Monday, August 24, 2009

Compliance in real-time banking is difficult

The biggest challenges of regulatory compliance for transformational banking is the real-time nature of the transactions. Transformational banking provides a platform for true real-time payment transactions. If properly implemented, the volume of transactions are also huge (even though the average value of transactions may be low).

Compliance management in traditional systems are typically off-line solutions. These systems work through transaction history and attempt to identify non-compliant transactions (money laundering, funding of terrorism, or other illegal transactions). Banks have a regulatory obligation to find these transactions, correct them and report on them. The inability to be proactive in doing this have lead to banks being fined in the past.

Banks are now confronted with a new category of systems where transactions occur in real-time from locations that are not necessarily known (could even be outside the geographical boundaries where the bank have jurisdiction). It is often also easier to open these accounts and to easily discard them again. Sometime regulation allows for account holders not to provide proof of residence. These factors necessitate the need for a new kind of compliance management.

We at Fundamo have been doing ground-breaking work in this area during the past months. We are doing this with our clients and industry experts in the space. I believe that as these systems start to evolve, the real-time management of compliance will become more important. As banks
are starting to tackle this issue, they will find that it is significantly more difficult than what it looked like initially.

Mobile banking regulations should be tiered more

This is so obvious that I am hesitant to blog about it: Regulatory guidelines for mobile banking should be tiered - it should allow for different layers of compliance. As far as I can gather (and I have read widely), it is only in South Africa where this is explicitly stated (with the E17 exclusion). As always, I would be happy to be corrected.

Different layers of compliance should be the basis (the foundation) of thinking about banking regulations applied to the marginally banked. It stands to reason that it does not make sense to apply the same rigour to an account for low value simple transactions, compared to a high value, sophisticated bank account. This approach would give comfort to all the participants in the banking industry as it would be ideal to manage risk.

We at Fundamo have always postulated and worked towards a four layered tier for compliance. The lowest layer or tier should provide for very little KYC (or client identification), but should be very strict regarding limits and functionality. This lowest tier becomes the entry point into banking for subscribers without a strong banking relationship. This provides for rudimentary services, but does not compromise the integrity of the system. With higher levels of compliance, more rigour is added to the registration and client management process, but at the same time, more functions and higher limits are associated with the account.

Tiers are the only way to think about compliance.

Friday, August 21, 2009

The SAM side of the SIM story

The SIM card in GSM mobile phones should probably qualify as the computer device that has been produced more than any other device. Far more SIM cards are produced than phones per year and with the invention of pre-paid telephony this accelerated even more. But the SIM card is actually a rip-off. It was copied from something called a SAM. As a matter of fact, it is not much different to a SAM.

Any-one with an interest in the technology of banking would of course know what I am talking about. A SAM is the tamper resistant device found in any ATM or POS terminal and it looks exactly like a SIM card. These cards sit at the heart of bank security in the sense that a bank PIN can only properly be encrypted if a SAM is present. Bank systems expect bank PIN's to be secured properly with keys stored on a SAM in such a way that it cannot be changed or manipulated. This is a well-understood mechanism widely deployed in banking systems.

Not only is it critical how the keys on the SAM is used, but also how the keys are installed on the SAM in the first place. The control over and access to the master-keys (used to derive the keys on the SAM's) are critical in order to ensure the security of the whole system. Millions and millions of ATM and POS transactions have been secured in this way for decades and (according to my information) has never been compromised. (All ATM (and POS) fraud attacks usually focus on intercepting the PIN before the SAM encryption).

With the invention of Internet banking (and because SAM's are not found on PC's), the discipline was somewhat forgotten (or maybe not applied). This is why the security deployed in Internet banking across the globe is not of the same level of security found in ATM's neither is it standardised and auditable as is the case with PIN encryption ala SAM.

