Phlo Systems
Payments compliance

ISO 20022 migration as a fixed project — not an open-ended one

From 14 November 2026, payment files with unstructured addresses are rejected outright. We deliver the compliance work and the certified pain.001.001.09 bank interface at a fixed scope and a fixed price, with your bank's own test gates as the acceptance criteria.

The deadline, stated honestly

Only one part of your bank's letter has a hard date: structured or hybrid postal addresses in payment messages from 14 November 2026 — unstructured addresses are rejected, not repaired. The move to the newer file format mostly has no published deadline. We scope the two separately, and if the honest answer is that you need not spend anything yet, that is the answer you will get. Read the full explainer.

$100bn+

what analysts at Celent estimate banks have already spent on ISO 20022 — the scale of the change your bank's letter sits on top of

$20–30m

typical spend per bank on the November 2026 requirements alone — which is why banks pace the certification cycles, not vendors

44%

of banks report being behind on their own ISO 20022 readiness for November 2026 — certification queues lengthen as the date nears

For the corporate side there is no published cost benchmark at all — which is why we price this as a fixed, itemised project, and why we are compiling an anonymised benchmark from real corporate experiences. Read the cost breakdown and contribute your experience.

What the fixed scope covers

Structured-address compliance

Every payable and receivable counterparty address split into the bank-required structured fields, and your capture screens changed so new records are born compliant. This alone meets the 14 November 2026 rejection rule.

Certified payment files

pain.001.001.09 built to your bank's published implementation guide, per payment type you actually use — not the full menu. Validated test files through your bank's certification process, with the bank's test gates as the acceptance criteria.

Status messages handled

pain.002 acknowledgements and rejections from the bank posted back into your ledger, so a rejected payment is something your team sees the same morning — not when the supplier chases.

The secure channel

Host-to-host or API connectivity set up with your bank, certificates and registration included, tested on real payment runs before the old route is switched off.

How it runs

01

Scoping call — free

Thirty minutes. We read your bank's letter with you, separate what is mandatory in November from what is optional, count your payment types and counterparty records, and tell you plainly if the answer is 'you don't need to spend anything yet.'

02

Fixed quote, per payment type

A written scope priced by the payment types you actually use, with the split shown: what your team can do cheaper with our format guide (typically the address work), and what we deliver. A timeline anchored to your bank's certification calendar.

03

Build, certify, cut over

We build the files, run the bank's validation cycles, handle every test-round correction, and cut over only after live-run testing. You are invoiced against deliverables your bank has certified — not against effort.

Why the price holds

Payment-file projects overrun when they are priced by effort and the bank's test cycles keep finding deviations. We price by deliverable instead: the quote is per payment type, the acceptance criteria are your bank's own validated test files, and the test-round corrections are ours to absorb, not yours to fund. Where part of the work is cheaper done by your team — address cleansing against our format guide usually is — the scope says so and the price reflects it.

Phlo Systems builds and implements trading, treasury and payments software for commodity and trading businesses across the UK and Europe — payment files, bank connectivity and the ERP workflows that feed them.

Common questions

What happens on 14 November 2026?

Under Swift CBPR+ rules, payment messages carrying fully unstructured postal addresses are rejected outright — no contingency period. Town and country as discrete fields are the minimum. The file-format migration to pain.001.001.09 is a separate question and, for most corporates, has no published deadline.

Do we have to migrate to pain.001.001.09 now?

Usually not. Several banks have confirmed in writing that current formats stay acceptable after November 2026 provided addresses are structured. We will tell you if your situation is the exception — for example, corporates paying through German banks lose the DTAZV format in November 2026.

How long does it take?

Corporate-to-bank connectivity typically runs four to twelve weeks end to end because the bank paces the certification cycles. Our build sits inside that window; starting early is what buys the fast end of the range. Certification queues lengthen as November approaches.

Does this work with our ERP?

Yes — we deliver it embedded in an ERP implementation or standalone against the system you already run. The file is built to your bank's specification from your ERP's payment data, whatever produces it today.

Book the free scoping call

Send your bank's letter if you have one — we will come to the call with it already read and the mandatory parts separated from the optional ones. Sharing your migration experience for our anonymised cost benchmark instead? Use the same form and start your message with "benchmark" — a sentence or two is enough.