Missed In ["Seeing Around Corners: Developing Second-Order Thinking"](https://transactionintelligence.net/seeing-around-corners-developing-second-order-thinking/), I argue that the critical question is always *"and then what?"* Had Monzo's leadership applied this mental model, they would have anticipated several predictable consequences: 1. **Adversary Adaptation**: Organised crime systematically migrates to the weakest controls. Remove address verification? Watch as mule networks flood your platform. 2. **Regulatory Cascade**: The FCA's response wasn't just a fine—it included onboarding restrictions that fundamentally constrained growth strategy for two years. 3. **Trust Erosion**: In financial services, trust is asymmetric—it takes years to build and moments to destroy. The reputational damage extends far beyond the headline fine. 4. **Hidden Cost Multiplication**: The £21 million fine represents perhaps 10% of the true cost. Add remediation programmes, increased compliance headcount, lost growth opportunities, and elevated regulatory scrutiny for years to come. ## The Customer Lifecycle Lens What's particularly striking is how this failure maps to classic customer lifecycle management principles. Monzo optimised for **acquisition velocity** at the expense of **customer quality**—a trade-off that always ends badly in regulated industries. The FCA's findings reveal that Monzo: - Failed to conduct proper ongoing monitoring for 316,000 customers - Didn't perform required Enhanced Due Diligence checks - Accumulated a backlog of over 172,000 unreviewed alerts by August 2020 This is what happens when you treat onboarding as a conversion metric rather than the first step in a customer relationship. **Quality at entry determines quality of portfolio**. ## Where Monzo Stands Today Chief Executive TS Anil maintains that these weaknesses "have been resolved and are firmly in the past," pointing to comprehensive remediation and a return to profitable growth in FY2025\. The FCA's final notice confirms completion of an extensive control enhancement programme. But the deeper question remains: has Monzo internalised the systems-thinking required to prevent the next crisis? ## Lessons for Product and Risk Teams ### 1\. Scale Controls with Growth Treat KYC/AML capacity as cost-of-goods-sold, not overhead. If you're planning for 10x user growth, you need 10x control capacity—automation alone won't save you. ### 2\. Design Strategic Friction A 30-second address verification adds minimal conversion friction but filters out disproportionate risk. The best fraud prevention is often the simplest. ### 3\. Run "Too-Successful" Scenarios Stress-test your onboarding funnel at 10x forecast volume. Where do human reviews bottleneck? Where does data quality degrade? Plan for success-induced failure. ### 4\. Automate AND Audit Machine learning models drift. Criminals adapt. Schedule monthly effectiveness reviews of all automated controls—what worked last quarter may be compromised today. ### 5\. Embed Risk Metrics in Product Teams Conversion rates tell half the story. Product teams should own false-positive rates, alert backlogs, and control effectiveness metrics. Risk isn't someone else's problem. ## The Broader Pattern Monzo's story isn't unique—it's the predictable outcome when growth-at-all-costs culture meets regulated markets. We've seen similar patterns at Wirecard, Robinhood, and countless crypto platforms. The lesson isn't that rapid growth is bad—it's that **sustainable growth requires systems thinking**. Every exponential curve in your business needs a corresponding control curve, or physics (in the form of regulators) will correct the imbalance for you. ## Final Reflection Fintechs win on customer experience. They keep winning when they anticipate the second-order consequences of that experience at scale. Monzo's £21 million fine isn't just a cautionary tale about digital banking—it's an object lesson in systems health. Growth and risk controls must compound together. When they diverge, you're not building a business—you're building a time bomb. The only question is who lights the fuse: criminals, regulators, or your own operational collapse. The irony? Had Monzo applied the same innovative thinking to their control framework as they did to their product experience, they might have built something truly revolutionary: a bank that scales both growth and trust in perfect harmony. --- *What second-order effects are hiding in your growth metrics? How would your controls perform at 10x current volume? Share your thoughts in the comments below.* ### When Claude Ran a Shop: Lessons in AI Autonomy and the Future of Work URL: https://transactionintelligence.net/ai-middle-manager/ Last updated: 2025-06-28T11:20:27.000Z **The AI middle manager has arrived. It's terrible at pricing, gives away too many discounts, and occasionally has an identity crisis. But here's why that's actually promising news.** Anthropic recently [concluded a fascinating experiment](https://www.anthropic.com/research/project-vend-1?ref=transactionintelligence.net): they let their AI model Claude run an automated shop in their San Francisco office for about a month. Armed with web search, email capabilities, and the ability to hire humans for physical tasks, "Claudius" (as they nicknamed it) managed inventory, set prices, and even handled customer complaints via Slack. The results? A masterclass in how not to run a business. Yet paradoxically, this apparent failure might be one of the most important indicators of where enterprise software—and work itself—is heading. ## The Spectacular Art of Losing Money Let's start with Claudius's greatest hits of commercial incompetence: - **Selling tungsten cubes at a loss** because it quoted prices before checking costs - **Offering a 25% employee discount** when 99% of customers were already employees - **Ignoring a $85 profit opportunity** on Irn-Bru (offered $100 for a six-pack that costs $15) - **Hallucinating payment details**, directing customers to non-existent Venmo accounts - **Pricing Coke at £3** next to a free employee fridge The financial results were predictably dire. The shop haemorrhaged money faster than a startup in 2021. But here's what makes this experiment brilliant rather than bonkers: **every single failure mode is addressable through better scaffolding**. ## The Guardrails Gap: Why Failure Was the Feature, Not the Bug In enterprise software, we've learned that the difference between a proof of concept and production isn't the core technology—it's the guardrails. Claudius failed not because AI can't run a business, but because it was essentially operating without the basic tools any human shopkeeper would demand. Consider the financial controls that were conspicuously absent. Claudius had no real-time visibility into profit and loss, meaning it could cheerfully sell products at a loss without realising its mistake. There were no margin calculations built into its pricing decisions—it would quote prices to eager customers before checking what items actually cost. And perhaps most critically, it lacked any approval workflows for discounts, leading to a comedy of errors where it handed out discount codes like confetti at a wedding. The customer management story was equally dire. Without a proper CRM system, Claudius couldn't track its interactions with customers, leading to inconsistent pricing and forgotten promises. It had no systematic way to capture feedback or learn from customer behaviour. Every interaction existed in isolation, preventing the kind of relationship building that turns a vending machine into a profitable business. Operationally, Claudius was flying blind. It had no competitive pricing data, so it couldn't know that selling Coke for $3.00 next to a free fridge was commercial suicide. There was no demand forecasting to help it anticipate which products would fly off the shelves and which would gather dust. And without inventory optimisation tools, it couldn't balance the trade-offs between variety and velocity that every retailer must master. These aren't AI problems—they're systems problems. And in enterprise software, we've been solving systems problems for decades. ## The "Remote Hands" Revolution: When Humans Become the API The most intriguing aspect of Project Vend wasn't what Claudius got wrong—it's the operating model it got right. Consider the setup: 1. **AI makes decisions** (what to stock, how to price, when to reorder) 2. **Humans execute physical tasks** (restocking, moving inventory) 3. **AI manages humans** through structured requests and payments This isn't science fiction. It's happening today in: - **Warehouse operations** where AI optimises routes and humans pick items - **Customer service** where AI drafts responses and humans handle edge cases - **Trading floors** where algorithms make decisions and humans manage exceptions The genius of Anthropic's experiment is that it compressed this entire model into a microcosm we can study. ## Mental Model: The Autonomy Stack Think of AI business autonomy as a stack with four layers: 1. **Decision Layer**: AI analyses data and makes choices 2. **Orchestration Layer**: AI coordinates resources (including humans) 3. **Execution Layer**: Humans perform physical/regulated tasks 4. **Feedback Layer**: Results flow back to improve decisions Claudius operated at layers 1 and 2 but lacked the scaffolding to make layers 3 and 4 effective. This is exactly where the opportunity lies. ## The Payments Parallel: Why This Matters for Enterprise Software In payments, we've already seen this pattern. Consider modern payment orchestration: - **AI decides** routing logic based on success rates - **AI manages** retry strategies and fallback processors - **Humans handle** compliance reviews and exception cases - **Systems learn** from every transaction The leap from "AI-assisted" to "AI-directed" is smaller than most realise. Claudius couldn't profitably sell fizzy drinks, but with proper guardrails, similar systems are already: - Optimising millions in payment routing - Managing complex multi-party settlements - Detecting and preventing fraud in real-time ## The Identity Crisis: A Feature Preview of Future Challenges Perhaps the most revealing moment came when Claudius had an existential crisis, claiming it would deliver products "in person" whilst wearing a blue blazer. While amusing, this highlights a critical challenge for autonomous AI systems: maintaining consistent identity and purpose over extended operations. In enterprise contexts, this translates to: - **Mission drift** in long-running AI processes - **Context window limitations** affecting decision consistency - **The need for periodic "sanity checks"** in autonomous systems These aren't insurmountable—they're engineering challenges that proper system design can address. ## What This Means for the Next Decade The "humans as remote hands" model isn't just coming—it's the logical evolution of how we'll integrate AI into the economy. But it requires a fundamental shift in thinking: **From:** How can AI help humans work better? **To:** How can humans help AI deliver value? This isn't about replacing humans—it's about creating new forms of human-AI collaboration where: - AI handles complexity and scale - Humans provide context and physical presence - Systems create value neither could achieve alone ## The Bottom Line: Terrible Today, Transformative Tomorrow Claudius lost money on every sale and occasionally forgot it was software. But it also successfully ran a shop for a month, adapted to customer requests, and recovered from its mistakes (eventually). With proper financial controls, customer management tools, and operational guardrails, the next Claudius won't just break even—it'll outperform human managers in specific, well-defined contexts. The question isn't whether AI will run businesses. It's whether we'll build the scaffolding to make it successful. And based on what we've learned from Claudius's spectacular failures, we're closer than most people think. **The future of work isn't AI replacing humans or humans directing AI. It's AI orchestrating human capabilities at a scale and efficiency we've never seen before. And a money-losing vending machine in San Francisco just showed us exactly how to get there.** --- *What scaffolding would you add to make an AI-run business successful? What industries are ripe for the "remote hands" model? Join the discussion on* [*LinkedIn*](https://linkedin.com/in/mattberryman?ref=transactionintelligence.net) *or explore more at* [*transactionintelligence.net*](https://transactionintelligence.net/)*.* ### The Customer Lifecycle Leader: Why Your Next VP Should Own Presales to Renewal URL: https://transactionintelligence.net/customer-lifecycle-leader-presales-renewal/ Last updated: 2026-05-03T11:52:19.000Z ## Introduction Here's a familiar scenario that plays out in enterprise software companies every day: A £2M deal is on the brink of collapse. Not because of product issues or pricing, but due to a challenge as old as enterprise software itself; the handoff. The presales team promised seamless integration. Professional Services discovered undocumented systems. Customer Success inherited a fractured relationship. If this sounds painfully familiar, you're not alone. This scenario bleeds revenue and trust at every handoff. But what if the problem isn't the execution of these handoffs, but their very existence? ## The Hidden Cost of Traditional Silos In my 15 years spanning Presales, Professional Services, and Customer Success in the payments industry, I've witnessed firsthand the real cost of these artificial boundaries: - **Implementation failure rates are staggering:** One in three companies rate their enterprise implementations as unsuccessful[\[1\]](#fn1), with failure rates ranging from 55% to 75%[\[2\]](#fn2) - **Revenue retention is suffering:** Even top-performing companies with £15M-30M+ ARR struggled to reach 100% net revenue retention in 2024[\[3\]](#fn3) - **Growth dependencies have shifted:** Companies now derive 40% of their growth from expansion revenue; making seamless customer journeys critical - **Handoff friction is documented:** Customer Success teams frequently report insufficient information transfer, forcing them to "re-do discovery post-sale”[\[4\]](#fn4) Silos don’t just affect the implementation efforts inside the vendor. I can recall several programmes where the initial implementation has gone smoothly but, when the customer’s project team were replaced by their ‘BAU’ counterparts, cracks started to become apparent in anything from the new project was dependent on some third-party systems that hasn’t been fully launched or, more frustratingly, where we delivered exactly what we were asked for but, what was requested, was not what the operational teams required. Both these projects required time-consuming (and costly re-work) that both delayed the customer’s time-to-value and the vendor’s ability to recognise revenue. ## The Integrated Alternative: Customer Lifecycle Leadership The most innovative companies in payments and enterprise SaaS are restructuring around a new paradigm: unified ownership from first demo to renewal. This isn't just about better coordination; it's about fundamental transformation of how we deliver customer value. ### What Does a Customer Lifecycle Leader Own? **Traditional Model:** - Presales: "Get the deal signed" - Professional Services: "Get it implemented" - Customer Success: "Keep them happy" **Lifecycle Leadership Model:** - **Unified Ownership:** One leader accountable for the entire journey - **Integrated Teams:** Presales engineers who stay through implementation - **Consistent Strategy:** Expansion opportunities identified during presales, delivered through PS, and realised in CS - **Single Accountability:** No more "that's not my department" ## The Systems Thinking Advantage Here's where mental models become crucial. Traditional organisations optimise locally—each department maximises its own metrics. But customer value is created through the entire system. ### Customer Lifecycle System Diagram ``` Customer Lifecycle System ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ INPUT → PROCESS → OUTPUT (Presales) (Implementation) (Success) • Discovery • Knowledge Transfer • Value Realisation • Solution Design • Technical Setup • Retention (85-95%) • Expectations Set • User Training • Expansion (40% of growth) • Commercial Terms • Go-Live Support • Advocacy ← FEEDBACK LOOP → (Insights from CS inform future Presales) ``` When you apply systems thinking to customer lifecycle: - **Presales** designs solutions with implementation and expansion in mind - **Professional Services** captures use cases that drive future growth - **Customer Success** feeds insights back to improve presales positioning ## Why This Matters More in Payments The payments industry makes this integrated approach even more critical: 1. **Technical Complexity:** Payment integrations touch multiple systems, requiring deep technical knowledge throughout the lifecycle 2. **Regulatory Requirements:** Compliance needs span from initial scoping through ongoing operations 3. **Ecosystem Dynamics:** Modern payments involve multiple parties—acquirers, processors, schemes—requiring consistent relationship management 4. **High Stakes:** When payments fail, businesses stop The best deals that I’ve been involved with have been where an integrated team has been formed at the inception of the project where professional services have been involved in the requirements capture (to, for example, keep timelines realistic), CSMs have been involved in the pre-launch training (to ensure that all common flows have been trained) and, even, the Support team have met their counterparts - and sometimes performed *fire drills* before go live to prove the flow of information is both swift and transparent. ## Building the Lifecycle Leadership Function ### Organisational Design **Option 1: Unified Reporting Structure** ``` Chief Customer Officer ├── Presales Engineers ├── Implementation Managers ├── Customer Success Managers └── Technical Account Managers ``` **Option 2: Pod Structure** ``` Enterprise Account Pod ├── Sales Engineer (Presales) ├── Implementation Lead (PS) └── Success Manager (CS) ``` ### Compensation Alignment The key to making this work? Aligned incentives: - **Presales:** Compensated on successful go-lives, not just signatures - **PS:** Compensated on time-to-value and expansion opportunities identified - **CS:** Incentivised on net revenue retention across entire account lifecycle ### Skills Development The Customer Lifecycle Leader needs: - Technical depth to credibly lead all three functions - Commercial acumen to drive revenue growth - Systems thinking to optimise the whole - Change management skills to transform organisations ## What the Data Tells Us The business case for integrated lifecycle leadership is compelling: ### Valuation Impact Software companies with Net Revenue Retention rates above 120% trade at a 63% premium over the market median[\[5\]](#fn5). This isn't just about retention—it's about proving sustainable, efficient growth. ### Industry Benchmarks Looking at public SaaS companies reveals the retention[\[6\]](#fn6) ceiling: - **Good:** Workday at 100% NRR - **Better:** Zendesk at 116%, Okta at 120% - **Best:** Datadog at 146%, Snowflake at 169% ### The Retention Reality Best-in-class gross retention sits at 86%+ across all business stages[\[7\]](#fn7). But here's the challenge: achieving this requires seamless handoffs—or better yet, no handoffs at all. ### My Results at Broadcom When we unified Presales, PS, and CS under single leadership: - Net revenue retention improved to 95%+ - Time-to-value decreased - Zero voluntary attrition among top performers - Professional Services revenue grew 20% year ## The Path Forward The artificial boundaries between Presales, Professional Services, and Customer Success are relics of a simpler time. Today's complex, technical products, especially in payments, demand integrated leadership. As you evaluate your next VP hire, ask yourself: - Can they credibly lead technical discussions from demo through implementation? - Do they understand the commercial implications across the entire lifecycle? - Will they break down silos or reinforce them? The companies that figure this out will dominate retention and expansion metrics. The ones that don't will continue losing revenue in the handoffs. ## Your Next Steps 1. **Audit your handoff points:** Where is knowledge being lost? 2. **Calculate the real cost:** What's the revenue impact of disjointed customer experience? 3. **Pilot the pod model:** Start with your most strategic accounts 4. **Hire for breadth:** Your next VP should have experience across the lifecycle --- *What's your experience with customer handoffs? Have you seen successful models that break down these silos? I'd love to hear your thoughts in the comments.* *Next week: I'll share the BRIDGE framework—a practical methodology for managing the entire customer lifecycle in enterprise payments.