This is why it is a mystery to me why many proponents of mobile banking attempt to propagate Internet banking solutions on mobiles. The SIM card in a mobile phone, looks like a SAM card, acts like a SAM card, shares almost all of the characteristics of a SAM card. It seems absolutely logical that one should apply the proven, accepted mechanisms that banks are comfortable with regarding SAM cards and apply them to SIM cards.

Wednesday, August 12, 2009

The next step for the USAA iPhone check application

My previous post on the USAA iPhone application was extremely popular. I suddenly had much more visits to my blogpage, which implied that I have a lot of US readers (thank you), or this check imaging system is really groundbreaking...

I have not used a check (nor seen one) for years (I do all of my payments electronically), so I had to do some thinking to get my head around what the application actually do. My recollection is that a check is a paper instruction to my bank to pay money into the bank account of the beneficiary. Typically, I would give the check to the beneficiary that passes it on to his/her bank and then this bank passes it on to my bank. Ultimately the check lands up at my bank where the money is duly subtracted from my account and paid over to another bank. It seems in the US it is now possible to pass an image of the check from bank to bank, rather than the physical check itself. And this is possible because we now have technology that is powerful enough to replicate the physical process exactly.

Surely, one should use technology to improve, rather than replicate the manual process? The obvious (and simple) application would be for me (rather than getting the beneficiary and his/her bank to do it), to pass the image of my own check to my own bank, instructing them to pay the money over to the beneficiary. As an even more bold step, we could remove the image and just ask my bank (electronically), using my iPhone to subtract the money and pay the money into the account of the beneficiary.

This would have been real innovation in my book.

Tuesday, August 11, 2009

London University to the rescue of mobile banking security!







City University London received a three year grant from the Government’s UK-India Education and Research Initiative (UKIERI) to "secure the future of mobile banking". Read more here. According to the report, the researchers are under the impression that most banking systems requires a separate (second) SIM card in order to produce a secure session. This means that subscribers have to swap their SIM's in order to do banking. (I am quoting from the article on the Universities website - I am serious!). The article describes how the researchers are busy pioneering "a new form of security software, which generates a personal code or “crypto key” to each user via their existing SIM card."

I suppose they could use the grant money to catch a flight to Africa (the majority of countries in Africa) to come and see how this kind of solution actually works in production, where millions of people do banking with one SIM.... and where every transaction are encrypted with a personal crypto key.

How can one get excited about an iPhone image of a check?

As part of my job, I am regularly exposed to great innovations in the mobile banking domain. Recently, when I read about the USAA iPhone application (Read here and many, many more places), I first thought someone was pulling my leg. In short, USAA (a relatively small US bank catering for the military) will be launching a service where one can take a photo of a check and send it to the bank for processing. I soon realised that many people (predominantly from first world countries) actually thought this was cool and great progress in mobile banking technology.

This reaction for me is a clear indication that mobile banking is way behind in the US compared to most other countries. Many things about this application is strange.
  • The iPhone is a great phone, but most people will agree that the camera technology is probably the worst on the market. The business process for fuzzy checks will be interesting.
  • It is doubtful that people with checks would want to use a phone to bank the checks. Typically most of these people would have access to a PC. The user experience on a PC would be much easier to manage than utilising a phone.
  • Risk and fraud management will be particularly difficult
  • Future extension to this application (to ultimately turn this into a real mobile banking solution) will be difficult, architecturally.
I suppose these kind of applications will be developed in a country with a large part of the payment economy still based on checks. But it does say something about the state-of-the-art of the technology.

Tuesday, August 04, 2009

Will smartcards out-smart mobile banking in India?

India recently announced an ambitious plan to deploy a national biometric smartcard to everybody in the country. (Read here). Seen as the biggest IT project ever attempted, this project aims to provide every-one in the country with a digital identity, while connecting many other services to this central system. The good guys at CGAP make the point that it would actually be easy to provide rudimentary banking services on this card. (Read here).

