According to a reputable news source well, the (Daily Mail) the Royal Mint is casting (sic) around to find things to do when the Treasury caves to the inevitable and tells them to quit wasting everyone’s time and money by minting coins. They’ve come up with the idea of making a credit card out of real gold. This isn’t the Royal Mint’s idea, of course. They stole it wholesale from 30 Rock a few years ago.
The cards will have the owners signature engraved on the back (I’ve no idea why, since the card schemes are discontinuing the use of the pointless signature panels on cards) and will apparently be worth $3,000 each which (as a number of Twitterwags immediately pointed out) will greatly increase the number of fake ATMs in the streets around Belgravia after midnight. They are apparently working on ways to get these 18-carat gold cards to work in ATMs and, of course, at contactless terminals.
Wait, what?
Contactless?
How do you make metal cards work in contactless terminals? The metal card messes with the magnetic jiggery-pokery that makes contactless cards work. I know this because Consult Hyperion’s awesome contactless robot test rig (below) has a frame for the card, terminal or card under investigation that is made from wood so the there’s no metal in the field when testing.

The metal contactless cards that I’ve seen before are made using a plastic laminate or by cutting a segment from the metal and replacing it with plastic, so I discounted this report on the Royal Mail’s bold ambitions and filed it away and went off to enjoy Money20/20 in Las Vegas with my Consult Hyperion colleagues.

I had a great time in Las Vegas chairing the “Around the World of Identity” session on the first day, and then I enjoyed the tremendous privilege of interviewing Jed McCaleb and Adam Ludwin of Interstellar on the main stage on the third day. Interstellar is the crypto giant formed by the takeover of Adam’s Chain by Stellar’s Lightyear. This was particular fun for me because I’d visited both Stellar [here] and Chain [here] for our “Tomorrow’s Transactions” podcast series some time ago (we rather pride ourselves on helping clients to spot what’s coming next) and had noted that both of these guys were really smart and really nice. As they proved on stage.

During a break from conference sessions, business meetings and blackjack I went for a stroll around the exhibition floor to catch up with old friends and see what sort of fun fintech things are heading our way. You could have knocked me down with a feather when spotted a stand from Amatech, who are based in Galway in Ireland. They were prominently displaying the bold claim that they had working contactless metal cards. Naturally, I went to investigate, it turns out that they were telling the truth. They’ve developed a clever manufacturing process that combines multiple layers of metal with different elecromagnetic characteristics so that the metal card now helps the chip on a card to communicate contactlessly instead of blocking such communications. Wow. Very cool (and they can do it with graphite too). I saw it working with my own eyes…

For all the talk about changing business models in the self-sovereign identity world to orient around data sharing, re-imaging AML with AI to change the cost-benefit around the regulations and on using cryptocurrency to transfer value across borders, you just can’t beat talking with someone who has made something that you didn’t know existed until you saw it. The satisfying clunk of a metal card on a glass counter was the highlight of the day for me. Apart from running into Shaq in the green room, of course.

Money2020 was exhausting, because all of our clients (and a great many of our prospective clients) are all there and I loved meeting all of them, but I wouldn’t miss it! I’m already looking forward to flying the CHYP flag at the inaugural Money2020 China next month. See you all there!
Category: Payment Cards
Securing Payments in a Post-EMV Chip World
Now that the US has (finally) migrated from magnetic stripe to chip payments, and signature will soon be going too, the time has come to think about where the fraud will go next. This was the topic of a great discussion at Money 20/20 involving amongst others EMVCo, Capital One and USAA.
Obviously the first place fraud will jump to will be card-not-present transactions such as e-commerce. This is well understood by those of us who went through the EMV chip migration over a decade ago. Brian Byrne outlined the various initiatives in EMVCo to secure these transactions – Tokenisation, 3DS 2.0 (with live solutions being imminent) and SRC (which is open for public comment).
Increasingly though it’s an identity problem. Identity theft and synthetic identities are being used to attack payments in a number of ways.
Because EMV chip cards are much harder to counterfeit than magnetic stripe cards, fraudsters instead will try to get their hands on genuine cards. This could be through opening a fraudulent account or by taking over an account and ordering a replacement card.
Identity fraud will be a big issue in faster payments too, with a need for good authentication on both ends of the transaction.
