Sunday, March 16, 2008

Institutions influencing mobile banking and payments


Initially, especially in Europe, the industry has seen the establishment of many standards bodies all trying to influence the industry. These bodies ultimately tried to advance the case of their sponsors or owners rather than the industry as a whole.

Lately, a number of institutions started generating traction and the industry is being formed through their actions. These organisations are either non-profit bodies looking after the interests of their members or are philanthropic in nature. It is important to take cognizance of their actions as they have a major influence on the industry today.

I have listed some of these organisations below. This is not intended to be a comprehensive list, but rather an attempt to trigger more thoughts and contributions. (In other words: help me to make this list more comprehensive)

  • The Mobile Payment Forum is one of the earliest institutions with membership from all participants in the mobile payment eco-system. Founded during the heydays of mobile payments in 2001, the organisation is currently trying to define its role and contribution, having moved its attention more towards proximity payments and mobile marketing.
  • The Mobey Forum is an organization initially established by major European banks (including Deutsche Bank, ABN Amro and others). A lot of the initial work was spent on developing security standards to be deployed amongst the banks. Since about two to three years ago Mobile Operators and Vendors were also invited to join and the organization became much more relevant.
  • The GSM Association have been especially active during the past few years. The MMT program was announced during the GSM World Congress in Barcelona (2007) with a number of objectives: To increase mobile operator revenue through financial services, to activate every phone to be able to send and receive money and to actively accelerate this through well-funded programs. In executing on these objectives, the GSMA is working closely with banks and other relevant organisations (e.g. Mastercard, Western Union etc
  • Pay Circle was founded during 2002 by technology companies (like Siemens and Sun) to advance the development of relevant technology solutions. According to the website, the mission was achieved and the organisation closed. There are other organizations that were also active in the past, but have subsequently disappeared. (like Radicchio)
  • CGAP (and the WorldBank) are very active to support mobile payment initiatives. A number of grants were recently announced and included amongst others grants for Consolidated Bank in Kenya, Tameer Bank in Pakistan, Wizzit in South Africa, XAC Bank in Mongolia. In addition to money CGAP also provides consulting support, excellent research and other guidance.
  • Finmark Trust is a South African based organisation with interest into Africa that supports the deployment of low cost financial services including through mobile banking
There this is a start. See if we can increase and add to the list

A perspective on Mobile Payments in Europe


Europe’s venture into mobile banking is characterised by many small initiatives that all failed. A case in point is the example of small Dutch company Global Payways with a product called Moxmo launched during 2003 with a mild take-up in the Netherlands. During the collapse of Paybox, Global Payways acquired the subscriber base of Paybox in Germany. This small company was soon in financial difficulties and had to disband services within six months of having taken over the larger subscription base. (Many reference, but read the following blog.)

Soon afterwards major mobile operators announced the Simpay alliance. Simpay endeavoured to provide a common payment platform between Vodafone, T-systems, Telefonica and Orange. While the European industry waited, Simpay had the central stage for three years and produced… nothing. This fiasco had a lasting impact on the European mobile payment industry.


A company that is quite visible at the moment is a company called Monitise. An initiative started by Morse with a Java based service on top of the ATM network is now being deployed by 1st Direct, HSBC and Alliance & Leicester. The company is very visible (because of a large marketing budget?) and is making big headway from a brand building perspective, but the technology offer little functionality to the subscriber. Recently Monitise listed on the LSE raising a substantial amount to fund the current burn-rate. Another company with a similar profile is the Finnish company called Meridea. With backing from Nokia and Accenture this company was the technology behind amongst others Standard Chartered mobile banking initiative. Unfortunately it closed its doors a few months ago when they ran out of funds.


A noteworthy deployment is the mobile payment solution supported by Banksys in Belgium. Banksys is the central ATM and POS switching company owned by the major banks. Banksys recently announced a SIM card based solution supported by all the major mobile operators that allows subscribers to make payments from their existing bank cards utilising the mobile phone.


The deployment of Paybox in Austria is still operational today and very successful. The service is available on more than one network, provides excellent functionality and utility and is used by close to half a million people on a regular basis. (This is quite a big coverage considering the size of Vienna where most of the subscriber services are available). The service is claimed to be profitable and is one of the best examples of a mobile payment solution that ultimately became successful because of dedication of management.

Thursday, March 13, 2008

PCI compliance for mobile payments

Many research reports and experts warn about the risks of allowing fraudsters and criminals access to sensitive credit card details. It is especially operators of financial and payment services that tend to be the biggest targets. Quoting Jon Kerr from Verisign: "It's no surprise that online banks and retailers are some of the most popular targets for identity theft since so many personal details are required by users,... With the average UK consumer worth over £10,000 to criminals, it's clear that each of us is a target."

It is because of this threat that the industry decided to publish a standard that a bank or payment processor should adhere to in order to provide acceptable protection to cardholders. This certification is known as the PCI compliance and is being driven by the Credit Card Associations. The objective of PCI compliance - to protect the consumer - is commendable and should be accelerated. Customers should be educated and should take their business away from banks and payment operators that do not comply.

An interesting question is how the providers of mobile payment solutions should (or should not) comply with PCI standards. In as much as mobile payment solutions touches card information the application of the standard is clear: None of the card information must be in the clear and it must not be possible for an un-authorised person to get access to this information. But what if no credit card information is used? What if the routing of payments are made on the basis of a subscribers telephone-number (as is often the case)? What should the minimum conformance be.

This topic is much more complex to deal with in the space of a short blog, but it is clear that the mobile payment industry should develop unique compliance requirements. Obviously this would be very similar to Card PCI compliance (catering for instance for access, un-authorised actions, reporting, physical protection etc.). But what about not displaying a telephone number when you could potentially see phone numbers of some-one just call you? What about look-up tables and what should the controls be around security elements?

It could be worthwhile to develop some of these rules pro-actively.

Wednesday, March 12, 2008

INCSR getting involved


I didn't know that the US Department of State pay good money for people with complex names like the Bureau of International Narcotics and Law Enforcement Affairs to produce reports like the International Narcotics Control Strategy Report (the INCSR). I cannot comment on the rest of the report, but the section that talks about "mobile payments - a growing threat" triggered my interest and I read it with attention.

I must say that the sentiments expressed and the conclusions reached is so far removed from the practices or the intention of the mobile payment and remittance industry. Very few of the statements regarding risks and lack of controls have been verified or tested against the existing practices employed by mobile payment vendors. Compliments to the authors for publishing the report on the Internet. (Read it here). Unfortunately, I could not find any feedback mechanism that would have enabled me to communicate with the authors in order to rectify many of the inaccuracies.

