- Spotlight
- Jul 15, 2026
Payments in Indonesia: From Entity to Activity-Based Regulation
Budi Gandasoebrata, Vice Chairman of the Indonesia Fintech Association, gives an interview to The Sumsuber about the transformation of Indonesia's payments sector under activity-based regulation.

Indonesia is entering a new phase in the evolution of its payments sector. Under Bank Indonesia's Blueprint Sistem Pembayaran Indonesia 2030 (BSPI 2030), the country is pursuing a more open, interoperable, and inclusive payments ecosystem, supported by initiatives such as BI-FAST, QRIS, SNAP, and the future digital rupiah. Indonesia's payments infrastructure market is projected to expand from USD 110.69 billion in 2025 to USD 294.85 billion by 2031, driven by rising adoption of mobile wallets and real-time payments.
Bank Indonesia's 2020 "umbrella" regulation (PBI No. 22/23/PBI/2020) introduced an activity- and risk-based approach to payment system oversight, marking a departure from the traditional entity-based model. More recently, BI Regulation 10/2025 has sought to operationalize that shift through a new licensing architecture, risk-based scoring framework, capital requirements, and differentiated oversight for Payment Service Providers. As the industry prepares for implementation, questions remain about how the new framework will affect innovation, competition, financial inclusion, and risk management across Indonesia's fast-growing digital payments ecosystem.
Today we’re sitting down with Budi Gandasoebrata, the Vice Chairman of the Indonesia Fintech Association (AFTECH / Asosiasi FinTech Indonesia), to discuss what’s in store for payments in Indonesia against the backdrop of the new regulatory framework.
THE SUMSUBER: Budi, Bank Indonesia began moving toward an activity- and-risk-based framework in 2020. Looking back, what gaps or limitations remained under that framework that BI Regulation 10/2025 is specifically designed to address?
BUDI GANDASOEBRATA: PBI 22/2020 laid an important foundation for transforming Indonesia’s payment ecosystem by introducing a more activity- and risk-based approach. However, over the past few years, the payments landscape has evolved much faster and become increasingly complex. Business models are now more integrated, interoperable, and supported by various partnerships involving banks, non-bank payment providers, digital platforms, and supporting service providers.
In that context, I see BI Regulation 10/2025 as a natural evolution. It operationalizes the principles of activity-based regulation through a more structured framework covering licensing, supervision, governance, and risk management, all proportionate to the activities being performed. In other words, regulation is no longer focused primarily on institutional form, but rather on the nature of the activities and the risks associated with them.
From the industry's perspective, this is a positive development. The next challenge is ensuring that implementation remains clear, consistent, and proportionate, so that it strengthens resilience without reducing room for responsible innovation.
THE SUMSUBER: Right, the implementation is always a separate story with its own underwater stones. How will it be for smaller providers?
Activity-based regulation is often presented as being more innovation-friendly, but the new framework also introduces stronger capital requirements, risk scoring, and the distinction between Primary and Non-Primary PSPs. Do you see a risk that smaller providers could face greater compliance burdens or consolidation pressure, and how does that align with BSPI 2030's financial inclusion objectives?
BUDI GANDASOEBRATA: Any regulatory transition naturally requires adjustments from the industry. Capital requirements, risk assessments, and differentiated supervision are intended to strengthen resilience and maintain trust in the payment system. However, it is important that proportionality remains at the heart of implementation.
Indonesia’s payments ecosystem consists of players with diverse scales, business models, and risk profiles. In that sense, activity-based regulation creates an opportunity to apply supervision more aligned with each provider’s risk exposure, rather than adopting a one-size-fits-all approach.
I believe this is also important in supporting the financial inclusion objectives under BSPI 2030. Many smaller and specialized providers play a significant role in serving underserved communities and SMEs. Therefore, strengthening governance and resilience should go hand in hand with preserving space for innovation, specialization, and inclusive growth.
THE SUMSUBER: 100%. Right now, Indonesia's payments ecosystem is becoming increasingly interconnected through BI-FAST, QRIS, SNAP, embedded finance, and super-app platforms.
Does the new framework provide sufficient flexibility for these converging business models, or are there areas where regulatory boundaries remain unclear?
BUDI GANDASOEBRATA: I believe the activity-based approach is well-suited to address the convergence of business models that is taking place across the ecosystem. Traditional boundaries between banks, fintech companies, digital platforms, and supporting service providers are becoming increasingly blurred. The focus is no longer on who the provider is, but rather on what activities are being performed and what risks those activities pose.
Going forward, the challenge may not be distinguishing whether a service is offered by a bank, a fintech company, or a platform, but making sure that accountability remains clear when a single customer journey involves multiple parties. Issues such as data responsibility, fraud management, consumer protection, and operational resilience require increasingly close coordination.
Therefore, I believe the current framework provides a strong foundation. However, continued dialogue among Bank Indonesia, industry associations, and market participants will remain essential, so that regulatory interpretation evolves in step with increasingly dynamic business models.
