Three Reasons Why Corporate Banks Must Invest in New Security Measures
The New Payments Ecosystem brings great opportunities, if banks can mitigate the new risks and threats that arise. Real-time and open payments enable a wealth of new revenue streams; however, the potential for growth must be balanced against maintaining payments security. They cannot break the bank.
New kinds of security threats must be carefully considered in order to maintain #SleepAtNightability, whilst enabling new services and an improved customer experience.
The challenge for banks is multifaceted; how to provide fraud and financial crime protection for both the bank and the customer, and maintain compliance?
Corporate payments security protocol is twofold; how to prevent financial crime, and how to prevent mistakes. A mistake can be just as costly, in financial and reputational terms, as a fraud breach.
Operators in the back office must be able to repair and verify transactions to help the straight-through process. This human touchpoint is crucial, in that it offers the chance to perform critical maintenance on transactions, which automatic processes were unable to address. But any manual maintenance on payments introduces the possibility of error, or even fraud.
Well documented breaches of several bank back offices have highlighted the need for banks to better protect their operators - and their operations - from internal and external attacks. Typical approaches have included Two-Factor Authentication and Four-Eyes Verification to ensure that no single person can make a mistake, or send a rogue transaction unnoticed. But I also see banks moving to prevent external internet connectivity from back office PCs, to combat man-in-the-middle or browser attacks. New applications of biometric technologies such as vein recognition authentication are also being discussed for corporate clients. These all help protect against genuine security breaches and inadvertent mistakes.
Financial crime detection has typically been performed on the origination side of the transaction, helping to ensure that the bank’s customer did not have funds taken incorrectly. But now we see an increase in detection measures; ensuring that any transaction that passes out of, into or even through the bank, is checked for suspicious activity. It is now scored and monitored in the same way that card transactions have been monitored for years.
Corporate banks, with long-standing relationships and a large transaction history with their customers and intermediaries, are well equipped to build profiles that support anomaly detection. Unusual transaction features such as time, location, device and IP address can be easily flagged to review, verify and (if required) halt the payment.
The new open ecosystem and the move to irrevocable real-time payments mean that real-time risk scoring of WIRE transactions is essential to reduce financial crime. Know Your Customer (KYC) will continue to be crucial to the security of payments, but it will become more complex in an Open API-enabled ecosystem. Banks that implement real-time risk monitoring technology ahead of the market curve, will be able to position it alongside the real-time payment propositions as another value-added service for their customers, as well as protecting their own business and reputation.
- Regulatory Rigour
When servicing important corporate customers and their transactions, you need to be confident that due diligence has been done on both the initiator and recipient of the payment. The regulatory requirements vary by country, but in an increasingly globalized world, banks are responsible for ensuring the compliance of a transaction throughout the payment lifecycle, especially if that crosses borders. This includes anti-money laundering (AML) and counter-terrorism financing checks, in line with regulation such as the Fourth AML Directive (AMLD4), designed to support domestic financial intelligence units.
Specially Designated Nationals and Blocked Persons Lists (SDNs) are mandatory for cross-border transactions, but not all countries insist on this at a domestic level. A bank cannot just check the payment parties against a domestic list of banned entities; it must consider the entire payments chain, including Politically Exposed Persons (PEPs), those individuals whose prominent position in public life may make them vulnerable to corruption. It is better to run as many lists as possible at the source to ensure you don’t fall foul of sanctions screening later in the payments lifecycle.
Sanctions legislation is particularly stringent in the U.S. market. Office of Foreign Assets Control (OFAC) checks are standard when transacting with U.S. banks, and are a sensible precaution on international payments to ensure your transactions are not impounded when they reach their U.S. counterparty.
The potential fines for falling foul of OFAC regulation are high, including not just a large fine from the U.S. financial authorities, but potential loss of a very lucrative U.S. banking license. A bank must do everything possible to validate the parties of a transaction from being SDNs, otherwise the full wrath of the authorities will arrive rapidly. Efficient processes, fuzzy matching of data and ease of resolution are critical; for every single correctly stopped transaction, there will be at least ten that could be ‘false positives.’ It is essential to lower those false positives, or get them moving again, as quickly as possible before missing the date for value delivery.
