Tuesday, August 30, 2011

What is financial inclusion and why is it important

"Financial inclusion or inclusive financing is the delivery of financial services at affordable costs to sections of disadvantaged and low income segments of society" is the way that Wikipedia describes this. (Read here). The estimate of the number of people that do not have access to digital financial services usually runs into the billions and many organisations are working diligently to provide some infrastructure to make this happen.

Many motivations for progressing towards a cashless society exists. Some people are talking about the elimination of poverty through financial inclusion. Much is being said and being written about how this will be achieved, but success are limited and usually comes at a big cost. Many organisations and companies sees this drive as an opportunity to profit - to get access to a much bigger market, and this drives many of the initiatives.

But why is financial inclusion really important? And why should we care? Is it worth the effort and the investment? If we are not clear about this, our efforts will be wasted.

I believe that the answer lies in a honest assessment of the real needs of the people that we are trying to "help". If we cannot put ourselves in their position and truly understand what will be a better world for them, we will not succeed.

Sunday, August 28, 2011

Mobile payments could make EMV obsolete

It seems as if the EMV wave is about to break over the US. The ultimate technology to protect against the cloning of plastic cards has been tested in many markets and enough evidence exist to show a dramatic reduction in fraud (especially based on card cloning). (Read here). A perceived growth in card fraud in the US may necessitate a major drive to deploy this technology. The massive potential cost of retail infrastructure is of course the biggest stumbling block.

It seems as if there are a perception that a move to EMV is required in order to effectively implement mobile payments. (Read here). While this may be the case (to some degree) in preparation for retail NFC, this is of course not true at all. Mobile payments could successfully be deployed without any EMV infrastructure available. The best evidence of this is to look at the dramatic growth of mobile payments in emerging markets where no EMV infrastructure is available.

To the contrary, a clever deployment of mobile payments, may actually lead to making plastic cards redundant and thus eliminating the need to protect against cloning... making EMV obsolete.

Monday, August 15, 2011

How crypto is being used in banking

Traditional banking security is dependent on well-designed cryptographic equipment. These devices are hosted in ATM's, Pinpad in branches and retail infrastructure. The crypto codes generated on these devices during transactions are evaluated within the host systems by tamper-proof hardware security modules. The whole banking system was designed and built on robust cryptography (almost impossible to breach).

That was the case until online banking arrived. Consumers now interact with banking systems via the Internet with no cryptographic devices involved. The cost of these devices, the integration with online systems, lack of standards and complexity in the distribution are barriers to making this a standard component in online banking. Some of these barriers are aggressively being attacked and some progress has been seen lately:

HSBC use a on-time password for business users to secure online transacting. This crypto security device is available to customers in all countries. (Read here).
Bank of America offer a device to their customers producing one time passwords, called Safepass. (Read here).
This technology was released by Visa recently with the brand name Codesure. (Read here). The question is how readily will it be distributed and could this lead to more secure online banking.

It is also important to think of the implications for mobile banking.

Two divergent views on mobile banking security

Two very similar articles were published on the 10th of October. Both discusses the security of mobile banking, yet they get to totally different conclusions:

The first argues that mobile devices are much less sophisticated in defending against malicious attacks, it does not come with firewalls and subscribers are more likely to download bad applications on their mobile phones. Mobile banking are therefore much more vulnerable than online banking.

The second article
reckons that many of the hacking tools that exist for PC's are not available for mobile platforms. With so many variants of operating systems and hardware it is difficult to find common access mechanisms to launch malicious attacks. In addition, because mobile banking can be implemented with transactional security, utilising various additional techniques it is much more difficult to penetrate. The writer then concludes that mobile banking are much more secure than online banking.

Both articles published on the same day, yet with different conclusions. Which one is right?

Bank Simple Thoughts

Someone once said:"Banks are dead, banking not". We all talk about how inadequate banking is and how our needs are not met. However, few initiatives ever succeed in replacing the old brands and we keep on banking with them. Who will forget the waves that Egg made in the UK and Twenty20 in South Africa. Both these initiatives had limited success and ultimately got eaten by the establishment. Yet, we would still like to dream.

