Post-Industrial Archeology

Greyscale backing image

The BBC World Service has a podcast series called “50 things that made the modern economy” hosted by the economist Tim Harford. It features inventions ranging from COBOL and banks to antibiotics and, interestingly, M-PESA. This caught my attention because M-PESA is one of the Consult Hyperion projects from the last couple of decades that we might find ourselves chatting about at the forthcoming 20th annual Forum, Tomorrow’s Transactions 2017. The Forum will be held at the America Square conference centre in London on 26th/27th April and Kevin Amateshe, the current M-PESA product manager will be coming in from Nairobi to give us a detailed picture of where M-PESA is now and where it will be going next.

The Forum, thanks to the wonderful support from our friends at Vocalink, PaySafeGroup, WorldPay and Olswang, will once again provide a unique environment for learning, investigation, discussion and debate about the future of electronic transactions. The future of people, businesses and government in the post-industrial online and interconnected economy.

This year’s invited keynote will be given by Professor Lisa Servon, one of the world’s leading authorities on financial and social inclusion. All delegates will receive a copy of Lisa’s new book “The Unbanking of America: How the New Middle Class Survives”.

 Other speakers and panelists include Gilad Rosner (IoT Privacy Forum), Nick Telford-Reed (WorldPay), Amy Parsons (Discover), Sandra Alzetta (Visa), Terry Cordeiro (Lloyds Bank), Jane Zavalishina (Yandex Data Factory), Tim Jones (Mondex co-founder), Will Judge (MasterCard), Katie Evans (Money and Mental Health), Vasily Suvorov (Luxoft), David Rennie (gov.verify), Emma Lindley (Innovate Identity), Andy Tobin (Evernym), Ben Whittaker (Masabi) and other people who are shaping the future of retail electronic transactions right now will be discussing PSD2, shared ledgers, AI, real-time payments, the Internet of Things, financial inclusion, open-loop migration and everything else shaping strategy across a variety of industries.
 
In addition to a fireside chat about instant payments with David Yates (CEO, VocaLink) and Ron Kalifa (Vice Chairman, WorldPay), there will be an introductory keynote from me, the judging of the annual Future of Money Design Award for artists and at the end of the first day a 20th anniversary drinks and networking reception. You’d be mad to miss it. As always, the Forum is limited to 100 people to ensure every gets a chance to meet and interact with everyone else so run, don’t walk, to our web site and buy a place right now. I look forward to seeing you all there.

Incidentally, listening to the BBC podcast narrating the story of our good friends Nick Hughes and Susie Lonie (Susie will be at the Forum too if you’d like to come along and say hi to her) brought back many memories, so I decided to conduct a little bit of post-industrial archaeology and I tracked down the presentations on M-PESA that Nick Hughes and our very own Paul Makin (who led the original feasibility study for M-PESA!) ave at the Centre for the Study of Financial Innovation (CSFI) in November 2005 when M-PESA had 300 users and eight agents!!! As of today, it has 25 million users and 261,000 agents across 11 countries.

You can read them here….

Nick Hughes [csfi_Nov_05_Hughes.pdf]Paul Makin [csfi_Nov_05_Makin.pdf]

See you all in April when we get together and try to work out what the next M-PESA will be!

Our live five for 2017

Greyscale backing image

It’s that time of year again. No matter how much I complain that silly lists of what will be big in the New Year are trivial and superficial and not really representative of a more detailed analysis of key trends… I still feel I have to annoy my colleagues at Consult Hyperion into giving me a few ideas so that I can surf the end of year blog wave.

Goodbye 2016

Here we go then. As for the last few years, I’ve put together a “live five” of technology-driven changes in the secure transactions field that will have a real business impact over the coming year. But first, in the spirit of openness and honesty and disclosure that we are known for, I think it’s not right to bother you with this kind of thing without first assessing how we did last time so that you can judge whether to pay any attention to this year’s list or not! So let’s see how our live five for 2016 did:

  1. Amazonisation. We got this one right. The focus on APIs increased through the year and not only for the interfaces to 3rd parties but also as a mechanism for restructuring internal processes and operations.

    the more far thinking will be re-engineering their businesses to develop a whole bunch of APIs outside of PSD2 and will be working out the business models behind opening them out to developers and businesses.

    From Open Banking APIs: Threat and Opportunity | Consult Hyperion

    It’s been really interesting see how the bank (in particular) attitudes to the priority and scope of API strategies has evolved over the year.

  2. Mobile ID and Authentication. Again, largely correct. The European Directive on Strong Customer Authentication (SCA) means that banks and other financial services organisations have had to up their game and make significant investments in improving their authentication methods. For most, this has meant moving to solutions that somehow involve the mobile phone. The impact of the NIST report on 2FA (which said that one-time password sent by text message can no longer be considered a secure authentication method) has yet to be felt, but the shift to more sophisticated and comprehensive mobile identity solutions is underway.

    The NIST guideline goes on to talk about using push notifications to applications on smart phones, which is how we think it should be done.

