Direct debits are a dated hack

[Dave Birch] When I was at a mobile payments event a couple of weeks ago, someone asked the usual question in the coffee break: why bother? The existing payment systems works pretty well, they said. Who cares about mobile wallets, they said. (And so do the public, incidentally!). You can see why people think like this.

“Credit, debit and cash all work pretty good in the United States,” says Gene Signorini, a vice president at Mobiquity, which designs and builds mobile applications for corporate clients. “Those payment options aren’t really broken.”

[From Are Mobile Payments Fixing Something, Or Just Hot Doggin' ? | Wired Business | Wired.com]

Gene is a smart guy, and he knows what he’s talking about it. The payment options aren’t broken. But as to whether they are pretty good or not, you have to ask: “pretty good” for who? Who does cash work pretty good for? Not for me. Last time I went to an ATM in the US I got charged $5 to draw out some money. Who do credit cards work pretty good for? Not for merchants, apparently, as they are in the process of turning down a multi-billion dollar settlement and continuing legal action against Visa and MasterCard.

A long-running legal dispute pitting Visa and MasterCard against a group of retailers over payment processing rules and fees might finally be reaching a settlement that would compel the card networks to relax some of the regulations they currently impose on merchants who accept their cards.

[From Credit Card Surcharges May Be Coming to a Retailer Near You — moneyland.time.com — Readability]

Credit cards do work for me, since I never use a debit card for anything except getting money out of an ATM. One of the reasons they work for me is all the people using debit cards are subsidising the frequent flier miles I get from my credit card — thanks guys — for no benefit of their own. Does debit work pretty good? Well, if it did surely Congress wouldn’t have found it necessary to regulate debit interchange, would they?

How to make sense of this? How should we think about what’s “good” and “bad”? You have to separate the medium from the message. There are two different issues here and they need to be discussed separately. One is the payment instrument — prepaid, credit, debit etc — and the other is the payment mechanism — paper, card, phone etc. — and the feedback loop is complex.

So, for example: I really, really want a good set of mobile payment options because I always have my phone with me but I don’t always have my wallet with me. This leads to one set of potential outcomes that centre on taking the existing plastic card products and shoehorning them into the mobile phone.

But there’s another, more general path. Suppose mobile doesn’t replace cards payments. Suppose it replaces other payments. Cash, obviously, but there are electronic options that may be open for disruption. Consider another commonly-used payment mechanism, the direct debit, another example of something that appears to be working well. But is it?

I like reading the problem pages in the personal finance sections of newspapers because they give a useful window into practical issues. Can we find any guidance there? Well, yes. In the Daily Mail (23rd October 2013, page 48) is just such a useful sidelight. One of the letters concerns an SME account (for a charity) that keeps losing small amounts to direct debits. Each time it happens, they complain to the bank, and the bank (acting entirely correctly under the terms of the direct debit scheme) refunds the money. The customer is protected, yet everyone’s time and money is wasted (and not accounted for). The root of the problem, as noted in the response to the letter, is that it is too easy to set up a direct debit and no way to approve them individually. Of course, it’s not only criminals and idiots who fill out the wrong numbers who can loot your bank account using this mechanism, it’s also companies with legitimate mandates who, for one reason or another, take money and infuriate customers. Here’s just such a typical member of the public (well, actually, a typical sister of the Mayor of London and fully-paid up one-percenter, I should clarify, which is why her whinge is in the national press in the first place):

What makes this so easy and legal for companies, and maddening and opaque for consumers, is partly the direct debit system. In theory, it should make life easier – about six billion automated payments, worth £4.3 trillion, are made in the UK per year.

[From RACHEL JOHNSON: We've been mugged - and they did it by direct debit! | Mail Online]

Once you have set up a direct debit mandate, the money can be taken from your bank account without you knowing anything about it. I remembered seeing another news item about direct debits in the same newspaper a few months ago. A quick google, and sure enough….

A holidaymaker was left £27,000 in debt after mobile phone company Orange extracted £120 an hour from her account for almost a week.

[From Woman is left £27,000 in debt after her new Orange pay as you go mobile withdraws £20 from her bank account every TEN MINUTES | Mail Online]

I know this is just a stupid technical error, but it served to make me think about the future for the direct debit as a payment instrument in a world with laser beams, transistors and mobile phones. It seems to me that direct debits exist because of a technical limitation on the communications between the the biller, the bank and the consumer. It the olden days, before year zero (1995, when the Netscape IPO heralded the modern age), it was impossible to imagine how a biller might communicate a bill to a consumer instantly, have the consumer authorise payment instantly, and the the money transfer from the consumer’s bank account to the biller’s bank account instantly. So it made sense to set up the complex, centralised, batch process around direct debates and introduce the notions of mandates and then pass a new set of laws around them.

But now imagine that someone has invented just such a mechanism. The gas bill falls due, a message pops up on the consumer’s phone, the consumer looks at the bill, the consumer is bounced to their bank app for authentication and they then authorise the bill payment. The payment is sent by FPS directly from the customer’s bank account to the gas company’s bank account. That’s it, sorted. I think the generalised solution of pushed e-billing has wide applicability in a mobile age and might well have the potential to replace a significant fraction of existing non-cash payments in time.

What I found quite interesting is the strange obligation for non-bank payment operators to be able to offer direct debits and account services to former bank-account customers.

[From The proposed Bank Account Directive: wrong tool]

There is no need for direct debits, whether SEPA or otherwise, in a world that has FPS and Dwolla, smartphones and apps. Direct debits are a hack, a disco-era (my new favourite payments phrase) workaround for the days before real-time payments, the internet and mobile phones. They are, in essence, an anachronism.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Response to the Federal Reserve consultation on Payment System Improvement

[Dave Birch] This is the draft version of Consult Hyperion’s response to the The Federal Reserve Banks’ Public Consultation Paper on “Payment System Improvement” (10th September 2013).

Consult Hyperion is a specialist consulting company in the secure electronic transactions field. The company has almost three decades’ worth of experience advising the private and public sectors around the world. We have offices in New York USA and Guildford UK. We have detailed and significant experience in the specification and deployment of mass-market payment systems and are recognised thought leaders in the fields of digital money and digital identity through our “Tomorrow’s Transactions” series of blogs, podcasts and events.

Full details on the company are, of course, to be found on our web site at http://www.chyp.com/.

Question 1.

We are in general agreement with the gaps and opportunities identified in the documents although we might summarise them at high level slightly differently by saying that the essential complaints of stakeholders concerning the operation of the national payment system might be categorised in three summary concerns that the system is too expensive; too slow; and too opaque.

Question 2.

We think it might be better to restate the desired outcomes for payment system improvements in wider terms recognising the responsibility of the payment system to the economy as a whole. One way of doing this might be to look for more quantifiable targets that can be negotiated and agreed. One suitable candidate target might be the total social cost of the payment system. There has been significant academic work in recent years looking at the calculation of overall social costs by more properly accounting and cross-referencing the individual private costs of participants and this work has probably reached the point whereby a meaningful target could be established by the Federal reserve in consultation.

We recommend “The Social and Private Costs of Retail Payment Instruments — A European Perspective” by Heiko Schmiedel, Gergana Kostova and Wiebe Ruttenberg (European Central Bank Occasional Paper Series no.137) as a useful input. We hope our comments on this paper may prove useful.

Suppose it were to be determined that the total social cost of the payment system is in the region of 1% then a ten-year target to cut this in half could serve as an aggressive focus for strategy and give immediate direction to tactics, including the creation of national, ubiquitous near-real time payment system. For the sake of brevity and wit, we propose to refer to such as a system as the UR (US Real-time) system.

We think the Federal Reserve should initiate a conversation about balancing the payment system to fulfil wider social goals and recognising that the payment system is not a stand-alone “machine”. It might be relevant to begin discussions with taxation, welfare and law enforcement representatives to examine the potential for reducing cash-based transactions and reducing the amount of cash in circulation, particularly the high-value notes that fuel crime.

Question 3.

We feel that the role of the Federal Reserve as catalyst will be central to the changes and improvements needed over the coming decade.

Question 4.

We would disentangle the issues brought together under the discussion of ubiquitous near real-time payments into three areas where the Federal Reserve might support the industry in making significant and lasting improvements to the payment infrastructure.

The first issue is that of UR itself, the institutions that it might interconnect and the nature of the accounts that it would access.

The second issue is that of the identification, labelling and addressing of the accounts that would be reachable through UR. While we understand the natural focus on the mobile phone number as a suitable labelling system, we would like to take this opportunity to point out that mobile phone numbers are not exactly analogous bank account numbers. We commented on this in the UK in response to the report from the Independent Commission on Banking in 2011 and we think that  short diversion into this topic might provide useful support to later arguments!

A phone number is an indirect reference to the phone (actually, it’s a reference to the SIM card in most of the world) whereas the account number is the “target”. Thus, we shouldn’t really compare the account number to the phone number, but think of it more as the SIM. Each SIM card has a unique identifier, just as each bank account has an international bank account number (IBAN). When a consumer switches on their phone, the SIM tells the mobile operator which phone it is in and then “registers” with a network. In most countries there is an “All Call Query” or ACQ system: a database of mobile phone numbers that tells the operators which mobile network each number is routed by. In order to make call connections as fast as possible, each operator has their own copy of this database that is regularly updated.

