Protecting Customers from STP: A Case of Polish Banking Jurisdiction
Although it could seem that the EU regulations concerning cross-border payments are a step forward towards the wider introduction of straight-through processing (STP) into the EU banking industry, the reality looks different sometimes. The local jurisdiction may clash with the principles of this regulatory, pro-STP environment, practically reversing payment processing to the age of manual intervention. This article claims that the unfortunate prevailing force of such jurisdiction should be annulled by the proper introduction to the legal system (at least at the local level) of the regulations concerning the ways payment orders should be placed. In particular, such regulations should allow the payment industry to enjoy all the benefits resulting from the introduction of account numbering based on IBAN (international bank account number) and BBAN (basic bank account number) concepts.
Once upon a time (in 2001) a small Polish economic enterprise (hereafter: “P” like “payer”) decided to send a local payment to its beneficiary (hereafter: “B” like “beneficiary”). P placed the payment order with its bank (hereafter: the “Originating Bank”). The payment order included the name of B written in the “beneficiary’s name” field, but – by P’s mistake – it also included an existing account number of another entity (not B) in the “beneficiary’s account number” field. The Originating Bank, upon receipt of the payment order, debited the account of P and directed the payment, via electronic clearing, to the bank that was indicated by the content of the “beneficiary’s account number” field. The bank that received the payment from clearing (hereafter: the “Receiving Bank”) – in a way typical for STP – immediately and automatically credited the account indicated in the “beneficiary’s account number” field (account of the “receiver”, hereafter: “R”).
Soon after the operation has taken place, P realized its mistake: it was R’s account (which P indicated in the payment’s “beneficiary’s account number” field) credited, not B’s (which name was indicated in the same payment’s “beneficiary’s name” field). The problem was that P wanted to send money to B, not to R.
P wanted to recover the funds (equivalent of almost €8,000) from R, but R declared it had no funds anymore and would not pay it back. Not being able to recover the money from R, P went to court with a charge against the Receiving Bank, instead. According to P’s complaint, the Receiving Bank, when crediting the account, should not only rely on the account number but should also verify, whether the name written in the “beneficiary’s name” field of the payment is the same as the name of the holder of the account, indicated in the payment’s “beneficiary’s account number” field. Since the names were not the same, the Receiving Bank should restrain from crediting the account indicated by the number. It is not clear what particular action the Receiving Bank should undertake in case of such discrepancy of names, but, according to P, crediting the account indicated in the payment’s “beneficiary’s account number” field, was – in this case – the “inappropriate execution of the payment order”.
After years of court proceedings, including appeals, the Polish Supreme Court (SC) finally ruled against the Receiving Bank, deciding – on 19 March 2004 (Ref.: IV CK 158/03) – that the bank should be liable for the improper execution of a payment order:
“A bank that hasn’t verified whether the beneficiary’s account number corresponds to the name of the beneficiary, as indicated in the payment order instruction, shall be considered as acting without the necessary care, which is required from the professional institution”.
The SC has concluded that since the banks expect the payers to fill in the “beneficiary’s name” field in payment orders – as this field is included in all electronic and paper payment order forms – then the customers may expect that banks will process this information and use it when crediting accounts of supposed beneficiaries. Since the Receiving Bank did not process the payment on the basis of all the information it received and could use (especially the name of the beneficiary), the bank is liable for the improper execution of a payment order and shall pay to P 50 per cent of the original payment’s amount (equivalent of almost €4,000) plus statutory interest (as defined by the Civil Code) for the period from the first legal claim till the moment of the final return of funds (as required by the SC’s final judgment) to P by the Receiving Bank. Since the whole case also resulted from P’s mistake, the Receiving Bank shall not be liable for the remaining 50 per cent of the payment amount, since P was also responsible for the loss which happened. Obviously, both sides (P and Receiving Bank) may still claim and sue R for the amount not recovered (P) or the amount which had to be paid (by the Receiving Bank to P) on the basis of the SC’s decision. However, the success of these claims against R seemed to be doubtful in this instance.
