Tuesday, May 13, 2008

"The Branch is Back"

VRL Knowledgebank recently announced a new report: "the branch is back" (see more info here). The summary of the report reads as follows:
"The global retail banking industry is now in a period of innovative commitment to the branch, arguably not seen since the early 1990s. This quiet revolution is dealing with a more broadly-based agenda than just branch design, and is focusing on creating more customerorientated experiences and greater retail banking profitability."
If interested in the content, you can pay almost € 2000 to get access to the content.


From a mobile banking perspective, this is of course bad news, so I tried to get a bit more information on why a report could come to such a conclusion. I did not want to pay such a big price-tag just to find why these analysts see a different world that I do, so I used the information available for free. I could find no reference in the Contents page on how the evaluation was done to get to such a conclusion - now survey, no relative profitable measurements, nothing that could make one make such a statement.

I saw that the report refers to many case studies (predominantly in the UK and the US - not the markets where branchless banking is expected to be big), but did see reference to a case study in India (where, I presume "the branch is back"). The case study is for a bank called YES bank, which when you do a Google Search returns the following:

"Obopay India and YES Bank launch instant money transfer via mobile..."

Maybe the branches are required to sign up the mobile banking customers.

Saturday, May 10, 2008

Regulatory Challenge to Mobile Banking

South African tax year ends at the end of February and tax returns must be completed and filed by about July every year. This is a terrible time for me, because I have to go through all the forms and filing to ultimately submit this declaration. Sure it is a challenge for me as I do not like filling in the forms and collecting all the information, but I get it done every year, now for almost thirty years. I also draw on the expertise of my accountant who has been doing this for a long time and actually enjoys doing it.

When talking about regulatory challenges for mobile banking, I was trying to get this clear in my mind, what we mean by challenges:
a. Is it impossible to do, or we don't know how to do it and therefor a major barrier to deploying mobile banking
b. It is possible to do but maybe complex. We can do it but we have to fill in a number of forms and conclude agreements. We can work with experts that have done this before and know exactly what must be done.

In terms of my reference framework, it is b). What do you think?

Wednesday, May 07, 2008

Gartner is cautious

Gartner produced research indicating that mobile payment subscribers will increase from 33 million to 104 million subscribers in the next three years. This is quite conservative compared to some of the other recent results (see my blogs on this here and here) that were produced by other research companies. Especially their estimate of (only) 500 thousand mobile payment subscribers in Europe at the moment. I think companies like paybox in Austria would be surprised that they have more subscribers in Austria than those that Gartner counted in Europe... wait a minute, last I checked Austria was in Europe. Also the fact that they did not count African subscribers - does that mean that they do not know about the massive penetration of mobile payment subscribers in Africa (my estimate between 7 and 12 million), or that Africa does not exist?

I still remember a previous estimate that Gartner got terribly wrong: the "75% probability that 60% of companies were not ready for Y2K" predication. After all the angst that they produced during 1999, maybe policy now is that they should play everything down?

Monday, May 05, 2008

Airtime as Currency

I should have blogged on this before, as this is a hot topic. Many examples of schema that utilise airtime as an alternative to real currency can be found. These solutions either provide for person to person payments and also for remittance solutions in a number of cases. The question now arises if this is not the way to go.

My take on this, is an emphatic NO! This is for one just not sustainable (see some of my comments below), but also potentially extremely hazardous to the underwriter of this currency (the mobile operator). If this approach really takes off and more and more currency needs to be produced to support the demand (money supply), serious problems like inflation, run-on-the-bank etc. could materialise. Mobile Operators are not in a position to deal with this. If they fully assess the potential implication on a devaluation of their airtime stock, I believe that they would put measures in place to stop it immediately (like elapse dates on pre-paid airtime). They should be apprehensive to ever start treating their airtime like money in the hands of consumers.

In addition, I think that using airtime for money in any format is totally unsustainable, because I believe that using airtime as money would be:
  • Very expensive
  • Totally inefficient as compared to proper e-money solutions
  • Does not provide security to the client
  • Would be illegal in any properly regulated environment
If airtime is being used as currency, it should be seen as an absolute indication of banks failing to
provide in an obvious need.

So what about NFC?

I have been critical of many things on my blog. I have highlighted the problems with premium SMS's, Internet payments, Chip and Pin and many other approaches to solving payment problems. In the same way I have discussed problems that I see with NFC solutions (As far as I can re-collect twice: here and here)

I don't think that we can ignore the growing interest in NFC payments and when today I was asked twice why I don't support NFC payments, I realised that I should post a firm position on this blog.

Card-based proximity payments is nothing new. We have stirling examples of these having been deployed successfully. I am the proud owner of a Oyster Card myself (even though I don't live in London). I really enjoy seeing how seamless everything work, each time I have to use the underground.

So here is my position: To merely replicate these kind of payments by replacing the card with a mobile phone does not add much value, and I believe that most business cases will be rickety. If we were to utilise the new NFC capabilities in phones, I think it is critical to be much more innovative about these features. Some of the things that we should possibly develop (not an exhaustive list) is:
  • On phone wallet applications
  • Phone to phone NFC interaction (I personally think that this is one potential killer app)
  • OTA issuing (another killer, but extremely complex and challenging)
  • Mobile data interactions between the application on the phone and back-office
At the end of the month, I will be speaking at a high-level NFC conference. I was invited...

Monday, April 21, 2008

Positive report on mobile banking

Juniper Research released a very positive report on the growth of mobile banking from now till 2011, today. According to the research, subscribers will grow tenfold from now till 2011 to ultimately be 816 million (this is very close to the predictions made by Edgar Dunn (see my comments on this here). In addition transactions will increase from 2.7 billion to 37 billion during the same time.

What I found particularly interesting about this report is that the analysts tried to not only predict number of subscribers, but also number of transactions. This is of course important because it is an indication of how much banking will be used. I have done some quick calculations of the findings and this is what I found:
  • The prediction is that every subscriber would (on average) do more than three banking transaction per month on their mobile. I found this to be quite low based on the experience that we have had with Fundamo deployments. We have seen transaction volumes that is as high as three transactions a day (or even higher).
  • The volume of transactions will have to more than double every year to grow to these volumes. If the hockey-stick is more steep, growth could even be more spectacular.
Seems like we should be expecting some very interesting times in mobile banking.

