I received this rather intriguing email from Eurofinance, which organises conferences for corporate treasurers, regarding a new board game they are going to unleash at Eurofinance Miami 2008.
Called, 'Cash Flow at Risk', Eurofinance designed the game to teach treasurers how to come to grips with the cash flow, credit and liquidity uncertainties ahead. I do wonder though if they should be targeting it more at the banks, given that it was them that seemed to lose their way.
Apparently, HSBC uses the board game as part of its corporate training, although one wonders if a board game, let alone a major credit crunch, is really going to teach banks anything about risk.
You may think I am being a little harsh, but the other day a risk management consultant told me he had started a training company as a sideline for his consultancy business, as selling risk to banks was a bit of a difficult sell. No bank wanted to really think about risk too much as it might stem their financially motivated creative urges.
The board game requires participants to answer economic questions in order to progress, but one has a feeling for some participants it would be a case of "Do Not Pass Go, Do Not Collect $200".
Can a board game though really teach treasurers about the "dangers ahead"? Is a simple toss of the dice and answering a few economic questions going to resonate with financial managers sitting in boardrooms across the country, the very same managers who in the real world, and not one confined to a board game, perhaps saw the warning signs but chose to ignore them?
Friday, February 29, 2008
Thursday, February 21, 2008
What went wrong at SocGen?
Well, the SocGen saga continues, with the commercial and investment bank reportedly publishing a report in French detailing how the trader Jerome Kerviel managed to evade controls.
Following publication of the report, IBM, the latest vendor to jump on the What Went Wrong at SocGen bandwagon, sent out an email reiterating the question everyone has been asking: How can you manipulate tens of billions unnoticed?
As I do not read French I am going to have to rely on IBM's interpretation of SocGen's interim internal investigation report, which reportedly claims that Kerviel's "position keeping and risk systems were unable to report such a large exposure because they [failed] to capture distant forward, incomplete and modified trades, and they were known to function improperly and be prone to recurrent errors."
An IBM spokesperson expressed amazement that a sophisticated organization was not capable of managing and properly reporting such simple transactions as stock future purchases, on the account that they were following unusual trading patterns (distant forward dates, multiple modifications, cancellations and transfers.)
Risk consultants from IBM Business Consulting Services outlined some of the major causes of large trading losses and stated that the "quality, coherence, and integration of position keeping systems," was crucial in counteracting some of these causes. "Effective position keeping" it said could also address employees trying to conceal losses and that "oversight mechanisms" which integrated monitoring, governance, and compliance requirements into a "holistic, focused, and practical framework," needed to be put in place.
Arguably however, there is only so much technology can do, and at some point a human needs to intervene or manage the process in order to prevent people who are clever enough from fooling or overriding internal risk control procedures and systems.
This is borne out by an independent report, which reportedly concluded that while risk control procedures were followed, "compliance officers rarely went beyond routine checks and did not inform managers of anomalies." According to the independent report, 75 warning signs on the activities of rogue trader Jerome Kerviel, were overlooked.
Following publication of the report, IBM, the latest vendor to jump on the What Went Wrong at SocGen bandwagon, sent out an email reiterating the question everyone has been asking: How can you manipulate tens of billions unnoticed?
As I do not read French I am going to have to rely on IBM's interpretation of SocGen's interim internal investigation report, which reportedly claims that Kerviel's "position keeping and risk systems were unable to report such a large exposure because they [failed] to capture distant forward, incomplete and modified trades, and they were known to function improperly and be prone to recurrent errors."
An IBM spokesperson expressed amazement that a sophisticated organization was not capable of managing and properly reporting such simple transactions as stock future purchases, on the account that they were following unusual trading patterns (distant forward dates, multiple modifications, cancellations and transfers.)
Risk consultants from IBM Business Consulting Services outlined some of the major causes of large trading losses and stated that the "quality, coherence, and integration of position keeping systems," was crucial in counteracting some of these causes. "Effective position keeping" it said could also address employees trying to conceal losses and that "oversight mechanisms" which integrated monitoring, governance, and compliance requirements into a "holistic, focused, and practical framework," needed to be put in place.
Arguably however, there is only so much technology can do, and at some point a human needs to intervene or manage the process in order to prevent people who are clever enough from fooling or overriding internal risk control procedures and systems.
This is borne out by an independent report, which reportedly concluded that while risk control procedures were followed, "compliance officers rarely went beyond routine checks and did not inform managers of anomalies." According to the independent report, 75 warning signs on the activities of rogue trader Jerome Kerviel, were overlooked.
Who will buy?
It is no secret that Larry Ellison, Oracle's CEO is hell bent on world domination, and the other day I had the pleasure of seeing just how determined the man is to provide the complete software stack covering almost every permutation of financial services.
Over lunch an Oracle exec presented me with a 'place mat' - which I proceeded to eat my lunch on - demonstrating Oracle/i-flex solutions' banking footprint across retail, commercial and private wealth management.
With no fewer than 38 acquisitions under his belt, in the next issue of financial-i magazine, we look at the ramifications of Oracle's 'stack' approach for financial service providers.
Critics say that IBM tried it in the 1970s but failed. It is a question of who will buy, and of course with any software vendor that is so acquisitive in nature, customers are always going to be concerned about how well integrated its solutions are. Oracle's Fusion Middleware is an effort to pull the applications together, and the Oracle execs I met with were insistent that any company acquired by Oracle soon becomes part of the fold.
When it comes to Oracle/i-flex's existing banking footprint, most of the boxes on the place mat representing the customer experience, product and transaction processing, master data management, corporate admin, compliance, risk-based monitoring, analytics platforms and enterprise technology, were greyed out, meaning that Oracle already occupied that space.
The executive indicated that the white boxes were where Oracle would make its next acquisitive strike; in areas such as trade processing, securities trading, derivatives pricing, Lock Box, custody and structured derivatives.
Interestingly, Ellison has deep pockets and has financed acquisitions without having to resort to injections of private equity capital. The latest target is BEA Systems, which Oracle appears to be acquiring for its capital markets customer base.
Any guesses where Ellison is likely to strike next? But it seems not all banks are buying the stack approach. No bank is going to want to lock themselves into a single vendor, although the pace with which Oracle is acquiring companies they may be forced to. Additionally, some of the bigger banks still tend to favour building proprietary solutions in-house rather than buying something off-the-shelf.
Over lunch an Oracle exec presented me with a 'place mat' - which I proceeded to eat my lunch on - demonstrating Oracle/i-flex solutions' banking footprint across retail, commercial and private wealth management.
With no fewer than 38 acquisitions under his belt, in the next issue of financial-i magazine, we look at the ramifications of Oracle's 'stack' approach for financial service providers.
Critics say that IBM tried it in the 1970s but failed. It is a question of who will buy, and of course with any software vendor that is so acquisitive in nature, customers are always going to be concerned about how well integrated its solutions are. Oracle's Fusion Middleware is an effort to pull the applications together, and the Oracle execs I met with were insistent that any company acquired by Oracle soon becomes part of the fold.
When it comes to Oracle/i-flex's existing banking footprint, most of the boxes on the place mat representing the customer experience, product and transaction processing, master data management, corporate admin, compliance, risk-based monitoring, analytics platforms and enterprise technology, were greyed out, meaning that Oracle already occupied that space.
The executive indicated that the white boxes were where Oracle would make its next acquisitive strike; in areas such as trade processing, securities trading, derivatives pricing, Lock Box, custody and structured derivatives.
Interestingly, Ellison has deep pockets and has financed acquisitions without having to resort to injections of private equity capital. The latest target is BEA Systems, which Oracle appears to be acquiring for its capital markets customer base.
