Wednesday, June 11, 2008

Boiled Sweets, Hand-Rolled Cigars and John McCain


Guest blogger Richard Muirhead, CEO and founder of Tideway Systems reports from the SIFMA Technology Management Conference in New York where signs of a looming US recession appear to be masked by fancy cigars, the latest hand-held and software gimmicks and presidential hopefuls courting Wall Street bankers.


Apparently Wall Street technology budgets are in rude health - that is, if the array of attention-grabbing gimmicks at SIFMA today are anything to go by. Nintendo Wiis; iPod Touches; young ladies in Pink Fairy costumes; and our very own Dave Kirby will be thrilled to hear that one messaging vendor featured a dragon boat’s worth of booth attendants resplendent in tie-dye, trippy t-shirts. They stood out, but they were still not a patch on Dave’s tie-dye jumpsuit.

So such great lengths become necessary when all four floors of the exhibition are packed with vendors touting their wares and you are one of innumerable messaging vendors who appear to be one millisecond faster than one another. At that point perhaps it becomes more the battle of the brands than the technologies. Think of tennis for example; could you prove your game is better with a Head tennis racket than a Dunlop, or does it just matter which racket Federer uses?

Virtualisation was sprinkled around liberally also, from the likes of Sun, IBM, Novell and others. As long as it can resist being overshadowed or at least out-shouted by the crescendo of interest in cloud computing, which I think it shall, then I believe server virtualisation’s finest year is yet to come.


The theme of relentless demand for better infrastructures was a recurring one. Data centres are constrained by space, cooling and perhaps latency, which will have a bigger impact on the surge in new builds. Tracking friends via GPS on Helios; video calling on the new consumer friendly iPhone; computationally intensive derivatives portfolio calculations, could create the biggest strain. Have CFO’s accepted yet that the current acceleration in investment is not a blip, but the beginning of a trend?

Other noticeable themes were complex event processing and 'low-latency’; and I am not just referring to the adept networking of the regulars that make up the PR cognoscenti in the 'SIFMA set'.

So, there I was propping up the bar meeting various journalistic characters that were plucked from an Evelyn Waugh novel. That is until the bar opened and I was told that sitting there for 15 minutes without consuming alcohol was not doing my bit to support the US economy and I should move on.

But I was impressed by the number of people milling round the bar, taking it as clear evidence of frantic education and deal-making - or perhaps simply marketing budgets still bulging from the exuberant planning assumptions of 2008. Until, that is, out of the corner of my eye I caught sight of a neatly turned out, silver haired gentleman, sweeping from a bank of brass-clad lifts and softly holding court to his entourage.

The presumptive candidate and some might say now in the face of Barrack Obama’s rising tide of popularity, the presumptuous President: John McCain. What was striking was the relatively small number and indeed small stature of his group. That was until 25% of the bar revelers promptly switched off their secret-service earpieces and vanished into sweltering Sixth Avenue.

Today is to culminate in the parties. The largest, hosted by SunGard, great sushi, lashings of sake, but be careful not to drop your guard. The most exclusive, hosted by the unlikely bed fellows of Intel and Sun and featuring every successful executive’s favourite indulgence: hand rolled cigars. All of this nestling under a party theme of trade-processing power undiminished by prudent and conscientious data centre efficiency. A domani.

Friday, June 06, 2008

Sniffing out SIFMA

While other more fortunate journos will be winging their way to New York in a day or two for the annual SIFMA Technology Management Conference, I have been excluded from such a coterie

However, FinancialTech Insider will be covering the buzz on the exhibition floor remotely with the help of Richard Muirhead, CEO of Tideway Systems, who will be filing his personal insights on the conference and exhibition on a daily basis.

Tideway Systems helps companies gain greater insight into their IT infrastructure and application dependencies. Richard is the brother of Charlie Muirhead who created software company Orchestream at the height of the dot.com boom. In five years Orchestream went from angel funding of £20,000 to a dual listing on Nasdaq and the London Stock Exchange, and a market cap of more than £1 billion. It was later sold to Metasolv in 2002 and then Oracle in 2006.

Tuesday, June 03, 2008

Rogue trading - not an isolated incident

With rogue trading, data leakage and malicious attacks adding to banks' litany of reputational woes, it is no surprise to learn that banks are taking a peek 'under the bonnet' to see how well their risk management and detection systems are actually performing in today's more heightened regulatory environment.

When the SocGen rogue trading incident blew up earlier this year, other banks may have breathed a collective sigh of relief that it wasn't them receiving the unwelcome publicity, but at the same time they probably secretly acknowledged that rogue trading was not isolated to a single institution.

In fact it is probably fair to say that the bonus culture within most investment banks means they are unlikely to design and implement risk management systems that wholly curtail the creative urges of their traders.

Having said that,it is interesting to hear that an increasing number of firms (85%) plan on modifying internal controls in light of recent rogue trading incidents and that 60% have created special task forces in response to high-profile rogue trading incidents, according to Actimize's Rogue Trading Peer Review.

In order to keep the regulators at bay, banks need to be seen to be doing something to address what is at best an endemic problem. According to Actimize's review findings, more than 75% of respondents anticipate another large rogue trading fraud loss, worth more than $100 million to be uncovered at a large financial institution within the next 12 months.

An additional 50% indicated that rogue trading activities ranging from thousands to millions of dollars go unreported every year at their firms. One has to ask why these incidents are going unreported? Is it because risk management systems are not detecting them? Or is it a culture of silence fuelled by the bonus culture within investment firms that is preventing these incidents from being reported?

According to Actimize's review, 24% of respondents said they had experienced a case of trading fraud at their firms in the last 12 months, and 44% confirmed a case of employee fraud had occurred in the same period.

This confirms the increasing view that the greatest threat financial firms face is not external but internal, be it either unintentional (accidental data leakage from laptops, P2P technologies, USB sticks) or malicious (disgruntled employees, rogue traders).

When it comes to securing trading systems, Frédéric Ponzo, managing director of NET2S consultancy, says historically it has been a case of trying to make conventional security technologies (firewalls, anti-virus, anti-spyware, anti-keyloggers etc) work in a trading environment.

One of the biggest problems, he says is providing a secure infrastructure around "black box" trading terminals, some of which have email systems that do not necessarily fall within the usual security guidelines and policies of a company. These email systems remain vulnerable to attack or data leakage.

French IT security firm, SkyRecon Systems believes it has the answer in the form of its TradeShield solution, which aims to replace point-to-point security solutions in the trading environment with a "single agent, single management console" for managing system and user risk.

Designed specifically for the trading environment, TradeShield provides integrated protection including device control, data encryption, intrusion detection, firewall, network access control and centralised security policy enforcement.

Instead of having to enforce security policies and procedures for normal desktop computer use and trading applications, SkyRecon says that when a trading application is launched, for example, the computer cannot be used for anything else (for example, sending emails, personal instant messaging, peer-to-peer downloads).

The challenge for any solution in this space has to be providing the right level of control while enabling traders to have access to the tools they need (files, emails, IM) in order to trade effectively. Instead of completely "locking down" applications, SkyRecon says TradeShield allows applications to run but with the appropriate level of protection.

Thursday, April 17, 2008

Real-time realities

Guest blogger, Brussels ICSD, Euroclear, responds to news of Clearstream's new processing environment.

If memory serves me well, in 1998 both Clearstream and Euroclear (Euroclear Bank now) planned to launch real-time settlement platforms. Euroclear launched its daylight real-time settlement platform in 1999 and Clearstream postponed theirs indefinitely, citing other higher priorities such as Y2K.

Later, Clearstream launched its ‘continuous-batch’ daylight settlement platform called Creation for Clearstream Banking Luxembourg clients only; the CASCADE platform used by Clearstream Banking Frankfurt clients continues to operate today separately from Creation.

From our 10 years of experience in operating a real-time platform at Euroclear Bank, and our understanding of how real-time settlement works at other Euroclear CSDs, we know that there are different ways to organise a real-time processing environment, for example, event driven or calendared. To the client, however, the end result is the same – real-time availability of cash and securities.

Because Europe’s capital markets do not yet operate with harmonised market rules and practices, each processing platform must accommodate the particularities of the market(s) served, so the right approach for one market may not be the best for another.

Therefore, assessing whether one system is lower in cost to run than another requires highly complex analysis, including factors such as market practices, system capacity, processing peaks, levels of data-protection and client business-continuity sophistication.

Obviously, upgrading an existing system and consolidating five separate platforms into a single platform are very different initiatives. It would be nonsensical to compare a system upgrade with an unprecedented programme of infrastructure redesign that will save clients more than EUR 300 million per year.

Euroclear’s new Single Platform will, of course, operate in real time. Of equal significance are the joint efforts by Euroclear and our clients in the group’s five European markets (Belgium, France, Ireland, the Netherlands and the UK) to profit from the efficiencies of harmonised market rules and practices within these markets, in accordance with the Giovannini Group recommendations.

We firmly believe that platform consolidation and market practice harmonisation - in parallel - will deliver the most meaningful operational efficiencies and savings to the market. In recognition of these benefits, Euroclear Bank is now working with Clearstream Banking Luxembourg to harmonise market rules and practices for the international securities market, through the International Securities Market Advisory Group.

The two ICSDs have an excellent track record in making regular improvements to the Bridge, which is often credited by market participants as a stellar example of interoperability. Discussions are ongoing between the two ICSDs to further enhance the Bridge; interoperability can be improved further now that both Euroclear Bank and Clearstream Banking Luxembourg are operating in real time.

