Anti-anti money laundering

[Dave Birch] I was involved in a discussion about the relationship between the cost of customer acquisition for simple payment services and KYC/AML/terrorist finance legislation and, once again, I said that I was not sure that keeping people out of the “system” was the best strategy (because if the terrorists, drug dealers and bank robbers on the run stay in the cash economy, then they can’t be tracked, traced or monitored in any way). I made a similar point when I was in the City at a round table on financial regulation. I really didn’t expect my views to be particularly controversial, but they were. What I was arguing for was a relaxation in the controls around small payments — and in particular, getting away from quite strict identity checks, which I think hold back the development of low cost, competitive mobile and Internet payment systems — in order to shift the inclusion vs. exclusion balance that we’ve spoked about before.

I’ll play by Chatham House rules and not attribute what was said by anyone (except me, of course) about money laundering. I said — with poetic exaggeration — that the huge amount of time, money and effort that goes into the AML industry never catches any criminals, and I was given a suitablly hard time by someone from part of Her Majesty’s Revenue and Customs (HMRC) who said that they did indeed use Suspicious Activity Reports (SARs) to detect crime and used the example of last year’s major prosecution of criminals who had been using bureau de change as a front for money laundering. OK, I shouldn’t have said “any” criminals. What I should have said was “almost no” criminals.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Hello? Who’s that? Oh wait, let me google you

[Dave Birch] Central to the direction of digital identity is the issue of the connection between real and virtual identities. How is that connection formed, who controls it, who should have access to it, that kind of thing. Now, you can see that one way to make this connection is to demand a one-to-one “hard” correspondence between the physical identity and the virtual identity, constraining the digital identity completely. To do this you would need to register anyone obtaining any kind of virtual identity. I don’t just mean on the web. A mobile phone number is a virtual identity. Oh wait…

Everyone who buys a mobile telephone will be forced to register their identity on a national database under government plans to extend massively the powers of state surveillance.

[From Passports will be needed to buy mobile phones - Times Online]

This is hardly an original idea. It’s already the case in many countries that law-abiding citizens have to provide identity documentation in order to obtain a mobile phone. Ah, you might say, that’s not going to help catch criminals — which I’m sure isn’t true, as such an initiative must necessarily catch some stupid criminals — because the criminals will just carry on using pre-paid SIMs that have not been registered. Well, yes, but surely if a government makes a law that SIMs must be registered, then it will naturally get the operators to block all of the SIMs that haven’t been registered, as they are in the process of doing in Botswana.

The process of registering all prepaid Subscriber Identity Module (SIM) cards in the country will start in September, says the Chief Executive of Botswana Telecommunications Authority (BTA), Mr Thari Pheko. Speaking at a press conference in Gaborone this week… Mr Pheko said the registration process was expected to take 17 months and will be completed on the last day of 2009, adding that unregistered cards will be taken off-air in the beginning of 2010.

[From BOPA Daily News Archive]

Something similar is underway a little closer to home, in Spain.

From November 9, 2007, people who purchased pre-paid mobile phones have been obliged to provide proof of identity, but for those who purchased phones before this date, a two-year period of grace was granted which runs out on November 9, 2009. It is estimated that more than 15 million pay-as-you-go phones are still unregistered in Spain.

[From Costa News - Mobile phone cut-off]

If there is going to be a government database of all mobile phone numbers against registered names, then surely the only way to manage the new identity world that it creates is to just put it on the web and let new businesses spring up to use it. It’s the same principal as with initiatives around health and all sorts of other personal data. If people believe that their connection to their mobile phone number is “secure” but it isn’t, then the outcomes will be perverse. The bad guys will have access to the data and the good guys won’t. Since there is no more possibility of keeping this database secure than keeping, for sake of emotive comparison, the Children’s Index secure, isn’t it better to make it available for mash-up? And, by the way, I didn’t choose this emotive example at random…

Security flaws have halted work on the internet database designed to hold the details of 11 million children and teenagers. The Department for Children, Schools and Families (DCSF) admitted last night that it had uncovered problems in the system for shielding details of an estimated 55,000 vulnerable children.

[From Security flaws halt work on ContactPoint child database - Times Online]

If you can’t keep a government database like this secure, what chance is there of keeping a government database of mobile phone IDs secure?

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

I hope regulators get real

[Dave Birch] Competition is a good thing. Competition in financial services is a good. If society wants a better payments system (which it should, for many reasons) then the way to get it is by creating a regulatory infrastructure that fosters, encourages and perhaps even demands competition in the provision of payment services. This is why the Payment Services Directive (PSD) has a chance of making life better for European consumers. Should that competitive environment embrace banks and non-banks? Yes, it should. If banks and non-banks are to make progress together, then it is not clear that simply leaving them to get on with it is good enough. For one thing, banks in many countries don’t really want to compete, so if there is no explicit regulation to create a competitive landscape then there is a temptation to fall back on the old kind of competition in banking, which means competing and the regulatory level. This is the kind of situation that we see in Africa. Nigeria is a case in point.

Indications have emerged that Nigerian banks have moved against the quest of MTN Nigeria and Zain to obtain M-Banking license operations from the Central Bank of Nigeria (CBN). The regulatory body has only issued one mobile banking operating license to MoneyBoxAfrica to deplore branchless banking services across the country… the refusal of the apex bank to grant the [m-banking] license is as a result of Nigerian banks antagonistic to the idea.

[From ftr-africa.com - Financial Technology Report, Africa]

In Kenya, where the M-PESA mobile payment scheme is massive, the regulator had wisely decided to allow Safaricom to go ahead and launch that service despite bank pressure. The result has been a fantastically successful scheme that has transformed for the better the lives of million of Kenyans. But someone told me that the Kenyan regulator has now decided to revisit the situation and perhaps “tighten up” rules, inspired no doubt by the banks’ genuine concerns for customer protection and the soundness of the in-country remittance market. Incidentally, you may not be aware that M-PESA has been launched in other countries. Afghanistan, for example.

Take Afghan GSM operator Roshan; they recently licensed Safaricom’s hugely successful M-PESA system, and one of the first applications for it is paying the Afghan army.

[From Telco 2.0: March 2009 Archives]

When the alternative is transporting tons of cash through some of the most dangerous highways and byways in the world, the mobile phone offers a millionfold improvement whatever the regulators’ concerns might be. Mobile money is unstoppable.

[Read more...]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.