It’s entirely possible to envisage a similar system working for UR, whereby we separate the equivalent of the mobile phone number — let’s call it the Transaction Account Number (TAN) — from the underlying account and have an industy database that maps TANs to (for banks) IBANs. This database would be the equivalent of the ACQ database. An employer might send a salary payment via UR to the TAN, and the database tells UR which actual IBAN to route it to. No matter which bank accounts the consumer might use or change throughout their employment, the employer always sends the salary to the same TAN and thus reduces their costs. We assume that a consumer might log on, or call, at anytime to change their TAN to any target account and that this change would be almost immediate.

The third issue is that if there is to be a generalised identification system for payments, some kind of “payment name” might be more convenient for consumers than either some form of virtual IBAN or a TAN. The equivalent of a Twitter name or Facebook name might make sense. We suggest that the Federal Reserve initiate work to look at the introduction of a payment name, perhaps better labelled a “financial services identifier” (FSI), that could be bound with appropriate credentials — post customer due diligence (CDD) — to form a secure financial services passport which could then be used to effect considerable cost reductions in the financial services industry as a whole and shift more transactions online. Again our comments on this in connection with the UK’s Current Account Switching Service (CASS) are online.

As an aside, we think that the easiest way to do this would be to assign an FSI to a person or other legal entity the first time that they go through a CDD process. One someone has one of these FSIs, then there would be no for them to go through CDD again at other institutions. This would greatly reduce industry costs and make the process of obtaining a new financial service — a new bank account, a new credit card, a new insurance policy, a new accountant — much simpler. It doesn’t matter if a person has multiple FSIs, because each FSI will have been obtained as the result of a CDD process. Consumers might want to have personal financial persona and a small business financial persona that point to a personal and to a business accounts and use them for different purposes.

Question 5.

Once again we think that the issue of the addressing of the counterparty accounts should be decoupled from the issue of system functionality. A single credit push model is sufficient to provide all of the functionality required by the stakeholders and we agree that the confirmation of good funds on initiation and near real-time availability of those funds to the payee are the key features. We will make some further comments about the architecture of the system based on the U.K.’s experiences with the faster payments service (FPS) in response to question 14 below.

Question 6.

There are several reasons why we think that the creation of a separate system is a better solution than building on the existing a ACH or debit card infrastructure. The most important of these is that we for see the need to interconnect a wider range of transaction accounts than the existing accounts held by banks. There is no obvious reason why someone should not be able to use the system to send money from their checking account to their iTunes account, for example.

As the Federal Reserve observes, many legacy payment systems demand accounts that are “cumbersome to establish”. We agree, and suggest that the Financial Action Task Force (FATF) recommendations concerning risk-based regulation of new payment technologies are entirely appropriate. Therefore, the high-level requirement for the new system is for the general interconnection of transaction accounts that may be held by non-bank organisations with minimal CDD for low-value accounts.

In response to the final sub-question concerning payment scenarios we would like to add the observation that our specific experiences gained working on the M-PESA scheme in Kenya (where we were the consultants responsible for the initial feasibility study and the specification of the initial scheme) is that creating a system with open, transparent and non-discriminatory access is a more crucial step towards meeting any strategic goals that might be defined for this important piece of national infrastructure than attempts to optimise elements of the infrastructure for specific payment scenarios. Therefore whether the scheme is more likely to be used for (for example) B2B or P2P scenarios should not shift the design to make it less than optimal for other solutions. Indeed, one of the key lessons learned from the early deployment of M-PESA was that the addition of open APIs would have accelerated the creativity and innovation that has come to characterise the use of the scheme because the market, rather than the system designers, is most effective at identifying and exploiting efficiencies.

Question 7.

We do not see any benefit to diverting resources into incremental improvements in the check payment system. The use of checks in the United States has a cultural context that even the Federal Reserve’s own studies have been unable to understand in rational calculation. Check usage seems to be driven by habit more than it is driven by concerns around float, the commonly-given reason.

Question 8.

It is very clear that any system for real-time or near real-time transfers carries with it increased vulnerability to fraud. In the case of a national, ubiquitous system of the kind envisaged by the Federal Reserve, we feel that the most effective route to minimise the exploitation of these vulnerabilities is by strengthening the identification and authentication of counterparties. To put it glibly, identity is the new money. This is why the creation of some kind of financial services passport, as we discussed in response to question four, might be so beneficial because it would optimise countermeasure expenditure for the stakeholders overall. While previous efforts at strong authentication, including two factor authentication (2FA) for bank account access, have had issues with consumer acceptability, privacy and security, costs and benefits, we feel that the obvious fact that the mobile phone will become the most common authentication device for this kind of service means that the Federal Reserve can raise the bar on identification and authentication without undermining consumer interfaces.

We note that there are issues around consume protection that will need to be investigated further depending on the nature of the system. If, for example, transactions are immediate and irreversible then consumers will need clear mechanisms for challenging apparently incorrect transfer and for rectifying errors made in good faith.

Question 9.

The existence of an UR system would obviously revolutionise the specific mobile payment subsector of mobile-initiated account-to-account (M-A2A) transfers. The extent to which this particular subsector would come to substitute for other payments and mobile payments systems can only be a matter of speculation at this point. We do, however, think that a scenario with a degree of plausibility is that M-A2A transfer will increase in popularity for interpersonal payments in the first instance and will then begin to substitute for certain third party payment mechanisms that are currently used to compensate for the non-existent near real-time system at present as well as for other mechanisms such as cheques in the small business environment.

Question 10.

The opportunity cost of not implementing a near real-time payment service in the United States might be expected to be high unless there are compensating regulatory changes to make it easier for similar services to be developed and implemented by nonblanks. The straightforward comparison of the total social cost of payments in the US and, for example, the UK does not give a full account of the opportunity costs because innovation that is currently being directed into overcoming the limitations of what has rather amusingly been termed the “disco-era” payments infrastructure would, one might imagine, instead be directed into other areas of endeavour.

Question 11.

The estimated costs of implementing such systems for the US could be estimated by scaling the solutions chosen for the UK and Australia, but we think that a realistic estimate must take into account not only the sheer volume of interconnecting financial institutions in the US but the disparity in requirements between different categories of institution. This would suggest that some industry structures will need to be created to keep the expenditure realistic. It might be, to pick an obvious example, that a single gateway into the credit union system might be more cost-effective than the need for new systems at every credit union.

Given that the architecture of a target system depends on the ongoing input to this consultation process is difficult to make any comments on the impact on existing core processing and back-end systems. It might be useful to observe, however, that in the evolution of the Single European Payment Area (SEPA) most banks and commercial organisations found it effective to implement gateways for interconnectivity rather than to interrupt their normal cycles of core system review and replace them and we imagine that a similar process might evolve in the US.

Question 12.

If some kind of if some kind of semipermanent pseudonym (whether a TAN or a payment name) is to be used instead of account numbers, a development that we regard as both inevitable and desirable, then it is clear that a directory will be necessary. Whether this directory should be centralised or distributed is a matter for appropriate technical consideration downstream and is not, as far as we can see, either a complicated or uncertain element of the overall system. Techniques for managing large-scale distributed directories are well-known and well understood.

Question 13.

We think that the appropriate industry direction with respect to checks is to develop solutions that make electronic payments “better” than paper ones. Since there are a great many ways that this could be done (the use of APIs, the integration of remittance data, speed and cost, and others) we do not see any need to make separate plans to accelerate replacement of checks other than as part of an overall national payments plan to reach the desired level of total social costs as already discussed.

Question 14.

We agree that a barrier to electronic payments in some sectors has been the inability to link payment and remittance (and other) information. It seems likely therefore that a coordinating role for the Federal Reserve in other aspects of a near real-time payment system would extend to working with other industry bodies to integrate other appropriate initiatives in adjacent sectors. There is experience to draw on from the European initiatives in this area as well as from other industries and an early engagement with interested parties would be greatly beneficial.

With respect to the specific issues around the adoption of recurring payments – through both the ACH debit mechanisms and continuous authorities on card payments – we regard these as “hacks” developed to bypass inadequacies in the existing payment infrastructure and we see no need to replicate such functionality in a future system.

To give a simple example: the consumer gets a message on their smart phone indicating that the utility bill has fallen due and giving the amount, the consumer can either select more information and examine the bill in more detail or simply authorise the payment at which point a credit push settles the bill. This gives the consumer full control over the payment and means there is no need for direct debits or continuous authorities thus considerably reducing the cost and complexity of the structure.

Question 15.

We think the adoption of the XML-based ISO 20022 format is a sensible step for the United States. We think it is reasonable to comment on the UK Faster Payments Service (FPS) that with the wisdom of hindsight it might have been better to have implemented this standard in the infrastructure rather than staying with legacy standards. The inability of FPS messages to carry other than minimal remittance data does hamper the evolution of the service.

Question 16.

As a general point, we feel that the regulatory environment will have more of an impact on the shape of cross-border services than any constraints of technology. There will be no technical issue in creating, once again to give an obvious example, a gateway between the UK FPS and a US near real-time service assuming that the directory standards allow for cross-border addressing.

While not specifically on issue of cross-border payments, we feel that the European Commission’s approach to the regulation of payments, and specifically the separation of payments regulation from banking regulation, provides a useful example for the Federal Reserve and other stakeholders to consider. We might also add at this point that the European Commission’s current consultation on licensed third-party direct access to transaction accounts (the so-called “XS2A” consultation) might also result in some useful input to a design process in the US. Without jumping ahead to technical solutions, it is entirely reasonable to imagine that the system that allowed such third-parties circumscribed access to transaction accounts under consumer control could add substantial functionality to the infrastructure and mean significant cost savings across the stakeholders. Much as a consumer might give Facebook permission to access their Twitter account, they might give Verizon permission to access their bank account (directly, that is, so that Verizon could initiate credit push transactions that fell within certain limits).