Any guesses where Ellison is likely to strike next? But it seems not all banks are buying the stack approach. No bank is going to want to lock themselves into a single vendor, although the pace with which Oracle is acquiring companies they may be forced to. Additionally, some of the bigger banks still tend to favour building proprietary solutions in-house rather than buying something off-the-shelf.
Wednesday, February 20, 2008
Sovereign funds and banks
Once the target of various takeover rumours, Barclays now appears to be setting its sights on filling the gap left by the US investment banks that have suffered billions in write downs associated with subprime losses.
Interestingly, a question I have been asking in recent weeks, is what would have happened if sovereign wealth funds (SWFs) from Singapore and Kuwait had not bailed out some of the American banks eager to replenish their liquidity following such massive write downs?
The answers have been varied, but the bail outs themselves signify a new world order that is emerging, or as McKinsey likes to refer to the sovereign wealth funds, they are new 'power brokers' alongside hedge funds and private equity.
In fact, estimates suggest that sovereign wealth funds, while they may have considerable sums to invest, are not as big as say the Top 10 asset managers who are valued at $13.4 trillion, followed by the Top 10 central banks with reserves worth $4.4 trillion, the Top 10 pension funds valued at $2.9 trillion, and the Top 10 SWFs valued at $2.3 trillion.
But regardless of where SWFs sit in the financial pecking order, the sentiment seems to be that without the investments from Kuwait Investment Authority, Temasek Holdings and other SWFs, that the major US banks would have been forced to consolidate.
Interestingly, a question I have been asking in recent weeks, is what would have happened if sovereign wealth funds (SWFs) from Singapore and Kuwait had not bailed out some of the American banks eager to replenish their liquidity following such massive write downs?
The answers have been varied, but the bail outs themselves signify a new world order that is emerging, or as McKinsey likes to refer to the sovereign wealth funds, they are new 'power brokers' alongside hedge funds and private equity.
In fact, estimates suggest that sovereign wealth funds, while they may have considerable sums to invest, are not as big as say the Top 10 asset managers who are valued at $13.4 trillion, followed by the Top 10 central banks with reserves worth $4.4 trillion, the Top 10 pension funds valued at $2.9 trillion, and the Top 10 SWFs valued at $2.3 trillion.
But regardless of where SWFs sit in the financial pecking order, the sentiment seems to be that without the investments from Kuwait Investment Authority, Temasek Holdings and other SWFs, that the major US banks would have been forced to consolidate.
Thursday, February 14, 2008
Why settle for less, say Deloitte
After the initial exuberance had died down, most companies that had embarked on major IT or business process outsourcing projects discovered that there were 'hidden costs' in outsourcing to a third party provider.
As time and experience of outsourcing wore on, companies realised it was not simply a case of outsourcing a process to a third party and watching the cost savings pour in. The outsourcing process itself needed to be managed, monitored and governed, which entailed costs in and of itself.
Well Deloitte has just published some interesting findings on outsourcing based on its survey of 300 executives involved in outsourcing worldwide. More than 80% of respondents to its survey indicated a return on their investment of more than 25%.
However, while 70% said they were satisfied or very satisfied with their outsourcing. 39% said they had terminated at least one contract, and 50% of those that reported dissatisfaction with outsourcing had brought the process back in-house. In the first year of the contract, 61% of firms also indicated that they had "escalated problems" to senior management.
Therein perhaps lies the greatest challenge for both outsourcers and the firms that employ them, demonstrating not only one-off process improvements, but ongoing improvements on a continuous basis that satisfies customers' expectations.
As Deloitte's findings bear out, firms that outsource while financially gratified, would like to see a lot more benefits stem from the arrangement in terms of access to new ideas and innovation and better quality communications.
More than 30% wished they had spent more time on evaluating vendors before signing contracts, and if they had their time over again, almost 50% said they would have better defined service levels in line with their business goals, which just goes to show that a lot of firms have rushed into outsourcing mesmerised by the potential cost savings, without considering the processes, workflow and governance that needs to be put in place to ensure a better outsourcing experience.
So those businesses thinking that outsourcing or offshoring may be the solution to all their problems, particularly in an economic downturn when reducing costs is paramount, think again. Outsourcing is not a panacea and often entails 'hidden costs' which need to be considered in the overall cost/benefit analysis.
Martyn Hart, chairman of the UK National Outsourcing Association, says we could see the nature of outsourcing deals change in light of a recession. "In the past couple of years the ‘mega-deal’ has largely been consigned to the outsourcing scrap heap, in favour of multi-shoring and choosing separate suppliers for each process. Organisations will have to balance how to do this in the most cost effective manner," he says.
With mega-outsourcing deals a thing of the past, fixed price contracts are also likely to be abandoned for a more utility-based approach based on cost per unit.
As time and experience of outsourcing wore on, companies realised it was not simply a case of outsourcing a process to a third party and watching the cost savings pour in. The outsourcing process itself needed to be managed, monitored and governed, which entailed costs in and of itself.
Well Deloitte has just published some interesting findings on outsourcing based on its survey of 300 executives involved in outsourcing worldwide. More than 80% of respondents to its survey indicated a return on their investment of more than 25%.
However, while 70% said they were satisfied or very satisfied with their outsourcing. 39% said they had terminated at least one contract, and 50% of those that reported dissatisfaction with outsourcing had brought the process back in-house. In the first year of the contract, 61% of firms also indicated that they had "escalated problems" to senior management.
Therein perhaps lies the greatest challenge for both outsourcers and the firms that employ them, demonstrating not only one-off process improvements, but ongoing improvements on a continuous basis that satisfies customers' expectations.
As Deloitte's findings bear out, firms that outsource while financially gratified, would like to see a lot more benefits stem from the arrangement in terms of access to new ideas and innovation and better quality communications.
More than 30% wished they had spent more time on evaluating vendors before signing contracts, and if they had their time over again, almost 50% said they would have better defined service levels in line with their business goals, which just goes to show that a lot of firms have rushed into outsourcing mesmerised by the potential cost savings, without considering the processes, workflow and governance that needs to be put in place to ensure a better outsourcing experience.
So those businesses thinking that outsourcing or offshoring may be the solution to all their problems, particularly in an economic downturn when reducing costs is paramount, think again. Outsourcing is not a panacea and often entails 'hidden costs' which need to be considered in the overall cost/benefit analysis.
Martyn Hart, chairman of the UK National Outsourcing Association, says we could see the nature of outsourcing deals change in light of a recession. "In the past couple of years the ‘mega-deal’ has largely been consigned to the outsourcing scrap heap, in favour of multi-shoring and choosing separate suppliers for each process. Organisations will have to balance how to do this in the most cost effective manner," he says.
With mega-outsourcing deals a thing of the past, fixed price contracts are also likely to be abandoned for a more utility-based approach based on cost per unit.
Wednesday, February 06, 2008
Still miffed by MiFID?
I stole the title for this post from a panel discussion at Complinet's Compliance Conference in London today.
Judging by the number of people in the room (it was half full) they may not be that miffed about MiFID, or perhaps as most of the audience were risk and compliance officers, having to comply with non-prescriptive regulations is par for course.
Admittedly I walked in halfway through the debate, but judging by questions asked by the audience, it would appear that the Financial Service Authority's (FSA) principles-based approach to regulation, including MiFID, is causing consternation amongst risk and compliance officers, who would prefer a more prescriptive rules-based approach.
One compliance consultant chipped said that if firms went out and said what they think the rules mean (as they pertain to MiFID, then that would create a "stake in the ground," which is the safe way to develop compliance in a principles-based world.