    From SMS authentication isn’t security. And that’s official | Consult Hyperion

    Of course,  this means doing proper risk analysis on the mobile applications to make sure that they have the appropriate levels of security built in, but at Consult Hyperion we’re rather good at doing that, so it’s a sensible way to proceed.

  3. EMV Next Generation. Big for us, but I wouldn’t say it’s touched the mainstream yet. EMV is getting long in the tooth and needs to be refreshed.

    We celebrate St. Valentine’s Day on 14th February every year to commemorate the introduction of chip and UK In the UK on 14th February 2006. I am a payments romantic, so this is very special day.

    From Ten more years! Ten more years! | Consult Hyperion

    The work that we have been involved in, helping clients to assess and shape their strategies towards the future of EMV, continues.

  4. The Push for Push. When I wrote this I couldn’t have imagined just how right I would be. MasterCard spent a billion dollars on VocaLink.

    mark my words it was one of the most significant events in the evolution of the UK payments industry since Reg Varney got a tenner out of that first ATM in Enfield half a century ago.

    From MasterCard and VocaLink is a big deal | Consult Hyperion

    Enough said.

  5. Transparency. Mixed, I would say. I had expected shared ledgers to proceed further in the exploration of new markets and new kinds of markets but actually most of the work that we have been involved with (I mean paid professional services, not academic research) has continued to look at the ways in which this interesting new class of technology could be used to emulate, essentially, existing centralised systems. But I think our analysis, as set out in this paper, stands.

    The paper that Richard Brown of R3, my colleague Salome Parulava and I put together what seems like an age ago (a year is a long time in fintech) has finally been published!

    From A legacy of transparency | Consult Hyperion

    However, in one or two of the projects, the focus did begin to shift to new ways of doing things and we remain of the opinion that more transparent markets will come.

On the whole, not too bad I think. A good enough score, I hope, to make our thoughts about 2017 worth at least a glance.

EMV POS Upgrade

As you know, I’m all about new technology at the point of sale or service, so I’m going to choose five areas where new technology will make a significant difference to retail financial services – not only payments – over the coming year.

Hello 2017

On to the predictions for the coming year. I’m playing the same game as always here. I don’t want to give away any of the really cool stuff that our teams are working on for clients in business, NGO and government sectors right now, but I do want to make predictions that I already sort-of know will come true because we are already working with the technologies so that I can look clever! I’m sure you all understand how this works. Anyway, here goes…

  1. RegTech. A number of the new technology projects that we have been involved with recently have come to a similar conclusion, which is that the use of new technology to reduce the cost of transactions is a struggle, but the use of the new technology to reduce the cost of regulating the transactions has a much better business case.

    2017 will see the emergence of the next generation of innovation in fintech that addresses risk management and regulation for the bank. We expect that regulatory technology, also known as regtech, will emerge as a separate area of innovation…

    From 2017 predictions | Business Analytics 3.0

    For many of our clients, the costs of regulation are both high and out of control. If the blockchain or cloud or big data or biometrics or whatever can do anything to address the spiralling costs of compliance, they will have significantly more impact on the transaction space than if they could deliver a marginal reduction in transaction costs.

  2. Digital Identity. One of the key regtechs, if not the key regtech, is digital identity. It has finally risen to the top of the agenda and this year it will finally change the way business works. I notice that Karen Webster has come to a similar conclusion in her piece about the major trends for next year.

    More than just authenticating a consumer for a particular transaction, creating a secure digital identity will mean capturing a variety of attributes about that consumer that then can be selectively presented as needed.

    From 8 Big Shifts In FI, Retail, Payments | PYMNTS.com

    Indeed.  What’s more, implicit in this prioritisation, is the start of the identity wars as various constituencies struggle to deliver the mass-market identity solutions that we need. In some areas, it may be the government that does this, in other areas it may be the banks. But in some areas, it may be the big five: Facebook, Google, Amazon, Microsoft or Apple. Either way, there are big implications for our clients long-term strategies.

  3. PSD2 (still). One of the immediate  needs for digital identity infrastructure is to help with the delivery of PSD2 in Europe. Along with the Secure Customer Authentication directive mentioned above, a practical identity infrastructure is an urgent requirement if the industry is going to make open banking and API access work cost effectively .

    European banks and payments companies will spend much of 2017 preparing for the second phase of the EU’s Directive on Payment Services (PSD2).

    From Predictions 2017: What financial services executives can expect | ZDNet

    Right now this is all a bit of a mess because the “standards” that the industry is waiting for our being delayed and it seems to me that the timescales will be further extended in the New Year. However, she is still possible for banks to develop their strategies around the demands of PSD2 even if the details of the specific standards are not yet known.

    Specifications.