In practice, great care is taken to ensure that subscribers are enrolled with proper KYC compliance. The implications of the Patriot act and FinCEN are carefully researched and deployed to ensure compliance. Most of the vendors in the industry (and I know most) have a genuine intent to build an accessible electronic financial infrastructure for the poor, but that will also eliminate (and block) the actions of criminals and terrorists. These vendors work with the Worldbank and associated agencies (like CGAP) and reputable banks and other financial organisations to try and build well-governed solutions to the massive problem of the poor that is effectively eliminated from modern financial services.

The statements in the report not only harm the delivery of financial services worldwide, but also delay the deployment of electronic tools that would enable legit agencies to monitor transactions and to identify fraudulent and illegal activities. I would like to urge the author of the above report to contact representatives from the mobile payment industry so as to clarify mis-understandings, but also to assist the industry to build better (for all) financial instruments.

Monday, March 10, 2008

It is not what you have, but where you fit in

Such a lot of companies are doing good things in the mobile banking and payment space. It is great to live and work in such a vibrant industry. I recently made a list of companies that play a role in the development of the industry. These are companies that are making an impact and can be looked at for solutions (or at the least as a benchmark).

It was interesting for me when I realised how few of these companies actually can claim to be independent. Not that independence is that important, but still it is important to know where companies "fit in". This will help you to understand their actions and what drives them to be successful.. but also in what way could they be made to act by other forces.

The best examples are solutions predominately developed (or at least) owned by large operators. It would be unlikely that these solutions would be deployed by other operators. Examples of these are Vodafone's mPesa, Smart's Smartmoney and Globe's gCash.

Other examples are companies that have deployed a successful mobile payment solution in a specific market. Sometimes these deployments are quite spectacular. These companies then try and sell their solutions elsewhere. They try turning an operational solution into a packaged solution. This is particularly difficult and the jury is still out if this can be done commercially. Examples of this are Trumpet Mobile now selling technology as Affinity, Wizzit now offering a solution under the brand r-Qubed and others.

Many solution providers are a small sub-company of a much larger company. Even though these solution providers project themselves as a big supplier of mobile payment solutions, the division providing this product line is often very small. Because these companies also have other interest, the provision of mobile payment solutions may suffer in the interest of other priorities. Examples of these are multiple and include Eversystems, GFG, mFormation and Telesoft.

Few companies can claim to be independent suppliers of mobile payment solutions. These companies are often focused companies with excellent solutions and track records. Examples of such companies are Fundamo, mShift and Paybox.

Once again this is not a comprehensive list. It is my intention to trigger discussion on my (often controversial) positions which is always welcomed.

Regulatory discussion

One of the discussion topics that is dominating progress with mobile banking, is the regulatory constraints/dispensations. This is especially relevant when the delivery of mobile banking is based on the creation of a "new account" for every subscriber. The banking law that would govern the opening of such an account is always a topic for discussion.

Based on what I have seen in the industry, I think that one can identify four categories of regulatory conformance in the provision mobile banking based on a new bank account. The four are:
  • Full banking, where the underlying account that is created for a new subscriber conform to all the banking law requirements. The customer is properly identified and conforms to KYC prescriptions. The bank account is properly reflected on the deposit-taking balance sheet of a bank and all legal requirements have been met.
  • Relaxed conformance, which is typically the same as a full bank account with some relaxation of the KYC requirements (both in content and in process), although the customer is still properly identified.
  • Pre-paid debit, where the client is not identified. KYC requirements are postponed to a later stage where the client would be identified (for instance) where cash is to be withdrawn from the account, or when the balance is to exceed a specific limit.
  • No conformance
In selecting a specific approach, the provider of mobile banking should consider all implications and the potential impact on the business case. A valid strategy could also be to deploy a platform where more than one of the categories above are supported.

Mobile Money Partnerships

During 2004 the largest African bank (Standard Bank) and the largest African telco (MTN) formed a joint venture called Mobile Money Holdings. This is a 50:50 venture with the objective of developing product that will enable subscribers to have access to new and advanced mobile banking products. The company launched an exciting solution in South Africa the next year (2005) and is in the process of launching more solutions trough-out Africa and the Middle-East.

Recently, Citi-bank announce a joint venture with South Korea's telco SK Telecom. This will be a 50:50 JV called... Mobile Money Ventures and will be based in San Francisco. The objective of the venture will be to "develop an advanced mobile banking platform..." See any similarities?

Also see a previous post on Mobile Money.

Tuesday, March 04, 2008

Who can see your PIN

Researchers claim to have found flaws in some famous brand PIN entry devices - certified by Apacs and Visa. These devices have loopholes that can enable fraudsters to access unencrypted PINs and account numbers.

The "tapping" techniques to capture unsuspected cardholder's PINs require little technical know-how and fraudsters can easily attach to the PED a "tap" that records PIN and account details as they are transmitted between the card and the PIN pad. Criminals can then use this data to create counterfeit cards that can be used to withdraw cash at ATMs in countries where Chip and PIN hasn't yet been implemented. (Read more)

In another report, a British criminologist has warned that the new security card technology could actually increase, rather than solve, the problem of identity theft and fraud. The researcher said that identity cards and chip and pin technology for credit cards were unlikely to alleviate the problem, as fraudsters react with more creative responses and individual vigilance and knowhow, which remains the best protection against fraud and identity theft will decrease. (Read more).

The biggest exposure to fraudulent transactions in my view is the lack of control that a subscriber have on what can be done with his/her PIN. How is the PIN dealt with, can it be intercepted or is it stored anyway along the line. Any third party device or transmission line that the subscriber does not have control over is a possible source of attack. PIN entry devices that are not under the direct control of the subscriber is the weak point. It is possible to utilise these devices to capture a PIN fraudulently without the knowledge of the subscriber.

Techniques are available that enable a subscriber to enter their PIN on a mobile phone in a secure way that can also be certified by banks and credit card associations. The difference with this approach is that the PIN is entered on a personal device that is (usually) under the control of the subscriber and tampering in order to capture a PIN fraudulently is much more difficult.

Value Store System

It is impossible to provide a payment system (any payment system) without connecting (or being able to access) some kind of value store. A credit card based payment system must debit a credit card account and an EFT payment system must debit a bank account somewhere along the line. This is the case for mobile payments too. Without being able to debit (or credit) some kind of value store, it would be impossible to deploy a payment system.