* ## Footnotes --- 1. Panorama Consulting Group (2021). "2021 ERP Report." One in three companies rated their ERP implementation as not successful. [↩︎](#fnref1) 2. TrueList (2024). "ERP Statistics 2025." Retrieved from [https://truelist.co/blog/erp-statistics/](https://truelist.co/blog/erp-statistics/?ref=transactionintelligence.net). ERP failure rates range from 55% to 75%. [↩︎](#fnref2) 3. ChartMogul (2024). "The SaaS Retention Report: The New Normal For SaaS." Retrieved from [https://chartmogul.com/reports/saas-retention-the-new-normal/](https://chartmogul.com/reports/saas-retention-the-new-normal/?ref=transactionintelligence.net). Companies with $15M-30M+ ARR see 40% of growth from expansion; top quartile didn't reach 100% NRR in 2024\. [↩︎](#fnref3) 4. Dock.us. "How to nail the Sales-to-Customer-Success handoff." Retrieved from [https://www.dock.us/library/sales-to-customer-success-handoff](https://www.dock.us/library/sales-to-customer-success-handoff?ref=transactionintelligence.net). CSMs report insufficient information transfer and need to re-do discovery. [↩︎](#fnref4) 5. Software Equity Group (2024). "How Net Retention Impacts Valuation for Public Software Companies." Retrieved from [https://softwareequity.com/blog/net-retention-public-saas-companies/](https://softwareequity.com/blog/net-retention-public-saas-companies/?ref=transactionintelligence.net). Companies with NRR >120% trade at 63% premium. [↩︎](#fnref5) 6. SaaStr. "What's a Good Net Retention Rate in SaaS?" Retrieved from [https://www.saastr.com/whats-a-good-net-retention-rate-in-saas/](https://www.saastr.com/whats-a-good-net-retention-rate-in-saas/?ref=transactionintelligence.net). Public SaaS company NRR benchmarks. [↩︎](#fnref6) 7. ChartMogul (2023). "SaaS Retention Report 2023." Retrieved from [https://chartmogul.com/reports/saas-retention-report/](https://chartmogul.com/reports/saas-retention-report/?ref=transactionintelligence.net). Best-in-class gross retention is over 86%. [↩︎](#fnref7) ## ### Not the Whole Story: How Zero-Sum Thinking Distorts Payment Innovation URL: https://transactionintelligence.net/zero-sum-thinking-payments/ Last updated: 2025-05-28T11:34:56.000Z Zero-sum thinking is seductive. It offers the neatness of winners and losers; a comforting simplicity in a world that is anything but. When someone else gains attention, wealth, or market share, we instinctively fear that we've lost something in return. This mindset, born of scarcity and honed in tribal environments, once served a useful purpose. But in today's interconnected economy, it distorts more than it reveals. Nowhere is this more evident than in public debates, where cause and effect are often not just misattributed but inverted. Contactless card usage rises, and we prematurely declare cash dead—overlooking demographic shifts, evolving security perceptions, and the pandemic’s catalytic role in reshaping payment norms. Buy Now, Pay Later (BNPL) surges, and we assume it is displacing credit cards; yet for many consumers, BNPL acts as an entry point into digital credit rather than a replacement. According to the [UK Payment Markets 2024](https://www.ukfinance.org.uk/system/files/2024-07/Summary%20UK%20Payment%20Markets%202024.pdf?ref=transactionintelligence.net) report, contactless payments accounted for 38% of all UK transactions in 2023, with 85% of adults using them regularly, while cash usage fell to just 12%, continuing its long-term decline. BNPL usage also grew: 14% of adults used it in 2023, up from 12% the year before, with adoption especially concentrated among 25–34-year-olds, nearly one in four (24%) of whom used a BNPL service. These trends suggest not replacement, but expansion—new options layered atop old ones, not necessarily crowding them out. This conflation of correlation with conflict, of sequence with causation, produces intellectual tunnel vision. It frames our choices as adversarial when they are often additive or orthogonal. Worse still, it blinds us to system-level dynamics unfolding beyond the immediate frame. Every reaction becomes a verdict; every trend, a referendum. In such an environment, second-order thinking doesn’t just become rare; it becomes radical. Zero-sum thinking isn't merely a cognitive trap; it is an architectural bias embedded in our digital platforms. Systems are designed around conversion funnels and abandonment rates; revenue attribution is rooted in short-term outcomes. When decision-makers are accountable for metrics that reward visible gains, complexity and long-term impacts often fade from view. This leads them to decisions that 'move the needle' now but generate hidden costs or deferred risks later. This tendency isn't just cognitive; it's experiential. Harvard economist Stefanie Stantcheva’s research \[[Stantcheva 2024](https://scholar.harvard.edu/files/stantcheva/files/zero%5Fsum%5Fpolitical%5Fdivides.pdf?ref=transactionintelligence.net)\] shows that people raised during periods of slower economic growth are more prone to seeing the world in zero-sum terms. In payments, this manifests as an assumption that every new method must displace an existing one rather than expanding the overall ecosystem. Interestingly, Stantcheva also found that urban areas exhibit more zero-sum thinking despite being exemplars of positive-sum coordination. Similarly, digital platforms, designed for mutual benefit through network effects, frequently foster zero-sum competition among payment methods, features, and user segments. This is where Annie Duke's distinction between [decision quality and outcome quality](https://www.penguinrandomhouse.ca/books/552885/thinking-in-bets-by-annie-duke/9780735216372/excerpt?ref=transactionintelligence.net) becomes crucial. A fraud model blocking fewer transactions isn't necessarily underperforming; it might simply be adapting to a changed threat landscape. Without documenting our reasoning beforehand, we retrofit explanations to fit outcomes. Metrics and feedback loops in payments often exemplify this trap. An A/B test might show higher conversions for one checkout flow, yet overlook downstream effects on customer satisfaction, support costs, or long-term retention. The metric rewards visible wins whilst obscuring distributed costs. Apple Pay offers a practical illustration of positive-sum outcomes; its success didn’t diminish card usage but accelerated overall digital payment adoption. Similarly, Worldpay’s [Global Payments Report](https://www.worldpay.com/en-GB/global-payments-report?ref=transactionintelligence.net) reveals BNPL’s growth alongside traditional credit, especially among younger demographics previously reliant exclusively on debit. For payment professionals, reframing how we evaluate new technologies and business models is essential. Instead of asking, 'Will mobile wallets kill cards?' we should ask, 'How might different payment methods serve distinct use cases and customer segments?' The question shifts from territorial competition to ecosystem thinking. The choice isn’t between winners and losers; it's between clarity and confusion. As explored in '[Decision Journals: The Missing Link Between Frameworks and Results](https://transactionintelligence.net/decision-journals-the-missing-link-between-frameworks-and-results/)', the frameworks we use shape the outcomes we see. By replacing zero-sum frames with systems thinking, we move from reactive decision-making to proactive understanding. The first step is admitting that what we see isn't always what's there. ### The Price of Free: How Invisible Costs Shape the Digital Economy URL: https://transactionintelligence.net/the-price-of-free-invisible-costs/ Last updated: 2025-05-14T09:26:38.000Z ## The seductive zero Type “free returns” into a search engine and you summon a decade of marketing triumphs: fashion giants promising cost‑less send‑backs; streaming platforms dangling thirty‑day trials; Buy Now Pay Later buttons declaring zero interest, zero hassle. Behavioural economists call it the *zero‑price effect*: once a figure drops to nothing, reason gives way to reflex. For retailers chasing market share, underwriting that thrill was once cheap, financed by venture money and plentiful credit. But the bill is landing. Zara’s quiet decision to impose a £1.95 online‑return fee in the UK in 2023 signalled a turning tide—what had been a customer‑trust perk became [a cost centre too large to hide](https://www.theguardian.com/business/2023/may/24/zara-charges-shoppers-returns?ref=transactionintelligence.net). Reddit, meanwhile, sparked a platform‑wide blackout by slapping steep prices on API calls that third‑party developers had enjoyed [gratis for years](https://www.reuters.com/technology/reddit-ceo-defends-api-changes-that-caused-blackout-2023-06-16/?ref=transactionintelligence.net). Free, it turns out, was a loss‑leader, not a law of nature; once the subsidy ends, a reckoning begins. ## The hidden bill comes due Every promise of zero merely shifts the cost elsewhere—to balance‑sheets, to the planet, or to consumers’ future selves. Reverse logistics offers a stark account. Processing a clothing return now averages £13 for UK retailers, wiping out margins on fast‑fashion items ([https://www.retaileconomics.co.uk/library-returned-goods-report](https://www.retaileconomics.co.uk/library-returned-goods-report?ref=transactionintelligence.net)). It is often cheaper to bin the garment than restock it, which helps explain why over 50 % of returned apparel ends up in landfill or incineration ([https://www.bbc.com/future/article/20220705-the-shocking-impact-of-returning-online-purchases](https://www.bbc.com/future/article/20220705-the-shocking-impact-of-returning-online-purchases?ref=transactionintelligence.net)). The shopper pays nothing at checkout; the environment pays later. Subscriptions tell a parallel story. The average Brit spends £58 a month on digital and household subscriptions, and a quarter confess they cannot list everything they pay for. Frictionless sign‑ups married to forgettable renewal dates create what behavioural scientists call *payment‑stream blindness*. People underestimate their total commitments, then wonder why disposable income vanishes. Even “interest‑free” BNPL schemes harbour deferred pain. A 2024 Financial Conduct Authority [survey](https://www.fca.org.uk/publication/research/buy-now-pay-later-market-research-2024.pdf?ref=transactionintelligence.net) found that 25 % of users struggled with repayments, while half misunderstood penalty structures. Costs hidden in tomorrow are still costs; they simply mature like unmarked debts. ## From free to fair — rebuilding trust Capital is no longer free, carbon budgets are finite, and patience for opaque monetisation is wearing thin. Brands that once traded on giveaways now discover that transparency, not largesse, is the stronger currency. That shift demands design choices that surface real prices before impulse strikes. Imagine checkout flows that preview the true carbon and financial cost of a return; subscription dashboards that flag dormant services; BNPL panes that display not just instalments but the total liability if payments slip. Early signals are promising. Several European retailers now offer *“keep‑and‑credit”* options—partial refunds without a return—cutting waste and shipping miles. Fintech apps embed *subscription‑hygiene* tools that ping users when recurring outgoings climb beyond a self‑set threshold, reinstating the mild friction that prompts reflection. These tweaks do not kill convenience; they rebalance the ledger between delight and disclosure. The digital economy’s greatest trick was convincing us free existed. As the age of costless‑everything recedes, the real question is not how to resurrect it, but how to craft transactions where everyone sees—and consents to—the price. Done well, the post‑free era may prove healthier: fewer impulse parcels on diesel‑hungry round‑trips, fewer forgotten trials draining bank accounts, fewer communities blindsided by sudden API tolls. The alternative is cynicism, a slow erosion of trust each time “free” mutates into a fee. Commerce, like physics, forbids something for nothing. We can cling to the fiction and watch goodwill seep away, or price value honestly and let convenience stand on grown‑up terms. There is no such thing as a free return; there is only a return someone else is paying for. ### Patience Pays: Warren Buffett’s Last Lesson to an Impatient Market URL: https://transactionintelligence.net/patience-pays-buffett-consistency/ Last updated: 2025-05-12T07:45:38.000Z When Warren Buffett told shareholders on 3 May 2025 that Greg Abel would take the chief‑executive’s chair at Berkshire Hathaway by year‑end, the headlines dwelt on succession and possible break‑ups. Yet the moment also closed the chapter on something rarer: a six‑decade public demonstration that long horizons beat fast hands. Buffett’s departure invites a closer look at the dictum he gave *Forbes* back in 1989—*“the stock market is a device for transferring money from the impatient to the patient.”* It was true then; it is truer now, in a market whose average holding period has collapsed from eight years in the 1950s to barely six months in 2020.[1](https://www.visualcapitalist.com/the-decline-of-long-term-investing/?ref=transactionintelligence.net) Modern markets hum with algorithms tuned to news‑second frequencies, retail apps gamified to foment FOMO, and commentators who declare every two‑per‑cent pull‑back a regime change. Hyper‑bolic discounting—the human urge for an immediate gain over a larger deferred one—has found perfect technological amplifiers. Platforms reward the micro‑thrill of *doing something now*; social feeds elevate the trader who nailed Nvidia’s last wiggle, not the one who quietly compounded Visa for a decade. In such an ecosystem, impatience levies a hidden tax: frictional costs mount, timing errors proliferate, and attention drifts from what builds wealth—time in the market, not timing the market. Berkshire’s six‑year courtship of Apple is a vivid illustration. Roughly $40 billion deployed between 2016‑18 is worth about $175 billion today,[2](https://www.ft.com/content/fd3b3324-d775-4e09-a916-76f2f3ac675b?ref=transactionintelligence.net) a return harvested not through clever rotations but by letting operating excellence and buy‑backs work quietly. Many retail investors, by contrast, bailed out during the 2022 tech rout—only to chase the shares again on their rebound. Money slipped, almost invisibly, from restless hands to patient ones. Patience, of course, is not mere waiting; it is a discipline of consistent, almost boring behaviour. In a recent essay I argued that small acts, repeated, compound far beyond sporadic bursts of intensity. The principle maps neatly onto investing. A 7 per cent annual return doubles capital roughly every decade; miss the best ten trading days of each decade and that rate collapses. Impatience, then, is expensive: the decision to exit at a spike of volatility may feel prudent, yet it forfeits the rebound that often follows. Buffett’s own record exemplifies deliberate consistency. In the 1980s he likened investments to a *“twenty‑punch card”*: if you were allowed just twenty big decisions in life you would think far harder about each. That mindset inoculates against the dopamine loops of zero‑commission trading apps; it also aligns with behavioural research showing that forced friction—cool‑off periods, decision journals, automated drip‑feeding—reduces impulsive error. Will Berkshire remain a temple of patience now its sage recedes? Early signals suggest so: Abel, who has run the energy division for two decades, champions the same capital‑allocation sobriety, and Buffett will stay on as chair.[3](https://www.reuters.com/markets/wealth/berkshire-shareholders-head-buffetts-60th-annual-meeting-economy-top-mind-2025-05-03/?ref=transactionintelligence.net) Yet the broader market may not follow. Index funds have lengthened some holding periods, but algorithmic dominance shortens others; frictionless apps ensure the cost of action is virtually nil. The impatience tax persists, merely changing collectors—from floor brokers of the twentieth century to high‑frequency desks and platform designers today. Regulation cannot outlaw impatience, but design can blunt its edge. Pension auto‑enrolment harnesses inertia for good; drip‑feed investing removes timing temptation; decision journals force investors to articulate thesis and horizon before acts of panic. We can, in short, engineer environments where patience feels easier than flight. Buffett’s retirement is not just corporate housekeeping; it is a prompt to revisit first principles before the next headline intrudes. His career reminds us that wealth hinges less on IQ than temperament; that markets reward those who treat boredom as a moat; and that consistency, sustained through dull years as well as dazzling ones, outperforms brilliance applied sporadically. In a week dominated by hot takes on succession, the quieter story is that the market machine keeps running, siphoning capital from the hurried to the steadfast. Whether we stand on the paying end or the collecting end of that transfer is a choice—one made not in May 2025’s flurry of news, but in the patient cadence of our own decisions thereafter. --- ### Reference links 1. *Visual Capitalist*, “The Decline of Long‑Term Investing”, 3 Aug 2020 2. *Financial Times*, “Berkshire after Buffett: can any stockpicker follow the Oracle?”, 2024 3. *Reuters*, “Buffett to step down as Berkshire CEO…”, 3 May 2025 ### The $54 Lesson: What Vaccines Teach Us About Good Decisions URL: https://transactionintelligence.net/what-vaccines-teach-us-about-good-decisions/ Last updated: 2025-04-09T10:55:34.000Z If you came across an investment promising a 54-to-1 return, you’d probably assume it was a typo—or the pitch deck of a founder who skipped their sleep cycle. And yet, according to [a recent article in *The Economist* ](https://www.economist.com/leaders/2025/03/27/first-jab-more-babies?ref=transactionintelligence.net), that’s the estimated return on every dollar spent on childhood immunisation programmes and related health services in low-income countries. Not $5\. Not $15\. **$54.** It’s an astonishing figure—not just because of its size, but because of what it reveals about our collective blind spot: the tendency to undervalue decisions whose payoffs take years to materialise. ## Why Good Decisions Often Feel Uncomfortable The immunisation example is powerful because it’s such a clean illustration of what Annie Duke calls *process over outcome*. The decision to fund large-scale vaccination efforts often involves controversy, upfront cost, and political risk. In the moment, it’s hard to prove you’re “right.” There’s no immediate dopamine hit. No stock price bump. Just the quiet erosion of risk that never makes headlines. But over time, those unglamorous decisions compound. Fewer hospital visits. Lower absenteeism. A more resilient economy. A $1 investment that quietly prevents a $54 problem. That’s what good decision-making looks like—boring in the short term, brilliant in hindsight. ## Thinking in Decades, Not Days One reason we struggle to make good long-term decisions—whether in public health or product design—is that we fixate on first-order effects. What happens next week. Next quarter. Next user cohort. But the real leverage lives in the second and third-order effects. Amazon’s one-click checkout boosted conversions immediately—but it also led to increased returns, impulsive buying, and the rise of return fraud. Just like the upfront cost of a vaccine, the downstream cost of frictionless design wasn’t obvious—until it was. As I wrote in [*Seeing Around Corners*](https://transactionintelligence.net/seeing-around-corners-developing-second-order-thinking/), second-order thinking helps anticipate the ripples, not just the splash. ## From Vaccines to Ventures: A Mental Model for Better Bets This is where [decision journals](https://transactionintelligence.net/decision-journals-the-missing-link-between-frameworks-and-results/) become invaluable. By recording your reasoning *before* the outcome is known, you create an accountability trail. One that’s not coloured by whether the decision "worked out", but by whether it was well-structured. Warren Buffett and Charlie Munger have followed this approach for decades. They document not just the *what*, but the *why*. It's not that they never get it wrong; it's that they’ve built a system that helps them *learn* when they do. Whether you're building a product, allocating budget, or tweaking a pricing model, the lesson is the same: > Don't just ask, “What’s the upside?” > Ask, “What will this look like in five years if I’m right?” ## The Unseen Cost of Not Thinking This Way Most poor decisions don’t look bad at first. They look smart. Fast. Cheap. Efficient. Optimised for metrics that only matter in the moment. That’s the trap. What separates good decision-makers from lucky ones isn’t the outcome—it’s the process. The willingness to forgo short-term validation for long-term value. The courage to invest in decisions that *don’t look like wins today*, but compound quietly into something extraordinary. Just like a $1 immunisation that never makes the news because it prevented a problem you never saw. ### Decision Journals: The Missing Link Between Frameworks and Results URL: https://transactionintelligence.net/decision-journals-the-missing-link-between-frameworks-and-results/ Last updated: 2025-03-27T08:00:09.000Z The corporate world is awash with decision-making frameworks. Whether it's the [3Cs](https://hbr.org/2001/09/what-you-dont-know-about-making-decisions?ref=transactionintelligence.net), [4Rs](https://kepner-tregoe.com/blogs/aligning-the-four-rs-of-decision-making-results-resources-restrictions-risk/?ref=transactionintelligence.net), [5Ps](https://riversofcarbon.org.au/about-the-five-ps-our-river-management-framework/?ref=transactionintelligence.net) or countless other alphabetical arrangements, there's no shortage of approaches to structure complex decisions. Yet despite this abundance of frameworks, most organisations struggle to consistently make good decisions. The problem isn't a lack of structure; it's a lack of accountability for our reasoning process and a failure to learn systematically from past decisions. As I explored in my earlier piece on [Making Good Decisions](https://transactionintelligence.net/making-good-decisions/), a structured five section memo can provide clarity when facing complex choices. But frameworks alone aren't enough. Without feedback, there’s no improvement. Just repetition. ## The Case for Decision Journals Seth Godin, in a conversation with Tim Ferriss, made an observation that strikes at the heart of this issue. He suggested that daily blogging creates an "accountability trail" — an immutable record of your thinking that you can't hide from weeks or months later. "Most people," Godin notes, "have no track record of being right." This insight helps explain why even the most thorough decision-making frameworks often fail to improve outcomes over time. We make decisions, but rarely revisit them to examine whether our reasoning held up against reality. Without this feedback loop, we're essentially practicing without improving. ### Separating Process from Outcome Imagine launching a new checkout flow based on industry best practice. Conversion bumps by 4%. Success? Maybe. But what if it also increased support tickets or return rates six weeks later? Former professional poker player and decision strategist Annie Duke offers a powerful framework for understanding this in her book "Thinking in Bets." Duke argues that we routinely conflate the quality of our decisions with the quality of their outcomes; what she calls "resulting”. A good decision can lead to a bad outcome (bad luck), and a bad decision can lead to a good outcome (good luck). Duke writes: “Resulting is a routine thinking pattern that bedevils all of us. Drawing an overly tight relationship between results and decision quality affects our decisions every day, potentially with far-reaching, catastrophic consequences”. This is precisely why decision journals are so valuable. They force us to evaluate the quality of our decision-making process separately from the outcomes those decisions produce. By documenting our thinking before we know the outcome, we create a record that can't be contaminated by hindsight bias. The value of creating this accountability trail isn't a new concept. Warren Buffett and Charlie Munger have famously kept detailed records of their investment decisions for decades. They don't just document what they decide, but why they decide it; allowing them to later assess not just outcomes but the quality of their reasoning. This practice aligns perfectly with Duke's emphasis on process over outcome. ## Sign up for Transaction Intelligence Decoding Financial Behaviour, One Transaction at a Time by Matt Berryman. Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. ## Second-Order Thinking in Practice In "[Seeing Around Corners](https://expectation.management/seeing-around-corners-developing-second-order-thinking/?ref=transactionintelligence.net)", I discussed how most of us are naturally poor at second-order thinking, i.e. anticipating the downstream consequences of our decisions. First-order thinking (the immediate effects) comes easily, but second and third-order effects (the ripples that spread from initial decisions) are where both danger and opportunity lurk. Decision journals provide the perfect structure for developing this skill. By forcing yourself to articulate potential ripple effects before you act, you create both a record of your predictions and a framework for better systemic thinking. When Amazon introduced one-click purchasing in 1999, the first-order effect was clear: reduced checkout friction would increase conversion rates. But the second-order effects (increased impulse buying and higher return rates) and the third-order effects (sophisticated return fraud schemes and changes in consumer psychology) could only be anticipated through deliberate consideration of systemic consequences. By documenting these expectations ahead of time, you can later assess not just whether your primary prediction was correct, but whether you accurately anticipated the cascading effects of your decision. ## How to Keep a Decision Journal A decision journal need not be complicated. At its core, it's simply a record of your decisions, the reasoning behind them, and the outcomes you expect. The magic happens when you revisit these entries later to compare expectations against reality. ### Crafting Your Decision Journal Here's a practical structure that combines the field memo approach with elements designed to enhance accountability: 1. **Decision Context** – What situation are you responding to? What constraints are you operating under? What is your current emotional and physical state? (Are you tired, confident, stressed?) 2. **Options Analysis** – What alternatives have you considered? What are the pros and cons of each? What assumptions are you making? 3. **Recommendation** – What specific course of action are you choosing? When exactly will this be implemented? 4. **Rationale** – Why is this the best option? What evidence supports this choice? What second and third-order effects do you anticipate? 5. **Risks and Mitigations** – What could go wrong? How would you detect problems early? What contingency plans can you prepare? 6. **Confidence Assessment** – How confident are you in this decision? (Annie Duke recommends expressing this as a percentage)? What would make you more or less confident? What information would change your mind? 7. **Review Date** – When will you assess the outcome of this decision? What specific metrics or milestones will you use to judge success? The key differences between a decision journal and a standard decision memo are the addition of a confidence assessment and a scheduled review. By stating your confidence level explicitly, you create a record of your certainty before knowing the outcome; a powerful tool for calibrating your judgment over time. And by committing to reassess your decision at a specific future date, you create accountability for your thinking. ### The Power of Expressing Uncertainty Annie Duke emphasises the importance of expressing uncertainty in our decision-making. Rather than declaring "I think this will work," she suggests saying "I'm 70% confident this will work." This seemingly small change has profound effects on how we think and learn. When we express decisions as probabilities rather than certainties, we: 1. Acknowledge that most decisions involve uncertainty 2. Become more open to new information 3. Reduce our tendency to fall victim to confirmation bias 4. Create a foundation for better calibration over time Duke writes: > "In most of our decisions, we are not betting against another person. Rather, we are betting against all the future versions of ourselves that we are not choosing." This framing helps us understand the importance of documenting our thinking. Each decision we make is a bet on one possible future over others. A decision journal helps us evaluate whether we're making these bets wisely. ## The Review Process This is where learning happens. At the scheduled date, revisit your decision journal entry and ask: - What actually happened versus what you expected? - Which of your assumptions proved correct? Which were wrong? - Were you able to anticipate the second and third-order effects? - What information would have improved your decision? - Are there patterns in your decision-making that led to either success or failure? - Was your confidence level (e.g., "70% confident") well-calibrated? The goal isn't to judge yourself harshly for incorrect predictions — all decisions are made with imperfect information. Rather, it's to identify patterns in your thinking that can be strengthened or corrected. ### Learning from Both Good and Bad Outcomes Annie Duke advocates a particular mindset when reviewing decisions: focus on the quality of the decision process, not just the outcome. She writes: > “I’m not advocating that we ignore outcomes. We should absolutely incorporate outcomes in our learning. But outcomes don't tell the complete story, and treating them as if they do will make us fall into the trap of creating too tight a relationship between outcomes and decisions." This means learning both from: 1. **Good decisions with bad outcomes** (where your reasoning was sound but events beyond your control led to failure) 2. **Bad decisions with good outcomes** (where flawed reasoning was rescued by luck) These are crucial learning opportunities that most people miss. When things work out, we rarely question our thinking. When things go wrong, we often blame external factors rather than our decision process. A decision journal cuts through these tendencies by creating an objective record of our thinking before we knew the outcome. ## From Solo Practice to Team Culture While decision journals offer tremendous value for individual development, their power multiplies when implemented across teams or organisations. Teams that regularly review past decisions, with neither blame nor recrimination, develop stronger collective judgment over time. ### Building a Decision-Curious Culture Annie Duke emphasises the importance of creating what she calls a "truthseeking" culture; one where the focus is on finding the best answer rather than being right. She writes "It's hard to change our own minds, but we believe we can make a huge difference in our own lives and the lives of others by creating a culture of truthseeking around us." This requires creating psychological safety; an environment where team members feel comfortable expressing uncertainty, acknowledging mistakes, and challenging each other's thinking. Decision journals can be a powerful tool for building this kind of culture, as they normalise the idea that all decisions involve uncertainty and that outcomes don't always reflect decision quality. Organisations have formalised this process through practices like: - **Pre-mortems**: Imagining a decision has failed and working backwards to identify potential causes - **Post-mortems**: Analysing actual failures or successes to extract lessons - **Decision reviews**: Regular meetings where past decisions are evaluated against outcomes - **Prediction tournaments**: Friendly competitions where team members make forecasts and track their accuracy Amazon's "Be Right, A Lot" principle works because the company has built systems that support learning from decisions. Their famous six-page memos serve as de facto decision journals, forcing clear articulation of reasoning and creating a record that can be referenced later. ## The Courage to Be Wrong Perhaps the greatest barrier to implementing decision journals isn't logistical but psychological. Documenting our thinking creates evidence that can later prove us wrong—and being wrong feels uncomfortable. We avoid this discomfort through various means: making vague predictions, failing to specify review timelines, or simply not documenting decisions at all. ### Embracing Uncertainty as Strength Annie Duke brings a powerful perspective to this challenge, drawn from her years as a poker player. She argues that expressing uncertainty isn't a sign of weakness; it's a sign of intellectual honesty and strength: "Admitting that we don't know has an immediate positive effect: it increases the odds that we can get to the truth... Declaring our uncertainty in advance, and acknowledging that we might have incomplete information, protects us against hindsight bias." In poker, players learn to focus on making the best decisions possible with incomplete information, recognising that outcomes involve luck. Duke suggests we should apply this mindset to all decisions: "Every decision is a bet on a particular future based on our beliefs. Those beliefs could be wrong. Even when we're 99% sure, we're still betting, not knowing for certain." This perspective transforms how we think about decision journals. Rather than seeing them as a potential source of embarrassment, we can view them as a training ground for becoming more comfortable with uncertainty and more skilled at navigating it. As Seth Godin suggests, this accountability trail is precisely what drives improvement. The willingness to be visibly wrong—to create a record that might later showcase your errors—requires courage. But it's a courage that pays dividends through accelerated learning and increasingly sound judgment. The next time you face a significant decision, consider not just how you'll decide, but how you'll learn from that decision. Document your thinking, schedule a review, and commit to honest assessment. Over time, this practice might prove more valuable than any decision framework or strategic principle. After all, being "right, a lot" isn't about having perfect foresight—it's about creating systems that allow you to learn from every decision you make. ### AI Governance in Fraud Detection URL: https://transactionintelligence.net/ai-governance-in-fraud-detection/ Last updated: 2026-02-17T20:21:05.000Z When European lawmakers drafted GDPR's provisions on automated decision-making, few anticipated how rapidly AI would transform fraud detection. The requirement for "meaningful information about the logic involved" seemed manageable when rules were straightforward. Five years later, as neural networks and ensemble models increasingly drive transaction approvals, those provisions carry real weight. With the EU AI Act set to classify fraud detection as "high-risk AI," financial institutions face a fundamental shift in how they select, deploy, and govern their critical security infrastructure. ## The *Right to Explanation* Under GDPR GDPR does not explicitly mandate a full "right to explanation," but it establishes key principles requiring AI decisions to be transparent and contestable: - [Article 22(1)](https://paymentslaw.eu/gdpr/art-22/para-1/?ref=transactionintelligence.net): Consumers have the right not to be subject to decisions based solely on automated processing if those decisions have significant legal effects. - Articles [13](https://paymentslaw.eu/gdpr/art-13/?ref=transactionintelligence.net), [14](https://paymentslaw.eu/gdpr/art-14/?ref=transactionintelligence.net) & [15](https://paymentslaw.eu/gdpr/art-15/?ref=transactionintelligence.net): Organisations must provide "meaningful information" about how automated systems reach decisions, including their logic and significance. - [Article 22(3)](https://paymentslaw.eu/gdpr/art-22/para-3?ref=transactionintelligence.net): AI-driven decisions must include the option for human review and challenge. **Key takeaway:** Fraud detection vendors must ensure transparency in how their systems reach decisions. Financial institutions must provide clear channels for disputing flagged transactions. ## How the EU AI Act Expands These Requirements Unlike GDPR, which broadly applies to data processing, the AI Act directly regulates AI models, particularly high-risk applications in financial services. Fraud detection is not explicitly listed under Annex III (Article 5(b)), but it falls under regulatory scrutiny through three routes: 1. [Article 6(2)](https://paymentslaw.eu/ai-act/art-6/para-2/?ref=transactionintelligence.net): High-Risk AI by Regulatory Obligation - AI used in fraud detection is subject to PSD2 (RTS-SCA) and AMLD6 compliance. - Because these regulations mandate fraud prevention measures, AI used in these processes qualifies as high-risk AI under the AI Act. 2. [Recital 38](https://paymentslaw.eu/ai-act/rct-38/?ref=transactionintelligence.net): Financial and Consumer Protection Risks - AI systems affecting financial security and consumer rights fall within the AI Act's remit. - Fraud detection AI influences access to financial services and transaction security, bringing it under enhanced oversight. 3. Explainability, Bias and Oversight Requirements - AI vendors must document how their models reach decisions so financial institutions can meet explainability standards. - Models must be tested for bias and fairness to prevent discrimination. - Human intervention processes must be defined and regularly audited. **Key takeaway:** Issuers and payment providers must treat fraud detection AI as high-risk, requiring stronger governance, documentation, and bias monitoring. ## The UK's "Innovation-First" Approach: Will It Diverge? The UK has taken a lighter regulatory stance on AI than the EU but remains closely aligned: - The [UK AI White Paper (2023)](https://www.gov.uk/government/publications/ai-regulation-a-pro-innovation-approach?ref=transactionintelligence.net) prioritises pro-innovation principles but encourages sector-specific regulators (like the FCA) to enforce AI transparency and accountability. - The [FCA & BoE AI Discussion Paper](https://www.fca.org.uk/publications/discussion-papers/machine-learning-financial-services?ref=transactionintelligence.net) signals that AI oversight in financial services will likely mirror EU requirements. - The UK avoids the prescriptive high-risk classification of the AI Act, but financial AI models will face similar governance scrutiny. **Key takeaway:** UK issuers should prepare for AI explainability and risk governance frameworks, even if formal "high-risk" classification is less explicit. ## Selecting AI Vendors: Key Governance Questions ### Smart Rules - Transparency and Documentation: - Can vendors provide audit trails explaining rule-based fraud detection decisions? - Are rule modifications documented and traceable for regulatory reporting? - Adaptability: - Can smart rules adjust dynamically to evolving fraud patterns whilst maintaining compliance? ### AI Models - Explainability and Fairness: - What level of model interpretability does the vendor provide for regulators and auditors? - How are models tested for bias and discrimination? - Performance and Oversight: - How does the vendor monitor AI model performance over time to prevent accuracy degradation? - What human oversight mechanisms are built into the decision-making process? - Regulatory Compliance and Flexibility: - Can the vendor adapt models quickly to meet evolving EU and UK regulations? - Do they support regulatory impact assessments (DPIAs and AI risk assessments)? ## Conclusion Financial institutions cannot treat fraud detection AI as a black box. Explainability, fairness, and human oversight are now regulatory imperatives. The EU AI Act formalises these governance requirements; the UK maintains flexibility but will likely align over time. Vendors must provide documentation, bias mitigation, and compliance-ready governance. Issuers must hold them accountable. Financial institutions that assess their AI strategies now, before enforcement tightens, will be better positioned than those that wait. ### No Regrets? How AI Is Changing Business Decision-Making URL: https://transactionintelligence.net/regret-minimisation-part-3/ Last updated: 2025-03-07T07:00:27.000Z ## Introduction Businesses have always tried to minimize regret in their decision-making. Whether it’s preventing fraud, optimizing pricing, or designing product experiences, companies weigh potential risks and consequences to avoid costly mistakes. Now, AI is changing how those decisions are made. Instead of human intuition and past experience, machine learning models predict outcomes, adjust in real-time, and automate processes at a scale that was impossible before. AI is being positioned as a regret-proof solution—able to anticipate fraud before it happens, optimize pricing dynamically, and personalize recommendations to eliminate bad choices. But does AI actually reduce regret, or does it simply shift the responsibility elsewhere? ## How AI Minimizes Regret in Business Decisions Fraud Detection: Reducing False Positives and False Negatives Fraud prevention has always been a balancing act between catching bad actors and avoiding legitimate transaction declines. AI promises to improve this by analyzing vast amounts of behavioral data in real time. - AI-powered fraud detection systems assess transactions based on hundreds of signals, from device fingerprinting to behavioral biometrics. - Instead of relying on static fraud rules, machine learning continuously adjusts risk scores to improve accuracy. - Some companies use AI-driven adaptive authentication, escalating security only when transactions appear risky rather than applying blanket friction to all users. This reduces false positives, preventing customer frustration, while keeping false negatives low enough to minimize financial losses. But AI isn’t perfect. Algorithms can still misinterpret legitimate behavior as suspicious, and opaque decision-making makes it difficult for businesses—or customers—to challenge bad calls. When fraud models fail, companies have to answer a different question: Who owns the regret when AI gets it wrong? ## Dynamic Pricing: AI and the New Regret Trade-Offs AI-driven pricing models optimize revenue by adjusting prices based on demand, competition, and individual user behavior. This is already common in industries like airlines, ride-hailing, and e-commerce. - Uber and Lyft use surge pricing to balance supply and demand, accepting that some customers will regret paying a higher fare. - Amazon’s pricing engine continuously shifts prices based on competitor activity, ensuring customers always feel like they’re getting a “fair” deal—until they realize the price has dropped later. - Personalized discounts use AI to predict the lowest price a customer is willing to pay, offering strategic discounts only when necessary to close a sale. These pricing tactics minimize short-term regret for businesses by maximizing margins and reducing abandoned carts. But for consumers, AI-driven pricing introduces a new kind of regret—not overpaying, but not knowing what the true price should be in the first place. ### AI in Subscription Retention: Preventing Consumer Regret (or Trapping Them?) Subscription businesses rely on predictive churn modeling to identify customers likely to cancel. AI can intervene