Monday, April 14, 2008

Clearstream's new processing environment

Well it certainly has been a busy few weeks for the world of European clearing and settlement. Not content with their trading counterparts stealing all the limelight in a post-MiFID world, the European CSDs announced their own 'Project Turquoise' in the form of the "Link Up Markets" initiative which will see seven European CSDs develop a common infrastructure for post-trade efficiency.

Fresh from that announcement, last week Clearstream the ICSD summoned a handful of journalists to its Canary Wharf headquarters in London to hear more details about the new generation of processing environment it announced back in March.

Instead of being courted with a glass of wine and a cocktail sausage, which we were told were being saved for all-important customers, we were given a detailed explanation of what Clearstream's new real-time processing environment really meant and how it provided a migration-free alternative to Euroclear's Single Settlement Engine (SSE), which aims to harmonise and improve settlement efficiency across five markets.

The move to a "real-time" processing environment is apparently part of a four-year strategic review that Jeffrey Tessler, president and CEO of Clearstream International initiated when he first joined the Luxembourg ICSD.

Philip Brown, relationship management, UK, Ireland & Nordics, Clearstream, said a number of market trends and requirements lead up to the new processing environment; a 25% increase per annum in custody volumes, increased complexity on the asset servicing side, investment fund volumes growing at a rate of 30% per annum, and the increasing move to same day repo which was putting pressure on clients to know where their collateral was and on ICSDs to support a same day settlement environment.

Brown said that Clearstream's new "real-time" processing environment would more tightly integrate settlement, custody and securities financing enabling clients to optimise their collateral by providing them with more timely information as to where their cash and securities are.

Clearstream's previous settlement engine was an overnight process which processed 95% of volumes efficiently. "It is the 5% we are trying to resolve by getting the market towards 100% efficiency" said Brown by providing same day settlement and financing.

Under the new processing environment, Clearstream will extend the settlement processing day from 4.30am to 6pm CET, which it said would not only optimise settlement efficiency by eliminating queuing times and enhanced fails management, but also minimise domestic turnaround times from three hours to three minutes, and optimise use of securities as collateral by enabling firms to hold less collateral.

"With event-driven real time processing we don't have a set time of day for starting processing," Brown explained. "Each cycle is driven by an event such as a corporate action or a bridge exchange file with Euroclear."

Commenting on its competitor Euroclear, Brown said that its processing environment was 'calendered' rather than event driven. I got the feeling that Clearstream also saw its new processing environment as an opportunity to steal some of the attention away from Euroclear's Single Settlement Engine project.

Brown was eager to point out that Clearstream was ready to switch on a real-time bridge between itself and Euroclear which would create the impression of a single processing environment, but that the Brussels ICSD was not quite ready yet.

"Euroclear's model is about the acquisition of CSDs around Europe for the creation of a single platform. Our solution is live now. Euroclear has not yet fully delivered its solution on a rolling basis," said Brown.


Arguably Euroclear's SSE, which requires platform consolidation in five markets, is a far more ambitious project than Clearstream's new processing environment. Brown would not be drawn on whether its processing environment was better than what Euroclear would offer. "I wouldn't say it is better or worse. We think you can get there quicker and more cheaply by using a robust infrastructure based on real-time processing."

Wednesday, April 02, 2008

European CSDs announce joint venture

At Sibos in Boston last year, Pierre Slechten, CEO, Euroclear France said that the European Central Bank's (ECB) Target2-Securities (T2S) proposal would lead to further consolidation of CSDs in Europe and cause CSDs to readdress their strategy in terms of moving up the value chain in custody.

Well it seems Slechten's predictions were right; well at least the latter point anyway. Whilst there may not be consolidation per se (at least not at this stage), today seven European CSDs (Clearstream Banking Frankfurt,Hellenic Exchanges Greece, IBERCLEAR Spain, Oesterreichische Kontrollbank Austria, SIS SegaInterSettle Switzerland, VP Securities Services Denmark and VPS Norway)announced that they would develop a commonly owned and designed routing and messaging infrastructure aimed at improving post-trade processing efficiency in Europe.

"It is an initiative that capitalises on domestic infrastructure," explained Jeffrey Tessler, chairman, Clearstream Banking Frankfurt. "It is about leveraging what is already in place for improved access and interoperability as outlined in the Code of Conduct (for Clearing and Settlement)."

The European Code of Conduct for Clearing and Settlement requires signatories to meet standards around price transparency, access and interoperability and service unbundling and accounting separation.

Announcing their joint venture, slated to cost $10 million, the seven CSDs stressed that their initiative would not replace existing domestic infrastructure, but instead create a "linked up market between CSDs so that everyone could speak the same format to one another". Couched in a slightly different way, Tessler said it was about bringing the efficiency of the domestic securities markets to the cross-border world.

Tessler would not be drawn on the exact cost savings of such an initiative, but said they would be "extremely significant". The key question on most journalists' lips however was, is this merely the CSDs going on the defensive in response to the ECB's T2S proposal for settling securities in central bank money using the existing Target 2 system?

Tessler was somewhat measured in his response. At first he said T2S would provide settlement not custody and that the market would benefit by having a "single gateway" for custody services offered by European CSDs, in addition to having a "single window" into the ECB's T2S Settlement Engine. "We are not building a settlement engine," Tessler stressed.

But as one journalist asked, does the joint venture between the seven CSDs mean that T2S is no longer relevant? Tessler said he didn't think that was the case and that the market believed in the benefits of a settlement system operating in an integrated model. "We have had conversations with the ECB about our initiative," he said, "and they see it as a facilitator to T2S."

However, there is no doubt that without the Code of Conduct and T2S, the CSDs would not have been forced to work more closely together. Tessler said the joint initiative would prepare market participants for a T2S world.

But with Euroclear pursuing its own market harmonisation strategy via its Single Settlement Engine and the ECB intent on introducing T2S, will the joint venture between the seven CSDs see the emergence of yet another market infrastructure that market participants have to connect too?

Tessler said that the joint venture was purely a domestic CSD initiative and that Euroclear could participate via its domestic CSDs, such as Euroclear France or CREST in the UK.

But given the SSE strategy Euroclear the ICSD is pursuing, are they going to want to participate in the joint initiative at the domestic level, and if more domestic CSDs in Europe do not join the initiative, are the real cost benefits and economies of scale that such a venture promises unlikely to be fully realised?

For those agent banks that may be feeling a little nervous about CSDs joining forces to provide custody services, Tessler said that they would continue to use agent banks for services such as tax processing and for settlement in central bank money. But hang on a minute, isn't that what T2S is meant to be doing?

Despite Tessler's assurances, the role of agent banks going forward appears less than clear, and there is a danger that with so many different market initiatives for harmonising and standardising clearing and settlement in Europe, that the market will merely end up with a handful of competing and uninteroperable initiatives.

Are corporates being heard on e-invoicing?

SEPA Credit Transfers are live and in recent months we have seen announcements from various vendors (Sterling Commerce's partnership with VAT and GST experts TrustWeaver, Fundtech's acquisition of Accountis)about their forays into the e-invoicing space, which is the 'e-SEPA' corporates often talk about.

Does that mean that banks are finally waking up to the fact that most corporates do not really give a damn about SEPA Credit Transfers (SCT) and SEPA Direct Debits (SDD), which lets face it are interbank instruments?

Not that there aren't advantages for companies using SCT and SDD, but that is not really what SEPA is about for most corporates. Corporate associations such as the European Associations of Corporate Treasurers (EACT)have been particularly vocal about their desire to leverage SEPA to overcome the remaining hurdles to pan-European e-invoicing.

The European Commission appeared to heed their call by setting up an Informal Task Force on e-Invoicing, which has issued recommendations for removing the remaining hurdles to pan-European e-invoicing.

While corporates are in dialogue with the EC Task Force, via a Corporate Supply Chain Panel set up by TWIST and EACT, we hear on the grapevine that any attempts by corporates to have a stronger voice in helping architect pan-European payment processing and e-invoicing standards, are being impeded by the Commission, or more correctly, the strongly represented and funded European banking lobby.

Some of the banks maintain that it is only a handful of larger corporates that want 'e-SEPA' and that to deliver what the corporates are asking for is all too difficult. Yet, just as banks(the European Payments Council) chose to sideline corporate opinions when they were drafting the frameworks for SCTs and SDDs, it seems they may be trying to do the same when it comes to pan-European e-invoicing.

The banks were so eager to be seen to be doing something about reducing the cost of cross-border euro payments, in order to avoid further regulation, that they only focused on the inter-bank processing aspects of SEPA rather than looking at the 'bigger picture' and the real opportunities SEPA presents to truly transform the European payments landscape.

Could this have something to do with banks wanting to tout their own proprietary e-invoicing solutions to corporates? After all, if they are losing so much revenue from standardising cross-border euro payments, they are going to have to make up the slack somewhere else, by trying to lock customers in somehow with proprietary solutions.

Yet, time and time again corporates, particularly those that are multi-banked, have said they don't want proprietary banking solutions; the same argument perhaps applies to e-invoicing. And while the banks maintain that they are best placed to drive widespread adoption of e-invoicing, corporates are far from convinced.

Despite all the rhetoric and the conciliatory attempts by the EC to engage corporate demands for pan-European e-invoicing, it appears that self-interest and preservation may be at work again and that SEPA merely represents a 'band aid' that banks have put over the existing infrastructure in their efforts to appease the regulators, rather than trying to treat what is intrinsically wrong with the existing infrastructure.