The US has no equivalent of the Payment Services Directive (PSD) and therefore no equivalent of the Electronic Money Institution (ELMI) or Payment Institution (PI), so that innovators in payments must either operate under banking licences or state money services licences. As the Federal Reserve is undoubtedly aware, approximately half of the PI licences issued in Europe are for money transmitters (who thus have no need to obtain licences in individual countries), approximately a quarter are card acquirers who want direct access to cards schemes and the remaining quarter are new “niche” PIs. In Europe, essentially, the regulators have begun to separate to regulation of payments and electronic money from the regulation of banking. This is in marked contrast with the current US framework and there seems little pressure for change and the banks want payments to continue to be limited to regulated banking institutions. We feel this is possibly too narrow a view that underestimates the potential benefits to banks from a more efficient infrastructure (since payments are, of course, a substantial cost to banks as well as source of income).

One avenue to explore might be to recognise EU-registered PIs and ELMIs and allow them to passport to the US or for the US to create equivalent legal categories.

Question 17.

We have already dealt with the issues around device authentication and the authentication of counterparties, so these do not need amplification. The security of the infrastructure will of course be a matter for the specification of that infrastructure and based on our experiences carrying out detailed risk analysis for scale transactional systems we see no reason why an appropriate level of exposure and countermeasure expenditure could not be identified to the satisfaction of the stakeholders. In short, we do not see security as a barrier to deployment.

Question 18.

Centralised clearing of threat and incident reports would indeed be a useful adjacency. The extent to which third parties might be allowed to monitor, control or block certain transactions is a matter for serious discussion and debate that is well outside the scope of this consultation. We do feel it would be irresponsible not to integrate the legitimate requirements of law enforcement and consumer protection agencies into the operation of the system, but we recognise that this must take place inside a more open debate and transparent multi-party settlement around privacy.

Question 19.

It is not clear to us that any specific new standards are required in this area provided that the minimum standards set for the identification and authentication of counterparties are of a reasonable degree. We do not think it makes sense to develop specific standards either for the payments industry or for the financial sector as a whole, and thinking much wiser to integrate the requirements of the financial sector into wide initiatives such as the US� National Strategy for Trusted Identities in Cyberspace (NSTIC), the FIDO Alliance and the Open Identity Exchange (OIX) to name but a few.

Question 20.

As is clear from our response to question 19 we feel that the Federal Reserve might be best placed to coordinate requirements relating to a new near real-time payment system with other financial sector requirements and work with the variety of organisations developing the wider identity management and authentication solutions throughout business, government and academia. It is a more cost-effective route for the payments industry to use the standards than to develop specific standards (such as the “Europay, MasterCard and Visa”, or “EMV”, standard for payment cards).

Question 21.

We think there is work to be done in understanding the national context to improvements in the payment system since there are clearly US specific cultural factors at work. These are manifest in many areas of US exceptionalism, including the continued use of low-value banknotes instead of coins, the continued use of extremely low-value coins, the persistent use of cheques even when that use delivers no rational benefit to counterparties, the fragmented infrastructure and the relatively high cost of payments. It might be useful for the Federal Reserve to continue its good work in researching some of these “softer” factors as they might help shape the near real-time system to make it even more desirable and useful.

We have recently been involved in work for both private and public sector clients looking at the relationship between financial and social inclusion and we certainly feel that the extension of real-time payments beyond regulated bank accounts (particularly to low value non-bank transaction accounts) might be of national benefit. We have also been involved in a project for UK government agencies looking at the delivery of financial services, including welfare benefit payments, to excluded groups. This has alerted us to the benefits of interconnecting a wide range of different accounts so that some institutions can develop specialities in helping, for example, the elderly or the housebound or people with varying degrees of disability. Specialised institutions built around transaction accounts in these areas might deliver better and more effective services than conventional banks and so these kinds of accounts need to be factored into the Federal reserve’s plans. We note that this would also be beneficial to the banks operating conventional accounts since many of these customers are money-losing propositions.

The innovation and creativity that we associate with the US technology sector will undoubtably, given the right regulatory environment, exploit the existence of a ubiquitous near real-time payment system to deliver incredible products and services that we cannot currently envisage. For this reason we are wholly behind the creation of such a system and believe that it will bring sustained benefits to our clients in the payments sector and beyond.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

What was new in New York?

[Dave Birch] When we had our second annual NYPAY / Consult Hyperion Tomorrow’s Transactions Unconference at Google in New York we were surprised and delighted to see the event full and with a full waiting list yet again. A big, big thank you to everyone who made this possible: NYPAY for organising, Google for getting behind us once again and providing such excellent facilities, Discover for supporting the Unconference series and providing books for the delegates and, of course, the 100+ people who came along.

Max Occupany

We had a terrific kick-off from Brett King, who got everyone thinking about topics for the day. Brett stayed for an onstage Q&A led by Dylan Love from Business Insider and got a fair variety of questions right off the bat. While the Q&A was underway, we were encouraging people to start filling making notes about what they wanted to talk about and passing them down the rows to us so that we could start grouping them.

Brett King Q&A

We try to experiment with the format each time, and this time one of the experiments that, I think, worked rather well was to put the sessions into streams to theme and organise them slightly. As a first cut, we decided to try streams themed around Technology, Business and Society. Then we added a special “Stream X” for hot topics. When all the post-its were in, we ended up with an agenda that was really, really good. After a minor amount of bullying of old friends to get the right chairpeople in place for each session, we were ready to rumble.

SessionTechnology StreamBusiness StreamSocial StreamStream X
OneEMV in the USA
Chair: David True
Barriers to Mobile Payments
Chair: Howard Hall
Financial Inclusion
Chair: Dave Birch
Future of Banking
Chair: Brett King
TwoNFC vs. QR vs. BLE
Chair: David True)
Payments Disruption
Chair: Lanny Byers
Regulatory Suggestions
Chair: Christine Genaro
Crypto-Currency
Chair: Leon Perlman
ThreeThe Next Big Thing
Chair: David Schropfer
Merchant Requirements
Chair: Steve Mott
Future of Money
Chair: Dave Birch
ID and Authentication
Chair: Howard Hall

We then reorganised the desks in the room to form three discussion areas for the streams and Google very kindly arranged a breakout room for us to host Stream X. After coffee we invited then delegates to choose their sessions and get going. The buzz was terrific, I’m happy to say. The delegates were comfortable with interacting right away and the learning and sharing got going immediately.

photo2

Here’s Consult Hyperion’s Lanny Byers leading the group discussing the trajectory of EMV in the USA, which did not, if this group is anything to go by, seem anything like as smooth as it did last year when we were discussing a similar topic.

photo8

In fact at the end of the discussion, which included people from the issuing, acquiring and merchant communities, the group seemed almost evenly split around whether EMV would ever happen at all (!) with a good fraction of the well-informed debaters of the opinion that having taken so long to set foot in the USA, the rapid pace of development in mobile payments, wallets, tokenisation, identity management and wireless interfaces of all kinds would overrun it.

The core messages that I brought back for our clients were around the three best attended sessions. These were the sessions on Financial Inclusion, NFC vs QR vs BLE and Merchant Requirements and each of these left me with some great ideas to feed back in to our projects. But here I think it is interesting to reflect on why it was that these were the top sessions. A “conventional” conference agenda set six months might have had a guess that Merchant Requirements would be hot because of MCX, but probably wouldn’t have guessed that the more technology focussed interface shootout would have attracted so many people and certainly wouldn’t have guessed that Financial Inclusion would be so hot.

In the latter case, I’m pretty sure that it is a combination of factors: Amex’s recent announcements about going after the unbanked at Money2020. By common acclaim, theirs was the best of keynotes in Las Vegas and they are making a big play for the “near bank” market.

Starting this fall, Serve clients can add cash at 14,000 CVS stores and many participating 7/Eleven stores free of charge. Serve has also launched a reserve account for savings and 36% of customers are not moving money into the reserve account on a regular basis. The account costs $1 a month, free if the customer does direct deposit or deposits $500 or more.

[From American Express aims to serve unbanked and underbanked » Banking Technology]

All in all, I have to say — given the comments that we received from the delegates — the Unconference format worked really, really well and I am glad to see that the popularity of the format is growing in our sector. We got some great feedback and some suggestions for changing the schedule slightly which we are going to try out and are always to keen to hear more from attendees: we will shamelessly plunder new ideas from anywhere. And, once again, sincere thanks to Google for being such excellent hosts and such firm supporters of the Tomorrow’s Transactions Unconference series. Next stop is Toronto on December 11th so I look forward to seeing you all there!

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Still a touchy subject it seems

[Phil James] The safety of contactless payments continues to attract considerable attention. The casual reader can be forgiven for believing that the technology and payment scheme has not been thought-through and security loop-holes remain to be “discovered”. Actually, one loop-hole is well-known and I’ll make another attempt to explain just what is going on here.

The usual reposte from the payments industry is that cardholders have nothing to fear from the technology even if the merchant and the transaction acquirer (who collects and makes the electronic payment) don’t follow the rules which protect the payments exactly. An explanation of this starts to get a bit complicated almost immediately and most casual readers are probably wary of long explanations about “liability”. So what is happening and has the industry simply overlooked the “holes” because it has been convenient to do so?

Reading Contactless Cards

The cards have been designed to be read using a contactless technology and that much of the data transferred over the air between the card and reader is in clear and not encrypted. This is deliberate and not a mistake. It would be quite difficult to encrypt the interface to the reader (you can do this for a proprietary or local system such as Oyster – but we need a system that will allow any card to work in any terminal anywhere in the world).

