payments modernization company - evolvus · my own credit card fraud • acquire card details •...

31
www.evolvussolutions.com Payments modernization company Evolvus is committed to ensuring that financial institutions and their customers are able to stay current with business, regulation and technology changes across the payments ecosystem. 1

Upload: others

Post on 28-Jul-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

www.evolvussolutions.com

Payments modernization company

Evolvus is committed to ensuring that financial institutions and their customers are able to stay current with business, regulation and technology changes

across the payments ecosystem.

1

Page 2: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Topic

Risk mitigation in digital payment processing – changing trends and future challenges

2

Page 3: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Objective

• Risks • Case study • Payment system - Comparison • Best practices • Fraud patterns analysis • Advancement • Future of payments fraud prevention

3

Page 4: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Types of Risks

4

Corporate Risk comprises of

Market risk

Credit risk

Liquidity risk • Funding liquidity

Operations risk • Fraud risk • People risk • Other risks

Page 5: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Risk and Data

Scenario : Your customer’s data is with you

5

Data is core to all corporate risks

• More than necessary - Risk of accountability

• Less than necessary – Weak decisions, Traceability, and evidence collection issues

Quantum of data Financial and Non-Financial data

Location of Data

Scenario : Your data with vendor / service provider

Effect : You are vulnerable

Effect : You are accountable

Page 6: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Topic

• Data Integration

• ETL • Interfaces • Reporting

6

Case Study

Page 7: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Financial Hack - Union Bank of India

7

Page 8: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Payment Attack - Case Study

Bank Muscat • 2013 • Pre-paid cards • Limits changed • Cards cloned • ATM withdrawal • Friday evening

8

Page 9: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Data Hack - Zomato

• 17 million user records • Card and other payment

information intact • Data priced at $ 1,001.43 • Source of the breach –

Developer account compromised

9

May 2017 – Zomato hacked and customer information stolen

Page 10: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Payment Attack - Case Study

My own Credit Card Fraud • Acquire card details • Set up multiple card

payments • Siphon off in less than

20 minutes

10

Remedy • Card limits • Deny storage of card data • 2 factor authentication • Virtual card accounts

(need support by the issuing bank)

• Authorization based payments only

Page 11: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Operations Attack - Case Study

Corporate - Operational attack • Email intrusion • Social media intrusion • Domain intrusion • Website intrusion

Remedy • 2 factor authorisation • Email monitoring for phishing attack • Captcha login • Periodic password change • Professional malware protection measures • 3rd party certification of cloud solutions • Enterprise grade security for Wireless access points

11

Page 12: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Topic

• Data Integration

• ETL • Interfaces • Reporting

Payment systems Comparison

12

Page 13: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Global Payment trends

13

Details India UK USA

Name Immediate Payments

Faster Payments Real Time Payments

Year of launch 2010 2009 (limited) 2017 (soft launch)

Fund availability 15 seconds A few hours 15 seconds

Types of payment Credit transfer Credit transfer Credit push, request to pay

Limit Rs. 200,000 GBP 100,000 USD 25000

Participation All banks Limited banks Limited banks

Page 14: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Card payments - India vs US

14

Details India USA

Technology Chip and Pin Magnetic stripe, Chip and pin

2 Factor Mandatory (OTP) Only PIN

Limits Apply Apply

Fraud coverage Provided by bank Provided by bank / card provider

Usage level Limited Primary mode of non-cheque payment

Alternate mode IMPS, UPI, BBPS Zelle, Venmo (limited, private)

Page 15: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

IMPS and UPI

IMPS features • Authorization based payment • Limits apply • OTP based 2 factor authentication

UPI features • Authorization based payment • Limits apply • Account number & IFSC code not required • OTP based 2 factor authorization • Recipient authentication • Payment can be limited to claim amount • APIs available for integration

15

Page 16: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Topic

• Data Integration

• ETL • Interfaces • Reporting

Corporate Payments

Best Practices

16

Page 17: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Corporate payment – Best practices

• Maintain separate account dedicated for payment

• Use smart funding mechanisms for payments

• Maintain short limits on corporate cards

• Limit authorization to specific value for mandate based payments

• Integrate QR codes on UPI tags

17

Sending Account Receiving Account

Pool Account

Page 18: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Consolidate Payment

Consolidate payment management to one system

18

Corporate

Dealer

Consumer

• Supplier Payment • Set up debit authority • Frequency based

collection

ACH Network

UPI Network

Payment Consolidation

Internal systems

Internal systems

Internal systems

Page 19: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Consolidated Payment automation

19

NPCI

Bank 1 (Scenario 1)

Interface

Bank 2 (Scenario 1)

Flux Corporate

Bank 3 (Scenario 2)

Interface

Corporate Sender 1

Corporate Sender 2

Corporate Sender 3

Payment Consolidation

Flux Corporate

Interface

Page 20: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Topic

• Data Integration

• ETL • Interfaces • Reporting

Fraud pattern analysis Conventional method

20

Page 21: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Payment trend analysis – Suspicion analysis

21

Page 22: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Fraudsters approach

Artificial Intelligence

It is machine vs man

22

Page 23: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Topic

• Data Integration

• ETL • Interfaces • Reporting

Fraud pattern analysis Advancement

23

Page 24: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Cognitive Analysis and Prevention

24

Power of Artificial Intelligence • Case study : JP Morgan – Legal

document • Facebook : Polling campaigns • Twitter : Suggested handles to

follow

Page 25: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Technology Direction

• Unstructured data compatibility • API integration

• UK – API Banking : Case Study

• Emotion tracking • AI based analytics • Fraud intention vs Fraud detection

25

Page 26: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Digitization and Pattern analysis

26

Distributed Ledger for digital integration

Case : Ripple vs SWIFT Case : UAE Government

VS

Page 27: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Future of Fraud Prevention

Artificial Intelligence

27

Distributed ledger

Machine Learning

Page 28: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

+1(201) 993-5327 + 971 56 136 6821

[email protected]

Contact us

www.evolvussolutions.com

+ 91 9845218948

28

Page 29: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Global Payment trends

29

Details India UK USA

Name Unified Payment Interface

? ?

Year of launch 2017

Applicability Individuals & corporates

Types of payment Credit push and request for payment

Limit Rs 200,000

Participation All banks

Page 30: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Topic

• Data Integration

• ETL • Interfaces • Reporting

Retail Payments Best Practices

30

Page 31: Payments modernization company - Evolvus · My own Credit Card Fraud • Acquire card details • Set up multiple card payments • Siphon off in less than 20 minutes . 10 . Remedy

Retail Payment - Best practices

Use payment mechanisms that enable the following security features • Authorization based payment • Transaction limits and value limits • Account number & IFSC code not

required • OTP based 2 factor authentication • Use virtual cards (one time cards) on

internet

31