SEPA Direct Debit: Meeting the Challenge
A recent report by Experian on debit fraud risk reflects a concern held by financial administrators in those businesses behind the game in getting ready for the single euro payments area (SEPA), specifically with regard to the imminent introduction of the SEPA Direct Debit (SDD) scheme due to come into effect in November 2009.
Yet this is not as problematic as it at first appears and can be readily addressed by using tried and tested tools already in common use. Putting in place a relatively simple process-driven ‘utility’, using the power of an embedded rules engine to automatically intercept every request to set up or amend a direct debit instruction, for example, could substantially reduce direct debit fraud.
Then, by using service oriented architecture (SOA) techniques, the same tool could both check for consistency in the direct debit request against that customer’s account details and at the same time contact the customer via their preferred method of communication to double-check that the request is indeed valid.
The SDD scheme provides a set of inter-bank rules, practices and standards that will allow the banking industry within the SEPA area (currently defined as the 27 EU member states making and receiving payments in euros, plus Iceland, Norway, Lichtenstein and Switzerland) to offer a direct debit product to customers. As a result, all core direct debits – whether between or within national boundaries – will be provided under the same basic conditions, rights and obligations, regardless of their location.
The UK is not directly part of SEPA because the UK does not (yet) use the euro, though UK-based corporates with significant operations on mainland Europe can now decide to centralise direct debits from all subsidiaries in SEPA countries with one or more banking partners. Sterling direct debits would, however, continue to be collected and processed separately. In order to offer a SEPA service to their major corporate customers, UK banks would have to do this through a European branch, subsidiary, correspondent or third-party service provider.
The SDD system offers benefits to all participants (creditors, debtors and their respective banks) in terms of lower cost, higher straight-through processing (STP) rates and reduced risk. Not surprisingly, however, the scheme is in large part corporate-driven, as major providers in industries such as telecoms, utilities and insurance dealing with large numbers of customers across Europe see the financial and operational benefits of a common direct debit mechanism.
For such organisations, this will provide a simple and cost-efficient way to collect funds, in terms of both one-off and recurrent bills. Critically, this will improve both cash flow and treasury management, as creditors will be able to determine the exact date of collection and have certainty of payment completion within a pre-determined time-cycle.
This common system will also enable straightforward reconciliation of received payments and automate exception handling such as returned, rejected, refunded collections or reversals. And finally, it offers the ability both to collect funds from debtors throughout SEPA through the use of a single payment instrument and will provide improved security and lower admin costs resulting from the optional use of digital signatures from signing mandates, as soon as electronic signatures become available.
In recent months, broader economic issues have pushed SEPA implementations down the agenda of many banks. As a result, as in the earlier case of SEPA Credit Transfers (SCTs), banks are likely to make best use of what they already have, rather than invest heavily in new technologies and systems.
At the same time, implementation will only be uniformly possible across all participating SEPA geographies in November 2009 if the Payments Services Directive (PSD) has been passed into national law in each country, enabling SDD mandates to be legally enforceable.
At present, SDD implementation is principally perceived in terms of a ‘carrot’, offering both cost savings and greater certainty and security of payment. However, in terms of a counterbalancing ‘stick’, the scheme, though optional at the outset, is likely to become compulsory in practise as national debit clearing schemes are withdrawn – possibly from as early as 2012.
Furthermore, the Dutch government has already announced its intention to use the scheme, and there is little doubt that momentum towards mass adoption will increase as other national administrations follow suit.
Overall, banks must recognise that they have to offer a service for issuers and creditors or risk losing business. The issue, therefore, is how to operate the scheme most effectively – by outsourcing to a service provider or another bank, by handling in-house or building a payments business and driving volume. Which approach to take will be an important strategic decision for banks and it is unlikely that in the longer term there will be more than 10-20 large payments providers across the SEPA zone.
Irrespective of the approach taken, the SEPA rulebook allows banks to provide value-added services, impacting significantly on the relationship with corporate clients.
Unlike existing mandates, which typically go direct to the creditor’s bank, under SEPA the creditor issuing the direct debit has to collect the mandate from the debtor client and manage a complex multi-phase process. This includes de-materialisation (scanning and parsing), turning it into an electronic file, combining archival with ready availability and attaching it to the payment file format (the instruction) for the bank to enter into the SEPA system in order for the funds to be collected.
Using existing payments software, banks can offer clients access to software that manages the full end-to-end process, including the ability to originate a direct debit arrangement over a website. And by extending this to the corporate client’s customer (B2B2C), the transaction is captured only once, stored in one place (the creditor’s bank) and immediately accessible for the bank to run any security checks required. This also enables the corporate creditor to take advantage of the bank’s inherently more secure electronic infrastructure in completing the transaction.
