Why Compliance Gets Harder as Money Becomes Programmable
Idalith Bustos
July 31, 2026 · 5 min read
Payment infrastructure has changed dramatically over the past decade. The controls governing it haven't evolved at the same pace.
For most modern finance, people decided when money moved, and that assumption shaped everything from approval workflows to audits and compliance reviews. Today, software is participating in those decisions through automated treasury systems, embedded payment workflows, stablecoin infrastructure, and AI. But not all of these systems operate the same way.
Traditional automation follows predefined business rules. AI systems can evaluate options, recommend actions, and, in some cases, complete financial tasks with limited human involvement under human-defined constraints. That distinction matters because governing delegated financial decision-making is fundamentally different from the governing software itself.
As organizations hand off more operational decisions to software, technical capability alone is no longer enough. The National Institute of Standards and Technology's Artificial Intelligence Risk Management Framework (AI RMF 1.0) recommends pairing technical capability with governance structures, accountability, and appropriate human oversight rather than solely relying on model performance. That recommendation extends naturally to financial operations as software gains more authority over payment decisions.
The same patterns appear in payment infrastructure. In The Financial Stability Implications of Tokenisation, the Financial Stability Board notes that tokenized financial systems introduce new operational, governance, and risk management considerations that cannot be addressed through settlement technology alone. Likewise, the International Monetary Fund argues that programmability changes the way payments can be initiated, coordinated, and executed within broader financial workflows.
More capable software doesn't reduce the need for oversight; in fact, it makes it even more important. As financial systems become more software-driven, organizations are moving policy enforcement to the point where payment decisions are made rather than relying primarily on reviews after the transaction has already happened.
Programmable Payments Expand the Governance Surface
Payment systems are no longer restricted to banking applications or manual approval processes. Across both traditional financial infrastructure and blockchain networks, payments are becoming integral to software workflows.
APIs embed payment capabilities into enterprise applications, treasury platforms automate liquidity management, embedded finance integrates payments into business software, and stablecoins enable continuous settlement across blockchain networks.
The International Monetary Fund describes this trend as programmability in payment and settlement, where payment infrastructure supports programmatic interaction and automated execution within larger operational workflows. With more payments becoming more tightly integrated with software, teams must govern not only how money moves, but also how payment decisions are made.
This also changes the role of compliance.
Historically, compliance focused on transactions after they happened. However, payment infrastructure is becoming more automated, so organizations also need to determine whether an application, workflow, or AI system was authorized to make a payment before it is executed.
Instead of focusing only on completed transactions, organizations are now beginning to consider the conditions under which payments are made. That includes delegated authority, organizational policy, transaction context, approved counterparties, identity verification, regulatory requirements, and required approvals before execution.
Governance Is Becoming Part of Payment Infrastructure
This shift in governance extends beyond payments.
Cloud platforms evaluate identity and access policies before granting access to infrastructure. Modern software development integrates security throughout the development lifecycle instead of relying mainly on end-of-cycle testing. Financial infrastructure is beginning to follow the same pattern by embedding governance into transaction execution rather than relying primarily on review after settlement.
The National Institute of Standards and Technology's Cybersecurity Framework (CSF) 2.0 places governance alongside the technical functions needed to manage cybersecurity risk. That same idea is beginning to shape payment infrastructure. Reviews after settlement still matter, but many organizations are moving approvals, permissions, and policy checks closer to the point where money actually moves.
This is changing what organizations expect from payment infrastructure. Accurate transaction data is still essential for reconciliation, reporting, and audit. It doesn't answer a different question, though: Was this application allowed to make the payment in the first place?
Finance teams can't reconcile payments using data they don't trust, and they can't enforce policy after funds have already moved. As financial infrastructure becomes more automated, governance can't be an afterthought, but rather, it has to be built into the system itself.
Amp and ampersend are built for exactly this shift. Amp provides verifiable blockchain transaction data for reconciliation, reporting, and audit, giving finance teams confidence in the integrity of the records they rely on. Ampersend operates further upstream by evaluating payment requests against organizational policy before execution, enforcing approvals and permissions before money moves rather than after.
As software takes on more responsibility for financial operations, organizations that pair observability with governance will be better positioned to scale automation without sacrificing control.