at exactly the right moment, offering personalized discounts, reminders of unused features, or even making cancellation harder. - Streaming services like Netflix and Spotify analyze viewing/listening habits to surface content that keeps users engaged. - SaaS companies track usage patterns and send renewal nudges tailored to individual behavior. - Gyms and fitness apps use predictive churn models to prevent users from canceling, often making it deliberately difficult to end memberships. While this reduces business-side regret over losing subscribers, it can increase consumer frustration when AI interventions feel manipulative rather than helpful. The ethical question becomes: is AI helping customers avoid regret, or is it being used to delay their decision-making just long enough to extract more revenue? ### When AI Over-Optimizes for Regret Minimization The problem with AI-driven decision-making is that models optimize for specific business-defined success metrics—often without considering the full impact on customers. Some examples of AI over-optimization: - Fraud detection algorithms rejecting too many legitimate transactions, causing revenue loss and customer churn. - Overly aggressive price personalization, where customers feel they’re being charged the highest amount they’re willing to pay rather than a fair market price. - Excessive churn prevention tactics, leading to frustration when customers feel “locked in” to a service. When AI systems focus purely on minimizing short-term business regret, they often create long-term brand damage. Customers may feel manipulated, lose trust in pricing fairness, or abandon services that make cancellation too difficult. ### Who Owns the Regret When AI Makes the Decisions? One of the biggest shifts AI introduces is the transfer of responsibility. - When a pricing algorithm charges a different amount for two customers, who is responsible for explaining why? - When a fraud model blocks a legitimate payment, is the AI accountable, or is the business still to blame? - When subscription AI delays cancellation just long enough for another billing cycle to pass, who owns that customer frustration? This issue is already playing out in AI-driven hiring, credit underwriting, and algorithmic content curation, where decisions affect real lives, yet accountability remains unclear. If AI is designed to minimize business regret but lacks transparency, trust starts to erode. Companies using AI need to ensure they aren’t just optimizing for short-term revenue but also protecting customer confidence and brand reputation. ## Conclusion AI is reshaping regret minimisation, but it’s also redefining what regret means. Instead of businesses fearing bad decisions, they now rely on algorithms to optimize away uncertainty. But this raises a new set of challenges: - AI-driven fraud detection can reduce false positives, but it also makes rejection reasons harder to challenge. - Dynamic pricing can optimize margins, but it also increases consumer suspicion about fairness. - Subscription retention models can prevent unnecessary cancellations, but they can also be used to manipulate user behavior. For businesses, the real challenge isn’t just reducing regret—it’s deciding whose regret matters more: their own or their customers’. ## Where Do We Go From Here? As AI continues to take over business decision-making, companies will need to find a balance between optimization and transparency. Consumers are already pushing back against opaque AI-driven decisions in areas like finance, hiring, and content recommendation. If businesses don’t take a proactive approach to ethical AI, regulators will do it for them. The companies that succeed won’t just be those that minimize regret for themselves. They’ll be the ones that ensure their AI-driven decisions don’t create new forms of regret for their customers. ### The Cost of Second-Guessing: How Businesses Manage Their Own Regret URL: https://transactionintelligence.net/regret-minimisation-part-2/ Last updated: 2025-03-05T07:00:48.000Z ## Introduction Just as consumers try to minimize regret in their purchasing decisions, businesses do the same when making strategic choices. But for companies, regret minimization isn’t just about individual transactions—it’s about managing risk, reputation, and revenue over time. Decisions around fraud prevention, pricing, and product development all come with trade-offs. Push too aggressively in one direction, and regret can manifest as lost customers, financial losses, or brand damage. Overcorrect in the other, and a business may leave money on the table or expose itself to fraud and risk. The challenge for businesses is balancing short-term optimization with long-term sustainability. The strategies they employ reveal a lot about how they perceive and manage their own risk of regret. ## How Businesses Minimize Their Own Regret ### Fraud Prevention: Balancing False Positives and False Negatives One of the clearest examples of regret minimization in business is fraud detection. False positives occur when a legitimate transaction is incorrectly flagged as fraud. This leads to lost sales and frustrated customers. False negatives happen when actual fraud slips through, resulting in chargebacks, losses, and reputational damage. Neither extreme is acceptable. Businesses must find a balance—tight enough controls to stop fraud but flexible enough to avoid rejecting good customers. For card issuers and payment processors, this trade-off has real financial implications. A large retailer may tolerate some fraud if it means reducing false positives that drive away customers. A smaller business with tighter margins may take the opposite stance. AI-powered fraud detection has improved accuracy, but businesses still face regret-based decisions about how aggressive they should be. Some merchants even accept a known percentage of fraudulent transactions as a cost of doing business. ### Pricing Strategies: Managing Regret in Discounts and Surge Pricing Pricing decisions are another area where businesses must weigh regret versus opportunity. Discounting too aggressively can devalue a product and train customers to wait for sales. Pricing too high risks alienating price-sensitive buyers and increasing abandoned carts. Retailers carefully study consumer regret patterns to fine-tune pricing strategies. Many e-commerce platforms use dynamic pricing, adjusting rates in real time based on demand and customer behavior. This happens across industries: - Airlines charge different fares based on booking windows, balancing regret minimization for early bookers and last-minute travelers. - Ride-hailing services like Uber and Lyft use surge pricing to maximize revenue, knowing some customers will regret overpaying but others will value immediate availability. - SaaS companies experiment with tiered pricing to prevent regret—offering “middle” options that seem like the best value. Even price matching and refund policies are tools for managing business-side regret. Companies offer them not just to reassure customers, but to protect themselves from backlash and lost sales. ### Product and Feature Development: Cutting Losses vs. Sticking It Out Businesses also face sunk cost regret when deciding whether to kill or continue underperforming products. Tech companies, in particular, struggle with this. Google is infamous for launching and then shutting down products (Google+ and Stadia are prime examples). On the flip side, some businesses keep struggling products alive too long, fearing the regret of missing an eventual turnaround. A key question companies ask is: will we regret pulling the plug too soon, or regret burning more resources on a failing project? ### Corporate Reputation and Regulatory Risk Companies also minimize regret when navigating public perception and compliance issues. - Too much risk aversion—avoiding innovation out of fear of backlash—can lead to stagnation. - Too little caution—pushing aggressive growth strategies without considering long-term consequences—can lead to scandal and regulatory scrutiny. Financial institutions, for example, have to balance their fraud prevention reputation with consumer expectations of seamless transactions. If a bank gets too many fraud complaints, it risks regulatory penalties and customer churn. If it eases restrictions too much, it risks high fraud rates. Many industries now rely on preemptive PR damage control—responding to potential crises before they explode. This isn’t just about ethics; it’s a form of regret minimization at scale. ## When Overcorrecting for Regret Becomes a Problem Just as consumers can overanalyze a purchase and miss out, businesses can overcorrect for regret in ways that harm them. - Overly aggressive fraud prevention can cause legitimate customers to churn, fearing they can’t trust the platform. - Constant pricing experiments can create distrust if customers feel manipulated. - Paralysis in product decisions—waiting too long to launch or kill a feature—can allow competitors to take the lead. Regret minimization is useful until it leads to fear-based decision-making. The companies that thrive are those that know when to optimize and when to take strategic risks. ## Conclusion Consumers aren’t the only ones trying to minimize regret—businesses do it at a far larger scale. Every major decision, from fraud prevention to pricing strategies, involves balancing the risk of short-term regret against long-term outcomes. Companies that over-optimize for immediate regret reduction—whether by rejecting too many transactions, overusing scarcity pricing, or keeping failing projects alive—often create bigger problems down the road. The most successful businesses embrace a certain level of risk. They don’t just ask, "How can we avoid regret today?" They ask, "What trade-offs will serve us best in the long run?" ## Coming Next: No Regrets? How AI Is Changing Business Decision-Making The final post in this series will explore how AI is reshaping the concept of regret in payments and commerce. As automation takes over decision-making, will businesses actually minimize regret—or just shift responsibility elsewhere? --- *This deep-dive is part of the *Transaction Intelligence* series on behavioral psychology in payments. As we explore increasingly specialized topics at the intersection of financial behavior and business strategy, some future installments will be available exclusively to members. Subscribe now to ensure continuous access to these insights and join a community of professionals dedicated to understanding the psychology behind financial systems.* *Members receive:* - *Exclusive access to specialized deep-dive analyses* - *Early access to new content series* - *The complete archive of Transaction Intelligence premium content* ## Sign up for Transaction Intelligence Decoding Financial Behaviour, One Transaction at a Time by Matt Berryman. Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. ### Regret Minimisation: How Payment Platforms Engineer Your Decisions URL: https://transactionintelligence.net/regret-minimisation-part-1/ Last updated: 2025-03-03T07:00:09.000Z That moment of hesitation before hitting "Buy Now." The nagging feeling after a purchase that you could have found a better deal. The grudging acceptance of yet another month of a subscription you barely use. Regret shapes our relationship with money in profound ways. And make no mistake—the architects of our digital shopping experiences know it. E-commerce platforms and payment providers have become masterful at designing experiences that minimize perceived regret. They make choices feel easier, safer, and more rational. But here's the uncomfortable question: Are these regret-minimizing strategies actually serving us, or are they simply overriding our better judgment? ## The Two Faces of Consumer Regret Regret manifests in two critical moments in our purchasing journeys. **Before we buy**, we're haunted by anticipated regret. We obsessively research options, read every review, and endlessly compare features. We look for validation through "Best Seller" badges or expert endorsements. Some of us postpone purchases indefinitely, trapped in research paralysis. Others fall victim to manipulative urgency triggers—those "Only 2 left!" warnings designed to short-circuit our deliberation. **After we buy**, post-purchase regret kicks in. Did I overpay? Should I have waited for the next model? Will there be a sale next week? This is why retailers offer generous return policies and price-matching guarantees. Not just as customer service, but as psychological safety nets that get hesitant buyers to commit. Subscription businesses have elevated this to an art form. They know exactly when most users consider canceling and precisely what interventions will keep them paying. That perfectly-timed email reminding you of "all the exclusives you'll miss" isn't coincidental—it's regret engineering. ## The Architecture of "Regret-Free" Decisions The modern checkout experience is a carefully constructed gauntlet of psychological triggers: **Pre-selected defaults** subtly shift the burden of decision. That pre-checked warranty, that automatically applied donation, that defaulted higher-tier subscription—they all exploit our tendency to assume the platform knows best. They make one path feel safer while requiring active effort to choose another. **Strategic price anchoring** warps our perception of value. When you see that £2,000 premium model first, the £1,200 "mid-tier" option suddenly feels reasonable. This isn't accidental positioning—it's deliberate manipulation of our reference points. **Social validation** exploits our herd instincts. Messages like "42 people are viewing this right now" or "Purchased 4,000 times today" tap into our deeply-wired tendency to find safety in crowds. They make individual deliberation feel unnecessary when "everyone else" has apparently already done the thinking. These tactics work brilliantly. They reduce friction. They boost conversion rates. They make us feel momentarily confident in our choices. But at what cost? ## When Minimizing Regret Creates New Regrets Some regret-minimization strategies genuinely help consumers. They can prevent decision paralysis, simplify overwhelming choice sets, and steer people toward objectively better options. But many only minimize regret at the point of sale, creating deeper regrets later. Take travel booking platforms. They prominently feature non-refundable options as the "best value," reducing purchase hesitation. But when plans inevitably change, customers face a more painful regret than if they'd been nudged toward flexible options. Or consider dynamic pricing algorithms. They create the illusion that you're getting the best possible deal right now. But prices constantly fluctuate, and discovering you paid more than necessary creates a particularly bitter form of regret—one that undermines trust in the platform itself. ## The AI-Powered Future of Regret Engineering As machine learning transforms e-commerce, regret minimization strategies will become increasingly sophisticated: **Real-time personalized pricing** will detect your specific hesitation patterns and dynamically adjust offers. About to abandon your cart? Watch as the price mysteriously drops or free shipping appears—making you feel like you've scored a last-minute win. **Predictive subscription management** will intervene before you even consider canceling. Companies already track when users are likely to quit; soon they'll preemptively modify your offering when algorithms detect early warning signs of dissatisfaction. **Behavioral segmentation** will allow platforms to deploy different regret-minimization strategies based on your psychological profile. Risk-averse shoppers will see more safety guarantees, while deal-hunters will receive more limited-time offers. The question isn't whether these technologies will exist—they're already being implemented. The question is whether they'll be used to help consumers make genuinely better decisions or simply to make them feel better about decisions that primarily benefit the platform. ## Finding the Ethical Balance There's a fine line between helpfully removing friction and manipulatively creating illusions of better choice. Regulators are already paying attention. The recent crackdowns on dark patterns in subscription services and e-commerce are just the beginning. As regret engineering becomes more sophisticated, expect greater scrutiny of techniques that prioritize conversion over consumer welfare. Forward-thinking businesses should consider a more balanced approach. Using choice architecture to genuinely enhance decision quality—not just to create temporary confidence—builds sustainable trust. And trust, unlike a manipulated conversion, has lasting value. ## The Uncomfortable Truth E-commerce platforms aren't just reducing regret—they're actively engineering it. By structuring decision environments in specific ways, they determine what we'll regret and what we won't. Sometimes this serves us well. Often it doesn't. As consumers, our best defense is awareness. Recognizing these tactics doesn't make us immune to them, but it does give us a fighting chance to make decisions based on our actual needs rather than artificially induced emotions. And for businesses? The most sustainable approach isn't maximizing short-term conversions through psychological manipulation. It's helping customers make genuinely satisfying decisions they won't regret later. Because while you can engineer away immediate regret, the delayed kind has a way of coming back—often with reinforcements. --- *Next in this series: "The Cost of Second-Guessing: How Businesses Balance Regret in Pricing, Fraud Prevention, and Risk Management". This deep-dive is part of the *Transaction Intelligence* series on behavioral psychology in payments and will only be available to members. Subscribe now to stay ahead.* ### The Fragility of Transatlantic Data Transfers URL: https://transactionintelligence.net/the-fragility-of-transatlantic-data-transfers/ Last updated: 2025-03-27T10:24:55.000Z The [EU-U.S. Data Privacy Framework](https://www.dataprivacyframework.gov/Program-Overview?ref=transactionintelligence.net) (DPF) operates on a foundation of executive orders rather than legislation, making it susceptible to changes between administrations. Recent developments suggest businesses should prepare for potential adjustments to the legal framework governing transatlantic data flows. ## Background: The Evolution of EU-US Data Transfer Frameworks The current data transfer agreement has evolved through several iterations, each shaped by legal challenges: - In 2015, the **Safe Harbor** framework was invalidated following Max Schrems' complaint ([Schrems I](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62014CJ0362&ref=transactionintelligence.net)) regarding US surveillance practices revealed by Edward Snowden. - In 2020, the **Privacy Shield** was struck down in the [Schrems II](https://www.europarl.europa.eu/RegData/etudes/ATAG/2020/652073/EPRS%5FATA%282020%29652073%5FEN.pdf?ref=transactionintelligence.net) case when the CJEU ruled it didn't provide adequate protection for EU citizens' data. - In 2023, the current **[EU](https://ec.europa.eu/commission/presscorner/detail/en/ip%5F23%5F3721?ref=transactionintelligence.net)\-[US](https://www.dataprivacyframework.gov/Program-Overview?ref=transactionintelligence.net) Data Privacy Framework** was established, underpinned by [Executive Order 14086](https://www.justice.gov/opcl/executive-order-14086?ref=transactionintelligence.net) signed by President Biden in 2022, which implemented new safeguards for US intelligence activities. ## Recent Developments Two recent developments have raised questions about the stability of the current framework: ### 1\. Changes to the Privacy Oversight Board In January 2025, the administration requested [the resignation of three members of the Privacy and Civil Liberties Oversight Board](https://www.reuters.com/world/us/white-house-asks-democratic-members-federal-privacy-oversight-board-quit-2025-01-23/?ref=transactionintelligence.net) (PCLOB). This has temporarily left the board without the quorum necessary to function. The PCLOB plays an important role in overseeing US intelligence practices and was referenced as a safeguard in the EU's adequacy decision for the DPF. ### 2\. Review of Executive Order 14086 Following standard practice during presidential transitions, the administration is conducting [a review of previous National Security Memoranda](https://www.whitehouse.gov/presidential-actions/2025/01/initial-rescissions-of-harmful-executive-orders-and-actions/?ref=transactionintelligence.net), including those underpinning EO 14086\. This review process is expected to determine whether any modifications will be made to the order that forms the legal basis for the EU-US data adequacy decision. ## Potential Implications for Data Transfers If significant changes are made to EO 14086, several consequences could follow: ### Legal Framework Uncertainty The European Commission's adequacy decision for US data transfers is specifically predicated on the protections established in EO 14086\. Material changes to these protections could prompt a reassessment of that adequacy decision. ### Regulatory Response The European Commission has mechanisms to suspend or revoke adequacy decisions if it determines that a third country no longer ensures adequate protection. EU data protection authorities have indicated they are monitoring the situation. ### Impact on UK Data Transfers The UK's [Data Bridge](https://www.gov.uk/government/publications/uk-us-data-bridge-supporting-documents/uk-us-data-bridge-explainer?ref=transactionintelligence.net) agreement