Home›Insights›Articles›Mobile credit card origination: speed without compromising PCI DSS

Blog · Secure file transfer · Banking

Mobile credit card origination: speed without compromising PCI DSS

The customer is standing in front of your associate, ready to buy. You have five minutes. What we learned helping Colombia's second-largest credit card issuer approve cards from a mobile device, in fewer than 5 steps and without opening security gaps.

A market of millions of cards and competition at every register

At the end of 2024, Colombia had about 16.6 million credit cards, roughly 14.5 million of them in active use, and the financial system was issuing an average of almost 209,000 new cards a month, according to Financial Superintendency data reported by La República. In a market like that, issuers increasingly win or lose on the application experience: how many steps, how many minutes and how much friction.

At the same time, the industry's security bar keeps rising. PCI DSS 4.0, published by the PCI Security Standards Council, expanded requirements for authentication, monitoring and data protection, and its future-dated requirements became mandatory in March 2025. Speeding up origination without designing for PCI DSS is a fast way to create a compliance problem.

Shortcuts worth avoiding

When commercial pressure says "go digital now," improvised solutions tend to show up:

  • Photos of documents over messaging apps. Fast for the associate, but with no controlled encryption and no trace of where the images end up.
  • Standalone web forms. They capture data, but someone still has to re-key it into the credit system, errors included.
  • Manual credit bureau checks. The underwriter looks it up, copies the result and decides: minutes the customer isn't always willing to wait.
  • Custom apps with months of development. By the time they reach production, the campaign is over.

Secure forms that trigger workflows: the GoAnywhere approach

Fortra's GoAnywhere MFT is best known as a secure file transfer platform, but its collaboration modules also cover data capture. Secure Forms publishes customizable web forms (text fields, dropdowns, checkboxes and file uploads) over HTTPS, restricted to authenticated users or exposed through a public URL, with multi-language support.

What sets it apart from an ordinary form is what happens after the user taps "submit":

  • An automated workflow fires (an Advanced Workflows Project) to validate, transform and route the data.
  • Files are encrypted with AES-256 in transit and at rest, with controls on allowed file types, sizes and counts.
  • The workflow can return a response or a file to the user, closing the loop in the same session.
  • Every submission is logged with date, user and responses, ready for audit.

For the bank, Redsis took Secure Forms to mobile devices and connected the workflow to the credit bureaus. The build was designed in 5 days.

In origination, security can't be an extra step. It has to live inside the same workflow that produces the answer.
Automation & Integration team, Redsis

Five lessons for originating cards on mobile

1. Design for the aisle, not the desk

A mobile-first process has few fields per screen, reuses what you already know about the customer and doesn't ask for documents you can verify online. The bank's target of fewer than 5 steps is a good benchmark for any issuer.

2. Build the credit check into the workflow

Most of an approval's elapsed time is spent waiting for information. If the workflow that receives the application queries the credit bureaus automatically, the decision can happen in minutes instead of hours.

3. Treat PCI DSS as a design requirement

Deciding up front which data you capture, where it's stored, who can access it and how it's encrypted shrinks your compliance scope and avoids a rebuild later. A channel that encrypts by default and logs every submission does much of the heavy lifting.

4. Favor a platform over custom code

Building on a platform that already handles encryption, authentication, auditing and orchestration lets you focus effort on business logic. That's why a build like this one can be designed in days rather than months.

5. Plan for scale from version one

A successful campaign can multiply applications overnight. The architecture has to absorb peaks without slowing responses, and operations needs real-time visibility into volume.

The result: approval in minutes and more cardholders

Today credit card approval for employees and customers is 80% faster, runs from a mobile device and returns an answer in under 5 minutes. The bank approves more than 500 cards a day, has seen a 35% increase in credit card users and maintains 100% PCI DSS compliance on a highly scalable solution.

For an issuer that competes for every customer at the point of sale, that means something very concrete: the card gets approved while the customer is still there, and security isn't traded away to make it happen.

Where to start

If your institution still approves cards with paper forms, messaging-app photos or manual credit bureau checks, it's worth mapping the full application journey and measuring how many steps and minutes you can remove. At Redsis we combine more than 25 years of mission-critical platform experience in banking with Fortra automation and integration solutions such as GoAnywhere MFT and JAMS.

Read the full story

See how Colombia's second-largest credit card issuer approves cards from mobile devices with GoAnywhere Secure Forms.

View success storyTalk to a specialist