Showing posts with label compliance. Show all posts
Showing posts with label compliance. Show all posts

Sunday, 6 February 2011

Are we doing enough to reduce identity theft and fraud?

In the past few years, there has been an increase in identity theft reported by various organisations. The economy and the society have to bear billions of pounds of losses caused by identity (ID) theft. According to the Home Office, ID frauds cost the UK economy nearly £1.7 billion a year. Although FSA, Home Office and other fraud prevention organisations like CIFAS are taking proactive measures in reducing fraud, the question is, are private sector organisations doing enough to combat fraud?


In 2008, more than 16.5 million people were placed at risk when their identities were lost or stolen by the financial services firms, reported by Computer Weekly.

Last year (2010), CIFAS, the not for profit association dedicated to prevention of fraud in UK identified and protected over 89,000 victims of identity theft. This has increased over nine-fold from 9,000 cases reported in 1999.

Almost every other retail business has an online presence. If you don’t have an online presence, you may be missing a business opportunity, which entices businesses to create ecommerce sites without realising the responsibility to the consumer it brings with it. Stealing an identity for professional criminals is easy, all you have to do is to go through someone’s paper waste and recover bills and invoices. Unless you live in Knightsbridge or South Kensington where due to the high rate of identity theft, residents take extra precautions in shredding every single invoice, people are generally laid back in how they dispose of important documents.

On the street, it is very easy to obtain official documents illegally. Consider opening a bank account and if you are a foreign student or just moved to UK you may have very little to none identity footprint. So how could you be eligible for a credit card, or bank account or even a mobile phone? The answer is to manufacture an identity through illegal means. Small and medium size financial organisations are aware of this and are most vulnerable but most use manual application forms while demanding paper based proof of identity documents from customers. Paper based procedures open the door for organised fraudsters and criminals to cheat the system. SMEs also tend to use manual identity verification sources to run identity and sanction checks which are time consuming. With high volumes, employees have to dedicate their time to running these checks instead of doing more productive work which causes pressure and often results in compromises in decision making. Simply put, more sophisticated systems are needed to solve these problems.

Similar problems exist for local authorities as most are suffering from project and hiring freezes. Council employees are under pressure to complete their work obligations because of shortage of staff. With increasing unemployment and layoffs, citizens are forced to claim benefits which further creates a strain on the council’s budget. Most councils rely on paper based procedures which like the SMEs in financial and retail sector, open room for the organised fraudsters to operate in.

Tabaq Software's Fraud Prevention Solution is an automated online electronic ID authentication solution developed on top of the jComply GRC platform. The solution offers a risk based approach to identity authentication by directly integrating with data providers such as Experian, Complinet, World Check, MK Denial, FSA, UK Companies House, FOA and more. The paper based forms are replaced by workflow based online forms which run automatic checks with the subscribed data sources while maintaining a full audit trail to prove compliance. With email notifications and alerts, employees are equipped with a system that enhances productivity, efficiency and reduces the cost of compliance.

To learn more about this system and how you can benefit from it, please email sales@tabaqsoftware.com or call Sultan Noori at 01344 668400.

Sunday, 24 October 2010

Why should businesses move to Electronic ID Verification?

Most businesses today still rely on manual application processing and identity verification. On the other hand, identity theft is on the high. There are more online businesses than ever before selling goods. From the consumer’s perspective, an average consumer is very aware of the identity theft and majority are apprehensive about disclosing confidential information to businesses online. Online retailers, especially the small to medium size businesses have little investment or understanding of the risks associated with identity theft. This is because the retailers outsource the credit card processing to third parties thereby transferring the risk to someone else. Or have they really transferred the risk?

Most small and medium size financial institutions rely on paper based applications with applicants required to submit paper documents (passport, utility bills, etc.) as proof of identity. There is a difference in perspective as applicants generally do not feel comfortable in submitting paper based documents. Delay in submitting the paper documents can cause the business a new customer. Paper based procedures also open the doors for fraudsters to submit forged documents.

