Tomorrow's Transactions » cdd http://tomorrowstransactions.com Thought leadership from Consult Hyperion Fri, 18 Jul 2014 06:22:13 +0000 en-US hourly 1 http://wordpress.org/?v=3.9.1 What about a financial services passport? http://tomorrowstransactions.com/2014/07/what-about-a-financial-services-passport/ http://tomorrowstransactions.com/2014/07/what-about-a-financial-services-passport/#respond Wed, 09 Jul 2014 19:53:08 +0000 http://tomorrowstransactions.com/?p=4510 The problems around KYC for new financial services, especially for new entrants, might be mitigated by the introduction of a financier services passport based on modern technology and not stupid bits of paper. There was a great story on BBC Radio recently. It caught my attention because it demonstrated faults with our useless and outdated […]

The post What about a financial services passport? appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

The problems around KYC for new financial services, especially for new entrants, might be mitigated by the introduction of a financier services passport based on modern technology and not stupid bits of paper.

There was a great story on BBC Radio recently. It caught my attention because it demonstrated faults with our useless and outdated cheque payments system and our useless and outdated identity infrastructure at the same time.

A listener posted a cheque for £36,000 to his bank. It was stolen and paid in by someone else to an account in approximately his name. £20,000 was withdrawn. Barclays, his bank, have agreed to refund him only the balance of £16,000. What are his rights? And will the new cheque imaging service be any safer and quicker?

[From BBC Radio 4 - Money Box, Wonga woes]

During the episode, the bank is quoted as saying that their cashiers are not experts in identification. Indeed, They are not. Which is why the business case for KYC and AML and ATF stuff is so confused. What is the point of asking people to present documents that cannot possibly be verified? How is the poor chap at the bank counter expected to know whether my Portugese fishing licence is still valid or not? Clearly the fraudster had to present some documents to open the account.

If you’re applying for a Barclays Bank Account or a Premier Current Account you’ll need to show us 2 valid and original documents from the list below -  one from the proof of ID list and the other to give proof of your current UK address. The same document cannot be used to verify both your identity and your address.

[From Identification for bank accounts]

Clearly, the documents presented were fraudulent. I’m not picking on Barclays, obviously. This is a general problem across jurisdictions and banks. While it is complicated and expensive and annoying for legitimate customers and business to comply with stupid KYC requirements, it is apparently trivial for the criminals to do so.

There is no point having an identity infrastructure where it is impossible to verify identity. On the other hand, an infrastructure that means identity is verified at every turn is invasive and open to abuse. We have a system that delivers neither, and costs a fortune.

KYC Exchange estimates that whereas a KYC request might take 30 – 50 days to turn around using standard industry measures, its own system can do the same work in five minutes. The time saved for a bank initiator is estimated at approximately 90%, while the receiving bank saves around 40-50%, according to von Hänisch.

[From Cost of KYC too high says Swiss start up » Banking Technology]

Maybe KYC Exchange could then issue a Financial Service Passport of some kind? There’s a thought. I’ve been with Barclays for 37 years: perhaps they could provide me with some sort of app on my smartphone that I could use to present KYC credentials when I want to take out insurance or get a mortgage or rent a house or anything. This is the sort of thing that I think we will be discussing at techUK next Monday, where Ian Jenkins of Deloitte and I will be chairing a discussion around the concept:

A ‘financial services passport’ refers to an aspirational digital identity, issued by UK financial services providers, and mutually recognised across the financial services industry. Such an interoperable digital identity could be utilised to correctly identify and authenticate end-users with appropriate security in a wide variety of circumstances and across a wide variety of channels.

[From Workshop: Towards a Financial Services Passport]

Look forward to seeing you there.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post What about a financial services passport? appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/07/what-about-a-financial-services-passport/feed/ 0
Payment system regulation as barrier to payment system innovation http://tomorrowstransactions.com/2014/06/payment-system-regulation-as-barrier-to-payment-system-innovation-2/ http://tomorrowstransactions.com/2014/06/payment-system-regulation-as-barrier-to-payment-system-innovation-2/#respond Mon, 16 Jun 2014 15:01:17 +0000 http://tomorrowstransactions.com/?p=4485 If we want more innovation, we need more competition, not more regulation. There was a good article back in the September “Financial World” magazine arguing that transparency is a key to regaining confidence in the banking system. I agree strongly, and I’m not the only one. More transparent record keeping would allow law enforcement to […]

The post Payment system regulation as barrier to payment system innovation appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

If we want more innovation, we need more competition, not more regulation.