Regional Regulations

This is something that have always intrigued me. Everyone that knows would agree that none of the countries that constitute the Eurozone is the same. Especially if one were to consider the different payment solutions and customer orientation towards these, one observe massive differences. Some countries are still heavily dependent on cash payments, while others have installed sophisticated PIN-based payment systems. In some it is acceptable to do Internet payments and in others cheques are still in circulation.

Especially, if one were to consider mobile payments, differences are even more distinct. Initiatives in Nordic areas are not at all comparable to what is happening in Austria nor some of the great work happening in the Iberia peninsula. The challenges regarding money supply and cost of doing business are all different from one country to another.

So here is my question: "How can you regulate all these different countries with the same banking regulation?"

Tuesday, April 15, 2008

The Emperor without clothes

This is something about the Mobile banking and payment (MB&P - I have decided to acronymise this term now, because I use it such a lot) industry. We have more than our fair share of people and companies that make claims that is so far removed from what is possible and also what they are obviously capable of. This is possibly because such a lot of people have turned MB&P into something romantic - the next big thing...

One of the best know examples of a nude emperor were of course Simpay. While this organisation were busy with grand schemes in Europe, many were modeling their strategies on what Simpay was supposed to deliver. Many millions of dollars were spent on this grand plan that most of the industry was expecting to come true. I recall companies that were basing their whole product strategy on the assumption that Simpay would have dictated the standards for mobile payments. Yet for a lot of us (especially those that were intimately involved with the industry), we did not see any clothes. We did say so, but not too loudly, because others were looking strange at us.

There are other examples, I believe. Some with grand plans and ever more spectacular visions. Who will be brave enough to name them this time round. Well, let me give you a clue: A nude emperor this time round have a name that starts with F and have just been acquired by a company with a name that starts with Q.

What do you think?

Wednesday, April 09, 2008

Tridge Banking

The term “tridgets” made their debut in Barcelona, meaning mobile devices that depend 100% on the network for all controls and data. The term was coined (invented) by some-one in Accenture and it has been used in good slogans: "The first trillion tridgets".

As an aside, I was wondering where the inspiration for the name came from, when I found this little piece on the web:

"There were exactly fifty Tridgets, separated like stars on an American flag, perched upright, balancing skillfully on pegs that protruded from an angled board near the back of the booth. They looked soft, like chipmunks, no more than five inches tall. They had fur of variable designs. Some were spotted, some were striped, some were calico and some were patchy, with dominant colors of light grey, white or tan and accent colors ranging from bright orange to deep blue.

They had little pug, almost human faces, with little noses that curled slightly up. Their bulging eyes were blue, green or hazel. They all had tight, curly, tails that were similar, but fatter and much furrier than that of a pig. Perhaps the most adorable thing about these little fuzz balls were the large pointed ears, bent at different angles just below the tips.
" see webpage

Little "fuzz balls"?

Anyhow, I tried to understand the implication of our banking software now not just being available on mobiles, but also on Tridgets. This means we can now start talking of Tridge banking?

Killer applications

Most would agree that doing payments or banking is not fun. It is not something that we would do if we could help it. (Well, maybe with the exception of receiving payments!). To provide sexy banking services is a contradiction in terms in my book. This is one of the reasons why mobile banking and payments will never prove to be successful unless it can be used for something, ... well sexy.

The mobile banking and payment industry refer to these things that you can do with mobile banking and payments as the "killer applications". Giving access to your consumers to "killer applications" that they can pay for easily on their mobile phone is the trigger (and key) to a successful mobile banking/payment implementation. In this blog-post, I list a few categories of what applications have been "killing" and which ones are likely to "kill" in the future.


The most frequently quoted killer application is the ability to buy pre-paid airtime directly from your bank account using a mobile phone. I have heard some observers talk of this as being not that sexy, but some of the case studies are immense and only thing I would say is:"ignore air-time purchases at your own peril"

Others that have already been implemented and have proved to be successful are bill payments (low margins are the biggest challenge here), cash on delivery (big money here), payment for parking (requires enough cars and less parking to work - not the case in many countries), some examples of retail payments, payments for content and other pre-paid (e.g. pre-paid electricity).

Payment for the purchase of lottery tickets and other gambling applications have been implemented by a few operators, but it is my opinion that this has not proved to be that successful. I am of the opinion that this is because we have not yet figured out how to do this effectively on mobile phones - so that it works for the new form factor. Many people have ideas on how to turn this into killing applications, but I have not seen them yet.

Others that should also be mentioned in this blog are of course money remittance. Many examples of this type of application have been deployed with good successes. The challenge in this area is working with regulatory constraints and to turn localised deployments into global deployments.

Other killers that I sense are lurking will come from micro lending, export/import, other financial services and many niche applications (like transport, medical, content etc.)

Once again, what do you think?

Sunday, April 06, 2008

Security is in the eye of the bank

It is a common saying that security is only as secure as it is perceived to be. It is quite possible to develop many different security solutions that can protect what it is supposed to protect economically. (The cost of the system is less than the fraud that could be committed in the absence of the system)


Unfortunately this is not the criteria for a successful security solution that will be deployed and used. Rather it is if the security solution is perceived to be secure. In the case of mobile banking, the question should be asked "perceived by who?" and "what will convince them that it is secure enough?"

In the case of mobile banking, I would like to argue that it is not end-consumers that are the primary evaluaters of security. The key is not to ensure that end-consumers perceive mobile banking as secure, but rather bankers. In my experience, it is the banking fraternity that are uncomfortable with mobile banking security more often than not. Only if they are made to be comfortable with the security is it possible to launch a mobile banking solutions. Even when the end-consumer would have been happy long-ago, or even if the security solution can be proven to be economically sound, bankers will still resist.

So what is it that banks look for in a mobile banking solution:
  • Conforming to banking standards. Banks are comfortable if some-one else says something is secure (VISA or the PCI etc.) Problem is that few of these standards exists that can be applied directly to mobile banking. Also read this blog-entry.
  • Bankers like security if it looks like the security that they know and understand. They like PIN-blocks that are never stored and is never in the clear. They like digital security keys where the master keys are well-managed (preferably by a bank or a banking body)
  • Bankers like security where the liabilities are clearly defined in the case if something do go wrong.
  • Bankers like security systems where all of the functionality/components are under the direct control of the bank
Generally bankers are not enthused by maverick, sharp and innovative solutions to manage security, but rather using tried and tested approaches that can be mapped to existing procedures and internal banking rules.