Synthetic identities are a particular challenge. Detecting them is tough, spotting the subtle clues that indicate that an identity record which looks legitimate has actually be cultivated over time by a fraudster. And this is big business, with criminals using the latest machine learning and ready access to data (thanks to all of those breaches) to launch well organised attacks at scale.
In the following session, Professor Pedro Domingos (author of “The Master Algorithm”) gave the great quote “if you try to fight machine learning with code you are doomed”. But it is not simply a case of implementing machine learning. As the Prof explained, the characteristics of fraud are constantly changing so any machine learning system will need to be constantly tuned and re-trained to keep up.
Definitely a case of whack-a-mole.
Avoiding Costs Abroad
Vacation season is upon us! In a few weeks’ time, you could be leaving your home country for some relaxation. Perhaps to the Mediterranean for some sun or somewhere further afield off the beaten track. In full holiday mode, as the sun shines high and mighty, you’re about to indulge in another sundowner. Just only one last hurdle before you can quench your thirst, as you hand over your credit card and are promptly presented with the mobile POS, whilst being asked politely “Would you like to pay in Sterling or local currency?”.
What will you choose?
It is a familiar situation experienced by many of us who have ventured abroad. In that instance, we must decide our fate without fully comprehending the ramifications of our choice. EUR or GBP? And with seeming enlightenment, many rookie fingers have floated reluctantly towards the more familiar currency, GBP, sheepishly smiling, whilst not knowing whether it was the right choice and perhaps not thinking further of the implications (because after all, there is only one cardinal rule during vacation time – no stress allowed!). Was it the right choice though? Well, not according to Starling Bank who have shed some light on the matter through an experiment on Dynamic Currency Conversion (DCC), as reported by This is Money in the article (http://www.thisismoney.co.uk/money/news/article-5784137/The-proof-pay-local-currency-never-pounds-holiday.html).
DCC is the capability that allows a purchase or cash withdrawal to be done either in the local currency abroad or in the home currency associated with the debit or credit card being used. If the home currency is selected, then the POS terminal does a currency conversion on the spot from the local (e.g. EUR) to the home currency (e.g. GBP) at an exchange rate decided by the merchant. The merchant could potentially add their own commission to that conversion operation, resulting in a more expensive purchase than it would be if the local currency were selected. Whereas, in the case of the latter, the purchase or withdrawal is carried out in the local currency, following which a currency conversion is done by the issuer bank or credit card provider at an exchange rate defined by the card scheme network, which is invariably about as good as you can get.
As an example, in their experiment, Starling Bank have found out that an ATM cash withdrawal of EUR 200 costed £195.18 when GBP was selected, meaning that the withdrawn amount was converted on the spot to the home currency (i.e. GBP) by the local bank. In comparison, when EUR was selected whilst keeping all other factors alike, the same withdrawn amount costed £177.44 since it got converted later by the Issuer bank or credit card provider at a better rate. Indeed, that is £17.74 in savings when carrying out the transaction in local currency (EUR) rather than converting it on the spot to the home currency (GBP). This was also true for all the purchases made; albeit the difference was much less (in pence) for each individual purchase. Yet, we all know that the cumulative amount of these smaller differences over purchases made during an entire week’s holiday could potentially result in significant savings. The bottom line from the experiment, and the article, is that you are much better off almost always paying in the local currency.
Understanding the workings of DCC is only one part of the puzzle when trying to save costs for card usage abroad; but there are additional “hidden” costs, which we need to be aware of. More specifically, Issuer banks or credit card providers could charge a fee per transaction for purchases or withdrawals abroad (on top of the conversion rate), which could accumulate during a holiday stay and set you back considerably. Personally, I prefer to completely avoid these costs by opting for payment cards (prepaid, debit or credit) tailored for frequent travelling that do not charge for usage abroad and can offer additional features. However, you do need to be familiar with the terms and conditions for using these cards, since the card providers could restrict their usage, for instance, by limiting the total daily spend, or the number of times you can withdraw cash from an ATM in a day. Most of these restrictions align with typical leisure spending behaviour abroad, including mine so I never had an issue, but every person has different needs. The advantage is that the majority of these travel-specific payment cards come with a companion mobile application that allows you to manage your card, including various features such as viewing your transaction history, topping up your balance (in case of prepaid), blocking your card if stolen or lost, requesting emergency cash, etc.
