The hidden cost of delaying card-issuing modernisation
Jonathan Bautista, APAC Regional Solution Director at BPC, discuss how modular architecture and disciplined migration are reshaping how banks approve, launch, and scale card products.
Banks in the APAC region have spent years improving their digital channels. Customers can now open accounts remotely, move money through mobile apps, and manage much of their financial lives without visiting a branch. But whilst the customer experience has changed significantly, the card issuing platforms behind it have not always evolved at the same pace.
The gap becomes apparent when a customer expects to receive a virtual card immediately after approval, add it to a digital wallet, adjust spending controls, and receive a fraud alert in real time. These may look like simple customer experiences, but they depend on the issuing platform working in real time with multiple systems behind the scenes.
When that infrastructure relies on batch processing, siloed applications, or heavily customised integrations, even a seemingly simple product change can turn into a lengthy technology project.
This matters in a region where digital finance has moved firmly into the mainstream and customer expectations have changed with it. According to the World Bank’s Global Findex 2025, 86% of adults in East Asia and the Pacific own a smartphone, and 83% have a financial account. Across developing economies, 42% of adults made a digital merchant payment in 2024, up from 35% in 2021.
For card issuers, modernisation is therefore not simply an infrastructure upgrade. It affects how quickly the bank can launch modern digital-first products and innovative card programmes, how reliably it approves transactions, and how effectively it can compete for customers’ everyday spending.
The cost of legacy extends beyond technology
Legacy card systems can remain operational for years, which can make the business case for modernising them difficult to articulate. The platform continues to process transactions, and customers continue to use their cards, so the immediate need for change may not always be obvious. The real cost often appears elsewhere.
One area where this becomes visible is transaction authorisation. Avoidable false declines do more than frustrate customers. They also represent legitimate transactions and revenue that an issuer could have captured. BPC’s Modernisation Without Disruption guide illustrates this with a modelled mid-sized issuer processing 10 million debit transactions per month. At an avoidable false-decline rate of just 0.5 percentage points, 50,000 legitimate transactions could be unnecessarily declined. The resulting financial impact varies by market, as illustrated below, even before considering the wider effect on customer behaviour.

Operational teams bear another part of the cost. Staff may need to repair reversals, reconcile inconsistent records, release account holds, or investigate disputes across several disconnected systems. These processes consume time that could otherwise support product development and customer service.
The opportunity cost can be larger still. Issuers operating on rigid platforms may struggle to introduce virtual cards, tokenisation, flexible limits, multi-currency products, instalment options, or embedded card propositions at the speed expected by the market. The platform may still process today’s transactions, but it steadily makes tomorrow’s growth slower and more expensive.
Card issuing now sits inside the digital experience
A card is no longer just a physical payment instrument. It can be issued virtually, added to digital wallets, used through merchant applications, and embedded into a broader banking or commercial experience.
Payment-scheme developments show how quickly these requirements are changing. Mastercard, for example, has set a goal of achieving full tokenisation in Singapore, Malaysia, and Vietnam by 2027, as part of its wider move towards number-free and password-free online payments across Asia Pacific.
Supporting these experiences requires more than a new mobile interface. The issuing platform must manage card credentials, tokens, customer controls, authorisations, fraud decisions, and card lifecycle events across different channels. It must also connect easily with payment schemes, core banking systems, wallets, and other services without creating a new point-to-point integration every time the bank introduces something new.
This is where modern architecture makes a difference. Modular services allow individual capabilities to be changed without replacing the entire platform. Open APIs make it easier to connect channels and external services, whilst real-time data can support better authorisation and fraud decisions. Cloud and hybrid deployment options also give banks flexibility to scale based on business and regulatory requirements.
BPC has seen this take different forms across the region. At ACLEDA Bank in Cambodia, a phased transition to a modular setup unified issuing and acquiring, improved integration across channels, and enabled the bank to host other institutions through the Cambodia Shared Switch. Its card base has since grown to more than two million.
In Vietnam, PVcomBank moved from its legacy environment to a modular SmartVista stack with API connections between modules. The bank had issued more than 1.1 million cards and processes an average of seven million card transactions each month, whilst continuing to expand capabilities such as fraud management and 3D-Secure.
Modernisation also goes beyond issuing and acquiring. In Malaysia, Co-opbank Pertama (CBP) deployed SmartVista Fraud Management across its retail and corporate digital banking services. This introduced real-time monitoring, machine-learning-based analysis, and a consolidated view of fraud activity across customer touchpoints. Using historical fraud data can help banks improve detection, reduce false positives, and better distinguish suspicious activity from legitimate customer behaviour.
Migration risk sits in the details
BPC has completed more than 300 migrations over 30 years, including replacements of legacy platforms from ACI, Tieto, TSYS, OpenWay, HPS, Electra, and FIS. From BPC’s experience, the biggest migration risks are often in the details: data quality, tokens, BIN and scheme setup, integrations, reconciliation, and operational readiness. Choosing the right migration approach for the bank is equally important.
Some of the most common risks are shown below, from maintaining wallet continuity and selecting the right migration groups, to scheme setup, parallel processing, and post-go-live stability.