  4. Paying on the Go. A key use of open APIs will be payments, and very likely mobile payments. Mobile payments are coming front and centre as a means to authorise access to payment accounts. Not for tap-and-go NFC but for the next generation of retail, transit, utility and other payments across all channels. As everyone has been saying, payments are vanishing inside the mobile phone and whether it is ordering your Starbucks via a voice interface or jumping out of an Uber or shopping at an increasing number of websites, the transaction will complete because of the identification and authentication (I tend to label these “recognition” for short) functionality of the mobile. Since the mobile delivers both convenience and security it seems to me unstoppable in this regard.

    Retailers across the board will adopt mobile payment solutions.

    From Retail Trends and Predictions 2017 | 12 Retail trends and predictions to watch for

    It is natural for retailers to want to manage the shopping experience in order to deliver the best possible service to their customers. As the bumper sticker says, they want to go from check-out to check-in.  One of the implications of this shift for our clients is that they will be delivering services to mobile app developers rather than end customers! Testing these mobile apps to make sure that they have the security necessary for the mass market needs specialist skills that Consult Hyperion has and that customers can rely on.

  5. Invisible POS.  In many of the markets where we provide professional services and indeed software to the transactions value network, the day when non-cash transactions will no longer be dominated by cards is now within the strategic planning horizon.

    No checkout lines. No registers. No self-checkout. No cash, credit or debit.

    From How To ‘Shoplift’ Legally With Amazon

    I’m not expecting the Amazon Go science fiction model to dominate world retailing any day soon, but the combination of mobile apps, instant payments and alternative payment solutions will combine to see volume shift away from the card dip, swipe or tap. Card payments (by card, by token etc) will continue to grow but as more and more of them vanish inside apps, so the nature of the card industry and the shape of the value networks will shift. And if you this is rose-tinted techno-determinist hype from engineers, have a look at what someone whose business this is think about it: 

    Amer Sajed, the chief executive of Barclaycard, says it will spell the steady demise of the physical plastic credit card, which his company introduced to the UK 50 years ago. “People will be able to seamlessly shop going between the web, an app or in store,” he says.

    From The invisible credit card of the future – BBC News

    When customers check in and then check out without plastic in their hands, the point of sale will undergo fundamental change. The competition between payment methods will be subject to new dynamics that are not yet visible or understood. Trying to introduce a new payment scheme to Tesco’s stores is one thing, but introducing a new payment scheme inside the Tesco app (with no changes to the stores, POS or any other infrastructure) is quite another. Our knowledge of both new payment methods and new POS environment help clients to make to informed decisions about their future retail environments.

What does this mean for our clients for the coming year? Given that by and large we work for the incumbents who currently dominate their markets, whether banks or card issuers or acquirers or retailers or government agencies, it’s all about linking these key trends together at a strategic level in order to be able to take advantage of the opportunities offered by the new technologies at the tactical level, working with new players where necessary, to stay on top.

My feeling is that these strategic trends will interact to cause some pretty interesting changes in our markets across the coming year, driven above all by the absolute necessity to restore sanity to the cost-benefit calculations around compliance. It will be regulatory pressures, not technology drivers, that shape most decisions in the next few months but we understand how to make effective use of new technology in responding to those pressures so that’s all good. Here’s to another great year in the world of secure electronic transactions!

The Tale of Money2020 Vegas, Part 2

Greyscale backing image

It’s Vegas, so time for a glass of champagne. Luckily, they had some in the green room for the W3C panel on “One-Click Buying: New W3C Standards for Web Payments” so I poured myself a large one and went on stage to toast the guys while they discussed the working draft of the W3C Payments Request API (July 2016). They deserved it, because in-app and in-browser payments are going to be huge. Bringing chip and PIN security into the web and mobile world is huge. I went to a demo hosted by Amex to see it actually working, which it did. The new API is implemented in Chrome and on the Samsung mobile browser and I saw it with my own eyes work on both. The latter use case – mobile browser triggering mobile wallet with biometric authentication – was slick. Once I can use Apple Pay on my iPhone to buy from mobile web sites and apps, I can’t see that I’ll ever pay any other way.

CHYP on Tour Vegas 16

The impact of this is, if the people I spoke to were anything to go by, considerably underestimated. The ability to make secure and convenient remote payments is transformational and it will inevitably mean a significant growth in online business. But more than that, it will drive more transactions in-browser and in-app and this will mean that there will be more competition, because it is easier to introduce new payment mechanisms this way. Here I am explaining this to one of the international delegates. I told her that the marginal cost of introducing a new payment scheme (such as a direct-from-account “push payment” into an app) would be vastly less than the cost of introducing it a traditional point of sale and she told me to stop following her. 

 Money2020

The next day I was sent off to the Money2020 exhibition floor like a flesh and bone drone remotely piloted from Guildford. I was getting instructions like “go to stand XXX and see if the PIN on glass solution is in the TEE (it was) and certified (it wasn’t)” and then “go to stand YYY and see if the demo is real or simulated” and so on. So I did, and then I ran into noted venture capitalist Matt Harris. I decided to tell him my theory about regtech being a more important use of new technology than fintech for many of our customers because of the disproportionate and uncontrolled costs of compliance. I think I may have convinced him. Then I explained to him why it sometime makes sense for Manchester City to play a “false 9” against teams who lack pace at the back, because midfield runners can always move around the centre backs who are caught between tracking and sitting back.