Prepaid travel cards are quite popular for usage abroad since they allow you to manage spending overseas with ease. An advantageous feature of prepaid travel cards is that they can be associated with different currencies. So, I could load the balance on the prepaid card with a choice from various popular currencies such as GBP, EUR, USD, etc whilst potentially locking in the exchange rate at the time of loading. This gives you total control (and certainty) over planning your holiday spending budget allowing you to make significant savings when compared to using any payment card not tailored for usage abroad. There are many prepaid travel card products available with different features and costs, so it is important to choose the right product that suits your needs and demand. Also, be aware of other costs that prepaid card providers might impose such as card inactivity fee. There are various comparison web sites that table out the different fees and limits associated with the various prepaid products, and of course always refer to the terms and conditions for each card product. For more information on different types of prepaid travel cards I suggest checking out a web site like the following https://www.moneysavingexpert.com/credit-cards/prepaid-travel-cards.
Although prepaid travel cards are ideal for daily spending abroad, I still recommend that you take other types of payment cards, preferably from different card network schemes, only as a fall-back. Unfortunately, a prepaid card might not be accepted in certain situations that would require pre-authorisation such as petrol stations, car rental deposits or hotel reservations, so it is best to have other travel specific debit or credit payment cards in hand. Also, as witnessed recently with the service disruption of one of the international card scheme networks, it is best to diversify the scheme network as a contingency measure.
Working for Consult Hyperion, I’ve had the opportunity to work for the kind of payments innovators who identify areas like this where customers get a bad deal and there are opportunities to make things better. It is thanks to the work of those striving to improve payments, with the support of people like us, that in today’s world we have different payment products to choose from. It is just a question of finding the right product for you, whilst making sure that you fully understand the terms and conditions, such as fees and limits for operating the product. Understanding DCC and carefully planning for the right payment instruments before travelling abroad could help you avoid certain costs, ultimately having more funds available to spend on that well-deserved vacation. So, start looking for the right payment instrument, so you can fully enjoy a stress-free summer vacation! Oh, and if during your vacation you have a great idea for a new payments product, we’d love to hear from you and help you turn the idea into reality.
London taking contactless for half of PAYG
Four years ago Consult Hyperion completed a transit project which changed not only the way people paid for their travel, but cemented contactless in the vocabulary of the masses. We were focussed on getting contactless bank cards to work for pay-as-you-go (PAYG) transit payments. This was a significant undertaking since it had not been done before and the customer proposition included a fair-price promise. This fair-price promise required the contactless bank card solution to mimic the existing Oyster “capping” which allows customers to travel without knowing the tariffs, trusting that they will only be charged the best price they could have got had they bothered to research it all beforehand. It required adding contactless payment card acceptance to all TfL readers and the building of a bespoke back office to support this new Account-Based Ticketing (ABT) where no travel information is stored on the card.
Convenience is king in mass transit. And our task was to meet the demands of one of the world’s busiest transit environments but make it cheaper to operate. The long-term vision was that by 2018, Oyster cards would be migrated to use the ABT back office and the legacy Oyster system would be turned off. The Oyster brand would remain alongside bank cards for those not using bank cards, but the technology powering this, would be changed to be ABT.
TfL and Consult Hyperion worked closely with the payment schemes to define the process of card acceptance and with the UK Card Association to establish a harmonized set of rules to balance risk between TfL and the card issuers.
The system launched on buses in 2012 and on the rest of the TfL Oyster network in 2014. Later in 2016 the privately-run river buses were added.
Fare collection costs were reduced from 14% to less than 9% of fare revenue. In 2016, 34% of TfL PAYG journeys were made using contactless bank cards (56% were Oyster and 10% were paper tickets). Is this good, bad or indifferent? Well, this figure needs to be understood in context:
- Contactless bank cards were still rolling out. In 2015, less than half[1] of UK bank cards were contactless.
- Not everyone has a bank account. In 2015, about 5%[2] of UK adults were unbanked and half of these did not want a bank account.
- Loss of government subsidy and a mayor-imposed TfL fare freeze meant that the vision of turning the legacy Oyster system off had to be reconsidered. Existing Oyster users have no incentive to switch over to using their bank cards.
- Not all foreigners arriving in London are keen to use their bank cards since they may be subject to bank charges back home, making Oyster the better choice for them.
Despite these barriers to the uptake of contactless bank cards, by April 2016, 9% of all UK contactless transactions took place on TfL services.[3] By 2018 (year 4 of acceptance of bank cards on the full Oyster network), the percentage of PAYG journeys made using bank cards (or their emulations on phones or wearables) has risen from 34% to approximately 50%.