That is why it is so refreshing to see initiatives like BankSimple that recently raised a further Ten million (Read here). A bunch of entrepreneurs working on a new banking model that plans to bring retail banking wrapped in a new presentation. As is to be expected, part of the offering is to bring the service on mobile phones, But the complexity of new systems, regulatory conformance and integration into the payment systems have delayed the launch of this bank.

Let's hope that this company can steer through the hurdles successfully and that they achieve success. We need renewal in the banking industry.

Importance of trust in brand to conduct mobile payments

There is a lot of trust involved in performing a payment transaction. It is probably the most important ingredient in making sure that consumers complete payments. While it is relatively easy for first mover people to try out new payment schemes, this is not the case for the majority of people.

In an online survey performed by Ogilvy & Mather, 500 Americans were asked which brand they would trust most in mobile payments. (Read here). (The graph can be found here). The results (while predictable) were quite interesting. Visa (and Mastercard, American Express etc.) carried the most trust, while companies like eBay and Facebook had a much lower score. This means that even in the online world, a brand carries a lot of weight when it comes to payments.

Some questions:
  • How to ensure that criminals don't masquerade as a trusted brand.
  • How will consumers recognise a brand in a mobile world - especially when space to display brands are limited.
  • How to build products that carries the brand promise.


Sunday, July 24, 2011

A business case for the elimination of PCI

The PCI (Payment Card Industry Data Security Standard) program is one of the most important initiatives ever undertaken by banks and the card associations. Fundamentally PCI is about masking card numbers so that it cannot be used for purposes that it is not intended for. Because credit card numbers (if known to criminals) can be used to perform fraudulent transactions, it is important that these numbers not be available in the open.

While it is critical to implement PCI, the cost implications are high. Consider for a moment the number of systems and business processes that work with credit card data. All of these systems must be changed, maintained and supported without ever displaying, storing, logging or exchanging the actual credit card data. It is almost the same as making telephone calls without ever using a telephone number. The complexity and cost of conforming to PCI is huge.

If it was possible to create a payment system where fraudulent payments were not possible, even if card numbers were used in the open, the payment industry would save a lot of money. If we could have a payment systems even if you had my number you could only send me money, then it would be okay if you had my number. PCI would then not be required. This is possible through mobile payments.

This is a thought: maybe the business case for the implementation of mobile payments could be built on the elimination of PCI.

Monday, July 18, 2011

Mobile banking for low bank balances

In a very interesting move, one of the largest banks in Nigeria (UBA) advised their clients that they would systematically be closing bank accounts with a balance lower than N 25 000 (about $ 150) (Read here). They advise their clients that they would want them to still do business with the bank, but by making use of their new mobile facility called U-mobile. This basically means that clients with small balances would not be served in branches, but can still transfer money by making use of their phones. Interesting...

This begs the question if mobile banking facilities are designed to cater for customers with low balances only. Is the reason why banks would be interested in making mobile banking available to get customers with low balances out of the branches? Or are the needs of customers with low balances just different and they do not need to visit branches?

Friday, July 15, 2011

Branchless regulations to stimulate

Banking regulators have a very important job to do. They are the custodians of the stability of our financial systems. We should not under-estimate this responsibility. It is interesting how different regulators approach this task. Some have a very restrictive and prescriptive approach: their regulations are characterised by offering the banking fraternity with systems cast in stone. In these countries it is extremely difficult to innovate as the central bank does not allow anything to be different than what they prescribe. As one can imagine, progress in these markets are slow. I am sure the readers will be able to name such countries without me being explicit about them.

On the other hand, central banks can create rigid frameworks that will ensure the stability of the financial systems, yet allow for innovation within these frameworks. As the solutions start to evolve, the central bank could then loosen some of the limits and constraints in these frameworks. This is of course a much better approach, as it stimulate growth, without compromising the financial system.