The industry claims that the cards must be very close to readers before they can be read. This is true. The reason is because the technology uses magnetic fields to power the card and communicate data, so it’s like a transformer and is not a radio device. This technology is infeasible for communication at long distances, with experts recognising that a custom built reader could stretch the range to 20cm but with difficulty. I have been part of a team which built a rig capable of powering a card at a metre, but the device was extremely large and created very large fields which rendered electronic equipment unusable for several metres around. Any cards getting too near the coils could be destroyed. (And communicating didn’t work). The equipment was extremely hazardous!

So if you want to connect to someone’s card, you need to get very close indeed. But you could, of course.

However, you can eavesdrop on a coupling between a card and a contactless reader. A card and reader in good contact will induce an electric field around the reader (sorry about the physics) and it is the signalling on that we can detect at distance. In other words, you can’t interact with a card yourself at a distance but you can snoop on a conversation between a card and reader. We concluded (in 2007) that distances of metres can be accommodated by a properly built and tuned eavesdropping coil. Recent reports have shown a simple device which can eavesdrop some 60cm from the card and reader. Engineers claim to prove risks of contactless bank cards – Telegraph

Anyway, it doesn’t matter if you interrogate a card close up or eavesdrop at a distance, you’ll see similar data.

The Data we can see

This has been covered in each response to the news stories. Along with a lot of transaction-specific data there are the Primary Account Number (PAN) and Expiry Date. There is an interesting data field which looks like the coding on the magnetic stripe but has a cryptographic value which is coded differently to the actual magnetic stripe. So this can’t be used to code a counterfeit magnetic stripe card unless the Issuer is careless with their checking. For the cynics out there we can be pretty sure this is one area that really is checked when the transaction gets to the Issuer. For any Issuers out there who don’t do this you shouldn’t be in business.

There is no other data which could identify the cardholder personally. Some cards used to include the cardholder name in the contactless data but this is being removed.

So, as has been said before, we are talking about the collection of the PAN and Expiry Date. This is also the data that hackers are keen to retrieve from online systems and web-sites. Why should that matter?

Liability

The payments industry wants and needs to support commerce. There are few rules that state “you cannot do that!” They usually say “on your head be it!” So the Issuers through their schemes (Visa, Mastercard etc) state rules that determine who will pay if the transaction turns bad. This is not the same as preventing bad transactions in the first place.

In the press articles challenging the security of contactless payments you may have seen “an industry spokesman” stating the cardholders have nothing to worry about because the rules protect the cardholder from liability if the merchant or his acquirer does not provide the necessary security information. Bear with me as I explain what this really means.

What the payments industry expects is that transactions in a “card present” environment (e.g. shop) are submitted with PAN, Expiry Date and transaction related data including a cryptogram generated by the chip card. The cryptogram is generated from important details in the transaction (including the amount) and cannot feasibly be predicted outside the card chip and the Issuer security processor. Both contact (Chip & PIN) and contactless cards generate the cryptograms. The cryptograms act as proof that the card was involved in the transaction.

In a “card not present” CNP environment (e.g. internet) the chip cannot be used directly. Some banks have supplied cardholders with devices that can generate cryptographic codes either with a Chip & PIN card or as a stand-alone device. However, transactions using such devices are usually restricted to bank account operations. Today, the only feasible method of performing CNP transactions outside banking is to supply the PAN, Expiry Date and a special code printed on the back of the card (often referred to as the “Security Code”) which is not encoded anywhere else on the card. Using the Security Code shows you have (or had) access to the card.

Of course, the security of this fixed code in CNP is inferior to the changing cryptogram we get with card present. In an effort to increase security sometimes internet transactions are referred to something called “3D Secure” where cardholders are asked to enter various characters from a password. The positions of the requested characters changes and is not predictable. This helps prevent the fraudulent collection of passwords from a computer. Most security experts describe 3D Secure as “better than nothing”.

Provided the merchants follow these simple rules for making payments, the Issuer accepts the liability for the transaction (and hence the cardholder). So do merchants do this?

Merchant experience

Card present transactions use chip technology and provide the necessary data for Issuers and cardholders to be liable for the transaction outcome. The vast majority of cardholders have little difficulty with the Chip & PIN procedure.

The experience of internet merchants shows that each additional step following a decision to pay requiring further data entry leads to incomplete purchases and a significant loss of business. By registering a card you can avoid some steps. The internet merchants are not allowed to record the Secure Code values, so entering this is an extra step. Furthermore, 3D Secure can lose significant business (it is not hard to find many gripes online). I.e. additional security measures requiring effort from the cardholder leads to a loss of business. Therefore, a business case can be made for using only the registered PAN and Expiry Date for payment, building your own fraud-prevention systems and accepting the liability for transactions which prove fraudulent. This is what the internet giant Amazon does, for example.

The overwhelming majority of transactions are instigated by people who have every intention of paying. It may be argued that far more business can be achieved by simplifying the means to make a payment than is lost through the few who exploit the systems weaknesses. If it costs more to prevent all fraud, why not just pay for some of the fraud? Industry figures for fraud show CNP-based card fraud accounted for over 60% of the total (UK Cards fraud figures ) and the trend has been upward over the last 10 years, unlike other card frauds. This is what can make the PAN and Expiry Date valuable.

Impact on Cardholders

Issuers accept card payments with PAN and Expiry date on CNP transactions. If there is no Security Code, then the liability stays with the merchant. In practice this means that if the cardholder denies the transaction (repudiates) then the transaction is charged-back and the merchant may suffer the loss.

Clearly this procedure requires cardholders to check their statements. Checking statements is best practice and should be undertaken to ensure the transaction record is correct (looking for accidental, missing or duplicate payments – which should be rare). However, in effect, cardholders are also being asked to check against fraudulent transactions because the payment system may not adequately prevent them.

Impact on society

Some years ago after outlining how chip & PIN works to the Serious Organised Crime Agency (a Home Office NGO) I asked them about the idea of regarding fraud as a “cost of doing business”. The response was unequivocal in that ALL fraud is unacceptable. This is because many frauds are conducted by “Organised Crime” (whatever that means) and the proceeds invested in other criminal activities. There is serious social cost of accepting fraud and all measures must be adopted to minimise its occurrence within payment systems. If achieving that means regulation, then so-be-it. That was their opinion.

 A further analysis of the implications of fraud is contained here There's more to fraud than lost money .

It is also worth noting that a globally-based organisation which gains from the idea of some fraud as a cost of doing business may pay little or no tax in the country of operation. So the full costs to society of treating fraud in this way may not be paid by those responsible for those costs.

So what about contactless?

In summary, what is happening is that card details are being read using the contactless interface and used to fund an online purchase. This is easy to demonstrate and where no fraud is intended you would expect the purchase to work. It does. The question is, are the fraud-prevention measures of the online merchants sufficient to stop real fraud in this situation?

Obscuring or removing the contactless interface changes nothing. The PAN and Expiry Date are visible on the front of the card, although it may be argued that the cardholder is in a better position to protect this. Removing contactless cards will not make internet transactions any more secure, so at best would be a removal of one channel (not a particularly fruitful channel at that) for collecting PAN and Expiry Date. Some Issuers use a PAN which is contactless-specific.

There are many technical solutions to this problem. The difficulty with most is that we have to deal with an enormous global machine which uses accounts at its heart. The solutions evolved to date have effectively supplemented an account-based payment engine with security processes (authentication) but retain the basic account operation. As long as payment channels exist which bypass or provide potentially lower security then there is the potential for a “cross-channel” attack. The irony here is that the superior technology is in the spotlight for criticism.

The press articles around contactless are noise obscuring the real issue. Indeed, contactless transactions are much more secure than any other non-chip based transaction.

It’s also worth reading John Elliott’s excellent piece on this topic here A Touchy Subject.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

EMV got us into bad habits

Fraud is out of control in the UK. Identity fraud is half of all fraud in the UK. SME account takeover is one of the fastest growing categories of identity fraud. So if you are an SME and an identity fraudster gets hold of your bank account, you could be in trouble. Here's a current story from the UK press.

NatWest said AEV’s liability was based on the fact it breached terms and conditions of Bankline. It said that it had told the company via pages on its internet banking website and in emails that it would never ask for a Smartcard Pin, notwithstanding the fact users are expected to enter the Pin into the card-reader device.

[From Bankline fraud: NatWest business accounts hit by online scam | This is Money]

You can see their point. My bank is always telling me that it will never ask for my PIN. If a screen popped up asking for my PIN when I logged in to online banking then I would assume that I had been hacked and would shut down immediately and contact the bank. But I am an "expert", not a member of the public. If a member of the public sees a screen that they think is from their bank and it asks them for their PIN then they will give it, no matter how many times the bank has told them not.

Bank card fraud is at its highest level since 2009, despite investment by banks and retailers in better security features such as chip and pin devices.

[From UK bank card fraud increases as crooks dodge security - FT.com]

The fraudsters have become admirably more inventive since the advent of chip and PIN. For example, I imagine that banks have also told customers (repeatedly) not to hand over their cards and PINs to other people either, but that particular kind of fraud is booming.

"Courier fraud" involves criminals phoning victims pretending to be from an authority to extract pin details. The fraudsters then send a courier to pick up the victim's bank card. The Met Police said 143 people had been arrested on suspicion of courier fraud, since January 2011.