There was a good article back in the September “Financial World” magazine arguing that transparency is a key to regaining confidence in the banking system. I agree strongly, and I’m not the only one.

More transparent record keeping would allow law enforcement to trace the transfer of funds and identify those responsible for the illicit use or theft of virtual currency.

[From Virtual Currencies, Real Theft - Javelin Strategy & Research Blog]

Indeed it would, and some might argue that that transparency be extended to legacy infrastructure as well. (It’s not really the topic of this post but remember than transparency need not subvert privacy. You could have pseudonymous dark pools but force the release of linked identities given a warrant, for example.) If, however, transparency is taken to mean thorough KYC/AML/ATF procedures (henceforth known as CDD, or customer due diligence) that identify all participants to a transaction to all observers, then it will force criminals, terrorists and corrupt politicians to abandon electronic means of exchange and go back to cash. If that happens, then we are all worse off. Having some traceability is better than having none at all, as I’ve argued before. And it’s not as if having rigorous CDD solves the problem.

Worse still, the increased cost associated with a tougher stance on KYC does nothing to make the system any more secure, and may in fact drive up risk rather than reduce it.

[From Cost of KYC too high says Swiss start up » Banking Technology]

I suppose you could argue that what is driving the players at the moment is not risk but liability. So long as they can shift the liability onto someone else, no-one really cares who you are. The system is broken.

The two set up 68 accounts in 19 different cities using 24 aliases to handle the transfer of funds and sent the bulk of the money to individuals in Nigeria, who set up the operation. Money was also wired to addresses in the UK, Ecuador, India, the United Arab Emirates, and the US, none of which has been recovered.

[From Mother/daughter team jailed for million-dollar internet dating scam • The Register]

Hold on. 68 accounts using 24 aliases? What was the point of the billions of dollars spent on KYC, AML and ATF? And why am I going on about this anyway? Well, in her keynote at Payments Innovation 2014, Mary Starks (the acting MD for the UK’s new Payment System Regulator) said that on the whole regulators “don’t do innovation”. I was on the panel with her, so I made what I think was a reasonable point that the best regulatory approach to innovation is competition, and that a focus on reducing the barriers to entry to payments markets that do not involve systemic risk is probably sufficient. We don’t need to imagine what people might come up with, we just want to make it easy for them to do so.

When it came to the discussion that followed, I used CDD as an example of such a barrier. The costs and complexity of CDD can make it very difficult for new entrants, especially those dealing with low-value payments, the excluded and specialist niches to get off the ground. One of the reasons for this is that there is no infrastructure for them to plug in to, so everyone has to build everything from scratch.

Surely all of this dialogue about passports and utility bills, declarations and signatories and KYC and AML is pushing a demand for a new digital infrastructure to cure all of this mess.

[From Digital identities demand a digital infrastructure | Banking View]

Karen Wendel from Identrust talked about the infrastructural approach in her presentation as well, and this all links to the discussions about the idea of a financial service passport (or a “pay name”) at techUK last year. I really think that the idea of pseudonymous, strongly-authenticated CDD-inside identities is an idea whose time has come. I should be able to participate in a transaction as John Doe, provided that I can prove that someone (e.g., my bank) knows who John Doe actually is and that is is someone who has been approved after CDD. You don’t need to know who I am to do business with me, so long as you know that someone knows who I am.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Payment system regulation as barrier to payment system innovation appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/06/payment-system-regulation-as-barrier-to-payment-system-innovation-2/feed/ 0
Payment system regulation as barrier to payment system innovation http://tomorrowstransactions.com/2014/05/payment-system-regulation-as-barrier-to-payment-system-innovation/ http://tomorrowstransactions.com/2014/05/payment-system-regulation-as-barrier-to-payment-system-innovation/#comments Fri, 30 May 2014 18:43:54 +0000 http://tomorrowstransactions.com/?p=4457 The new payment systems regulator is tasked with increasing innovation. This means increasing competition, which means reducing barriers to entry. There was a good article back in the September “Financial World” magazine arguing that transparency is a key to regaining confidence in the banking system. I agree strongly, and I’m not the only one. More […]