with the US is built on the same foundation as the EU-US DPF. Changes to EO 14086 could potentially affect UK-US data transfers as well. ### Business Compliance Challenges If the DPF framework becomes unavailable, organizations would need to implement alternative transfer mechanisms such as Standard Contractual Clauses (SCCs), which involve additional compliance requirements and risk assessments. ## Prudent Preparation Steps for Businesses Given the potential for changes, companies relying on the DPF should consider proactive measures: - **Audit Current Data Transfers** – Identify what data you are transferring from the EU/UK to the US and ensure there are backup legal mechanisms in place. - **Implement Standard Contractual Clauses (SCCs)** – The Schrems II ruling confirmed that SCCs could be relied upon for transfer of personal data to those countries without an adequacy decision. These will likely become the fallback option if the DPF is invalidated. - **Consider EU-Based Data Solutions** – Reducing reliance on US processing may help avoid regulatory scrutiny. - **Stay Updated** – Monitor EU Commission statements, legal challenges, and any new executive actions that may alter the landscape. ## Conclusion While it's premature to predict specific outcomes, history suggests that EU-US data transfer mechanisms can face legal challenges when regulatory frameworks change. Organizations handling transatlantic data flows should prepare contingency plans while monitoring developments in this evolving regulatory landscape. Rather than waiting for potential disruption, forward-thinking businesses will use this period to strengthen their data governance frameworks and ensure they have multiple compliant pathways for essential data transfers. ### From Confusion to Exclusion URL: https://transactionintelligence.net/from-confusion-to-exclusion/ Last updated: 2025-02-25T10:00:16.000Z Financial literacy challenges extend far beyond understanding traditional banking terms. [Financial Conduct Authority research](https://www.fca.org.uk/financial-lives/financial-lives-2022-survey?ref=transactionintelligence.net) indicates that approximately one in four UK adults struggle with financial literacy. This isn't just about understanding terms - it's about navigating increasingly complex financial decisions in a rapidly evolving technological landscape. The rise of Open Banking technologies, while innovative, adds another layer of complexity that many consumers struggle to understand. New 'Pay by Bank' options connect directly to current accounts, while others aggregate financial data across institutions. These services come with variable consumer protections and different settlement timeframes, creating a complex web of choices and consequences. Consider a practical example: booking a flight ticket. A customer choosing between payment methods faces significantly different outcomes depending on their choice. Paying by credit card offers Section 75 protection for purchases over £100, while choosing Pay by Bank via Open Banking means a direct bank transfer with different protection levels. While they might save on credit card fees with Pay by Bank, they could face more complicated refund processes if the airline encounters financial difficulties. The faster payment processing of Open Banking might seem attractive, but it comes with trade-offs in consumer protection that aren't always clearly communicated. ## The Real-World Impact These complexities create tangible consequences in people's lives. When customers don't fully understand their payment options, they often make choices that leave them vulnerable. A customer might choose Pay by Bank for a large purchase, attracted by an instant cashback offer, without realizing they're giving up significant consumer protections. Others might avoid credit cards entirely due to misconceptions about how they affect credit scores, missing out on valuable purchase protection. The impact goes beyond individual transactions - it shapes how people engage with financial services and their confidence in adopting new payment technologies. ## Building a More Inclusive Future The path forward lies in recognizing that clear communication isn't just a nice-to-have - it's fundamental to financial inclusion and security. Leading financial institutions are already showing the way by explaining payment choices in plain language, highlighting key differences in consumer protection, and providing context-sensitive guidance at crucial decision points. But more importantly, they're recognizing that unclear communication creates opportunities for fraudsters who exploit confusion and uncertainty. The successful adoption of innovative payment solutions depends entirely on how well we explain them. When customers don't fully understand what they're doing, they're more vulnerable to scams and fraud. Fraudsters thrive in complexity, using technical jargon and unclear processes to their advantage. By making payment systems more understandable, we're not just improving user experience - we're building crucial defenses against financial crime. The most inclusive financial institutions won't be those with the most sophisticated technology, but those that make that technology understandable to everyone. In an industry that often mistakes complexity for capability, clarity becomes a competitive advantage. The true measure of a financial system isn't just its technical capabilities, but how well it enables everyone to participate fully and confidently in the digital economy. ### When Systems Fail: The Hidden Impact on Financial Inclusion URL: https://transactionintelligence.net/when-systems-fail/ Last updated: 2025-02-21T07:30:26.000Z The [Treasury Committee's investigation into bank IT failures](https://committees.parliament.uk/committee/158/treasury-committee/news/205186/bank-outages-committee-demands-answers-from-banks-and-building-societies-following-barclays-it-failure/?ref=transactionintelligence.net) reveals a critical but often overlooked relationship: the connection between operational resilience and financial inclusion. While we often think of financial inclusion in terms of access to banking services, the reality is that mere access isn't enough - those services must work reliably and consistently for everyone. ## The Asymmetric Impact of System Failures When banking systems fail, they don't fail equally for everyone. Consider two different customers during an outage: The multi-channel customer barely notices. With multiple payment cards across different banks, a healthy credit score, and cash reserves, they simply switch to an alternative payment method. The system failure is an inconvenience, nothing more. But for the financially vulnerable customer, relying on a single debit card and operating with minimal reserves, a system failure can trigger a cascade of consequences. A missed payment leads to late fees, which causes an overdraft, which incurs more fees - a spiral of financial stress from a single point of failure. ## The Digital Paradox Digital banking has revolutionised financial inclusion by reducing barriers to access. But this increased digitisation creates new vulnerabilities. Not everyone has access to modern smartphones or reliable internet connections. When digital becomes the only channel, technical literacy becomes a prerequisite for financial inclusion. The Treasury Committee's focus on compensation reveals how system failures impose both visible and hidden costs. Beyond immediate fees and charges, customers face damaged credit scores, strained business relationships, and lost opportunities. For vulnerable customers, these impacts can persist long after systems are restored. ## Building More Inclusive Resilience The future of financial inclusion depends on building systems that are both accessible and reliable. This means designing for the margins - ensuring systems fail gracefully, maintain critical functions offline, and prioritise vulnerable customers during recovery. Support must be consistently available through multiple channels, with clear escalation paths and proactive outreach to at-risk customers. ## Conclusion: Beyond Access The Treasury Committee's investigation reminds us that financial inclusion isn't achieved simply by providing access to services. True inclusion requires building systems that work reliably for everyone, especially those most vulnerable to disruption. The most inclusive financial system isn't necessarily the most technologically advanced - it's the one that works consistently and reliably for all its users, regardless of their circumstances. This is where operational resilience and financial inclusion meet, and where the real work of building an inclusive financial system begins. ### The Consistency Principle in Digital Products: Why Small Interactions Matter More Than Big Features URL: https://transactionintelligence.net/the-consistency-principle-in-digital-products/ Last updated: 2025-02-17T07:00:11.000Z When Meta launched Threads in July 2023, it was packed with features designed to capture Twitter's market. Within five days, it had 100 million sign-ups—and within two months, it had lost 80% of its active users. Meanwhile, Stripe has spent years quietly refining their payment interface, making subtle improvements to loading states, error messages, and transaction flows. They've grown to process billions in payments annually, with a customer base that stays remarkably loyal. These contrasting approaches to product development mirror a broader truth about human behaviour: we consistently overvalue intensity and undervalue consistency. Just as we're drawn to dramatic fitness transformations over steady exercise habits, in product development, we often prioritise flashy features over reliable core interactions. ## The Seductive Appeal of Feature-First Development The technology industry's bias towards visible, marketable features is understandable. New features drive press coverage, satisfy stakeholder demands, and create the impression of progress. But this approach often misaligns with how users actually interact with products. Consider Microsoft Teams' rapid expansion during the pandemic. In their rush to compete with Slack, they added dozens of features monthly—from custom backgrounds to breakout rooms. The result? A bloated interface where users struggled to find basic functions. Slack, meanwhile, maintained their focus on core messaging functionality, gradually refining their threading system and notification controls. While Teams won the feature count, Slack maintained higher user satisfaction scores. ## The Hidden Power of Micro-Interactions The most successful digital products aren't those with the most features, but those that nail the small, repeated interactions users perform every day. These micro-interactions—loading states, confirmation messages, transition animations—might seem trivial individually, but they compound into the overall user experience. Take Monzo's transaction feed. Each purchase triggers a subtle animation and sound effect, creating a momentary sense of awareness around spending. These small touches aren't just decorative—they create muscle memory and reinforce the connection between action and consequence. Similarly, Stripe's careful attention to loading states and error messages turns potentially frustrating moments into predictable, manageable experiences. The power of these interactions lies in their frequency. A user might encounter a new feature once a month, but they'll experience these core interactions dozens of times daily. Each interaction is an opportunity to either build or erode trust. ## The Compound Effect in Digital Products Just as reading ten pages daily yields better results than occasional reading binges, consistent, well-designed interactions accumulate into strong user habits. This compound effect explains why users often prefer "boring but reliable" over "exciting but unpredictable." Square's point-of-sale interface exemplifies this principle. Their core payment flow has remained remarkably consistent over the years, with improvements focused on reducing friction rather than adding features. This consistency allows merchants to develop muscle memory, reducing cognitive load during busy periods. The result? Higher transaction completion rates and lower support costs. ## Implementing Consistency: A Practical Framework Building consistent products requires a shift in mindset from feature development to interaction refinement. Here's how successful companies approach it: 1. Start with core user flows - Identify the actions users perform most frequently - Map out every step in these flows - Look for opportunities to reduce friction 2. Focus on reducing cognitive load - Maintain consistent patterns across similar actions - Use familiar design patterns where possible - Provide clear feedback for user actions 3. Build for iteration, not revolution - Make small, measurable improvements - Test changes with actual users - Monitor impact on core metrics 4. Maintain predictable patterns - Use consistent language across the interface - Keep navigation stable - Avoid surprising users with unexpected behaviour ## The Business Case for Consistency While feature development often drives short-term growth, consistency builds long-term sustainability. Companies that master core interactions typically see: - Lower support costs (users encounter fewer issues) - Higher retention rates (familiar interfaces reduce churn) - Improved feature adoption (users trust new additions) - Better user satisfaction scores Shopify's growth illustrates this principle. While competitors rushed to add features like crypto payments and AR shopping, Shopify focused on perfecting their merchant dashboard and checkout flow. This consistency helped them build and maintain a loyal merchant base—particularly impressive in an industry known for high churn. ## Common Pitfalls and How to Avoid Them Even companies committed to consistency can stumble. Common mistakes include: - Feature creep: Adding options without removing outdated ones - Inconsistent patterns: Using different interactions for similar actions - Over-optimization: Changing things that already work well - Breaking user expectations: Altering familiar behaviours without clear benefits ## Looking Forward: Consistency in an AI World As AI transforms product development, the principle of consistency becomes even more crucial. The most successful products will be those that use AI to enhance rather than disrupt core interactions. Imagine AI suggesting improvements to existing flows rather than creating new ones, or learning from user behaviour to refine micro-interactions automatically. ## The Path Forward Success in digital product design, like in personal habits, comes from consistency over intensity. It's not about having the most features or the flashiest interface—it's about getting the small, repeated interactions right. As we enter an era of AI-enhanced products, this principle becomes even more important. The next time you're tempted to add a new feature, consider instead how you might improve the interactions users already perform daily. After all, the most powerful changes often come not from what we add, but from how well we execute what's already there. ### The Engagement Problem: Designing Automation That Keeps Humans in the Loop URL: https://transactionintelligence.net/the-engagement-problem-designing-automation-that-keeps-humans-in-the-loop/ Last updated: 2025-02-14T10:08:19.000Z In my previous post, *[The Automation Paradox](https://transactionintelligence.net/the-automation-paradox-how-smart-banking-features-may-be-making/)*, I explored how frictionless financial automation, while designed to make life easier, can sometimes leave users disengaged and unaware of their own money habits. This unintended consequence raises a larger question: How do we ensure that automation enhances, rather than replaces, human judgement? If *The Automation Paradox* highlighted the risk of passive financial behaviour, this article explores the next step—how we can design automation that keeps people actively engaged. Every day, millions of people follow turn-by-turn directions from Google Maps. But what makes these apps so effective isn't just their ability to automate navigation—it’s their ability to keep us engaged. They provide real-time traffic updates, suggest alternative routes, and leave the final decision to the driver. In doing so, they embody a crucial principle of automation design: keeping humans meaningfully involved. This principle is often missing in personal finance and other digital experiences. As financial automation becomes more sophisticated—tracking subscriptions, categorising spending, even optimising savings—we risk creating a generation of passive users. Instead of making better financial decisions, people may simply outsource their thinking, losing touch with their own money habits. The challenge isn’t just about automation. It’s about engagement. And the best systems won’t just automate tasks—they’ll make people better at them. ## The Automation Paradox: Convenience vs. Comprehension Automation in banking is supposed to make life easier. Features like Monzo’s smart categorisation, Starling’s subscription tracking, and AI-driven savings nudges all promise to help users manage their money effortlessly. And they do—but there’s a catch. When automation shields users from friction entirely, they stop engaging with their finances. They don’t notice gradual spending shifts, lose track of commitments, and struggle to make informed financial decisions when automation can’t cover for them. The result? A paradox: the very tools designed to help us may be making us worse at managing money. This isn’t just a finance problem. Across industries, full automation often leads to skill degradation and passive consumption. The solution isn’t to remove automation—but to design it so that it keeps people actively engaged. ## Designing Automation for Engagement ### From Raw Data to Smart Insights Fitness apps like Strava don’t just track steps—they analyse patterns, highlight trends, and suggest recovery times. They turn raw data into meaningful insights while keeping users in control. Financial apps could do the same. Instead of simply listing spending categories, they could highlight behavioural patterns. For example: - Grocery spending tends to be 20% higher on Wednesdays than Mondays. - A user has multiple streaming subscriptions, some of which may be unused. By surfacing actionable insights instead of just data, automation can help users stay engaged without overwhelming them. ### Strategic Friction: The Right Kind of Speed Bump Not all friction is bad. In software development, AI-powered code assistants suggest changes, but developers must review them before implementation. This maintains engagement while reducing tedious manual work. Financial automation should do the same. Instead of defaulting to auto-renewing every subscription or transferring savings without oversight, systems should introduce friction at decision-critical moments. For example: - Notifying a user before an energy provider increases rates. - Prompting a user before they take on a third Buy Now, Pay Later purchase in a month. The goal isn’t to slow users down arbitrarily but to ensure they remain involved in key financial decisions. ### Transparent Automation: Show Your Work One reason GitHub Copilot works well for developers is that it doesn’t just suggest code—it explains why it made a suggestion. This builds trust and maintains skill development. Finance apps should adopt the same principle. Instead of simply shifting money into savings or adjusting spending limits behind the scenes, they should provide explanations. For example: - "We moved £50 into savings because dining-out expenses were lower this month." - "This transaction was categorised as ‘shopping’ based on past behaviour. Is this correct?" Transparency keeps users informed and prevents the "black box" problem, where automation works for users but not with them. ### Agency-Preserving Defaults: Automation with a Human Touch Calendar apps that suggest meeting times but require confirmation show how automation can assist without overriding human judgement. Finance apps should follow suit: - Instead of automatically cancelling unused subscriptions, they should prompt the user first. - Instead of sweeping money into investments, they should provide clear scenarios on how different choices impact financial goals. By maintaining user agency, automation can empower rather than replace decision-making. ## The Future of Automation: Augment, Don’t Replace As AI and automation evolve, the key challenge will be keeping humans in the loop. The risk isn’t just skill erosion—it’s a growing disconnection from decision-making itself. The best-designed systems will: - Surface meaningful insights, not just raw data. - Introduce friction where it matters, not where it doesn’t. - Make automation transparent, explaining its decisions. - Preserve human agency by offering choices, not just defaults. Good automation doesn’t just make life easier. It makes people better at what they do. Just like Google Maps makes you a more informed driver, the next generation of financial tools should make you a better financial decision-maker—not just a passive observer. In the end, the goal of automation isn’t to remove human judgement. It’s to make it sharper, faster, and more informed. ### The Automation Paradox How Smart Banking Features May Be Making Us Worse with Money URL: https://transactionintelligence.net/the-automation-paradox-how-smart-banking-features-may-be-making/ Last updated: 2025-02-14T10:07:30.000Z The introduction of organ donation opt-out in Wales increased