THE SUMSUBER: That’s valuable feedback. What about the bigger picture? Let’s expand the geography a bit. Southeast Asia appears to be converging toward activity-based regulation, with jurisdictions such as Singapore adopting similar approaches. Does that regulatory convergence make cross-border payment connectivity easier to achieve, or does it create new challenges for Indonesian providers operating across markets?
BUDI GANDASOEBRATA: I see regulatory convergence as a positive development, because it creates a more common language around risk management, governance, consumer protection, and operational resilience. Singapore is a useful reference point in this regard. Its Payment Services Act has applied an activity-based approach since 2020, bringing both traditional payments and digital payment token services under a single framework, so the region already has a more mature example to learn from as Indonesia operationalizes its own model.
This alignment becomes increasingly relevant as regional payment connectivity continues to expand across ASEAN, and we can already see it in practice. The cross-border QR linkage between QRIS and Singapore's NETS, launched by Bank Indonesia and the Monetary Authority of Singapore, already allows customers and merchants in both countries to transact using their existing applications. Greater alignment in regulatory approaches should help providers build capabilities that can be applied more consistently across jurisdictions, which ultimately supports interoperability and strengthens trust in cross-border transactions.
That said, convergence does not mean uniformity. Each jurisdiction will continue to have its own institutional architecture, licensing requirements, and supervisory expectations. In Indonesia, for instance, payment system oversight sits with Bank Indonesia while digital financial assets fall under the Financial Services Authority, so providers operating regionally need to navigate these differences thoughtfully. For that reason, I believe the industry should view compliance not merely as a local obligation, but as a strategic capability that enables sustainable participation in a more interconnected regional ecosystem.
THE SUMSUBER: …which is also important for fraud prevention, right? Let’s touch on fraud in the country.
Indonesia ranked #2 globally for fraud vulnerability in 2025. It recorded more than 300,000 fraud reports and roughly Rp7.9 trillion (about USD 474 million) in losses in the year to November 2025, with over 500,000 bank accounts frozen as suspected mule accounts, and only a low single-digit share of stolen funds recovered. Much of that activity moves across channels, with mule networks layering funds through e-money, bank transfers, and merchant acquiring to stay below detection thresholds.
Does tying regulatory obligations more closely to specific activities and risks help close those cross-channel gaps, or does it mainly redistribute accountability among providers without materially improving detection and recovery?
BUDI GANDASOEBRATA: Be it Indonesia or Southeast Asia in general—fraud today no longer occurs within a single channel or institution. Its patterns have become increasingly sophisticated and can span accounts, platforms, and payment services. In this regard, activity-based regulation is key, as it clarifies accountability and encourages risk management practices to be more closely aligned with each participant's activities.
However, effectiveness does not depend solely on allocating responsibilities. It requires stronger coordination, better information sharing, and faster response mechanisms across the entire ecosystem. A good example is the Indonesia Anti-Scam Centre, established by the Financial Services Authority together with the Satgas PASTI task force and supported by the banking and payment industry. Bringing providers, regulators, and authorities into a single coordination forum allows suspicious transactions to be delayed and related accounts to be frozen far more quickly than any single institution could manage on its own. This is precisely the kind of collective, cross-institutional response that today's fraud environment demands.
At the same time, we should be honest that work remains, particularly in improving how quickly funds can be traced and recovered once they have moved across channels. That is why I see the value of activity-based regulation not just in assigning clearer responsibilities, but in encouraging more collaborative, data-driven, and risk-based approaches to managing increasingly real-time transaction environments. At the end of the day, strengthening this kind of coordination is what will make the system more resilient as transaction volumes and speed continue to grow.
THE SUMSUBER: With implementation underway and compliance timelines now in place, what is the single requirement or adjustment that payment providers are most likely to underestimate over the next three years, and what should the industry focus on today to avoid problems later?
BUDI GANDASOEBRATA: In my view, the most underestimated adjustment will be the shift in mindset that compliance is no longer merely a supporting function or a documentation exercise. In an increasingly real-time, interconnected, and activity-based ecosystem, compliance ultimately becomes an operational capability that must function continuously.
Many players may focus primarily on formal requirements such as licensing, capital, and reporting. Yet the bigger challenge lies in strengthening governance, integrating risk management, building data readiness, enhancing operational resilience, and demonstrating that internal controls are truly aligned with the activities and risks being undertaken.
Going forward, the most successful providers will be those that view compliance not as a cost center, but as a foundation of trust. Ultimately, trust is the prerequisite for scale, sustainable innovation, and a healthy and inclusive digital economy.
Relevant articles
- spotlight
- May 27, 2026
Take a peek into what a real investigation into scam compounds looks like, with Erin West, investigator and founder of Operation Shamrock.

- spotlight
- 1 week ago

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.