Most mobile payment solutions provide a mobile payment experience that integrate into an existing value store. For instance, mobile banking solutions that provide a mobile channel to existing bank accounts or mobile payment solutions that mobile enable an existing credit card. The challenge with these solutions is to ensure a seamless integration to the existing systems. Some of the challenges is to ensure that the registration process (when a mobile phone gets linked to a credit card for instance) does not create an opportunity for fraud. Also the boundaries and rules related to liabilities and disputes are not always easy to implement consistently.

Other solution providers (only a few) provide the ability to open a new type of value store that can be utilised to perform mobile payment transactions with. This facility is particularly interesting in markets where more people have mobile phones than does have bank accounts or credit cards. The advantage of this approach is that the value-store can be designed in such a way that it is much more tightly integrated with the mobile payment solution. At the same time many challenges must be overcome, like conformance to regulations, compliance with international protocols and the ability to perform audits and reconciliations that will be acceptable to a central bank.

The selection of and deployment of the value store element of the solution is probably the most important decision that can be taken. The different components that must ideally be present in a mobile enabled value store are:
  • Real-time clearing
  • Push and pull payment support
  • Support for a multitude of primitive transaction types
  • Security paradigms compatible with mobile enablement
  • Ease of use
  • Transparency
The key to deciding on a value store strategy should not be dictated by available technology, but rather be based on market realities and business objectives.

Tuesday, February 26, 2008

Administration Module


It is actually relatively easy to demonstrate a mobile banking transaction. To connect a phone channel to a banking system and to demonstrate the transaction being initiated by a phone subscriber is by far the easiest problem to solve in mobile banking.

Far more complex but much more important is to also provide robust administrative support for the mobile banking solution. This is an essential component to deliver a commercially sound and a production ready mobile banking system.

In evaluating a deployment ready solution one should expect to find the following components in a well designed Administrative module:
  • Support staff access is important as it is probably the biggest risk factor in the operations of the system. Statistics have shown that fraud is more often perpetrated by internal staff and the exposure is also much bigger. Well-designed systems should cater for defined responsibility matrix, with segregation of duties. Techniques like dual authorisation, limits and exception reporting should be available. Proper logging of support staff activities is important so as to ensure that activities can be tracked and audited.
  • Most of the administration activities are made available by means of suitable procedures. Systems should support standard procedures and workflow for the key functions (like registration of a new subscriber, renewal of a PIN, reversal of a transaction to name a few). In addition the workflow component should be flexible enough to accommodate changes and to add new procedures.
  • The tasks within the procedures should include Client support functions that would enable a client support staff member to handle queries, set new limits, change personal information etc. Support should be given to search the data by means of surnames, identification numbers etc. in addition to mechanisms to authenticate clients.
  • Administrative support could include the ability to raise interest and fees. To run reconciliation tasks, to change system parameters or to send communications to support staff or clients.
  • The availability of Management Information is critical not only to be able to operate a mobile banking system effectively, but also to be able to improve the service.
  • A well-designed system should cater for External administration functions. This would enable third party suppliers to possibly register clients or to pay commissions. It is preferably to have a defined interface to build customised access to the Administrative functions.
Administrative support is often delivered as an afterthought, or not based on a well-architected design. It is often inflexible, limited in its functionality, open to mis-use and expensive to change. It often does not provide sufficient management information support or caters for the exceptions. One should evaluate alternatives carefully on the basis of their administrative support, as this is usually the most expensive element to add or modify later.

Friday, February 22, 2008

Transaction Manager (Part Two)

The challenge with the development of a Mobile Banking transaction manager is to consider the following unique realities of mobile banking:
  • It is likely that the system will have to deal with much more transactions than would be expected from traditional banking systems. Remember that millions and millions of people have mobile phones and they just might want to access their banking at the same time
  • The different systems that mobile banking have to integrate to (Telecommunication Infrastructure, Pre-paid top-up billing systems etc.) are often not as stable (or sometimes as available) as what one would expect from financial systems.
  • The behaviour of cell-phone users reflect an expected immediate feedback. If they do not get a response within a few seconds, they would typically send the request again. The transaction manager must be able to deal with this kind of behaviour, without compromising integrity.
  • Security paradigms that can be implemented on mobile phones are not necessarily compatible with what is required for financial systems and this must be mapped somewhere
In looking at the design considerations for the above, it is clear that a synchronous architecture would probably not be able to deliver on these requirements. A transaction manager that has to keep thousands (if not millions) of transactions open while the transaction is completing would not be able to handle surges in requests, nor will it be easy to tune or scale such a system. The correct architecture (without a doubt) is a message based architecture.

Mobile banking solutions are often deployed without proper consideration for the transaction manager. Often mobile banking is bolted onto the Internet Banking functionality. This works great during pilot and initial production deployment, but starts to fail dramatically when the solution experience massive take-up (subscribers or transactions). Such conditions are then often aggravated when one component in the eco-system starts breaking or suddenly is not available. At that stage it is often too late to change.

Wednesday, February 20, 2008

Transaction Manager (Part One)


This is by far the most complex and often overlooked component of mobile banking. If one were to analyse the fundamentals of mobile banking, one will get to the conclusion that good mobile banking design is about the management of transactions originating on a phone and terminating on a bank account - and many similar types of transactions. A well-designed mobile banking system caters for the support of many different transaction flows. In addition proper consideration should be given for error conditions or when external sources are not available.

A transaction manager should cater for transactions to and from the following subsystems:

  • The transaction manager must be able to accept and send messages to the Mobile Channel. This should preferably be done in such a way that it can be done independently from the actual handset solution that has been deployed. Communication to this channel is very time sensitive, because a human would ultimately be receiving these messages. As such time-dependent actions should be configurable.
  • Applications that are often integrated into mobile banking offerings (called Third Party Applications) must also be integrated. Typical systems that the transaction manager must be able to talk to are bill payment, pre-paid airtime, COD systems and more.
  • Transaction Clearing is a often overlooked outcome of a mobile payment transaction. a well-designed transaction manager must be able to integrate to and support transactions to and from systems like Money Remittance systems, Central Clearing systems etc.
  • A mobile banking transaction will ultimately lead to a debit and credit transaction on some account, purse or card. The transactions to and from these Value Stores can be quite complex.
  • Many different security techniques can potentially be supported. This could be PIN-based, or User-ID and password. It could utilise CLI or certificates. The transaction manager must be able to route transactions to the correct source to verify security and adhere to requirements that may be applicable.
  • The switch must record transactions in such a way that it is fully auditable and that it can be proved that the operation is fully in compliance with regulations. A well-designed switch will cater for this too.
In addition, the transaction manager must be able to string together different transactions in a logical way. It should have the capability to roll transactions back if one component fails or is not available. It should also have the ability to place transactions in pending status and have the ability to resolve pending transactions. This should, according to my experience, be possible without human intervention as it is possible to get hundreds of thousands of transactions in a pending status (when a pre-paid top-up system is not available for a time). When the failing component comes on-stream again, the transaction manager should be able to resolve the transaction in pending state automatically.