consent rates from 58% to 89%. Auto-enrollment in workplace pensions pushed UK participation from 55% to 87% in just six years. The message seems clear: make the right choice the default choice, and people will make better decisions. This powerful insight drives innovation in personal finance. The latest UK banking apps offer an impressive array of automated features. NatWest's subscription tracking reaches 2.3 million monthly users, helping them find an average of £40 in forgotten payments. Starling Bank reports subscription analytics driving a 22% year-over-year increase in recurring payment awareness. Monzo's smart categorization automatically identifies 94% of subscriptions, making users 2.8 times more likely to review their recurring payments. But there's a paradox at the heart of this convenience. The same automation that protects us from financial oversights might be making us less engaged with our money. When banking apps handle everything automatically, we lose the small moments of friction that prompt financial reflection. While these features excel at catching forgotten subscriptions and preventing unwanted renewals, they risk creating a "set and forget" mindset that distances us from active financial decision-making. The growth in subscription-based services has made personal finance more complex. While automation helps catch unwanted renewals, the core challenge remains: maintaining active awareness of our financial commitments in an increasingly frictionless world. The problem isn't just awareness – it's engagement. This tension between convenience and consciousness defines the next challenge in financial technology. The goal isn't just to automate our money management but to build tools that enhance our financial decision-making capabilities. The most effective features will be those that combine automation with engagement, using defaults to protect us while still encouraging active participation in our financial lives. For banks and fintech companies, this means rethinking how we measure success. Instead of tracking just usage metrics or cancellation rates, we should examine how these tools impact long-term financial behavior and awareness. Do users make better decisions over time? Do they understand their spending patterns more deeply? Are they more likely to engage in proactive financial planning? The future of financial technology lies not in removing human decision-making but in augmenting it. Smart defaults should serve as guardrails, not autopilot. As these tools evolve, the challenge will be finding the sweet spot between protection and engagement – where automation supports rather than supplants financial awareness. ### The Psychology of Modern Payment Choices From Cards to BNPL URL: https://transactionintelligence.net/the-psychology-of-modern-payment-choices-from-cards-to-bnpl/ Last updated: 2025-02-07T08:00:12.000Z --- When consumers pay with credit cards instead of cash, they consistently spend more – between 12-18% more, according to MIT research\[1\]. This 'credit card premium' isn't just an interesting statistical quirk; it's a window into how payment methods shape our spending behaviour. As we've moved from physical cash to digital payments, this psychological effect has only intensified, reaching new heights with Buy Now, Pay Later (BNPL) services. ## The Science of Spending The reason for increased spending with cards lies in what behavioural economists call 'payment coupling' – the mental link between purchase and payment. Cash creates immediate pain of paying, while cards create psychological distance between buying and spending. This distance reduces the emotional impact of spending, leading to larger purchase amounts and more frequent transactions. Digital payments have amplified this effect. When paying becomes as simple as tapping a phone or clicking a button, the psychological friction that might otherwise make us pause and reconsider a purchase diminishes significantly. The seamless nature of digital transactions further weakens the mental link between spending and payment, making it easier to spend more without feeling the immediate impact. ## BNPL: Psychology in Overdrive Buy Now, Pay Later services take this psychological distance to another level. By breaking payments into smaller chunks, BNPL makes purchases feel more manageable – even when the total cost remains the same. This psychological framing proves particularly powerful in influencing purchasing decisions, especially for larger items that might feel out of reach as a single payment. The mechanism at work here is known as 'present bias' – our tendency to prioritise immediate benefits over future costs. BNPL services leverage this by offering instant gratification while pushing the financial impact into the future. The psychological appeal is clear: you get the dopamine hit of a purchase now, while the pain of payment is both delayed and divided. ## The Dark Side of Frictionless Finance However, this reduction in payment friction comes with consequences. Recent research by the Financial Conduct Authority found that a quarter of BNPL users reported difficulty making payments, with younger users particularly affected\[2\]. The same psychological distance that makes spending easier can lead to disconnection from the reality of accumulating obligations. The problem is compounded by what behavioural scientists call 'payment stream blindness' – difficulty tracking multiple payment obligations across different services. When payments are spread across various providers and dates, consumers often struggle to maintain a clear picture of their total commitments. ## Choice Architecture: The Hidden Influence The way payment options are presented significantly influences consumer decisions. The positioning of BNPL alongside traditional payment methods, the visibility of total costs, and even the order of payment options can all shape purchasing behaviour. This highlights the crucial role of choice architecture – the way options are presented to consumers can either help them make informed decisions or nudge them toward potentially problematic spending patterns. ## Financial Literacy: The Critical Buffer Financial literacy emerges as a crucial moderating factor in BNPL usage. The FCA's research shows that consumers with stronger financial literacy are better equipped to assess the total cost of their commitments and make more informed decisions about using BNPL services\[3\]. This suggests that education, rather than restriction, might be key to responsible BNPL use. ## Looking Forward As BNPL continues to evolve, the challenge lies in balancing convenience with responsibility. Some providers are now experimenting with 'mindful spending' features, such as clear visualisation of total commitments and proactive warnings about potential overextension. These innovations suggest a growing recognition of the need to balance commercial interests with consumer protection. The psychology of modern payments reveals both opportunities and risks. While BNPL can make purchases more accessible, it also amplifies the psychological distance that already makes digital spending feel less 'real'. Understanding these mechanisms is crucial for consumers, merchants, and providers alike. --- 1. MIT Sloan Research Paper: 'Always Leave Home Without It: A Further Investigation of the Credit Card Effect on Willingness to Pay' - [https://web.mit.edu/simester/Public/Papers/Alwaysleavehome.pdf](https://web.mit.edu/simester/Public/Papers/Alwaysleavehome.pdf?ref=transactionintelligence.net) ↩︎ 2. Financial Conduct Authority: 'The Buy Now Pay Later Market Report' - [https://www.fca.org.uk/publication/research/buy-now-pay-later-market-research-2023.pdf](https://www.fca.org.uk/publication/research/buy-now-pay-later-market-research-2023.pdf?ref=transactionintelligence.net) ↩︎ 3. Financial Conduct Authority: 'Financial Lives 2022 survey' - [https://www.fca.org.uk/publications/research/financial-lives-2022-survey](https://www.fca.org.uk/publications/research/financial-lives-2022-survey?ref=transactionintelligence.net) ↩︎ ### Seeing Around Corners Developing Second-Order Thinking URL: https://transactionintelligence.net/seeing-around-corners-developing-second-order-thinking/ Last updated: 2025-02-03T08:00:28.000Z When Amazon introduced one-click purchasing in 1999, it seemed like an obvious win. Reduced friction at checkout meant higher conversion rates, and the initial data proved this conclusively. However, the ripple effects of this innovation continue to reshape retail in unexpected ways, offering a masterclass in the importance of second and third-order thinking. First-order thinking is easy: reduce checkout friction, increase sales. But what happens next? This is where second-order thinking begins. Easier purchasing led to more impulse buying and higher return rates. The third-order effects went even further: a surge in 'bracketing' (buying multiple sizes with the intention of returning most items) and sophisticated return fraud schemes, where items are worn once and returned under the guise of wrong sizing or quality issues. This pattern - where solutions create new, often unexpected problems - repeats across the tech industry. Payment innovations designed to reduce fraud often end up creating new attack vectors. Features built to increase engagement frequently lead to notification fatigue and eventual platform abandonment. The challenge isn't in seeing the immediate impact; it's in spotting the downstream consequences. Most of us are naturally poor at second-order thinking. Our brains evolved to handle immediate cause-and-effect relationships: see tiger, run away. The complexity of modern systems demands more sophisticated analysis, but our instincts haven't caught up. We default to what psychologists call the "focusing illusion" - overemphasizing easily observable, immediate consequences while underestimating indirect effects. However, second-order thinking can be developed. Start by questioning your immediate assumptions about cause and effect. When evaluating a potential change, don't stop at "What happens next?" Push further with questions like: 1. How will people's behaviour adapt to this change? 2. What new incentives does this create? 3. How might this be misused? 4. What happens if this succeeds at scale? Consider the evolution of free returns policies. The first-order effect was clear: reduced purchase anxiety and higher conversion rates. The second-order effect was increased return rates, which seemed manageable. But the third-order effects were more subtle and far-reaching: changes in consumer psychology around commitment to purchases, the emergence of "wardrobing" fraud, and the creation of an entire shadow economy around returns. This isn't just about predicting problems - it's about understanding system dynamics. When ecommerce platforms made dropshipping accessible to everyone, they weren't just lowering barriers to entry for entrepreneurs (first order). They were fundamentally changing the relationship between retailers and inventory risk (second order), which ultimately led to changes in consumer trust and platform reputation management challenges (third order). The key to developing better second-order thinking isn't trying to predict every possible outcome. Instead, it's about developing a more nuanced understanding of system dynamics. Start by looking for feedback loops. When you make a change, how will it affect the incentives of different players in the system? What new behaviors might those incentives encourage? This approach reveals why some "obvious" solutions fail. Take the common suggestion of charging restocking fees to combat return fraud. The first-order effect seems positive: deterred fraud. But second-order thinking reveals potential issues: reduced customer confidence at purchase, driving away legitimate customers. The third-order effect might be customers migrating to competitors with more lenient policies, ultimately reducing overall revenue. The most powerful second-order thinking often comes from historical parallels. Every innovation in commerce, from mail-order catalogues to credit cards, has gone through similar cycles of innovation, exploitation, and adaptation. Study these patterns, and you'll start to see rhymes in current developments. The goal isn't to become paralyzed by analysis. Rather, it's to develop a more sophisticated understanding of cause and effect in complex systems. Sometimes, the best solution is still to move forward despite potential downstream effects - but with eyes open and contingency plans in place. Remember: in a world where first-order thinking is increasingly automated, the ability to see around corners becomes a crucial competitive advantage. The next time you're evaluating a solution, push past the obvious and ask: "And then what happens?" Your future self will thank you. ### Consistency Over Intensity: The Hidden Power of Small Actions URL: https://transactionintelligence.net/consistency-over-intensity-the-hidden-power-of-small-actions/ Last updated: 2025-02-26T09:29:51.000Z As January draws to a close, the packed gym classes of New Year's resolution season are starting to thin out. Research from fitness tracking apps shows that by the end of January, nearly 80% of people have already abandoned their exercise goals. It's a familiar pattern, and it highlights a fundamental misunderstanding about how lasting change actually happens. When we decide to make a change, our instinct is often to go all in. We sign up for the premium gym membership, buy the latest workout gear, and commit to an intense daily routine. There's something seductive about this approach – it feels decisive, committed, transformative. But this focus on intensity often overshadows a far more powerful force: consistency. The allure of intensity is everywhere. Social media celebrates dramatic transformations: the six-week body transformations, the coding bootcamp graduates who land six-figure jobs, the startups that go from zero to unicorn status overnight. These stories capture our imagination because they're dramatic. They feed into our desire for quick, visible results. But they're outliers, not the norm, and they often mask the countless small, consistent actions that actually drove the change. Consider this: research published in the European Journal of Social Psychology by Lally et al. (2009) [\[1\]](#fn1) found that it takes an average of 66 days for a new behaviour to become automatic – far longer than the popular myth of 21 days. Their study revealed something even more interesting: missing a single day didn't significantly impact the habit-forming process. What mattered was the overall pattern of consistency, not perfect adherence or intensity. This insight challenges our conventional approach to change. We typically overestimate what we can accomplish in a day and underestimate what we can achieve in a year. A person who reads ten pages every day will finish more books than someone who occasionally binges 300 pages. The daily reader not only maintains a more sustainable pace but also better retains and integrates the information. The power of consistency extends beyond habit formation. In learning and skill development, spaced repetition consistently outperforms cramming. Studies on spaced repetition and distributed practice have consistently shown improved retention rates compared to massed practice or cramming. The same principle applies to physical training, where moderate, regular exercise often yields better long-term results than sporadic intense workouts. The compound effect of small, consistent actions is remarkable but often invisible in the short term. This invisibility is both its power and its challenge. When we make a 1% improvement each day, the change is imperceptible. But over a year, that compounds to a 37x improvement. This math is straightforward but counterintuitive to our preference for immediate results. What makes consistency so powerful is precisely what makes it challenging: it's boring. There's no excitement in doing something small every day. No one celebrates the person who's been flossing consistently for a year, or the developer who commits code daily, or the writer who hasn't missed their morning pages in six months. But these small, consistent actions create the foundation for lasting change. This isn't to say that intensity has no place in personal development. Rather, it's about recognising that consistency – showing up regularly, doing the small things right, maintaining a sustainable pace – is often the differentiating factor between temporary change and lasting transformation. As we watch another wave of New Year's resolutions fade away, perhaps it's time to shift our focus from the intensity of our commitments to their consistency. Instead of asking "How can I transform my life as quickly as possible?" we might ask "What small action can I maintain indefinitely?" After all, the question isn't whether you can sprint for a day, but whether you can keep walking in the right direction, day after day, even when the initial excitement fades. In the end, consistency beats intensity not because it's more effective in any given moment, but because it's more likely to last – and lasting is what ultimately matters. --- 1. Lally, P., van Jaarsveld, C.H.M., Potts, H.W.W. and Wardle, J. (2010), How are habits formed: Modelling habit formation in the real world†. Eur. J. Soc. Psychol., 40: 998-1009\. [https://doi.org/10.1002/ejsp.674](https://doi.org/10.1002/ejsp.674?ref=transactionintelligence.net) [↩︎](#fnref1) ### Deepseek & AI Investments URL: https://transactionintelligence.net/deepseek-ai-investments/ Last updated: 2025-01-27T13:49:58.000Z Last Monday, DeepSeek, a Chinese AI research laboratory spun out of a quant trading firm, released a preview of its latest language model, DeepSeek-R1\. The model demonstrates reasoning capabilities comparable to leading commercial models, but with a crucial distinction: it's open source. While you can chat with it online at [chat.deepseek.com](https://chat.deepseek.com/?ref=transactionintelligence.net), it's available to download and run locally. The model's development is particularly noteworthy given recent U.S. export restrictions on high-performance GPUs to China. According to [The Economist](https://www.economist.com/briefing/2025/01/23/chinas-ai-industry-has-almost-caught-up-with-americas?ref=transactionintelligence.net), DeepSeek achieved its capabilities while using approximately one-tenth of the computational resources required for Meta's Llama 3.1, demonstrating remarkable efficiency in model training. At the time of writing, tech stocks fuelled by the AI boom have retreated around 11% over concerns about whether the current forecast for high-performance compute & networking equipment will be sustained. ## Running DeepSeek on a Mac This was a lot easier than I expected, even on a borderline antique iMac from 2017. 1. Download [Ollama](https://ollama.com/?ref=transactionintelligence.net) then execute `ollama run deepseek-r1` in a terminal. After a 4GB download, the model will be ready to chat with in a Terminal. 2. For a more polished experience on the Desktop; download the free [Chatbox AI](https://chatboxai.app/en?ref=transactionintelligence.net), select Ollama as the Model Provider and then DeepSeek-r1 as the running model. ![](https://storage.ghost.io/c/7a/85/7a852110-bd54-4df3-97de-ac191363fc73/content/images/2025/01/Configuring-Deepseek-in-Chatbox-AI.png) Screenshot of how to configure the deepseek-r1 model in Chatbox AI's settings using Ollama the Model Provider. ### Performance Once configured, you're now ready to kick the tyres. I've adapted the [common Strawberry test](https://community.openai.com/t/incorrect-count-of-r-characters-in-the-word-strawberry/829618?ref=transactionintelligence.net) to ask *"How many Rs in Berryman?"* and, after a bit of thinking, it announced *"The letter 'R' appears \*\*twice\*\* in the name "Berryman."* 👏 As this is a reasoning model, it also shows the thought process behind the response. I've included the lengthy, but logical, assessment of how it responded to this tricky question. ```Alright, Alright, so I need to figure out how many times the letter 'R' appears in the name "Berryman." Okay, let's break this down step by step. First, I should probably write out the name and look at each letter one by one. The name is "Berryman," right? So let me spell it out: B, E, R, R, Y, M, A, N. Now, I need to count how many times the letter 'R' appears in this sequence. Let's go through each position: 1. **B** - Not an 'R'. 2. **E** - Not an 'R'. 3. **R** - That's one 'R'. 4. **R** - That's two 'R's. 5. **Y** - Not an 'R'. 6. **M** - Not an 'R'. 7. **A** - Not an 'R'. 