In deploying mobile banking solutions, it is critical to keep this in mind.

Where is the money?

Mobile payments is an interesting concept. I have heard a lot of people talking about how making payments from a cellphone could be earth-shattering - how it would change the way that people shop and do business for ever. And I believe that they are right, but in order to make this vision happen we have to solve a difficult problem... where is the money?

No, I don't mean, how we are going to make money by running a mobile payment scheme. I mean, what are people going to use as money to pay with. If they complete a transaction and they hit "send" (or "pay") where will the money come from to do this payment. To put it in another way: "which account will be debited". Many different solutions have been suggested and implemented, but all have significant challenges. Below is a summary of some of the Value Stores that could be used as the money in mobile payments:
  • Using an existing credit card as the source for doing a mobile payment would seem to be the most obvious approach. This has successfully been implemented, but suffers from the following challenges: A relatively small percentage of people with mobile phones have credit cards globally, the transaction can be expensive as credit card fees must be paid before any other revenue can be generated and the rigid (but sound) rules regarding fraud places a very big risk on such an approach.
  • Using the mobile operator's billing engine as the source for payments have been proposed, but this approach can even be more expensive than credit card transactions. (See one of my previous blogs) . In addition, expect regulatory problems and significant challenges to extract cash out of the system. It is also unlikely that the mobile operator would be happy with sharing money earmarked for telecommunications with other retailers.
  • Utilising existing bank accounts could be interesting, but integrating telecommunication systems to core banking systems can be expensive and time-consuming. Also the strain on a banking system when millions of small transactions starts hitting it, can be outside the design limits of such a system.
  • A new dedicated mCommerce account may be the way to go. Remember that when credit cards (a new payment system) were launched in the 1970's, it came with its own dedicated account management system. Why should that not be the case for mobile payments?

Wednesday, April 02, 2008

Interesting Architectural Problem

ABSA is a leading retail bank in South Africa with a good mobile banking solution deployed. They were one of the first companies that have deployed mobile banking solutions in the world and have managed to grow their subscriber based to a substantial size. The solution has been developed and is supported by and internal team and is a very advanced deployment compared to world standards.

In order to improve security, ABSA recently deployed an SMS alert to their Internet Subscribers whenever the subscriber logs into the Internet Banking site. This means that a subscriber gets a SMS as soon as a successful login has been done.

An interesting side-effect of this deployment is that subscribers to their mobile banking service now gets multiple SMS's confirming that the user has logged on whenever a transaction is done on the mobile phone. This leads me to the following conclusions:
  • The ABSA cellphone banking application sits on top of the Internet banking application and requires a login for every transaction
  • The benefit of dual channel confirmation for an Internet login with mobile confirmation, turns into an irritation when the same confirmation is utilised for mobile banking
  • Security techniques for the Internet (especially when utilising the phone) is not directly applicable on mobile banking
  • It is a risky architectural design to bolt mobile banking onto an existing Internet banking application
As always, to stimulate debate... What do you think?

Mobile Banking and Usability

We have all lived through an amazing journey to see how fast mobile phones have grown in popularity. Many reasons for this massive growth have been given, ranging from the communication needs to fashion-awareness. One of the reasons for this growth in my opinion is that phones are so easy to use. I know that some people will disagree with me, but fact is that the majority of people use phones without (ever) reverting to a manual, having to go on mobile phone usage training or requiring assistance from family or friend. (Very different to what we have got used to in the Personal Computer Space).

So why is it that phones are so easy to use?

Usability design and testing has around as a formal discipline for the best part of twenty years. Mobile phone manufacturers (all of them) take usability very serious. Every design and every model usually go through rigorous usability testing cycles. Results are fed back into the design and never will a phone be released without a green light from the usability guru's. Industry advances and standards have made big leaps in this space. Techniques like the Mobile Phone Usability Questionnaire (MPUQ), the Usability Checklist for Mobile phones and many others are utilised in the design of mobile phones

Just a thought: how frequently have your mobile banking application and solutions been tested (or designed) for usability? have you contracted a supplier with a track record and capability to build mobile banking solutions that are usable?

I believe that this is the single most important reason why mobile banking applications are not being used as extensively as they could/should be. Most mobile banking applications have not been designed with due insight in and proper application of mobile usability techniques.

Thursday, March 20, 2008

Two Versions of the Same Story?

It is so important to read the media to follow what is happening with mobile banking. Many of the findings and research results related to mobile banking are published and discussed the media. I regularly scan what gets published.

Therefore, I was very disappointed when I saw the following headline in an on-line news-report: "
Americans not interested in m-banking" (Read more about this here). I read the article and found that it was based on some research published by Harris Interactive. The poll summarised the reaction of 1000 odd sample (not a very big sample and I am not sure how representative it is). I found some of the results very positive. According to my interpretation at least a third of the respondents were interested in mobile banking in some format or other. Although much lower than in other markets, this is still huge. Any other product to be launched in the US with a potential take-up of a third of the population would be described as having massive potential.

Anyhow, the next day I saw the following headline on another website: "Cell phone users open to on-the-go banking". (Read about it here). This seemed to be a much more positive view of mobile banking and I read on with interest. It turns out that these two headlines were articles reporting on exactly the same research and the numbers referenced were exactly the same.

Which all goes to show that some people view the half empty glass as half full. It is just a pity that the "half empty" journalists seems to be reporting on mobile banking more often than not.

Sunday, March 16, 2008

Institutions influencing mobile banking and payments


Initially, especially in Europe, the industry has seen the establishment of many standards bodies all trying to influence the industry. These bodies ultimately tried to advance the case of their sponsors or owners rather than the industry as a whole.

Lately, a number of institutions started generating traction and the industry is being formed through their actions. These organisations are either non-profit bodies looking after the interests of their members or are philanthropic in nature. It is important to take cognizance of their actions as they have a major influence on the industry today.