CHYP on Tour Vegas 16

I went off to a couple of conference sessions but since my first meetings of the day were at 7am on all of the first three days, I found it a little hard to concentrate. When I went to the Cafe Presse to get a little pick me up (quadruple shot latte with an extra shot) I kid you not there were two guys in there who were fast asleep. Lightweights.

The Tale of the Princess and the POS.

Once upon a time there was a Princess. She went to see the King and told him that she was bored and that she wanted to be an entrepreneur so she wanted the money to set up a shop. She decided to set up a potpourri shop and it was very successful.

She ordered a lovely POS terminal and put it on the counter.

Several customers came in every time to buy potpourri, including a Prince, who was very attractive to her because of his tubby Dad body. The Prince paid with his John Lewis MasterCard but things didn’t go as smoothly as the Princess had hoped because it took far too long for the transaction to complete.

When she went to bed at the night, she couldn’t sleep. The POS was bothering her.

“It’s big and ugly Daddy and it takes up space that should be occupied by lovely potpourri”.

So the King got her a small POS and attached it to her mobile phone.

But when she went to bed that night, she still couldn’t sleep. The POS was still bothering her.

“Daddy all my friends have Venmo and Zelle, so why do we make them use stupid old cards like the peasants have?”

So Daddy took away the POS and next time the Prince came in for some potpourri, he Venmo’d the money to the Princess. And his number.

“That’s better Daddy” she told the King. “Now that there’s no POS I can sleep properly again. And my potpourri sales have gone up because of the loyalty scheme in my app”.

The Prince and the Princess changed their status to “hooked up” and they lived happily ever after.

Night night.

<- Part 1  Part 3 ->

The Tale of Money 2020 Vegas, Part 1

Greyscale backing image

CHYP on Tour Vegas 16

Money2020 was pretty different this year. I’m glad I went, it remains one the most important events in our calendar and it’s a fantastic opportunity for Consult Hyperion folk to meet up with all of our key customers and soon-to-be customers. And I’ll go again next year. But… it’s not like in the old days. Money2020 has matured into a mainstream business event. It’s no longer a place where people go to see fascinating presentations on what a blockchain is or how P2P lending works. It’s not longer a place where people go to watch passionate debate on panels full of conflicting views of the future. It’s a place where people go to do serious business. Here I am, for example, engaging in an in-depth discussion about the business opportunities for Payment Service Providers (PSP) because of the European Commission’s Second Payment Services Directive (PSD) open API provisions on the retail payments ecosystem in the UK, in the light of the UK Treasury’s parallel initiative, the Open Banking Working Group (OPWG).

CHYP on Tour 16

I told our commercial chap Nick that I’d been into the conference and was a bit bored. He told me that we’ve done five times as much business at the event this year as we did last year. I couldn’t help but reflect on the fact that next door to Money2020 was the National Fasteners Conference. I’m afraid to say it, but this is the vision of a successful future: a trade show where everyone goes to do real business year after year. I spoke to a few other people about this. There was a feeling like we all know that SXSW will be more fun, but Money2020 will make us more money.  And to be fair, Money2020 was bigger, better organised and easier to navigate than ever before. They’ve built a very successful show.

Vegas 2016

The main reason that I was at the event (apart from to make money for the company, of course) was because I had been invited to moderate one of the financial inclusion panels and I chose to focus on what the US could learn from emerging markets when it comes to the topic. They asked me who I would like to have on my panel and my first pick was Professor Lisa Servon from Penn. Lisa wrote one of the best papers on financial inclusion that I have ever read and I thought that the best way to explore the many aspects of the issues pertaining to the small percentage of American’s who are unbanked (perhaps around 7%) and the much larger proportion who are underbanked (perhaps 20%) would be to go to a Cirque de Soleil show, so I chose their Beatles show. It was great, by the way.

Vegas 2016

I was delighted to welcome Lisa on board along with Jed McCaleb from Stellar, Michael Schlein from Accion, Daniel Monehin from MasterCard and Arjuna Costa from Omidiyar Network. Michael wrote a very good blog post on the key takeaways from this panel so there is no need to repeat them here. What I will say is that the panelists received a well-deserved compliment later in the week when I was told that is was one of the stand out panels of the event, and I wasn’t surprised. I refused to have a set script so I asked them interesting questions and they responded with interesting answer, discussion and debate. A great start to the event.

