I compiled a full list of every financial license Bank Indonesia, OJK, and Bappebti issue, and QRIS kept showing up in it without actually explaining itself. It's the payment rail literally everyone in Indonesia touches daily, but "how does a payment actually get from my phone to a merchant using a different bank" isn't a licensing question, it's a plumbing question. So here's the plumbing, on its own.
Before QRIS, every bank and e-wallet ran its own proprietary QR code. A merchant who wanted to accept GoPay, OVO, and a bank transfer needed three separate stickers taped next to the register, interoperability was zero, and adoption crawled because of it.
Bank Indonesia, under Governor Perry Warjiyo, launched the Quick Response Code Indonesian Standard (QRIS) on August 17, 2019, coinciding with Indonesia's 74th Independence Day, and gave every payment service provider until January 1, 2020 to adopt it. BI
- May 27, 2019: BI introduced the QRIS code system. The Jakarta Post
- August 17, 2019: Official launch.
- January 1, 2020: Mandatory adoption by all payment service providers. Tech in Asia
The mandate sits on the provider, not the merchant, directly. Every licensed Payment System Service Provider (bank or e-wallet) has to support QRIS; a provider that doesn't risks BI sanctions ranging from a reprimand to outright license revocation.
How fast it actually grew
As of August 2024, QRIS users reached 52.55 million, with 33.77 million merchants, and a 217.33% increase in transactions on an annual basis.
Source data — 9 points, Dec 2019 to Q1 2026 (click to expand)
| Date | Users (M) | Merchants (M) | Source |
|---|---|---|---|
| Dec 2019 | ~0 | 0.04 | BI launch figures |
| Dec 2022 | 28.75 | 23.97 | Databoks |
| Q1 2023 | 31 | 25 | Antara News |
| Q1 2024 | 48 | 32 | Databoks |
| Aug 2024 | 52.55 | 33.77 | Perbanas |
| Q1 2025 | 56 | 38 | Databoks/ASPI |
| Q3 2025 | 58.02 | 41 | Databoks/ASPI |
| Q4 2025 | 60 | 43 | Databoks/ASPI |
| Q1 2026 | 62 | 44 | Databoks/ASPI |
Source data — every quarter, Q1 2023 to Q1 2026, value and volume (click to expand)
| Quarter | Value (Rp trillion) | Volume (M transactions) |
|---|---|---|
| Q1 2023 | 13 | 125 |
| Q2 2023 | 17 | 155 |
| Q3 2023 | 20 | 201 |
| Q4 2023 | 34 | 301 |
| Q1 2024 | 42 | 374 |
| Q2 2024 | 52 | 494 |
| Q3 2024 | 66 | 619 |
| Q4 2024 | 82 | 779 |
| Q1 2025 | 104 | 1,021 |
| Q2 2025 | 110 | 1,192 |
| Q3 2025 | 128 | 1,469 |
| Q4 2025 | 170 | 1,847 |
| Q1 2026 | 203 | 2,118 |
Source: ASPI Indonesia (Asosiasi Sistem Pembayaran Indonesia), the industry association's own published quarterly statistics, published as image infographics on their site rather than a data table, current as of their Q1 2026 update.
The mechanics: who's actually involved
A QRIS transaction has six moving parts: the merchant displaying the code, the consumer scanning it, the issuer (PJSP), the bank or e-wallet serving the consumer, the acquirer, the bank or e-wallet serving the merchant, a switching network connecting the two, and a settlement bank handling final settlement.
Before ON-US/OFF-US even comes into play, every QRIS code is either static or dynamic. A static code is printed once and reused forever, the customer types in the amount themselves, cheap for a merchant to set up, but also the easiest to physically tamper with, since a fraudster only has to swap or overlay one unchanging sticker. A dynamic code is generated fresh per transaction with the amount already encoded, common at a POS terminal, and much harder to counterfeit convincingly since it can't be printed once and left in place.
On top of that, a transaction is either ON-US (issuer and acquirer are the same provider) or OFF-US (they're different). ON-US is simple, one company's own systems talking to themselves. OFF-US is the interesting one, and the one I actually wanted to trace.
Say a customer on the GoPay app pays a merchant whose acquirer is BCA. The request goes: customer to GoPay, GoPay to GoPay's own switch, GoPay's switch to BCA's switch, BCA's switch to BCA, BCA to its merchant. Five hops. And behind those five hops, at least six separate daily reconciliations have to run to catch anything that went wrong along the way: inside GoPay's own systems, between GoPay and its switch, between the two switches, between BCA's switch and BCA, inside BCA's own systems, and between BCA and its merchant. Any call inside a single provider's own infrastructure is usually reliable.
Each hop outside their network increases the chances of failures, and each recon increases the time taken for refunds to reach the consumer.
Every issuer and acquirer here operates under a Payment Service Provider (PJP) license from Bank Indonesia, the same licensing regime I catalogued in full separately. As of the latest data, the largest issuers include GoPay, Dana, OVO, LinkAja, BCA, BNI, and BRI, out of over 100 banks and 50 e-wallets that now support QRIS in some form.