I have listed some of these organisations below. This is not intended to be a comprehensive list, but rather an attempt to trigger more thoughts and contributions. (In other words: help me to make this list more comprehensive)

  • The Mobile Payment Forum is one of the earliest institutions with membership from all participants in the mobile payment eco-system. Founded during the heydays of mobile payments in 2001, the organisation is currently trying to define its role and contribution, having moved its attention more towards proximity payments and mobile marketing.
  • The Mobey Forum is an organization initially established by major European banks (including Deutsche Bank, ABN Amro and others). A lot of the initial work was spent on developing security standards to be deployed amongst the banks. Since about two to three years ago Mobile Operators and Vendors were also invited to join and the organization became much more relevant.
  • The GSM Association have been especially active during the past few years. The MMT program was announced during the GSM World Congress in Barcelona (2007) with a number of objectives: To increase mobile operator revenue through financial services, to activate every phone to be able to send and receive money and to actively accelerate this through well-funded programs. In executing on these objectives, the GSMA is working closely with banks and other relevant organisations (e.g. Mastercard, Western Union etc
  • Pay Circle was founded during 2002 by technology companies (like Siemens and Sun) to advance the development of relevant technology solutions. According to the website, the mission was achieved and the organisation closed. There are other organizations that were also active in the past, but have subsequently disappeared. (like Radicchio)
  • CGAP (and the WorldBank) are very active to support mobile payment initiatives. A number of grants were recently announced and included amongst others grants for Consolidated Bank in Kenya, Tameer Bank in Pakistan, Wizzit in South Africa, XAC Bank in Mongolia. In addition to money CGAP also provides consulting support, excellent research and other guidance.
  • Finmark Trust is a South African based organisation with interest into Africa that supports the deployment of low cost financial services including through mobile banking
There this is a start. See if we can increase and add to the list

A perspective on Mobile Payments in Europe


Europe’s venture into mobile banking is characterised by many small initiatives that all failed. A case in point is the example of small Dutch company Global Payways with a product called Moxmo launched during 2003 with a mild take-up in the Netherlands. During the collapse of Paybox, Global Payways acquired the subscriber base of Paybox in Germany. This small company was soon in financial difficulties and had to disband services within six months of having taken over the larger subscription base. (Many reference, but read the following blog.)

Soon afterwards major mobile operators announced the Simpay alliance. Simpay endeavoured to provide a common payment platform between Vodafone, T-systems, Telefonica and Orange. While the European industry waited, Simpay had the central stage for three years and produced… nothing. This fiasco had a lasting impact on the European mobile payment industry.


A company that is quite visible at the moment is a company called Monitise. An initiative started by Morse with a Java based service on top of the ATM network is now being deployed by 1st Direct, HSBC and Alliance & Leicester. The company is very visible (because of a large marketing budget?) and is making big headway from a brand building perspective, but the technology offer little functionality to the subscriber. Recently Monitise listed on the LSE raising a substantial amount to fund the current burn-rate. Another company with a similar profile is the Finnish company called Meridea. With backing from Nokia and Accenture this company was the technology behind amongst others Standard Chartered mobile banking initiative. Unfortunately it closed its doors a few months ago when they ran out of funds.


A noteworthy deployment is the mobile payment solution supported by Banksys in Belgium. Banksys is the central ATM and POS switching company owned by the major banks. Banksys recently announced a SIM card based solution supported by all the major mobile operators that allows subscribers to make payments from their existing bank cards utilising the mobile phone.


The deployment of Paybox in Austria is still operational today and very successful. The service is available on more than one network, provides excellent functionality and utility and is used by close to half a million people on a regular basis. (This is quite a big coverage considering the size of Vienna where most of the subscriber services are available). The service is claimed to be profitable and is one of the best examples of a mobile payment solution that ultimately became successful because of dedication of management.

Thursday, March 13, 2008

PCI compliance for mobile payments

Many research reports and experts warn about the risks of allowing fraudsters and criminals access to sensitive credit card details. It is especially operators of financial and payment services that tend to be the biggest targets. Quoting Jon Kerr from Verisign: "It's no surprise that online banks and retailers are some of the most popular targets for identity theft since so many personal details are required by users,... With the average UK consumer worth over £10,000 to criminals, it's clear that each of us is a target."

It is because of this threat that the industry decided to publish a standard that a bank or payment processor should adhere to in order to provide acceptable protection to cardholders. This certification is known as the PCI compliance and is being driven by the Credit Card Associations. The objective of PCI compliance - to protect the consumer - is commendable and should be accelerated. Customers should be educated and should take their business away from banks and payment operators that do not comply.

An interesting question is how the providers of mobile payment solutions should (or should not) comply with PCI standards. In as much as mobile payment solutions touches card information the application of the standard is clear: None of the card information must be in the clear and it must not be possible for an un-authorised person to get access to this information. But what if no credit card information is used? What if the routing of payments are made on the basis of a subscribers telephone-number (as is often the case)? What should the minimum conformance be.

This topic is much more complex to deal with in the space of a short blog, but it is clear that the mobile payment industry should develop unique compliance requirements. Obviously this would be very similar to Card PCI compliance (catering for instance for access, un-authorised actions, reporting, physical protection etc.). But what about not displaying a telephone number when you could potentially see phone numbers of some-one just call you? What about look-up tables and what should the controls be around security elements?

It could be worthwhile to develop some of these rules pro-actively.

Wednesday, March 12, 2008

INCSR getting involved


I didn't know that the US Department of State pay good money for people with complex names like the Bureau of International Narcotics and Law Enforcement Affairs to produce reports like the International Narcotics Control Strategy Report (the INCSR). I cannot comment on the rest of the report, but the section that talks about "mobile payments - a growing threat" triggered my interest and I read it with attention.

I must say that the sentiments expressed and the conclusions reached is so far removed from the practices or the intention of the mobile payment and remittance industry. Very few of the statements regarding risks and lack of controls have been verified or tested against the existing practices employed by mobile payment vendors. Compliments to the authors for publishing the report on the Internet. (Read it here). Unfortunately, I could not find any feedback mechanism that would have enabled me to communicate with the authors in order to rectify many of the inaccuracies.

In practice, great care is taken to ensure that subscribers are enrolled with proper KYC compliance. The implications of the Patriot act and FinCEN are carefully researched and deployed to ensure compliance. Most of the vendors in the industry (and I know most) have a genuine intent to build an accessible electronic financial infrastructure for the poor, but that will also eliminate (and block) the actions of criminals and terrorists. These vendors work with the Worldbank and associated agencies (like CGAP) and reputable banks and other financial organisations to try and build well-governed solutions to the massive problem of the poor that is effectively eliminated from modern financial services.

The statements in the report not only harm the delivery of financial services worldwide, but also delay the deployment of electronic tools that would enable legit agencies to monitor transactions and to identify fraudulent and illegal activities. I would like to urge the author of the above report to contact representatives from the mobile payment industry so as to clarify mis-understandings, but also to assist the industry to build better (for all) financial instruments.

