The Analyst Note   Financial Services series  ·  piece 8 of 8  ·  Last updated July 2026

Corporate treasury and finance technology 2026: what a $500M–$5B revenue company's treasurer should actually procure between FedNow, RTP, ISO 20022, and the Nacha fraud-monitoring rules.

Instant payments inflected. SWIFT ended MT coexistence for cross-border payment instructions on November 22, 2025. Nacha Fraud Monitoring Phase 1 hit March 20, 2026 and Phase 2 on June 22, 2026. The mid-market treasurer's procurement question is no longer "which TMS" — it is "what stack pattern lets me use the rails I want, meet the fraud-monitoring rules I now own, and reconcile against the ERP without a middleware graveyard."

14 min · Deep-dive · Financial Services series, piece 8 of 8

Questions this article answers

  • Where are FedNow and RTP actually running in 2026, and what does adoption inflection mean for a treasurer's rails choice?
  • What is the operational reality of the SWIFT ISO 20022 end of coexistence on November 22, 2025, and what must a treasurer verify with the bank?
  • What do the Nacha Fraud Monitoring Rules Phase 1 (March 20, 2026) and Phase 2 (June 22, 2026 practical) require of non-consumer ACH originators?
  • Which treasury management systems fit a $500M–$5B revenue mid-market treasurer — Kyriba, GTreasury, ION Treasury / Reval, HighRadius, Bottomline PTX?
  • Where do vendor-payment fraud tools — Trustpair, nsKnox, Eftsure, Trustmi, Bottomline SafeCash — fit into the treasury stack?
  • How does the payments-hub layer relate to ERP treasury modules — NetSuite, Sage Intacct, Dynamics 365 Finance, SAP S/4HANA, Oracle Fusion, Workday?
  • What sourcing checklist should the treasurer walk into the CFO's office with in 2026?

The mid-market treasurer's job description changed twice in 24 months. In November 2025, SWIFT ended MT-message coexistence for cross-border payment instructions between financial institutions, forcing every corporate on a cross-border rail to inherit the bank's ISO 20022 posture — or wear contingency-processing fees that began in January 2026. In March through June 2026, Nacha's fraud-monitoring rules for ACH originators became enforceable: Phase 1 hit large originators on March 20, 2026; Phase 2 eliminated the volume threshold and made every non-consumer originator, TPSP, and TPS responsible for a documented risk-based fraud-detection process by June 22, 2026. Meanwhile FedNow and RTP inflected. RTP processed 2.27 million transactions worth $8.62 billion on May 1, 2026. FedNow is at 1,800+ participants including 7 of the top 10 U.S. banks. The 2026 procurement question for a $500 million to $5 billion revenue treasurer is not "which TMS" — it is which stack pattern lets the treasurer use the rails the business wants, meet the fraud-monitoring rules the corporate now owns, land in ISO 20022 without wearing bank contingency fees, and reconcile against the ERP without silent middleware failure.

Instant payments inflected in 2026 — treasurers should now design for both rails.

FedNow launched in July 2023 and by December 2025 had crossed 1,500 participants, up 44 percent year over year. By mid-2026 the participant count is 1,800+ financial institutions, including 7 of the top 10 U.S. banks, per the Federal Reserve Financial Services participant roster. The Fed's two-year growth update documents the small-institution adoption pattern that matters for a corporate: settlement agents and certified service providers now sit between smaller community banks and the network, meaning a treasurer's bank does not need to be a direct participant to send or receive. RTP on The Clearing House side is further along. Q2 2025 recorded $481 billion in RTP value, and the network hit a single-day record of 2.27 million transactions and $8.62 billion on May 1, 2026. Same Day ACH — the Nacha rail treasurers know best — processed roughly 1.4 billion payments and $3.9 trillion in value in 2025, up 16.7 percent in count and 21.4 percent in value year over year. The 2026 procurement implication: the treasurer's rails-posture question is no longer "instant or not" — it is which rails the primary bank supports on send and receive, which rails the TMS or payments hub supports, and how the two match. Gap that before procuring anything else.

SWIFT ISO 20022 ended MT coexistence on November 22, 2025 — the treasurer inherits the bank's posture.

