Borderless Payments - Borderless Fraud

While the single euro payments area (SEPA) forced its way to the top of the agenda for the financial services industry some time ago now, the focus to date has largely been on meeting the minimum standards required for compliance through tweaking legacy systems. In recent months, however, some financial institutions have started to view their SEPA projects in a more strategic manner. As a result, one of the areas that has come to light is the issue of fraud security in the post-SEPA environment.

In spite of the lack of fanfare, 28 January 2008 marked the first SEPA deadline – the SEPA credit transfer system went live. Many of the initial implementation issues surrounding SEPA as a whole have been identified and are being addressed. However, the typical SEPA project has largely been quick fix in nature, characterised by banks reworking legacy systems for short-term expediency rather than innovating for longer-term strategic and competitive advantage. In recent months, however, financial institutions have started to take a step back and consider SEPA more strategically; at times using it as an opportunity to review their entire payments strategy and infrastructure.

As part of this wholesale review of the strategic opportunities associated with SEPA, it has also become clear that enhanced financial crime management will be required to protect customers in the post-SEPA environment. The increased risk of fraud associated with SEPA is only now beginning to be properly understood. Banks are starting to recognise the risk and realise that meeting basic fraud management standards is but one part of a larger, more complicated SEPA puzzle. The European Commission has set up the Fraud Prevention Expert Group (FPEG), which will also contribute to the debate.

Fraud Migrating Across Borders

The breaking down of national payment barriers within the financial services industry and facilitating the movement of money cross-border through SEPA is a positive step for banking customers. Yet, organised crime is also viewing SEPA as an opportunity – an opportunity to make money from a brand new payments channel. As the transferring of funds cross-border becomes much easier and faster as the scheme becomes fully operational, it will also become more attractive for fraudsters to tap into this channel, and if adequate fraud prevention solutions are not put in place fraud losses will increase.

Past experience has shown that fraud will always evolve and migrate, looking for new outlets once former ones are closed or made more secure. Fraudsters are naturally drawn to softer targets by the same inevitable pull that draws a moth to a flame. A clear example of this is the introduction of EMV. When EMV went live in the UK, payments fraud didn’t go away, but it shifted both to the card-not-present environment and to markets where the EMV infrastructure had not yet been established. Similarly, the introduction of schemes such as the UK’s Faster Payments service when person-to-person payments will be processed in near real-time, creates a potential new target for fraudsters if the correct risk and anti-fraud solutions are not put in place. In fact, when similar schemes went live in other parts of the globe, such as in Canada and Australia, there was a corresponding increase in fraud. Based on such experiences, it is highly likely that a similar change in fraud patterns will emerge post-SEPA if preventative action isn’t taken.

The risk will be more apparent for those financial institutions that have not yet implemented EMV, a requirement for compliance with the SEPA Cards Framework created by the European Payments Council. Non-card based transactions such as SEPA direct debits and SEPA credit transfers will also come in towards the top of the fraudsters’ target list. Potential SEPA-related fraud will include phishing, social engineering and organised financial crime resulting in an increase of identity theft and account takeovers.

As financial institutions have only recently begun to come to terms with the increased risk of SEPA, many do not yet have the necessary anti-fraud strategies in place to deal effectively with cross-border transaction fraud. Banks are, however, beginning to treat risk solutions for SEPA as a priority given the potential impact not only on revenue, but also on their brand and customer experience, if a security failure were to occur. At a time when the general public is still reeling from the effects of the credit crisis, Northern Rock and Societe Generale, the last thing the banks need is further bad publicity or to contribute to the lack of trust among consumers. In order to remain competitive and to protect their brands, banks need to demonstrate that they can cope with any new risks post-SEPA.

A Strategic Approach to Security

Banks need to implement enterprise-wide risk monitoring systems that oversee and cross reference data from multiple payments channels, including SEPA, providing fraud teams with a complete picture. Transaction and account information from a variety of channels will enable banks to better detect and put a stop to suspicious activities. While multi-channel monitoring should already form a key component in any banks’ risk approach, as banks add further channels and endeavour to offer customers greater flexibility, enterprise risk management will become even more important in the post-SEPA environment.

A two-pronged approach to security is required whereby banks address potentially fraudulent transactions at the point of access as well as those that have avoided initial detection but appear suspicious in nature. Security techniques that can be considered include two-factor authentication, real-time risk monitoring and the tracking of Internet log-on details to generate alerts against suspicious IP addresses or suspicious customer behaviour. This fraud monitoring technique, IP intelligence, provides financial institutions with the ability to set up monitoring based on customers’ IP addresses and uses the information to establish patterns in the IP addresses of their customers. The data is then used to identify where fraudsters are logging on and can lead to a total ban on transactions initiated from known or suspect addresses.

This is an example of an area where banks need to co-operate amongst themselves and start to share information. The idea that fraud is a non-competitive issue is one of increasing importance for the entire banking community particularly in the SEPA environment. Technology, regulation and fraudsters will all continue to evolve and an industry-wide view of fraudulent activity will be pivotal in making in-roads into the ongoing fraud battle. The effectiveness of solutions against fraud in the SEPA landscape will be similarly bolstered by the banking industry’s adoption of a community spirit. Traditionally, banks have considered their fraud prevention techniques as proprietary and therefore a competitive issue. As cross-border payments become easier, the sharing of fraud techniques needs to become accepted and easy to facilitate.

The reality is that fraud will continue to evolve and migrate. As the European financial services industry becomes more integrated, financial institutions need to be prepared for the fact that their security and risk solutions will need to broaden from a domestic focus to more of a European, if not international, one. As SEPA enables the easy movement of money cross-border, it is imperative that the benefits of such a scheme are not outweighed by security risks. By implementing an enterprise-wide risk strategy in which all payment channels, new and established, are monitored in real-time, and combining it with more industry collaboration on security, financial institutions will be able to keep pace with, if not overtake, the fraudsters and beat them at their own game.

Whitepapers & Resources

2021 Transaction Banking Services Survey
Banking

2021 Transaction Banking Services Survey

5y
CGI Transaction Banking Survey 2020

CGI Transaction Banking Survey 2020

6y
TIS Sanction Screening Survey Report
Payments

TIS Sanction Screening Survey Report

7y
Enhancing your strategic position: Digitalization in Treasury
Payments

Enhancing your strategic position: Digitalization in Treasury

7y
Netting: An Immersive Guide to Global Reconciliation

Netting: An Immersive Guide to Global Reconciliation

8y