In the next blog, I will discuss characteristics and special conditions that a well designed transaction manager must cater for. I will also discuss critical conditions that the system will have to cater for and typical solutions to this.

Monday, February 18, 2008

m Commerce management


This is one of the most tricky elements of mobile banking. This is where mobile banking systems integrate with mobile operator infrastructure and where the intricacies of telecommunications must be dealt with in such a way that financial transactions can be processed without losing accuracy. It is in this layer where a mobile phone number (or an identifier in the telecommunication world) is mapped to a banking number. The procedures for the establishment and maintenance of this link is often complex and should cater for many different scenarios.

A well designed mCommerce layer should also cater for risk management elements (like functionality available to specific profiles or daily and transaction limits). This is especially important in multi-channel deployments. This layer must be able to allow (for instance) a balance enquiry from a SMS channel with only CLI security but at the same time person to person payment with PIN encryption from a SIM Toolkit channel. In order to effectively be able to deploy this functionality proper mapping of profiles and access matrices is essential. This component must enable the operator of the system to present different options/menus to different people by making small parameter adjustments.

Often this component is grouped with the mobile channel layer (especially in the case where only one channel is supported or when the solution is inflexible in working with alternative channel providers). Grouping this component with the Channel management is often referred to as a wallet system as sufficient information must be stored to be able to process and route financial instructions to financial back offices systems. More than 75% of mobile banking vendors specialise in the provision of only these two components with at best limited features that could be classified as belonging to the remaining three components.

Mobile Channel Access Layer


The subscriber of a mobile banking deployment would interact with this component of the total solution. Depending on the deployment paradigm, the component may consist of application(s) downloaded to the mobile phone (SIM Toolkit or Java as examples), or in some instances would have no logic on the phone (WAP/xHTML or USSD deployments). This portion of a mobile banking deployment must cater for the user interface and manage the interaction with the subscriber.

Many different security paradigms can also be implemented ranging from security that ius only based on CLI (does the transaction come from the expected phone?), to advanced cryptographic solutions. Sometimes the security deployed utilise very innovative and unique techniques, and sometimes solutions are based on standard, tested security techniques.

It is virtually impossible to deploy this component without some logic on a hosted server in the back office. The hosted functionality must manage versions of deployed applications, as well as menu structures and expected responses. The hosted environment must be able to respond to error conditions (specific to the channel) and should be able to adapt to fault conditions (for instance when a SMS-C is not available or when response times from an application on the phone is slower than expected.

Typically solution providers favour some or other channel technology and their specific solution is based towards the channel technology. Thus, one finds that solution providers favouring Java based channels would have developed security, access management, user interfaces dictated by the functionality and characteristics of Java. It is extremely difficult to develop a channel access layer that is technology agnostic.

Sunday, February 17, 2008

Mobile Banking Fundamentals


I thought that it could be worth my while to document the different components that constitute mobile banking the way that I see it. Many different views of mobile banking exists in the market today. These views of banking are often driven by the realities of different markets. It stands to reason that mobile banking solutions applicable in a London main-street bank and mobile banking in war-ravaged Congo will be different. But surely there should be some similarities. It must be possible to find elements of the same thing in both.

I do believe that mobile banking can easily be made up of five components. Every mobile banking deployment must have all five components. Some of these components may already exist in some instances or in others all have to be sourced (because nothing exists). In some instances two or more of the components are bundled together and are almost undistinguishable as separate components. Yet the following framework is a sound way to think about mobile banking. The components are:

1. Mobile channel access

2. m-Commerce management layer

3. Banking transactional manager

4. The value store system

5. Administrative support

In the next few blogs, I will describe each of these in more detail.


The story of the Nano and Mobile Banking

I have heard Mark make this comparison at the MWC in Barcelona and thought that it was very apt. Now I can point prospective readers to his blog to read it themselves: What do Tata’s Nano and Mobile Banking Share?

Friday, February 15, 2008

Premium SMS futures

I have often been asked why Operators don't drop the share of Premium SMS's, so that this is not such an expensive payment instrument. The fact of the matter is that they can't. Many cost elements are built into SMS's that must be recouped by the Operator and they just don't have the lee-way to discount more. One may argue that it does not cost the Operator anything to deliver an SMS from a technology perspective and this is of course correct.

But a review of the other cost elements (especially regarding distribution, billing and in-built inefficiencies), have created a cost structure that represents (according to my calculations) in the region of 25% of the amount billed to the customer. It is therefor impossible for the operator to reduce their portion of a premium SMS billing much below 30%.

As such, a premium SMS is a highly inefficient payment mechanisms (for the operator, the service provider and the subscriber). As a matter of fact, the availability of an alternative payment mechanism will benefit the total mobile payment eco-system. It would be interesting to see the development of this into the future.

The SIM is built in


As I passed through Heathrow on my way back to Cape Town, I saw this billboard. I have known for some time that Intel have built GSM support into their new chipsets and was waiting for the first products to hit the market... and here it is. Dell have built a laptop with support for broadband where-ever you are and this is a big advance.

But what is really exciting for me is the convergence of mobile payments with computers that this technology allows. A SIM built iin a mobile phone provides for an effective vehicle to distribute secure elements. Any serious payment solution with aspirations to provide bank robust payment solutions should be based on the usage of a secure element in some format or other. This is why mobile payments utilising SIM cards are so powerful and of course secure.

With on-board access of a SIM card in a computer, this opens the door for very secure payment solutions. It will be interesting if any announcements based on this architecture will be forthcoming.

Tuesday, February 12, 2008

Is this the year of mobile transacting?

I have now spent three days at the Mobile World Congress. I have met many people and have sort-of walked through all of the halls. I think that it is safe to say that this year no clear theme is dominating. In the past Mobile TV and Advertising was clearly the talk of the town.

I have found the many different mobile phones very interesting. Some of the models that were on show from iMate, Palm and Blackberry were interesting. Even Garmin have now produced a phone (designed to be a super GPS of course). Handset manufacturers from the east have also shown great handsets. I found the Viewby from LG to be the most interesting.