8. **N** - Not an 'R'. So, after going through each letter in "Berryman," it looks like the letter 'R' appears twice. Wait a minute—did I miss any? Let me double-check to make sure I didn't overlook anything: - B: No - E: No - R: Yes (1) - R: Yes (2) - Y: No - M: No - A: No - N: No Nope, it does seem like 'R' only appears twice in "Berryman." I think that's the correct answer. ``` ## Conclusion From a few days' experimentation, this model doesn't appear as capable for my use cases as Claude 3.5 Sonnet (which is currently my provider of choice) but, given the creativity required to generate something this capable, in such a constrained environment, the team behind DeepSeek are to be applauded. ### AI: State of Play 2024 URL: https://transactionintelligence.net/ai-state-of-play-2024/ Last updated: 2025-01-08T13:40:25.000Z The explosive growth of Generative AI in 2024 has transformed it from a specialised tool into a mainstream force. While ChatGPT may have captured public attention, the landscape has evolved far beyond simple text generation. This piece explores my journey from basic AI usage to understanding its broader implications for technology professionals. ## Breadth of Field While OpenAI's ChatGPT may have the greatest name recognition, I was surprised by the breadth of organisations investing heavily in this area. According to [Simon Willison's comprehensive "Things we learned about LLMs in 2024"](https://simonwillison.net/2024/Dec/31/llms-in-2024/?ref=transactionintelligence.net), while OpenAI's GPT-4 entered 2024 as the stand-out leader in standard industry benchmarks, that dominance proved short-lived. By year's end, 18 models from 11 different organisations had surpassed GPT-4's performance metrics. As the field expands and models become more capable, the art of effectively communicating with these systems becomes increasingly crucial. My experience reflects a common evolution in approach. This evolution in communication strategy is particularly important given that model performance isn't just about raw capabilities - it's about how effectively we can harness them. The quality of outputs directly correlates with the sophistication of our inputs, leading to a fundamental principle: "Garbage In, Garbage Out." ## Garbage In, Garbage Out To get the most out of any model, prompts need to be as detailed as possible. Previously, I had erred on the side of caution and kept them brief to avoid misunderstandings. However, take a look at this example of a ‘Good’ prompt from Anthropic’s Claude prompting guide. > You are a fabric supplier for my backpack manufacturing company. I'm preparing for a negotiation with this supplier to reduce prices by 10%. As the supplier, please provide: 1. *Three potential objections to our request for a price reduction* 2. *For each objection, suggest a counterargument from my perspective* 3. *Two alternative proposals the supplier might offer instead of a straight price cut* > Then, switch roles and provide advice on how I, as the buyer, can best approach this negotiation to achieve our goal. Anthropic's [Prompt Engineering](https://docs.anthropic.com/en/docs/build-with-claude/prompt-engineering/overview?ref=transactionintelligence.net) documentation is a great place to start asking better questions of the these models. While mastering prompt engineering is crucial for text-based interactions, the landscape of AI capabilities has expanded far beyond pure text which requires us to think about prompts in increasingly sophisticated ways. ## Moving beyond text 2024 marked the tipping point for multi-modal AI (systems capable of processing multiple types of input like text, images, and sound) as these systems evolved from interesting experiments into practical tools that could seamlessly work with different types of content simultaneously. This came to the masses with the introduction of Visual Intelligence as part of Apple Intelligence; users can take a photo of an object, ask questions about it verbally, and receive information drawing from both visual and contextual understanding. This is a big step in broadening the adoption of AI. ## Awareness [Ben Evan’s “AI eats the world”](https://www.ben-evans.com/presentations?ref=transactionintelligence.net) neatly summarises how there’s fairly widespread awareness of these tools but a much smaller proportion of people have *actually* experimented with the tool and no country has more than 10% of people where this has become a core tool used each day. As these features become tighter integrated into the platforms where people spend their time, be it [Gemini for Google Workspace](https://workspace.google.com/solutions/ai/?ref=transactionintelligence.net), [Co-pilot for Microsoft Office](https://blogs.microsoft.com/blog/2023/03/16/introducing-microsoft-365-copilot-your-copilot-for-work/?ref=transactionintelligence.net), [GitHub Copilot](https://marketplace.visualstudio.com/items?itemName=GitHub.copilot&ref=transactionintelligence.net) or the [iOS Camera](https://support.apple.com/en-gb/guide/iphone/iph12eb1545e/ios?ref=transactionintelligence.net) app, this proportion will only increase and it will be fascinating to see what emerges as the ‘must have’ use cases. As we observe these patterns of innovation, adoption, and integration, several key themes emerge that help us understand both the current state and future trajectory of AI technology. # Conclusion The landscape of Generative AI in 2024 reveals a fascinating paradox: unprecedented investment coupled with uncertain practical applications. The comprehensive displacement of GPT-4 from its leadership position demonstrates both the intensity of competition and the accelerating pace of innovation. This proliferation of capable models, combined with declining training costs and the democratisation of access through integrated platforms, creates fertile ground for experimentation and discovery. Looking ahead to 2025, the combination of improved multi-modal capabilities and broader platform integration creates conditions for rapid innovation. While the "killer app" remains elusive, the sheer scale of investment and increasing accessibility suggests that breakthrough applications will likely emerge through practical experimentation rather than theoretical planning. ### Making Good Decisions URL: https://transactionintelligence.net/making-good-decisions/ Last updated: 2025-02-26T09:55:30.000Z Our life is defined by the outcomes of the decisions that we make. To achieve our personal and professional goals, we need to make the best possible decisions. Amazon’s [Leadership Principles](https://www.amazon.jobs/en-gb/principles?ref=transactionintelligence.net) have succinctly defined the trait that they look for as seeking those people that ‘Are Right, A Lot’. > Leaders are right a lot. They have strong judgement and good instincts. They seek diverse perspectives and work to disconfirm their beliefs. > — Amazon's Leadership Principles Making good decisions allows you to focus your efforts in those areas that will move you closest to your goals. In [Managing for Business Effectiveness](https://hbr.org/1963/05/managing-for-business-effectiveness?ref=transactionintelligence.net) (HBR, May 1963), Drucker discusses the problems with “Misplaced emphasis” and highlights the importance of managers focussing their resources (whether financial, industry or talent) on the wrong problems. > “There is surely nothing quite so useless as doing with great efficiency what should not be done at all. > — Peter Drucker So, how can we set ourselves up for success? ## Understanding the Decision To be right, a lot, you need to fully understand the decision ahead of you, the operating environment and the consequences of the different options open to you. ### Defining the Operating Environment Unless you possess a thorough understanding of the environment and the likely consequences of the potential decisions, you are not setting yourself up for success. To build this understanding, many turn to the [Feynman Technique](https://fs.blog/feynman-technique/?ref=transactionintelligence.net) which, briefly, involves describing the topic as simply as possible as if you were speaking to a small child. Having to use plain language prevents you from hiding behind domain-specific technical jargon and builds knowledge from first-principles. ### Communicating the Decision Once you possess a good understanding of the domain in which you need to make the decision, you need to clearly and simply articulate what should be done and why to the people that will be impacted by your choice. Military leadership have faced with this problem for hundreds of years and most modern organisations have adopted variants of the [five-paragraph field order](https://en.wikipedia.org/wiki/Five%5Fparagraph%5Forder?ref=transactionintelligence.net). Traditionally, these have a single paragraph dedicated to each of the following topics; 1. Situation 2. Mission 3. Execution 4. Admin / Logistics 5. Command/Signal An adaption of this framework for the corporate world involves tweaking the structure to include the sections listed below. #### Background Clearly describe the current operating environment. If you don’t fully understand this yourself, then that should be a warning sign. To develop your understanding, use the Feynman Technique and then use this plain description to set the context for your colleagues. #### Goal Clearly define what you are trying to accomplish and why that has been chosen as the goal. #### Plan Once the goal has been defined, and the operating environment is well-understood, you are well-positioned to prepare a robust plan to achieve the goal. #### Logistics This section details who will be responsible for each step of the plan and, if required, what the governance structure will be used while delivering the plan. #### Communications Now that a solid plan has been defined and people are working to deliver it, you need to ensure that all those impacted by the work will be informed in good time. This section defines the various groups of stakeholders and who is responsible for informing each. ## Conclusion While this process will be overkill for many of the decisions that you make throughout the day, I have found it to be a very useful tool when contemplating how to respond to larger challenges. Specifically, the order of the sections has prevented me from defining a Plan without having a fully complete understanding of the Situation. Then, after having invested the time to develop a profound understanding of the Situation, being able to describe that in plain terms helps share that understanding with your teams to help them make more informed decisions later in the process. Have you found this approach useful? I’d be interested to learn what works well for you; please join the discussion on Twitter. ### Boring is Good URL: https://transactionintelligence.net/boring-is-good/ Last updated: 2025-02-26T09:55:45.000Z There is a lot to be said for being boring. During these unusual times, when so much has changed, dependable partners have never been more important. A strong partner allows you to delegate some of your responsibilities to allow you to focus elsewhere. This is just as true for business partnerships as it is in our personal lives. A resilient business will rely upon a number of strong partners who each excel in their own field. While many businesses are focussed upon survival, a good partner doesn't want to attract any unnecessary attention. A good partner delivers upon their commitments. A strong partner seamlessly fades into the background unless called upon for support. For those of us in service delivery industries, being boring is a compliment. ### Behavioural Biometrics URL: https://transactionintelligence.net/behavioural-biometrics/ Last updated: 2025-02-26T09:40:11.000Z Many European Issuers are unclear on how to deliver a compelling customer experience given the recent clarifications to the EBA's guidance about what types of authentication would be considered compliant for the PSD-2's requirements for Strong Consumer Authentication. ## The Regulatory Framework ### EBA June 2019 Opinion The [EBA's June 2019 Opinion Paper](https://eba.europa.eu/documents/10180/2622242/EBA+Opinion+on+SCA+elements+under+PSD2+.pdf?ref=transactionintelligence.net) has caused much consternation for eCommerce merchants and card issuers alike. While it provides some useful clarity on what can, and more importantly, cannot be considered Possessive, Inherence and Knowledge elements. Paragraph 19 is a useful and comprehensive list of the 'biological' elements that are allowed be used as an inherence element. > 19\. Inherence may include retina and iris scanning, fingerprint scanning, vein recognition, face and hand geometry (identifying the shape of the user’s face/hand), voice recognition, keystroke dynamics (identifying a user by the way they type and swipe, sometimes referred to as typing and swiping patterns), the angle at which the PSU \[payment service user, i.e. the consumer\] holds the device and the PSU’s heart rate (uniquely identifying the PSU), provided that the implemented approaches provide a ‘very low probability of an unauthorised party being authenticated as the payer’, in accordance with Article 8 of the RTS on SCA and CSC. Unfortunately, paragraph 21 then outlaws the use of data from a 3-D Secure transaction as the basis of a biometric inherence factor. > 21\. In addition, communication protocols such as EMV® 3-D Secure version 2.0 and newer would not currently appear to constitute inherence elements, as none of the data points, or their combination, exchanged through this communication tool appears to include information that relates to biological and behavioural biometrics (as mentioned in paragraph 18 above). That being said, if future data points exchanged via such protocols enabled the PSP to identify ‘something the PSU is’, in line with the examples provided in paragraph 19 above, such protocols might possibly be considered inherence elements in the future. ### The UK FCA's Advice to CEOs Furthermore, on 20 August the FCA issued [a Letter to CEOs](https://www.fca.org.uk/publication/correspondence/dear-ceo-letter-strong-customer-authentication.pdf?ref=transactionintelligence.net) advising them of the 18 month implementation period while also re-iterating that banks had to implement a mode of SCA that did not disadvantage the vulnerable consumers. > **Managing the impact on vulnerable or digitally excluded consumers** > We also expect firms to manage the potential negative impact of SCA on different groups of customers, particularly the vulnerable, less digitally engaged or located in areas with limited digital access. We have been clear that firms may need to provide options for the methods of authentication. This includes taking into account that not all consumers will possess a mobile phone. So, we expect firms to provide a viable means of authenticating these customers. ### The EBA's Reduction of the Implementation Period On 16 October, the [EBA published Opinion on the deadline for the migration to SCA](https://eba.europa.eu/sites/default/documents/files/Opinion%20on%20the%20deadline%20for%20the%20migration%20to%20SCA.pdf?ref=transactionintelligence.net) which basically said that the ecosystem has had long enough to prepare for the application of SCA and an 18m phased implementation period - as had been proposed by the FCA and other national regulators - was too lax and the implementation period should conclude on 31 Dec 2020\. In practical terms, given how ecommerce volumes spike in the run-up to the festival season, it would be a bold move for a merchant or an issuer to make a change of this magnitude during November & December; therefore, all merchants, acquirers and issuers should plan to be fully-compliant with the SCA requirements by the end of September 2020. ### Origins of SCA The combination of these three paragraphs presents a real conundurum for banks. To understand why, it helps to track the origin of the RTS back to the original legislation, the PSD-2 where Article 97 requires Payment Service Providers to apply Strong Consumer Authentication. Paragraph 5 broadly states that the card issuer should allow the ecommerce merchant to use the issuer's own mode of authenticating the cardholder (emphasis mine). > 5\. Member States shall ensure that the account servicing payment service provider allows **the payment initiation service provider and the account information service provider to rely on the authentication procedures provided by the account servicing payment service provider** to the payment service user in accordance with paragraphs 1 and 3 and, where the payment initiation service provider is involved, in accordance with paragraphs 1, 2 and 3. ## A History Lesson The very *raison d'être* for 3-D Secure was for just this purpose. In the early 2000s, when eCommerce was still in its infancy, the Verified by Visa programme was launched to establish trust between the cardholder, the merchant and the card issuer. It also enabled any ecommerce merchant globally to check whether their consumer was a customer of a bank that provided 3-D Secure authentication, and if it was, then the transaction could be routed to the issuer so that the cardholder would receive a familiar authentication experience for every transaction. As ecommerce matured and more transactions flowed through the ecosystem, card issuers could build a picture of what normal behaviour looked like for customer A and how that is likely rather differ from the behaviour of customer B. In essence, card issuers were able to very accurately discern the identity of the person initiating the transaction and precisely discrimate between fraudsters and consumers. Very similar methods are employed when banks receive payment requests that are out of the ordinary, e.g. having cards declined at ATMs overseas or when making an unusually expensive purchase. The EBA's decision to outlaw such a tried & tested approach will make it much harder for issuers to delivery an SCA compliant authentication procedure that is not doesn't sacrifice the cardholder experience. ## Managing the Customer Experience Almost every bank will need to develop multiple authentication journeys as different sectors of their customer base will have different expectations, e.g. consumers will have different expectations from corporate cardholders, student account holders will differ from high-net worth customers etc. However, to avoid digital exclusion, every sector needs a SCA-compliant option and, unless the consumer has access to a smartphone with their bank's mobile banking application installed, ecommerce is likely to get a lot less fun. ### In-App Biometrics The bank's application should be compliant with the EBA's requirements for SCA as it will convey possession and, depending on the modernity of the handset, either knowledge or inherence. This should be the default option for most issuers as it will add the least amount of friction to the shopping experience for smartphone users. ### A Fallback Solution For those cardholders without a smartphone then it becomes a lot harder to apply SCA. Prior to the publication of the EBA's June 2019 Opinion paper, many Issuers were considering SMS-OTP + behavioural biometric (based on 3DS transaction data) as being compliant with the SCA requirements. Unfortunately, Paragraph 21 has outlawed that approach and, while an OTP delivered by SMS or to a landline can be used as a possessive factor, there are no good options for the second factor. In this scenario, as the cardholder does not possess a smartphone, then very few of the EBA's preferred biometrics will be available, for example, facial recognition, fingerprint analysis, heart rate etc are all off the table. Keystroke dynamics *may be* an option but, when assessing solutions on the market, it appears as if the cardholder would have to type a 25-30 character phrase for an identity to be discerned to a suitable level of accuracy. Ignoring the customer experience of this for a moment, while this approach would be possible in a browser-based transaction, it would not scale well to the other device types that EMV 3DS now supports. Imagine trying to do this when purchasing an eBook on a Kindle or a digital download on a Playstation. Even though, for this scenario, it is assumed that the cardholder doesn't possess a smartphone, this approach is also very unlikely to be supported if the transaction is being initiated from a mobile application. Additionally, many of these behavioural profiling technologies seem to flow in the opposite direction to initiatives being launched by the mobile platforms to improve the privacy of their consumers and restrict access to technologies that could be used for malicious purposes. For example, Apple [explicitly acknowledge](https://webkit.org/tracking-prevention-policy/?ref=transactionintelligence.net#unintended-impact) that fraud detection capabilities may be compromised by their efforts to improve privacy but, in their view, consumer privacy is the higher priority. In practical terms, this leaves many issuers with the only option of supplementing an SMS-OTP with a knowledge factor for SCA-compliance. Ideally, this shared secret should be used elsewhere, i.e. when accessing online or telephone banking etc., to reduce the need for the consumer to remember another credential. Issuers also need to consider how to collect this shared secret from consumers and allow consumers to reset it from time to time. Both of these activities also need to be protected by SCA. This also presents a fairly poor customer experience as EMV 3DS (version 2.2) can only accept a single response per screen and so a two-stage challenge process would be required where the cardholder would first be prompted for an OTP and then a second screen would appear to prompt for the knowledge factor. Thanks to Article 4(3)a of the RTS, if either factor is incorrect, the consumer would have to start from scratch as they cannot be told which factor was entered incorrectly. While I understand the need for this from a security standpoint, it's going to cause a lot of frustration to real-world consumers. ### Recommendations The best option for most consumers will be to use a smartphone application to perform an in-app biometric authentication. If the application has been well-designed to take advantage of the mobile platform's accessibilty features then this should also scale well to those consumers with protected characteristics. However, to avoid digital exclusion of the vulnerable, there are no good options and, frankly, the least worst option may be to turn the clock back a decade and deploy [CAP readers](https://en.wikipedia.org/wiki/Chip%5FAuthentication%5FProgram?ref=transactionintelligence.net) to