Consult Hyperion were uniquely qualified to help TfL deliver their ambition. Bringing in-depth knowledge and a heritage of working with the major payment networks and their detailed specifications for three decades, a solid understanding of proprietary transit technologies and practical experience of delivering innovative payment methods, outside of the retail community.
The team at Consult Hyperion is now involved across the globe working with transit agencies looking to emulate the success of London in their own cities. As well as Transport for the North in the UK, these projects have included working in countries where contactless success has outpaced the UK, such as Australia to territories where contactless payments are still emerging, like India and Colombia. Our US team has been working for a number of agencies who, today are developing systems capable of accepting contactless payment cards, even though issuance is less than 0.01%, in the hope that transit will drive banks to start issuing cards. There are early signs of success.
It is clear, that the success of TfL’s Future Ticketing Project has helped drive a sea-change in the payments and transportation industries that can save money in one industry and drive transaction volumes up in another. With our help, we are confident this success will continue.
TLS, DSS, and NCS(C)
As I was scanning my list of security-related posts and articles recently, my eye was drawn by the first sentence of an article on (Google security engineer) Adam Langley’s blog, indicating that Her Majesty’s Government does not understand TLS 1.3. Of course, my first thought was that since HMG doesn’t seem to understand the principles of encryption itself, it’s hardly surprising that they don’t understand TLS. However, these aren’t the thoughts of an understandably non-technical politician but instead those of Ian Levy, the Technical Director of the National Cyber Security Centre at GCHQ – someone you’d hope does understand encryption and TLS. Now normally, I would read this type of article without feeling the need to comment. So what’s different?
Well, following the bulk of the article discussing how proxies are currently used by enterprises to examine and control the data leaving their organisation, by in effect masquerading as the intended server and intercepting the TLS connection, is the following throwaway line:
For example, it looks like TLS 1.3 services are probably incompatible with the payment industry standard PCI-DSS…
Could this be true? Why would it be true? The author provided no rationale for this claim. So, again in the spirit of Adam Langley, “it is necessary to write something, if only to have a pointer ready for when people start citing it as evidence.”
Adam’s own response – again following a discussion about how the problem with proxies is their implementation, not with TLS – is that
…the PCI-DSS requirements are general enough to adapt to new versions of TLS and, if TLS 1.2 is sufficient, then TLS 1.3 is better. (Even those misunderstanding aspects of TLS 1.3 are saying it’s stronger than 1.2.)
which would seem to make sense. Not only that, but
[TLS 1.3] is a major improvement in TLS and lets us eliminate session-ticket encryption keys as a mass-decryption threat, which both PCI-DSS- and HIPAA-compliance experts should take great interest in.
In turn, Ian follows up to clarify that it’s not TLS itself that could present problems, but the audit process employed by organisations
The reference to regulatory standards wasn’t intended to call into question the ability of TLS 1.3 to meet the data protection standards. It was all about the potential to affect (badly) audit regimes that regulated industries have to perform. Right or wrong, many of them rely on TLS proxies as part of this, and this will get harder for them.
So that’s alright. TLS 1.3 is not incompatible with PCI DSS. So what is the problem? Well, helpfully, Simon Gibson outlined this in 2016:
…regulated industries like healthcare and financial services, which have to comply with HIPAA or PCI-DSS, may face certain challenges when moving to TLS 1.3 if they have controls that say, “None of this data will have X, Y, or Z in it” or “This data will never leave this confine and we can prove it by inspecting it.” In order to prove compliance with those controls, they have to look inside the SSL traffic. However, if their infrastructure can’t see traffic or is not set up to be inline with everything that is out of band in their PCI-DSS, they can’t show that their controls are working. And if they’re out of compliance, they might also be out of business.
So the problem is not that TLS 1.3 is incompatible with PCI DSS. It’s that some organisations may have defined controls with which they will no longer be able to show compliance. They may still be compliant with PCI DSS – especially if the only change is to upgrade to TLS 1.3 and keep all else equal – but cannot demonstrate this. So what’s to be done?
Well, you could redefine the controls if necessary. If your control requires you to potentially degrade, if not break, the very security that you’re using to achieve compliance in the first place, is it really suitable? In the case of the two example controls above, however, neither of them should actually require inspection of SSL traffic.