A national smart card with a cheap mechanism to store money electronically would have a major impact on the fledgling mobile banking industry in India. The impact on business plans, payment switches and distribution strategies would be huge. While the jury is still out if it would be possible at all to deploy this system effectively, it is important for mobile banking operators and vendors in India to consider this implication and to develop complimentary strategies.

Tuesday, July 28, 2009

How Mobile banking will make the Soccer Worldcup a more enjoyable experience

This is a billboard that shows how FNB mobile banking will make the 2010 Soccer World Cup in South Africa more enjoyable. As can be seen, it is now possible to win a Kuduzela if you use FNB mobile banking to buy airtime!

At this time, it is required to give some background information. Soccer supporters in South Africa have a unique custom. During soccer matches they blow on an indigenous "trumpet" called a Vuvuzela all the time. This single-note, noise generator creates an almost unbearable din. Some people have described this experience as similar to putting your head in a bee-hive. Enter the Kuduzela (a new kind of trumpet - shaped like the horns of one of the biggest antelopes in Africa, a Kudu). This trumpet generates a milder sound, much more bearable to the untrained ear. If it is possible to replace Vuvuzelas with Kuduzelas before 2010, we are guaranteed of a much more enjoyable World Cup.

And mobile banking is making this possible.

Mobile banking celebrates their tenth birthday this year.

It is not clear where mobile banking was invented as one can find a number of candidates. What is clear is that the first deployments all were started during 1999.

We at Fundamo developed our solution during the late 1990's and lodged our first patents early in 2000. Our technology were (even then) based on SIM card security, which was quite forward looking as most phones could not even send and/or receive SMS's. The intention of our invention was to find a way to replace payment systems and some of the first applications that we experimented with, was the use of mobile payments in a retail environment.

This was similar to the guys at paybox, who launched their solutions in Germany during about the same time. The intention was to deploy an alternative payment system for retail purchases. Their solution utilised IVR to capture a PIN (much less secure, but then who needed security in Germany?). The solution evolved to also be used in taxi's and for "card not present" solutions.

I think that Smartmoney (launched during 2000) was specifically designed to augment functionality of pre-paid credit cards. The phone could be used to "top-up" the card and to see the remaining balance. I never had an opportunity to talk to people working on this product in the early days, so this is purely assumptions. Smartmoney was also based on a SIM application.

We will be hosting a dinner for a selection of people that were involved with Fundamo during that time to celebrate the tenth birthday during October. We came a long way and it was an amazing journey, but we have not yet arrived.

Sunday, July 26, 2009

Existing banking systems are too old for mobile banking.

If we know, we tend to forget this, and if we are ignorant, we would never believe it: but banking is actually not real time. What you see is not necessarily what is, nor is it what you may get. Listen to what Bill Streeter say in a recent article in the ABA Banking Journal:

"On the other hand, if you define real time as handling any transaction at any channel only once, at which point final posting occurs, then very few U.S. institutions are doing that..... Real time was also the norm for years with savings and loans and credit unions, and still is in some cases, though the movement to check-based transactions changed things for many of these institutions."

The rest of the article is a great read about the state of real-time-ness in banking and how difficult it is to turn existing banks into real time machines. Or to quote from the article: “Changing core systems is not for the faint of heart,”

Which made me think: why do we want to put mobile banking and payment solutions on top of old banking systems? The whole idea of using a mobile phone for banking is that I can do stuff in real-time. I mean, can you imagine having a telephone call in batch? Phones are made (and consumers expect them to be) real-time devices. It is just absolutely crazy to plug a mobile phone into a system that does not work in real-time.

In order to bring the true benefit of mobile banking, we will have to re-define banking from the ground up. The banking systems that should sit underneath mobile banking should be designed in a different (more modern view). If a transaction happens we post a debit and a credit and it is done (simple). If we have to reverse the transaction, we post a credit and a debit. This is not so difficult. This means that mobile banking (in many cases) would initially be a separate system.

Once again, this is not so far-fetched. Banks did it when they launched credit card systems a few decades ago, and it seemed to work pretty well. Why should we not do it with mobile payment systems. Just a thought...