[From BBC News - London 'courier scam' victims lose £3m to conmen]

You can see why the public are easily hoodwinked by those phoney security calls when the real ones are so confusing. I get asked for all sorts of daft things when I'm trying to log in to do stuff or get some help on the phone. You know how it us: you phone up to sort something out on your cable bill and they guy asks you what your special word is and you can't remember if you had a special word, let alone what you might have told the cable company when they asked you twelve years ago. When I logged in to iTunes on my new iPhone the other day, I was asked for my favourite character on TV when I was at school! I must have chosen this as a "security" question at some point in the distant past, but naturally had no memory of such. I hazarded the guess of Sir Keith Joseph, but this turned out to be wrong, and I still can't buy anything from the US iTunes store.

So, yes, we can try and educate the public, but in the UK at least this is a waste of time, since a fifth of them are functionally illiterate. Alternatively, we could try and build a working identity and authentication infrastructure (and then manage the convergence of the infrastructure so that there is a single, shared experience when purchasing whether in-store or on-line). What's more, unless there is some serious work done in the industry in the near future, we have to face the fact that EMV is not that infrastructure and that chip and PIN is not going to save us.

Terry Dooley, senior vice president and CIO of EFT network SHAZAM noted that EMV implementation, as it is currently being done in the U.S., will not do much to prevent fraud unless it is coupled with PIN as opposed to signature authentication.”

[From Card Not Present.com CNP Expo: EMV Leaves CNP Out in the Cold - May 23, 2013]

We've already spent the money, so we have to keep working on chip and PIN. But if we hadn't spent the money yet, would we? Come on, be honest.

To prevent fraud, then, many companies are moving toward more identity-centered solutions and behavioral profiling to determine the level of risk for CNP transactions. Birch suggested that with the proliferation of mobile phones, the way forward will likely tie in to some form of mobile app payment, since customers’ phones already have chips, and customers are willing to put PINs into their own device.

[From Card Not Present.com CNP Expo: EMV Leaves CNP Out in the Cold - May 23, 2013]

Actually I said something slightly more controversial than that. I said that in the long run, EMV might turn out to have been a bad idea because it was a bad idea to train customers to enter their PINs into other people's devices (e.g., merchant terminals). It would have been better from an all round security point of view to have told people never to put their PIN into a device they didn't own and then issue everyone with a chip card reader!

Well, you might say, that's true from a purely academic security standpoint but in practical terms it would have been too expensive (I'm unconvinced about this, since it would have reduced CNP fraud and PCI costs as well). And, you might say, the personal device that you might put PINs into, the handset, is not secure anyway. Mobile malefactors and mountebanks the world over can send viruses and loggers and worms (oh my) into your handset to steal your PIN and other passwords and such like. Indeed, but there are two points to be made here that redress the risk analysis balance to make mobile use tolerable.

  1. Mobile has multiple protection factors (e.g., location) so even if your malware steals my PIN and your Eastern European hackers figure out how to make their mobile banking app look like my mobile banking app, they’ve still go to make their phone look like my phone and log in from a place where I might log in and so on.
  2. Mobile has a trajectory. I’ve written before about the move towards trusted processing in the handset and the evolution of the ARM Trusted Execution Environment (TEE) into “live” environments.

Now that handsets with trusted processing are wending their way toward to the market, they really should be on the roadmap for organisations interested in the secure electronic transactions in the retail marketplace. I’ll be down at the Global Platform TEE event in Santa Clara on 31st October 2013 to join in the conversation about mobile security and I look forward to seeing you all there. 

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Off the rails

[Dave Birch] A little while back, the always-interesting Tom Noyes raised an issue about "tokenization", a topic that is now (post-Money 2020) front and centre. Tom said that:

I am implying that banks could leverage their entire acceptance and authorization infrastructure without routing anything through V or MA.

[From Business Implications of Payment Tokens | FinVentures]

Tom's right. But, as I said at the time, let's not for one moment think that the folks at Visa and MasterCard are too dumb to have noticed this. Of course they have, and that's why they are working hard to develop propositions (e.g., wallets) that can deliver more value. Yes, bank tokenization could led to ACH-based solutions that bypass the schemes, but will they? Now we read that…

Visa, MasterCard and American Express want to overhaul global e-commerce security, ditching account numbers in favour of digital tokens for online and mobile transactions.

[From Finextra: Card giants bid to boost online checkout security with digital tokens]

Visa already has some experience with this, as I mentioned a few months ago when I wrote about BankInter's token-based approach to NFC. The BankInter mobile app generates a one-use PAN that is valid for a short time and passes this "token" to the merchant terminal. Since it is a standard PAN, it wends its way across the network back to BankInter, where it is converted back to the customer's debit PAN and authorised. Why bother doing this? Well, it means that the merchant (and the processor etc) never see the real PAN so it doesn't matter if it gets stolen, thus saving money on both fraud and fraud prevention. The solution re-uses the existing rails so it is not especially expensive to implement. This is hardly a new idea: one-use PANs have been around for yonks, but they are huge pain in the arse for consumers because they had to run something to generate the PAN, then copy it over to the whatever form you're filling out on the web. And there are other issues to do with refunds and so forth. But when a mobile app is doing it for them, consumers won't even know that it's not their "real" PAN that is being passed to the merchant.

This all sounds straightforward. Nevertheless we all, I'm sure, understand Tom's reasoning. When the first card network (Diners Club) was launched in 1949, the idea that there would be a free network connecting all of the consumers with all of the merchants and all of the banks was unimaginable (although not to science fiction authors – see Robert Heinlein's "Beyond This Horizon", for example) so it made complete sense to invent just such a network: by telephone and post, in the first instance, so that merchants would phone the network for authorisation and then send in their slips for payment. If you want to see how it worked behind the scenes in those days, check out the old Danny Kaye movie "The Man from Diner's Club" that I wrote about before. Magnetic stripes and automated authorisation, chip cards and 3D Security have made it all more efficient, but the basic concept hasn't changed. So, certain persons (e.g., merchants) say, why not? Now we have a network that connects all of the consumers and all of the merchants and all of the banks, so why don't we just use that? Why bother with Visa and MasterCard? Provided the consumer has some "token" to identify the relevant bank account, why can't they just give this token to the merchant and have the merchant go directly to the bank account to get their money?

One day soon, my Waitrose app will obtain tokens from my V.Me wallet, my MasterPass wallet, my PingIt app, my Zapp app and any other wallets it can find on my phone through a standard discovery process and standard API. Then when I check out at Waitrose, my app will pop up and take care of business. Maybe I will have configured my MasterPass wallet, which is where my John Lewis MasterCard will be stored, to allow the Waitrose app to charge £100 without additional authorisation.

Tom's right that this has significant business implications, which is why I was looking forward to his panel on the topic at Money2020. The tokens don't have to run over the conventional rails, which is why the schemes are moving to get a new standard in place quickly (and this is a good thing). So long as Waitrose don't surcharge, I will always have my app use my John Lewis MasterCard because I get cash back in John Lewis vouchers that I can use at Waitrose. I would always do this, rather than opt for the direct-to-bank payment mechanism, until such time as I am heavily incentivised not to. Tom says that

Each group is working to “lock out” others. Banks are working to lock up the ACH rails, V/MA are placing new network fees and controls, issuers are requiring tokens, retailers are locking up data and delivering financial services, MNOs are pushing SWP NFC.

[From Network War – Battle of the Cloud Part 4 | FinVentures]

Tom's point about ACH is an interesting one. Many industry observers have pointed out that a token front-end to ACH (either as a decoupled debit proposition or as a new low-cost bank-owned brand, like Zapp in the UK) might, given consumers' revealed preference for debit, being what many of the stakeholders would prefer. Except, of course, banks. They would (perfectly reasonably) point out that they have no incentive to move to this.

The network where banks have the most influence is ACH, yet they don’t want to encourage ACH use as there is no revenue.

[From Payment Tokenization | FinVentures]

Indeed. So there are two options: make them do it (rather like the Faster Payment Service in the UK), or couple ACH with non-payment revenue opportunities around data (the mobile wallet).

One final point about tokens for today. On Tom's panel, the discussion ranged around what I have taken to calling "weak" tokenization (ie, one-shot PANs) and what I have taken to calling "strong" tokenization (ie, the consumer's identity in some form or other). I will blog about this in the future, but I just wanted to note here that if the schemes were to adopt a long-term strategy to shift to strong tokenization, then I cannot see why this would be restricted to e-commerce. It would surely be logical to allow people to continue legacy card use at POS for limited purposes but to shift both card-present and card-not-present transactions to the "something present" model. Thus, as a consumer, I have the same payment experience whether in-store, online or via mobile. When I want to buy something, a message pops up on my phone asking me to authorise the transaction, which I do.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

American Paycho

[Dave Birch] My wife was very suspicious about my time in Vegas. I told her that nothing unsavoury had occurred, but unfortunately she had the proof. CSI:Woking had spotted that some undershirts in my suitcase had been packed neatly. Damn! She knows I never put away undershirts properly, so I was caught with my pants folded, so to speak. Cornered, I had to tell her the truth…

I love the Peter Rauhoffer “Doomsday” remix of the Frankie Goes To Hollywood 80s classic, “Relax”. It’s a track that genuinely benefits from the longer version, allowing the textures of the •music to evoke and to interweave to form a richer version than the original. Yet the nostalgia that I have for the original remains, refracted and enhanced through the remix. Perfect for a walk across the Aria concourse, into the guest elevators and up to the room.

Pulling on my Marks & Spencers cords, which I think still look good although they are last year’s sage green, I take the elevator down to the casino level. I’m not sure which way to turn, so I just stand there, people watching for a few minutes. A very attractive young lady walks up to me wearing a pair of Gap shorts. I think she must have recognised me from my Money2020 water bottle.

“Hey,” she says, “are looking for some company?”

Yeah, I tell her, I’m looking for Dwolla.

