With my peers

Greyscale backing image
[Dave Birch] I went over to the FS Club to hear Forum friend Giles Andrews of Zopa give an update on their progress. He explained that one way of thinking about Zopa is as a bond market for consumers, but one that allows people to get a social return as well as a financial one. What an interesting description. And it was an interesting meeting. I won’t quote anyone, because the meeting was held under the Chatham House rule, but rather I will give some general impressions of the discussion…

We all know Zopa as P2P lending, a marketplace for money. It’s not that hard to set up a web site, though, so there must be more to it. What makes it work, seeing as their numbers have steadily climbed? Giles gave a few insights: he said, for example, that the core of Zopa’s business is their sophisticated credit rating model. I deduce it must be working tolerably well, since their bad debts over the last five years have averaged 70bp.

What I found particularly interesting was the relationship between Zopa and retail banks. In an odd way, the credit crunch came along at the right time for Zopa. Their lending went from £15 million in 2008 to £35 million in 2009 to £75 million this year. It seems to me that as public trust in banks collapsed (along with the interest rates) so more and more people turned to Zopa.

Recently Zopa have been lobbying for regulation of P2P Lending in UK.

[From New Datamonitor report on P2P Lending in the UK has some interesting analysis points « The Bankwatch]

This is true. In fact Giles has said that Zopa think they should be highly regulated and properly supervised. This would be good for them for two reasons: first of all it would create a structure for more competition, and more competition is good for innovation and excellence, and secondly it would further legitimise the P2P sector, thus bringing in more borrowers and lenders. It would also, presumably, bring in more competitors, which would be good for competition.

Criminal inconvenience

Greyscale backing image
[Dave Birch] It was identity theft week, or something like that, and since I’m about to start the CSFI’s 2010/2011 Research Programme into “Identity in Financial Services”, with support from Visa Europe, I’ve been thinking about the key aspects of the problem. For example: how well are current know-your-customer procedures working? After all, they are pretty stringent. To the point where the typical customer finds dealing with financial services organisations an absolute nightmare.

The ID banks require is getting beyond a joke. I’ve just been locked out of one of my online accounts, through no fault of my own, and they’re demanding I send them a certified document plus a utility/bank bill, but they won’t accept one printed online. Yet like many people, both for the environment and ease, I opt for paperless billing wherever I can, so I simply don’t get any printed statements anymore, leaving me at an ID disadvantage when banks refuse to count those as ID.

[From Martin Lewis’ Blog… | The bank ID farce: online accounts don’t accept online statements]

Still, I’m sure we’d all agree that it’s worth the massive imposition on customers, and the massive costs to companies, in order to crack down on ne’er-do-wells who are trying to defraud our banking system (at least, the ones who don’t work for banks). But since identity fraud appears to be at record levels, either these stringent controls are counter-productive (because only criminals will bother jumping through the hoops) or a total waste of money.

Drawing upon victim and impostor data now accessible because of updates to the Fair Credit Reporting Act, the data shows that identity theft impostors supply obviously erroneous information on applications that is accepted as valid by credit grantors. Thus, the problem does not necessarily lie in control nor in more availability of personal information, but rather in the risk tolerances of credit grantors. An analysis of incentives in credit granting elucidates the problem: identity theft remains so prevalent because it is less costly to tolerate fraud. Adopting more aggressive and expensive anti-fraud measures is extremely costly and jeopardizes customer acquisition efforts.

[From SSRN-Internalizing Identity Theft by Chris Hoofnagle]

Given the amount of trouble I find in accessing my own accounts — I tried to log in to my John Lewis card account this week and it asked me a password that I’d forgotten and when I followed the “forgotten password” link it asked me for a secret word or something that I didn’t even know I’d set — I can only assume that the total amount of time, effort and money wasted on this sort of thing across the financial services sector as a whole is enormous.

Share and share alike

Greyscale backing image
[Dave Birch] I’m not sure if it was a good idea to have National Get Online Week at the same time as National Identity Fraud Prevention Week and at the same time as announcing record identity fraud figures!

The National Fraud Authority (NFA) said fraudsters who stole identities had gained £1.9bn in the past year. Their frauds had affected 1.8 million people, the NFA estimated.

[From BBC News – Identity fraud now costs £1.9bn, says fraud authority]

As Philip Virgo notes, there appear to be some conflicting messages here and there may be some danger of a lack of strategic co-ordination.

Just after Martha had described her plans to the “Parliament and the Internet” conference last week, those at the session on “On-line Safety” discussed the need to bring the two sets of messages together lest they cancel each other out.

[From Mixed messages: “Get Online Week” v. “National Identity Fraud Prevention Week” – When IT Meets Politics]

I’ve scoured the coverage to find out exactly what it is that the “Get Online” campaign and the “Fraud Prevention” campaign plan to do about identity infrastructure and I’ve looked through the Cabinet Office “Manifesto for a Network Nation” (which does not mention identity or authentication even once) to find out what the British equivalent of the US National Strategy for Trusted Identities in Cyberspace is but I’m afraid I’ve come up with a bit of a blank (although a search of the Get Online Week website did turn up one article that mentioned identity theft in 2008). Perhaps I’m looking in the wrong places and a correspondent can point me in the right direction.

The UK national security strategy that was released last week does at least mention identity theft as a problem (it says that “Government, the private sector and citizens are under sustained cyber attack today, from both hostile states and criminals. They are stealing our intellectual property, sensitive commercial and government information, and even our identities in order to defraud individuals, organisations and the Government”) but doesn’t actually mention identity or authentication, nor does it put forward any suggestion as to what might be done about the problem.

SEPAarate development

Greyscale backing image
[Dave Birch] There is a looming deadline for SEPA compliance in the cards business: by 31st December 2010, all payments cards and ATM cards in the EU27 plus Norway, Switzerland, Iceland, Liechtenstein and Monaco must be EMV-compliant and all POS and ATM terminals in those countries must support EMV applications. This is extremely unlikely to happen as far as I (and other observers) can see. Currently Germany, Portugal, Italy and Slovenia have less than 80% of their cards converted and Romania, Greece, Bulgaria, Hungary, Spain, Portugal and Malta have less than 40% (according to Banking Automation Bulletin for September 2010). Apart from the UK & Ireland, France and Luxembourg, no countries have 100% POS compliance (in Germany it's not even 10%). Additionally, many countries do not have ATM compliance, including Germany, Belgium, Italy and Portugal.

Why the slow progress? And what does it mean for the future? Well, I was invited along to a meeting of experts to discuss the progress towards SEPA and eSEPA (SEPA for the internet and mobile payments), but unfortunately I've been told by the Commission that the discussions were confidential and so I can't comment on them here.

Subscribe to our newsletter

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

By accepting the Terms, you consent to Consult Hyperion communicating with you regarding our events, reports and services through our regular newsletter. You can unsubscribe anytime through our newsletters or by emailing us.