MoBank's features not good enough

The problem with the architecture of the new UK mobile banking provider Mobank (www.mobank.co.uk ) is that it is based on the UK banking infrastructure. Because it is offering banking services on a realtime device, the service amplifies the shortcomings of the UK banking infrastructure. Michael, one of my friends, enrolled for the service, and linked up his debit card and added his online banking details recently. He told me that he was instantly dissatisfied as the service did not meet his expectations of a mobile banking service.

Some of the things that he was unhappy with, were:
  1. The fact that the service did not provide real-time information
  2. The limitations in terms of payment options (could not move funds to another bank account, or move funds to another telephone number, for instance)
  3. The security paradigm. A lot of information was required in order to enroll (CVV number, all his existing banks Internet logon service). What MoBank were doing with all this info was not clear. A subscriber must feel uncertain with offering all this info and Mobank suddenly becomes a target for fraudulent attacks. The service also lacks dual-factor authentication.
  4. The iPhone application was also poorly executed, with (for instance) text being able to be entered into numeric fields.
Even though the service was quite expensive (50 p per transaction and £1 per month for balance enquiries), Michael was quite prepared to pay for a service that lived up to his expectations. He said that he read MoBank's literature and was prepared for a revolution - what he got did not qualify as such.

Differentiation of online services

I enjoyed reading the findings of a recent Gartner research report on online banking services. Gartner surveyed almost 4 000 consumers in the UK and the US. The findings ring true to what we are seeing in the industry. One of the findings (in my opinion) do have specific implications for banks. In the report Stessa is quoted as saying: "As consumer adoption of online banking increases, banks are searching for ways to differentiate their services while maximizing the cost-effectiveness of self-service channels". Banks will have to spend more time to ensure that their offerings cater for very specific needs of consumers and will have to keep on adapting these services as they learn more about their customers. While the research was focused on Internet banking, many of the findings can most definitely be made applicable to mobile banking too.

This insight must surely challenge the trend to outsource online banking to third parties and for banks to offer online banking services on the same platform as many other banks. If banks really intend to compete and win customers from others, it is essential that they should have more control over the features, security and functionality of their online services. This in my mind is indicative of a need for an online banking platform (with much more in-house control) than a managed service. Banking is evolving to a state where a customer's online access to the bank is a key competitive capability.

Tuesday, July 21, 2009

Four (or five?) phases of mobile banking

Some time ago, I postulated that bank adoption of mobile banking can be traced through five stages. (Read here). Recently, I saw that Diarmuid Mallon (from Sybase) have reduced the phases to four in his suggested route for banks. (Read here). By carefully studying the two approaches it is actually possible to map the two to each other and then find many similarities in the two models.

Notwithstanding this, my view is that the two models are significantly different. This is because of two fundamentally different ways of looking at the problem. Diarmuid describes the four phases predominantly in terms of how the consumer behaviour will change. It is an approach where the bank takes on the role of educating the consumer to ultimately have access to a sophisticated mobile banking platform. Thus he describes phases starting when (for instance), ".. consumers are fully engaged".

My model (on the other hand) describe a route through the five phases where the bank has to change and all of the internal challenges related to accepting a fundamentally new approach to banking. It is actually not the customer that has to change, but bank management and internal approaches and business processes and this often takes time. If mobile banking were to be launched with a big bang, customers will gladly adopt. It is the structures and processes in the bank that will have difficulty.

It seems to me that we are talking of two fundamentally different models.

Monday, July 20, 2009

Wearable computers and mobile banking

I enjoy seeing and reading about the research being conducted by Pattie Maes and her group from the MIT Media Lab. The Sixth Sense project shows what is possible with wearable computers. This means that computers and "computer-driven" devices like projectors and cameras are hooked up on your body to more directly interact with your actions and behavior. In a recent article on Read Write Web, Richard MacManus warns: "Look out mobile phones, because in a decade's time wearable systems may be the primary means of accessing the Web!". Which made me think: what is it about phones that makes them different to computers to access the web? and the obvious answer is identity - your phone number (or your MSISDN), which is the fundamental reason why phones are so good as a payment device.