Money2020

I started to become somewhat deranged on the second day, partly because of lack of sleep, partly because of the over-stimulation at Bruce Parker’s top secret Payments Illuminati dinner (which had, I have to say, one of the best ice-breaker strategies I’ve ever come across at such events) and partly because of the amount of nonsense being talked about the blockchain was getting out of control. As you can see, my mental state was beginning to deteriorate. Someone tells me that the blockchain is going to revolutionise something or other. So I say “wow that’s great – how?” and they begin to describe some fantastical elaboration of some sort of distributed database with wholly mythic qualities and tell me “there, see”. I think perhaps some of his has to do with Money2020 Europe locating in Copenhagen, home of Hans Christian Anderson and his fairy tales. The spirit is permeating the event. I swear I saw a presentation that might as well have been about magic beans for all of the actual content it had or education it delivered. I was losing it, no about.

Vegas 2016

In fact, the more I start to think about it, the more the whole thing seems like it was one big fairy tale. Most of the stories I heard weren’t true, they were marketing, and that’s a sort of fairy tale.

The Tale of the Ugly Blockchain.

There once was a little blockchain. He didn’t use proof of work to form consensus, so all of the other blockchains made fun of him. You’re a quack, they told him. Quack, quack. And the little blockchain was very unhappy. But one morning the ugly blockchain was out playing by himself, because none of the other blockchains would play with him. In fact, they were chasing him with a hard fork. But then, as passing consultant saw what was going on and came over to help him. “Hey,” said the consultant, “what is a beautiful shared ledger like you doing out here with these ruffians?”. He wasn’t a blockchain after all, he was a double-permissioned shared ledger with a practical Byzantine fault-tolerant multi-round consensus algorithm! And he lived happily ever after.

Night night.

Part 2>

A way to embrace “over the counter” mobile money transactions

Greyscale backing image

As one of the pioneers of mobile money (cutting my teeth on the initial service proposition and business model for M-PESA, way back in 2004, three years before commercial launch), I’m always naturally inclined to see its potential in a positive light. But I’m starting to wonder if maybe we need to give it a bit of a nudge – realign it, if you will.
One of the more interesting phenomena we’ve seen in recent years is the rise of Over The Counter (OTC) transactions – those transactions carried out by agents on a customer’s behalf, in many cases without any link to the real people relating to a transaction. We’ve seen cases where agents maintain four or five mobile money accounts, on different phones, so that they can spread their customers’ transactions across accounts and so avoid transaction limits.
The reasons for OTC can be various, but certainly include illiteracy, lack of appropriate language support on mobile handsets, and – fairly commonly – liability (after all, if things are going to go wrong, you want someone else to blame, don’t you?). But the obvious potential for money laundering means that this situation can be a financial regulator’s nightmare.
Of course, it doesn’t have to be this way, and there are examples of it being done properly, with even in some cases biometric authentication of all parties to an OTC transaction. Worldwide, however, this is rare.
But I digress. What I really wanted to talk about was the somewhat self-congratulatory attitude we in the industry are all guilty of at some time – after all, an industry that has grown from nothing to something more than 270 services in over 90 countries in only fifteen years is undeniably impressive. But I do wonder if we’re all kidding ourselves sometimes. I mean, sure, for the middle classes, and for many of the employed poor, it has been an amazing opportunity, and has transformed access to financial services. But there are gaps – possibly some big gaps.
As an example, I’d like to relate a recent experience. First, you have to understand that I believe you can’t develop anything new without spending time with the people who are going to be using it; so I like to go out to the field, and see what people are actually doing, not what the research tells me. Just sit and watch, and ask the occasional question. It can be very educational.
So we were working with this mobile money operator (MMO), who has a deal with an MFI for the delivery of MFI services through MM. On paper, it all looks very good, plenty of transactions, lots of people receiving loans and making repayments, all through MM. I was very keen to go to a group meeting and find out what the customers thought, how they used it, what else they did – the usual.
We turned up at the meeting, and the first thing that was happening was training from the field officer. Great. But there was a surprise in store; the training included the following advice about security: “Always keep your PIN secret. Never tell anybody. EXCEPT the Agent – you should whisper it quietly into his ear” – uh oh. The alarm bells started to ring.
And then the Agent turned up. At this point the field officer started to gather repayments, in the traditional way for group lending – laboriously entering everyone’s name into a list, checking that they have the cash to make the repayment, noting down the repayment amount, all at a glacial pace (now this is one area where investment in IT could make an immediate impact) – and then the mobile money part started. Each person making a repayment took their phone and their cash, one by one, to the Agent – who took their phone, ‘deposited’ the cash for them, then forwarded the repayment to the MFI.
There were also three loan disbursements that day, and the process was much the same: hand your phone to the Agent, whisper your PIN to him, walk away with a wad of cash.
All of these people at the group meeting are in the MMO’s books as active mobile money subscribers. So I have to ask: in what way are these people mobile money subscribers? How is this empowerment? All that I can see is that the MFI has outsourced their cash management problems to the Agent, who walks the streets with a bag full of cash. Glad that’s not me.
So there are clearly a large number of people, down towards the bottom of the pyramid, for whom the step from a pure cash environment to being asked to use a mobile money wallet or account to manage their finances is just too big. Expecting people who’ve never had a bank account to make the conceptual leap from paper cash to mobile finance in one step is asking too much. Without help many of them will never do it.
Maybe the way forward is to make the steps a little more manageable. Introduce an intermediate step. And I think the way to do that is to embrace OTC, but to do it in a way that formalises it and addresses the concerns of the regulatory authorities: give this section of customers a card, which identifies their account. Maybe secure it with biometrics, if you want. Let them visit an agent, and get the agent to do the transactions for them, but now with all transactions linked to the card/the account. Link it to their mobile phone, so that the more adventurous can see their balance via the MM service. Make sure they’re comfortable with this, and make sure there’s a migration path that leads to the full MM service over time.
After all, this is the long term migration path we’ve seen in Europe over the course of decades; the move from cash, to bank accounts, to debit and credit cards, to Internet banking and mobile payments has happened, of course; but with each step taking years or even decades. Expecting people immersed in a world of cash to make the leap in a matter of days or weeks is just unrealistic. Why should they be any different?