The post Payment system regulation as barrier to payment system innovation appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

The new payment systems regulator is tasked with increasing innovation. This means increasing competition, which means reducing barriers to entry.

There was a good article back in the September “Financial World” magazine arguing that transparency is a key to regaining confidence in the banking system. I agree strongly, and I’m not the only one.

More transparent record keeping would allow law enforcement to trace the transfer of funds and identify those responsible for the illicit use or theft of virtual currency.

[From Virtual Currencies, Real Theft - Javelin Strategy & Research Blog]

Indeed it would, and some might argue that that transparency be extended to legacy infrastructure as well. (It’s not really the topic of this post but remember than transparency need not subvert privacy. You could have pseudonymous dark pools but force the release of linked identities given a warrant, for example.) If, however, transparency is taken to mean thorough KYC/AML/ATF procedures (henceforth known as CDD, or customer due diligence) that identify all participants to a transaction to all observers, then it will force criminals, terrorists and corrupt politicians to abandon electronic means of exchange and go back to cash. If that happens, then we are all worse off. Having some traceability is better than having none at all, as I’ve argued before. And it’s not as if having rigorous CDD solves the problem.

Worse still, the increased cost associated with a tougher stance on KYC does nothing to make the system any more secure, and may in fact drive up risk rather than reduce it.

[From Cost of KYC too high says Swiss start up » Banking Technology]

I suppose you could argue that what is driving the players at the moment is not risk but liability. So long as they can shift the liability onto someone else, no-one really cares who you are. The system is broken.

The two set up 68 accounts in 19 different cities using 24 aliases to handle the transfer of funds and sent the bulk of the money to individuals in Nigeria, who set up the operation. Money was also wired to addresses in the UK, Ecuador, India, the United Arab Emirates, and the US, none of which has been recovered.

[From Mother/daughter team jailed for million-dollar internet dating scam • The Register]

Hold on. 68 accounts using 24 aliases? What was the point of the billions of dollars spent on KYC, AML and ATF? And why am I going on about this anyway? Well, in her keynote at Payments Innovation 2014, Mary Starks (the acting MD for the UK’s new Payment System Regulator) said that on the whole regulators “don’t do innovation”. I was on the panel with her, so I made what I think was a reasonable point that the best regulatory approach to innovation is competition, and that a focus on reducing the barriers to entry to payments markets that do not involve systemic risk is probably sufficient. We don’t need to imagine what people might come up with, we just want to make it easy for them to do so.

When it came to the discussion that followed, I used CDD as an example of such a barrier. The costs and complexity of CDD can make it very difficult for new entrants, especially those dealing with low-value payments, the excluded and specialist niches to get off the ground. One of the reasons for this is that there is no infrastructure for them to plug in to, so everyone has to build everything from scratch.

Surely all of this dialogue about passports and utility bills, declarations and signatories and KYC and AML is pushing a demand for a new digital infrastructure to cure all of this mess.

[From Digital identities demand a digital infrastructure | Banking View]

Karen Wendel from Identrust talked about the infrastructural approach in her presentation as well, and this all links to the discussions about the idea of a financial service passport (or a “pay name”) at techUK last year. I really think that the idea of pseudonymous, strongly-authenticated CDD identities is an idea whose time has come. I should be able to participate in a transaction as John Doe, provided that I can prove that someone (e.g., my bank) knows who John Doe actually is. You don’t need to know who I am to do business with me, so long as you know that _someone_ knows who I am.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Payment system regulation as barrier to payment system innovation appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/05/payment-system-regulation-as-barrier-to-payment-system-innovation/feed/ 2