By Jonathan Lee
Malaysia’s payments story has been a success, but banks now have to deal with the consequences of that success. More transactions, more channels and higher customer expectations are exposing the limits of issuing infrastructure that was built for a simpler market.
In its Financial Sector Blueprint, Bank Negara Malaysia set a target of at least 15% annual growth in average e-payments per person between 2022 and 2026. The market is already ahead of that pace, with e-payment transactions growing by 17% annually between 2022 and 2025, according to BNM’s 2025 Annual Report.
The growth is broad. Debit card transactions rose 20.5%, contactless payments reached 2 billion transactions, DuitNow QR volume doubled to three billion transactions, and the average e-money transaction size increased to RM43 from RM33 a year earlier.
For consumers, this increasingly feels like one payments experience. A customer may pay with a debit card in store, use the same credential in a mobile wallet, scan a DuitNow QR code at a merchant, approve an e-commerce purchase through 3DS and manage the whole relationship through a mobile banking app.
But inside the bank, the decisions behind that journey may still sit across separate systems: issuing, tokenisation, authentication, fraud monitoring, servicing and reporting.
That is why card management now sits at the centre of the pressure. The card management system, or CMS, has moved beyond issuing and servicing into the governance of payment credentials across cards, wallets, e-commerce, QR, mobile banking and fraud response. For Malaysian banks, legacy replacement is now about control: faster product change, clearer risk decisions and better service.
Where fragmentation bites
Fragmentation shows up fastest in the work that should be simple. Launching a virtual card, adding wallet provisioning or changing a debit-card control can pull in half the bank if issuing, tokenisation, fraud, servicing and reporting all sit apart. What looks like a simple product change becomes an integration exercise.
Over time, the bank spends more energy keeping the estate aligned than improving the proposition. Product teams wait for integration work. Fraud teams see partial behaviour. Service teams work with incomplete information. Risk teams pull evidence from different systems. Technology teams maintain old connections created for one product, one channel or one urgent deadline.
BNM’s 2026 Technology Requirements for Payment Services Regulatees focuses on cyber risk, fraud monitoring, secure digital services, customer protection and operational resilience across parts of the payments sector. Banks sit under their own technology-risk framework, but the pressure across the market is moving towards stronger controls, better evidence and less dependence on manual fixes behind the scenes.
A stronger issuing core
The issuing core has to become the place where products are created, changed and serviced with far less internal negotiation. Credit, debit, prepaid, virtual and wallet-linked products cannot sit in separate operational lanes when the customer sees one banking relationship.
A debit card may begin as a physical product, then end up tokenised in a wallet, used online, controlled through a mobile app, linked to loyalty rules and monitored for fraud across several channels. If each part of that journey is governed somewhere different, even small changes become slow. A service agent may not see the same view as the fraud team. A product manager may be ready to launch, while the integration work drags through the background.
A modern CMS should give the bank a cleaner way to manage product rules, credentials, servicing, limits, disputes, reporting and customer information in one place, or through one consistent operating layer.
BPC’s SmartVista Card Management and Issuing platform, for example, supports credit, debit, prepaid, virtual and multi-purpose card and wallet programmes, with open APIs, product configuration, workflow tools and reporting built around day-to-day issuing operations.
Most banks already have plenty of technology. The harder task is getting the issuing business to behave as one business. When the card platform, wallet layer, transaction controls and service workflows are closer together, banks can adapt products without turning every change into a mini-transformation programme.
Fraud belongs in the same view
Fraud is exposing the weakness of separated systems faster than almost any other pressure. Malaysia’s growth in e-commerce, wallets, QR and mobile banking means more transactions are happening in environments where speed and context carry real weight. A genuine customer can still be caught in a scam. A valid credential can still be used in a risky situation. A payment can look ordinary in the card system and suspicious when viewed alongside device, behaviour, merchant and recent activity.
BPC’s SmartVista ACS supports 3DS 2.x, out-of-band authentication and OTP-based methods. Fraud-management capabilities cover real-time monitoring across card, mobile, e-commerce, ATM, POS and digital banking activity. The practical gain for a bank is a shorter distance between authentication, fraud analytics and case handling. Risk can be assessed while the payment is still moving, and the bank has a better record of the decision if the customer later needs support.
Lessons from scale
In markets where digital payments have grown quickly, card modernisation often expands beyond the original CMS brief. PVcomBank in Vietnam began with legacy migration to SmartVista, then added modern card management, API connectivity, fraud management and a 3DS 2.2 upgrade as its portfolio grew.
Islami Bank Bangladesh PLC grew its card base fivefold to 12 million by 2026, while transaction activity rose 35 times to 15 million transactions a month. CRDB Bank’s migration in Tanzania brought issuing and acquiring onto a modern platform across a wider multi-country footprint, with links into mobile and agency banking.
Legacy modernisation can follow several paths, from a fast cutover to a phased migration by product, component or customer segment. The route matters less than the condition of the estate afterwards: fewer hand-offs, cleaner data, shared controls and a simpler route for the next product change.
For Malaysian banks, CMS modernisation should leave the payments business easier to change and easier to control. If fragmentation remains in place, banks will keep paying for it in slower launches, weaker fraud visibility and service teams left to explain journeys their systems cannot see clearly enough.
The author is the Partners and Alliances Director APAC, BPC