Footnote: Yes, the author is well aware of Safaricom’s moves to issue a companion card for the use of M-PESA for retail transactions. That’s somewhat different to the case described here, though in itself interesting.

Inclusion, identity and privacy

Greyscale backing image

Financial inclusion is necessarily built on a foundation of customer identity, but the rush to inclusion and the consequent focus on mass registration in many countries has placed at risk the citizens’ rights to privacy – even where these are recognised in law.  But the mere fact of being excluded should never mean that someones right to privacy is in any way diminished.

With support from Omidyar Network, Consult Hyperion has undertaken a global review of the privacy and data protection aspects of digital identity services, with particular reference to their relevance for financial inclusion. We have reviewed the various digital identity initiatives around the world from a privacy perspective. Building on this framework, we have developed a ‘roadmap’ for digital identity that ensures that privacy, and the needs of regulatory authorities, can be built into digital identity services, ensuring the drive towards financial inclusion can be at its most effective. We hope that this roadmap will be a useful contribution to the industry as it considers how best to deliver digital identity to those most in need.

The key elements of this roadmap are as follows.

Put the individual at the centre of privacy protection

This does not only mean giving individuals control over how their personal data is used; it needs to be reflected in the entire approach to the digital identity system. In order to avoid low levels of take-up and use, it is essential that the emphasis be placed on user needs, rather than vendor-driven use cases or so-called “gold standard” solutions.

Provide an effective legal environment

An effective legal environment must be in place that contains, and can enforce, legal remedies to prevent or punish abuses of personal data.  An effective legal environment will also increase confidence that any contractual measures put in place as part of the trust framework to ensure privacy can be enforced.

Design in privacy from the start

There is widespread recognition that privacy should be designed into any system from the start rather than bolted on as an afterthought.  Privacy–by–design requires a careful understanding of the expected goals of the identity system, an appreciation of the distinctive characteristics of the context of use and an awareness of the technological capabilities and privacy risks associated with proposed next generation digital identity systems.

Separate identification from authentication and authorisation

Many existing identity systems combine identification and authentication activities within the scope of the identity provider. Separating out identification from authentication allows for the relatively rapid roll out of basic digital identity credentials, perhaps issued to all but based on low assurance identity data. The quality of the digital identity can be enhanced over time, in part simply through a history of ownership and use or by incorporating additional data points.

Furthermore, if the basic digital identity credentials only show that the citizen is unique and identifiable and not include other data attributes by default, this will allow future developments to minimise disclosure of data. Today identity systems often include a default data set that is always shared, even when it is not necessary for the service being accessed.

Improve authentication then identification

In an ideal world, it would be desirable to move directly to high quality identification and high quality authentication.  In practice, however, the time and effort to improve the quality of these aspects of digital identity are different.  In general, improvements to authentication quality are likely to be quicker to achieve than improvements in identification quality.

Provide a viable commercial model that disincentivises abuse of personal data

Whilst the monolithic identity providers like Facebook and Google offer easy to use digital identity credentials, their business models could run counter to consumer privacy as key revenue streams come from sharing individual and aggregate customer data. Whilst it is possible to constrain such actions contractually and technologically, long term the commercial model must be designed so that incentives to protect privacy are aligned.

Consider who will pay for the identity system

If identity credentials are to become a key infrastructure for a society, then important questions of how they are to be paid for arise.  There are different models of charging for infrastructure provision that can be drawn upon, but choosing the right payment model can be problematic whether the identity provider is a government agency or a commercial body.

Address questions of liability

Service providers should not be held liable for actions based on properly authenticated identity claims. What then of the liability of the identity providers?  Here the complexity of the liability model grows as benefits and risks are shared unequally.  In extremis, the identity provider privatises the some of the benefits (e.g. payments for authentications) but socialises the risks (e.g. complete failure of trust in the identity system as a whole).