Deborah Sabalot, a regulatory consultant, begged to differ however. She reminded the gathered risk, compliance and audit staff that the great thing about MiFID is that it was not non-prescriptive - in other words it gave firms the flexibility to design their own systems instead of being locked into something that was not of their making.
Still it didn't sound like that was what compliance officers wanted to hear. It seemed to be more a case of give us a set of rules we need to comply with and we can work with that, rather than making it up as we go along.
That may be the view of MiFID across the board, however, in the front office where the trading that MiFID regulates is executed, some firms clearly see MiFID as an opportunity to set their own benchmarks particularly around aspects of the regulation such as best execution.
However, for those that prefer the certainty of a prescriptive rules-based world, some form of best practice appears to be emerging, albeit slowly. Although it may take 12 to 18 months before firms' application of best execution under MiFID beds down, one spokesperson from UBS investment bank said any firm that takes a simplistic approach to execution by executing all of its trades on a single venue, are likely to find themselves under regulatory scrutiny.
That is pretty much a 'no brainer,' but other investment bankers raised concerns about additional taping requirements from CESR and the FSA and the extension of MiFID to commodities.
Lyndon Nelson, head of risk at the FSA, conceded it had been a difficult time for the organisation, particularly in view of the Northern Rock affair which it has received considerable flack over. Non-believers of a principles-based approach to regulation are likely to say that Northern Rock highlights the pitfalls of a principles-based approach to regulation.
However, Nelson said the FSA intended to stick to its non-prescriptive guns, albeit gaining some valuable lessons along the way from the Northern Rock Affair, and where requested, he said the FSA would provide market guidance by publishing more information gleaned from its risk assessment of firms, which could then be used by their peers to benchmark themselves against.
Judging by the number of people in the room (it was half full) they may not be that miffed about MiFID, or perhaps as most of the audience were risk and compliance officers, having to comply with non-prescriptive regulations is par for course.
Admittedly I walked in halfway through the debate, but judging by questions asked by the audience, it would appear that the Financial Service Authority's (FSA) principles-based approach to regulation, including MiFID, is causing consternation amongst risk and compliance officers, who would prefer a more prescriptive rules-based approach.
One compliance consultant chipped said that if firms went out and said what they think the rules mean (as they pertain to MiFID, then that would create a "stake in the ground," which is the safe way to develop compliance in a principles-based world.
Deborah Sabalot, a regulatory consultant, begged to differ however. She reminded the gathered risk, compliance and audit staff that the great thing about MiFID is that it was not non-prescriptive - in other words it gave firms the flexibility to design their own systems instead of being locked into something that was not of their making.
Still it didn't sound like that was what compliance officers wanted to hear. It seemed to be more a case of give us a set of rules we need to comply with and we can work with that, rather than making it up as we go along.
That may be the view of MiFID across the board, however, in the front office where the trading that MiFID regulates is executed, some firms clearly see MiFID as an opportunity to set their own benchmarks particularly around aspects of the regulation such as best execution.
However, for those that prefer the certainty of a prescriptive rules-based world, some form of best practice appears to be emerging, albeit slowly. Although it may take 12 to 18 months before firms' application of best execution under MiFID beds down, one spokesperson from UBS investment bank said any firm that takes a simplistic approach to execution by executing all of its trades on a single venue, are likely to find themselves under regulatory scrutiny.
That is pretty much a 'no brainer,' but other investment bankers raised concerns about additional taping requirements from CESR and the FSA and the extension of MiFID to commodities.
Lyndon Nelson, head of risk at the FSA, conceded it had been a difficult time for the organisation, particularly in view of the Northern Rock affair which it has received considerable flack over. Non-believers of a principles-based approach to regulation are likely to say that Northern Rock highlights the pitfalls of a principles-based approach to regulation.
However, Nelson said the FSA intended to stick to its non-prescriptive guns, albeit gaining some valuable lessons along the way from the Northern Rock Affair, and where requested, he said the FSA would provide market guidance by publishing more information gleaned from its risk assessment of firms, which could then be used by their peers to benchmark themselves against.
Tuesday, February 05, 2008
A new world order
Oh how the mighty have fallen. According to a Bloomberg report, Chinese banks have toppled Citi from the top of the league tables based on market value.
Citi, which had long occupied the top position based on market cap, has been superseded by Industrial & Commercial Bank of China (ICBC), China Construction Bank and Bank of China. The three biggest Chinese banks are valued at $608 billion, says Bloomberg, compared to $496 billion for Bank of America, JPMorgan Chase and Citi.
ICBC leads the tables with a market value of $277 billion, $82 billion more than Bank of America, which is in second place, followed by HSBC in third place ahead of China Construction Bank and Wells Fargo, according to Bloomberg data. Citi is now in seventh position. Yet, it was only five years ago that 13 American banks featured in the top 20 banks by market cap.
Citi, which had long occupied the top position based on market cap, has been superseded by Industrial & Commercial Bank of China (ICBC), China Construction Bank and Bank of China. The three biggest Chinese banks are valued at $608 billion, says Bloomberg, compared to $496 billion for Bank of America, JPMorgan Chase and Citi.
ICBC leads the tables with a market value of $277 billion, $82 billion more than Bank of America, which is in second place, followed by HSBC in third place ahead of China Construction Bank and Wells Fargo, according to Bloomberg data. Citi is now in seventh position. Yet, it was only five years ago that 13 American banks featured in the top 20 banks by market cap.
Wednesday, January 30, 2008
Fragmentation is not a dirty word
In the run up to the implementation of MiFID there was considerable 'umming' and 'aahing' about the impact the relaxation of the 'concentration rule' would have on the proliferation of trading venues and what that would mean in terms of fragmenting liquidity in Europe.
Those that were keen to see the status quo preserved in terms of liquidity residing largely with the national exchanges, painted a confusing picture of multiple trading venues springing up and the challenges of having to connect to all of these venues in order to demonstrate best execution.
Well it seems that debate has been quashed and smart order routing systems are helping "re-aggregate" liquidity.
"Fragmentation is good," said George Andreadis, head of AES, liquidity strategy, Europe, Credit Suisse at Finexpo in London. He then went on to cite a long list of reasons as to why it was good; less cost, lower latency trading, and attracting more liquidity into this space.
While Chi-X Europe may have been the only game in town, with its smarter, faster, cheaper model, Andreadis highlighted a whole host of planned MTFs looming on the horizon, including SmartPool, scheduled to launch in Q2 2008, Project Turquoise, and US "dark liquidity pools" such as BATS Trading and Pipeline, which are contemplating whether to launch this side of the pond.
It appears to be a very crowded and fragmented trading landscape emerging in Europe, mirroring what has already occurred in the US. Yet, Andreadis said that smart order routing technologies made it easier to determine where liquidity resided in 'dark pools'.
His mantra seemed to be that dark liquidity pools and MTFs were here to stay and that traders looking to demonstrate best execution ignored them at their peril. But the key to success in a market where liquidity is fragmented is the smartness of your order routing systems. "There is dumb order routing, smart order routing and very smart order routing," joked Andreadis.
Those that were keen to see the status quo preserved in terms of liquidity residing largely with the national exchanges, painted a confusing picture of multiple trading venues springing up and the challenges of having to connect to all of these venues in order to demonstrate best execution.
Well it seems that debate has been quashed and smart order routing systems are helping "re-aggregate" liquidity.
"Fragmentation is good," said George Andreadis, head of AES, liquidity strategy, Europe, Credit Suisse at Finexpo in London. He then went on to cite a long list of reasons as to why it was good; less cost, lower latency trading, and attracting more liquidity into this space.