So if in a decade we are going to "wear" our computers, where will we put the identity module and how will proximity (NFC) payments work? Would that mean an implant? Would it mean that the most important module that we put on in the morning is our identity chip? And would it be good enough to just slip it in our pocket? Maybe the majority of us would prefer to wear it like a watch? One think is for certain, the entity that issue this identity module will be very powerful in the new world.

Thursday, July 16, 2009

Macro economic impacts of mobile banking

I found a recent article in Telecom Circle really interesting. It is a must read for any-one interested in the impact of mobile telecommunication on the macro-economics. The author quotes a number of studies showing that mobile telecommunication contributes (or could contribute) to the GDP with a growth of 0.6% for 10% growth in subscriber numbers. (I assume that this excludes the benefits of utilising the infrastructure to also deliver financial services, as many of the studies referred to excluded this benefit). In the article the benefits of delivering financial services are mentioned.

Studies have indicated that the replacement of cash with electronic payment systems will lead to direct macro-economic benefits. A white paper produced by Visa and Global Insights in 2003, found that a 10% increase in electronic payments can lead to as much as 1% growth in GDP and can directly lead to job creation. Numerous academic papers (Humphrey, Pulley and Vesala) have found potential gains as high as 3% (specifically savings) in GDP.

It seems to me (intuitively) that the simultaneous introduction of efficient electronic payment systems on top of mobile communication could lead to a spectacular growth in GDP (without almost doing anything). The indirect benefits, like the creation of jobs, increase in tax collection etc. etc. can be huge. In thinking about it, it almost seems logical that governments should force mobile operators to launch mobile banking services. (...rather than delaying it).

Homegrown mobile banking solutions

You may have noticed some months ago that CGAP listed an initiative that they supported in Mongolia in collaboration with Xac bank (see some of the announcements here). The support and the excitement generated by the visibility of this initiative enticed a number of suppliers to tender for the deployment of mobile banking in this beautiful country. I am not sure how many companies tried to get the work as we declined because Mongolia was not one of our target countries at the stage.

What was very interesting to me was when I recently saw an announcement of a new solution company, offering mobile banking solutions and using Xac bank as their first reference. This company is called: Noomadic. A little more research indicated that Noomadic is partially owned by Xac bank. Not only have the technology been deployed in Mongolia, but a new solution company has been created! While the deployment of this solution must be a great achievement, creating a solution company at the same time must be questioned. It is my believe that the development of a product and the deployment of a production system is totally two different propositions. Not only is the solution different, but also the organisation that supports a product compared to a production deployment.

Yet, this is not a new approach. The "well-now-that-we-have-deployed-the software-lets-see-if-we-can-sell-it-too" mentality is actually quite common in this industry. It is displayed regularly with not so good results in most cases. (I will not quote examples, but I am sure the reader can think of many themselves from countries like South Africa, the Philippines, US and many more). Why is it that companies think of selling the software when they should be worried about supporting a production deployment?

Wednesday, July 15, 2009

The m-Pesa development team

This is the one story that should have been told earlier:
"The technology behind mPesa was not built by Vodafone". Luckily the good folks at CGAP did tell the story. In short, what happened was that when Nick Hughes started to develop the concept in Vodafone, he contracted a very good engineering company called Sagentia to develop and deploy the technology for Vodafone. The way that the contract was done, even though the technology was developed by Segentia, the IP still belongs to Vodafone. It must be said that a big part of the success must be attributed to some of the excellent people working on the project (for instance Tim Murdoch).

Recently the key individuals have resigned from Sagentia and have started a new venture iCeni mobile. While little can be deduced from the website at this stage, one must expect something to get announced soon. It would be interesting to see what product and offering the ex-team from Sagentia produces.