- Customer Experience
Corporate banks hold an incredible amount of knowledge about their customers, thanks to effective relationship managers. There is no technology that can truly replace the knowledge of knowing your customer. But the right technology can apply the rules and be the guardian of your data, to enable you to better protect and support customers. And systems can help you enact what you know about customers.
Customer profiles need to extend beyond the individual and company level; you need to be able to analyze your entire customer base and look across transaction patterns to spot what is typical for your business. The application of machine learning models will improve this drastically. These models can work across large datasets to detect patterns too complex for humans, and they continually learn and adapt to stay ahead of potential threats to your business.
Anomalies are not necessarily fraud; spikes in transaction volumes or values around the end of the tax year may be normal. But outside of your usual patterns, they should be verified with the customer, to ensure the transaction details are exactly as intended. Preventing a mistake is as important as preventing a fraudulent attempt.
The pace at which regulatory developments and new security threats reach the market is not going to slow down. Open APIs in banking are new and unknown, and are therefore a tempting target for thieves. We must secure who is requesting data through balance enquiries and transaction histories, and on top of this we must ensure they have the authority to make a payment.
Banks should commit more resources to compliance and financial crime protection; finding a way to turn this investment into a value-add for customers will be the differentiator. Innovation in security layers onto a transaction bank’s foundations, providing a base for new real-time payment services.
Discover more about security in the Hierarchy of Payment Needs, watch the video with Silvia Mensdorff and Mark Ranta.
Related blog posts
Mobile is Transforming the Travel Sector
February in South Africa means long, hot days, and seemingly endless sunshine (interrupted only by the occasional thunderstorm). Temperatures often top 30 Celsius (that’s mid-eighties for my American friends) and nearly every day is deserving of a braai (that’s barbeque for the rest of the world). But I do spare a thought for my colleagues and friends in Boston, New York, Munich and London (amongst others) at this time of year, as they slog it out through the darkest and coldest months of winter. Who’s to blame them for seeking a bit of light escapism as they plan and book their spring and summer vacations?
“Roads? Where we’re going we won’t need Roads” - Open APIs and Financial Services
The word ecosystem is often used when discussing payments. Whether it’s to describe how a payment is made or to discuss a partnership or even understanding your place in the value chain. Though part of the issue with how we present the ecosystem is that we tend to emphasize only small portions of the overall picture, that is to say if we are discussing payments to a merchant or retailer, the picture shifts to just show eComm, mComm and POS while partially ignoring the Financial Institution, and to a lesser extent the FinTech’s domains. But those days may be coming to an end as we have begun the transition to a new payments ecosystem.
PSD2 Regulation Will Bring Down the Walls Not Build Them
The Payments Services Directive 2 (PSD2) is shaking up the industry, and for good reason. There is sometimes a tendency for the payments ecosystem to expect doom and gloom when it comes to new regulation; seeing it as restrictive, unnecessary interference, or costly. The reality is that PSD2, along with other regulatory changes across Europe and the world, offers a massive opportunity for all participants in the payments ecosystem to carve out new revenue streams.
Connected Devices are Opening Up New Forms of Payments and Partnerships
Of all the trends that are currently shaping – or re-shaping – the nature of payments, none is more significant than the rise of the Internet of Things (IoT). We often talk about the payments ‘ecosystem’ and the complexity that exists between the many participants that are part of this ecosystem, but this complexity will expand exponentially as millions – no, billions – of devices become internet capable.
Driving Toward Innovation in Digital Banking User Experience
The need for delivering on a user experience strategy necessitates the use of common and sometimes confusing lingo like CX, UX, information architecture, UX design and UI design. It introduces ways to gain deeper understanding of customers through methods like personas, journey mapping and Kano analysis. It commands phrases like customer-centric, experience-driven, and ideation/visioning. In the past 4 months, I have interviewed more than half a dozen agencies to engage one that could go beyond the buzzwords and the methods described above. I want to be convinced that great and meaningful changes can happen to UI’s. After all, talk is cheap.