Monday, March 10, 2008

It is not what you have, but where you fit in

Such a lot of companies are doing good things in the mobile banking and payment space. It is great to live and work in such a vibrant industry. I recently made a list of companies that play a role in the development of the industry. These are companies that are making an impact and can be looked at for solutions (or at the least as a benchmark).

It was interesting for me when I realised how few of these companies actually can claim to be independent. Not that independence is that important, but still it is important to know where companies "fit in". This will help you to understand their actions and what drives them to be successful.. but also in what way could they be made to act by other forces.

The best examples are solutions predominately developed (or at least) owned by large operators. It would be unlikely that these solutions would be deployed by other operators. Examples of these are Vodafone's mPesa, Smart's Smartmoney and Globe's gCash.

Other examples are companies that have deployed a successful mobile payment solution in a specific market. Sometimes these deployments are quite spectacular. These companies then try and sell their solutions elsewhere. They try turning an operational solution into a packaged solution. This is particularly difficult and the jury is still out if this can be done commercially. Examples of this are Trumpet Mobile now selling technology as Affinity, Wizzit now offering a solution under the brand r-Qubed and others.

Many solution providers are a small sub-company of a much larger company. Even though these solution providers project themselves as a big supplier of mobile payment solutions, the division providing this product line is often very small. Because these companies also have other interest, the provision of mobile payment solutions may suffer in the interest of other priorities. Examples of these are multiple and include Eversystems, GFG, mFormation and Telesoft.

Few companies can claim to be independent suppliers of mobile payment solutions. These companies are often focused companies with excellent solutions and track records. Examples of such companies are Fundamo, mShift and Paybox.

Once again this is not a comprehensive list. It is my intention to trigger discussion on my (often controversial) positions which is always welcomed.

Regulatory discussion

One of the discussion topics that is dominating progress with mobile banking, is the regulatory constraints/dispensations. This is especially relevant when the delivery of mobile banking is based on the creation of a "new account" for every subscriber. The banking law that would govern the opening of such an account is always a topic for discussion.

Based on what I have seen in the industry, I think that one can identify four categories of regulatory conformance in the provision mobile banking based on a new bank account. The four are:
  • Full banking, where the underlying account that is created for a new subscriber conform to all the banking law requirements. The customer is properly identified and conforms to KYC prescriptions. The bank account is properly reflected on the deposit-taking balance sheet of a bank and all legal requirements have been met.
  • Relaxed conformance, which is typically the same as a full bank account with some relaxation of the KYC requirements (both in content and in process), although the customer is still properly identified.
  • Pre-paid debit, where the client is not identified. KYC requirements are postponed to a later stage where the client would be identified (for instance) where cash is to be withdrawn from the account, or when the balance is to exceed a specific limit.
  • No conformance
In selecting a specific approach, the provider of mobile banking should consider all implications and the potential impact on the business case. A valid strategy could also be to deploy a platform where more than one of the categories above are supported.

Mobile Money Partnerships

During 2004 the largest African bank (Standard Bank) and the largest African telco (MTN) formed a joint venture called Mobile Money Holdings. This is a 50:50 venture with the objective of developing product that will enable subscribers to have access to new and advanced mobile banking products. The company launched an exciting solution in South Africa the next year (2005) and is in the process of launching more solutions trough-out Africa and the Middle-East.

Recently, Citi-bank announce a joint venture with South Korea's telco SK Telecom. This will be a 50:50 JV called... Mobile Money Ventures and will be based in San Francisco. The objective of the venture will be to "develop an advanced mobile banking platform..." See any similarities?

Also see a previous post on Mobile Money.

Tuesday, March 04, 2008

Who can see your PIN

Researchers claim to have found flaws in some famous brand PIN entry devices - certified by Apacs and Visa. These devices have loopholes that can enable fraudsters to access unencrypted PINs and account numbers.

The "tapping" techniques to capture unsuspected cardholder's PINs require little technical know-how and fraudsters can easily attach to the PED a "tap" that records PIN and account details as they are transmitted between the card and the PIN pad. Criminals can then use this data to create counterfeit cards that can be used to withdraw cash at ATMs in countries where Chip and PIN hasn't yet been implemented. (Read more)

In another report, a British criminologist has warned that the new security card technology could actually increase, rather than solve, the problem of identity theft and fraud. The researcher said that identity cards and chip and pin technology for credit cards were unlikely to alleviate the problem, as fraudsters react with more creative responses and individual vigilance and knowhow, which remains the best protection against fraud and identity theft will decrease. (Read more).

The biggest exposure to fraudulent transactions in my view is the lack of control that a subscriber have on what can be done with his/her PIN. How is the PIN dealt with, can it be intercepted or is it stored anyway along the line. Any third party device or transmission line that the subscriber does not have control over is a possible source of attack. PIN entry devices that are not under the direct control of the subscriber is the weak point. It is possible to utilise these devices to capture a PIN fraudulently without the knowledge of the subscriber.

Techniques are available that enable a subscriber to enter their PIN on a mobile phone in a secure way that can also be certified by banks and credit card associations. The difference with this approach is that the PIN is entered on a personal device that is (usually) under the control of the subscriber and tampering in order to capture a PIN fraudulently is much more difficult.

Value Store System

It is impossible to provide a payment system (any payment system) without connecting (or being able to access) some kind of value store. A credit card based payment system must debit a credit card account and an EFT payment system must debit a bank account somewhere along the line. This is the case for mobile payments too. Without being able to debit (or credit) some kind of value store, it would be impossible to deploy a payment system.

Most mobile payment solutions provide a mobile payment experience that integrate into an existing value store. For instance, mobile banking solutions that provide a mobile channel to existing bank accounts or mobile payment solutions that mobile enable an existing credit card. The challenge with these solutions is to ensure a seamless integration to the existing systems. Some of the challenges is to ensure that the registration process (when a mobile phone gets linked to a credit card for instance) does not create an opportunity for fraud. Also the boundaries and rules related to liabilities and disputes are not always easy to implement consistently.

Other solution providers (only a few) provide the ability to open a new type of value store that can be utilised to perform mobile payment transactions with. This facility is particularly interesting in markets where more people have mobile phones than does have bank accounts or credit cards. The advantage of this approach is that the value-store can be designed in such a way that it is much more tightly integrated with the mobile payment solution. At the same time many challenges must be overcome, like conformance to regulations, compliance with international protocols and the ability to perform audits and reconciliations that will be acceptable to a central bank.