While Chi-X Europe may have been the only game in town, with its smarter, faster, cheaper model, Andreadis highlighted a whole host of planned MTFs looming on the horizon, including SmartPool, scheduled to launch in Q2 2008, Project Turquoise, and US "dark liquidity pools" such as BATS Trading and Pipeline, which are contemplating whether to launch this side of the pond.
It appears to be a very crowded and fragmented trading landscape emerging in Europe, mirroring what has already occurred in the US. Yet, Andreadis said that smart order routing technologies made it easier to determine where liquidity resided in 'dark pools'.
His mantra seemed to be that dark liquidity pools and MTFs were here to stay and that traders looking to demonstrate best execution ignored them at their peril. But the key to success in a market where liquidity is fragmented is the smartness of your order routing systems. "There is dumb order routing, smart order routing and very smart order routing," joked Andreadis.
Project Turquoise gives it the hard sell
There was standing room only in the auditorium at the annual Finexpo event in London for the session on Project Turquoise presented by the MTF's CEO Eli Lederman.
After much fanfare and very little substance since the group of seven investment banks announced Project Turquoise back in 2006, Lederman seemed eager to dispel the notion that Turquoise was the mythical concoction of a bunch of investment bankers, rattling their sabres in the hope that the London Stock Exchange and others would reduce trading prices.
Well Project Turquoise has still not gone live, although Lederman was adamant that preparations for the launch date in September 2008 were well underway and that he was confident Turquoise would attract liquidity from day one. "We will have a lot of members, it is going to attract liquidity," Lederman kept repeating over and over.
And if that is not enough to convince those sceptics who are still doubtful as to whether Turquoise will get off the ground, Lederman was eager to stress that it had secured office premises. "We don't have marble steps or vaulted ceilings, but this is a modern exchange," he said.
Project Turquoise has chosen Swedish technology provider Cinnober (they also built Project Boat)to build its trading platform and Progress Apama is providing the CEP engine for the MTF's market surveillance system. But Lederman was short on the details regarding the trading platform. All he would say is that it will be an "integrated transparent order book with a dark pool."
It seems that the launch date for Project Turquoise may also be a moving target, as Lederman said that it was not focused on the date alone and that it was keen to implement a trading platform that was not a "monolithic purpose built system."
Yet, despite Lederman's efforts to reassure the market that Project Turquoise is "moving full steam ahead," anyone who has observed the Project Turquoise "showboat" for the past couple of years will probably be inclined to say, the proof is in the pudding. And after talking it up so much, almost to the point of evangelizing, Lederman better hope the pudding is worth eating.
After much fanfare and very little substance since the group of seven investment banks announced Project Turquoise back in 2006, Lederman seemed eager to dispel the notion that Turquoise was the mythical concoction of a bunch of investment bankers, rattling their sabres in the hope that the London Stock Exchange and others would reduce trading prices.
Well Project Turquoise has still not gone live, although Lederman was adamant that preparations for the launch date in September 2008 were well underway and that he was confident Turquoise would attract liquidity from day one. "We will have a lot of members, it is going to attract liquidity," Lederman kept repeating over and over.
And if that is not enough to convince those sceptics who are still doubtful as to whether Turquoise will get off the ground, Lederman was eager to stress that it had secured office premises. "We don't have marble steps or vaulted ceilings, but this is a modern exchange," he said.
Project Turquoise has chosen Swedish technology provider Cinnober (they also built Project Boat)to build its trading platform and Progress Apama is providing the CEP engine for the MTF's market surveillance system. But Lederman was short on the details regarding the trading platform. All he would say is that it will be an "integrated transparent order book with a dark pool."
It seems that the launch date for Project Turquoise may also be a moving target, as Lederman said that it was not focused on the date alone and that it was keen to implement a trading platform that was not a "monolithic purpose built system."
Yet, despite Lederman's efforts to reassure the market that Project Turquoise is "moving full steam ahead," anyone who has observed the Project Turquoise "showboat" for the past couple of years will probably be inclined to say, the proof is in the pudding. And after talking it up so much, almost to the point of evangelizing, Lederman better hope the pudding is worth eating.
Friday, January 25, 2008
Real-time volatility
Those of you who read my "Crisis of Confidence" post will know that I have been questioning to what extent advanced risk measurement approaches and real-time data management technologies could have prevented the current crisis of confidence in the banking sector.
Could it for example have enabled SocGen to detect and even prevent its €5 billion of losses caused by a rogue trader dealing in European stock futures? Maybe not. But it appears that in a new post-MiFID world, with multiple MTFs springing up and all of them looking to compete with one another on speed of trading and cost, that market surveillance and risk management is becoming more of an issue.
Project Turquoise, the MTF set up by a consortium of investment banks, has announced that it will incorporate a "real-time" market surveillance system combining Progress Apama's Complex Event Processing (CEP) engine and Detica's market surveillance expertise.
Turquoise's post-trade market surveillance system will capture breaches of trading rules, detect market irregularities and develop enhanced trading execution analytics. But given the risk failings that have been highlighted at individual banks recently, one has to ask how effective these technologies are.
The UK's Financial Services Authority (FSA) also worked with Progress Apama and Detica on its "next-generation market surveillance platform", called Sabre II, which also uses CEP to process and analyse real-time event streams. According to reports, the FSA's old market surveillance system only had "end-of-week" capabilities as opposed to the ability to detect market irregularities in real time.
If MTFs and the FSA are relying on CEP for market-compliance issues, is this likely to filter down to the individual bank level where risk management and detection systems are found to be wanting?
Giles Nelson, director of technology, Progress Software, says it is seeing an increasing number of organisations using technology to provide an integrated real-time view of their position and risk analytic systems, which he anticipates will only increase as electronic trading volumes increase.
Could it for example have enabled SocGen to detect and even prevent its €5 billion of losses caused by a rogue trader dealing in European stock futures? Maybe not. But it appears that in a new post-MiFID world, with multiple MTFs springing up and all of them looking to compete with one another on speed of trading and cost, that market surveillance and risk management is becoming more of an issue.
Project Turquoise, the MTF set up by a consortium of investment banks, has announced that it will incorporate a "real-time" market surveillance system combining Progress Apama's Complex Event Processing (CEP) engine and Detica's market surveillance expertise.
Turquoise's post-trade market surveillance system will capture breaches of trading rules, detect market irregularities and develop enhanced trading execution analytics. But given the risk failings that have been highlighted at individual banks recently, one has to ask how effective these technologies are.
The UK's Financial Services Authority (FSA) also worked with Progress Apama and Detica on its "next-generation market surveillance platform", called Sabre II, which also uses CEP to process and analyse real-time event streams. According to reports, the FSA's old market surveillance system only had "end-of-week" capabilities as opposed to the ability to detect market irregularities in real time.
If MTFs and the FSA are relying on CEP for market-compliance issues, is this likely to filter down to the individual bank level where risk management and detection systems are found to be wanting?
Giles Nelson, director of technology, Progress Software, says it is seeing an increasing number of organisations using technology to provide an integrated real-time view of their position and risk analytic systems, which he anticipates will only increase as electronic trading volumes increase.
"With the increasing pace of electronic trading it's vital that a real-time view is available. The volatility in markets over this last week demonstrates the need for this."
BIC and IBAN confusion persists
With all the turmoil going on in the markets, the first official day of SEPA, 28 January 2008 when SEPA Credit Transfers became commercially available, may pass without much fanfare.
However, just to add to banks' woes, Compass Management Consulting estimates that despite there being a low number of non-STP cross-border payments in the eurozone, the 2% to 5% of non-STP payments that require manual intervention, are steadily eroding banks' trading profits.