Review the role of compulsion

For countries introducing new identity credentials, questions of consent and compulsion become particularly significant from a market and rights perspective.  They may cause significant disruption to the roll out of system.  In such cases it is frequently stated that the new identity system is voluntary, not compulsory and that individuals can always choose not to have an identity credential. In this case, as the critical mass of credential holders develops, effective compulsion can arise. However, evidence from Europe suggests that the various electronic identity cards are used infrequently because most people have infrequent access to public services and those that do have more frequent access rarely need to formally identify themselves each time.

All of the underlying issues, and the elements of the proposed roadmap, are explored in detail in the report available here. It’s very detailed piece of work, so you might want to being with the Executive Summary that is available here. We are genuinely curious about your views and look forward to all feedback.

Beacons in Transit

Greyscale backing image

You’ve probable heard about Bluetooth Low Energy (BLE) Beacons being used to help the visually impared navigate on their own around public transport systems. This has been trialled in Bucharest on buses and in London Underground. These are examples of relevant information being pushed to users’ smart phones based upon their location. Other similar use cases might include telling passengers when they are approaching the stop at which they plan to get off, or telling them that their selected vehicle is about to arrive.

The use case I am more interested in is the one that allows passengers to travel without paying upfront and be charged afterward based on the journey that they took. We implemented this with TfL in London using contactless bank cards and it has become known as ‘Aggregated Pay As You Go’. This works well, but relies upon the passenger rembering to ‘tap in’ and ‘tap out’ to mark the end point of each leg of the journey in order that the back office can calculate the journey taken. Appropriate charges are made to the passenger’s bank card account at the end of the day.

Beacons could be used in implementations for this use case. Such a beacons trial is to be carried out in 2017 in West Yorkshire as part of the Transport for the North’s Integrated and Smart Travel (I&ST) programme.

The aim is to automatically determine the bus journey taken by the passenger and charge on a PAYG basis. Therefore, we need to know accurately where the passenger gets on and off the bus. This information will be determined by a smart phone app by interacting with beacons and sent to the back office where the charge is calculated and payment taken.

The trial, commissioned by West Yorkshire Combined Authority (WYCA), will be used to determine:

  • whether the passenger experience is favourable;
  • whether BLE technology can deliver sufficient location accuracy; and
  • how the journey timestamp and location information sent to the back office in such a way that can be trusted and not open to fraud.

Identity and inclusion, an ongoing case study

Greyscale backing image

America is a strange country to foreigner such as myself. And one thing that is particularly strange about it is the constant demand for identification in a society that lacks an identity infrastructure. The most obvious manifestation of this, as I’ve written before, is that when I am asked for identification (in order to get into a building in America, for example) I can present documents that the security guard cannot conceivably verify or validate (e.g., my UK driving licence) or documents that are not identity documents at all (e.g., my expired building pass for our office in New York) and gain entry. This is, as is often remarked, security theatre not security. It’s like a play about security where we all say our lines and play our parts but there’s no actual security involved at all. When it comes to identity, there’s definitely something odd about America.

Buying an assault rifle is easy. You need not show formal identification… Opening even the most basic bank account is far more arduous. The process begins with a rigorous ID check…

From It’s easier to buy an assault weapon than open a bank account. Really. – The Washington Post

Now, I don’t want to get into the madness of KYC/AML here as that’s not the point I want to make, although I will flag up the fact that America has something in the region of a hundred million unbanked people. The point I’m making here is that I don’t understand why we can’t implement a universal risk-based approach for “small” accounts in order to get people into the financial system (not necessarily through a bank account, of course). In Europe, we have a very interesting case study unfolding in front of us right now.

When Anas Albasha arrived in Germany after fleeing Syria in late 2014, one of the first things he tried to do was open a bank account. “In Germany you need a bank account for everything,” he says.

From Without German bank accounts, refugees are stuck in limbo – FT.com

Indeed. Rich Germans and people smugglers might well keep their cash in 500 euro notes, but poorer law-abiding Germans use debit cards and direct debits. If you don’t have an account, you have no access to the infrastructure of daily life. And, in my opinion, if you keep everyone out because one or two of them might be terrorists, then you don’t get to track, trace and monitor the terrorists anyway. Hence the German plan to give refugees a sort of provisional identity so that they can enter the financial system makes complete sense.

But it has been a struggle to persuade banks, which have to verify their customers’ identities, to open accounts for refugees. The heart of the problem is documentation. “Many refugees arrive in Germany without a passport or ID card; that’s just the way it is after the journeys they have been through,” says Katharina Stamm, an expert on migration law at the charity Diakonie.

From Without German bank accounts, refugees are stuck in limbo – FT.com

In September 2015, the Federal Financial Supervisory Authority (“BaFin”) relaxed the KYC requirements for refugees so that they could gain access to formal financial services.

With immediate effect and for a transition period, refugees will be able to open a basic account even if they cannot produce a document satisfying the passport and ID requirements in Germany.

