It is said that a chain is only as strong as its weakest link. This is especially true in the payments ecosystem, where every transaction passes through multiple gateposts and entities before being accepted or declined. When one link fails, the entire system is at risk, with far-reaching consequences for clients, partners, and cardholders alike.
It’s why in today’s fast-moving digital payments landscape, regulated entities who issue payment cards have a responsibility to ensure that cardholders can access their money, even in the face of unexpected disruptions. For the most part, the safeguards that are in place are formidable. From real-time transaction monitoring to redundant network infrastructure and data encryption protocols, multiple layers of contingency are in place to ensure that payments continue to flow and service is seamless, no matter what.
However, there is one risk vector that is easily overlooked. The implications of this oversight can be severe, potentially disrupting the financial lives of cardholders and in the process, damaging the reputation of the service provider. This is the customer facing website or app which holds various critical functions such as blocking cards, displaying balances and transaction histories.
Consider this, whether you’re on a well known platform like WordPress, Shopify, or something more bespoke, your website is built on software that receives updates to its code. Those updates are there to provide new functionality, bolster security, and make your service more efficient. But what if an update unexpectedly caused a critical error, crashing your website or app, and preventing you from maintaining service?
Well, that’s exactly what happened on July 19th this year when an update to Crowdstrike’s security platform sparked one of the largest outages in IT history. The outage grounded thousands of flights, caused major disruptions to hospitals, and halted services at online banking systems and financial institutions worldwide. All told, insurers have estimated that the cost of the outage will be $5.4 billion.
This type of risk is not just reserved to a bug in a software update either. It can take many forms from a cyber attack, a disgruntled employee messing with the code, or your website/app development studio going rogue or bankrupt. Whatever it is, the outcome is always the same: service is disrupted, cutting off cardholders from their financial lives. What’s more, this type of third-party risk is not something that many regulated entities in the payments chain think about because the risk isn’t specific to their operation.
Fortunately, these kinds of risks don’t have to spell disaster. There are solutions designed to ensure that should the unexpected happen, services remain uninterrupted, and everything can continue business as usual.
At Accomplish, we spotted this missing piece in operational resilience early. We realised that there was an inherent flaw in having a non-regulated entity build and deliver front-end access to cardholders. It was a gap that doesn’t fall under standard reporting requirements, yet it remains a significant point of failure. It’s the part most visible to consumers – the app and interface they interact with – which is often overlooked by the rigorous checks and balances seen elsewhere in the payment supply chain.
We’ve addressed this challenge by making sure that we can quickly spin up a contingency portal that ensures the continuous delivery of the most essential parts of the service. This is Holistic Issuing. At Accomplish, we take our responsibility to ensure that cardholders are not cut off from their financial lives very seriously. We see it as an insurance policy. Fortunately, it’s one that few of our clients know exists. In our decade-long history, we’ve only had to deploy it once. But it’s there, just in case.
Why do we do it? Some might say it’s because we’re control freaks, and they might be right! Jokes aside, there’s a deeper reason. At Accomplish, we’re not just technologists. Many of us, including our founder, Guy Raymond El Khoury, have enjoyed successful careers working in highly regulated sectors. When you work with banks you’re wired to look at risk from all angles. You look for every risk vector, including those that you’re not directly responsible for. It’s about stress testing every part of the chain, looking for the weak link.
We do it because it’s the right thing to do, and because it’s a critical part of our mission to ensure the best possible service for our clients and cardholders.