Me thinks that the European payments landscape may be setting itself up for its own 'Project Turquoise', except this time it won't be driven by banks but by corporates disgruntled with the status quo.

Friday, February 29, 2008

Playing with risk

I received this rather intriguing email from Eurofinance, which organises conferences for corporate treasurers, regarding a new board game they are going to unleash at Eurofinance Miami 2008.

Called, 'Cash Flow at Risk', Eurofinance designed the game to teach treasurers how to come to grips with the cash flow, credit and liquidity uncertainties ahead. I do wonder though if they should be targeting it more at the banks, given that it was them that seemed to lose their way.

Apparently, HSBC uses the board game as part of its corporate training, although one wonders if a board game, let alone a major credit crunch, is really going to teach banks anything about risk.

You may think I am being a little harsh, but the other day a risk management consultant told me he had started a training company as a sideline for his consultancy business, as selling risk to banks was a bit of a difficult sell. No bank wanted to really think about risk too much as it might stem their financially motivated creative urges.

The board game requires participants to answer economic questions in order to progress, but one has a feeling for some participants it would be a case of "Do Not Pass Go, Do Not Collect $200".

Can a board game though really teach treasurers about the "dangers ahead"? Is a simple toss of the dice and answering a few economic questions going to resonate with financial managers sitting in boardrooms across the country, the very same managers who in the real world, and not one confined to a board game, perhaps saw the warning signs but chose to ignore them?

Thursday, February 21, 2008

What went wrong at SocGen?

Well, the SocGen saga continues, with the commercial and investment bank reportedly publishing a report in French detailing how the trader Jerome Kerviel managed to evade controls.

Following publication of the report, IBM, the latest vendor to jump on the What Went Wrong at SocGen bandwagon, sent out an email reiterating the question everyone has been asking: How can you manipulate tens of billions unnoticed?

As I do not read French I am going to have to rely on IBM's interpretation of SocGen's interim internal investigation report, which reportedly claims that Kerviel's "position keeping and risk systems were unable to report such a large exposure because they [failed] to capture distant forward, incomplete and modified trades, and they were known to function improperly and be prone to recurrent errors."

An IBM spokesperson expressed amazement that a sophisticated organization was not capable of managing and properly reporting such simple transactions as stock future purchases, on the account that they were following unusual trading patterns (distant forward dates, multiple modifications, cancellations and transfers.)

Risk consultants from IBM Business Consulting Services outlined some of the major causes of large trading losses and stated that the "quality, coherence, and integration of position keeping systems," was crucial in counteracting some of these causes. "Effective position keeping" it said could also address employees trying to conceal losses and that "oversight mechanisms" which integrated monitoring, governance, and compliance requirements into a "holistic, focused, and practical framework," needed to be put in place.

Arguably however, there is only so much technology can do, and at some point a human needs to intervene or manage the process in order to prevent people who are clever enough from fooling or overriding internal risk control procedures and systems.

This is borne out by an independent report, which reportedly concluded that while risk control procedures were followed, "compliance officers rarely went beyond routine checks and did not inform managers of anomalies." According to the independent report, 75 warning signs on the activities of rogue trader Jerome Kerviel, were overlooked.

Who will buy?

It is no secret that Larry Ellison, Oracle's CEO is hell bent on world domination, and the other day I had the pleasure of seeing just how determined the man is to provide the complete software stack covering almost every permutation of financial services.

Over lunch an Oracle exec presented me with a 'place mat' - which I proceeded to eat my lunch on - demonstrating Oracle/i-flex solutions' banking footprint across retail, commercial and private wealth management.

With no fewer than 38 acquisitions under his belt, in the next issue of financial-i magazine, we look at the ramifications of Oracle's 'stack' approach for financial service providers.

Critics say that IBM tried it in the 1970s but failed. It is a question of who will buy, and of course with any software vendor that is so acquisitive in nature, customers are always going to be concerned about how well integrated its solutions are. Oracle's Fusion Middleware is an effort to pull the applications together, and the Oracle execs I met with were insistent that any company acquired by Oracle soon becomes part of the fold.

When it comes to Oracle/i-flex's existing banking footprint, most of the boxes on the place mat representing the customer experience, product and transaction processing, master data management, corporate admin, compliance, risk-based monitoring, analytics platforms and enterprise technology, were greyed out, meaning that Oracle already occupied that space.

The executive indicated that the white boxes were where Oracle would make its next acquisitive strike; in areas such as trade processing, securities trading, derivatives pricing, Lock Box, custody and structured derivatives.

Interestingly, Ellison has deep pockets and has financed acquisitions without having to resort to injections of private equity capital. The latest target is BEA Systems, which Oracle appears to be acquiring for its capital markets customer base.

Any guesses where Ellison is likely to strike next? But it seems not all banks are buying the stack approach. No bank is going to want to lock themselves into a single vendor, although the pace with which Oracle is acquiring companies they may be forced to. Additionally, some of the bigger banks still tend to favour building proprietary solutions in-house rather than buying something off-the-shelf.

Wednesday, February 20, 2008

Sovereign funds and banks

Once the target of various takeover rumours, Barclays now appears to be setting its sights on filling the gap left by the US investment banks that have suffered billions in write downs associated with subprime losses.

Interestingly, a question I have been asking in recent weeks, is what would have happened if sovereign wealth funds (SWFs) from Singapore and Kuwait had not bailed out some of the American banks eager to replenish their liquidity following such massive write downs?

The answers have been varied, but the bail outs themselves signify a new world order that is emerging, or as McKinsey likes to refer to the sovereign wealth funds, they are new 'power brokers' alongside hedge funds and private equity.

In fact, estimates suggest that sovereign wealth funds, while they may have considerable sums to invest, are not as big as say the Top 10 asset managers who are valued at $13.4 trillion, followed by the Top 10 central banks with reserves worth $4.4 trillion, the Top 10 pension funds valued at $2.9 trillion, and the Top 10 SWFs valued at $2.3 trillion.

But regardless of where SWFs sit in the financial pecking order, the sentiment seems to be that without the investments from Kuwait Investment Authority, Temasek Holdings and other SWFs, that the major US banks would have been forced to consolidate.

Thursday, February 14, 2008

Why settle for less, say Deloitte

After the initial exuberance had died down, most companies that had embarked on major IT or business process outsourcing projects discovered that there were 'hidden costs' in outsourcing to a third party provider.

As time and experience of outsourcing wore on, companies realised it was not simply a case of outsourcing a process to a third party and watching the cost savings pour in. The outsourcing process itself needed to be managed, monitored and governed, which entailed costs in and of itself.

Well Deloitte has just published some interesting findings on outsourcing based on its survey of 300 executives involved in outsourcing worldwide. More than 80% of respondents to its survey indicated a return on their investment of more than 25%.

However, while 70% said they were satisfied or very satisfied with their outsourcing. 39% said they had terminated at least one contract, and 50% of those that reported dissatisfaction with outsourcing had brought the process back in-house. In the first year of the contract, 61% of firms also indicated that they had "escalated problems" to senior management.

Therein perhaps lies the greatest challenge for both outsourcers and the firms that employ them, demonstrating not only one-off process improvements, but ongoing improvements on a continuous basis that satisfies customers' expectations.

As Deloitte's findings bear out, firms that outsource while financially gratified, would like to see a lot more benefits stem from the arrangement in terms of access to new ideas and innovation and better quality communications.

More than 30% wished they had spent more time on evaluating vendors before signing contracts, and if they had their time over again, almost 50% said they would have better defined service levels in line with their business goals, which just goes to show that a lot of firms have rushed into outsourcing mesmerised by the potential cost savings, without considering the processes, workflow and governance that needs to be put in place to ensure a better outsourcing experience.

So those businesses thinking that outsourcing or offshoring may be the solution to all their problems, particularly in an economic downturn when reducing costs is paramount, think again. Outsourcing is not a panacea and often entails 'hidden costs' which need to be considered in the overall cost/benefit analysis.

Martyn Hart, chairman of the UK National Outsourcing Association, says we could see the nature of outsourcing deals change in light of a recession. "In the past couple of years the ‘mega-deal’ has largely been consigned to the outsourcing scrap heap, in favour of multi-shoring and choosing separate suppliers for each process. Organisations will have to balance how to do this in the most cost effective manner," he says.

With mega-outsourcing deals a thing of the past, fixed price contracts are also likely to be abandoned for a more utility-based approach based on cost per unit.

Wednesday, February 06, 2008

Still miffed by MiFID?

I stole the title for this post from a panel discussion at Complinet's Compliance Conference in London today.

Judging by the number of people in the room (it was half full) they may not be that miffed about MiFID, or perhaps as most of the audience were risk and compliance officers, having to comply with non-prescriptive regulations is par for course.

Admittedly I walked in halfway through the debate, but judging by questions asked by the audience, it would appear that the Financial Service Authority's (FSA) principles-based approach to regulation, including MiFID, is causing consternation amongst risk and compliance officers, who would prefer a more prescriptive rules-based approach.

One compliance consultant chipped said that if firms went out and said what they think the rules mean (as they pertain to MiFID, then that would create a "stake in the ground," which is the safe way to develop compliance in a principles-based world.

Deborah Sabalot, a regulatory consultant, begged to differ however. She reminded the gathered risk, compliance and audit staff that the great thing about MiFID is that it was not non-prescriptive - in other words it gave firms the flexibility to design their own systems instead of being locked into something that was not of their making.