SWIFT's coexistence period between the legacy FIN MT messaging standard and the FINPlus ISO 20022 MX standard for cross-border payments began in March 2023 and ended on November 22, 2025. After that date, cross-border payment instructions sent between financial institutions must be in ISO 20022. Legacy MT sends may be negatively acknowledged by the network or converted through SWIFT's contingency translation service, which introduces validation risk and — as of January 2026 — a contingency-processing fee. Adoption sits at roughly 80 percent of daily traffic in ISO 20022 with more than 3.1 million payment messages exchanged daily across 210+ sending countries and 220+ receiving countries. The corporate treasurer does not send SWIFT messages directly. The treasurer inherits the bank's posture. Two questions belong in every 2026 bank-review conversation. First, what is the bank's post-November-2025 CBPR+ posture and its use of the SWIFT contingency service for legacy MT sends the corporate might be pushing through? Second, is the enriched remittance data ISO 20022 carries end-to-end reaching the corporate's TMS, or is it being truncated at the bank or an intermediary? Truncation is where the migration's practical value disappears.

Nacha Fraud Monitoring Rules make the corporate treasurer accountable — not the bank.

Nacha's fraud-monitoring amendments landed in two phases. Phase 1 was effective March 20, 2026 and applied to Originators, TPSPs, and TPS that transmitted more than 6 million ACH entries in 2023. Phase 2 was effective June 19, 2026 — practically June 22 given the federal holiday — and eliminated the volume threshold. Every non-consumer Originator, TPSP, and TPS now owns a documented risk-based fraud-detection process, regardless of volume. RDFI ACH-credit monitoring obligations landed alongside. The rule is written to the corporate originator, not the bank. A treasurer who assumes "our bank handles fraud monitoring" is misreading the rule. The 2026 posture is: document the process, staff it, evidence it on demand, and ask the TMS and payments-hub vendor what fraud-monitoring hook they expose to the originator's workflow. Nacha's Supplementing Fraud Detection Standards for WEB Debits — a separate, existing rule — sits alongside and applies to consumer B2C debits. Both should be on the compliance checklist.

Buyer-side. Supplier-paid. Buyers pay zero. Compensation has zero weight in the Cardinal Index scoring inside the Cardinal Method. Specific commercial terms live only in the private Decision Memo a buyer signs, never on this page.

The TMS and payments-hub mainline for $500M–$5B revenue: Kyriba, GTreasury, HighRadius, ION, Bottomline.

The mid-market TMS field is well-populated. Kyriba runs as a cloud TMS with a payments-hub module and launched its TAI agentic-AI capability in late 2025, positioning as pure-SaaS heritage. GTreasury is modern cloud-native with a unified data core across cash, payments, and risk. ION Treasury, which includes Reval, holds its historical strength in FX, derivatives, and hedge-accounting workflows and is the mainline choice when the treasury program is derivatives-heavy. HighRadius covers order-to-cash and treasury, publishes agentic-AI capability, and was recognized as a Leader in the IDC MarketScape 2025–2026 for AI-Enabled Treasury and Risk Management Applications. Bottomline PTX is U.S.-focused for payment automation and cash management. FIS extends treasury capability across a broader platform, and Coupa reaches into treasury from spend management. The 2026 selection question is not "who is the leader" — it is which vendor's bank-connectivity map, ERP fit, agentic-AI roadmap, and contract-term flexibility matches the specific corporate. Score each independently against those four axes.

ERP treasury integration is where treasury procurement quietly fails.

Every ERP with a finance module offers a treasury story. Oracle NetSuite is the mid-market cloud ERP leader for the 50–1,000 employee band and exposes SuiteTalk (SOAP and REST) plus SuiteScript as its integration surface. Sage Intacct's multi-entity consolidation strength makes it the default for companies with subsidiaries or restated books. Microsoft Dynamics 365 Finance carries the multi-currency and global posture Microsoft-standardized shops require. SAP S/4HANA Cloud sits on the enterprise side (1,000+ employees) with the Financial Closing Cockpit. Oracle Fusion Cloud Financials and Workday Financial Management round out the enterprise cloud set. The pattern that breaks in production is the same across ERPs: vendor demos show TMS-to-ERP integration working, and nightly reconciliation runs cleanly in staging. Production runs cleanly for months, and then breaks silently — a currency-mismatch, a bank-file format change, an ISO 20022 payload the ERP treasury module cannot parse. The 2026 procurement discipline is to score TMS-to-ERP integration on real testing against real bank files, not on demo footage.

Vendor-payment fraud is a required stack layer in 2026, not an add-on.