All of the above mentioned practices, beliefs and difference is perspectives create a market place that is ripe for the identity thief and intelligent fraudster.

The solution is to move the paper based application forms to digital workflow based forms with electronic verification of identity. The workflow based forms provide cost savings in paper and human resource and also fulfils compliance requirements. The electronic verification of ID eliminates the need for paper documents for customer due diligence. It eliminates the risk of a fraudster submitting forged documents and fast tracks the process of identity verification.

If you require help with converting a manual paper application form to an electronic workflow based form or integrating with electronic ID verification, Tabaq Software has the solution for you. Tabaq has successfully converted paper based procedures into workflow based procedures and also partner with identity management providers to provide a completely integration solution.

To get more information on electronic ID verification and workflow based forms, email sultan.noori@tabaqsoftware.com.

Wednesday, 21 April 2010

WHY COMPANIES NEED STRONGER ANTI-MONEY LAUNDERING CONTROLS?

It is tempting for many organisations to view AML training programs as 'just another compliance burden'. As a result, part of the focus of the new AML regime to date has been on the large individual and corporate penalties that may be levied for non-compliance under the Act. In fact companies can be fined as much as $ 11 million for a breach of a civil penalty provision and individuals can be fined up to $2.2 million. These fines may also quickly escalate if multiple breaches are involved.

For companies which have yet to realize the importance of implementation and training of AML programs it is worth considering the potential costs and risks of having an inadequate approach to money laundering. Besides financial lose due to penalties companies face various other risks such as reputational risks, regulatory risks, legal risks and concentration risks as result of non-compliance with AML policies. Companies conducting business internationally have a higher risk factor especially those subject to the AML regimes of the UK and the US. Such companies are increasingly looking to deal with other companies with a strong AML program in place in order to help meet their own AML regulatory requirements and to avoid guilt by association. The biggest risk for any organisation besides financial lose is potential damage to its reputation arising from the organisation’s alleged involvement in money laundering or even worse, terrorism. In today’s world no organisation can stand the risk of association with terrorism. Clearly its up to the organisation’s chartered secretaries and MLRO (Money Laundering Reporting Officer) to promote the message and its importance within the company.
As costly and time-consuming AML compliance will be for an organisation, there are a range of real benefits to be gained from a robust AML compliance program that has been endorsed by its governing body including:
  • Increased revenue and marketing opportunities through the acquisition of more comprehensive and reliable customer information through KYC and Due Diligence.
  • Reducing bad debts and fraud losses as a result of enhanced customer due diligence
  • Improving operational efficiencies through more integrated and automated management of financial crime
  • Reducing the risks of exposure to corruption, identity crime, terrorist financing and a range of other potentially damaging criminal activities
  • Enhancing the overall control and risk environment by tightly linking AML to broader operational risk measures with potentially favourable outcomes for capital adequacy requirements.
Every organisation with a strong knowledge and objective to support and implement AML program should have a plan in place including an efficient software for risk assessment, generation and dissemination of related policies and procedures and training of employees on regular basis.

Tuesday, 6 October 2009

Do US Compliance regulations play a part in the UK ?

As a UK vendor of compliance software I get increasingly annoyed at how most news worthy articles I read on the web referring to compliance and regulations constantly refer back to US legislation.

Its almost as if the UK does not have to comply to legislation. Certainly the "does not live here" attitude from many UK Compliance Managers I meet should consider the more subtle British way of introducing change.

I wrote in my blog of 30th September that the onus of responsibility has changed in the UK for Health and Safety issues. Indeed, not only are line managers more accountable for health and safety issues, the concept of innocent until proven guilty in a legal situation appears to have shifted to that of prove you have complied.

Irrespective of the lack of legislation within the UK towards Corporate and Information Governance the trend is toward individual responsibility,but when does responsibility become culpability.

Back in the early 1970's VAT was introduced to the UK. Suddenly, all those business owners who traded over the stated threshold became instant tax collectors and responsible for completing quarterly returns and submitting these along with the tax collected. Anyone to this day who does not carry out this function is liable to receive fines and possibly a custodial sentence if deemed appropriate. Is this a responsibility or culpability?

