
Mark Donohue, Managing Director iSky, Global
Our Q3 2026 commercial banking and merchant services analysis of digital trends and innovations shows convergence around a bigger job for financial institutions: helping businesses operate, protect and grow through one connected experience.
The most revealing developments in commercial financial services are not isolated feature launches. They point to a broader shift: providers are moving beyond balances and payments to support more of the work around them.
Business customers do not experience banking as a standalone task. Payments begin with invoices; growth brings new users, approvals and risks; cash flow shapes everyday decisions. Connecting those moments can reduce administration and make the financial relationship more useful.
Across new experiences observed via RFI Global’s iSky Radar platform of selected global providers in the four months to August 2026, five shifts stand out.
The strongest security experiences appear when a decision is being made and make the safer action clear.
Truist and PayPal have added passkey options, reducing reliance on password entry after enrolment and supporting device-based authentication. Suncorp now uses Confirmation of Payee when customers add a recipient, showing whether the entered name is a match, close match or no match before a payment proceeds.
Other providers add visible friction at higher-risk moments. ANZ warns customers about scams when they increase a Pay Anyone limit. Commonwealth Bank requires corporate users to acknowledge guidance about WhatsApp impersonation scams before entering the authenticated channel. Airwallex’s configurable transfer-approval workflows include amount ranges, approval layers and controls that can prevent people approving their own submissions.
The emerging model combines simpler authentication with stronger intervention and accountability at higher-risk moments.
The opportunity for financial institutions is removing effort before a payment and uncertainty after it.
Novo now lets customers upload an invoice or bill and automatically populates the payment details. The reduced rekeying is valuable, but customers still need to verify extracted details before submitting a payment. SumUp creates invoices from sales history and reports using successful transaction data, while Airwallex has added “incomplete” and “blocked” payment statuses.
CIBC’s communication and status-centre work addresses the need after an action, helping customers track requests that are not completed immediately rather than call or visit a branch for updates.
Together, these changes point to a richer payments UX: capture the source information, reduce rekeying, show the transaction’s state and make the next action obvious.
Payment providers increasingly help merchants sell, not simply accept money.
Airwallex has introduced usage-based billing that can meter consumption by token, gigabyte, API call or usage tier. Stripe’s merchant-of-record solution supports digital products while handling indirect-tax compliance across more than 80 countries, alongside fraud, disputes and transaction-level support.
SumUp has expanded web access to QR ordering and gift-card management. Revolut lets merchants with an active Revolut Pay integration create campaigns charged against sales rather than views, while PayPal has added an Ads Manager waitlist.
These moves place payments inside a broader loop: configure an offer, reach a customer, complete the sale, collect the funds and understand the result. The closer those activities become, the harder it is to separate merchant acquiring from business software.
Business banking platforms are also moving into the everyday account administration.
Starling now combines invoicing and automatic payment matching with accounting tasks, transaction categorisation and core financial reports. VAT tools are available through its paid Accounting Plus tier.
Revolut supports automatic money-movement rules, an income sorter, supplier management, configurable expense fields and mileage claims. Chase has added customer insights alongside cash-flow views, while HSBC has introduced mobile spending and cash-flow analysis for business current accounts.
The common thread is action. Data becomes more valuable when it helps a business decide what to do next, automate routine work or complete an adjacent task without leaving the platform.
AI assistants remain visible, including Bluevine’s public-web assistant and RBC’s optional cybersecurity summaries. Stripe illustrates a more consequential, and more contested, next step: operational access. Stripe now lets businesses create restricted credentials for AI agents and connect those agents to selected APIs, documentation and support content. The experience explicitly directs merchants never to share a secret key with an agent. These remain contested use cases rather than inevitable next steps.
The implication is a governance test for every commercial platform. Useful AI must be permissioned, observable and proportionate; convenience without boundaries will not be enough.
Our analysis this quarter also includes product closures, channel removals and support-page consolidation. These are cautionary examples: progress can be offset when a familiar control disappears, or a migration leaves gaps in the journey.
The practical test is simple. Does a change help a business complete a meaningful job, reduce repeat work, understand its position or control risk? Does it make the wider journey more coherent?
The next phase of development should not be defined by the longest feature list, but by how much of a customer’s day the platform makes simpler, safer and more connected. The strategic opportunity for institutions is to move beyond managing transactions and become an integral part of how businesses operate, protect themselves and grow.