What does follow from the SC’s decision? What practical suggestions can be drawn from it? Fundamentally, the ruling suggests that whatever data is being provided with the payment order, this data should be used by the banks in the course of payment’s processing. It doesn’t matter whether the particular data is structured or automatically processable, the banks shall take it under consideration if and when it proves necessary. The ruling is a corollary of the extended concept of customer protection and the mirroring duties of professional financial institutions.
The problem appears especially at the receiving bank, which is expected – by the sentence of the ruling – to “exercise the necessary care” of the professional institution and to verify whether the “name of the beneficiary” of the payment message is the same as the name of the holder of the account indicated in the “account of the beneficiary”.
However, new or extended rights (the “demand side”) usually have their new or extended costs (the “supply side”). If the banks were to comply strictly with the letter of the ruling, the receiving banks should start to verify (manually) every name of the payment’s beneficiary in correspondence to the name of the account holder to which the payment is to be credited. The outcome of this is simple to predict:
Whatever the immediate practical results would be, the problem is that going the way suggested strictly by the letter of the SC’s ruling is not the option at all. One of the reasons is that Poland falls under the long-established and supposedly well known and well understood regime of EU cross-border payments regulations. These regulations do not specify the ways local payments should be executed, yet they seem to set up certain framework for ordering and executing intra-regional payment settlements (for the sake of simplicity, any amount limits will be disregarded here). These settlements should be easy to order, generate, process, possibly faultless, quick and relatively inexpensive. STP is one of the foundations of such payment framework. In case of cross-border payments, indicating the amount of the currency (esp. euro), providing IBAN and BIC is considered enough to properly order (address) the payment. Other information can be considered more or less relevant but not necessary.
It is difficult to imagine that such a framework for intra-regional cross-border payments could co-exist with a completely different, fundamentally anti-STP, local payment environment. Yet, this is the picture that the letter of the new Polish jurisdiction is drawing. Although the revolutionary change of all local bank numbers into BBANs has been completed in 2003 and since mid-2004 no other account numbers can officially be used, these BBANs seem to create no added value if confronted with the above mentioned, severely extended judicial concept of customer protection (or the mirroring concept of the bank’s professional duties).
Today, before any local payment order would be accepted by the originating institution (a bank or a post office), the two-digit check number in front of the beneficiary’s BBAN is usually verified first to avoid the case of sending funds to a non-existing account. This is the best and currently sufficient condition for introducing STP at the level of local payments, since the clearing number of the beneficiary’s bank (or particular branch of this bank) is already included in the beneficiary’s account number. To generate the proper plain local payment in Polish currency it is enough to indicate the amount of funds sent and the beneficiary’s BBAN. Additional information can be included especially in the “payment details” field and it can even be processed by the receiving bank, but it would not be crucial for the proper execution of the payment itself.
If the banking industry in the EU is to be quick, efficient, faultless and inexpensive at least in the area of payment services, the payment processing shall be consistent: STP shall be used freely not only for cross-border (at least intra-regional) but also for local payments. If any local jurisdiction counters this principle, the regulatory environment – on the local or international level – shall be changed appropriately to eliminate the need to consider data (especially ‘free format’ data), which cannot be, and, after the introduction of IBANs and BBANs, is not necessary to be, processed automatically.
The discussed ruling – notwithstanding its counter-STP aspect – introduces several practical problems resulting from the fact that names of account holders have never been considered as particularly decisive, at least in any aspect of life other than taxation. Shortly speaking: it is difficult to follow the ruling strictly, because it does not consider many obvious practices of everyday life.
Beneficiary’s account holder name is a simple “free text” field in payments in Poland. The content of this field is regulated neither by Polish nor any other applicable law. In particular, this field is not structured in any way. Whether the first name or the family name should be put first is left to the decision of the payer. The same applies to the completeness of the name (which, for the business entity, can be very long therefore various shortenings are frequently and freely used), not mentioning the fact that names of different companies are very often very similar or even identical (especially in the case of SMEs).