“Me too” she says, and suggests that we go up to my room and I give her five of the new Benjamins. I wasn’t sure if she misheard me because of the loud music or my accent.

I’m outraged by her suggestion, I tell her. Her proposition is disgusting and I reject it utterly. I find the $100 bill morally questionable will simply will not use it. But I am interested in her tender choices. “Have you tried Square?”, I ask her.

“No,” she tells me, and then goes on to say “and if you suggest PayPal, I’ll call the cops myself”.

I’m curious. So I ask her “Is this because of chargebacks?” (which is what I suspected) “or is there some other reason?”.

She ignores me. So I ask her whether future tokenised ACH-based solutions might be interesting to her because of the limited chargeback rights, but she tells me that she has suddenly remembered she has an important meeting. She presses a card into my hand and leaves. I can’t be bothered to read it so I slip it into my pocket.

You’ve got to take your hat off to the Money2020 folk. Out of nothing, they have created a star in the firmament of payments conferences. If you are in our industry, can’t not go. Everyone is there, and while is it undeniably exhausting to fit a year’s worth of meetings into a week, there is an efficiency to it that means the Consult Hyperion crowd will be there again next year.  I finish the meetings of the day and get ready for my session. I think that as there are a lot of bankers present I need to think carefully about my clothes. I think that a suit will hit the right note and luckily I’ve brought a dark grey one that will work. I picked it up a few years ago a little place in Manhattan called Men’s Wearhouse. I haven’t told the other guys about this place because I sort of want to keep it as my secret. If they find it they find it. I think the grey looks good with my white Thomas Pink shirt and my blue Manchester City tie.

After the session I decide that glass of champagne is in order so I head over to the exhibition hall where, as you might imagine, there are girls suspended from the ceiling pouring glasses of champagne as you walk underneath them. I don’t always feel like champagne, generally preferring a gin and tonic at this time of day, but I’ve seen some pretty positive tweeting about my session (it’s not every day that you are labelled the Obi-Wan Kenobi of moderators) so champagne seems appropriate even though it’s not what I really feel like. Conflicted.

Champagne

Once the alcohol starts to work, I can feel my anger started to burn. I thought I’d made the funniest joke in the entire history of payments conferences. One of the keynote speakers, who had presumably never seen the movie, said that Money 2020 was like Woodstock for payments experts and then went on to announce that his bank was about to launch an NFC product. So I said that he must’ve taken the bad acid. This is a joke that is hilariously funny on several levels. To see why you have to be familiar with the soundtrack of the 60s counterculture gathering. Rather famously, at one point in the soundtrack the stadium announcer warns people against taking the wrong type of acid (this is slang for the noted hallucinogenic lysergic acid diethelamide). Given all of the negative comments about NFC during the last couple of days, my joke was drawing a parallel between the hallucinogenic nature of our acid experience and the location of NFC in a bank strategy. I’m still laughing now thinking about it.

But goddam that Ron Shevlin. He pointed out that the soundtrack soundbite is actually a warning against taking the “brown acid” not the “bad acid”. Goddam that Ron Shevlin. Next time I see him, I’m going to have a nail gun and plenty of polythene sheeting in the trunk.

The best keynote was from Dan Schulman at American Express. He was dressed pretty casually, a carefully-assembled dress down Friday set, and I felt I echoed his outfit perfectly in my sage-green Marks & Spencer’s cords. He talked about financial services for the unbanked, which I will blog about at length shortly, and hit just the right tone. He’s talking about a big win-win.

I love JJ Cale. In fact I’d forgotten how much I love JJ Cale. When I was at college, I used to listen to JJ Cale all the time. “Have you heard the news, it’s same old blues again”. It’s country rock, I suppose, but more than the sum of the parts. When he died, they played a wonderful live version of “After Midnight” that I’d never heard before. Played it on Paul Jones show. So I googled around and found it, went over to Amazon and ordered the CD, but thanks to the brilliant Amazon download service I was able to load the tracks into my iTunes before the CD arrived. Great album, with an especially fun version of “Mama Don’t Like”.

Most fun technology play? That was definitely Loop with their induced magnetic field stripe simulator. Who knows whether it will work out. I was talking with some of the guys over coffee and there was a definite sense that using phones to simulate cards is not the long term trajectory, which is using phones to get rid of cards. At the end of the day though there were two technology threads that I thought would be most immediately relevant to our clients. One is tokenization, the other is “new POS” as you might call it. Tablets and APIs to deliver niche POS services. Companies like Leaf, for example. And the First Data Clover play in that space is sure to be significant. When I was Down Under last year I saw Commonwealth Bank demonstrate something similar and thinking that an app store for POS would lead to some innovation, part of the process of replacing special-purpose devices with general-purpose devices plus special-purpose software.

I wanted a relaxed look for dinner, so I went with the Marks & Spencer’s cords (I think Sage Green is a good look for dinner in such a dark restaurant) and went down. The guys were already at the table. We have a beer. I move around until I’m sitting next to the most attractive woman at the table. It takes negotiation because she is the only woman at the table. Sitting quietly, trying to think of something to say to her. The conversation wanders around until, suddenly, she transfixes me. Wow. She knows everything about the early history of Diner’s Club and how it lost out to American Express because of their heavy investments in technology. She knocks me out with the best piece of payments-related film trivia I’ve ever heard. In the 1963 Danny Kaye caper “The Man from Diner’s Club“, Danny is shown clowning around in front of the Diner’s Club computer, which looks exactly as you would imagine a computer might look in a film from 1963. But Diner’s Club didn’t have a computer, this was invented for the film. Wow again. What a woman. I ask her to go downtown with me, but she says she had a long day is off to bed. I wonder she thought it was a euphemism?

The defining album of psychedelic space rock, and one of the top ten best live albums of all time, is Hawkwind’s “Space Ritual – Alive in Liverpool and London” (1972). I walked through the casino with “Earth calling… this is Earth calling…” rebounding through my head like echoes in a crystal cave. The key changes in the remastered version of “Orgone Accumulator” are visceral. You can feel them reverberate through your body. It must be what the steady throb of life-support machinery in an interstellar spacecraft feels like.

I meet up with the guys and we decide to hit the tables. I want a more casual look, so I decide to go with the Marks & Spencer’s cord and my favourite Ralph Lauren shirt. We jump in a cab and head down to the Golden Nugget. I notice that none of them are dressed as stylishly as me, especially with my Boots light-tint glasses that I think round off the look perfectly. Downtown, I pay for the taxi ride using my watch, as I imagine most normal people would do in the circumstances.

Would you believe it! We end up at the Golden Gate, where it looks as if the gogo dancers are celebrating my good fortune. I’m $50 up from an evening of craps (which I was taught to play by American colleagues Lanny Byers and Howard Hall and ended up loving) and blackjack. I had the good fortune to find myself at the tables between a raven-haired beauty and a knockout blonde. Before you say anything there’s no hypocrisy here. We weren’t gambling with cash, but with casino chips. These are a kind of special-use currency (they would be exempted under the provision of the Payment Service Directive under the limited redemption exception) that you can only use in the specific casino that issued them. Like all currencies, they are a target for forgers. They looked pretty easy to counterfeit to me. Not especially secure at all, not like nuclear missile launch codes or something, which is why a dude in a hat keeps coming round at counting them while the cuties deal the cards.

The blonde seemed to know a fair bit about payments. She was a Brit, so she knew what a real-time payment system looked like. I’m glad I’ve run into her, because her bright white top looks great against my favourite Ralph Lauren shirt,  and because the Brit presentation about Zapp, the new bank-centric ACH solution for retail was one of the best panels I’d attended. I ask whether, in retrospect, it might have been better for the Brits to have gone with an ISO 20022 XML-based standard so that the payment system could carry additional remittance information. She becomes inexplicably drowsy and so she has to leave. It must be jet lag, I guess. I turn back to my left but she is gone too. I see her playing craps with the guy who won $5000 in gold in the SecureKey draw at the exhibition. Gold. Huh.

Walking back into my room at 4am I remember the card in my pocket, and I take it out. It says “call XXX-XXX-XXXX and we’ll have a girl in your hotel room in 20 minutes”. So I call and give my room number, and they say the girl is on her way. I tell them that she needs to bring a Coke and some potato chips. When the girl arrives, she’s tells me she’ll do whatever I want, so I give her some Tide hand wash and send her into the bathroom with my undershirts and pants while I settle down to enjoy my refreshing beverage and overcome my night starvation. She dries off my smalls with the hairdryer and folds them neatly into my suitcase. It’s Las Vegas people. It’s cheaper to get a hooker than to use the hotel minibar or laundry service. Anyway, getting that girl was was the fatal error. I should have put the smalls back in the suitcase myself, then I’d have got away with it.

Heading out to the airport I put Serena Ryder’s “Stompa” on a loop. It’s a lovely confection, stirring together what sounds to me like a little bit of country (although other people say that they can’t hear this), a little bit of dance and a little bit of rock to make a delicious new flavour. Something you can’t stop eating, like the Ben & Jerry’s ice cream that we were given at Money2020 last year.

I’m going home via New York. A detour out of the City to see a special lady in Brooklyn. I decide to go with sage green Marks & Spencer’s cords, and I pull on my favourite Ralph Lauren shirt to go with it. The shirt is old and the collar is torn. The shirt was old when I got it from the thrift shop. Well, truthfully, my sister-in-law got it from the thrift shop for me. Long story that involves Bill Gates, but that’s for another time. The shirt has just the right weight and cut for me. It’s comfortable and stylish, but it’s finished. I have a spot in the garden for it when I get home. I pull on my Eddie Bauer rain jacket (it’s raining) and complete the look with a pair of Boots light-tint prescription glasses. I take the F-train to a little spot she tells me about. I walk in and immediately notice that there’s an iPad with a Square stand where a POS terminal should be.