Managing these risks comes down to preparation and control. This includes having a complete token inventory, planning migration waves based on risk, aligning early with schemes and processors, reconciling results throughout the migration, defining clear rollback criteria, and closely monitoring the platform after go-live.
The safest migration model depends on the bank
After helping hundreds of customers migrate from legacy platforms , BPC has learned that there is no single safest route. The right model depends on the condition of the existing platform, the complexity of the portfolio, regulatory or scheme deadlines, operational risk, and the bank’s ability to run two environments during the transition.
A Big Bang migration moves the full scope during a tightly controlled cutover window. It can work well for a clearly defined portfolio or when the existing platform is approaching the end of support. But it requires well-prepared data, rehearsed procedures, and a clear fallback plan. Success depends as much on preparation and operational readiness as it does on the cutover itself.
A Conservative Pilot starts with a selected product, customer group, or business area. This allows the bank to see how the new platform performs with real transactions and gives operational teams time to become familiar with it before expanding the migration. The pilot, however, needs to be representative enough to identify real issues before the wider rollout.
A Parallel Run keeps the legacy and new platforms running together for a defined period. This allows teams to compare authorisation, reporting, and settlement results before the old platform is switched off. It provides additional validation, but running two environments also adds cost and complexity, so clear exit criteria are important.
A Phased or Box Migration moves the portfolio in controlled waves, for example by BIN, product, channel, or customer segment. For many SmartVista customers, this has provided a lower-risk route to modernisation. It allows parts of the legacy environment to be isolated whilst maintaining service continuity, and existing integrations and certifications can be reused whilst each migration box is tested independently.

BPC’s Modernisation Without Disruption guide looks at all four approaches in more detail, including where each approach works best, the risks to consider and the preparation required before migration begins.
The partner decision is a delivery decision
Financial institutions often compare modernisation partners by looking at platform functionality. Those capabilities are important, but a long list of features does not prove whether a provider can successfully migrate a live card business.
The real test is how the provider handles the migration itself: data conversion, payment-scheme certification, existing integrations, transaction testing, and post-go-live support. Financial institutions should also look at whether the provider has experience with similar card volumes, portfolio complexity, and deployment requirements.
Architecture and migration approach also need to work together. A modular platform can make phased migration easier, but the team still needs to understand how to manage the legacy environment and new environments during the transition, control the exchange of transactions and data, and make sure results are properly reconciled.
This approach was recently applied by BIDC in Cambodia, which replaced its legacy payment systems with BPC’s SmartVista platform. The modernisation brought issuing, acquiring, and EMV contactless capabilities onto a consolidated platform, providing a foundation for faster new product development and digital self-service.
Ultimately, the objective is not to replace technology simply because it is old. It is to remove the limitations that make it harder for the bank to approve legitimate transactions, introduce new products, and respond to changes in the payments market.
A legacy platform may still process today’s transactions. The more important question is whether it can support the card business the bank wants to build next.