Colombia

Bogota Headquarters

93rd Street #16-46, Office 404, Zenn Office PH Building
Medellin
Cra 43rd No. 7-50, Office 1102 - Dann Carlton Business Center
Cali
Cra 100B #11A -19 Office 516 Pance Tower

Espain

Madrid

Calle Conde de peñalver, 45, entre planta oficina 2, 28006, Madrid

USA

Miami-Florida

1000 Brickell Av, PMB 5137

Mexico

Mexico DF

Av. Rio Misisipi 49 Int. 1402, Cuauhtémoc

Panama

City of Panama

Calle 50, edificio, torre BMW, San Francisco

We Warned You in Our Webinar, and Bre-B Confirmed It

There is no way to guarantee that a participant in an interoperable payment ecosystem will never fail again; that exceeds what any single institution can control.

See more articles

Autonomous AI Agents Making Purchases: Who Is Liable When They Fail?

Applying agentic AI to payments requires the exact same level of rigor as any system handling third-party funds—extended to a type of actor that did not exist two years ago: one that decides and executes, rather than merely recommends.

680 customers exposed without a single line of code being breached

The same neobank that just received its full banking license in Colombia confirmed, three days earlier, a data breach that didn’t involve a single hacked server.

Everyone’s selling AI as a way to go faster. Science says almost no one has succeeded

The institution that takes this scenario seriously and builds the discipline of measurement, governance, and continuous testing necessary to respond to it with evidence will not only avoid the error that science has already documented.

AI agents are already operating within Mexican banking. Who holds the accountability?

Mexican banks and insurers already have artificial intelligence agents with active permissions inside their systems; however, adoption is outpacing the corporate governance meant to control it.

Panama Bets Big on Full Interoperability: What Comes After Yappy, Kuara, Nequi, and Zinli

On September 10th, Q-Vision Technologies will host a session to discuss key developments in instant payments across Latin America and how Panama can get ahead as it prepares for full interoperability.

Key Business Takeaways on AI from Inbound Summit 2026

This article translates high-level concepts into concrete business decisions—backed by verifiable data and real case studies from Postobón, Puntos Colombia, The New York Times / The Athletic, and Tienda Nube.

Between September 30 and October 1, Daviplata experienced low approval rates followed by a complete outage within the Bre-B ecosystem. Other ecosystem actors, such as the fintech Cobre, were forced to clarify publicly that the failure did not originate on their end. That episode—unfolding just this week—is the real-world manifestation of the exact scenario we discussed in our quality assurance webinar for instant payments: in an interoperable ecosystem, the system is only partially under our control.

On September 30, around 7:00 PM, Daviplata—one of the key participants in Colombia's Bre-B instant payments system—began exhibiting low approval rates and transaction delays affecting both senders and receivers. The issue persisted for hours. The following day, on October 1, around 1:00 PM, the same participant suffered a complete outage that lasted over seven hours. Cobre, a Colombian fintech operating within the ecosystem, was forced to issue a status update clarifying that the service disruption was external—attributable to Daviplata and the Banco de la República's infrastructure—and explicitly noting that it was entirely unrelated to any failure in its own platform.

That episode, unfolding just this week, serves as the clearest possible real-world illustration of a core challenge we were discussing live as the situation unfolded. Mauricio Buitrago, Automation Leader at Q-Vision, put it succinctly during the session: in an interoperable payment ecosystem, each institution controls only a fraction of the end-to-end flow while certifying against system rules it does not fully own. What happened to Cobre this week is that exact principle in practice—their infrastructure functioned perfectly, yet end users had no way of knowing it, because the user experience does not differentiate who bears the fault.

THE CUSTOMER EXPERIENCES IT INSIDE OUR APP

Carol Ortega, Performance Lead, put it another way during that same conversation: ultimately, for the customer, where the error originated is completely transparent. The customer experiences the failure inside whatever app they currently have open, regardless of whether the actual issue sits three steps down the line in a participant whose name they might not even know. That is precisely what Bre-B users experienced this week when attempting to send or receive funds while Daviplata was unavailable—most likely never realizing that the source of the disruption was neither their own bank nor the application sitting open on their screen.

