IoT Hasn’t Revolutionised Finance: Telematics and Payments Lead

IoT has not produced an industry-wide revolution in banking and financial services. Its clearest commercial impact is concentrated in motor insurance and connected payments: the 2024 EIOPA market survey found that IoT was still used by only a small number of European insurers, even as digitalisation reshaped the wider sector.
The more accurate verdict is evolution. Connected devices now supply useful evidence about physical activity, enable purchases in particular environments and sharpen operational decisions, but they have not displaced banks’ core accounts, payment rails, credit systems or regulatory obligations.
Where connected data already changes a financial product
Motor insurance is the strongest established example because the connection between observed behaviour and insured risk is relatively direct. Mileage, time of travel, acceleration, braking and other vehicle signals can be incorporated into usage-based insurance rather than relying solely on broad historical categories.
The NAIC’s telematics guidance explains that insurers use this information to align premiums more closely with current driving behaviour, assess accident circumstances and support services such as theft recovery. It also identifies the counterweight: tracking raises privacy concerns, implementation is resource-intensive, and insurers must justify new rating structures under applicable state rules.
This is materially different from claiming that every wearable, home sensor or industrial machine has become an underwriting tool. A device is valuable only when its measurements have a defensible relationship to the covered risk, remain sufficiently reliable and can be used lawfully. Motor telematics meets those conditions more readily than many proposed health, home or commercial applications.
Payments are becoming embedded, not independent
Connected commerce is the second visible advance. Vehicles can hold a tokenised payment credential and initiate purchases for fuel, charging or tolls from their onboard environment; Mastercard’s connected-car examples include partnerships involving Mercedes and Škoda.
The device does not become a bank in this arrangement. It provides context and an interface, while the underlying transaction still depends on credentials, authentication, merchant acceptance, payment networks, an issuer and controls for disputes and fraud. IoT therefore moves the point of payment into the car, appliance or industrial system without removing the regulated financial infrastructure underneath it.
That distinction matters when evaluating more ambitious scenarios such as machines automatically replenishing supplies. A useful implementation needs explicit purchasing limits, a recognised merchant, a way to revoke the device’s authority and a clear answer about who bears responsibility when a sensor, software rule or price is wrong.
Why banking has moved more slowly than insurance
Banks usually receive IoT data at one step removed from the physical event. A lender might use equipment activity to monitor financed assets, or a transaction system might compare device context with an attempted payment, but the signal rarely provides a complete credit or fraud decision by itself. Ownership, maintenance, location and device integrity can all change the meaning of the same reading.
The practical gain is therefore selective rather than universal: faster verification, earlier exceptions and more timely servicing of a loan or payment. Institutions still need conventional customer records, contractual evidence and human escalation because a malfunctioning or transferred device can produce accurate telemetry about the wrong borrower or asset.
Successful projects begin with a bounded decision rather than a mandate to collect every available signal. The financial institution should be able to state which decision will change, how quickly it must change and what happens when the device is offline, compromised or disputed.
The customer bargain is part of the product
Connected finance exchanges convenience or individualised pricing for continuing observation. That bargain is clearest when participation is voluntary, customers can understand what is measured, and the consequence of refusing or withdrawing permission is stated before enrolment.
More data does not automatically produce fairer treatment. A driving score may reflect behaviour, but location or time-of-day data can also correlate with circumstances a customer cannot easily change. Product governance must therefore cover data relevance, retention, access, correction and the route for challenging an automated outcome—not merely the wording of an initial consent screen.
Institutions also need to separate essential measurements from attractive but unnecessary enrichment. Collecting fewer fields reduces the information exposed in a breach, makes model behaviour easier to explain and limits the number of third parties that must be governed.
Security and resilience now set the adoption threshold
Since 17 January 2025, the EU’s Digital Operational Resilience Act has applied harmonised requirements covering ICT risk management, incident handling, resilience testing and third-party risk across the financial sector. The ESMA overview of DORA says the framework reaches 21 types of financial entity, illustrating why an IoT project cannot be treated as an isolated product experiment.
Every additional device creates identities, software versions, network relationships and external dependencies that must be managed beyond launch. A bank or insurer needs an inventory, secure credential provisioning, controlled updates, monitoring and a retirement process that removes access when hardware is sold or no longer supported.
Monitoring also has to distinguish expected communication from suspicious behaviour. NIST’s 2025 network-behaviour methodology recommends documenting the communications a device requires so operators can restrict unnecessary connections and identify deviations that may indicate compromise.
A practical test for a credible IoT finance project
The relevant question is no longer whether a connected device can generate data. It is whether the complete financial workflow can turn that data into a lawful, reversible and supportable decision.
- Decision: Name the payment, pricing, servicing or risk action that the signal will change.
- Evidence: Establish that the measurement is reliable, attributable to the correct customer or asset and sufficiently related to the decision.
- Authority: Define consent, transaction limits, revocation and responsibility for erroneous automated actions.
- Resilience: Provide a safe fallback for outages, delayed data, compromised hardware and unsupported software.
- Economics: Compare the measurable reduction in losses or friction with integration, security, compliance and device-lifecycle costs.
On this test, IoT is neither empty hype nor a wholesale replacement for conventional finance. It is an enabling layer whose strongest results appear where physical evidence clearly improves an existing product or transaction. Telematics and embedded payments demonstrate real change; the slower spread elsewhere shows why the industry’s trajectory remains evolutionary.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.