Fast forward to the changes in the UK licencing regulations in the middle of this decade. Each licensed establishment is now required to assign a designated premises supervisor who holds ultimate responsibility for the running of that premises. This includes health and safety, enforcing anti social behaviour laws and bye laws both within and immediately outside of the designated premises, non smoking rules, stopping under age drinking, stamping out drug abuse, etc.

These are not bad things to try to address but when does the responsible bar owner go from being responsible to culpable.

More importantly for this article when does the law support those responsible rather than use them to apportion blame and liability when it comes to issues involving legislation and Corporate Governance.

How can an organisation and individuals working within those entities ensure they are acting responsibly and endorsing policies and procedures rather than appearing culpable to a wider audience.

The answer lies within the such legislation as Sarbanes Oxley, Basell II, HIPAA and the like all be them US law. All these acts were delivered to help support the use of properly managed processes, probably utilising technology to show good corporate practice within each Acts specified area.

Rather than review such news items that quote US legislation with an attitude of "it does not fit here", personnel operating within UK organisations should consider the shift of emphasis in this country from "innocent until proven guilty" to "proof of compliance".

The use of technology really can make a difference and I am particularly proud to sell jComply our policy and procedure management solution. This application is designed to support all people within an organisation understand, meet and then deliver responsibility be it in health and safety, information security, corporate governance or best practice.

Visit http://www.jcomply.com/

Saturday, 27 September 2008

Testing results of jComply beta 1.0

Over the past two months, jComply Beta 1.0 has undergone some rigorous testing schedule. Apart from our ongoing in-house testing, we have worked with industry professionals, consultants, compliance and risk managers from the financial, healthcare and pharmaceutical sectors to carry out detailed functionality testing of our policies and procedures management system. These efforts have resulted in bringing out issues/bugs and a number of recommendations to further improve our product. The issues were logged in our issue management system and are being traced to resolution. The recommendations on the other hand have been absorbed in our development roadmap.

I am therefore thankful to all those who have participated in our testing so far and can’t wait to work with individuals who are scheduled to test our releases in the coming months.

jComply, a policy and procedure management system is expected to be released next month. To learn more about jComply, visit www.tabaqsoftware.com/jcomply

or

to register for a free no-obligation demo, fill up the form at http://www.tabaqsoftware.com/registration.html.

Tuesday, 16 September 2008

Collapse of Lehman Brothers - Is the worse yet to come?

The collapse of Lehman Brothers is so huge that I feel compelled to write my two bits. The financial markets have suddenly plummeted overnight and most of the positive thinkers like me are hoping that this is the deep end of it and it will not get any worse. Will it get better from here onwards or is the worse yet to come?

Fingers are pointing at US with concern and some people on this side of the Atlantic are probably worrying what this situation has to do with them. In simple terms, companies like Lehman Brothers used to lend money to high street banks. High street banks then had the liquidity or cash to lend to mere mortals like us. Now, if the high street banks are not going to raise money easily, they will have difficulty lending it to us. In UK, the situation is already bad and the property market is infected with high interest rates and negative equity which is deterring people from buying.

Well, the outlook is certainly not good. There are rumors that the insurance giant AIG could be next in the financial crisis. Banks are anticipating the next two weeks to be volatile, lets see what happens. Investors who have the holding capacity are advised to not panic and think long term. Stay away from high risk investments! You are better off leaving your savings in fixed deposits.

Tabaq Software Ltd is a developer of enterprise compliance solution, jComply which can help heavily regulated sectors like finance, pharmaceuticals, healthcare, airline, etc. to comply with regulations and their internal policies and procedures. The first release of jComply is expected in October 2008. To learn more about jComply, visit http://www.tabaqsoftware.com/jcomply.