For the organisation to be compliant in the first place, access to the data must only be possible to authorised personnel on authorised (i.e. controlled) systems. If you control the system, you can stop that data leaving the organisation more effectively by prohibiting its access to arbitrary machines in the external world. After all, you have presumably restricted access to any USB and other physical storage connectors, and you hopefully also have controls around visual and other recording devices in the secured area. It is difficult in today’s electronic world to think of a situation where a human (other than the cardholder) absolutely must have access to a full card number without (PCI DSS-compliant) alternatives being available.
So TLS 1.3 is a challenge to organisations who are using faulty proxies and/or inadequate controls already. It certainly doesn’t make you instantly non-compliant with PCI DSS.
Given this, we, as humble international payments security consultants, are left puzzled by the NCSC’s line about TLS 1.3 and PCI DSS compatibility. At worst, organisations need to redefine their audit processes to use the enhanced security of TLS 1.3, rather than degrade their security to meet out of date compliance procedures. But, of course, this is the type of problem we deal with all the time, as we’re frequently called in to help payment institutions address security risks and compliance issues. TLS 1.3 is just another tool in a complex security landscape, but it’s a valuable one that we’re adding to our toolkit in order to help our clients proactively manage their cyber defences.
Crossing continents for knowledge sharing
Chyp believes that collaboration and knowledge sharing across markets can help the advancement of the industry and this is particularly true in transport ticketing. For example, we have found that our work for TfL with a large population and high journey count is not all directly applicable to smaller countries who cannot make such significant investments in infrastructure to serve small populations.
Recently, we have been working for MMRDA in Mumbai, India. While the environment is very different in some respect, compared to the UK, they have large passenger numbers and administer a system that makes extensive use of private transport operators, two factors similar to Transport for the North (TfN).
Sharing knowledge not only helps speed to market of deployments but creates a trusted environment and one with credibility. MMRDA asked Chyp to facilitate meetings for them in the UK with transport operators and suppliers in order that they could learn from those who have done it before or are planning to deliver a similar project. The result was a tour of the UK starting in London and taking in Transport for the North. The picture above shows the meeting which was held in Leeds and included presentations from:
Transport for the North
- Alastair Richards (Director Integrated and Smart Travel (IST))
- Jo Tansley Thomas (Programme Manager (IST))
- John Elliott (ABT Back Office Requirements Team Lead (Consult Hyperion))
MMRDA
- Ashish Chandra (PWC India)
Partnerships are hard to form. We hope that MMRDA will benefit from the organisations they met and their sharing in experience planning and deploying ABT in complex environments in the UK, remembering that differences can be as important to learn as similarities.
World payments
Wow. One of my very favourite companies has always been Worldpay. They have a very special place in my heart because many years ago, when they were first starting out, I was sent up to Cambridge by a client to go and meet them and assess what they were doing. As a junior deputy assistant under-consultant, I went to take a look at the technology they had put together to see whether it worked as advertised. Which it did. I returned to our client and told them that the Worldpay had no future, because all they’d done was to plug a PC into the Internet on one side and to a NatWest Streamline acquiring service on the other side. This seemed like a fairly trivial integration to me so my assessment was that all the banks would do it and that WorldPay would not be able to sustain a margin. Last week, Worldpay agreed to a possible offer from Vantiv that would value the combined group at more than NINE BILLION QUID, proving conclusively that you shouldn’t listen to me about anything. Anything at all. Still, it was a useful lesson in banking strategy for me in those long ago days: just because all of the banks could have connected their acquiring services to the internet in about a day didn’t mean that they would, and when they did it didn’t mean they’d make a success of it. Worldpay have done that in spades.
Driven by the inexorable shift from cheques and cash to cards and digital payments, Worldpay’s revenues have risen over 50 per cent and its operating profits have more than trebled since it was sold for £2.5bn by Royal Bank of Scotland seven years ago.
I remember visiting Vantiv in Cincinnati around twenty years ago when they were still Fifth Third Processing, the second biggest acquirer in the US (I can’t remember why I was there but it may have been something to do with smart cards). The combined group will be the biggest merchant acquirer in the world and will give Vantiv access to Worldpay’s global markets and e-commerce business, which is why it makes good business sense.
The deal marks a further step towards the industry’s consolidation. Last year, for example, Global Payments, the sixth-biggest American acquirer, bought Heartland, a smaller rival, for $4.3bn in cash and shares. TSYS bought TransFirst for $2.4bn. Vantiv snaffled Moneris USA, the American arm of a Canadian payments-processor, for $425m.