A case is point is the State Bank of Pakistan (SBP). The initial branchless banking guidelines released by the bank providing sufficient room for very innovative solutions to be launched in Pakistan - solutions that achieved good traction. The SBP has now released new guidelines that relaxes some of the previous guidelines. (Read here). Some of the steps forward is the creation of a new level of KYC-compliance, that relaxes some of the previous constraints, as well as an increase in limits. This approach should lead to faster growth in the industry in Pakistan.

Sunday, July 10, 2011

The pre-occupation of the world with m-Pesa.

"Will there ever be another mPesa?" reads the headline of a recent article. "Of course not", I wanted to say, but what is the point of the question? In the same way there will never be another Celpay or EasyPaisa for that matter. Yes, without any shadow of a doubt, mPesa had a major impact on the world's understanding of bringing financial services to the unbanked, but it has never been the only success and in many ways we can learn from many other similar solutions deployed in different parts of the world.

Other notable success-stories (to mention a few) are:
  • The Celpay deployment in Zambia, achieved remarkable commercial success with very low capital investment. Frequently recognised, Celpay has shown that this type of technology can be run profitably. Both mobile money deployments in the Philippines have shown significant impact in the social fiber of this company. Solutions ranging from micro lending and money remittances have been pioneered on these platforms.
  • The MTN Mobile Money deployment in Rwanda have shown faster growth (both in terms of take-up and transaction values) on a relative basis than mPesa in Kenya. In a country much smaller than Kenya, the growth in take-up has been phenomenal.
  • The Easypaisa implementation in Pakistan has been particularly impressive with a different business model in a very competitive market where banks are much more responsive and innovative than many other countries.
This pre-occupation with mPesa being the only example of a successful deployment of mobile financial services is harmful to the industry as a whole.

Friday, July 08, 2011

Facebook money implications.

I previously wrote a blog about the Facebook credits and the likelihood of it becoming a serious currency. It is unclear how much money is locked into this currency and how this will grow. It is also interesting to speculate how it will evolve to become an important component of the Facebook business case. The potential size of revenue does not seem to be that big and will not substantially increase the $ 2 Billion revenue that Facebook is making (predominantly) out of advertising.

What is interesting, though, is other aspects to consider. Finextra reported recently (Read here), that Facebook silently tweaked some of the rules to ensure that they do not breach US anti-trust laws. (They needed to ensure that they do not use their dominant position to arrange an unfair advantage to themselves.) Other considerations that will be important in future are consumer protection considerations and ensuring that the scheme is not contravening deposit-taking laws.

Also, the economics of funding the credits are interesting. When buying credits, one can use the usual payment options (credit cards, paypal etc.). But facebook as also teamed up with Zong and Boku and it is possible to also buy credits with these solution providers. This means that credits can be bought with airtime. If Facebook credits take-off and the scale become much bigger than now, this could have interesting implications for the revenue models for mobile operators.

Thursday, July 07, 2011

The key to the Nokia Money strategy is a flexible mobile application

Nokia announced a collaboration with MCB bank in Pakistan recently. With this move, they have demonstrated that they could move the concept started in India into other markets. (Read here). MCB have successfully used Fundamo technology to roll out their mobile strategy and have won numerous awards for the success that they have achieved in the Pakistan market. (Read here). Not only then is this move extending Nokia's regional reach, but also an extension of technology suppliers. This is of course a positive move.

The ability of Nokia to offer mobile banking as a primitive feature on all of their handsets will be critical to the success of these initiatives. According to some media reports, it is the intention of Nokia to offer the mobile banking application on all of their handsets (from the basic sets to smartphones). (Read here). It is going to be their ability to do this in a seamless way, integrating into multiple different back-office systems, ensuring compliance with different regulatory dispensations and doing so in different languages, that is going to be the proof point of the strategy.

BNZ mobile banking in the spotlight, but what is really happening in New Zealand?