Thursday, 17 January 2008

Clamp down by FSA

The Financial Services Authority (FSA) is setting an example by clamping down on financial institutions found in breach of their regulatory requirements. FSA has started the year by issuing huge fines to two financial institutions; £1.085 million to HFC Bank (part of HSBC Group) for PPI failings and £250,000 to Square Mile Securities Limited (a stock brokerage company) for high pressure sales tactics.

The big question is, is FSA setting the tone for 2008? Are we going to see more fines issued for negligence or lack of having customer due diligence policies in place?

What puzzles me is that the average John is so naive enough to buy into the pressure sales tactics used by companies like Square Mile. We are not really talking about a door to door sales man trying to con innocent housewives. Surely, the customer also needs to take some responsibility, step back, educate oneself and then take a calculated risk. As they say, ignorance of law is no excuse. I feel, while FSA is clamping down on financial institutions to comply with its regulations, efforts ought to be made to educate the customer on making sound financial decisions based on calculated risk.

Note:
PPI covers repayments on loans, mortgages and credit cards if the borrower is unable to make them because of loss of earnings as a result of accident, sickness, unemployment or death.

News Links:
http://www.fsa.gov.uk/Pages/Library/Communication/PR/index.shtml
http://news.bbc.co.uk/1/hi/business/7191506.stm

Friday, 14 December 2007

Falling standards in UK healthcare

It is not very encouraging to see that some of the prominent hospitals in UK have shown below par hygiene standards in recent years. NHS body Health Facilities Scotland produced a report last year which showed three of the Scotland’s leading hospitals not meeting the hygiene standards. NHS Watchdog and the Healthcare Commission have produced reports in the past two years highlighting various levels of falling standards.

Where are these falling standards taking us? According to the Patients Association, the general views shared by patients about NHS service are long waiting periods, delayed appointments, fear of filing complaints and confronting the doctor, office hours only, etc. Instead patients ought to be treated as customers and stakeholders.

For once globally renowned and exemplary British NHS service, up to-date and technologically advanced tools are required to give fair judgement to the assessment criteria. In that respect, it was a relief that NHS decided to part with the star rating system for the hospitals which was more synonymous with giving stars to children in schools. For the first time, last year NHS trusts assessed themselves against 44 quality standards of basic competence. According to the health inspection body, only third of the country’s 570 trusts met the standards, which include safety, governance and patient focus.

Thankfully, developments in technology have given us the ability to develop systems that can help the trusts implement these standards across the board and certify themselves. Read more about jComply and how it can help with your compliance process at jcomply.com.

Monday, 3 December 2007

What is KYC and what does it stand for?

To enhance my knowledge on the subject I engaged in a few discussions with some professionals on KYC. I realized that very few people have detailed knowledge on the subject. Given the increased need for the implementation of KYC, I decided to share some basic information on the subject.

The term KYC – Know Your Customer means that financial institutions such as banks and insurance companies are obligated to record information on their customers and to check the plausibility of the information entered. The basis for KYC is endorsed by Article 8 of the 3rd EU Anti-Money Laundering Directive, 12.5 of the Banking (General Practice) Regulatory Code under the Banking Act 1998 and 6.1 of the Financial Supervision (Conduct of Business) Regulatory Code under The Investment Business Act 1991 for UK.
KYC consists of two parts; Customer Identification Program (CIP) and Enhanced Due Diligence (EDD). CIP consists of collecting basic evidence on customer identification information such as utility bills, driver’s license, passports etc.

EDD goes further to adopt a risk based approach and demands financial institutions to identify the risk a customer represents, validate those risk categories and demonstrate effective customer due diligence to the regulator. The source of funds that are utilized as part of the business relationship and/or transaction as well as their intended use also must be determined. In the event that the source of the funds is not clear the financial institution must observe due diligence in carrying out a risk base assessment on the customer profile.

In an ideal situation this information is stored electronically in the “Know Your Customer” profile (KYC profile). Due to rapid globalization financial institutes all over the world should stress on KYC, keeping track of customer movements, risk assessment and profiling across borders. Breach of KYC and AML rules and regulations can result in serious penalties by the regulators.

Anjum
03/12/07