From BaFin – News – BaFin makes opening bank accounts easier for refugees

Later last year, in October, the German government went further and passed a law requiring banks to offer these basic bank accounts to refugees. Unfortunately, and despite that law coming into effect in June of this year, “

Germany’s anti money laundering law still contains a clause that effectively requires a passport or ID card to open an account.

From Without German bank accounts, refugees are stuck in limbo – FT.com

Incidentally, we have the same problem here in the UK because the only ID document that refugees have is the Biometric Residence Permit (BRP) and many bank staff refuse to accept this as an ID document for opening an account. As the British Banking Association point out, “banks have to undertake thorough checks before opening accounts in order to comply with strict anti-money laundering rules”. Once again, as in Germany, it is AML rules trumping KYC rules. And I don’t want to point the finger as to the origin of the problematic AML rules, but the Centre for Financial Inclusion do note that it might be better for society to have people inside a system where they can be monitored and risk managed. 

Lower [KYC] requirements also means that governments concerned with international security (particularly the U.S.) must determine how they will mitigate the risk of new financial services innovations.

From Financial Inclusion and Immigration in Europe – Disrupting Identity Norms | Center for Financial Inclusion blog

I’m writing about this because I’m in Ivory Coast for the International Finance Corporation (IFC) and MasterCard Foundation conference on “Partnership for Financial Inclusion”. I was here to keynote about risk management for digital financial services (and how “fintech” and “regtech” can help) but I’ll definitely be hoping to learn more about the relationship between identity and inclusion from the experts here. 

IFCMCF2016 Q&A

I’ve already had a couple of pretty interesting discussions about the idea of building “bottom up” (i.e., attribute-driven) identity to help with inclusion and the relationship between such identities and those KYC/AML issues discussed above. I’m genuinely curious to know what you all think about this stuff – please get in touch – and how some of this thinking might connect with initiatives such as Identity 2020.

Financial inclusion and the power of little things (and no Blockchain!)

Greyscale backing image

I went along to my first NYPAY event in New York this week, called “Innovate or Abandon: The Business of US Financial Inclusion”. This was the first time that I had been to an event organised by our good friends at NYPAY and it was very enjoyable.

According to the CFSI (Center for Financial Services Innovation), research shows there are 68 million un-banked and under-banked people in the US. The panel discussion formed around the financial problems of these people, the importance of certain financial products and failures of the industry incumbents to deliver these services to low-income parts of population.

I was waiting for someone to shout out “Blockchain” at a random point in time, but no one did! Even the “marketplace lending” discussion (formerly known as peer-to-peer lending), brought up by one of the guests, was rapidly exhausted and put aside for “the better times” – regulatory uncertainty makes business cases around these topics quite elusive. And NYPAY event was very much oriented toward practical business model discussions.

Talking about the importance of the key financial attributes, Vinay Patel, CEO and Co-Founder of Bee Financial (One Financial Holdings), hilariously pointed out that the expected lifetime of a joint checking (current) account of a married couple is probably longer than the expected lifetime of their marriage.

This could easily be true. Checking (current) account is a very “sticky” financial product due to the cumbersome on-boarding process, credit score building models surrounding it, loyalty programs and simple habit. However, this product is not available for some parts of population; as is credit. Ability to take credit was seen as a crucial, even key to better financial inclusion by the vast majority of the NYPAY event attendees. But whichever financial product is in question, there is one important observation made by Celia Edwards-Karam, MVP Consumer Deposits from Capital One:

“Payment fees are not the problem – it’s the surprise!”

– Celia Edwards-Karam, MVP Consumer Deposits from Capital One

The surprise charges make a huge difference for low-income, less financially educated, people. This is why understandable fees, even if they are higher, are preferred and more trusted. (Professor Lisa Servon of The New School has detailed research on this and you can hear here talk about it in our podcast with her in 2013).

New business models and new institutional forms are emerging to address this and many other problems of the un-banked and under-banked. For example, Vinay Patel, CEO and Co-founder of Bee Financial, says that during thousands of interviews with potential and existing customers, the start-up team realised that it is crucial to ease up the registration process and on-board people in a way that encourages certain financial behaviour in the future. He shared this insight from the start-up’s research:

“One of the reason low-income people don’t put mobile apps on their phones is because their phones are full of stuff… Good phones, like iPhones and Galaxies come blank. [Bad] phones like $40 Samsungs are pre-loaded with lots of native apps… People are trying to download new stuff – it doesn’t download. So one of the things we’ve learned is that one thing you do for a customer is you check if they have native apps on their phones, look at the apps they never use and delete for them.”

– Vinay Patel, CEO and Co-founder of Bee Financial

A crucial takeaway for me from the event was that income level is just one factor that influences “financial health” of a person. According to CFSI research, there are two important aspects to person’s financial behaviour that also contribute to his or her financial health: to plan ahead and to save regularly.

All of the comments made by the panel supported the idea that little but targeted changes in provision of financial services could lead to drastic changes in financial behavior of customers and therefore can make a big difference for the country’s overall financial health.

A very useful event: many thanks to everyone at NYPAY for putting it together.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.