Apart from being one of my favourite companies, Worldpay are also one of Consult Hyperion’s favourite clients. While the newspaper reports focused on Worldpay’s scope and scale, it is their R&D operation that is the focus of my attention. Worldpay have been making serious investments in the next generation of payment services, looking beyond the current card infrastructure into the future of immediate, invisible and invulnerable payments. Some of you may have seen the Internet of Things (IoT) demonstrator that we helped to build for them last year (we were one of the sponsors of the brilliant WorldPay IoT hackathon) and the virtual reality payments demonstrator that we helped to build for them this year.
In my opinion (and in the opinion of a great many other people as well) however, the most exciting project that we have been chosen to support and the most important new product to come out of their R&D lab for a long time was launched at Money 2020 in Copenhagen last month. It’s called My Business Mobile, and it means that merchants can download a POS terminal to the their mobile phones and start accepting contactless payments without any additional equipment. No plugs, no dongles, no fuss.
Nick Telford-Reed, director of technology innovation, at Worldpay comments: “The pilot scheme we’re running in London will give cash only businesses the opportunity to catapult themselves into the 21st Century by taking contactless card payments on the go. But this is really only the beginning.
When Nick presented at this year’s Tomorrow’s Transactions Forum (which WorldPay were kind enough to sponsor again) he painted a pretty compelling picture of the future of retail payments, talking about the “friction free” payment experience of the future. This is a definitely a step in that direction. Every coffee shop and kebab van that wants to take cards but either doesn’t want to, or can’t, rent and install a traditional point-of-sale terminal can now just use a smart phone. And customers can use the contactless cards in their pockets or the mobile phones in their hands (the phones will accept payments from ApplePay and AndroidPay) to pay quickly and conveniently. They can even use their Apple Watch, as you can see in this video featuring Consult Hyperion’s Gary Munro and Worldpay’s Kevin Gordon. As contactless payments continue to displace cash from the retail point of sale in the UK (my guess is that contactless transactions are currently about third of all retail transactions and the latest figures show that they account for more than half of all card transactions) this gives WorldPay a solution that can really scale.
As MasterCard said in their press release about this, making it easier for small and micro businesses to accept digital payments may spur additional growth for them and enable an additional 40 million of these merchants globally over the next four years and will undoubtedly generate significant volume and large numbers of smaller transactions.
So what’s so innovative about this? After all, we’ve been working on mobile contactless applications for years, using phones to read cards for a decade or so (here’s my favourite app: a demo of a nightclub ticket that you put your mobile phone number into). But it’s a long way from reading a card to having an operational service that complies with scheme rules, has a decent UK, has. It was really intellectually challenging to create a POS terminal running on a user device. Therefore the security architecture is absolutely critical to the success of the product. The guys and gals in Consult Hyperion’s Hyperlab have been building, testing (and breaking) secure mobile apps for a very long time. We know all about doing this efficiently and cost-effectively.
One more point. Helping these merchants to move from cash to cards means that they will have data that they never had before. The future, as I wrote after this year’s Merchant Payment Ecosystem conference in Berlin, is about replacing the fees from processing with the fees from value-added services. Most observers would agree that these value-added services are real and if the merchant acquirers can transform into Merchant Service Providers (MSPs, as Ron Kalifa, the vice-chairman of Worldpay, called them at MPE), are able to deliver them then there will be a ready market. But these kinds of value-added services based on data analysis and artificial intelligence and machine learning and all that sort of thing are voracious consumers of data, making this above all a scale business. The bigger players with more data at their fingertips ought to be out to deliver services that merchants value and this will be an area of vigorous competition in coming years, a competition that Vantiv/Worldpay look well placed to compete in.
Cards vs non-cards or cards and non-cards?