The selection of and deployment of the value store element of the solution is probably the most important decision that can be taken. The different components that must ideally be present in a mobile enabled value store are:
  • Real-time clearing
  • Push and pull payment support
  • Support for a multitude of primitive transaction types
  • Security paradigms compatible with mobile enablement
  • Ease of use
  • Transparency
The key to deciding on a value store strategy should not be dictated by available technology, but rather be based on market realities and business objectives.

Tuesday, February 26, 2008

Administration Module


It is actually relatively easy to demonstrate a mobile banking transaction. To connect a phone channel to a banking system and to demonstrate the transaction being initiated by a phone subscriber is by far the easiest problem to solve in mobile banking.

Far more complex but much more important is to also provide robust administrative support for the mobile banking solution. This is an essential component to deliver a commercially sound and a production ready mobile banking system.

In evaluating a deployment ready solution one should expect to find the following components in a well designed Administrative module:
  • Support staff access is important as it is probably the biggest risk factor in the operations of the system. Statistics have shown that fraud is more often perpetrated by internal staff and the exposure is also much bigger. Well-designed systems should cater for defined responsibility matrix, with segregation of duties. Techniques like dual authorisation, limits and exception reporting should be available. Proper logging of support staff activities is important so as to ensure that activities can be tracked and audited.
  • Most of the administration activities are made available by means of suitable procedures. Systems should support standard procedures and workflow for the key functions (like registration of a new subscriber, renewal of a PIN, reversal of a transaction to name a few). In addition the workflow component should be flexible enough to accommodate changes and to add new procedures.
  • The tasks within the procedures should include Client support functions that would enable a client support staff member to handle queries, set new limits, change personal information etc. Support should be given to search the data by means of surnames, identification numbers etc. in addition to mechanisms to authenticate clients.
  • Administrative support could include the ability to raise interest and fees. To run reconciliation tasks, to change system parameters or to send communications to support staff or clients.
  • The availability of Management Information is critical not only to be able to operate a mobile banking system effectively, but also to be able to improve the service.
  • A well-designed system should cater for External administration functions. This would enable third party suppliers to possibly register clients or to pay commissions. It is preferably to have a defined interface to build customised access to the Administrative functions.
Administrative support is often delivered as an afterthought, or not based on a well-architected design. It is often inflexible, limited in its functionality, open to mis-use and expensive to change. It often does not provide sufficient management information support or caters for the exceptions. One should evaluate alternatives carefully on the basis of their administrative support, as this is usually the most expensive element to add or modify later.

Friday, February 22, 2008

Transaction Manager (Part Two)

The challenge with the development of a Mobile Banking transaction manager is to consider the following unique realities of mobile banking:
  • It is likely that the system will have to deal with much more transactions than would be expected from traditional banking systems. Remember that millions and millions of people have mobile phones and they just might want to access their banking at the same time
  • The different systems that mobile banking have to integrate to (Telecommunication Infrastructure, Pre-paid top-up billing systems etc.) are often not as stable (or sometimes as available) as what one would expect from financial systems.
  • The behaviour of cell-phone users reflect an expected immediate feedback. If they do not get a response within a few seconds, they would typically send the request again. The transaction manager must be able to deal with this kind of behaviour, without compromising integrity.
  • Security paradigms that can be implemented on mobile phones are not necessarily compatible with what is required for financial systems and this must be mapped somewhere
In looking at the design considerations for the above, it is clear that a synchronous architecture would probably not be able to deliver on these requirements. A transaction manager that has to keep thousands (if not millions) of transactions open while the transaction is completing would not be able to handle surges in requests, nor will it be easy to tune or scale such a system. The correct architecture (without a doubt) is a message based architecture.

Mobile banking solutions are often deployed without proper consideration for the transaction manager. Often mobile banking is bolted onto the Internet Banking functionality. This works great during pilot and initial production deployment, but starts to fail dramatically when the solution experience massive take-up (subscribers or transactions). Such conditions are then often aggravated when one component in the eco-system starts breaking or suddenly is not available. At that stage it is often too late to change.

Wednesday, February 20, 2008

Transaction Manager (Part One)


This is by far the most complex and often overlooked component of mobile banking. If one were to analyse the fundamentals of mobile banking, one will get to the conclusion that good mobile banking design is about the management of transactions originating on a phone and terminating on a bank account - and many similar types of transactions. A well-designed mobile banking system caters for the support of many different transaction flows. In addition proper consideration should be given for error conditions or when external sources are not available.

A transaction manager should cater for transactions to and from the following subsystems:

  • The transaction manager must be able to accept and send messages to the Mobile Channel. This should preferably be done in such a way that it can be done independently from the actual handset solution that has been deployed. Communication to this channel is very time sensitive, because a human would ultimately be receiving these messages. As such time-dependent actions should be configurable.
  • Applications that are often integrated into mobile banking offerings (called Third Party Applications) must also be integrated. Typical systems that the transaction manager must be able to talk to are bill payment, pre-paid airtime, COD systems and more.
  • Transaction Clearing is a often overlooked outcome of a mobile payment transaction. a well-designed transaction manager must be able to integrate to and support transactions to and from systems like Money Remittance systems, Central Clearing systems etc.
  • A mobile banking transaction will ultimately lead to a debit and credit transaction on some account, purse or card. The transactions to and from these Value Stores can be quite complex.
  • Many different security techniques can potentially be supported. This could be PIN-based, or User-ID and password. It could utilise CLI or certificates. The transaction manager must be able to route transactions to the correct source to verify security and adhere to requirements that may be applicable.
  • The switch must record transactions in such a way that it is fully auditable and that it can be proved that the operation is fully in compliance with regulations. A well-designed switch will cater for this too.
In addition, the transaction manager must be able to string together different transactions in a logical way. It should have the capability to roll transactions back if one component fails or is not available. It should also have the ability to place transactions in pending status and have the ability to resolve pending transactions. This should, according to my experience, be possible without human intervention as it is possible to get hundreds of thousands of transactions in a pending status (when a pre-paid top-up system is not available for a time). When the failing component comes on-stream again, the transaction manager should be able to resolve the transaction in pending state automatically.

In the next blog, I will discuss characteristics and special conditions that a well designed transaction manager must cater for. I will also discuss critical conditions that the system will have to cater for and typical solutions to this.