Still it didn't sound like that was what compliance officers wanted to hear. It seemed to be more a case of give us a set of rules we need to comply with and we can work with that, rather than making it up as we go along.

That may be the view of MiFID across the board, however, in the front office where the trading that MiFID regulates is executed, some firms clearly see MiFID as an opportunity to set their own benchmarks particularly around aspects of the regulation such as best execution.

However, for those that prefer the certainty of a prescriptive rules-based world, some form of best practice appears to be emerging, albeit slowly. Although it may take 12 to 18 months before firms' application of best execution under MiFID beds down, one spokesperson from UBS investment bank said any firm that takes a simplistic approach to execution by executing all of its trades on a single venue, are likely to find themselves under regulatory scrutiny.

That is pretty much a 'no brainer,' but other investment bankers raised concerns about additional taping requirements from CESR and the FSA and the extension of MiFID to commodities.

Lyndon Nelson, head of risk at the FSA, conceded it had been a difficult time for the organisation, particularly in view of the Northern Rock affair which it has received considerable flack over. Non-believers of a principles-based approach to regulation are likely to say that Northern Rock highlights the pitfalls of a principles-based approach to regulation.

However, Nelson said the FSA intended to stick to its non-prescriptive guns, albeit gaining some valuable lessons along the way from the Northern Rock Affair, and where requested, he said the FSA would provide market guidance by publishing more information gleaned from its risk assessment of firms, which could then be used by their peers to benchmark themselves against.

Tuesday, February 05, 2008

A new world order

Oh how the mighty have fallen. According to a Bloomberg report, Chinese banks have toppled Citi from the top of the league tables based on market value.

Citi, which had long occupied the top position based on market cap, has been superseded by Industrial & Commercial Bank of China (ICBC), China Construction Bank and Bank of China. The three biggest Chinese banks are valued at $608 billion, says Bloomberg, compared to $496 billion for Bank of America, JPMorgan Chase and Citi.

ICBC leads the tables with a market value of $277 billion, $82 billion more than Bank of America, which is in second place, followed by HSBC in third place ahead of China Construction Bank and Wells Fargo, according to Bloomberg data. Citi is now in seventh position. Yet, it was only five years ago that 13 American banks featured in the top 20 banks by market cap.

Wednesday, January 30, 2008

Fragmentation is not a dirty word

In the run up to the implementation of MiFID there was considerable 'umming' and 'aahing' about the impact the relaxation of the 'concentration rule' would have on the proliferation of trading venues and what that would mean in terms of fragmenting liquidity in Europe.

Those that were keen to see the status quo preserved in terms of liquidity residing largely with the national exchanges, painted a confusing picture of multiple trading venues springing up and the challenges of having to connect to all of these venues in order to demonstrate best execution.

Well it seems that debate has been quashed and smart order routing systems are helping "re-aggregate" liquidity.

"Fragmentation is good," said George Andreadis, head of AES, liquidity strategy, Europe, Credit Suisse at Finexpo in London. He then went on to cite a long list of reasons as to why it was good; less cost, lower latency trading, and attracting more liquidity into this space.

While Chi-X Europe may have been the only game in town, with its smarter, faster, cheaper model, Andreadis highlighted a whole host of planned MTFs looming on the horizon, including SmartPool, scheduled to launch in Q2 2008, Project Turquoise, and US "dark liquidity pools" such as BATS Trading and Pipeline, which are contemplating whether to launch this side of the pond.

It appears to be a very crowded and fragmented trading landscape emerging in Europe, mirroring what has already occurred in the US. Yet, Andreadis said that smart order routing technologies made it easier to determine where liquidity resided in 'dark pools'.

His mantra seemed to be that dark liquidity pools and MTFs were here to stay and that traders looking to demonstrate best execution ignored them at their peril. But the key to success in a market where liquidity is fragmented is the smartness of your order routing systems. "There is dumb order routing, smart order routing and very smart order routing," joked Andreadis.

Project Turquoise gives it the hard sell

There was standing room only in the auditorium at the annual Finexpo event in London for the session on Project Turquoise presented by the MTF's CEO Eli Lederman.

After much fanfare and very little substance since the group of seven investment banks announced Project Turquoise back in 2006, Lederman seemed eager to dispel the notion that Turquoise was the mythical concoction of a bunch of investment bankers, rattling their sabres in the hope that the London Stock Exchange and others would reduce trading prices.

Well Project Turquoise has still not gone live, although Lederman was adamant that preparations for the launch date in September 2008 were well underway and that he was confident Turquoise would attract liquidity from day one. "We will have a lot of members, it is going to attract liquidity," Lederman kept repeating over and over.

And if that is not enough to convince those sceptics who are still doubtful as to whether Turquoise will get off the ground, Lederman was eager to stress that it had secured office premises. "We don't have marble steps or vaulted ceilings, but this is a modern exchange," he said.

Project Turquoise has chosen Swedish technology provider Cinnober (they also built Project Boat)to build its trading platform and Progress Apama is providing the CEP engine for the MTF's market surveillance system. But Lederman was short on the details regarding the trading platform. All he would say is that it will be an "integrated transparent order book with a dark pool."

It seems that the launch date for Project Turquoise may also be a moving target, as Lederman said that it was not focused on the date alone and that it was keen to implement a trading platform that was not a "monolithic purpose built system."

Yet, despite Lederman's efforts to reassure the market that Project Turquoise is "moving full steam ahead," anyone who has observed the Project Turquoise "showboat" for the past couple of years will probably be inclined to say, the proof is in the pudding. And after talking it up so much, almost to the point of evangelizing, Lederman better hope the pudding is worth eating.

Friday, January 25, 2008

Real-time volatility

Those of you who read my "Crisis of Confidence" post will know that I have been questioning to what extent advanced risk measurement approaches and real-time data management technologies could have prevented the current crisis of confidence in the banking sector.

Could it for example have enabled SocGen to detect and even prevent its €5 billion of losses caused by a rogue trader dealing in European stock futures? Maybe not. But it appears that in a new post-MiFID world, with multiple MTFs springing up and all of them looking to compete with one another on speed of trading and cost, that market surveillance and risk management is becoming more of an issue.

Project Turquoise, the MTF set up by a consortium of investment banks, has announced that it will incorporate a "real-time" market surveillance system combining Progress Apama's Complex Event Processing (CEP) engine and Detica's market surveillance expertise.

Turquoise's post-trade market surveillance system will capture breaches of trading rules, detect market irregularities and develop enhanced trading execution analytics. But given the risk failings that have been highlighted at individual banks recently, one has to ask how effective these technologies are.

The UK's Financial Services Authority (FSA) also worked with Progress Apama and Detica on its "next-generation market surveillance platform", called Sabre II, which also uses CEP to process and analyse real-time event streams. According to reports, the FSA's old market surveillance system only had "end-of-week" capabilities as opposed to the ability to detect market irregularities in real time.

If MTFs and the FSA are relying on CEP for market-compliance issues, is this likely to filter down to the individual bank level where risk management and detection systems are found to be wanting?

Giles Nelson, director of technology, Progress Software, says it is seeing an increasing number of organisations using technology to provide an integrated real-time view of their position and risk analytic systems, which he anticipates will only increase as electronic trading volumes increase.

"With the increasing pace of electronic trading it's vital that a real-time view is available. The volatility in markets over this last week demonstrates the need for this."

BIC and IBAN confusion persists

With all the turmoil going on in the markets, the first official day of SEPA, 28 January 2008 when SEPA Credit Transfers became commercially available, may pass without much fanfare.

However, just to add to banks' woes, Compass Management Consulting estimates that despite there being a low number of non-STP cross-border payments in the eurozone, the 2% to 5% of non-STP payments that require manual intervention, are steadily eroding banks' trading profits.

Based on its analysis of European banks, Compass estimates that non-STP payments can reduce overall trading profits by up to 25%. To back up its claim, it cites its observation of a banking operation handling 300,000 transactions a day that generated 7,000 exceptions. "Despite the relatively low 2.3% exceptions rate, 270 full-time equivalent staff (FTEs) were required for manual processing of these payments, each of which costs between £25 to £40 to handle," said Richard Bissett, head of banking services at Compass.

Compass found that an average of 20% of all transactions fail requiring manual intervention. These 20% of transactions account for 80% of total back office costs. Bissett says 60% of exceptions could be fully automated. Yet, according to Compass' analysis, banks are only managing to automate 4% of exceptions.

Shedding some light on the results, Bissett said that the real question is why are there still non-STP payments when BICs and IBANs were introduced to try and increase the automated handling of cross-border payments in euro? He says corporates are still "totally confused" by BICs and IBANs and that of the 62,000 BICs, only 20,000 are connected (SWIFT network participants).

With SEPA placing further pressure on banks' payments processing margins, Compass anticipates that this will bring the challenge of exceptions processing into greater focus. It still doesn't resolve the rather confusing issue of BICs and IBANs though, and with cross-border payment volumes tipped to rise post-SEPA, one can only expect the number of exceptions to increase unless something is done to remedy this.

Thursday, January 24, 2008

A crisis of confidence

There is nothing like a whiff of a financial crisis, to inspire technology vendors to espouse such pearls of wisdom, which go something along the lines of, 'Well if they had implemented such and such a piece of software, that does so many millions of risk calculations per second, then they would have been able to calculate their real risk exposure much earlier on and perhaps prevented such a crisis.'