If a dominant theme were to be picked, then I think it probably would be Mobile Remittances. The workshops and presentations on this topic was hugely oversubscribed. Maybe this year is the year of mobile transacting.

Monday, February 11, 2008

Build your own

It is quite amazing that many operators have opted to build their own mobile banking solutions. Quite a few examples exists of which the mPesa initiative that Vodafone have rolled out in Kenya and have announced initiatives in Russia and Afganistan is probably the most famous. In a survey conducted by Edgar and Dunn recently, it was found that 48% of mobile operators are considering building their own wallet solution (rather than buying it). The question needs to be asked why this is the case.

It is an accepted fact that no reputable company would even think of attempting the development of their own general ledger system. This is just unthinkable. It would never be sensible to do this as it would be too expensive and too risky from a general auditability perspective. Yet Mobile Operators (with very little skills as banks), are contemplating building their own banking systems (because wallet solutions are for all considerations the same as bankings systems).

In thinking about this phenomena, I can think of three reasons why they would consider doing this. It could be that mobile operators think that they can build competitive advantages into the mobile wallet solution. This may be the case, but this will only be the case in the short term, when successful solutions will be copied by competitors. Another reason could be because of internal politics and based on the aspirations of staff members of the mobile operator.

Another reason could be that mobile operators are under the perception that no reputable mobile wallet vendor exists that are able to provide scalable, industry robust solutions. If this is the case, the wallet solution industry have a lot of work to do.

Sunday, February 10, 2008

Explosion in mobile wallets


In a report released by Edgar, Dunn and company (under contract by the GSM Association) today, an explosion in mobile wallets is predicted. Based on solid research, the report predicts a growth from 10 million wallets today to more than a billion wallets by 2015. If this were to only materialise partially, this would be the biggest financial revolution in the history of mankind. To grow from almost nothing to a third of the world's population would be nothing more than miraculous.
The interesting thing about the research is that it was based on the opinion of market leaders in the mobile industry. Executives in mobile operators (representing 30% of the global subscriber base) were interviewed and the results were based on their opinions. Another interesting finding is that wallets based on and utilising elements of the SIM card is by a factor the preferred technology for the deployment of mobile wallets. See a previous entry in my blog.

Monday, February 04, 2008

NFC Science Fiction


In a recent Aite report it was found that one could expect only about 2.0% of merchants to have the capability to accept contactless payments in the United States. This would be the case after five years from now. Surely this is a HUGE stumbling block to even think of NFC payments as a remotely viable product.

If this information is correct, it is highly unlikely that any NFC product can be made commercially successful. Why would any-one consider walking around with a payment product that will only be accepted at 2 in every 100 outlets? The report also highlights the challenge of providing every player with a slice of revenue that will make it worth their while to deploy and push this infrastructure. It is almost as if every-one is working on NFC solutions when no problems exist that needs solving.

In my opinion, NFC payments is not a silver bullet. We all know the form of the hype curve. It is not difficult to judge where NFC is on this curve on the moment. Next phase: valley of disillusion.

Sunday, January 20, 2008

The Mobile Banking Eco-system

One of the most complex problem in deploying mobile banking systems is solving (or establishing, or nurturing) an eco-system for the development of mobile banking services. Generally, observers describe mobile banking as a clash between banks and mobile operators. But in reality the different players that are impacted by the deployment of a mobile banking solution are much more. It is critical to understand all the players, their fears and aspirations before starting to tinker on the delicate eco-system of payments.

Of course, if mobile banking is limited to balance enquiries and a few simple transactions, the impact is much smaller. However, when advanced and (sometimes) radical mobile banking solutions are deployed, the impact on the eco-system is much bigger. The participants that should be considered are the following:

1. The banking community should be the custodians of banking and payments in all markets. Banks usually have strong ideas about payment systems. They tend to try and conform to industry standards and are generally more conservative... rightly so. They look after our money.

2. Sometimes card issuers are different entities than banks. They are usually driven by the number of cards that they issue and the number of merchants that would accept their cards. Any scheme that could potentially disrupt this gameplan are usually viewed with aggression.

3. It is possible to offer mobile banking without the collaboration of mobile operators. However, if they are part of the mix, they can bring their distribution network, their strong brand to bear to ensure a much more successful deployment. Collaboration with operators also lead to more effective and secure solutions.

4. Central banks and other regulatory bodies are central to effective deployment of mobile banking. Often specific challenges (like deposit taking, open of new bank accounts, settlement and foreign currency transactions) can only be solved with the support from the central bank.

5. Cash handling companies are important in many countries - especially when the economy is still a cash-based economy. These companies (sometimes they are banks and sometimes even the mobile operators - but often independent) deliver and fetch cash from remote places and are often key to the functioning of micro-economies. Mobile banking and payments puts the business of these companies at risk.

6. Payment processors are often highly influential in the payment profile of a market. These companies process millions of transactions from ATM's and POS's. Their businesses are totally dependent on ensuring that the source of these transactions are not threatened. Mobile payment can be an opportunity for them or they could see it as a dangerous initiative.

7. Airtime distributors are often-time very powerful companies. In some cases the mobile operator distribute their airtime themselves, but in most markets these are independent (yet very powerful) companies. Any change to their margins, marketshare and control over the distribution of airtime can have a major impact in their livelihood.

8. Infrastructure suppliers could either benefit or loose out depending on the way that mobile payments are deployed. Often mobile payments lead to a reduction in the need for ATM's and other payment infrastructure.

This is not a complete list, but serve to illustrate the complexity of the environment. Also, different players will have a different relative strength in different markets. The important fact is to consider all of these (and more) and to develop plans to address threats and opportunities. Failing to do this, will seriously jeopardise any mobile banking deployment.

Wednesday, January 16, 2008

Jump in APM's

APM's? Alternative payment methods that is. In a recent survey conducted by solution specialist company, Brulant, it was found that retailers are offering more and more APM to customers. As a matter of fact the growth reported is a staggering 25% more retailers in the past ten months. (Up from 24% to 30%). Payment methods like "Bill me Later", Paypal and Google Checkout have been the biggest gainers.

What intrigue me about this is "Why?" Why not just sticking with the good old Visa and MasterCard mechanisms? They have been serving us well for the past thirty years. What is different about the APM's and why would shoppers want to use alternative methods? I suggest three reasons:

1. Security. The existing credit card rules place a lot of risk on retailers. In the case of fraudulent transactions, retailers are often the biggest losers. Even though the credit card companies have done much to reduce this risk, the process is still onerous and places the retailer at a disadvantage.