This connects directly to a concrete recommendation Mauricio outlined during the session: building ecosystem participant simulators that go far beyond standard "everything green" responses. Institutions must simulate the exact conditions observed this week—low approval rates, severe latency, and full seven-hour outages—long before they manifest in production. A payment ecosystem's certification environment validates that messaging meets protocol standards. It is not designed, by nature, to stress-test how an application responds when an entire partner network drops off the grid for seven hours on a regular business day.

A SOURCE WITH MORE AUTHORITY THAN ANY CONSULTANT: BRE-B'S OWN DIRECTOR

What elevates this conversation from a hypothetical concern is that Ana María Prieto, Director of the Payment Systems Department at Banco de la República, publicly acknowledged it months ago: the expansion of Bre-B into retail merchants will introduce novel fraud patterns into an environment where controls must rapidly adapt to higher transaction volumes and unfamiliar dynamics. This is not an external warning—it is the ecosystem's leadership stating, from the inside, that scaling exposes an expanded attack surface that legacy controls do not yet fully cover.

That warning materialized in a distinct form over the subsequent months: security authorities in Bogotá issued at least four separate alerts regarding targeted smishing campaigns—fraudulent SMS messages impersonating Bre-B to harvest banking credentials, with documented waves in March, July, and August. While none of these campaigns exploited a technical vulnerability within the platform itself, they actively eroded user trust in a brand name they had come to recognize. This is precisely the scenario that Freddy Silva, Functional Testing Lead at Q-Vision, highlighted during our webinar as the essential mindset shift required for quality engineering teams: moving beyond verifying whether a workflow executes, and beginning to stress-test what occurs when an adversary deliberately attempts to exploit or manipulate that workflow.

IRREVOCABILITY OFFERS NO BENEFIT OF THE DOUBT

Freddy was emphatic on a key point during that session: in instant payments, there is no reversal window. A duplicate transfer, a debit without a credit, or a transaction rejected without clear explanation—as Bre-B users reported during a similar incident in October of last year, coinciding with payroll payday—are no longer bugs you patch in the next deployment sprint. The money has already moved, or the customer has already experienced the anxiety of not knowing whether it moved, and both outcomes generate the exact same erosion of trust.

That October 2025 incident shares an almost exact parallel with this week's event: in both cases, the issue originated within a specific ecosystem participant, impacted users across multiple banks equally—because that is precisely how interoperability works—and resolved within hours. The difference between an incident that turns into a damaging headline and one that passes almost unnoticed does not lie in the underlying technical bug. It lies in how rapidly the entire ecosystem can detect, contain, and communicate what is happening.

WHAT A QA TEAM NEEDS TO HAVE RESOLVED BEFORE THE NEXT TIME

There is no way to guarantee that a participant in an interoperable payment ecosystem will never fail again; that exceeds what any single institution can control. What remains strictly within each participant's control is how rigorously it tested, in advance, what happens to its own user experience when a dependent entity—be it a bank, a digital wallet, or the central key directory—stops responding, experiences severe latency, or returns an ambiguous transaction state.

This requires the exact three-front strategy we discussed during our webinar, now reinforced by real-world evidence from this very week: simulators capable of reproducing third-party failures rather than just happy-path responses; performance testing embedded into every release cycle rather than isolated to a quarterly exercise; and a functional testing discipline that moves past validating whether the ideal flow works, focusing instead on how gracefully its own platform behaves when the rest of the ecosystem fails to cooperate.

An institution that establishes this discipline will not prevent the next Daviplata, or any other ecosystem participant, from experiencing an outage. It will, however, prevent a third party's failure from morphing into a brand-damaging outage of its own in the eyes of the customer, who ultimately only cares whether their money arrived safely.

Press enter or click outside to cancel.

Puedes configurar tu navegador para aceptar o rechazar cookies en cualquier momento. Si decides bloquear las cookies de Google Analytics, la recopilación de datos de navegación se verá limitada. Más información.