Some grid computing and data management vendors have been having a field day with the current crisis sweeping through the global credit markets. I for one remain sceptical as to whether technology can really overcome the financial markets' overwhelming desire to not only make money, but to behave like a pack of herd animals converging on a tasty corpse.

Although risk management and Basel II may be at the top of the agenda (well at least it is at the top of regulators' agenda), does any amount of technology and advanced risk measurement approaches really make a difference, or have recent events merely provided the stimulus that tipped over an already precarious house of cards? The apple was already rotten and recent events have only served to demonstrate how rotten it actually is.

Confidence in banks, particularly those that were considered to be financial heavyweights that could survive almost anything, including a nuclear holocaust, is at an all time low, and one has to ask have we only seen the beginning of the unsightly chinks in the banks' armour?

Then there was today's announcement by Société Générale that it had uncovered €5 billion of losses caused by a rogue trader dealing in European stock futures. Sound familiar? Nick Leeson of Barings Bank lost approximately £800 million in 1995 in rogue trades.

Commenting on the SocGen announcement, David Dearman a partner at accountants and business advisers, PKF had this to say:

"This fraud highlights the continuing lack of controls at some major financial institutions. The lessons of the Nick Leeson and Barings case in 1995 appear to have been forgotten by some. The scale of this clearly surpasses that fraud and is truly shocking."


According to Dearman, there was much "soul-searching" and review of procedures at financial institutions in the City of London following the Barings' incident, and procedures were tightened in a number of instances.

"I can only trust that the procedures adopted in the City a decade ago are working and being regularly reviewed, but there will undoubtedly be some very nervous senior people in the industry today," Dearman continues.


Interestingly, perhaps what both incidences highlight is the ability for someone with detailed knowledge of a bank's control systems to override those very systems put in place to prevent such an incident from occurring.

It reminds me of a comment one compliance consultant made not so long ago, that banks tend to focus more on external threats as opposed to internal threats. One has to ask though, would any amount of sophisticated risk management techniques and real-time data management technologies have uncovered or even been able to prevent someone using their knowledge of a company’s security systems to conceal fraudulent positions?

Tuesday, January 22, 2008

The 'superbanks' of tomorrow

In recent months with bank stocks plummeting and the aftershocks of the US credit crunch continuing to resound in global markets, no one would be surprised if the outlook for the banking sector going forward was dire.

Yet, while our faith and confidence in banks may be at an all-time low, McKinsey believes banks will double their profits and revenues by 2016.

It predicts that global banking revenues will grow, on average, by a not too unhealthy 7.5% a year from 2006 to 2016, compared with an average of 8% a year from 2000 to 2006 (and 12.6% from 2002 to 2006). Although revenues are expected to slow somewhat, McKinsey says they will still exceed current forecasts for GDP growth by more than one-half of a percentage point a year over the 10 years from 2006 to 2016.

"Consequently, we expect the industry to generate $5.7 trillion in revenues and $1.8 trillion in after-tax profits by 2016 —more than twice the levels at the end of 2006."


How can this be, you may ask with household names such as Citi having to grovel to Middle Eastern sovereign wealth funds to help balance their balance sheets after significant write-downs in the current sub-prime debacle.

Well it seems part of the reason for McKinsey's rather bullish predictions for the banking sector is the growth in demand for banking and financial services in emerging markets, which it says will contribute roughly half of the absolute growth in new banking revenues from 2006 to 2016, while North America and Western Europe will account for 25% and 20%, respectively.

Russia, says McKinsey will be one of the fastest-growing large markets in the next few years, alongside China. More importantly perhaps, India is predicted to overtake Central and Eastern Europe. Those segments that are likely to be profitable include retail banking and investment banking, trading and securities services, which McKinsey says will provide a larger relative share of bank revenues.

But perhaps the biggest driver that may support McKinsey's predictions is the prospect of more consolidation in the banking sector to create "superbanks".

"Over the next five years, we expect a new wave of consolidation to speed the emergence of 'superbanks,' with more than $500 billion in market capitalization," says McKinsey.


Today, global banking is the least concentrated industry says McKinsey with the top 20 banks accounting for less than 40% of its global market cap, compared with an average of 67% in other key industries. Interestingly, those banks that are in the Top 20 today, are not guaranteed to be the 'superbanks' of tomorrow. "Even the current top European and US banks aren’t guaranteed to achieve 'superbank' status with their existing portfolios," says McKinsey.

Outsourcing crunch time

Regular readers of this blog will know that I have regularly commented on the hype surrounding outsourcing. Outsourcing is definitely here to stay, but as firms' experiences of outsourcing have matured and some of the gloss has gone off outsourcing as being a cost-effective panacea for companies' woes, outsourcing entered the 'trough of disillusionment' for some firms.

Having said that, the latest quarterly stats from sourcing advisers, TPI, suggests that outsourcing is on the rise, particularly in Europe, which has now surpassed the US in terms of total number of contracts signed (220 valued at €32.7 billion) compared to 194 contracts signed in the US valued at €21.3 billion.

While in the past a significant portion of contracts signed were renewals of existing outsourcing business, according to TPI, in 2007, the annualised value of new contracts awarded in Europe was up almost 31% on 2006 levels, compared with an increase of 13% globally.

And it seems financial services firms are once again leading the way in the demand for outsourcing, representing more than 38% of the total value of outsourcing contracts signed. According to TPI, the worldwide market for Financial Service Operations (FSO) outsourcing has grown by 22.5% since 2003.

I think we have only seen the tip of the iceberg when it comes to outsourcing by financial service providers. A number of regulatory imperatives (Basel II, MiFID, SEPA) is placing significant demands on banks' back offices, and not all banks are well positioned to meet those demands in terms of their systems and investment capability.

Some difficult decisions have yet to be made by financial institutions regarding their back office processing, whether it is in the securities or payments business. Crunch time is rapidly approaching for them to decide what is strategic to their business and what they can outsource or white label.

Wednesday, January 16, 2008

Lunches, trains and automobiles

Are we on the brink of a recession? Well even if we aren't, it seems like the markets are talking themselves into one, and it seems I am not alone in thinking that the market is panicking itself into a recession. Christmas sales haven't been what they used to be for retailers (although I think far too much weight is put on analysts' expectations especially when supermarket giants like Tesco still manage to record a 3.1% rise in Christmas trading, even though it was below analysts' expectations of 4%), and based on December figures the UK housing market is at its worst since the recession of 1992.

But retail earnings and housing slumps aside, some say a true sign that we are in a recession has to be the demise or otherwise of the business lunch and the number of people taking taxis.

I was just discussing this over a business lunch today, which lasted for a couple of hours - always a good sign that the days of the two-hour business junket are far from over. And judging by the busy lunchtime crowd that was in the restaurant, businesses are not battening down the hatches quite yet.

So it is official, while consumer confidence may be ebbing, all important business confidence is hanging on by the skin of its teeth, and those that work in the markets say, despite the credit crunch, trading volumes have not declined.

I feel another round of outsourcing coming on. The credit crunch may not mark the end of the business lunch, not yet anyway, but will it prompt banks to more seriously consider what is core to their business and what it is not and outsource the non- value-added menial tasks to high volume processors that benefit from economies of scale?

Tuesday, January 15, 2008

Compliance tops the agenda

For those of you wanting to get a heads up on the post-MiFID environment, Basel II, the third Anti-Money Laundering Directive, what regulators may have in store for the hedge fund community or the next installment of 'MiFID-like' directives, Complinet is hosting its fifth annual Compliance Conference in London on the 6-7 February.

The conference program features some of the European Commission's and the FSA's leading lights who can fill banks in on the latest developments surrounding the MiFID Directive Level 3 (not so good news for those that thought MiFID had come and gone). The FSA's head of risk will happily share its vision of principles-based regulation and what it means in a post-MiFID environment, and why it is imposing so many fines for lack of compliance with Treating Customer Fairly breaches.

And if that wasn't enough to make any risk manager's head spin, there will also be sessions on how data protection laws and other regulatory requirements often result in competing and conflicting requirements (something I am particularly interested in). Do KYC requirements, for example, often conflict with firms' data protection obligations?

There will also be sessions on Basel II, the latest anti-money laundering edict handed down from on high, and leaping into the uncharted territory of principles-based regulation, which we know a number of financial service providers developed a distaste for in the run-up to MiFID's implementation.

Monday, January 14, 2008

Prudential - less than prudent with customer details

Prior to Christmas the UK's HM Revenue & Customs lost the personal details of millions of child benefit recipients, and the latest data management debacle by institutions that consumers entrust with their data is Prudential, which has been less than prudent with their wealthiest customers' personal records.

According to the latest reports, a box containing premium customer details, including cheques and other sensitive information, was found on a roadside near Reading Berskhire by a vehicle recovery driver.

Apparently the box fell to the side of the road when it was being transported from Prudential's offices in Reading to a "secure" facility in Essex. In this day and age with electronic data storage facilities, image scanning and remote backup of data available, it seems astonishing that personal customer information is still being transported in paper format in boxes.

Even if the box had not been lost on the side of the road, anyone transporting the information could have easily photocopied some of the sensitive documents and used them for fraudulent purposes.

It begs the question, why are government departments and financial service providers opting for the least expensive and less safe option when it comes to protecting customers' personal data? There are really no excuses for these organisations who we entrust with our personal information to be reliant on such antiquated systems when it comes to data storage and protection. What is it going to take for these organisations to take data protection more seriously?