2. Ease of subscription. The difference in enrolling for a credit card vs. getting a payment instrument and registering online is still too big. Especially for certain segments of the market enrolling for an APM is still much easier.

3. Degree of anonymity. Shoppers require a certain degree of anonymity for many services offered in virtual space.

Why talk about APM's on a Mobile Banking blog? Because Mobile payments solutions can surely be classified as an "APM", and many of the lessons of this study should be considered in the development of mobile payment solutions.

Saturday, December 29, 2007

Prosperous 2008

Just a thank you for every-one that has made some time to read my blog during the past year. Thank you for bearing with me and some of my wayward ideas. I also appreciate all the feedback and comments. Also thank you for referencing this blog on others. I am humbled to see what great entries on mobile banking are published on the other blogs in this space. See the links on the side (all worthwhile reading).

Anyhow, wishing all of you a prosperous 2008. It is (no doubt) going to be an amazing mobile banking year.

Tuesday, December 11, 2007

A new record!

Today's Google Alert for "mobile banking" delivered 29 hits. This is by far more than what has been delivered to me in the past. Although not a direct metric of mobile banking take-up, it does indicate an fast growing interest in mobile banking. Much more people are talking and writing about it.

Saturday, December 08, 2007

Three rules to defend against e-Fraud

After having read my previous blog-post, I realised how scary it can be for un-informed people doing their banking in the electronic world. I thought one can make it simple by giving three simple rules to consumers that will make banking much safer. In my view these are:

1. Never write your passwords, PIN's or any security information down. Make sure that no-body can see this information or steal it in any way. When you feel that this information has been compromised, contact your bank or log on to the website or mobile phone and change the secret information to something else immediately.

2. Never communicate with your "bank" via a mechanism or channel that you are not fimiliar with. If your "bank" phone you or send you an e-mail or SMS requesting you to give security information, don't do it. Rather contact your bank via channels that you have used before (a known website, a known telephone-number or menu on your phone) to check this unsolicited request.

3. When your phone dies unexpectantly, phone your phone from another phone. If your number rings and it is not the phone in your hand that rings, chances are that your SIM has been swapped illegally. Phone your mobile Operator and report your phone as stolen so that they can switch it off immediately. Even if this does not stop a bank fraud, at least it will stop some-one calling on your account.

As with anything in life, safety is common-sense. People feel safe in their houses only because they know that they must lock-up at night. People feel safe in their cars, because they put on safety belts.... to feel safe in doing banking remotely, one must stick to a few simple rules.

Another SIM swap fraud


I was phoned by one of South Africa's popular radio hosts (Bruce Whitfield) on 567 Cape Talk on Friday to ask my opinion on another recent fraud perpetrated by means of swapping the SIM of the target account holder (See story) (Transcript of the call). It is of concern that these incidents are creating the perception that mobile banking is not safe, as it does not have anything to do with mobile banking.

In order to explain this statement, I need to describe how South African banks have improved Internet Banking by utilising an additional channel to improve the security of sensitive transactions. Most South African banks enable customers to log into their Internet banking websites in the acceptable ways through entering Username/Account-number and a secret password. Some have even improved on this by utilising soft-keypads (to counter key-logging attacks) and partial passwords. Typically this would be viewed as "strong-enough" security in most places in the world.

However, most South African banks have improved on this security by also sending a one-time password to a client's mobile phone for sensitive transactions (e.g. registration of a new beneficiary). The client is then required to enter this one-time password into the Website. This is an ADDITIONAL security mechanism for Internet Banking.

If the passwords of a victim were compromised (either by means of phishing, resetting or physical stealing), a fraudster would have been able to commit a fraud in most other countries. However in South Africa, the fraudster is now also confronted with the need to have access to the one-time password that will be sent to the victim's mobile phone. It is in these instances that an illegal SIM swap is performed to get access to the one-time password.

This fraud is solely to perform an Internet Banking fraud and has very little to do with mobile banking. We at Fundamo have deployed more advanced functionality that would have countered even these types of frauds which I will not publish. What we have deployed for one of our clients is a feedback mechanism from the Mobile Operator that would render the sending of a one-time password temporary suspended in the case of a SIM swap. The customer is then required to confirm the SIM swap with the bank first (via other security mechanisms), before the transaction can be completed.

Thursday, November 29, 2007

More evidence of traction


According to a number of press releases today, Bank of America have reached 500 000 subscribers to mobile banking within five months. Amongst others, the story wqs picked up by CNN. I am of the opinion if this was the case with any other product launched by the bank, everybody would hail it as a big success. I looking at Bank of America's mobile banking offering, a number of things struck me:
  • A link to mobile banking can be found on the Bank of America home page. This is an indication that they view mobile banking as mainstream.
  • They have registered a .mobi domain-name (www.bofa.mobi). No sense in doing this, if you don't view it as important.
  • They spend a lot of effort to demonstrate the solution, by making use of the media, special blog pages, videos etc. At least they understood that the public would only respond if told about things... and it seems as if they were right.
Now they just need to improve the offering with more innovative services.

Tuesday, November 27, 2007

Secure Mobile Banking


The perception still exists that mobile banking transactions in Africa is based on low security SMS technology in the clear. Nothing can be further from the truth. All of the more serious mobile banking security deployments (MTN banking, Celpay, 121Cellmoney, mPESA, MODE) are much higher than most other payment solution. The advantage of the deployments on mobile phones is that you can design extremely secure transactions. This is achieved by making use of the crypto keys that are resident on the SIM card in GSM phones. In our solutions, we employ many innovative designs to ensure very security solutions:

1. All messages are encrypted on the phone using the keys on the SIM with 3DES encryption algorithms. This is application-based encryption - not just carrier encryption.
2. All messages on GSM networks are compressed and then encrypted again using GSM protocols (every message is thus encrypted twice)
3. The PIN entry is accepted by a special program resident on the SIM card (impossible to replace with Trojan horses or Phishing attacks).
4. The PIN is never stored, it is encrypted on the SIM card according to Banking specifications. (As a matter of fact, Fundamo technology was the first to be certified by Mastercard according to PPED specifications for banking transactions)
5. Each payment message is MAC'ed with a special tamper-proof algorithm, that protects against Man-in-the-middle attacks and possible re-playing of messages.

By the way, the biggest transaction value on our solution was a business to business payment of more than US$ 50 000. This will never be possible with SMS's in the clear.

