ISO 20022
ISO 20022 is an open global standard for exchanging financial information electronically between financial institutions. It defines a consistent, structured way to carry richer data across payments and other financial activities. The goal is to make financial messages more detailed and uniform than older messaging formats.
ISO 20022 is a multi-part International Standard prepared by ISO Technical Committee TC68 (Financial Services) that establishes a common platform for developing financial messages and describes a metadata repository containing descriptions of message components. It provides consistent, structured data intended for electronic data interchange between financial institutions across business areas including payments, securities, trade services, cards, and foreign exchange. It is implemented in modern payment infrastructures; for example, the FedNow Service uses the ISO 20022 messaging standard. Note that ISO 20022 governs financial messaging and is separate from the PCI standards; whether and how ISO 20022 messages carry cardholder data has implications that depend on implementation and must be assessed against the applicable PCI DSS requirements.
Why it matters
ISO 20022 matters because it establishes a common, structured foundation for exchanging financial information across institutions and business areas, including payments, securities, trade services, cards, and foreign exchange. Older messaging formats often carried limited or inconsistently structured data, which complicated automation, reconciliation, and analysis. By providing consistent, rich, and structured data, ISO 20022 is intended to make financial messages more detailed and uniform, which can help institutions process transactions and interpret message content more reliably.
For security and compliance teams, the significance lies in how the standard is implemented rather than in the standard itself. ISO 20022 governs financial messaging and is separate from the PCI standards. Whether and how a given ISO 20022 implementation carries cardholder data has direct implications for PCI DSS scope, and those implications depend on the specific implementation. Richer, more structured message data can be an operational advantage, but it also means teams must understand exactly what data fields are populated and transmitted so that any cardholder data is handled under appropriate controls.
The standard is used in modern payment infrastructures; for example, the FedNow Service uses the ISO 20022 messaging standard. As such implementations expand across business areas, organizations that interact with these systems should assess how message content maps to their existing data-handling and compliance obligations rather than assuming a messaging-format change is compliance-neutral.
Who it's relevant to
Inside ISO 20022
Common questions
Answers to the questions practitioners most commonly ask about ISO 20022.