Coffee-Shop POS

I ask the girl behind the counter about her POS choice. She tells me that they used to use the audio jack reader but it was unreliable. She loves the new arrangement and is very happy with it. I ask her about cardless choices and she tells me that people do occasionally pay with the iPhone app and she finds it convenient when they do. Nice. She swipes my Simple and I entirely pointlessly sign for the transaction. I spend a few minutes explaining my anti-fraud strategy to her (amazingly she’d never heard of Sergio Aquero, two-goal hero of Manchester City’s 3-1 triumph over Everton last weekend) and showed her my watch. I think she wanted to learn more, but she told me that she’d just heard that her grandmother was sick and she had to leave right away. Oh well.

Signed and Sealed

When I get back in to the City, I meet up with a couple of old friends and we go for a coffee down by Union Square. We stroll in to the coffee shop.

“Check that out”, I whisper as we stand in the line. I gesture at the window, trying not to draw too much attention to myself.

“What?” says my colleague, staring through, not at, the decals in the window.

“Come on, ” I urge them, “really look”. But they don’t get it, so I have to go and show them. The coffee shop has LevelUp and PayPal logos in the window. I have no choice but to try both of them, so I get in line and order a coffee and pay using PayPal Here.

Dave Birch & Graffiti-0274

Then I get in line and go round again and pay with LevelUp. Both of them work perfectly. The dynamic is good, because I have time standing in the line to run the relevant app and then the transaction itself is super quick. And in both cases I get the receipt e-mailed to me, which I love, because I hate standing there waiting for a printer to churn out a paper receipt (is this regulation “E” or regulation “Z”?) that I have no interest in and immediately throw away. I ask the girl behind the counter about her preferred options and she says that she likes LevelUp, but she doesn’t say why. Maybe not everyone has as distinctive a cartoon caricature in their PayPal wallet.

Dave Birch & Graffiti-0285

A psycho is a person with a mental disorder that makes them prone to behaviour that normal people would regard as abnormal, but that the subject regards as completely normal. A paycho is a person with a mental disorder that makes them prone to believe that normal people think that electronic payments are fascinating, absorbing and central to their lives. For most of the year, I’m just a regular paycho. But for one week every year, I’m an American Paycho.

(With sincere apologies to Brett Easton Ellis.)

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Pals in Palo Alto

[Dave Birch] Well we went off to our first ever Bay Area Tomorrow’s Transactions Unconference. For those of you not familiar with these, “Tomorrow’s Transactions” is Consult Hyperion’s brand for our thought leadership activities in digital identity and digital money (hence the Tomorrow’s Transactions Blog and the Tomorrow’s Transactions Podcast and the Tomorrow’s Transactions Forum), and an Unconference is the use of “open space technology” in events where the agenda for the day is chosen by the participants. Hope you get the picture. If not, here’s one of Gloria Benson welcoming me to the Palo Alto Golf and Country Club for the day!

Untitled

One of my very favourite authors, David Wolman, kicked the day off by reading from his book “The End of Money”“, a copy of which was provided for each of the delegates, and then he joined me on stage for a “fireside chat” with a couple of questions from me to get things started and then questions from the delegates.

Untitled

After David and I had spent some time speculating about the trajectory of cash in the retail payment space, Nate Wehunt from City National Bank mounted a strong defence for the physical and took the opportunity to announce their new cardless ATM product, whereby you go to an ATM and ask for money, the ATM displays a QR code that is scanned by your City National app. You authenticate on the handset and then the cash drops out of the machine. Excellent idea, although it still wouldn’t persuade me to use cash anywhere other than strictly necessary, such as Las Vegas, to pick a random example.

Untitled

Somebody asked me if there was anything that surprised me about the day and I have to say that there was and it came from an unexpected direction. After we gathered in the notes in the morning, I saw that there were quite a number of notes asking questions about payments regulation and making observations about the role of payments regulation in innovation. I thought regulation would be a bit boring and that no one would want to talk about it, so I gathered those notes together for an afternoon session and I thought that, since I couldn’t really ask anybody else to do something I thought would be boring, I chaired the table myself. It turned out to be fantastically interesting. Not only were there people at the table who had practical, day-to-day, experience of dealing with US payment regulations, there were people who had interesting ideas about how the regulations could be improved. It was terrific.

Untitled

My main takeaway from that session was that the people running payment-related businesses weren’t as upset as I thought that they would be about the patchwork nature of US regulation and, in particular, the need for state-by-state licensing for money transmission businesses, because from a business point of view the costs of identity-based compliance were far, far greater. The people round the table were telling me that the cost of know your customer (KYC), anti-money-laundering (AML), and anti-terrorist financing (ATF) regulations (now collectively known as CDD, “customer due diligence”) were the focus of concerns because the associated costs are high and ongoing. I thought I’d make a useful contribution to the group by bringing in the issue of the Financial Action Task Force recommendations on a risk based approach to payment regulation, which I’ve written about at length before on the blog, and by being optimistic about how improvements in the identity infrastructure might help.

One point I could have made, but didn’t want to make too much of the conversation about the UK, was that there are some discussions underway in a number of fora (such as at Intellect, the UK IT trade association, and the Payments Council) about the idea of some kind of financial services passport. Maybe something like this could really help in the US as well. The FIDO Alliance, which was the subject of informed discussion at one of the other tables (because Phil Dunkelberger, their CEO, took part in the discussions) are providing hope on the authentication front and this might be combined with hope from the federated identity side to at least make the vision plausible. I might imagine such a passport being used to open bank accounts, obtain new credit cards, get insurance, manage investment accounts and so on.

This could greatly reduce the costs of CDD, especially if the federated “recognised” customer identity was mutually recognised by the banks and the regulators. So I show up in the US and open up a Simple account, Simple have to bear the cost of the initial CDD, but in addition to giving me an account they give me my financial services passport so that the next time I go to open an account, get a post-paid mobile phone, or get a new credit card then I can just use that Simple passport and no one has to go through these costs again.

But back to regulation. One topic that came up in passing was the European Commission’s consultation on third-party direct access to bank accounts (the so-called XS2A consultation). I will blog about this properly later on but I do want to make the point that it’s an example of a potential regulatory change that may seem obscure from a distance but is actually quite revolutionary if it is adopted. If I can give a third-party permission to access my bank account, much as I give applications permission to post to my Twitter account, then I would think that a great many service providers will opt to go down that route rather than use conventional card networks and this has obvious strategic implications for people investing in the cards businesses. One of them might be, as I’ve long suspected, that the son-of-EMV will be identity driven and more about the passport than the payment.

Lanny leads the discussion

There were great tables about EMV in the USA and the impact of recent announcements about tokenization on retail payments strategies, key trends in the security space, the design of new payment networks and so on. As far as I could see every single table generated a buzz of discussion and people came away feeling that they’d learned more than had I forced them to sit in rows and read PowerPoint.

We had a nice interlude before lunch. Through the superpower of Twitter I discovered that Forum friend Heather Schlegel was in town, so I asked her to pop over and tell people about her new project, the Future of Money TV series. Heather is, as she put it, eating her own dog food by raising money for the series on Kickstarter. I’ll be supporting Heather’s project and I hope that you will too.

Untitled

Then it was out to lunch in the beautiful California sunshine where, as you might expect, we spent most of the time discussing the Umberto Eco’s admonition that we should not be nostalgic for Disneyland as a post-modern explanation for the relationship between the gold standard and Bitcoin, amongst other things.

Untitled

After my thought-piece reviewing some predictions about the future of money from 1998 (I’ll put these in a separate blog post), we had our second round of discussion tables and then we gathered around to join a terrific session led by Sam Lessin, Head of Identity Products at Facebook.

Untitled

Sam grabbed a pen and a flip chart and proceeded to make everyone really think about the role of transactions in the future. I will not attempt to repeat any of Sam’s excellent riffs on the balance between financial and social capital except to observe that on the relevant value of social and financial capital. He said that if all of his financial capital vanished then his social capital would mean that he could rebuild it, but conversely if his social capital disappeared than it would be much harder for his financial capital to restore it. (Although, as Spike Milligan famously observed, while money may not buy you friends, it does buy you a better class of enemy.) I hope I didn’t annoy Sam by pointing out that Shakespeare had thought of this first! Anyhow, I intend to refer to Sam’s model in a book I’m writing at the moment, so more on this later.

I hope the implications of what Sam was saying were not lost on delegates from the world of banking (ie, identity is the new money). A decade from now, Visa and MasterCard might well be switching your identity, your credentials and your reputation as much as they are switching your ability to pay for something. Making the bank the place that stores your identity, since you can store your money anywhere, makes sense in a world where (if Sam is right) social capital re-asserts its superiority over financial capital.

We had an extended Q&A with Sam, exploring facets of the reputation economy, and then wrapped with coffee, more dessert and sunshine networking. I’d said at the beginning of the day that we run the Unconferences to get new ideas, and that the best way to get new ideas was to give your ideas away for free. Palo Alto proved that calculus of creativity to be substantially accurate.

