Home›Insights›Articles›How to integrate card clearing and settlement with AS400, Tandem and COBOL without leaving PCI DSS
Blog · Secure file transfer · Payments
How to integrate card clearing and settlement with AS400, Tandem and COBOL without leaving PCI DSS
Mission-critical platforms from different eras, card-brand files that can't be late and auditors asking who did what. What we learned orchestrating clearing for one of Colombia's leading card-payment networks.
More transactions, more files, less room for error
Electronic payments are growing fast in Colombia. According to the central bank's Financial Infrastructure and Payment Instruments Report, the retail payment systems that clear and settle debit and credit card payments grew 7.9% in value and 15.1% in transaction volume in 2024. More transactions mean clearing files that are larger, more frequent and processed in tighter windows.
Then there's regulatory pressure. PCI DSS, the payment card industry's security standard, requires protecting cardholder data wherever it is stored, processed or transmitted, and version 4.0 tightened requirements for monitoring, authentication and activity logging. In clearing, that means every file moving between systems is in compliance scope.
Why clearing is an integration problem
Our client's challenge had three fronts: integrating AS400, Tandem and COBOL; complying with PCI DSS; and ensuring operator traceability. They tend to show up together at any network or processor:
- Platforms that speak different languages. Each system has its own way of generating, receiving and validating files, and wiring them point to point multiplies scripts and interfaces.
- Operator-dependent processes. If someone has to launch a transfer or a command by hand, clearing depends on that person's schedule and memory.
- Scattered evidence. When logs live on each server, proving to an auditor who did what means reconstructing the story after the fact.
- Exposure risk. A file that travels unencrypted or lingers in a staging folder is a PCI DSS finding waiting to happen.
MFT as an orchestration layer, not just transport
Fortra's GoAnywhere MFT is usually described as a secure file transfer platform, but in environments like this its real value is orchestration. Three modules make the difference:
- Advanced Workflows: models clearing as a workflow with push/pull transfer steps, PGP encryption and decryption, database operations and actions before and after each exchange.
- Agents: lightweight components installed on enterprise servers that run transfers and workflows locally, with compression and encryption, under GoAnywhere's central management.
- Scheduling and auditing: time- or event-based executions and detailed logs of every transfer and every user.
For the network, Redsis combined Advanced Workflows , GoAnywhere agents on AS400 and the IBM CMD Client API to bring IBM back-end command execution into the workflows. The result is Mastercard and Visa clearing that runs on scheduled executions, without waiting for someone to launch each step by hand.
In payments, it's not enough for the file to arrive. You have to be able to prove how, when and by whom it was moved.
Five lessons for orchestrating clearing on mission-critical platforms
1. Don't rewrite what works
The COBOL applications and the Tandem and AS400 systems behind clearing are stable and proven. The goal isn't to replace them but to wrap them in a layer that integrates them. Moving orchestration into the MFT platform lowers project risk and shortens time to production.
2. Run close to the data
Installing agents on the servers where files are generated avoids pulling them into staging zones. Files are encrypted and transferred from their source, which shrinks the exposure surface and simplifies PCI DSS scope.
3. Integrate commands, not just files
In clearing, moving a file is usually preceded or followed by a command: close a batch, launch a program, update a status. Bringing those commands into the same workflow, for example through IBM APIs, removes the manual steps that used to separate one transfer from the next.
4. Give every action an owner
Operator traceability isn't a report you assemble at the end; it's a design property. Every execution, manual or scheduled, should be logged with user, time and outcome in a single audit repository.
5. Schedule and monitor by card brand
Each card brand has its own schedules and formats. Separating workflows by brand and scheduling them independently lets you catch and fix a problem without stopping the rest of clearing.
The result: clearing that is secure, traceable and on time
Today the network has a single solution for Mastercard and Visa clearing, integrated with the IBM back end, with scheduled executions, high operator traceability and 100% PCI DSS compliance. Workflow automation lets clearing wrap up quickly on a secure, reliable solution.
For a network that handles a meaningful share of the country's card payments, that means something very concrete: fewer manual steps in the process that moves money between banks, merchants and card brands, and evidence ready for every audit.
Where to start
If clearing, settlement or other critical exchanges at your institution still depend on scripts, manual transfers or logs scattered across servers, a good first step is an inventory of the flows and platforms involved. At Redsis we combine more than 25 years of mission-critical platform experience in banking and payments, including IBM platforms, with Fortra automation and integration solutions such as GoAnywhere MFT and JAMS.
Read the full story
See how one of Colombia's leading card-payment networks orchestrated its clearing with GoAnywhere MFT.