Although still responsible for applying due diligence procedures in doing business with each customer, the corporate treasurers‘ role is therefore made much easier. By working in partnership off the same infrastructure, hand-offs are minimised, so eliminating the risk of misunderstanding, losing or transposing information.
To manage this electronically, each mandate (which can be used to complete a one-off or recurring periodic payment) becomes a ‘case’. The SEPA scheme consists of a number of fully-codified rules that need to be followed when managing the case, either to initiate or reject payment, or recover a duplicated or late payment.
The ideal software solution, therefore, consists of an integrated rules engine and case management software tool. Already in place for other payments processes within many banks, it then becomes straightforward to translate the SEPA rulebook into a set of processes that will maximise STP rates. This is true even in the case of exceptions, as these defined reactions can be automated to ensure the right information is transmitted to the right person at the right time.
With the growing confidence in, and adoption of, electronic signatures – which will address directly issues of authorisation and non-repudiation – STP rates will further increase as SEPA allows, and indeed encourages, the move from mandates as a paper-based to an electronic instrument.
Under the new rules, if for example a French citizen purchases a mobile phone in Italy, the provider will be able to set up a direct debate mandate from its head office – wherever situated in the SEPA area. This will then automatically hit that individual’s bank account and withdraw money from it.
This does not in itself present a new channel for fraud or money laundering as, if properly managed, the risk is no greater than in the case of a national direct debit payment today. If the corporate creditor and its banks work in partnership in providing the right infrastructure, using payment detection, monitoring and filtering techniques already widely in use domestically will similarly secure any direct debit.
Furthermore, with the right systems in place, it is possible to overlay best practice procedures with local specificity, by applying rules and safeguards relevant to each country in which the creditor operates.
Managing the mandate, or case, in this way makes it possible to automatically watch for suspicious sets or patterns of transactions in an exactly similar way to existing international payments systems currently. The only difference is that the system needs to provide a higher degree of agility and flexibility, as direct debits are typically greater in volume and of lower individual value.
For corporate treasurers, it is essential upfront to make the decision as to whether or not they wish to participate in the SEPA scheme from a pre-determined date.
Although at first sight the potential savings look attractive, this should be undertaken in close collaboration with several banking partners. The reason for this is straightforward and pragmatic, as the unprecedented volatility of today’s financial markets means that the risk of ‘putting all one’s eggs in one bank’s basket’ is a much tougher decision than might have been the case just 12 months ago.
At the same time, corporate treasurers will want to understand the pricing impacts in each case, to ensure that the attractive headline of being ‘able to do international business at a national price’ will in reality deliver the savings indicated.
And finally, to take full advantage they will need to have a SEPA payments strategy in place, both in terms of infrastructure and organisational processes. Thus, for example, whether or not they scale up or down existing infrastructures will in large part be driven by the amount of funds they collect in each country within the SEPA zone.
In summary, a corporate treasurer of a major utility, telecoms provider, insurance company or any other major business managing direct debits, the priority must be to have a detailed conversation with perhaps two or three of the company’s major banking partners across Europe.
The purpose of this is threefold: to understand what their pricing policy is likely to be; to clarify what value-added services each can offer in order to streamline as far as possible the setting up and management of mandates; and finally, what safeguards can be built into the relevant relationship to ensure full compliance and protect all parties from fraud and other aspects of financial crime.
In doing this, corporate treasurers should be pushing at a partially open door. Enlightened banks should recognise that by being proactive in this area they will significantly increase the likelihood of retaining business they might otherwise lose – the potential risk is increased in that what was a national business is suddenly open to realistic competition from providers of banking services in more than 30 countries.
By providing an end-to-end solution and sharing infrastructure will enable the bank to become more embedded within the corporate client’s operation – ideally to the benefit of both organisations. And finally, if a bank has taken the strategic decision to make payments a line of business, it will help achieve the critical mass necessary to become a lowest-cost provider.
The introduction of SDD is the second milestone in a three-phase programme of regulatory development, preceded by SCT, which has already gone live, and with SEPA Credit Card Transactions to follow. In the UK at least, which is not directly part of SEPA, visibility of implementations to-date has been relatively low-key, with other concerns across European banking arena overshadowing their importance.
However, for corporates to review their direct debit strategy, and put in place best practice infrastructure and procedures to take best advantage of SEPA, could take up to a year to implement effectively. Thus, for those who have yet to take any meaningful steps, the time to act is now.
The upside is that the business process tools needed to make this happen already exist, are well-proven and in place in many banks. In short, although timing may be critical for corporate treasures, the problem itself is undoubtedly more apparent than real in addressing issues around these new regulatory obligations.