These are personal opinions and should not be misunderstood as representing the opinions of�
Consult Hyperion or any of its clients or suppliers

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Britain’s no longer number one and I for one am celebrating

At the UK Card Association autumn reception, which was rather splendidly held on the walkway over Tower Bridge, giving an excellent view of the city of London by night, forum friend Melanie Johnson, the Chair of the Association, gave a super talk about pickpockets and prostitutes and there was much good cheer. Melanie used to be a politician but she's really nice and it was a pleasure to see her again. In her talk she mentioned that the industry has had some success in reducing card fraud, but I feel that she missed the opportunity to celebrate a tremendous milestone in the evolution of our card payments industry. So let me do it for her…

Untitled

I couldn't resist raising a glass of the champagne so liberally supplied and making to a toast to our friends across the water. Yes, the UK is no longer the card fraud capital of the continent. France has overtaken us and, as the chart below shows, while there's a really big drop off to the number three position, we should be pleased to be number two for a change.

European Card Fraud mid-2013

In France, overall fraud losses have risen by two-thirds in the last five years, with the highest lost-and-stolen fraud levels in Europe. Although fraud is rising in the UK (up 14% last year and up even faster in the first half of 2013) it is still below its historic high.

The number of frauds against plastic card accounts (e.g. credit or store cards) rose by 19% in first half of 2013 compared with the last six months of 2012. Frauds targeting loan products (personal unsecured loans and payday loans) also increased markedly over the same period.

[From Plastic card account fraud (e.g. credit or store cards) rose by 19% in first half of 2013]

Despite our sterling efforts (sic), it is Russia that has the fastest card fraud growth rate. Overall, card-not-present fraud is booming everywhere, but the UK issuers have spent a lot of money on fraud detection, as evidenced by the phone calls I get from my issuers from time to time. I get robocalls from my bank asking me to confirm transactions (some of which, if I recall, were chip and PIN transactions), a chap from an issuer asking me if I used my card for something or other online which I couldn't remember but turned out to be a shareware licence fee (which, as I recall, was a chip and PIN transaction) and a message asking me to call Amex to see if I'd used my card in Detroit car wash (I hadn't, and my new Amex card arrived yesterday).

You can see how, from the card industry point of view, things aren't too bad. According to the UKCA's annual report for 2013, fraud on UK-issued cards is a touch over six basis points (a decade ago it was over 13 basis points) so the investment in chip and PIN has worked. But this is a narrow analysis. Yes, chip and PIN has made some impact on card-present fraud (although criminals are coming up with ever more sophisticated scams to get hold of cards and PINs), and yes, significant industry investment in various types of fraud prevention and detect systems has stopped card-not-present fraud from zooming off the scale, but this has been at the expense of other stakeholders. The costs have been transferred to merchants and consumers and law enforcement.

If we were keeping a lid on fraud, then all of these costs (e.g., PCI-DSS costs) could be justified and (perhaps shared more fairly) sustained. But they are not. Fraud is going up and the cost of fraud is going up too. LexisNexis reckon that every dollar in fraud loses merchants almost three dollars in total costs. When we as industry add up the total costs of fraud, the costs of fraud prevention and the associated costs that fall on others (e.g., the cost of handling chargebacks) then the picture is not so rosy. Chargebacks are a particularly interesting case: I mentioned before that the most interesting panel that I attended at the CNP Expo this year was the one about chargebacks. I suppose like a lot of people in the payment space I don't spend too much time thinking about the retailers' issues with chargeback management, but these costs are high.

Results of the LexisNexis Fourth Annual True Cost of Fraud Study drive home this point. Conducted by Javelin Strategy & Research, the study calculates the overall cost of chargebacks for merchandise, as well as fees and interest paid to financial institutions and processors to replace and redistribute lost or stolen merchandise. In 2012, that cost worked out to $2.70 for every $1.00 in fraudulent transactions, up from $2.30 in 2011, and that doesn't count costs associated with lost business.

[From The Green Sheet :: E-Magazine]

The costs are not distributed evenly, as you might imagine.

Merchants hardest hit by card fraud are those with mobile, e-commerce and international transactions, the LexisNexis report revealed. In 2012, mobile merchants paid $2.83 for every $1.00 lost, compared to just $2.00 in 2011.

[From The Green Sheet :: E-Magazine]

At that expert panel on Best Practices for Chargeback Management, I learned a lot about the nature of these costs. For example, I learned that criminal fraud using stolen credit card information is the most visible source of chargebacks for merchants, and the most prevalent kind of fraud. Jim Rice, director of market planning for LexisNexis, said during the session some two-thirds of a US merchant’s fraudulent transactions, on average, originate from professional fraudsters using stolen credit-card information. It is just too easy to steal card data and then go and use it. But there's a growing problem for merchants in "friendly fraud", where a cardholder or accomplice makes a card-not-present purchase, receives the goods and then calls the card issuer or merchant and claims he never received it. Rice noted that friendly fraud accounts for a fifth of all fraudulent transactions and that it is more costly to merchants than traditional criminal fraud because it is more expensive to investigate. Jim also pointed out that sometimes chargebacks are not the result of nefarious actions on the part of outsiders at all but stem from the operational processes of the retailers themselves. In fact, an otherwise healthy merchant can expect more than a fifth of their chargebacks to be caused by business process failures.

I think that latter problem is going to get worse. It happened to me a while back when I saw a charge I didn't recognise on my card statement and called up to put it into dispute. It subsequently turned out to be a perfectly valid charge, but it was for a transaction in Spain (where I had been) that was acquired through a French parent company leading to a reference that meant nothing to me. While I was puzzling over the charge ("What is this? I didn't go to France last month") and pointlessly clicking on the online statement for more information (there wasn't any – my issuer knew no more about it than I did). Hopefully, when we get working digital wallets, this problem will go away because my wallet will link the charge and the receipt for me.

In the last two decades we've stuck some band-aids on cards and shoehorned them into new channels while avoiding fundamental changes to the legacy infrastructure. It's time for change. We need to start work on post-internet infrastructure that reduces the costs of fraud and shares those costs fairly across the stakeholders in proportion to the risks that they are prepared to take. Some retailers might prefer a high risk, low cost option (rather like they do in Germany) whereas other might prefer a lower risk but higher cost option. I might mention this idea to a few people at the Merchants & Payments Conference in London in October. Consult Hyperion are one of the sponsors for this excellent event (I've had a heads up on the delegate lists and I'm really happy to see so many merchants coming along – it signals to me that payments have become interesting to them again) and I'm looking forward to chatting to John Lewis, IKEA, Carrefour, Aurora, Waitrose and others to find out what they want from the next-generation payment products. See you there.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

Missing transactions

[Paul Makin] Consult Hyperion are strong advocates of mobile money – we believe that not only does it offer the best route for financial inclusion, it also represents the next generation of financial services, unencumbered by legacy issues and constraints.

So we’re disappointed to note that, of the 191 services that are apparently live (according to the Mobile Money Tracker), very few of them have reached that milestone of 1 million customers – the level at which they can be viewed as a profitable, successful service. In fact, rather less than 10% have reached this point.

Why are so few reaching this milestone? We contend that in many cases it’s to do with relevance to most customers’ lives. Much of the industry is founded on watching M-PESA, and doing what they do: to paraphrase, “M-PESA is built on domestic remittances (P2P), and M-PESA is successful, so we must do the same”. But Kenya is different from many other countries in having such a strong culture of domestic migration. The consequence is that very few services have been able to build a base of regular and sustained P2P transactions. And since the profitability of mobile money services is largely determined by the number of transactions they carry out rather than the amount spent, they need to find other transactions beyond P2P if they are going to prosper.

Consider this. The large majority of the unbanked populations in emerging markets do not have access to refrigeration, so that they need to buy fresh food every day. Whether they buy the staples from a small shop or from a market trader, it is likely that this amounts to (say) one transaction a day, or 7 over the course of a week. In even the most optimistic scenario where a customer receives a P2P remittance from a relative once a week, these small retail transactions outnumber P2P by 7:1!

Addressing Retail

So if retail transactions are the answer, the question becomes “how?” Merchants are not going to be willing to sign up to multiple mobile money operators with the attendant inconvenience of using multiple MMO handsets with multiple transaction experiences and making multiple claims for settlement in order to accept payments, and so an interoperable solution is needed.

The conventional answer to this problem is the payment switch: someone – probably a bank or a large international payments organization – should be tasked with providing a switch, connecting all of the merchants, banks and mobile money operators, and giving customers a card. This familiar solution, the standard model in the so-called developed world, has evolved over five decades to overcome limitations such as the difficulty of communication, the limited availability and power of computers, and the reliance on paper for confirming contracts.

But emerging markets are coming to this need for interoperable payments with a blank sheet, to which none of these limitations apply: we have powerful mobile telecommunications, mobile phones which exceed the power of the fastest supercomputers of 30 years ago which can all interconnect via the mobile Internet, and an understanding of modern cryptography. Taken together, these factors give the emerging markets the potential to leapfrog the rest of the world and to adopt a truly modern approach to payments interoperability.

WinguPay

Consult Hyperion have developed such a solution. We call it WinguPay. It:

  • Allows complete interoperability for retail/merchant payments across participating mobile money operators and banks;
  • Uses a single merchant smartphone or POS terminal for all transactions;
  • Makes no assumptions about the capabilities of the customer’s mobile phone;
  • Does away with the need for a switch;
  • Does not require the retailer to have multiple accounts – his/her account can be at any participating mobile money operator or bank;
  • Uses public key cryptography to ensure the integrity and confidentiality of transactions;
  • Uses NFC technology to enable customer identification.

The details of WinguPay are too complex to set out in this blog post.  I’ve prepared a White Paper, which may be downloaded at:

http://www.chyp.com/assets/uploads/Documents/2013/09/White_Paper-MM_Interoperability-Introducing_WinguPay_V0_8.pdf

Of course, adopting WinguPay is not sufficient. There also need to be changes in tariffs, of which more in another blog post.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.