Loss-sharing framework for banks, telcos should keep pace with evolving scams, say industry watchers
Yong Jun Yuan
THE proposal for financial institutions (FIs) and telecommunication providers to share responsibility for phishing scam losses is seen as a good first step, but industry watchers have said the framework will need to evolve as more sophisticated scams emerge.
Their reactions follow Wednesday’s (Oct 25) release of a consultation paper by the Monetary Authority of Singapore (MAS) and the Infocomm Media Development Authority (IMDA). The document lists the duties of FIs and telcos in mitigating the risk of consumers falling prey to phishing scams.
The proposed approach places the responsibility on the banks to bear the full loss first, followed by the telcos.
If both are found to have fulfilled their duties, the proposed framework leaves consumers to bear the loss.
Yam Wern-Jhien, director at Setia Law, said the proposed framework is a “welcome rationalisation” of the existing state of affairs, under which losses are compensated based on the goodwill of banks.
The “waterfall approach” adopted by the framework should incentivise institutional players to ensure that the necessary safeguards are in place, he said.
However, consumers will need to be more vigilant as FIs and telcos will now be less likely to offer the “safety net” of goodwill payments, he added.
Melvin Yong, president of the Consumers Association of Singapore, said the proposed framework is “reasonable and sound in apportioning responsibilities” between the parties involved in scams.
“It will, hopefully, expedite the reimbursement process for victims who rely on (their lost) savings for their livelihood,” he said.
He added that there is room for the proposed framework to expand its coverage to include malware scams, which have been on the rise.
The proposed framework is designed to cover phishing scams that happen digitally. Malware scams and other scams – such as investment or love scams, in which victims authorise payments to scammers – are excluded.
Police statistics show that between January and August, 1,400 victims lost at least S$20.6 million to malware scams. Almost half of these victims fell prey to such scams between July and August.
The way Kennedys Legal Solutions partner Robson Lee sees it, the proposed framework is a “Version 1.0” of the set of solutions addressing the burgeoning problem of phishing scams.
Therefore, the duties expected of FIs and telcos should be continuously fine-tuned to meet the standards of the proposed framework, and combat increasingly sophisticated scams.
“The proposed Shared Responsibility Framework should not be perceived as an immutable concrete set of solutions to address a dynamic and mutating problem,” he said.
With malware-enabled scams that cannot be contained by industry stakeholders within the local jurisdiction, it would also be premature to institutionalise a clear framework to address them, he noted.
Lee cautioned that the proposed framework may raise consumers’ expectations of the reliability of the systems and the technological capabilities of FIs and telcos.
“Any system failure or malfunctioning on the part of the FI or telco in a phishing scam may invoke a cathartic response and raise more public ire to start naming and blaming,” he said.
On Oct 14, DBS’ and Citibank’s digital-banking services were disrupted after a technical issue at an Equinix data centre caused its data halls to overheat.
The annex of the consultation paper cites a case study in which an FI that fails to make a “kill switch” option available to consumers at all times could find itself liable for scam losses. The “kill switch” is a self-service feature for consumers to report and block unauthorised access to their accounts.
KPMG financial-services advisory partner Grace Tan said the proposed framework achieves the objective of providing an appropriate level of consumer protection, without being overly punitive on FIs and telcos.
“It remains clear that FIs and telcos have a duty to ensure consumer monies are safeguarded; they need to demonstrate that they have put in place the requisite internal controls to detect and prevent such scams,” she said.
She suggested that FIs and telcos may become more cautious in offering new payment and banking services, or of entering into new partnerships with digital enablers under the proposed framework.
FIs that will be regulated under the proposed framework include banks, non-bank credit card issuers, finance companies and relevant payment service providers as defined in MAS’ E-Payments User Protection Guidelines.
TRENDING NOW
He built the Vingroup empire. Now South-east Asia’s richest man is handing some key roles to his sons
DBS wants to be ‘Asian bank for Asians’ rather than global bank: CEO Tan Su Shan
Ex-Goldman trader builds mini pod shop in Singapore with offbeat hires
Asean’s challenge is to become resilient against global geopolitics: former Indonesia trade minister