Tuesday, December 04, 2007

Fraud from within

Judging by my last few posts, you are probably beginning to think that FinancialTech Insider has it in for anti-money laundering systems and the banks implementing them. Make no mistake, we do feel that banks have got the raw end of the deal with financial regulators and governments effectively forcing them to police every financial transactions on their watch.

It is no easy task and despite banks throwing millions at the latest and greatest AML solutions, can any bank really say they have got it well and truly 'sussed?' The regulatory burden is only increasing with the Third EU Money Laundering Directive due to be implemented in 2008.

And as recent events have demonstrated, preventing fraud and AML is not just about monitoring transactions and implementing technology. In fact Innovations Softwaretechnologie of Germany says that transaction monitoring should not only cover the threat of fraud being committed by an external perpetrator, but also employee conflicts of interest,insider trading and market abuse.

According to a poll by KPMG of more than 220 banks across more than 50 countries, 33% of banks are not satisfied with the effectiveness of their own transaction monitoring systems, and less than 25% have the capabilities to monitor the transactions and accounts of a single customer across multiple international borders.

Why then is so much of the onus for policing financial transactions on the banks, when banks do not have the adequate systems in place to meet these requirements, and the internal threat from their own employees is not being adequately addressed?

At a time when trust in banks and government departments is being eroded, isn't it time for regulators, governments and banks to engage in a more serious debate about the effectiveness of current approaches to transaction monitoring and money laundering, rather than adding more complexity to an already unworkable solution?

Wednesday, November 28, 2007

Making financial crime a priority

Well it seems the HM Revenue & Customs (HMRC) incident where millions of customers personal and financial details stored on an unencrypted CD went amiss, has opened a veritable can of worms.

My inbox is suddenly being inundated with emails questioning how well customer data is protected not just by government departments, but banks and other companies.

The HMRC incident prompted the British Bankers Association (BBA)to publish these rather terse words for law enforcement officers:

"Looking at the wider context in which this unacceptable lack of sensible data protection took place, it is clear that the Government has not yet accepted properly the case for making fraud and financial crime a priority for law enforcement in its own right," says the BBA.


Not only are government departments it seems letting the side down by not adhering to the strictest data protection principles, but the very same government that requires banks to spend millions on anti-fraud and money laundering measures, is apparently not even bothering to allocate sufficient resources to law enforcement to tackle both money laundering and fraud risks, says the BBA.

“It is quite extraordinary that the industry does so much on anti-money laundering, on fraud prevention and on identifying suspicious transactions, and yet this doesn’t feature among the priorities the police has been given by the Home Office.”


Those of you who read this blog regularly will know that we have been particularly vocal about the cost/benefit of banks investing millions in AML solutions, when there is a very clear lack of transparency as to the success of these systems in accurately identifying suspicious transactions, and the percentage of transactions that lead to successful prosecutions.

Not only are the banks unwilling to talk about how many suspicious transactions they are actually reporting (although we hear the number of Suspicious Activity Reports have increased exponentially as compliance officers are reporting everything to cover their backs), but it appears the due diligence of law enforcement officers does not match the time and money being invested by banks in generating SARs.

Not only that it appears government departments appear to be giving potential fraudsters a hand-up by failing to adequately protect consumers' personal details. Surely the government needs to be made as accountable as the banks?

Tuesday, November 27, 2007

Thwarting fraudsters

I have purposely avoided writing anything about the HM Revenue & Customs'(HMRC) data breach of millions of UK consumers personal and banking details, but I felt compelled to say something when I started seeing information security vendors leaping on the bandwagon.

While it may be true to say that "fraud is already firmly on the banking industry agenda," when information security vendors say that consumers should not lose sleep over the HM Revenue & Customs' debacle because banks have risk management systems in place, it does not really provide me with much comfort.

The fact remains that despite these systems, fraud and identity theft still occur on an ever increasing scale, and it is arguable whether banks' systems are adequate. Even if thieves cannot access a person's bank account directly, they could still use their name and address details to apply for a credit card or other forms of financing.

What is the most alarming thing about the HM Revenue & Customs data leak is that it reflects well entrenched practices within government departments of posting customer data on unencrypted CDs.

It strikes me as rather odd that on the one hand you have a government wanting ISP providers and banks to take more responsibility for protecting consumers' identity and personal details, but yet government departments which hold reams of information on millions of people, are not subject to the same levels of scrutiny or compliance.

According to Jeremy Smith, managing director of Jardine Lloyd Thompson’s Financial & Professional Risks division, the HMRC incident has prompted security experts to renew their request for the current law to be urgently reviewed for, unlike our American counterparts, the Data Protection Act does not currently compel companies to notify those affected by the loss of data.

Smith points to the almost £1 million fine levied by the FSA on the Nationwide Building Society for a laptop theft from an employee’s house. Yet, no such fines will be levied on government departments which do not face the same regulatory scrutiny as banks. Arguably however, as the government steps up its "Big Brother" campaign to collate as much information as possible on individuals, one has to seriously question the lack of government department accountability.

On the technology side, there has been so much focus on authenticating a customer's identity at the point of sale using chip or pin, but very little focus on securing the storage and transmission of customer data between government departments and banks that share this data and training employees to abide by the strictest codes when it comes to managing that data.

At this point, information security experts are going to proffer some kind of comment about the latest and greatest solutions that can help banks identify fraud before it occurs. One such comment in the wake of the HM Revenue & Customs' debacle was:

"By understanding customer behaviour across multiple payment channels in real time, banks will be able to identify irregular account activity that could potentially thwart fraudsters before they have even committed a crime.”


Sounds great in theory, but show me a bank that has the systems and business processes in place that they can accurately monitor and understand customer behaviour across multiple channels and product silos in real time. Even if such a bank exists I don't think they would be game to put their hand up for fear that they will be proven wrong.

The banking industry and government cannot afford to rest its laurels on the fact that banks have implemented a nice piece of software kit with bells and whistles, which is going to make everything alright. With banks, government departments and web sites collating unprecedented levels of personal information on consumers, is it any wonder that identity theft is on the rise. And no amount of banking software is going to change that.

Thursday, November 01, 2007

Don't forget to switch off the lights


"Have a green day," said BT Global Services CEO Francois Barrault as he introduced The Green Bank event at the Tate Modern in London yesterday. His remark is perhaps an indication of how far industry CEOs have come in embracing the environmental sustainability agenda.

After all, Barrault conceded when he first met environmental campaigner Al Gore, who proceeded to show him pictures of Arctic ice caps melting, he thought he was a little "crazy".

John Williams, head of group sustainable development at HSBC, which lays claim to being the world's first "carbon neutral" bank (whatever that means), said he was perceived initially as being somewhat of a "hippy", which is how the corporate world has always liked to portray those that express concern about business' impact on the environment.

One would have hoped that the so-called "Green Debate" had moved on from such redundant stereotypes, but it appears that the corporate world, while on the hand it is waking up to it environmental responsibilities, does not want to be associated too closely with the 'hippies' and 'tree huggers' who do not need a cost/benefit analysis, brand protection or new business opportunities to justify their passion for the environment.

So when a CEO of a major company says, "Have a green day" or HSBC says it is a "carbon-neutral" bank, what does that actually mean? There is no question that HSBC is a major investor in renewables, has project financing guidelines based on environmental principles and has constructed solar-powered buildings.

Yet they have also been accused of being one of the myriad number of banks that leave their office lights on all night at Canary Wharf, and they do not totally rule out providing project financing for environmental "dinosaurs" such as the coal industry.

So does being 'green mean saying one thing and doing another, or being 'green' part of the time and not for the rest of the time. There is no question that the industry has come a long way in terms of its support for "sustainability", but business and banking by its very nature contradicts a lot of sustainable principles.

After all banks are in the business of making money, and if it did not make business sense, win them customers or save them money, then they wouldn't 'green' their IT or use recycled paper, just for the sake of environmental sustainability.

At yesterday's event, HSBC and Morgan Stanley spoke about the dilemma of what to do about executives that need to travel. Both are looking at telepresence and the latest videoconferencing technologies as a way of reducing executive air travel, but I am dubious when banks say that for those carbon emissions they cannot reduce easily, they can merely offset it by buying carbon credits.

In that sense the "carbon-neutral" title is somewhat misleading as it appears to suggest that the bank has a zero carbon footprint, which is not entirely true.

A lot of yesterday's debate at the Tate Modern was spent showing graphs and theoretical proofs of concept around what is sustainability and what does it mean, when the reality of why banks and industry should be doing this was more succinctly put by the CIO of Morgan Stanley who said that if oil and commodity prices continue to rise, reducing energy consumption and their data centre footprint, was pretty much a 'no-brainer'.

A guy sitting next to me from Barclays Capital said he was a bit disappointed by yesterday's presentation. He wanted to hear what other banks were doing when it came to "greening" their IT and data centres, and thought the industry debate had moved on to more concrete tangibles rather than debating the vagaries of what sustainability means.

After all there are things firms can do now that will cut costs and save energy; turning office lights off, printing on both sides of the paper, using teleconferencing, virtualising servers, grid computing; without having to debate what sustainability means. That is just good business sense.

Yet while there certainly is an impetus amongst banks to sign up to being "green" for whatever reason, once they ascribe that label to themselves, it is not merely something that you can throw money or technology at and say you have done your bit.