Monday, February 18, 2008

m Commerce management


This is one of the most tricky elements of mobile banking. This is where mobile banking systems integrate with mobile operator infrastructure and where the intricacies of telecommunications must be dealt with in such a way that financial transactions can be processed without losing accuracy. It is in this layer where a mobile phone number (or an identifier in the telecommunication world) is mapped to a banking number. The procedures for the establishment and maintenance of this link is often complex and should cater for many different scenarios.

A well designed mCommerce layer should also cater for risk management elements (like functionality available to specific profiles or daily and transaction limits). This is especially important in multi-channel deployments. This layer must be able to allow (for instance) a balance enquiry from a SMS channel with only CLI security but at the same time person to person payment with PIN encryption from a SIM Toolkit channel. In order to effectively be able to deploy this functionality proper mapping of profiles and access matrices is essential. This component must enable the operator of the system to present different options/menus to different people by making small parameter adjustments.

Often this component is grouped with the mobile channel layer (especially in the case where only one channel is supported or when the solution is inflexible in working with alternative channel providers). Grouping this component with the Channel management is often referred to as a wallet system as sufficient information must be stored to be able to process and route financial instructions to financial back offices systems. More than 75% of mobile banking vendors specialise in the provision of only these two components with at best limited features that could be classified as belonging to the remaining three components.

Mobile Channel Access Layer


The subscriber of a mobile banking deployment would interact with this component of the total solution. Depending on the deployment paradigm, the component may consist of application(s) downloaded to the mobile phone (SIM Toolkit or Java as examples), or in some instances would have no logic on the phone (WAP/xHTML or USSD deployments). This portion of a mobile banking deployment must cater for the user interface and manage the interaction with the subscriber.

Many different security paradigms can also be implemented ranging from security that ius only based on CLI (does the transaction come from the expected phone?), to advanced cryptographic solutions. Sometimes the security deployed utilise very innovative and unique techniques, and sometimes solutions are based on standard, tested security techniques.

It is virtually impossible to deploy this component without some logic on a hosted server in the back office. The hosted functionality must manage versions of deployed applications, as well as menu structures and expected responses. The hosted environment must be able to respond to error conditions (specific to the channel) and should be able to adapt to fault conditions (for instance when a SMS-C is not available or when response times from an application on the phone is slower than expected.

Typically solution providers favour some or other channel technology and their specific solution is based towards the channel technology. Thus, one finds that solution providers favouring Java based channels would have developed security, access management, user interfaces dictated by the functionality and characteristics of Java. It is extremely difficult to develop a channel access layer that is technology agnostic.

Sunday, February 17, 2008

Mobile Banking Fundamentals


I thought that it could be worth my while to document the different components that constitute mobile banking the way that I see it. Many different views of mobile banking exists in the market today. These views of banking are often driven by the realities of different markets. It stands to reason that mobile banking solutions applicable in a London main-street bank and mobile banking in war-ravaged Congo will be different. But surely there should be some similarities. It must be possible to find elements of the same thing in both.

I do believe that mobile banking can easily be made up of five components. Every mobile banking deployment must have all five components. Some of these components may already exist in some instances or in others all have to be sourced (because nothing exists). In some instances two or more of the components are bundled together and are almost undistinguishable as separate components. Yet the following framework is a sound way to think about mobile banking. The components are:

1. Mobile channel access

2. m-Commerce management layer

3. Banking transactional manager

4. The value store system

5. Administrative support

In the next few blogs, I will describe each of these in more detail.


The story of the Nano and Mobile Banking

I have heard Mark make this comparison at the MWC in Barcelona and thought that it was very apt. Now I can point prospective readers to his blog to read it themselves: What do Tata’s Nano and Mobile Banking Share?

Friday, February 15, 2008

Premium SMS futures

I have often been asked why Operators don't drop the share of Premium SMS's, so that this is not such an expensive payment instrument. The fact of the matter is that they can't. Many cost elements are built into SMS's that must be recouped by the Operator and they just don't have the lee-way to discount more. One may argue that it does not cost the Operator anything to deliver an SMS from a technology perspective and this is of course correct.

But a review of the other cost elements (especially regarding distribution, billing and in-built inefficiencies), have created a cost structure that represents (according to my calculations) in the region of 25% of the amount billed to the customer. It is therefor impossible for the operator to reduce their portion of a premium SMS billing much below 30%.

As such, a premium SMS is a highly inefficient payment mechanisms (for the operator, the service provider and the subscriber). As a matter of fact, the availability of an alternative payment mechanism will benefit the total mobile payment eco-system. It would be interesting to see the development of this into the future.

The SIM is built in


As I passed through Heathrow on my way back to Cape Town, I saw this billboard. I have known for some time that Intel have built GSM support into their new chipsets and was waiting for the first products to hit the market... and here it is. Dell have built a laptop with support for broadband where-ever you are and this is a big advance.

But what is really exciting for me is the convergence of mobile payments with computers that this technology allows. A SIM built iin a mobile phone provides for an effective vehicle to distribute secure elements. Any serious payment solution with aspirations to provide bank robust payment solutions should be based on the usage of a secure element in some format or other. This is why mobile payments utilising SIM cards are so powerful and of course secure.

With on-board access of a SIM card in a computer, this opens the door for very secure payment solutions. It will be interesting if any announcements based on this architecture will be forthcoming.

Tuesday, February 12, 2008

Is this the year of mobile transacting?

I have now spent three days at the Mobile World Congress. I have met many people and have sort-of walked through all of the halls. I think that it is safe to say that this year no clear theme is dominating. In the past Mobile TV and Advertising was clearly the talk of the town.

I have found the many different mobile phones very interesting. Some of the models that were on show from iMate, Palm and Blackberry were interesting. Even Garmin have now produced a phone (designed to be a super GPS of course). Handset manufacturers from the east have also shown great handsets. I found the Viewby from LG to be the most interesting.

If a dominant theme were to be picked, then I think it probably would be Mobile Remittances. The workshops and presentations on this topic was hugely oversubscribed. Maybe this year is the year of mobile transacting.

Monday, February 11, 2008

Build your own

It is quite amazing that many operators have opted to build their own mobile banking solutions. Quite a few examples exists of which the mPesa initiative that Vodafone have rolled out in Kenya and have announced initiatives in Russia and Afganistan is probably the most famous. In a survey conducted by Edgar and Dunn recently, it was found that 48% of mobile operators are considering building their own wallet solution (rather than buying it). The question needs to be asked why this is the case.