Thursday, November 22, 2007

Research confirming growth in Mobile Banking


Recent research released in South Africa by World Wide Worx, have some very interesting findings about Mobile Banking in South Africa. The advantage of this research is that it has been conducted for the past three years. Clear trends can now be formed comparing the findings of 2005, 2006 and 2007. The results show an explosion in the usage by end-consumers of mobile banking. In this survey the number of respondents that have used mobile banking during 2007 have jumped to 17% (from 8%). In addition the research found that more than 50% of respondents plan to be using mobile banking by 2008.

However, the most interesting result of the research (which also tracks other services delivered via mobile phones) is that mobile banking is by far the mobile service used by older people. According to the research the likelihood of using cellphones for banking services increases with age, in contrast to the usage of other cellphone functions going down as users get older. For instance, urban cellphone users aged from 46 to 55 years are twice as likely to use cellphones for banking as those in the 19 to 24 age group.

I think some analysts might want to take notice of these findings.

Monday, November 19, 2007

Qualcomm investing in GSM technology

This was a major announcement last week and quite a surprise to every observer of mobile banking: Qualcomm intends purchasing Firethorn for $210 Million. In looking at this announcement many questions will probably stay unanswered, but it is still good fun to ask them:

1. On what basis did Qualcomm get to a valuation of $210 Million? Firethorn had very little revenue and to all accounts technology that have not yet been proven in robust business environments. The number of subscribers utilising Firethorn technology is so low that this could also not have been the basis of the valuation. Seeing that Qualcomm is a publicly traded company, one would expect some more info being made available rather than the sketchy press release provided last week.

2. How does the major partners of Firethorn feel about the acquisition, and have they been consulted? It is really interesting that Qualcomm (major CDMA and Brew supplier) should purchase a Java based company with some of the major GSM Operators as customers (Verizon and Cingular). Interestingly, neither Verizon nor Cingular are mentioned in the press release (only the banking partners).

3. Qualcomm is currently an investor in Obopay - a direct competitor to Firethorn in terms of their technology and business model. What does this acquisition say about the future of Obopay? Does this mean that Qualcomm has discarded Obopay? Are they thinking of merging the propositions... very difficult. I just have difficulties getting my mind around this.

4. Which investors will gain most from this transaction and how could they have influenced the transaction? Maybe this deal does not have anything to do with the fundamentals of the solution and how this will change the landscape of mobile banking, but rather about more complex economic principles that not all of us can understand.

If I were a Qualcomm shareholder, I would really have felt aggrieved about this transaction, but then, I am not and now I am just frowning...

Saturday, November 03, 2007

Mobile banking in Africa

Fundamo was one of the first companies that demonstrated a working mobile payment solution with the first pilot in conjunction with Boland Bank announced during 2000. Absa Bank launched the first commercial mobile banking solution during 2002 in South Africa. Absa claims that more than 300 000 subscribers have enrolled for the service to date. This early launch have been followed up with launches of different types of solutions from Standard Bank, FNB, Nedcor, Investec and others. Although numbers are not readily available, a rough estimate of more than a million mobile banking subscribers is not far off. This is amazing if one considers the short time that mobile banking has been available.
During the past five years many initiatives were announced and often launched in South Africa. Many large technology companies and smaller ones made announcements and then disappeared again. South African companies that offered mobile banking solutions include Prism, Namitech, Cointel and Paym8. The launch of Wizzit in conjunction with Bank of Athens was so spectacular that they featured on CNN, Financial Mail and many other publications. Citibank and Standard and Chartered played with ideas to use the mobile channel to enter the South African market with a different and exciting angle, but did not implement.
The launch of MTN Banking during 2005 can be considered as the ultimate mobile banking solution with many new angles and an exciting offering. Combining mobile concepts with banking a totally new banking experience was created. Some of the concepts like "a banking starter pack", "pay as you bank" etc. worked well to grow a subscriber base quickly into hundreds of thousands of subscribers.
Today, South Africa is one of the leading examples of successful mobile banking deployments.
With the exception of South Africa and the successful deployments of Celpay in the DRC and Zambia (supported by Fundamo technology), quite a number of other examples of mobile payment and banking solutions exist in Africa. Celpay is one of the first mobile payment solutions deployed in the world and provides advanced payment functionality in countries with little (if any) payment infrastructure. It has been reported that Celpay payments in Zambia now accounts for almost 4% of the GNP.
Nigeria
has turned into a hotbed of mobile payment innovation with one of the mobile operators Glo offering a product called Glomoney since launch. This solution provides mobile payment features on ATM cards from most banks. The solution is supported by one of the ATM switches called Interswitch who is now rolling this out to other banks and talking of providing it also via Celtel. (The solution initially available on special SIM cards, is now also available via a Java client to be downloaded on the phone). Other successful initiatives are from a company called eTranxact whom operates the solution themselves. The same technology is currently in production in Zimbabwe with Kingdom Bank. Flash-me-Cash is a SMS based viral payment mechanism that are claiming to have more than 500 000 subscribers and is based on a structured SMS solution.
Another area in Africa with a number of initiatives under way or in production is Kenya and surrounding countries. A number of banks recently announced mobile banking solutions. A noteworthy example is Consolidated Bank with a USSD mobile banking offering. South African company, Paym8 have deployed their solution since 2005 with Safaricom and is claiming an acceptable take-up. Card payment acquirer, iVeri (a Blue Label company) offers mobile payment functionality in Rwanda. One of the most important initiatives, however is the Vodafone backed mPesa initiative. This technology (developed in London) has been in pilot deployment since early 2006 and was recently placed in production with Vodafone subsidiary Safaricom. mPesa is receiving massive backing from London and is poised to be rolled out to other Vodafone networks (Egypt and possibly South Africa). The technology is SIM based and well designed with good “cash-out” functionality. A recently announced collaboration with Citibank allows for money remittance from London to Kenya.

A North African example is the roll-out of a mobile payment solution in conjunction with VISA in Morocco. The technology utilised was provided by French company Upaid and supported in country by Maroc Telecom and BCP (a bank). Other examples in North Africa are initiatives launched in Egypt and Tunisia.

