A bank postpones a payments-modernisation programme for another year. The existing platform is stable, the migration looks complex and the budget can be directed elsewhere. On paper, the decision appears cautious.
Yet the costs does not disappear. They move into maintenance budgets, longer product cycles, manual processes, security controls and layers of integration. Each expense may look manageable in isolation. Together, they steadily reduce the institution’s ability to compete.
BPC’s Modernisation Without Disruption guide illustrates one of these hidden costs through the impact of false declines. For a portfolio processing 10 million attempted debit transactions each month, an avoidable false-decline rate of just 0.50 percentage points would block 50,000 legitimate transactions. At an average transaction value of USD 30, that represents USD 1.5 million in lost approved spend every month. Based on the issuer-interchange benchmarks examined in the guide, the resulting annual revenue loss could range from approximately USD 42,000 to USD 160,000, depending on the market and card mix. That calculation does not include reduced card usage, customer complaints or the bank losing its position as the customer’s preferred payment method.
Modernisation requires investment and careful execution. But maintaining the status quo is not the cost-free option it can appear to be.
More technology spending, less room to change
Legacy platforms rarely operate alone. Over time, banks add middleware, custom interfaces and manual processes to connect older systems with mobile banking, digital wallets, fraud platforms and newer payment rails.
Each addition keeps the environment running, but also makes it harder to change. A product update that should be relatively simple may require development across several systems, extensive regression testing and coordination between specialist teams. Resources that could support new services are instead used to maintain existing ones.
The cost can be considerable. McKinsey reported in 2024 that technology debt can account for as much as 40% to 50% of total investment spending in some organisations. This is where the economics of postponement begin to shift. A bank may avoid the visible expense of modernisation while continuing to fund the same underlying constraints year after year.
There is also a talent cost. Expertise in older programming languages and highly customised systems is becoming harder to replace. When knowledge sits with a small group of specialists, routine changes become slower and operational risk rises as those employees retire or leave.
The opportunity cost rarely appears in the budget
The clearest measure of a payments platform is no longer whether it processes transactions reliably. It is also how quickly the business can respond when customer behaviour, regulation or market conditions change.
Consider the work required to launch a new card proposition, connect a digital wallet, introduce real-time controls or enter a new market. On a tightly coupled legacy platform, these projects can require extensive customisation. Commercial teams may have a viable proposition, but the technology timeline weakens the business case.
The resulting loss is difficult to record. It appears as a launch that arrived six months late, a partnership that could not be supported or a product that was never proposed because the technical effort was considered too high.
This matters as competition shifts towards institutions that can configure and launch services without redesigning their entire processing environment. The Basel Committee’s 2024 report on the digitalisation of finance warned that banks may struggle to remain competitive and profitable if they cannot adapt their strategies to an increasingly digital market. It also noted that competition from fintechs and technology firms could reduce market share and place further pressure on revenues.
The cost of delay, therefore, includes the revenue a bank was technically unable to pursue.
Operational stability can become expensive to defend
Banks often retain older systems because they are considered proven. That stability has value, particularly in payments, where even brief interruptions can affect thousands of customers.
Age, however, does not remove operational risk. It can make that risk harder to see. A platform may depend on ageing components, limited documentation and a web of interfaces built over many years. Even a small change can have consequences elsewhere in the environment.
The impact becomes visible when systems fail. In March 2025, the UK Parliament’s Treasury Committee reported that nine major banks and building societies had accumulated at least 803 hours of unplanned technology outages over two years. Across 158 incidents, millions of customers were prevented from accessing or using banking services.
The direct expenses include incident response, remediation and compensation. The longer-term costs are harder to repair: damaged customer confidence, greater regulatory attention and hesitation within the bank whenever another system change is proposed.
Keeping a legacy platform running can preserve continuity in the short term. It does not automatically create resilience for the next stage of the business.
Security upgrades become harder to absorb
Modern payment environments must respond to new fraud patterns, cyber threats and regulatory expectations without weakening service availability. Older architecture can make that balance difficult.
The US Office of the Comptroller of the Currency stated in its 2025 Cybersecurity and Financial System Resilience Report that prolonged use of legacy systems can introduce security vulnerabilities, complicate maintenance and reduce operational resilience. It also warned that delaying architecture upgrades could create unwarranted risk.
This does not mean newer technology is inherently secure. Modern platforms still require strong governance, testing, access controls and monitoring. The difference lies in how readily the underlying architecture can support updated security measures and integrate with real-time fraud-management capabilities.
The financial consequences of cyber incidents are also widening. According to the International Monetary Fund’s 2024 analysis, the size of extreme losses from cyber incidents had more than quadrupled since 2017 to US$2.5 billion, while indirect losses such as reputational damage and security remediation were substantially higher.
For banks operating fragmented technology estates, each new control can require another integration or workaround. Security spending rises, but the underlying complexity remains.
Modernisation does not require a single leap
The risks surrounding payments modernisation are real. Poorly planned migrations can disrupt customers, extend project timelines and replace one form of complexity with another.
That is why the choice should not be framed as a contest between retaining the existing platform indefinitely and replacing everything at once.
A phased programme can prioritise the areas creating the greatest business constraint. Banks may introduce modular services, APIs or cloud-ready components alongside their existing environment, then move products and transaction volumes in controlled stages. Clear migration checkpoints, parallel processing and thorough testing can protect continuity while the architecture evolves.
BPC supports financial institutions in taking this measured approach, using SmartVista’s modular architecture to modernise specific payment capabilities while accommodating existing systems and operational requirements. This allows each stage of the programme to be aligned with a defined business priority, rather than treating modernisation as a single large-scale technology replacement.
The objective is not to modernise for its own sake. It is to reduce the cost of change. A successful programme should make it easier to launch products, integrate new services, scale capacity and strengthen operational control without creating another rigid technology estate.
The cost of waiting compounds
The business case for modernisation is often assessed against the immediate cost and risk of migration. That calculation is incomplete unless it also measures the cost of maintaining the current environment.
Those costs accumulate through higher maintenance expenditure, scarce technical skills, delayed launches, complex security work and opportunities the business cannot pursue. Waiting may defer a transformation programme, but it can also leave the eventual migration larger and more difficult.
The practical question is no longer whether an older platform can continue processing transactions. It is whether the institution can afford the constraints that come with keeping it unchanged.
To examine the risks, priorities and practical considerations involved in building a modernisation strategy, download BPC’s latest modernisation guide.