It is an accepted fact that no reputable company would even think of attempting the development of their own general ledger system. This is just unthinkable. It would never be sensible to do this as it would be too expensive and too risky from a general auditability perspective. Yet Mobile Operators (with very little skills as banks), are contemplating building their own banking systems (because wallet solutions are for all considerations the same as bankings systems).

In thinking about this phenomena, I can think of three reasons why they would consider doing this. It could be that mobile operators think that they can build competitive advantages into the mobile wallet solution. This may be the case, but this will only be the case in the short term, when successful solutions will be copied by competitors. Another reason could be because of internal politics and based on the aspirations of staff members of the mobile operator.

Another reason could be that mobile operators are under the perception that no reputable mobile wallet vendor exists that are able to provide scalable, industry robust solutions. If this is the case, the wallet solution industry have a lot of work to do.

Sunday, February 10, 2008

Explosion in mobile wallets


In a report released by Edgar, Dunn and company (under contract by the GSM Association) today, an explosion in mobile wallets is predicted. Based on solid research, the report predicts a growth from 10 million wallets today to more than a billion wallets by 2015. If this were to only materialise partially, this would be the biggest financial revolution in the history of mankind. To grow from almost nothing to a third of the world's population would be nothing more than miraculous.
The interesting thing about the research is that it was based on the opinion of market leaders in the mobile industry. Executives in mobile operators (representing 30% of the global subscriber base) were interviewed and the results were based on their opinions. Another interesting finding is that wallets based on and utilising elements of the SIM card is by a factor the preferred technology for the deployment of mobile wallets. See a previous entry in my blog.

Monday, February 04, 2008

NFC Science Fiction


In a recent Aite report it was found that one could expect only about 2.0% of merchants to have the capability to accept contactless payments in the United States. This would be the case after five years from now. Surely this is a HUGE stumbling block to even think of NFC payments as a remotely viable product.

If this information is correct, it is highly unlikely that any NFC product can be made commercially successful. Why would any-one consider walking around with a payment product that will only be accepted at 2 in every 100 outlets? The report also highlights the challenge of providing every player with a slice of revenue that will make it worth their while to deploy and push this infrastructure. It is almost as if every-one is working on NFC solutions when no problems exist that needs solving.

In my opinion, NFC payments is not a silver bullet. We all know the form of the hype curve. It is not difficult to judge where NFC is on this curve on the moment. Next phase: valley of disillusion.

Sunday, January 20, 2008

The Mobile Banking Eco-system

One of the most complex problem in deploying mobile banking systems is solving (or establishing, or nurturing) an eco-system for the development of mobile banking services. Generally, observers describe mobile banking as a clash between banks and mobile operators. But in reality the different players that are impacted by the deployment of a mobile banking solution are much more. It is critical to understand all the players, their fears and aspirations before starting to tinker on the delicate eco-system of payments.

Of course, if mobile banking is limited to balance enquiries and a few simple transactions, the impact is much smaller. However, when advanced and (sometimes) radical mobile banking solutions are deployed, the impact on the eco-system is much bigger. The participants that should be considered are the following:

1. The banking community should be the custodians of banking and payments in all markets. Banks usually have strong ideas about payment systems. They tend to try and conform to industry standards and are generally more conservative... rightly so. They look after our money.

2. Sometimes card issuers are different entities than banks. They are usually driven by the number of cards that they issue and the number of merchants that would accept their cards. Any scheme that could potentially disrupt this gameplan are usually viewed with aggression.

3. It is possible to offer mobile banking without the collaboration of mobile operators. However, if they are part of the mix, they can bring their distribution network, their strong brand to bear to ensure a much more successful deployment. Collaboration with operators also lead to more effective and secure solutions.

4. Central banks and other regulatory bodies are central to effective deployment of mobile banking. Often specific challenges (like deposit taking, open of new bank accounts, settlement and foreign currency transactions) can only be solved with the support from the central bank.

5. Cash handling companies are important in many countries - especially when the economy is still a cash-based economy. These companies (sometimes they are banks and sometimes even the mobile operators - but often independent) deliver and fetch cash from remote places and are often key to the functioning of micro-economies. Mobile banking and payments puts the business of these companies at risk.

6. Payment processors are often highly influential in the payment profile of a market. These companies process millions of transactions from ATM's and POS's. Their businesses are totally dependent on ensuring that the source of these transactions are not threatened. Mobile payment can be an opportunity for them or they could see it as a dangerous initiative.

7. Airtime distributors are often-time very powerful companies. In some cases the mobile operator distribute their airtime themselves, but in most markets these are independent (yet very powerful) companies. Any change to their margins, marketshare and control over the distribution of airtime can have a major impact in their livelihood.

8. Infrastructure suppliers could either benefit or loose out depending on the way that mobile payments are deployed. Often mobile payments lead to a reduction in the need for ATM's and other payment infrastructure.

This is not a complete list, but serve to illustrate the complexity of the environment. Also, different players will have a different relative strength in different markets. The important fact is to consider all of these (and more) and to develop plans to address threats and opportunities. Failing to do this, will seriously jeopardise any mobile banking deployment.

Wednesday, January 16, 2008

Jump in APM's

APM's? Alternative payment methods that is. In a recent survey conducted by solution specialist company, Brulant, it was found that retailers are offering more and more APM to customers. As a matter of fact the growth reported is a staggering 25% more retailers in the past ten months. (Up from 24% to 30%). Payment methods like "Bill me Later", Paypal and Google Checkout have been the biggest gainers.

What intrigue me about this is "Why?" Why not just sticking with the good old Visa and MasterCard mechanisms? They have been serving us well for the past thirty years. What is different about the APM's and why would shoppers want to use alternative methods? I suggest three reasons:

1. Security. The existing credit card rules place a lot of risk on retailers. In the case of fraudulent transactions, retailers are often the biggest losers. Even though the credit card companies have done much to reduce this risk, the process is still onerous and places the retailer at a disadvantage.

2. Ease of subscription. The difference in enrolling for a credit card vs. getting a payment instrument and registering online is still too big. Especially for certain segments of the market enrolling for an APM is still much easier.

3. Degree of anonymity. Shoppers require a certain degree of anonymity for many services offered in virtual space.

Why talk about APM's on a Mobile Banking blog? Because Mobile payments solutions can surely be classified as an "APM", and many of the lessons of this study should be considered in the development of mobile payment solutions.