The vendor-account-validation and B2B payment-fraud category has consolidated to a small set of named vendors. Trustpair covers vendor account validation across 190+ countries with 500+ enterprise customers and is listed on Nacha's Preferred Partner page for account validation and fraud monitoring. nsKnox ships PaymentKnox as an in-network and out-of-network micro-payment validation suite. Eftsure covers bank-account verification. Trustmi covers B2B fraud detection. Bottomline SafeCash sits adjacent to the payments-hub and cash-management stack. Trustpair's 2026 fraud report — vendor-published research, attributed as such — cites that 71 percent of U.S. companies saw AI-powered fraud increase year over year. That growth rate is faster than most vendor-control release cycles, which is the argument for treating the layer as required rather than optional. The vendor stack covers vendor-payment fraud specifically; internal wire fraud (executive impersonation, business email compromise on the AP team) is a separate control set and is not solved by these vendors alone.

Instant payments are irrevocable — maker/checker and segregation of duties are non-negotiable.

RTP and FedNow sends cannot be recalled the way an ACH originator can attempt a reversal within the return window. A payments-hub workflow that lets a single user initiate and release a high-value instant payment is a control weakness that auditors, regulators, and insurers will flag in 2026. The correct posture is enforced maker/checker on high-value and instant-payment sends, segregation of duties between initiation and release, and an evidenced audit trail per transaction. The 2026 procurement implication: score the TMS and payments hub on how it implements maker/checker for instant payments specifically, not just on the ACH workflow the vendor has shipped for a decade.

What breaks: bank-does-it-all assumption, ISO 20022 truncation, theoretical integration.

"Our bank handles fraud monitoring." The Nacha rule is written to Originators, TPSPs, and TPS. The corporate treasurer owns the risk-based fraud-detection process, regardless of what the bank has in place. ISO 20022 payload truncation. Banks pass ISO 20022 upstream but strip enriched remittance data before delivering to the corporate's TMS. The corporate receives the same data it had under MT, and the migration's practical value disappears. Ask the bank explicitly. TMS-to-ERP integration is theoretical. Vendor demos show clean reconciliation; production runs for months, then breaks silently on a bank-file format change or a currency-conversion edge case. Score integration on real testing against real bank files. Vendor-payment fraud stack fills only the vendor-payment vector. Trustpair, nsKnox, Eftsure, and Trustmi cover the outbound-to-vendor risk. Executive-impersonation and internal wire fraud need separate controls. Instant-payment sends without maker/checker. RTP and FedNow are irrevocable; a single-user release path is an unacceptable posture in 2026.

What this means for procurement in 2026.

The 2026 mid-market treasurer's procurement implication is executable. First, run the rails-posture gap — which instant rails your primary bank supports on send and receive, which rails your TMS supports — before procuring anything else. Second, close the ISO 20022 conversation with the bank and confirm whether enriched remittance data is reaching the corporate end-to-end. Third, document the risk-based fraud-detection process required under Nacha Phase 2 and evidence the workflow inside the TMS or payments hub. Fourth, treat vendor-payment fraud as a required stack layer and score Trustpair, nsKnox, Eftsure, Trustmi, and Bottomline SafeCash against vendor-master hygiene and cross-border footprint. Fifth, enforce maker/checker and segregation of duties on high-value and instant-payment sends at the workflow level, not the policy level. The mid-market treasurer's job description changed twice in 24 months. The stack that reflects both changes looks different from the one signed in 2023.

This is the eighth and final piece in the Financial Services Analyst Note series. The anchor is How mid-market financial services operators should source technology contracts in 2026. Every vendor named here is in The Cardinal Source's active supplier pool.

Corporate treasury stack sourcing checklist (2026)