As financial institutions expand from managing transactions to supporting business operations, understanding where the market is moving is increasingly important. Get in touch for further insights from RFI Global’s iSky Radar platform.

Mark Donohue
Managing Director iSky, Global
Mark Donohue is Managing Director of iSky at RFI Global, working with clients globally on data-led financial services intelligence.
View full profileFinancial institutions are moving beyond managing balances and payments to supporting the wider work around them – invoicing, approvals, cash flow and risk. RFI Global’s analysis of digital experiences via its iSky Radar platform, covering selected global providers in the four months to August 2026, identifies five converging shifts: smarter security, payments-as-workflows, merchant growth tools, the account as an operating layer, and an emerging governance test around AI agents.
By combining simpler everyday authentication with stronger checks at the moment risk actually rises. Truist and PayPal have introduced passkeys to reduce reliance on passwords, while ANZ and Commonwealth Bank add warnings or acknowledgements specifically when customers raise payment limits or use higher-risk channels. The pattern across providers is ease at low-risk moments, friction at high-risk ones.
Confirmation of Payee checks whether the name on a new payment recipient matches, closely matches, or does not match the account being paid, before the payment is sent. Suncorp has introduced this at the point a customer adds a new payee, giving them a clear signal to stop, check or proceed before money moves.
Cautiously, and with explicit boundaries. Stripe now lets businesses issue restricted credentials so AI agents can access selected APIs and support content, while directing merchants never to share a secret key with an agent. The analysis frames this as a governance test for the industry: useful AI access has to be permissioned, observable and proportionate rather than open-ended
| Cookie | Duration | Description |
|---|---|---|
| __cf_bm | 1 hour | This cookie, set by Cloudflare, is used to support Cloudflare Bot Management. |
| __hssc | 1 hour | HubSpot sets this cookie to keep track of sessions and to determine if HubSpot should increment the session number and timestamps in the __hstc cookie. |
| __hssrc | session | This cookie is set by Hubspot whenever it changes the session cookie. The __hssrc cookie set to 1 indicates that the user has restarted the browser, and if the cookie does not exist, it is assumed to be a new session. |
| AWSALBCORS | 7 days | Amazon Web Services set this cookie for load balancing. |
| AWSALBTG | 7 days | Amazon Web Services set this cookie for load balancing. |
| AWSALBTGCORS | 7 days | Amazon Web Services set this cookie for load balancing. |
| cookielawinfo-checkbox-advertisement | 1 year | Set by the GDPR Cookie Consent plugin, this cookie records the user consent for the cookies in the "Advertisement" category. |
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| CookieLawInfoConsent | 1 year | CookieYes sets this cookie to record the default button state of the corresponding category and the status of CCPA. It works only in coordination with the primary cookie. |
| elementor | never | The website's WordPress theme uses this cookie. It allows the website owner to implement or change the website's content in real-time. |
| rc::a | never | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| rc::c | session | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
| wpEmojiSettingsSupports | session | WordPress sets this cookie when a user interacts with emojis on a WordPress site. It helps determine if the user's browser can display emojis properly. |
| XSRF-TOKEN | 2 hours | This cookie enhances visitor browsing security by preventing cross-site request forgery. |
| Cookie | Duration | Description |
|---|---|---|
| AWSALB | 7 days | AWSALB is an application load balancer cookie set by Amazon Web Services to map the session to the target. |
| AWSALBTG | 7 days | Amazon Web Services set this cookie for load balancing. |
| AWSALBTGCORS | 7 days | Amazon Web Services set this cookie for load balancing. |
| Cookie | Duration | Description |
|---|---|---|
| __hstc | 6 months | Hubspot set this main cookie for tracking visitors. It contains the domain, initial timestamp (first visit), last timestamp (last visit), current timestamp (this visit), and session number (increments for each subsequent session). |
| _ga | 1 year 1 month 4 days | Google Analytics sets this cookie to calculate visitor, session and campaign data and track site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors. |
| _ga_* | 1 year 1 month 4 days | Google Analytics sets this cookie to store and count page views. |
| hubspotutk | 6 months | HubSpot sets this cookie to keep track of the visitors to the website. This cookie is passed to HubSpot on form submission and used when deduplicating contacts. |
| wmc | 1 year 1 month 4 days | Workable sets this cookie to assign a unique visitor ID for statistical purposes. |
| Cookie | Duration | Description |
|---|---|---|
| _cfuvid | session | Description is currently not available. |