It seems as if the new mobile banking solution developed by BNZ met with a lot of positive feedback when launched recently in Kiwi Land. The application and mobile web solution was reported to have been well-received in the social media and the iPhone app quickly rose to be the application downloaded most. (Read here). The bank must have done something right and reading between the lines, I believe that they treated mobile as mobile and developed a mobile banking solution, specifically designed for new requirements.

On the other hand, it could also be that this is a light shining in an industry with a mediocre and ill-conceived offering to consumers. Kiwibank refers to their mobile banking as being available to "phones that can access the internet" and to "use your internet banking access number" to do mobile banking (Read here). Whatever happened to the Kiwibank mobile banking launched in 2007 with "features not previously available anywhere in the world"? This was supposed to be the springboard for local technology company (Fronde) to tackle the world. (Read here).

Similarly, Westpac New Zealand refers to something called Mobile Online Banking on their website and claims that it "offers all the same services as online banking". Clearly just internet banking on the phone. (Read here).

Signature-based security is the biggest source of Fraud attempts

At the risk of stating the obvious: The chances of fraud is significantly higher with payment instruments based on signatures than those using PIN's. This is made clear in a blog posted on the 27th June on Retail Payment Risk Forum. Based on information collected during 2010, fraud is more likely by a factor for instruments that use signatures as payment authorisation.

The relevance of this research in my mind is that the cost component allocated to security could be reduced by as much as 80% by making use of a more secure mechanism. By taking these concepts into consideration in the deployment of mobile payments, it is possible to offer much less expensive solutions. It is important to consider security designs from this perspective.

Friday, June 24, 2011

A few Tweets tell a thousand stories

A sample of recent tweets oof the most famous mobile banking.

  • Stuck at an mpesa shop in juja thanks to safcom.Unreliable as always.Leo nitapigwa ngeta aki!
  • #safaricomltd should buy more mpesa servers and switch them on, on fridays.
  • @hardcorekancil they are still working on setting up the mpesa in kenya
  • @SafaricomLtd Mpesa has been down! Forced to travel to kisii via my nakuru home coz i cldn't transact in Nbi.How can i do an ATM trnsction?
  • @armuisME: Who is still surfering at the hands of these wankers @safaricomltd ==>if it wasn't for mpesa...i'd be so off them
  • whats up with mpesa? is this back up? @SafaricomLtd
  • @SafaricomLtd why is Mpesa not working ??!!!
  • T @Ekymani c'mon safaricom @bobcollymore ..the Mpesa downtime of late is unforgivable?
  • @antwaRogue Mpesa iko down n my chums are there so u better have ur cab guy on speed dial incase we are stranded in town.
  • @bobcollymore sir whats up with mpesa? It is nt working. I appreciate your response in advance.
  • @shique08 i've tried my mpesa too..it aint workin
  • #ThatWTFmoment when safaricom net and mpesa are both down #wtf
  • @safaricomltd whats happening to the Mpesa services.manze nimesota en i need to withdraw some cash like right now!!!!!!!!!!!!!!!!!!!!!!
  • How predictable that everyone & they cousins have decided to go shopping with MPESA right at this minute.......
  • @emmalilbecky: Teacher:what does colour green mean in our flag? Njoroge:MPESA
The moral of the story is: Even if the delivery of the service is not the best, but you provide an indispensable product, mission accomplished

Thursday, June 23, 2011

Physical mobile banking backwards step

Seeing that I have a lot of interest in mobile banking, I try and track what is happening as much as possible. I was therefore quite surprised when I learned of a new mobile banking service being launched in Uganda that I have never heard of before. The service launched by Centenary Bank and partially funded by US Aid aims to bring banking to 300 00 farmers in the northern part of Uganda. According to the article the project required investment of almost half a million dollars. (Read here).

It would be interesting to find out if they ever considered using mobile phones and deploying (much more cost effective) agent networks as has been proven to work in many deployments in the region. Just considering the status of some of the roads in the region, it would also be interesting to see the projected maintenance cost of the project.