  1. Rails posture. Which instant-payment rails does your primary bank support (FedNow send, FedNow receive, RTP send, RTP receive)? Which does your TMS support? Gap this before procuring anything else.
  2. ISO 20022 posture. Ask your bank for its post-November-2025 CBPR+ position, whether you receive enriched remittance data end-to-end, and whether you are being charged contingency-processing fees on any legacy MT sends.
  3. Nacha fraud-monitoring compliance. As of June 22, 2026, if you are a non-consumer ACH originator you own a documented risk-based fraud-detection process. Document it, staff it, evidence it. Ask the TMS and payments-hub vendor for the fraud-monitoring hook they expose.
  4. TMS and payments-hub selection. Score Kyriba, GTreasury, HighRadius, ION Treasury, and Bottomline PTX independently on bank connectivity, ERP fit, agentic-AI roadmap, and contract-term flexibility.
  5. ERP treasury integration. Test TMS-to-ERP integration on real bank files against your NetSuite, Sage Intacct, Dynamics 365 Finance, SAP S/4HANA, Oracle Fusion, or Workday tenant. Do not accept demo footage as evidence.
  6. Vendor-payment fraud stack. Trustpair, nsKnox, Eftsure, Trustmi, Bottomline SafeCash. Pick against vendor-master hygiene, cross-border footprint, and integration path. Trustpair is a Nacha Preferred Partner.
  7. WEB debit account validation. For any B2C business receiving WEB debits, confirm compliance with Nacha's Supplementing Fraud Detection Standards for WEB Debits.
  8. Maker/checker enforcement. Enforce segregation of duties on high-value and instant-payment sends at the workflow level. RTP and FedNow are irrevocable.
  9. Vendor-risk consolidation modeling. Consolidating fraud tools plus TMS plus payments hub across fewer vendors reduces integration surface but increases lock-in. Model migration cost explicitly.
  10. Embedded finance evaluation. For companies operating a customer-facing payments or wallet product, add a separate BaaS and embedded-finance underwriting layer (see the sponsor-bank and middleware checklist in the prior piece in this series).

In short

  • Instant payments inflected in 2026: FedNow at 1,800+ FIs including 7 of the top 10 U.S. banks; RTP hit 2.27M transactions and $8.62B on May 1, 2026. Treasurers should now design for both.
  • SWIFT ended MT coexistence for cross-border payment instructions between FIs on November 22, 2025. Legacy MT sends incur contingency-processing fees from January 2026 and risk NAKed responses.
  • Nacha Fraud Monitoring Phase 1 was effective March 20, 2026; Phase 2 (all non-consumer originators regardless of volume) was effective June 19, 2026, practical June 22. The corporate treasurer owns the risk-based fraud-detection process.
  • TMS and payments-hub mainline: Kyriba, GTreasury, HighRadius. ION Treasury for hedge and FX-heavy programs. Bottomline PTX for U.S.-focused. Score independently — do not default to a single "leader" label.
  • Vendor-payment fraud stack — Trustpair, nsKnox, Eftsure, Trustmi, Bottomline SafeCash — is a required layer. Trustpair's 2026 report (vendor-published) cites 71 percent of U.S. companies with rising AI-powered fraud year over year.
  • Instant payments are irrevocable. Maker/checker and segregation of duties on high-value and instant-payment sends are non-negotiable 2026 controls.

Sources

  • Federal Reserve Financial Services, "FedNow Service — About." frbservices.org
  • Federal Reserve Financial Services, "FedNow Service Participants and Service Providers." frbservices.org
  • Federal Reserve Financial Services, "FedNow Service — Two Years of Growth and Innovation." frbservices.org
  • The Clearing House, "RTP — Real-Time Payments." theclearinghouse.org
  • The Clearing House, "RTP Network Marks May Day with Record-Breaking Volume and Value." theclearinghouse.org
  • The Clearing House, "RTP Q2 Value Surge." theclearinghouse.org
  • SWIFT, "ISO 20022 for Financial Institutions." swift.com
  • SWIFT, "End of Coexistence Guide" (PDF). swift.com
  • Nacha, "New Rules." nacha.org
  • Nacha, "Risk Management Topics — Fraud Monitoring Phase 1." nacha.org
  • Nacha, "Risk Management Topics — Fraud Monitoring Phase 2." nacha.org
  • Nacha, "Same Day ACH and Business-to-Business Payments Propel ACH Network Volume Growth in 2025." nacha.org
  • Nacha, "Supplementing Fraud Detection Standards for WEB Debits." nacha.org
  • Kyriba, Payments Hubs. kyriba.com
  • HighRadius, Treasury Management Software. highradius.com
  • Trustpair. trustpair.com
  • Nacha, Trustpair Preferred Partner listing. nacha.org

All linked sources were live at time of publish (July 2026). Verify before quoting in a procurement document.

Re-scoring your treasury stack in 2026?

Run the Tier 1 benchmark.

Submit your TMS or payments-hub contract, primary-bank service agreement, and the ERP treasury-module configuration. We return a benchmark PDF in five business days showing your instant-rails posture, ISO 20022 gap, Nacha Phase 2 compliance evidence chain, and where TMS-to-ERP integration is likely to break silently in production. Free. No follow-up sales drip.

Run the Tier 1 benchmark →