A perspective on the History

The first mobile banking and payment initiatives was announced during 1999 (the same year that Fundamo deployed their first prototype). The first major deployment was made by a company called Paybox (largely supported financially by Deutsche Bank). The company was founded by two young German’s (Mathias Entemann and Eckart Ortwein) and successfully deployed the solution in Germany, Austria, Sweden, Spain and the UK. At about 2003 more than a million people were registered on Paybox and the company were rated by Gartner as the leader in the field. Unfortunately Deutsche Bank withdraw their financial support and the company had to reorganise quickly. All but the operations in Austria closed down.
Another early starter and also identified as a leader in the field was a Spanish initiative (backed by BBVA and Telephonica), called Mobi Pago. The name was later changed to Mobi Pay and all banks and mobile operators in Spain were invited to join. The product was launched in 2003 and many retailers were acquired to accept the special USSD payment confirmation. Because of the complex shareholding and the constant political challenges of the different owners, the product never fulfilled the promise that it had. With no marketing support and no compelling reason for adoption, this initiative is floundering at the moment.

Many other large players announced initiatives and ran pilots with big fanfare, but never showed traction and all initiatives were ultimately discontinued. Some of the early examples are the famous vending machines at the Helsinki airport supported by a system from Nokia. Siemens made announcements in conjunction with listed and high-flying German e-commerce company, Brokat. Brokat also won the lucrative Vodafone contract in 2002, but crashed soon afterwards when it run out of funds.

Israel
(as can be expected) produced a large number of mobile payment start-ups. Of the many, only one survived – Trivnet. Others like Adamtech (with a technically sound solution called Cellpay) and Paytt disappeared after a number of pilots but without any successful production deployments.
Initiatives in Norway, Sweden and France never got traction. France Telecom launched an ambitious product based on a special mobile phone with an integrated card reader. The solution worked well, but never became popular because of the unattractive, special phone that participants needed in order to perform these payments.

Since 2004, mobile banking and payment industry has come of age. Successful deployments with positive business cases and big strategic impact have been seen recently.

Sunday, October 28, 2007

Will People Use It?

It is such an amazing situation for me - this constant question: "will people use it?". It is like self-fulfilling prophecies. It seems to me that that is what analysts do. They take positions and then their positions make things happen... and we easily forget when they were wrong.

Take Y2K. Even weeks before 31 December, the world was only 63% ready. Yet nothing happened, except that the world spent billions to be "ready".
So why can't analysts get themselves to say that if banks don't deploy mobile banking they will be out of business in ten years.... like they did with Internet banking? Maybe it is because there is nothing sexy about stating the obvious. Lets just take one case study in South Africa. A bank called First National Bank (FNB), launched mobile banking in little more than two years ago. This is some of their results:
  • Have more mobile banking customers than Internet banking customers within two years. It took them more than fifteen years to get to the same numbers with the Internet
  • The monetary value running through their mobile banking deployment have risen to a point where it is conceivable to outstrip credit card purchase volumes in the next year.
  • The service became profitable within eighteen months - now adding a sizable value to the bottom line.
Will people use it? Come-on, get real..

Tuesday, October 16, 2007

Mobile Banking Fraud!


Two cases of transactional fraud was recently reported in South Africa. The one related to the arrests of waitresses at a well-known restaurant. Waitresses were paid for "skimming" of credit card information, which were later utilised for fraudulent transactions. Read more here.

In the other it was reported that criminals conducted fraudulent transactions on ABSA clients, by swapping client's SIM cards. Read more about it here. This was a much more elaborate sting and was based on a security measure implemented by ABSA where a one-time password is sent to a clients cellphone for entry into a website. By swapping SIM cards, criminals could intercept this critical and important password in order to complete the fraud.

Both of these fraudulent acts were possible because of a weak Dual Factor Authentication (DFA)implementation (or the lack thereof). Criminals were able to steal clients' identity, because this was solely based on one factor (the card, or the mobile phone). If one managed to intercept this device (only one factor), one would have access to the client's financial information and it is possible to commit a fraud.

An improved version of DFA would have prevented these frauds. For instance, even if the SIM have been swapped, the one-time password would only be visible after entry of a private key, or if the card have been skimmed, could only be used if a secret PIN entry is required before a payment can be completed. Both these designs are incorporated in Fundamo technology, which makes it the most secure mechanism to interact with your bank.

Sunday, October 14, 2007

Perceptions of Banking in Developing Worlds


It is a phenomena that many observers have seen: Mobile banking is taking off in developing world more rapidly than in first world economies. Many people have asked why? I have now come across a number of people that seems to imply that this is because people in developing countries are prepared to use inferior products, that they would not mind using mobile banking if it is insecure or not usable - this is so far from the truth and is an indication of a lack of exposure and understanding.
Mobile banking deployments in Africa are far more advanced (both technologically and conceptually) than what is available in other parts of the world. These solutions deploy the highest degree of security and design than any I have seen. (and I have been around). As a matter of fact these solutions represents a quantum jump in security and features. If true (which I think you may doubt anyhow), why would this be the case?
I believe this came about because of the following reasons:
a. Development of mobile banking in Africa was developed "under the radar". It was not scrutinised as is usually the case with advances in technology. Nobody felt like copying the developments or even to analyse them in more detail. This lead to the development of extremely advanced secure solutions over almost TEN years, without any-one else doing it.
b. Africa do not have any legacy systems. As we all know, legacy systems often constrain systems development. Mobile banking systems in the early days were not exposed to these constraints.
c. When you have very little and have lots of needs, you are more prepared to experiment. This was/is the case in Africa, where subscribers, corporates and governments embraced mobile banking as a means to alleviate many of the problems of Africa. Also in these situations you are more forgiving. This allowed mobile banking to evolve to a very powerful solution.
It pains me when people belittle the technology from developing economies. This technology is far more advanced than what is available in developed economies. If you don't believe me, come and have a look.

Monday, October 01, 2007

Mobile Money


Mobile Money is the brand that MTN banking also use in their deployments in South Africa and on their other networks in Africa. We are the primary technology partner for all of these deployments.

But then, "Mobile Money" is a very widely used brand name, as a simple Google search show. I know that everyone can do a Google search so at the risk of boring the reader I thought I would pick my fovorites:

1. Mobile money is the name of a lending company in the UK. I don't know why they call it MM - probably because the loans fly off the shelf.
2. In Malaysia Mobile Money is owned by entrepreneur Lee Eng Sia, who is also known for Cutie Compact toilet rolls which he pioneered and seems to be a well known brand in Malaysia. An yes, MM in Malaysia is the name of a mobile payment solution.
3. The mobile payment solution mPesa (currently being deployed in Kenya and supported by Safaricom/Vodafone) is supposedly Swahili for "mobile money".
4. Mobilemoney is the name of an application that can be loaded on the iPhone, Palm or Winodws CE devices with which you can manage your financial information.

So it is absolutely clear that Money is getting more and more mobile.