Based on its analysis of European banks, Compass estimates that non-STP payments can reduce overall trading profits by up to 25%. To back up its claim, it cites its observation of a banking operation handling 300,000 transactions a day that generated 7,000 exceptions. "Despite the relatively low 2.3% exceptions rate, 270 full-time equivalent staff (FTEs) were required for manual processing of these payments, each of which costs between £25 to £40 to handle," said Richard Bissett, head of banking services at Compass.
Compass found that an average of 20% of all transactions fail requiring manual intervention. These 20% of transactions account for 80% of total back office costs. Bissett says 60% of exceptions could be fully automated. Yet, according to Compass' analysis, banks are only managing to automate 4% of exceptions.
Shedding some light on the results, Bissett said that the real question is why are there still non-STP payments when BICs and IBANs were introduced to try and increase the automated handling of cross-border payments in euro? He says corporates are still "totally confused" by BICs and IBANs and that of the 62,000 BICs, only 20,000 are connected (SWIFT network participants).
With SEPA placing further pressure on banks' payments processing margins, Compass anticipates that this will bring the challenge of exceptions processing into greater focus. It still doesn't resolve the rather confusing issue of BICs and IBANs though, and with cross-border payment volumes tipped to rise post-SEPA, one can only expect the number of exceptions to increase unless something is done to remedy this.
However, just to add to banks' woes, Compass Management Consulting estimates that despite there being a low number of non-STP cross-border payments in the eurozone, the 2% to 5% of non-STP payments that require manual intervention, are steadily eroding banks' trading profits.
Based on its analysis of European banks, Compass estimates that non-STP payments can reduce overall trading profits by up to 25%. To back up its claim, it cites its observation of a banking operation handling 300,000 transactions a day that generated 7,000 exceptions. "Despite the relatively low 2.3% exceptions rate, 270 full-time equivalent staff (FTEs) were required for manual processing of these payments, each of which costs between £25 to £40 to handle," said Richard Bissett, head of banking services at Compass.
Compass found that an average of 20% of all transactions fail requiring manual intervention. These 20% of transactions account for 80% of total back office costs. Bissett says 60% of exceptions could be fully automated. Yet, according to Compass' analysis, banks are only managing to automate 4% of exceptions.
Shedding some light on the results, Bissett said that the real question is why are there still non-STP payments when BICs and IBANs were introduced to try and increase the automated handling of cross-border payments in euro? He says corporates are still "totally confused" by BICs and IBANs and that of the 62,000 BICs, only 20,000 are connected (SWIFT network participants).
With SEPA placing further pressure on banks' payments processing margins, Compass anticipates that this will bring the challenge of exceptions processing into greater focus. It still doesn't resolve the rather confusing issue of BICs and IBANs though, and with cross-border payment volumes tipped to rise post-SEPA, one can only expect the number of exceptions to increase unless something is done to remedy this.
Thursday, January 24, 2008
A crisis of confidence
There is nothing like a whiff of a financial crisis, to inspire technology vendors to espouse such pearls of wisdom, which go something along the lines of, 'Well if they had implemented such and such a piece of software, that does so many millions of risk calculations per second, then they would have been able to calculate their real risk exposure much earlier on and perhaps prevented such a crisis.'
Some grid computing and data management vendors have been having a field day with the current crisis sweeping through the global credit markets. I for one remain sceptical as to whether technology can really overcome the financial markets' overwhelming desire to not only make money, but to behave like a pack of herd animals converging on a tasty corpse.
Although risk management and Basel II may be at the top of the agenda (well at least it is at the top of regulators' agenda), does any amount of technology and advanced risk measurement approaches really make a difference, or have recent events merely provided the stimulus that tipped over an already precarious house of cards? The apple was already rotten and recent events have only served to demonstrate how rotten it actually is.
Confidence in banks, particularly those that were considered to be financial heavyweights that could survive almost anything, including a nuclear holocaust, is at an all time low, and one has to ask have we only seen the beginning of the unsightly chinks in the banks' armour?
Then there was today's announcement by Société Générale that it had uncovered €5 billion of losses caused by a rogue trader dealing in European stock futures. Sound familiar? Nick Leeson of Barings Bank lost approximately £800 million in 1995 in rogue trades.
Commenting on the SocGen announcement, David Dearman a partner at accountants and business advisers, PKF had this to say:
According to Dearman, there was much "soul-searching" and review of procedures at financial institutions in the City of London following the Barings' incident, and procedures were tightened in a number of instances.
Interestingly, perhaps what both incidences highlight is the ability for someone with detailed knowledge of a bank's control systems to override those very systems put in place to prevent such an incident from occurring.
It reminds me of a comment one compliance consultant made not so long ago, that banks tend to focus more on external threats as opposed to internal threats. One has to ask though, would any amount of sophisticated risk management techniques and real-time data management technologies have uncovered or even been able to prevent someone using their knowledge of a company’s security systems to conceal fraudulent positions?
Some grid computing and data management vendors have been having a field day with the current crisis sweeping through the global credit markets. I for one remain sceptical as to whether technology can really overcome the financial markets' overwhelming desire to not only make money, but to behave like a pack of herd animals converging on a tasty corpse.
Although risk management and Basel II may be at the top of the agenda (well at least it is at the top of regulators' agenda), does any amount of technology and advanced risk measurement approaches really make a difference, or have recent events merely provided the stimulus that tipped over an already precarious house of cards? The apple was already rotten and recent events have only served to demonstrate how rotten it actually is.
Confidence in banks, particularly those that were considered to be financial heavyweights that could survive almost anything, including a nuclear holocaust, is at an all time low, and one has to ask have we only seen the beginning of the unsightly chinks in the banks' armour?
Then there was today's announcement by Société Générale that it had uncovered €5 billion of losses caused by a rogue trader dealing in European stock futures. Sound familiar? Nick Leeson of Barings Bank lost approximately £800 million in 1995 in rogue trades.
Commenting on the SocGen announcement, David Dearman a partner at accountants and business advisers, PKF had this to say:
"This fraud highlights the continuing lack of controls at some major financial institutions. The lessons of the Nick Leeson and Barings case in 1995 appear to have been forgotten by some. The scale of this clearly surpasses that fraud and is truly shocking."
According to Dearman, there was much "soul-searching" and review of procedures at financial institutions in the City of London following the Barings' incident, and procedures were tightened in a number of instances.
"I can only trust that the procedures adopted in the City a decade ago are working and being regularly reviewed, but there will undoubtedly be some very nervous senior people in the industry today," Dearman continues.
Interestingly, perhaps what both incidences highlight is the ability for someone with detailed knowledge of a bank's control systems to override those very systems put in place to prevent such an incident from occurring.
It reminds me of a comment one compliance consultant made not so long ago, that banks tend to focus more on external threats as opposed to internal threats. One has to ask though, would any amount of sophisticated risk management techniques and real-time data management technologies have uncovered or even been able to prevent someone using their knowledge of a company’s security systems to conceal fraudulent positions?
Tuesday, January 22, 2008
The 'superbanks' of tomorrow
In recent months with bank stocks plummeting and the aftershocks of the US credit crunch continuing to resound in global markets, no one would be surprised if the outlook for the banking sector going forward was dire.
Yet, while our faith and confidence in banks may be at an all-time low, McKinsey believes banks will double their profits and revenues by 2016.
It predicts that global banking revenues will grow, on average, by a not too unhealthy 7.5% a year from 2006 to 2016, compared with an average of 8% a year from 2000 to 2006 (and 12.6% from 2002 to 2006). Although revenues are expected to slow somewhat, McKinsey says they will still exceed current forecasts for GDP growth by more than one-half of a percentage point a year over the 10 years from 2006 to 2016.
