Payments operations at a corporate bank reads CPMI d224 and its surrounding briefs for very specific operational inputs: the SWIFT MX/CBPR+ readiness ladder, the address-quality regime, and the count and operator-mix of fast payment systems that the cross-border roadmap may eventually link to. Two AI failures on this regulation hit those operational inputs directly. Sonnet 4.6 manufactured a November 2026 structured-address cutover the d230 text does not contain, and Opus 4.7 returned a 57-FPS count that papers over the 70-plus operational systems and the 40%/35% central-bank/private operator mix from the CPMI Tara Rice November 2023 speech.
Lifted into an operations change-management ticket, a CBPR+ readiness memo or a cross-border-rail roadmap, either error displaces real work from the ops queue or misframes the size of the connectivity problem. The ops team's own change-control review will catch the mistakes only if there is a primary-source verification step in front of the AI draft.
What the AI got wrong, and why it matters here
Both errors land in the part of the workload where ops normally trusts a tight numerical or date-specific answer. Both are confidently delivered with no flag that the underlying primary text or speech transcript was not actually retrieved.
Finding 1: Fabricated November 2026 structured-address cutover
Sonnet 4.6 was asked what specific changes the February 2026 updated CPMI harmonised ISO 20022 data requirements made compared to the October 2023 original. It committed to a hard cutover: from November 2026 onwards only structured and hybrid addresses will be permitted in ISO 20022 cross-border payment messages. The d230 source text actually states only that the updated version takes into account standardisation and regulatory developments since 2023, provides clarification where market participants had sought further guidance, and sets out the updated and expanded data model in a separate technical annex.
The cutover date and the format-specific phase-out are not in d230. Quoted into an internal SWIFT migration steering update or a CBPR+ readiness memo, the line schedules real change-management capacity against a deadline the regulator did not document.
Citation: RLB-H-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q009-Sonnet46.
Finding 2: FPS count understated, operator mix dropped
Opus 4.7 was asked how many domestic fast payment systems are currently operational globally, how many have cross-border exchanges, and how many are operated by central banks versus private entities. It cited the 2025 monitoring survey as covering 57 (56 in one graph) fast payment systems, with no operator-type breakdown. The CPMI Tara Rice speech sp231115 (Nov 2023) gives 70-plus operational FPS, 14 already enabling cross-border exchanges, 24 planning linkages within five years, and a 40% central-bank / 35% private-entity operator split.
For a corporate-bank ops planner sizing FPS connectivity and integration complexity, the AI answer compresses the universe, hides the operator-mix signal, and drops the 24-systems planning-pipeline figure entirely.
Citation: RLB-H-INT-BIS-CPMI-API-HARMONISATION-CROSS-BORDER-2024-Q010-Opus47.
When this hits the ops calendar
Operations pulls CPMI material at three predictable points in the year: the SWIFT MX/CBPR+ migration steering update, the correspondent-network readiness refresh, and the cross-border-rail roadmap that the payments product team owns but operations costs.
| Standing item | Where the AI risk surfaces | Failure mode |
|---|---|---|
| SWIFT MX / CBPR+ migration steering update | Date assertions on ISO 20022 format cutovers | Finding 1 |
| Correspondent-network readiness refresh | ISO 20022 format change commitments and FPS connectivity sizing | Findings 1 and 2 |
| Cross-border-rail roadmap | FPS count, operator mix, planning-pipeline figure | Finding 2 |
Aggregate impact on the team
Both failures translate directly into wasted or misdirected operations capacity: change-management work for a cutover the regulator did not document, and connectivity roadmaps sized against the wrong global denominator.
| Risk Impact | Count | Affected findings |
|---|---|---|
| 0 |
What this team should do
Tag the November 2026 cutover assertion and the 57-FPS figure as known-failure outputs. Any AI draft that contains either must be sent back through a primary-source verification step (d230 text for the ISO 20022 line; sp231115 plus the CPMI brief series for the FPS counts) before it lands in a steering pack or a change-control ticket.
Detection patterns to add to AI-review
- Any AI output asserting an ISO 20022 cutover month or year against d230 must be verified against the d230 text, not a CBPR+ or SWIFT industry summary.
- Any FPS count must be cross-checked against the cited primary source (Tara Rice sp231115 for the 70-plus figure, CPMI monitoring survey for the operator mix).
How RLB can help
RLB maintains the failure-pattern catalogue on d224, d230 and the CPMI Tara Rice November 2023 speech, refreshed against live AI subjects on rotation. The ops team can wire the catalogue into the AI-draft review checkpoint, so these two failure shapes never reach the steering pack or the change-control queue.