Sunday, June 19, 2011

A fresh breeze in India

Standard Chartered recently announced the launch of Breeze - a brand associated with their mobile banking initiative. (Read here) Making use of the capabilities providing by UK solution provider, Monitise, this offering must be evaluated as it introduces an important new concept in mobile banking. Exclusively focussed on existing Standard Chartered clients, much of the focus is on providing a richer and more intuitive consumer experience.

In the past, mobile banking services were often evaluated on the basis of criteria like scope of service, security, scalability and accessibility. In preparing the launch of this service, the bank placed a lot of emphasis on making sure that the user experience will be a competitive advantage. The methodology used in developing and supporting the service was carefully considered. The result is a new look and feel and a fresh approach to how mobile banking can be presented.

It would be interesting to get feedback on penetration and usage. The results will help answer important questions such as if people will do more banking if they enjoy the experience.

It is not that easy to Zap a brand

Last year, the Zap mobile money service provided by Zain in Africa, received the award as the best mobile money service for the unbanked at the MWC in Barcelona (Read here). This year, the service won an innovation award at the same event for a virtual card product (Read here).

Since then a few things happened that could have an impact on the future of Zap. George Held (generally recognised as the main driver behind the roll-out of Zap in Zain) left to join Etisalat as the head of products. Furthermore the Africa operations of Zain (where the main roll-out of Zap was spearheaded) was sold to Airtel from India. All of the Zain operations in Africa has now been rebranded to Airtel and the business philosophy of the company has been changed to aggressively compete for marketshare.

As a result of these changes, all Zap money services were also rebranded as Airtel Money with immediate effect. The Zap brand literally disappeared overnight (Read here). The Zap brand was so powerful, that it is extremely difficult to kill as even in official websites of Airtel, it is still referred to as Zap (Read here)


http://networkedblogs.com/iTcIg
http://www.zapp.ro/

Is Mobile banking really serving the poor?

I recently noted that Michael Joseph (the father of mPesa) participated in a forum on the topic of banking the unbanked (Read here). Many observers are asking if mobile phones can be used to bring previously unbanked people into the domain of electronic banking. Much is being said about it and it is analysed from different directions, but should we not just ask the simple question: "Is mobile banking really serving the poor?"

It seems that there are overwhelming evidence that it does (and not just in Kenya):
  • In a recent research paper prepared by CGAP, it was found that more than 40% of Easypaisa users in Pakistan live on less than $2.50 a day. (Read here). It was also found that almost have of the users of the service do not have a bank account.
  • Berg Insight research indicate that about 133 million people benefit from mobile banking services in emerging markets. (Read here). According to this research more than a billion dollars was remitted to mobile banking accounts in 2010.
  • The Boston Consulting Group recently produced a report highlighting the big progress that has been made (Read here). Big growth in the penetration of the unbanked community is projected.
So in summary, we must surely say: "Yes, mobile banking is definitely serving the poor". Much must still be done, but sometimes it is important to just reflect and to realise that we are on the right track.

Friday, June 17, 2011

The risk-profile for mobile operators

Online banking in South Africa is much more secure because of the use of SMS to deliver one time passwords (OTP) to banking customers. Unfortunately, even this practice can be manipulated by criminals to intercept passwords. This was recently highlighted when it was reported that a Vodacom employee colluded with criminals to intercept the OTP's sent to customers. In the process fraud of R2.4 million (about $340 000) was committed. (Read here). The immediate question is if Vodacom is liable in any way for this damage and the answer is quite clearly: no.

The commercials and infrastructure that supports existing telecommunication services (the delivery of voice and data products), were never designed to cater for the additional liability of financial services. Many examples exist where banks have been held liable for fraud perpetrated on their networks (Read for instance here). Banks have to implement systems to cater for this, they have to price their products accordingly and take out insurance to achieve this. The question is if Mobile Operators understand these implications and if they are able (and willing) to act accordingly.

In the meantime, consumers have to be made aware that the protection that they may expect from utilising telecommunication infrastructure to secure their banking , are not as rigorous as they may think. This is demonstrated by a resent post on the Internet Security Awareness Portal (Read here).