"Being green" is an ongoing responsibility, after all if you are reducing the carbon footprint of your data centre, but then continuing to issue paper bank statements and faxes every day, forgetting to switch your office lights off or project financing major oil and coal projects, doesn't that mean companies are only being 'green' when it suits them?

Tuesday, October 30, 2007

Clients likely to challenge 'best execution'

As the 1 November MiFID deadline is almost upon us, my inbox is being inundated with vendors' last minute words of wisdom regarding the much talked about Markets in Financial Instruments Directive.

One has to marvel at the PR strategies of some companies - bombard journalists with as many emails as possible, even if it is the same information that they were propagating about MiFID a few months back. Let's repackage it and hope no one notices, a bit like some of the so-called 'MiFID ready' solutions out there.

What surprises me though is that for a regulation that is lacking in "prescriptive" detail, vendors seem to know more about what firms need to comply with MiFID than firms do themselves. Is there a danger of firms installing all this whiz bang technology, only to find they did not need half of it?

Having said that Atos Origin's survey of the market suggests that firms have actually spent 20% to 25% less on MiFID than they initially intended and have not implemented smart order routing technologies, as suggested, because they are still unsure that liquidity will be as fragmented as some have suggested.

Vendors are eager to dispel the perception that they are flooding the market with technology which is simply a repackaging of existing solutions with a MiFID label slapped on it.

Some of them are even forming alliances (The Open MiFID Alliance comprising Allen Systems Group and vendors like Sun Microsystems, SAS and Gissing)where they purport to have put aside their "single-vendor" approaches and opted for a more "synergistic" approach.

I have to say though I am sceptical of some vendors trying to cash in on MiFID and the confusion that still reigns in the marketplace. But it appears no amount of "best-of-breed" technology is going to prevent firms from being fined for non-compliance with MiFID.

Well at least that is the expectation of firms surveyed by Thomson IFR which indicated that all firms expect fines for non-compliance as early as Q1 of next year, and 90% expect more fines every following quarter.

Despite all the rhetoric about "best execution" and what it means and solutions for addressing it, almost 70% of firms surveyed expect the first client to challenge their “best execution” in the first quarter of next year. Firms are not even confident about their own MiFID implementations, let alone the technology underpinning it.

Despite all the consultant-speak about MiFID being an opportunity to differentiate, it appears a number of firms are throwing technology at the problem and hoping it satisfies the regulators, without carefully considering what their strategy should be in a post-MiFID environment.

Friday, October 26, 2007

SEPA - a case of industry mismanagement

Although they don't necessarily court publicity or boast about the innovative ways in which they are using technology, Nordic banks tend to have grasped the fundamentals of technology long before many other banks and do not approach it with the same level of fear or risk aversion.

That is why perhaps the Nordic payments infrastructure is considered to be 'light years' ahead of many other European states. It boasts a relatively efficient credit transfer system and the concept of "real time", which most other banks only pay lip service to, is enshrined in consumer internet payments which are credited same day. Float has also been reportedly done away with in domestic Norwegian transfers and internet banking uptake generally is much higher.

Some of these aspects are only now being considered on a European-wide scale as part of the Single Euro Payments Area, which in effect means European banks and their customers now have the opportunity to catch up with their Nordic counterparts, which have enjoyed these efficiencies for some time.

No surprises then that a lot of Nordic banks see SEPA as a step backwards for them. They already offer a relatively efficient cost-effective electronic payments infrastructure, which is linked in with value-added services such as e-invoicing.

I was having a discussion about SEPA via email with Bo Harald, ex e-banking guru for Nordea and now head of executive advisors at financial software provider, TietoEnator, which has helped Nordic banks build innovative e-invoicing solutions.

In his initial email he had this to say:

"The thing is we need to be rather forthright together with the ECB and the EU to get the banking community to move to new services. Having met people in London yesterday it did strike me how many still cling to the past(it has NEVER been a good business strategy) and try
to find reasons to delay starting reforms - only to have to do them later in gigantic panicky efforts without being properly prepared
."


My remark to him was that the industry's tendency to want to preserve the 'status quo' meant that the only form of innovation at times was that forced by regulation, and that SEPA was a good example of that.

His reply was that "SEPA had in fact been an issue of industry mismanagement - by resisting the credit/debit part instead of steering it and promoting e-invoicing instead, the banking industry and thus its customers will have to invest and pay close to €10 billion and revenues will go down. Instead he says they could have invested very little and saved €200 billion plus the cost for EU enterprises and corresponding earnings."

It appears that "fostering creativity in payment services" through the introduction of SEPA-wide payment related services such as e-invoicing, is going to be the difficult part for banks.

SEPA Direct Debits and Credit Transfers is a start, but as we have been hearing from corporates, they have yet to be convinced of the business case for implementing these new instruments and where are the additional optional or value-added services that everyone is saying banks need to provide in order to make up for revenues lost through SEPA's implementation?

Thursday, October 25, 2007

Project Turquoise gets its act together, or does it?

Well it seems after much speculation that it would not get off the ground, Project Turquoise, the multi-lateral trading facility announced by seven leading investment banks, has appointed a CEO and technology provider.

There were rumours that Project Turquoise may buy PLUS Markets, a London-based quote-driven electronic trading platform based on OMX technology in a reverse takeover. But after that deal fell through, it selected Cinnober Financial Technology, a Swedish company which also provides the technology for BOAT, the pre- and post-trade market data consortium, as its technology provider.

It has also finally appointed a CEO, Morgan Stanley managing director Eli Lederman. But in an interview with Reuters, Lederman said Project Turquoise's launch would be pushed back from November this year to next summer, giving NYSE Euronext, BNP Paribas and HSBC time to launch its SmartPool for trading so-called "dark" liquidity pools anonymously.*

The delayed launch of Project Turquoise also continues to stoke the rumour mill that it may still not manage to get off the ground.

A shorter time to market would have been preferable if Project Turquoise was to finally silence its critics and start competing with the likes of Chi-X, which is already capturing significant market share in trading of some major blue chip European stocks.

But with other MTFs gradually coming on line, it is unclear how long Chi-X will enjoy first mover advantage and what trading models or technologies are likely to gain the upper hand in the battle for liquidity.

It is reminiscent of the battle between American ECNs at the onset of the millennium, but look what happened to them. They consolidated and eventually got bought by the exchanges they competed with.

Are Chi-X, Project Turquoise and SmartPool destined for the same fate?

*PS For any of you who have ever wondered why liquidity pools are often referred to as being 'dark'. Well apparently, according to one knowledgeable insider, they are 'dark' because when you switch the lights on, there is nobody inside of them.

Tuesday, October 23, 2007

'Home-grown' software difficult to manage

A common tale one hears from financial software vendors is that banks are riddled with legacy systems, some dating back to the 70s, and that the code for those systems or applications has been lost forever because the person who developed it is no longer with the company or has filed it away in a drawer somewhere where no-one can find it.

With banks running so many IT systems as part of their daily operations, including the ones they have inherited from acquisitions, is it any wonder that they may not have a real grip on their IT environment? It is a bit like corporate treasurers saying they are not quite sure how many bank accounts they have globally - which in effect means cash could be sitting somewhere idle without being invested for maximum return or used more wisely.

With IT, the implications can be resounding. Not knowing how many IT systems, servers and applications a bank has running and their interdependencies with one another, particularly when new applications are installed, could have 'alarming' consequences in terms of rogue IT attacks and system downtime and failure.

This scenario has obviously played into the hands of vendors touting application dependency mapping and IT configuration tools, which essentially seek to provide a map or 'blueprint' of a firm's IT environment and its interdependencies so it can be more effectively managed.

Yet, according to one such provider, Managed Objects, a lot of application dependency mapping tools do not work well with "home-grown" or customised applications which banks have developed in-house.

Based on research commissioned by Managed Objects and conducted by Vanson Bourne, more than half of 100 UK IT managers and senior leaders in the retail banking, investment banking and insurance sectors, indicated that they run home-grown software, with 56% needing over six people and 38% needing more than 15 people to operate it.

What is concerning is that 57% estimated that software outages cost more than $10,000 per hour. And outages happen with regular frequency with almost 80% experiencing outages impacting the business in the past year. More than 20% had more than six outages in the same time frame.

Thirty-nine percent of banks surveyed by Vanson Bourne attributed 25% of outages to application changes, which let's face it, occur somewhat frequently in a banking software environment where the need to upgrade applications to support rising transaction volumes and to stay ahead of the competition, is an ongoing battle.

Banks are not going to retire some of this 'home-grown' software - too many applications rely on them and if it ain't broke why fix it. But it seems the challenge is integrating newer applications with these supposedly "complex" customised and home-grown applications.

Have software and integration vendors oversimplified the challenge of working with in-house software, and is encouraging firms to buy rather than build applications likely to have any impact, particularly as some banks will always see 'off-the-shelf' solutions as a leveler that stifles any so-called competitive advantage?

Wednesday, October 17, 2007

A PLUS for Project Turquoise

A week or two couldn't go by without some more news surrounding MiFID. And it seems that the latest is a revival in Project Turquoise's flagging fortunes. You know Project Turquoise, the multi-lateral trading facility announced by seven leading investment banks that has yet to get off the ground?

Well according to a report in Financial News, Project Turquoise looks like it may finally have 'lift off' with the announcement that it had moved to buy PLUS Markets, a London-based quote-driven electronic trading platform which trades more than 1,000 shares of largely small and mid cap stocks.