How can this be, you may ask with household names such as Citi having to grovel to Middle Eastern sovereign wealth funds to help balance their balance sheets after significant write-downs in the current sub-prime debacle.
Well it seems part of the reason for McKinsey's rather bullish predictions for the banking sector is the growth in demand for banking and financial services in emerging markets, which it says will contribute roughly half of the absolute growth in new banking revenues from 2006 to 2016, while North America and Western Europe will account for 25% and 20%, respectively.
Russia, says McKinsey will be one of the fastest-growing large markets in the next few years, alongside China. More importantly perhaps, India is predicted to overtake Central and Eastern Europe. Those segments that are likely to be profitable include retail banking and investment banking, trading and securities services, which McKinsey says will provide a larger relative share of bank revenues.
But perhaps the biggest driver that may support McKinsey's predictions is the prospect of more consolidation in the banking sector to create "superbanks".
Today, global banking is the least concentrated industry says McKinsey with the top 20 banks accounting for less than 40% of its global market cap, compared with an average of 67% in other key industries. Interestingly, those banks that are in the Top 20 today, are not guaranteed to be the 'superbanks' of tomorrow. "Even the current top European and US banks aren’t guaranteed to achieve 'superbank' status with their existing portfolios," says McKinsey.
Yet, while our faith and confidence in banks may be at an all-time low, McKinsey believes banks will double their profits and revenues by 2016.
It predicts that global banking revenues will grow, on average, by a not too unhealthy 7.5% a year from 2006 to 2016, compared with an average of 8% a year from 2000 to 2006 (and 12.6% from 2002 to 2006). Although revenues are expected to slow somewhat, McKinsey says they will still exceed current forecasts for GDP growth by more than one-half of a percentage point a year over the 10 years from 2006 to 2016.
"Consequently, we expect the industry to generate $5.7 trillion in revenues and $1.8 trillion in after-tax profits by 2016 —more than twice the levels at the end of 2006."
How can this be, you may ask with household names such as Citi having to grovel to Middle Eastern sovereign wealth funds to help balance their balance sheets after significant write-downs in the current sub-prime debacle.
Well it seems part of the reason for McKinsey's rather bullish predictions for the banking sector is the growth in demand for banking and financial services in emerging markets, which it says will contribute roughly half of the absolute growth in new banking revenues from 2006 to 2016, while North America and Western Europe will account for 25% and 20%, respectively.
Russia, says McKinsey will be one of the fastest-growing large markets in the next few years, alongside China. More importantly perhaps, India is predicted to overtake Central and Eastern Europe. Those segments that are likely to be profitable include retail banking and investment banking, trading and securities services, which McKinsey says will provide a larger relative share of bank revenues.
But perhaps the biggest driver that may support McKinsey's predictions is the prospect of more consolidation in the banking sector to create "superbanks".
"Over the next five years, we expect a new wave of consolidation to speed the emergence of 'superbanks,' with more than $500 billion in market capitalization," says McKinsey.
Today, global banking is the least concentrated industry says McKinsey with the top 20 banks accounting for less than 40% of its global market cap, compared with an average of 67% in other key industries. Interestingly, those banks that are in the Top 20 today, are not guaranteed to be the 'superbanks' of tomorrow. "Even the current top European and US banks aren’t guaranteed to achieve 'superbank' status with their existing portfolios," says McKinsey.
Outsourcing crunch time
Regular readers of this blog will know that I have regularly commented on the hype surrounding outsourcing. Outsourcing is definitely here to stay, but as firms' experiences of outsourcing have matured and some of the gloss has gone off outsourcing as being a cost-effective panacea for companies' woes, outsourcing entered the 'trough of disillusionment' for some firms.
Having said that, the latest quarterly stats from sourcing advisers, TPI, suggests that outsourcing is on the rise, particularly in Europe, which has now surpassed the US in terms of total number of contracts signed (220 valued at €32.7 billion) compared to 194 contracts signed in the US valued at €21.3 billion.
While in the past a significant portion of contracts signed were renewals of existing outsourcing business, according to TPI, in 2007, the annualised value of new contracts awarded in Europe was up almost 31% on 2006 levels, compared with an increase of 13% globally.
And it seems financial services firms are once again leading the way in the demand for outsourcing, representing more than 38% of the total value of outsourcing contracts signed. According to TPI, the worldwide market for Financial Service Operations (FSO) outsourcing has grown by 22.5% since 2003.
I think we have only seen the tip of the iceberg when it comes to outsourcing by financial service providers. A number of regulatory imperatives (Basel II, MiFID, SEPA) is placing significant demands on banks' back offices, and not all banks are well positioned to meet those demands in terms of their systems and investment capability.
Some difficult decisions have yet to be made by financial institutions regarding their back office processing, whether it is in the securities or payments business. Crunch time is rapidly approaching for them to decide what is strategic to their business and what they can outsource or white label.
Having said that, the latest quarterly stats from sourcing advisers, TPI, suggests that outsourcing is on the rise, particularly in Europe, which has now surpassed the US in terms of total number of contracts signed (220 valued at €32.7 billion) compared to 194 contracts signed in the US valued at €21.3 billion.
While in the past a significant portion of contracts signed were renewals of existing outsourcing business, according to TPI, in 2007, the annualised value of new contracts awarded in Europe was up almost 31% on 2006 levels, compared with an increase of 13% globally.
And it seems financial services firms are once again leading the way in the demand for outsourcing, representing more than 38% of the total value of outsourcing contracts signed. According to TPI, the worldwide market for Financial Service Operations (FSO) outsourcing has grown by 22.5% since 2003.
I think we have only seen the tip of the iceberg when it comes to outsourcing by financial service providers. A number of regulatory imperatives (Basel II, MiFID, SEPA) is placing significant demands on banks' back offices, and not all banks are well positioned to meet those demands in terms of their systems and investment capability.
Some difficult decisions have yet to be made by financial institutions regarding their back office processing, whether it is in the securities or payments business. Crunch time is rapidly approaching for them to decide what is strategic to their business and what they can outsource or white label.
Wednesday, January 16, 2008
Lunches, trains and automobiles
Are we on the brink of a recession? Well even if we aren't, it seems like the markets are talking themselves into one, and it seems I am not alone in thinking that the market is panicking itself into a recession. Christmas sales haven't been what they used to be for retailers (although I think far too much weight is put on analysts' expectations especially when supermarket giants like Tesco still manage to record a 3.1% rise in Christmas trading, even though it was below analysts' expectations of 4%), and based on December figures the UK housing market is at its worst since the recession of 1992.
But retail earnings and housing slumps aside, some say a true sign that we are in a recession has to be the demise or otherwise of the business lunch and the number of people taking taxis.
I was just discussing this over a business lunch today, which lasted for a couple of hours - always a good sign that the days of the two-hour business junket are far from over. And judging by the busy lunchtime crowd that was in the restaurant, businesses are not battening down the hatches quite yet.
So it is official, while consumer confidence may be ebbing, all important business confidence is hanging on by the skin of its teeth, and those that work in the markets say, despite the credit crunch, trading volumes have not declined.
I feel another round of outsourcing coming on. The credit crunch may not mark the end of the business lunch, not yet anyway, but will it prompt banks to more seriously consider what is core to their business and what it is not and outsource the non- value-added menial tasks to high volume processors that benefit from economies of scale?
But retail earnings and housing slumps aside, some say a true sign that we are in a recession has to be the demise or otherwise of the business lunch and the number of people taking taxis.
I was just discussing this over a business lunch today, which lasted for a couple of hours - always a good sign that the days of the two-hour business junket are far from over. And judging by the busy lunchtime crowd that was in the restaurant, businesses are not battening down the hatches quite yet.