A payment scheme isn’t just a data switch that connects consumers, banks, merchants and retailers. If it was, there wouldn’t be any, because we’d all just use the internet instead. There are rules that need to be in place to make a scheme work in the mass market, to protect the participants and to fairly distribute liabilities. Hence when I saw this interesting comment about the opening up of the European payments marketplace under PSD2, in a discussion about Google wallet at the recent Google I/O conference, I did think that it perhaps underestimates what it takes to create a new consumer payment scheme:
For now, the service is linked to a user’s credit card, but not for long (at least for European users), Daniel Döderlein, CEO for payments systems provider Auka, told Bank Innovation. “Once Google’s able to go to direct to account they will cut out the cards companies and to some extent, the bank,”
From Would You Like to Set Google As Your Default Financial Institution? | Bank Innovation
This resonated with a story that I heard last year and mentioned to a few of our clients in seminars and workshops. A friend of mine was on a study tour of the US during which he visited a number of different technology companies as well as a number of different technology users in a group of related industries. He told me that the whole time he was in the US, the only people who had asked him about PSD2 came from Facebook and Google. Not from banks, not from retailers, not from payment processors and not from card issuers. Yet, as I think comes over in our recent webinar on threats and opportunities, PSD2 is a fundamental driver for all of their strategies for the foreseeable future.
When my friend came back from California with his tale of PSD2 indifference, I remember thinking at the time that it might be an indication that not all of the participants in the payment marketplace had fully evolved their open banking strategies. Hence I explained to him that as PSD2 was going to completely change the way in which consumer data is managed by banks, it was natural that banks had no strategy for dealing with it whereas people who sell consumer data for a living (e.g., Facebook and Google) would undoubtedly have already created and explored a number of different scenarios and set a strategy to exploit the changes.
Is that rather dramatic Google I/O comment justified though? Is it right that once the banks are required to open up their APIs and are forced to allow third parties to obtain account information, instruct payments and obtain confirmation of available funds, will those third parties cut out the “card companies”? In other words, is open access bad news for, to choose the obvious examples, Visa and MasterCard? Well, that depends. I remember answering this question a couple of years ago at a conference by saying that if the people that Consult Hyperion were working for at Visa and MasterCard were stupid, then it was a threat. But since the people that we were working for at Visa and MasterCard were not at all stupid, and could read the newspapers just as well as we could, I thought that on balance the new infrastructure would present an opportunity. At the time, of course, I couldn’t have foreseen that MasterCard would step up to the plate and pay $1 billion for VocaLink so quickly, thus ratifying my conclusion!
“Somehow this takeover didn’t make the news headlines, but mark my words it was one of the most significant events in the evolution of the UK payments industry since Reg Varney got a tenner out of that first ATM in Enfield half a century ago. It’s a significant milestone on the road to #cardmaggedon, and it’s not only me who thinks this.”
via MasterCard and VocaLink is a big deal | Consult Hyperion
The reasoning behind our general advice to clients at that time was that the network itself, the technological component of a scheme (the interfaces and switches and connections) is easily replicated, but the non-technological components (the “3Rs” of rules, rights and relationships) are much harder to create and manage. This where Visa and MasterCard have half a century on the competition. I saw this view echoed in a recent magazine article.
It is felt that as the distinction between cards and other forms of payments (e.g. credit transfers) breaks down, the management experience of card schemes positions them well to extend into these other payment methods rather than being replaced by them.
What it comes down to is that sending money from account to account over instant payment rails is ultimately cheaper, quicker and simpler than messing around with 16-digit PANs, authorisation networks and settlement files. As many industry observers have pointed out, in the long run the “push” payments will win. However, sending the money around is only a very small part of a real-world, mass-market, effective payment infrastructure. The rules, rights and relationships may well be simpler than in the world of the 16-digit PAN but they still have to be there. Someone still has to set the messaging standards, define the format of the associated data, draw up merchant agreements and so on. At the excellent Merchant Payment Ecosystems conference in Berlin earlier this year, I chaired a terrific panel session that touched on this issue.
The key concept that came out of this discussion, that the traditional merchant acquirer will transmute into a Merchant Service Provider (MSP), fits within this narrative. I can see that merchants want value-added services, a great many of which depend on collecting and analysing large quantities of data, rather than just “cost plus” payment processing. What’s more, as the cost of payments heads toward zero, nodes in the value chain will have to provide those value-added services or be bypassed.
So, will Visa and MasterCard be bypassed by open banking? If they do nothing, then yes. Facebook, Google, Amazon, Alipay and others will simply go direct to consumer payment accounts via APIs and payments will begin to drift away from the 8583 rails put in place over many years. But they won’t do nothing.
Canadian cash and credit
As I’m in Canada, I thought I might mention that a detailed investigation into the cost of payments at POS just released by the Bank of Canada shows (absolutely as I would have predicted given the scale and dynamics of the Canadian market) that
Debit cards are the least costly in terms of total resource costs, followed by credit cards, whereas cash is the most costly.