The deal has yet to be confirmed by either side but it would certainly give Project Turquoise the hand-up it needs as it still has not settled on a technology platform and has had well publicised difficulties finding a CEO.

Interestingly, PLUS Markets is installing a new trading platform, supplied by the Nordic Exchange Group, OMX, who Project Turquoise were also looking to purchase technology from. PLUS Markets new trading platform will support its "enlarged trading services offering under MiFID" and extend its share coverage to UK and EU liquid shares and some 7,500 securities.

Hacker 2.0

PR companies and consultants will go to any lengths it seems to raise the interest of us tired and cynical hacks. As I opened my email inbox this morning, two headlines leaped out at me (which I must say is pretty unusual as I generally find it hard to get excited about any press release that graces my inbox); "Hacking the Stock Market with Comsec," read the first one, and the second one was "The Hackers arms race 2.0," which sounds more like something that belongs on the front page of a tabloid newspaper.

The first pertained to an invitation from Comsec Consulting to come and see them "hack" into the world of online stock trading at the upcoming RSA Conference.

The Comsec presentation said that it would "review advanced analysis and hacking capabilities within the world of online stock trading – one of the most vulnerable sectors of online business, as well as demonstrating common weak security practices used by developers from an attacker's perspective, and an in-depth look into commonly used protocols and their vulnerabilities."


The other presentation at the same conference pertains to websites designed using good old "Web 2.0" technologies which are meant to provide a richer, more interactive internet experience, but allegedly at the expense of security says VeriSign who adds that the "complexity" of Web 2.0 websites means "traditional" security measures can no longer keep pace, leaving gaps for hackers to get in.

I am beginning to wonder if the IT security companies, hackers and PR companies are all in cahoots with one another?

Banks in hot water over AML

Still on my AML rant, it appears that Lloyds TSB is the latest bank to find itself in hot water under US legislation.

According to a report on Bob's Guide, Lloyds is alleged to have "knowingly assisted" Lycourgos Kyprianou, founder and former chairman of AremisSoft, in laundering approximately $500 million through his bank accounts. The Bank of Cyprus is also implicated in the allegations.

A Lloyds spokesperson stated there was no basis for the action by the US. But it does remind me of the debate we have been having on this blog over a period of months about the effectiveness of anti money-laundering measures and whether banks really know their customers or whether the solutions they are putting in place are merely to satisfy the regulators.

Well it seems US regulators are a rather difficult bunch to satisfy. Lloyds is not the first UK or European bank that has found itself in hot water. NatWest and Credit Lyonnais are the subject of lawsuits in the US that allege the banks channeled funds to organisations that raise money for Hamas, which is designated a terrorist organisation by the US, but not necessarily by other countries.

The lawsuits against the latter two banks were filed under the US's Anti-Terrorism Act, which says it is unlawful for any person or entity to provide "material support" to foreign terrorist organisations. The banks need to prove they did not knowingly channel funds and that the provision of "routine banking services" does not amount to "material support".

With reputational risk very much at the forefront and the heavy hand of regulators so eager to clamp down on any potential threat of money laundering (after all haven't some UK banks been fined under AML measures not for actually laundering money but for not having adequate measures to combat it in place?), the real question is not whether banks are "knowingly" participating in money laundering, but whether all the millions they have invested in combating AML is money well spent?

Even if there is a stray employee within a bank facilitating money laundering, what measures does the bank have in place to try and prevent that from occurring? It comes back to that age-old question, are banks spending so much time on 'ticking boxes' for regulators that they actually know relatively little about their customers?

Furthermore should the onus for 'policing' fraud and terrorist financing activities lie with the banks given that their raison d'être is to make money?

Monday, October 15, 2007

"Unusual" account activity?

I have been quite vocal about anti-money laundering (AML) measures put in place by banks to help combat fraud. Industry insiders, including those working for AML solution providers maintain that while banks are forced to put measures in place in order to avoid regulatory fines, no one can say with any certainty whether the millions being spent on AML and anti-fraud measures is actually working.

I alongside others have argued for a review of AML measures and legislation, which has not been forthcoming. All parties concerned appear to want to be seen to be doing something, even if it is not effective.

Recently, I experienced first hand the anti-fraud measures some banks have put in place. While travelling abroad to the US I found that I was unable to use my Maestro/Switch debit card facility to top up my pay-as-you-go telephone, although i was able to withdraw money from ATMs.

Upon my return to the UK still finding I had problems using the Maestro facility, I rung my bank upon which they informed me that they had identified some "unusual" activity on my bank account and had barred the Maestro facility.

The "unusual" activity turned out to be cash withdrawals I had made from ATMs in the US and a switch payment to my UK internet provider. According to the bank's anti-fraud department its "automated" anti-fraud system, which had just been updated, flagged the transactions based on the logic of how can someone be withdrawing money in the US while a Maestro payment on their card is being made in the UK?

Well the Maestro ISP payment comes out of my account every month and if they had bothered to check they would have seen a record of that, but as the anti-fraud officer I spoke to told me, automated anti-fraud solutions do not provide that level of detail, they merely flag things, which to them look unusual.

While I appreciate my bank's efforts in trying to combat card fraud, I do question the reliability of automated systems that flag everything without some form of manual verification of my transaction history and spending behaviour.

If my bank really knew their customer then they would have realised that I do make regular overseas trips and that the Maestro payment to my ISP is a regular payment made from my account.

Thursday, October 04, 2007

Banks enter uncharted territory

Well it is the end of yet another Sibos - an eventful or uneventful one depending on how you look at it. There has been the usual SWIFT speak - advancing critical dialogue, price reductions, rebates and a SWIFT that wants to get closer to its customers.

But as some of the journalists I spoke to this week have said, 'There has been very little meat' in terms of major announcements. OK the leading European banks have signed up to delivering SEPA- they are now "legally committed" as one person put it.

But take-up and migration to SEPA, particularly SEPA Direct Debits, still presents significant challenges, and there is a feeling that the regulators will need to do more to give SEPA a "nudge" to ensure it gets through these final yet all-important stages.

This Sibos will perhaps be best remembered for turning the tide when it comes to attendance - more corporates now attend SWIFT's annual user conference than investment managers, although those in attendance from the securities industry believe the debates around derivatives, the European clearing and settlement landscape and the future of the industry, were enlightening.

Yet, it is questionable whether the SWIFT community can truthfully say they 'gained momentum'? With the challenges around SEPA, automating securities and derivatives, the general confusion and uncertainty around whether banks can really play an enlarged role in the financial and the physical supply chain and provide value-added services customers want, it appears the industry is faltering somewhat.

The same applies to SWIFT in a way. Can it be everything to everybody - it is now even contemplating entering the insurance market - or has it bitten off more than it can chew, particularly given that it is talking about extending SWIFT connectivity to mid-tier corporates.

That was not in the original game plan, at least not that based on former SWIFT CEO Leonard Schrank's vision, which only saw SWIFT corporate connectivity as an option for the Fortune 100 companies.

His incumbent Lazaro Campos appears to have a slightly different agenda, which is likely to see SWIFT enter uncharted territory, just as the banks are finding themselves moving into traditionally non-bank areas (AP automation, e-invoicing, logistics). And like the banks, SWIFT is likely to enjoy mixed success.

Target2 Securities is not going to go away

Having opined at length about corporates and payments at this year's Sibos conference in Boston, I thought it was time to focus on some of the securities issues being raised at this year's event.

Despite there being negligible representation at the conference from investment managers, some of the vendors on the exhibition floor that sell in the securities services space, feel that the securities sessions, particularly those on derivatives processing and the future of the industry have encouraged a high level of debate.

Well all you investment managers that did not come to Boston, you have apparently missed out on a scintillating debate. One debate that continues to rage at this year's Sibos is Target2 for Securities (T2S) which saw Jean-Michel Godeffroy, director-general, payment systems and market infrastructure, European Central Bank, nervously hovering around Euroclear's stand last year at Sibos in Sydney.

The debate around T2S this year does not appear to have really moved on, with the ICSDs Euroclear and Clearstream still asking for further clarification around the ECB's proposal for settling securities in central bank money using its existing Target 2 system.

Euroclear was obviously hoping that its Single Settlement Engine encompassing five markets would be enough to appease the regulators, and everyone else including agent banks and national CSDs were probably hoping that T2S would just go away.

Well, that doesn't look likely it seems and national CSDs and local agent banks are contemplating what the future holds for them if T2S goes ahead.

If T2S is implemented, there will be clear winners and losers," said Pierre Slechten, CEO, Euroclear France. "The implementation of T2S will lead to further consolidation of CSDs in Europe and cause us to readdress our strategy in terms of moving up the value chain in custody."


As T2s proposes to replace the settlement engines of existing CSDs with a joint settlement engine, there was some suggestion that local CSDs and agent banks could team up to deliver new business services. "T2S relies on CSDs so CSDs will not disappear," said one speaker.

Katja Rosenkranz, member of the executive board, business strategy, Clearstream, said that those CSDs and agent banks that did not change their business models were likely to end up out of business.

Despite calls for the Eurosystem to join forces with other market harmonization initiatives such as Euroclear's SSE, Rozenkranz said T2S was the only solution that allowed for integrated settlement in central bank money. However, Slechten of Euroclear suggested there was likely to be some overlap with Euroclear's Settlement of Euronext-zone Securities initiative.

"I would be surprised if the T2S model does not end up looking like the model that we have developed for ESES. It is not sharing a platform, but it is sharing a view in terms of harmonisation."