BSP Circular 1223 orders ISO 20022 for all retail payment systems — one use-case in year one, full compliance in two — and defines full compliance as the phase-out of message translators. The regulator's own finding: implementations were inconsistent. Every institution now has to prove its mappings are right, not merely that messages flow.
Here is the demonstration we open every engagement with: corrupt one byte inside a packed-decimal amount in the extract. The resulting message is perfectly schema-valid — every validator passes it — and the amount is wrong. The only thing that catches it is the control-total chain: trailer counts and sums, carried from the extract, reconciled against the message's own CtrlSum. Message-side tools can't run that check because they never see your bytes. We start from the bytes.
| Capability | Message-side tools | CobolStack |
|---|---|---|
| Validate XML against schema and usage guidelines | yes | yes — differentially tested against an independent validator, 104 cases, zero disagreements |
| Ingest the legacy side (copybooks, IBM i DSPFFD catalogs, EBCDIC/packed extracts) | — | yes |
| Field-level equivalence, bytes → message and back | — | yes |
| Completeness proof (control totals vs CtrlSum) | — | yes |
| Findings citing the circular's own sections | — | yes — every Tier-2 finding carries its citation |
| Rehearse a full cycle against a synthetic core before cutover | — | yes — the bench |
Adopt ISO 20022 across retail payment rails on the regulator's timetable, demonstrate at least one use-case in year one, and file recurring conformance-testing results. Full compliance means the translators come out.
A mapping that validates but mis-states amounts or references is a settlement and audit exposure, not an IT bug. The regulator's stated reason for the mandate is that implementations were inconsistent — supervision will look where the inconsistency was.
An evidence file: every finding tied to a section of the circular, every number reproducible, inputs fingerprinted. Filed once per assessment, re-run per rulebook year. Your team's effort: artifact capture measured in hours, run by your own staff.
The pipeline, in your terms: we ingest the record layout (COBOL copybook parsed to field offsets/types/scales, or the DSPFFD listing straight off an IBM i) and the raw extract bytes. Amounts decode via exact decimal arithmetic — a float never touches money. The mapping executes field-by-field into the target message; the result is validated against the XSD (our validator is differentially tested against an independent engine — 104 cases, zero disagreements) and then against the circular-derived rule pack, where every rule carries its citation. Equivalence runs the mapping in reverse and diffs. Completeness reconciles your control trailer — counts and per-type totals — against the message's CtrlSum chain. Output: HTML/PDF/JSON, deterministic (two runs on the same inputs are byte-identical), inputs sha256-pinned, fully offline — suitable for an air-gapped review. Exit codes are honest: conformant, findings, or input error. Nothing phones home.
A synthetic payments core generates authentic fixed-format traffic — dirty sign nibbles, truncations, charset violations included — and your mapping runs against full cycles before cutover. The translator phase-out forces every participant through exactly this motion; the bench is how you get there without betting the rail. Annual rulebook updates become annual re-certification runs.
One command, fully offline; the report is a self-contained file you can archive or hand to audit. Version-pinned inputs, sha256 throughout.
The institutions the big-vendor stacks skip: thrift and rural banks, EMIs, remittance companies — all inside the circular's scope, none with a Volante budget. IBM i estates are explicitly welcome: layouts come straight off the machine's own catalog (DSPFFD), no copybook archaeology.
Assessment findings cite regulations; they do not imply regulator endorsement. Translation generation is engagement-gated — see capability & roadmap.
Training your payments team for this? CS310 — ISO 20022 for Payments Teams is the course built on this toolkit.