Home›Insights›Articles›Instant payments in Colombia: what integration demands

Blog · Integration · Payments

Instant payments in Colombia: what integration demands

Transfers in seconds, at any hour, using a mobile number instead of an account number. What that means for the integration layer at banks and payment operators, and what we're seeing in an ongoing project with the country's main interbank payments operator.

Bre-B: the turning point

On October 6, 2025, Bre-B went live: Colombia's interoperable instant payment system, run by the central bank, Banco de la República. Its design rests on two core pieces: a centralized key directory (DICE) that identifies each customer's account for receiving payments, and a settlement mechanism (MOL) that moves funds between the sending and receiving institutions. The system is available 24/7/365 and interconnects private low-value payment operators under common rules, preserving the investments each had already made.

Adoption has been rapid. According to Banco de la República, by January 2026 Bre-B had processed more than 370 million transactions worth about COP 59 trillion. By May 2026, according to figures reported by Infobae, the system had 34.9 million registered users, more than 105 million active keys and up to 5 million transactions a day, with payments completing in 6 to 8 seconds, well under the 20-second regulatory maximum.

A key can be a mobile number, an email address, a national ID number or another authorized identifier. When a transfer starts, the system validates the key, verifies the destination account and settles within seconds.

What instant payments demand from integration

Behind an eight-second transfer is a chain of systems that must talk to each other without failing: digital channels, core banking, fraud prevention, key directories, operators and settlement mechanisms. That chain imposes requirements many traditional integration architectures were never designed to meet:

  • Always-on availability. There's no overnight maintenance window and no weekend close.
  • End-to-end latency measured in seconds. Every hop between systems eats into a very tight time budget.
  • Zero message loss. A payment can never be lost or processed twice.
  • Perimeter security. Every participating institution is a connection point that must be authenticated and protected.
  • API governance. Versions, quotas, credentials and monitoring for dozens of different consumers.

A layered architecture with IBM Cloud Pak for Integration

IBM Cloud Pak for Integration brings together, on a container-native platform built for hybrid environments, the capabilities a real-time payments operation requires. In the project we're supporting, each component has a defined role:

  • IBM API Connect to create, secure, manage and publish the APIs participating banks consume.
  • IBM DataPower Gateway for end-to-end security and encryption at the transaction entry point.
  • IBM App Connect Enterprise to integrate systems and orchestrate clearing-flow logic.
  • IBM MQ for guaranteed, once-only message delivery that preserves the integrity of every transaction.

On that foundation, the project targets three pillars: controlled API exposure for participating banks, reliable real-time orchestration of clearing flows, and management of the key and alias domain under industry security guidelines.

In instant payments, integration stops being background plumbing and becomes the product. If it doesn't respond in seconds, there is no payment.
Automation & Integration team, Redsis

Five lessons for integrating real-time payments

1. Separate responsibilities by layer

API management, gateway security, orchestration and messaging solve different problems. Keeping them in separate layers makes it easier to scale each one to its load, isolate failures and change one piece without touching the rest.

2. Design for idempotency

In a distributed system, retries are inevitable. Every operation must be able to arrive more than once without creating a duplicate payment, and guaranteed-delivery messaging is the foundation for that.

3. Treat keys as critical data

In practice, a key is the door to an account. Registering, changing and looking up keys should follow strict security controls, with full traceability and protection against enumeration and fraud.

4. Measure your latency budget

If the standard requires completing a transaction in seconds, every component needs its own time target, visible in monitoring. That way any degradation is caught before it reaches the user.

5. Test like it's production

Mid-month and end-of-month paydays, tax-free shopping days and payroll dates generate loads far above average. Performance and resilience tests should reproduce those scenarios, including partial failures, before go-live.

A project in motion

The implementation with the operator is still underway, and we look forward to sharing measured results when it's complete. What's already clear is that instant payments have raised the bar for the entire industry: any institution that wants to take part in this ecosystem needs an integration layer designed for real time, security and always-on availability.

Where to start

If your institution is evaluating how to connect to the instant-payments ecosystem or how to modernize its integration layer, a good first step is an assessment of your current architecture: where time is lost, where single points of failure sit and how APIs are governed today. At Redsis, an IBM Platinum Partner, we combine more than 25 years of mission-critical platform experience in banking with integration solutions such as IBM Cloud Pak for Integration.

Read the full story

See how Colombia's main interbank payments operator is enabling instant, alias-based transfers with IBM Cloud Pak for Integration.

View success storyTalk to a specialist