No surprise at all. What is surprising, however, is that the total cost of payments in the Canadian market is estimated at 0.78% of GDP (compared to 0.54% for Australia, which I would have e thought a reasonable comparison). I haven’t read every single page of the report but I suspect that the inefficiency must stem somewhat from the size of the country (distributing and collecting cash is expensive) and but mainly from much higher credit card use than in (say) the UK.
Me eating poutine in Montreal.
According to our Canadian cousins, cash only has the lowest cost to society for POS transactions below approximately $6, which means as far as I can see that it is irresponsible to produce banknotes above $10 since by doing so the central bank is making the economy less efficient. (I’m not familiar with their charter but this cannot be one of the goals.) It’s time for action.
The main point I wanted to make about the Canadian payment environment is how it illustrates the difference between incentives based on private costs compared to what is best for the economy. We cannot say what is the “best” payment mechanism since that varies by perspective. Indeed, as the report says:
If stakeholders make their payment choices based on their private costs alone, consumers would prefer to use credit cards, while retailers and financial institutions would prefer debit card payments.
But what we might say is that the best solution for society is the mechanism with the lowest total social cost, and that’s PIN debit (soon to be overtaken by credit push I expect). Hence that is what society should encourage. But it doesn’t: it allows a suboptimal payment system instead. The big winners with this arrangement are the credit card issuers because customer use credit cards to obtain rewards at the expense of other customers who are using debit cards and even cash. In Canada this results in unusually high credit card use because people just love their rewards, such as frequent flyer miles. These, incidentally, have turned into a huge business.
“Airlines are earning upwards of 50 percent of [income] from selling miles to a credit card company, which we believe is a great business to be in”
From Bloomberg
Scatchamagowza. Half? Seriously. Non-credit customers are subsidising a massive programme of wealth transfer to well-off people who like to fly a lot! I’m not complaining, by the way. I use my Amex card with frequent flyer rewards (well, Avios) all the time. And I’m clearly not the only Amex customer who prefers this kind of deal.
American Express says that Delta SkyMiles accounted for approximately 7 percent of its business last year and approximately 20 percent of its outstanding credit card loans as of the end of the year.
Do Loyalty Programs Make More Money for Airlines Than Flying?
It’s amazing what a big business credit card miles have turned out to be. Every time that the person in front of me at the supermarket pays using cash or a debit card I feel like hugging them (I don’t, of course, because I’m English) and thanking them personally for their selfless contribution to my cashback, miles and Uber credits.
Why can’t digital identity be easy, like payments?
I have often seen payments (especially the card networks) used as an analogy for digital identity. In fact, I brought up the analogy myself at the fun OIX meeting in Amsterdam last Thursday. Certainly when you look at something like GOV.UK Verify there are some striking comparisons:
- A central scheme with a brand, rule book, governance body and switching infrastructure (i.e. Verify itself),
- Issuers (i.e. the private sector identity providers), and
- Merchant acquirers (well merchants anyway, in the form of government relying parties).
We have to keep reminding ourselves that these card networks did not appear overnight. What we have today is a result of 60 or more years of evolution. Admittedly the pace of change has increased significantly but we need to recognise it often takes time to build scale and gain adoption. There are special cases of course. PayPal, for example, grew out of a significant pain point within eBay – which gave it immediate scale.
There is however one key difference between payments and identity. You cannot sell stuff online without a means to receive payment and normally that means integrating with a payments scheme that works for your customers. You can however sell stuff without leveraging an external identity scheme – you just give the user an ID and password specific to the service. This is however bad news for users – resulting in the fragmented personal data and password mess we find ourselves in today. There needs to be an incentive for merchants to do something different to this. Perhaps merchants need a big stick? Like GDPR for example. Merchants are going to have to be a lot more careful with personally identifiable information in the future. One thing they could do is use an identity provider to hold that data and in the process reduce their risk.
Individuals also need to realise that their personal data is valuable, just like their money. That is going to require some education because so far they’ve been taught to share data without considering the consequences.
In the UK, arguably the most significant digital identity initiative over the past 5 years has been the GOV.UK Verify programme. They are at the stage where they need to grow. The scheme is up and running and so they are now busily signing up citizens and services. It is a critical point in its development. We are very pleased that David Rennie who leads industry engagement on the programme will be taking time out of his busy schedule to join us at Tomorrow’s Transactions. Come along and find out how it is going.
You can also get added to our mailing list here.