So it is official, while consumer confidence may be ebbing, all important business confidence is hanging on by the skin of its teeth, and those that work in the markets say, despite the credit crunch, trading volumes have not declined.
I feel another round of outsourcing coming on. The credit crunch may not mark the end of the business lunch, not yet anyway, but will it prompt banks to more seriously consider what is core to their business and what it is not and outsource the non- value-added menial tasks to high volume processors that benefit from economies of scale?
Tuesday, January 15, 2008
Compliance tops the agenda
For those of you wanting to get a heads up on the post-MiFID environment, Basel II, the third Anti-Money Laundering Directive, what regulators may have in store for the hedge fund community or the next installment of 'MiFID-like' directives, Complinet is hosting its fifth annual Compliance Conference in London on the 6-7 February.
The conference program features some of the European Commission's and the FSA's leading lights who can fill banks in on the latest developments surrounding the MiFID Directive Level 3 (not so good news for those that thought MiFID had come and gone). The FSA's head of risk will happily share its vision of principles-based regulation and what it means in a post-MiFID environment, and why it is imposing so many fines for lack of compliance with Treating Customer Fairly breaches.
And if that wasn't enough to make any risk manager's head spin, there will also be sessions on how data protection laws and other regulatory requirements often result in competing and conflicting requirements (something I am particularly interested in). Do KYC requirements, for example, often conflict with firms' data protection obligations?
There will also be sessions on Basel II, the latest anti-money laundering edict handed down from on high, and leaping into the uncharted territory of principles-based regulation, which we know a number of financial service providers developed a distaste for in the run-up to MiFID's implementation.
The conference program features some of the European Commission's and the FSA's leading lights who can fill banks in on the latest developments surrounding the MiFID Directive Level 3 (not so good news for those that thought MiFID had come and gone). The FSA's head of risk will happily share its vision of principles-based regulation and what it means in a post-MiFID environment, and why it is imposing so many fines for lack of compliance with Treating Customer Fairly breaches.
And if that wasn't enough to make any risk manager's head spin, there will also be sessions on how data protection laws and other regulatory requirements often result in competing and conflicting requirements (something I am particularly interested in). Do KYC requirements, for example, often conflict with firms' data protection obligations?
There will also be sessions on Basel II, the latest anti-money laundering edict handed down from on high, and leaping into the uncharted territory of principles-based regulation, which we know a number of financial service providers developed a distaste for in the run-up to MiFID's implementation.
Monday, January 14, 2008
Prudential - less than prudent with customer details
Prior to Christmas the UK's HM Revenue & Customs lost the personal details of millions of child benefit recipients, and the latest data management debacle by institutions that consumers entrust with their data is Prudential, which has been less than prudent with their wealthiest customers' personal records.
According to the latest reports, a box containing premium customer details, including cheques and other sensitive information, was found on a roadside near Reading Berskhire by a vehicle recovery driver.
Apparently the box fell to the side of the road when it was being transported from Prudential's offices in Reading to a "secure" facility in Essex. In this day and age with electronic data storage facilities, image scanning and remote backup of data available, it seems astonishing that personal customer information is still being transported in paper format in boxes.
Even if the box had not been lost on the side of the road, anyone transporting the information could have easily photocopied some of the sensitive documents and used them for fraudulent purposes.
It begs the question, why are government departments and financial service providers opting for the least expensive and less safe option when it comes to protecting customers' personal data? There are really no excuses for these organisations who we entrust with our personal information to be reliant on such antiquated systems when it comes to data storage and protection. What is it going to take for these organisations to take data protection more seriously?
According to the latest reports, a box containing premium customer details, including cheques and other sensitive information, was found on a roadside near Reading Berskhire by a vehicle recovery driver.
Apparently the box fell to the side of the road when it was being transported from Prudential's offices in Reading to a "secure" facility in Essex. In this day and age with electronic data storage facilities, image scanning and remote backup of data available, it seems astonishing that personal customer information is still being transported in paper format in boxes.
Even if the box had not been lost on the side of the road, anyone transporting the information could have easily photocopied some of the sensitive documents and used them for fraudulent purposes.
It begs the question, why are government departments and financial service providers opting for the least expensive and less safe option when it comes to protecting customers' personal data? There are really no excuses for these organisations who we entrust with our personal information to be reliant on such antiquated systems when it comes to data storage and protection. What is it going to take for these organisations to take data protection more seriously?
Tuesday, December 04, 2007
Fraud from within
Judging by my last few posts, you are probably beginning to think that FinancialTech Insider has it in for anti-money laundering systems and the banks implementing them. Make no mistake, we do feel that banks have got the raw end of the deal with financial regulators and governments effectively forcing them to police every financial transactions on their watch.
It is no easy task and despite banks throwing millions at the latest and greatest AML solutions, can any bank really say they have got it well and truly 'sussed?' The regulatory burden is only increasing with the Third EU Money Laundering Directive due to be implemented in 2008.
And as recent events have demonstrated, preventing fraud and AML is not just about monitoring transactions and implementing technology. In fact Innovations Softwaretechnologie of Germany says that transaction monitoring should not only cover the threat of fraud being committed by an external perpetrator, but also employee conflicts of interest,insider trading and market abuse.
According to a poll by KPMG of more than 220 banks across more than 50 countries, 33% of banks are not satisfied with the effectiveness of their own transaction monitoring systems, and less than 25% have the capabilities to monitor the transactions and accounts of a single customer across multiple international borders.
Why then is so much of the onus for policing financial transactions on the banks, when banks do not have the adequate systems in place to meet these requirements, and the internal threat from their own employees is not being adequately addressed?
At a time when trust in banks and government departments is being eroded, isn't it time for regulators, governments and banks to engage in a more serious debate about the effectiveness of current approaches to transaction monitoring and money laundering, rather than adding more complexity to an already unworkable solution?
It is no easy task and despite banks throwing millions at the latest and greatest AML solutions, can any bank really say they have got it well and truly 'sussed?' The regulatory burden is only increasing with the Third EU Money Laundering Directive due to be implemented in 2008.
And as recent events have demonstrated, preventing fraud and AML is not just about monitoring transactions and implementing technology. In fact Innovations Softwaretechnologie of Germany says that transaction monitoring should not only cover the threat of fraud being committed by an external perpetrator, but also employee conflicts of interest,insider trading and market abuse.
According to a poll by KPMG of more than 220 banks across more than 50 countries, 33% of banks are not satisfied with the effectiveness of their own transaction monitoring systems, and less than 25% have the capabilities to monitor the transactions and accounts of a single customer across multiple international borders.
Why then is so much of the onus for policing financial transactions on the banks, when banks do not have the adequate systems in place to meet these requirements, and the internal threat from their own employees is not being adequately addressed?
At a time when trust in banks and government departments is being eroded, isn't it time for regulators, governments and banks to engage in a more serious debate about the effectiveness of current approaches to transaction monitoring and money laundering, rather than adding more complexity to an already unworkable solution?
Wednesday, November 28, 2007
Making financial crime a priority
Well it seems the HM Revenue & Customs (HMRC) incident where millions of customers personal and financial details stored on an unencrypted CD went amiss, has opened a veritable can of worms.
My inbox is suddenly being inundated with emails questioning how well customer data is protected not just by government departments, but banks and other companies.
The HMRC incident prompted the British Bankers Association (BBA)to publish these rather terse words for law enforcement officers:
Not only are government departments it seems letting the side down by not adhering to the strictest data protection principles, but the very same government that requires banks to spend millions on anti-fraud and money laundering measures, is apparently not even bothering to allocate sufficient resources to law enforcement to tackle both money laundering and fraud risks, says the BBA.