Moreover, the clearing house does not support all possible ways of coding very specific Polish fonts, not available in any other latin alphabet. Therefore, it is often suggested that all names and other texts that include specific Polish fonts should be changed and written with the English fonts most similar to these original, Polish-specific ones. Even if the name were regulated and considered a processable alphanumeric “string”, many persons and companies would first have to “reduce” their names to fit the latin alphabet. After this operation, these would not be their true, exact names anymore.
In practice, verification of the content of the “beneficiary’s name” field of the payment order and the “account holder’s name” in the bank’s files would often prove that they do not match, but only “seem to be similar to some extent”.
In Poland at least, many people change family names at the time of marriage. This change should be indicated to the bank holding the account of the person, but often it isn’t. Yet, the adoption of the new family name is frequently declared to many other institutions, like the employer, tax office, business partners, friends, providers of services and goods. If the bank of the new wife was not informed about the change of her family name, it should probably not accept any salary payment directed by her employer to her new name and her account number (remaining unchanged), until the lady informs the bank about the change of her personal data. Hopefully for customers of the banks in Poland, banks are usually not rejecting such payments on the basis of “non-complete compliance of the customer’s data”. It may not be very prudent in the light of the SC’s ruling, but the majority of banks decided not to “strike back” their customers in result of the ruling. It also reveals the banks’ fundamental belief that:
Yet, even if we decide not to bother with the problems indicated above, can we really be sure who is the intended beneficiary? Since the unique identifier – the account number – may prove to be unreliable (due to the originator’s mistake), could we really use names of customers as decisive in the process of crediting accounts? The answer is: definitely not! Soon after the SCs ruling, one of my friends working for the same bank, decided to find out how unique the combination of his quite untypical first name and his quite untypical family name is for our bank (third largest bank in Poland). After the database query, my friend has found that there are eight different people having his first name and his family name, who hold accounts with our bank! I shall leave this argument without comments but the argument should be considered by anybody, who would like to consider processing “name” text fields as necessary element of payment processing when designing any future, more detailed regulations on the subject.
The new jurisdiction, especially in its part on financial liability, is also the unfortunate precedence opening room for possible frauds, which could be made at the expense of banks. If – as a result of the mistake (discrepancy between the name and the account number of the beneficiary) of the originating party (A) – the account of company B could be “incorrectly” credited by a bank receiving the payment and using STP procedure, resulting in 50 per cent of financial liability of the receiving bank (maintaining B’s account), then such legal environment encourages A and B to try setting an illegal plot against such receiving bank. The idea of such conspiracy is simple: A agrees with B that they will share the 50 per cent fine which the receiving bank will have to pay, if it credits the account of B with a payment, which A will generate. Then, A generates a payment, in which, in the field “beneficiary’s account no” he puts the account no of B, but in the field “beneficiary’s name” he puts the name of C (non-B). If the payment is credited to the account of B by the receiving bank, then A first makes official efforts to recover funds from B, but since B “unexpectedly” proves to have no funds anymore, A immediately sues the receiving bank for the amount of the payment. If the court charges the receiving bank with the 50 per cent liability, the conspirators (A and B) quickly end up with 50 per cent “return on investment” (the amount of the original payment) at the expense to the sued receiving bank. There seems to be no good safeguard from proliferation of such conspiracies at the moment.
Fortunately, the discussed ruling, in its long-awaited, extended justification text, has shown banks an uneasy path towards a way out of the problem. The path is uneasy since it can practically be employed only by the local banking community (at least as long as similar reasons will not force other EU local banking communities to take common, more coordinated steps to reduce the risk resulting from non-verifying the name of the payment’s beneficiary) and it will probably never cover 100 per cent of local payments.