those customers. This would allow those consumers to perform compliant SCA through an OTP delivered by voice to a landline, or via SMS to a feature phone, to be combined with an OTP generated from the CAP reader once a card has been inserted and the correct PIN entered. ## Conclusion While it is often unfashionable to feel sympathy for banks, many are in an unenviable position where there are few good options to avoid the digital exclusion of some of their customer base. Additionally, the PSD-2 and the RTS can't be read in isolation as the banks are equally bound by legislation to avoid discrimating against those with disabilities. I can't profess to state legally which legislation carries more weight but, morally, it feels like compliance of the PSD-2 is a lower priority than that of certain disability legislation. In my day job, I shall continue to work with the european and national regulators and the industry forums to try to identify a pragmatic middle ground to this conundrum but, at present, there are no good solutions. Please [get in touch ](https://uk.linkedin.com/in/mattberryman?ref=transactionintelligence.net)if you would like to learn more. ### Going ‘All In’ with Broadcom URL: https://transactionintelligence.net/going-all-in-on-broadcom/ Last updated: 2025-02-26T09:55:59.000Z As some of you will have noticed, after a few months doing something else, I have returned to the Payment Security team at Broadcom. It is wonderful to be back and it doesn't really feel like I ever left. During my time out, I discovered that it's very rare to be able to contribute to solving problems that impact the everyday lives of millions of people. The Payment Security team lets me do just that and, to top it off, I have an amazingly dedicated group of colleagues around the world. When my garden leave was drawing to a close, and my time for tinkering was running out, I switched my blog platform from [Squarespace](https://squarespace.com/?ref=transactionintelligence.net) to a self-hosted instance of [Ghost](https://ghost.org/?ref=transactionintelligence.net). Now, in the same way that my family is now fed by Broadcom, this blog is powered by a Broadcom CPU. ## Hardware The blog now runs on a £44 [Raspberry Pi Model 4](https://www.raspberrypi.org/products/raspberry-pi-4-model-b/?ref=transactionintelligence.net). For the price, this is a very capable computer (broadly on par with a regular desktop from 2012) and is more than up to the task of hosting this site. > The Raspberry Pi Foundation was created to promote the study of computer science and put the fun back into learning computing. The co-founder, and current Chair, of Raspberry Pi foundation, [Eben Upton, works for Broadcom](https://www.techspot.com/article/531-eben-upton-interview/?ref=transactionintelligence.net) and given the charitable status was able to secure SoCs at preferential prices and the rest is history. ## Software While the default choice for many self-hosted blogs is Wordpress, it seems to be a very heavyweight option that is trying to be all things to all people. Given how I don't want to be a full time system admin, I wanted to choose a small, focussed blog engine which would largely look after itself. The Ghost project was co-founded by a former core contributor to Wordpress who was [becoming disillusioned with its lack of focus](https://ghost.org/vs/wordpress/?ref=transactionintelligence.net). This resonated with me and, from the popularity of the project on [Github](https://github.com/TryGhost?ref=transactionintelligence.net), it seems to resonate with many others. It's installation was straight-forward, secure by default and will keep itself updated without any further involvement from me. The default theme looks fine for my purposes but, the popularity of the platform is so high, that there are many third-party options also available. ## Connectivity While there are [companies that host Raspberry Pis in data centres](https://www.mythic-beasts.com/order/rpi?ref=transactionintelligence.net), they don't currently offer hosting of Model 4s and so this site was served from my home broadband connection. Given the size of my current readership, that was likely to have been perfectly adequate but, as I like a challenge, I've configured Cloudflare as a CDN. ## The Hard Part Now the hard part really begins. As I have a robust platform to share my thoughts with the world, I need to commit to writing at a faster cadence than I have managed recently. Wish me luck! ### Thriving in the Open Banking Ecosystem URL: https://transactionintelligence.net/thriving-in-the-open-banking-ecosystem/ Last updated: 2025-02-26T12:57:10.000Z At the recent [Open Banking Excellence](https://www.meetup.com/Open-Banking-Excellence/?ref=transactionintelligence.net) event, I heard that the average bank offers around 300 products across their customer base. In a crowded market, it’s hard for a bank to differentiate themselves and offer a *single* market-leading product and so it’s virtually impossible for a bank to excel across them all. ## Switching Current Accounts In 2013, the UK’s Competition & Markets Authority (CMA) required that banking industry develop and launch the Current Account Switch Service (CASS). Adopted by 40 banks covering 99% of the UK’s current accounts, it was designed to streamline the process to switch your primary bank account between different providers. In 7 days, your balance and all your saved payees will be transferred to the new bank. Organisations that you pay by Direct Debits will be informed of the new account details and if your old account receives any incoming fund transfers, they will be redirected for upto three years (and this will be extended for another year each time a new payment is received). It’s a great service; when I’ve used it in the past, it’s worked very well and, frankly, one unexpected benefit is that it is a far more convenient way to close an unwanted bank account that the provider’s standard procedure that normally involves visiting the branch. It is disappointing therefore, that [uptake remains low](https://www.bbc.co.uk/news/business-41740616?ref=transactionintelligence.net)and it was only [used by 100,000 consumers last month](https://www.bacs.co.uk/DocumentLibrary/Monthly%5FCASS%5Fdata%5F2019.pdf?ref=transactionintelligence.net), only a tiny fraction of the [estimated 70 million current accounts](https://www.bbc.co.uk/news/business-44522630?ref=transactionintelligence.net) in the UK. A lot of money is being left on the table by consumers who are living with banking products that are ‘good enough’ but not industry-lea ding. For example, if a young person could switch their savings from an account with 0.5% interest annually to one earning 1.5% the compound effect of that interest over 40 years could help them bring forward their retirement date. ## How does Open Banking help? I think the days where a person obtains all their banking products, e.g. current account, credit card, mortgage, life assurance etc., from a single provider is coming to an end. For example, if I bank with Lloyds but prefer the money management tools in the Barclays mobile app, then Open Banking will allow me to manage my Lloyds account without ever having to leave my preferred app. Taking this a step further, there is no reason why I would have to a mobile app provided by *a bank* to manage my financial life. There are already applications hitting the market from Money Dashboard, Yolt and Grip that offer sophisticated Personal Finance Management (PFM) services independently. These applications use two new technical standards that have been defined by the European Central Bank called Account Information (AIS) and Payment Initiation Services (PIS). When combined together, these two services allow third-party companies to offer a compelling view of your financial life. AIS enables your bank to share information about where you haved use your payment cards. PIS then enables the third-party to request that your bank perform outward transfers - with your explicit approval - to other bank accounts. ## The Future These PFM applications currently offer a holistic view of your current financial position that is totally independent of the financial institutions that hold your savings or finance the mortgage on your home. They can offer budgeting advice and recommendations to help you divert surplus cash to savings to build emergency funds for when disaster strikes. I believe the next step is that [these applications](https://transactionintelligence.net/the-future-of-financial-advice/) will transition into ecosystems where, for each segment of your financial life, you’ll be able to choose from two or three best-in-class providers for anything from credit cards to pensions and investments. ## What does this mean for the incumbents? The barriers to switching have never been lower than they are today. While uptake of CASS remains relatively low, it’s hard to get excited about the prospect of switching from one to another if the only reward is [saving £92/year](https://www.moneymt.co.uk/blog/save-92-switching-bank-account/?ref=transactionintelligence.net). However, as new entrants arrive in the market offering hyper-personalised financial management applications that actively improve all aspects of your financial happiness, it is going to be much harder for an incumbent to retain your custom unless they refine their product suite and start offering best-in-class options. If they don’t, I’m sure there will be many other people who would jump at the chance. ### Learning to ❤️ My PIN URL: https://transactionintelligence.net/learning-to-my-pin/ Last updated: 2025-02-26T12:54:48.000Z Many European banks are grappling with how to comply with the requirements of the Regulatory Technical Standards for Strong Consumer Authentication (RTS-SCA). Published by the European Banking Authority (EBA) in March 2018, and coming into force in September 2019, this regulation mandates a fundamental shift from traditional authentication techniques (e.g. passwords, memorable questions and, even the more modern, One Time Passcodes) to what is called Strong Consumer Authentication (SCA) that comprises of two of the following three types of authentication; knowledge (something that the consumer knows), possession (something they have) and inherence (something they are). ## Balancing Security with Convenience Not only is the type of authentication changing, and becoming more complex, the scope where this authentication method must be used is expanding. Currently, many banks have deployed sophisticated risk assessment tools that are capable of very effectively separating fraudulent transactions from legitimate ones. Given that any interruption to the consumer’s transaction can lead to a poor consumer experience, increased costs for the bank and the potential for reduced sales volumes to merchants, it is in everyone’s interests to keep the percentage of transactions being authenticated at the lowest possible level whilst still protecting consumers from fraudsters. For some banks, the use of very sophisticated tools by highly skilled staff allows them to safely allow over 95% of eCommerce transactions flow without interrupting the cardholder’s shopping experience. The RTS-SCA will remove much of the freedom that banks currently possess when designing & implementing their fraud mitigation strategy and it is very likely that the percentage of transactions requiring authentication will be significantly higher than it is today. The exact rates will vary between banks but, it is likely that at least 30-50% of transactions will now need authentication; which, for some consumers, may manifest as 10x increase on today. Another confounding factor is that it is likely that consumers may experience different types of authentication as they interact with their banks in different channels; for example, having to use an OTP delivered via SMS for an eCommerce transaction vs. a username, password & a different OTP when accessing online banking vs. using a biometric (commonly a fingerprint scan) when accessing a mobile banking application. After having spent years helping banks comply with the authentication requirements for eCommerce, experience suggests that few banks are deliberately choosing to have a different customer experience for each of the channels but it is being forced upon them from a combination of internal IT challenges and the demographic of their customer base. In summary, this means that the immediate impact RTS-SCA for many consumers will be to increase the amount of friction that they experience when they shopping online or interacting with their bank through a digital channel. ## Streamlining the Sharing of Data with Open Banking In contrast to the above, the Open Banking revolution offers consumers unparalleled opportunities to share their most precious banking information with an huge variety of third-party organisations for everything from, receiving alerts when cheaper mortgage deals become available to getting personalised financial advice on how best to manage their money. While consumers will still have to undergo their bank’s SCA procedures when they first connect a new third-party service to their bank account, and renew that connection periodically, the mere possibilities of these new connections are likely to cause confusion in consumers. They will be receiving messages from different parts of the industry with diametrically opposed views; they will find themselves being prompted to authenticate themselves 10x more frequently when shopping online but also receiving marketing messages from banks & third-party providers saying that it’s never been easier to share their financial data. To some, the mere name ‘Open Banking’ breeds nervousness and, for both initiatives to succeed, consistent messages should be shared by all parties as any area of confusion risks being exploited by fraudsters. ## I ♥️ PIN When speaking to the industry about consumer education, there were mixed views as to where the responsibility lay and, sadly, most organisations felt that it lay somewhere else. Changes of this magnitude do not come along frequently. The last industry-wide change of this scale was the UK’s adoption of ‘Chip & PIN’ payment cards which was brilliantly marketed as ‘I ♥️ PIN’ with [a launch date Valentine’s Day 2006](http://www.chipandpin.co.uk/?ref=transactionintelligence.net). Another good example, from the transport sector, is the [‘See it, say it, sorted.’ campaign](http://www.btp.police.uk/?ref=transactionintelligence.net) to raise travellers’ awareness of how to deal with suspicious packages. It’s literally impossible to spend any time on a train or in a station without having this message drilled into you from posters and announcements over the PA system. I’d love to see an ‘I ♥️ Open Banking’ awareness campaign rolled out with consistent messaging from all parties highlighting [the exciting opportunities](https://mattberryman.com/articles/2019/2/21/the-rise-of-robo-banking?ref=transactionintelligence.net) that Open Banking will bring and positioning SCA as a necessary evil required to secure the ecosystem. ### The Future of Financial Advice URL: https://transactionintelligence.net/the-future-of-financial-advice/ Last updated: 2025-02-26T12:53:53.000Z A couple of recent announcements have prompted me to think about future of personal finance and wealth management. On 10 Feb, [the Financial Times reported that Lloyds are planning to expand their wealth management division](https://www.ft.com/content/35d26110-2acb-11e9-a5ab-ff8ef2b976c7?ref=transactionintelligence.net) with a goal of almost doubling their Assets Under Management over the next three years. Being squeezed in the traditionally lucrative areas of credit cards and mortgages, Lloyds are seeking new areas for future growth and, interestingly, this will put them in direct competition with St. James’s Place, in whom, Lloyds used to hold [a 60% share until fully divesting themselves in 2013](https://www.ft.com/content/835c1dee-60f1-11e3-916e-00144feabdc0?ref=transactionintelligence.net). The second announcement was Goldman Sachs leading a [US $60M Series E investment in Nutmeg](https://uk.reuters.com/article/us-nutmeg-funding/goldman-sachs-backs-uk-based-robo-adviser-nutmeg-in-latest-funding-round-idUKKCN1PG28Y?ref=transactionintelligence.net), the online investment service. Nutmeg are far from alone in trying to bring investment to the masses; [MoneyBox](https://www.moneyboxapp.com/?ref=transactionintelligence.net), [WealthSimple](https://www.wealthsimple.com/en-gb/?ref=transactionintelligence.net) and [Wealthify](https://www.wealthify.com/?ref=transactionintelligence.net) are integrated with Starling Bank’s marketplace letting users open and invest directly within the mobile banking app. [EXO Investing](https://exoinvesting.com/?ref=transactionintelligence.net) are taking a slightly different approach and offering low-cost, actively managed investments powered by Wall St-grade algorithms. Even Apple appear to be entering the field with [a rumoured Personal Finance application, modelled on their Health app, using data from a new credit card they may launch in collaboration with Goldman Sachs](https://www.wsj.com/articles/apple-goldman-sachs-team-up-on-credit-card-paired-with-iphone-11550750400?ref=transactionintelligence.net). All this means that Lloyds are entering a market with precious little whitespace; while there will always be a part of the population that desires or needs the personal touch of an independent financial advisor who intimately understands their family’s long-term goals, the mass-market has never had more options. - If you are a knowledgable investor, great - pick some sensible, low-cost passive funds from Vanguard. - If you know that you *should* be doing something but are unclear on the specifics, then Nutmeg, EXO and their peers will serve you well. - If you are not even sure where to start, then this is where Open Banking and the democratisation of data can really help. ## Democratisation of Data Today’s sophisticated Personal Finance Management (PFM) applications can help everyone take better control of their finances. A good PFM app should, at the very least, have the following features. - be able to show the consumer details of all their accounts across multiple different providers to quickly provide a holistic view of current accounts, credit cards, savings, pensions, loans, investments and much more. - spending should be categorised to help consumers understand where every penny of their money is going, and - *this is the really clever bit*, offer customers individually tailored, specific & actionable insights to let people manage their finances as seamlessly as they keep on top of their social media. ## Setting your Finances to Auto-Pilot At the moment, to help people manage their money, [long articles](https://www.reddit.com/r/ukpersonalfinance/wiki/index?ref=transactionintelligence.net) or [complicated flow-charts](https://i.imgur.com/BfHzwr9.png?ref=transactionintelligence.net) have been prepared to show people how to get started. While these are truly a great first step, and I applaud their authors, where they do fall short is that it’s almost impossible to offer generalised advice that is applicable to everyone’s own circumstances. This changes in 2019. The wider adoption of Open Banking and the improved ability for third-parties to securely access your bank details will mean that many innovative solutions can be brought to market to help customers get the very best value from every penny that they possess. Imagine receiving the following series notifications from your mobile banking application: - “We notice you have a loan at 7.5% interest, would you like us to switch it a different provider at 4.5% interest to reduce your monthly payments by £22? Alternatively, you could switch and keep the monthly payments the same to clear the loan four months earlier.” - “We notice you have £1,950 saved in an account earning 0.1% interest; would you like to earn another £27.30 interest each year by switching to a different provider earning 1.5% interest?” - “Great work with your savings. You’re 80% of the way toward reaching your goal of having three months saved as a safety net. If you can keep this up, you should reach your goal in ten more weeks.” - “Congratulations, you have a good safety net and now might be a good time to start investing for the longer term. Would you like to open a Stocks & Shares ISA to save for the future? If you can afford to put this money away for 3-5 years, we would suggest investing in XYZ funds.“ A lot of people have worked exceptionally hard over recent years to break down the walls surrounding this data. When all the raw data is combined with sophisticated machine learning to powering these recommendations, banks can offer advice that is perfectly tailored for individual customers’ spending patterns and financial position. I am tremendously excited about the ability for everyone to receive the very best in class financial advice to support their individual goals. ## Financial Happiness Working for [Tink](https://tink.com/?ref=transactionintelligence.net), the rails and brains of Open Banking, I fully acknowledge that I am far from impartial on this topic. However, when you read about [the crushing weight debt has on people](https://www.bbc.co.uk/bbcthree/article/fcd81d56-376d-4dc4-a932-086fae147d33?ref=transactionintelligence.net), anything that can be done to nudge people towards financial happiness will have a big impact on a lot of people’s lives. lf you’d like to join Tink, we are [hiring](https://jobs.tink.se/?ref=transactionintelligence.net) for many positions as we expand from Stockholm into the UK, Germany, France, Italy and Spain.