For most of the ATM's history, the plastic card was the key. No card, no cash. That assumption is quietly breaking down — in a growing number of markets, the card is now optional, and the phone in the customer's pocket does the job instead.
Why cardless is having its moment
Several forces are pushing banks toward cardless withdrawals at once:
- Fraud. If no card is inserted, there is nothing at the card slot to skim. Cardless sidesteps an entire category of physical attack.
- Reach. In many markets more people carry a smartphone with a payment app than carry a debit card — cardless serves customers a card-only ATM turns away.
- Speed and hygiene. A quick scan-and-go is faster than card, PIN and menus, and it's touch-light.
- Fewer lost-card headaches. Forgotten or blocked card? The withdrawal still works from the app.
How a cardless withdrawal actually works
The exact flow varies by scheme, but the shape is consistent: the customer starts the withdrawal in their bank or payment app, the ATM presents a QR code (or the customer enters a code shown in the app), the payment scheme authorises the transaction against the customer's account, and the ATM dispenses. The card rails are replaced by the QR/mobile rails — but the dispense, the cash handling and the switch messaging on the ATM side are much the same.

It's a patchwork of schemes, not one standard
This is where it gets hard. There is no single global "QR withdrawal" standard. India runs on UPI; Indonesia on QRIS and related rails; Vietnam on VietQR / NAPAS; other markets have their own. Each has its own message formats, authorisation flow and certification requirements. The real engineering challenge isn't the QR code — it's the middleware that sits between the ATM's world (XFS, ISO 8583, the switch) and whichever QR scheme the customer is using, ideally without ripping out the existing card flow.
What about security?
Cardless removes card-present skimming, but it isn't magic — it introduces its own surface, such as fake QR codes or attempts to hijack a withdrawal session. The mitigations are well understood: short-lived, single-use tokens, binding the authorisation to a specific amount and machine, and keeping the actual authorisation on the scheme side. Done properly, cardless is at least as safe as card — and immune to the skimmer.
The bottom line
Cardless isn't about replacing the card; it's about the ATM speaking more than one language. An estate that accepts both card and QR simply serves more people, more safely. The blocker is rarely the ATM hardware — it's connecting that hardware to a moving landscape of national QR schemes.