According to the ruling’s justification, “a bank could free itself from the liability for not verifying the beneficiary’s payment name only if it proved that his contractor knew and agreed in advance that in the payment’s processing only the beneficiary’s account number would be used”. What the SC means by “contractor” here is difficult to agree in advance. Here, the SC seemed to go too far astray from the reality. Since it is the receiving bank that is practically liable here and the only party that could be liable is the sender of the payment, then the only case to which the above suggestion could be literally applicable, would be the “internal” payment, i.e. the one, in which the sender and the beneficiary keep the accounts within the same bank. Only in such a case, can the receiving bank “agree” with the sending party (the “contractor”). Usually, receiving banks do not have any civil law contracts with senders of payments. Even if some bank wanted to conclude contracts with all senders, it should conclude it with all people, entities and institutions capable of legal actions (being potential originators of payments). Moreover, not just with all such domestic persons, entities and institutions, but with virtually anybody in the world (since the ruling makes no particular waiver for incoming cross-border payments). And, whenever any new person is born or a new business entity or institution formed, the new contract would be required.
It is very important to note, that since the time of the SC’s ruling, the regulatory environment changed considerably, extending the liability for the “improper execution of the payment order” from the bank which was actually guilty of the particular fault (as was the case before 1 May 2004) to all banks which participated in the process of the money transfer. The new situation is well described by the new wording of art. 64 of the Bank Law Act, which has been in force from 1 May 2004, the day Poland joined EU:
“If an order for payment settlement placed by an account holder is to be carried out by several banks, each of these banks shall be jointly and severally liable towards the account holder for damages resulting from the non-execution or the improper execution of the order.”
This joined and several liability is not only the new risk for all banks which participate in the execution of the payment order and often have no idea how other bank-participants of the same process actually behave (how quickly and faultlessly they process a payment, how well they manage their payment liquidity, how often they back-up the payment files, how secure their systems are, and last but not least, what are their procedures for crediting accounts of their customers) but also a reason to act in a coordinated way, to eliminate or at least reduce risks which happen to appear.
Having all this in mind, in 2004 I formulated a proposal for all Polish banks to include the below provision (or a similar one) into their account holding agreements with their customers: “The payment order placed by the account holder, effected only on the basis of the beneficiary’s account number, shall be considered as properly executed. To execute such payment orders properly, it is not necessary for the initiating bank or for other banks which participate in carrying it out, to verify the name of the holder of the beneficiary’s account.”
If all (or at least the majority of largest banks) include this (or a similar) provision into their account holding agreements, we would be able to consider the majority of local payments as originated under such a contractual regime (defined by the account holding agreement of the originator and the originator’s bank), which allows receiving banks to apply STP for domestic payments without the discussed risk. Obviously, the originators’ banks should be interested in doing so, since – according to the new formulation of the above mentioned art. 64 of the Bank Law Act – they are liable for the results of the actions (or ways of processing applied) of the receiving banks.
Since this time the case was debated at the forum of the Polish Banking Association and several banks have already included similar provisions into their account holding agreements.
Notwithstanding the ways the local banks could use to try to mitigate the risk of STP, the solution as well as the problem of the ruling lies elsewhere.
Although critical about the SC ruling’s consequences, I would claim the ruling is fundamentally right. The problem is that after the introduction of proper BBANs throughout the Polish banking system, the ruling still prevails. It prevails, however, because the introduction of BBANs and the ways they could be used have not been properly addressed by the appropriate, primary legislation.
To lay the proper legal foundation for STP of payments in Poland, the respective domestic institutions that are responsible for regulating and increasing the quality of the payment industry and which have the “right for legislating initiative” (the right to propose new acts or their modification) should propose to amend the Bank Law Act in such a way as to consider the BBAN of the beneficiary (and not just the beneficiary’s name) as the only data needed to credit the indicated account. Whether this legislation would actually declare the name of the beneficiary as purely redundant information is another issue.
Although the issue is tackled in this article with Polish domestic legislation and jurisdiction, it is a typical case study, i.e. a particular example of a more general problem. According to my information, last year a UK customer, which was to be the beneficiary of a payment sent by the Polish originator, claimed that his UK bank acted improperly when it credited the other customer, whose account number, but not name, was indicated in the payment order. This article may therefore turn out to be an introduction to a wider subject of EU payments traffic.