The angle that is of interest to me is where this move puts Vodafone. The technology that drives mPesa (and that they own) should probably be supported by Sagentia. Unfortunately the key team is not employed by Sagentia anymore and have recently started an even smaller company. I wonder if Vodafone could do it again, if they would not have considered licensing the technology from a larger and dedicated company.

Competition between MMU vendors

I was quoted in a recent interview on "le paiement mobile" with Carol Realini, saying "Mobile Money community is maturing. The fierce competitive spirit between different companies in the past has been replaced with a drive for open interfaces and creating networks of benefits for all connected parties." (read more here). This is from a previous blog-entry, specifically talking about the latest MMU meeting in Barcelona.

While I am still of the opinion that the more mature companies are now starting to look for ways of collaboration and how to grow the market, this is not true of many new entrants. The provision of mobile payment solutions seem to have a magic perception to it. Everyone entering the industry (and their financial backers) believe that they have an offering that will turn the industry upside out. They start of selling the solution at a discount - often offering the solution for free (on revenue share downstream), just trying to break into the market and creating some reference. The result of this behaviour is a kind of fierce competition. Although this is not visible amongst the established vendors.

The competition between operators of mobile payment solutions seems to be growing in intensity. The behaviour of Zain (with their ZAP) product and Orange does create the perception of fierce competition. Is it possible for vendors to have a collaborative approach when their clients are competing fiercely?

Tuesday, July 14, 2009

Information on the Mexican mobile banking guidelines mean?

It looks as if the first press release that mentioned the Bank of Mexico guidelines was published on the 13 July was the one written by Noel Randewich and published by Reuters. (Read here). Subsequent press, added very little to the Reuters article. (Read here and here, as other examples). A search on Noel Randewich seems to indicate that he is a free lance reporter based in Mexico that have reported on many different aspects, but very little about banking. The analysis and interpretation should therefor be taken with some reservation.

The most interesting quote in these articles is the following:
"The rules stipulate measures to promote competition and inhibit possible discriminatory practices in transferring funds within a bank and from one bank to another," the Bank of Mexico (Banxico) said in a statement. This possibly means that an Operator will be forced to offer mobile banking services with every bank, or at a minimum that an Operator can not stop a bank from offering a service on the network. If any of these are true, the following should be considered:
  • it is extremely short-sighted as it would take away free-market forces and the competitive incentive to launch product quickly
  • it would be impossible to police as the bank have little control over the actions of the Operator, as the Operator is not governed by the financial regulator and
  • it would create extremely complex technological interpretations in order to give substance to the guidelines (for instance the definition of fund transfer, the routing and clearing of transactions etc.)
The articles refer to a statement made by the bank on Monday, but I could not find the original statement and it is thus not possible to comment on the implications, not having had an opportunity to study the statement. I would appreciate any opportunity to see the statement and any of the supporting information.


Sunday, July 12, 2009

Eradicate poverty according to Muhammad Yunus

The seventh Mandela Memorial Lecture was presented by Muhammad Yunus, the Nobel prize winner and the founder of the Grameen Bank recently. (Read more here). This was particularly meaningful to me as a South African. First, because this was a lecture in honour of Nelson Mandela (The icon of South Africa), who as Prof Yunus put it: "...inspired the whole world". Second the lecture was given by some-one that has done so much to help human kind achieve what I also believe in and that I have been working on for the past ten years. Some of the messages of the lecture rung true:

1. … those who told us it (Grameen Bank) would collapse – they collapsed.
2. ...that poverty does not lie in the person but rather is a result of systems put in place by society.
3. ...capitalism needs to evolve such that it encourages businesses that incorporate the selfless aspects of the human condition.
4. Let’s make South Africa the first county without poverty,” he said, “and let’s do it fast, let’s do it in the next 20 years,”

However, I still believe that the community based model of Grameen Bank is not really scalable and that the only way that we can truely bring financial inclusion to every-one is via mobile banking, as I have been quoted saying.