Those of you who read this blog regularly will know that we have been particularly vocal about the cost/benefit of banks investing millions in AML solutions, when there is a very clear lack of transparency as to the success of these systems in accurately identifying suspicious transactions, and the percentage of transactions that lead to successful prosecutions.
Not only are the banks unwilling to talk about how many suspicious transactions they are actually reporting (although we hear the number of Suspicious Activity Reports have increased exponentially as compliance officers are reporting everything to cover their backs), but it appears the due diligence of law enforcement officers does not match the time and money being invested by banks in generating SARs.
Not only that it appears government departments appear to be giving potential fraudsters a hand-up by failing to adequately protect consumers' personal details. Surely the government needs to be made as accountable as the banks?
My inbox is suddenly being inundated with emails questioning how well customer data is protected not just by government departments, but banks and other companies.
The HMRC incident prompted the British Bankers Association (BBA)to publish these rather terse words for law enforcement officers:
"Looking at the wider context in which this unacceptable lack of sensible data protection took place, it is clear that the Government has not yet accepted properly the case for making fraud and financial crime a priority for law enforcement in its own right," says the BBA.
Not only are government departments it seems letting the side down by not adhering to the strictest data protection principles, but the very same government that requires banks to spend millions on anti-fraud and money laundering measures, is apparently not even bothering to allocate sufficient resources to law enforcement to tackle both money laundering and fraud risks, says the BBA.
“It is quite extraordinary that the industry does so much on anti-money laundering, on fraud prevention and on identifying suspicious transactions, and yet this doesn’t feature among the priorities the police has been given by the Home Office.”
Those of you who read this blog regularly will know that we have been particularly vocal about the cost/benefit of banks investing millions in AML solutions, when there is a very clear lack of transparency as to the success of these systems in accurately identifying suspicious transactions, and the percentage of transactions that lead to successful prosecutions.
Not only are the banks unwilling to talk about how many suspicious transactions they are actually reporting (although we hear the number of Suspicious Activity Reports have increased exponentially as compliance officers are reporting everything to cover their backs), but it appears the due diligence of law enforcement officers does not match the time and money being invested by banks in generating SARs.
Not only that it appears government departments appear to be giving potential fraudsters a hand-up by failing to adequately protect consumers' personal details. Surely the government needs to be made as accountable as the banks?
Tuesday, November 27, 2007
Thwarting fraudsters
I have purposely avoided writing anything about the HM Revenue & Customs'(HMRC) data breach of millions of UK consumers personal and banking details, but I felt compelled to say something when I started seeing information security vendors leaping on the bandwagon.
While it may be true to say that "fraud is already firmly on the banking industry agenda," when information security vendors say that consumers should not lose sleep over the HM Revenue & Customs' debacle because banks have risk management systems in place, it does not really provide me with much comfort.
The fact remains that despite these systems, fraud and identity theft still occur on an ever increasing scale, and it is arguable whether banks' systems are adequate. Even if thieves cannot access a person's bank account directly, they could still use their name and address details to apply for a credit card or other forms of financing.
What is the most alarming thing about the HM Revenue & Customs data leak is that it reflects well entrenched practices within government departments of posting customer data on unencrypted CDs.
It strikes me as rather odd that on the one hand you have a government wanting ISP providers and banks to take more responsibility for protecting consumers' identity and personal details, but yet government departments which hold reams of information on millions of people, are not subject to the same levels of scrutiny or compliance.
According to Jeremy Smith, managing director of Jardine Lloyd Thompson’s Financial & Professional Risks division, the HMRC incident has prompted security experts to renew their request for the current law to be urgently reviewed for, unlike our American counterparts, the Data Protection Act does not currently compel companies to notify those affected by the loss of data.
Smith points to the almost £1 million fine levied by the FSA on the Nationwide Building Society for a laptop theft from an employee’s house. Yet, no such fines will be levied on government departments which do not face the same regulatory scrutiny as banks. Arguably however, as the government steps up its "Big Brother" campaign to collate as much information as possible on individuals, one has to seriously question the lack of government department accountability.
On the technology side, there has been so much focus on authenticating a customer's identity at the point of sale using chip or pin, but very little focus on securing the storage and transmission of customer data between government departments and banks that share this data and training employees to abide by the strictest codes when it comes to managing that data.
At this point, information security experts are going to proffer some kind of comment about the latest and greatest solutions that can help banks identify fraud before it occurs. One such comment in the wake of the HM Revenue & Customs' debacle was:
Sounds great in theory, but show me a bank that has the systems and business processes in place that they can accurately monitor and understand customer behaviour across multiple channels and product silos in real time. Even if such a bank exists I don't think they would be game to put their hand up for fear that they will be proven wrong.
The banking industry and government cannot afford to rest its laurels on the fact that banks have implemented a nice piece of software kit with bells and whistles, which is going to make everything alright. With banks, government departments and web sites collating unprecedented levels of personal information on consumers, is it any wonder that identity theft is on the rise. And no amount of banking software is going to change that.
While it may be true to say that "fraud is already firmly on the banking industry agenda," when information security vendors say that consumers should not lose sleep over the HM Revenue & Customs' debacle because banks have risk management systems in place, it does not really provide me with much comfort.
The fact remains that despite these systems, fraud and identity theft still occur on an ever increasing scale, and it is arguable whether banks' systems are adequate. Even if thieves cannot access a person's bank account directly, they could still use their name and address details to apply for a credit card or other forms of financing.
What is the most alarming thing about the HM Revenue & Customs data leak is that it reflects well entrenched practices within government departments of posting customer data on unencrypted CDs.
It strikes me as rather odd that on the one hand you have a government wanting ISP providers and banks to take more responsibility for protecting consumers' identity and personal details, but yet government departments which hold reams of information on millions of people, are not subject to the same levels of scrutiny or compliance.
According to Jeremy Smith, managing director of Jardine Lloyd Thompson’s Financial & Professional Risks division, the HMRC incident has prompted security experts to renew their request for the current law to be urgently reviewed for, unlike our American counterparts, the Data Protection Act does not currently compel companies to notify those affected by the loss of data.
Smith points to the almost £1 million fine levied by the FSA on the Nationwide Building Society for a laptop theft from an employee’s house. Yet, no such fines will be levied on government departments which do not face the same regulatory scrutiny as banks. Arguably however, as the government steps up its "Big Brother" campaign to collate as much information as possible on individuals, one has to seriously question the lack of government department accountability.
On the technology side, there has been so much focus on authenticating a customer's identity at the point of sale using chip or pin, but very little focus on securing the storage and transmission of customer data between government departments and banks that share this data and training employees to abide by the strictest codes when it comes to managing that data.
At this point, information security experts are going to proffer some kind of comment about the latest and greatest solutions that can help banks identify fraud before it occurs. One such comment in the wake of the HM Revenue & Customs' debacle was:
"By understanding customer behaviour across multiple payment channels in real time, banks will be able to identify irregular account activity that could potentially thwart fraudsters before they have even committed a crime.”
Sounds great in theory, but show me a bank that has the systems and business processes in place that they can accurately monitor and understand customer behaviour across multiple channels and product silos in real time. Even if such a bank exists I don't think they would be game to put their hand up for fear that they will be proven wrong.
The banking industry and government cannot afford to rest its laurels on the fact that banks have implemented a nice piece of software kit with bells and whistles, which is going to make everything alright. With banks, government departments and web sites collating unprecedented levels of personal information on consumers, is it any wonder that identity theft is on the rise. And no amount of banking software is going to change that.
Subscribe to:
Posts (Atom)