The switches themselves are run by Artajasa and Rintis (both private, bank-driven), Jalin (owned by Himbara, the state-owned bank group), and Alto (private, fintech-friendly). Four separate companies, each one a potential point of failure in that five-hop chain above.
Who actually gets paid, and how much
Bank Indonesia regulates QRIS fees through the Merchant Discount Rate (MDR), and as of March 15, 2025 it's tiered by merchant category rather than flat: regular merchants (UKE/UME/UBE) pay 0.7% across all transaction sizes, micro merchants (UMI) pay 0% up to Rp500,000 and 0.3% above it, education pays 0.6%, gas stations 0.4%, and government services and nonprofits pay nothing. MDR QRIS For Merchants
BI says it takes no share of the MDR itself, the fee is split among issuer institutions, acquirer institutions, switching institutions, ASPI, and PTEN (National Electronic Transaction Settlement). What BI doesn't publish is the actual split between those five parties, which means anyone quoting you a specific issuer/acquirer/switch percentage is guessing, not citing something official. I looked for that breakdown and couldn't find it anywhere public.
Cross-border: real, but still small
QRIS cross-border only runs through G2G (government-to-government) corridors, where the switches on each side connect directly and handle FX conversion at a spread BI mandates.
Three corridors are actually live: Thailand (PromptPay), piloted August 2021 and launched August 29, 2022; Malaysia (DuitNow), piloted January 2022; and Singapore (NETS), work starting August 2022. InsightPlus
By mid-2025, all three corridors combined had moved roughly IDR 1.66 trillion (about USD 105 million) in total transaction value. Compare that to the Rp512 trillion QRIS moved domestically in 2025 alone, and cross-border is still a rounding error. BI has early-stage MOUs with Japan, China, South Korea, India, and the UAE, none with a confirmed launch date, so this stays a corridor-by-corridor rollout for now, not the regional network the announcements make it sound like.
QRIS Tuntas: the ATM-adjacent features
Tuntas, launched August 17, 2023, bolts cash withdrawals, transfers, and deposits onto the existing QRIS rail, letting a user do at a QRIS-enabled ATM or agent what they'd otherwise need a physical card for. BI Publication
- Cash withdrawal (Tarik Tunai): Rp6,500 fee. Bank Indonesia
- Transfer: Rp2,000 or Rp2,500 depending on transaction type.
- Cash deposit (Setor Tunai): Rp5,000 fee.
BI doesn't break out adoption numbers for Tuntas separately from overall QRIS usage, so I can't tell you how much of QRIS's growth is actually coming from these features versus plain payments.
QRIS Tap: NFC, without the QR code
BI launched QRIS Tap on March 14, 2025 at MRT Bundaran HI station, with trials on the MRT and DAMRI bus routes, an NFC tap instead of a scan. It shipped on schedule, inside the Q1 2025 window BI had originally projected.
There are two flows: a one-step tap that processes immediately (built for mass transit, where you don't want a queue), and a two-step tap that requires a confirmation on the user's device afterward (built for retail, where you actually want a chance to check the amount before it's final). Video walkthrough
The sticker problem
The most common real-world QRIS fraud isn't a software exploit, it's physical. A scammer prints their own QRIS code, often registered to a fake merchant account, and sticks it directly over a legitimate merchant's real code. Static codes look identical to the eye and don't visibly change, so the swap is nearly impossible for a customer to catch before scanning.
A scanner can't tell a genuine sticker from one glued on top of it five minutes ago, which is exactly why dynamic codes, generated fresh per transaction on a screen instead of printed once on paper, are the safer default wherever a business can support them.
This is reported most often at restaurants, cafes, parking lots, mosque donation boxes, and vending machines, exactly the places a sticker sits unattended. QRIS transaction volume grew 148.5% year-on-year in Q2 2025, and fraud losses tied to QR-code scams over the same period have been reported at around Rp7 trillion (roughly USD 438 million), a scale that's grown alongside adoption itself, not despite it. BI's own prevention guidance is basic: check that a sticker looks undamaged and hasn't obviously been placed over something else, and cancel anything that looks off before confirming.
Refunds are still slow, and nobody's in a hurry to fix that
A failed or duplicate QRIS transaction can take days to weeks to refund, and there's no real-time dispute mechanism, you file a claim with your bank or e-wallet and wait for manual verification. Because a single transaction touches an issuer, acquirer, switch, and settlement bank, a stuck refund can get lost in the handoff between any of them, and each institution runs its own refund policy and timeline, so the experience varies depending on which bank or e-wallet you happen to use.
BI and providers have floated real-time refund processing, a unified dispute-resolution framework, and better cross-provider coordination, but none of it is live yet, and given how many separate companies would need to agree on a shared standard, I wouldn't expect it soon.
QRIS solved fragmentation. What it hasn't solved yet is trust at the edges, the sticker on the table, the refund that takes a week, and both of those are now genuinely bigger problems than interoperability ever was.