The broader scope of payment risk

Post on 22-Nov-2014

462 views 3 download

description

With risk and fraud commonly merchant chargeback risk comes to mind. But in a world of OBeP, SEPA Direct Debit, identity theft, alternative currencies and digital signatures, there is much more that goes into to a good risk assessment. What are the trends and developments in online payment fraud? And what is being done by the ECB and others to mitigate these risks?

Transcript of The broader scope of payment risk

Online fraud is still a big problem and as long as the number of online shoppers continues to grow, so will the number of fraud cases.

According to the European Central Bank there were 7.9 million cases of fraud with a value of 1.16 billion euros in 2011 of which 56%

took place in e-commerce.

European Merchant Services organizes the EMS RISK EVENT annually for retailers who are active in e-commerce and multichannel.

It is an excellent opportunity to increase your knowledge in the field of online fraud, risk management and advanced fraud prevention

and detection tools. We help you to stay ahead of online fraudsters and to protect your online business by sharing the knowledge and

experience of our fraud and risk experts, our customers and our partners.

Do you want to attend next year’s EMS RISK EVENT?

Please contact the EMS Marketing Department at T +31 20 660 3054 or send an email to marketing@emscard.com.

For more information visit www.emscard.com/riskevent

Follow us on:

tomorrow’s transactions today

Trends in online payments and online fraudThe broader scope of payment risk

4 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Jacob Boersma, senior consultant @ Innopay

• Senior consultant at Innopay

• Passion for information security & European Medieval Martial Arts

• 13 years of bridging gap between business & IT

− In e-identity: Dutch government PKI, eHerkenning

− In e-payments: iDEAL SEPA-compliant, FiNBOX, Masterclass Bitcoin

− In e-security: Masterclass Online Security

5 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

innopay. tomorrow’s transactions today

Online payment

E-invoicing

E-identity

Mobile payment

• Consulting in payments and transaction services

• Innovation, products, channels, users

• Independent, international

From Strategy to Execution

Bridging providers & merchants/corporates

Collaborative innovation & scheme development

tomorrow’s transactions today

Trends in e-payments

7 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

A brief history…

8 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Once upon a time: ‘traditional’ payment instruments, used in online contexts

1995 20152005

1. Making traditional payment products suitable for use on the internet

(...cards were never designed for the web…)

Vo

lum

e

9 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Dedicated payment methods arose

1995 20152005

1. Making traditional payment products suitable for use on the internet

(...cards were never designed for the web…)

2. Developing new payment products designed for use on the internet

3-party based challengers

3-partymodel

Vo

lum

e

10 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Followed by solutions from banks

1995 20152005

1. Making traditional payment products suitable for use on the internet

(...cards were never designed for the web…)

2. Developing new payment products designed for use on the internet

3-party based challengers 4-party based challengers

3. Developing new transaction services designed for use on the internet

(...e-invoicing, e-identity, e-mandate…)

3-partymodel

4-partymodel

Online Banking

Online Banking based ePayment

Vo

lum

e

11 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Now: new wave of new players,focused on mobile contexts…

12 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Trend 1[Payment methods follow users]

13 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Significant differences in local preferences

Market share of (cards) brands for various geographies

0

0,1

0,2

0,3

0,4

0,5

0,6

0,7

0,8

0,9

1

Switch

Solo

Laser

JCB

Invoice

iDEAL

Dankort

Cheque

Carte Bleue

American Express

Visa Electron

Bank transfer

Direct Debit

Can I pay with . ? Huh?

14 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Merchants helped by PSPs

15 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Trend 2[Offline and online are converging]

16 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Traditional retailers continue moving online…

17 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

…while e-commerce looks for offline presence

.com

19 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Mobile internet is taking ‘e’ everywhere

20 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Trend 3[‘m’ is the next ‘e’]

21 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Mobile internet will soon surpass the desktop

22 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Mobile important tool for shopping

• Mobiles used for purchases, information, also in-store

• Consumers willing to pay, payment methods lacking

0%

20%

40%

60%

80%

Mobile productsearch

Instore productsearch

M-commerce

Europe

Mobile phone usage, Q2 2012

23 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Trend 4[Checkout becoming more complex]

24 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Loyalty & marketing demand attention at checkout

25 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Payments integrated in advertising platforms

tomorrow’s transactions today

Contexts in e-payments: all about risk

27 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Why so many payment methods…?

28 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Payment methods address specific contexts

Built of many parameters• Relation

• Product

• Location

• Timing

PPay

RRisk

DDeliver

AAgree

RA

RD

RP

Context:

Relation (r)

Product (p)

Location (l)

Timing (t)

Source: Innopay, 2007

Risk

? ?

Key element is risk

29 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Perceived risk higher online

• Risk in each step of a transaction

• Online - less time between steps

• Requires much better risk analysis

Ordering | Order

Delivering | Delivery

Paying | Payment (via banks)

Contracting | Contract

Entity A

Procurement

Entity B

Sales

Tax returning | Tax return (via tax authorities)

Invoicing | Invoice

30 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Trends in payments and fraud

• Card fraud: organised crime

− Skimming

− Phishing

− Banking Trojans

• But banks are fighting back

− Blocking cards outside EU

− EMV standard

− 2-factor authentication online

• And so fraud is evolving…

31 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Trend 1: payment methods follow users

• From merchant initiated (credit card) to consumer initiated

• Trust in payment system shifts to trust in customer(relationship)

• E-identity solutions needed to know your customer

• Criminals know this too:

− Card theft Identity theft

• ECB proposal: SecuREpay

32 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Trend 2: offline and online converging

• Fraudsters look for the weakest link

• Offline methods to fuel online fraud (social engineering)

• Online gains go offline (pre-paid cards, gift cards)

33 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Trend 3: ‘m’ is the new ‘e’

• Smartphones 10 years behind in security

• Android malware on the rise

• Mobile convenience > security

34 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Trend 4: checkout becoming more complex

• It’s about more than just traditional money

• Identity, computing power (botnets), digital goods

• Alternative currencies: Bitcoin

− Exchange rate risk

− DDoS

− Anonymous payments… but guaranteed

− Regulation?

35 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Bitcoin in the news

tomorrow’s transactions today

Lessons for the future

37 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Understanding the context is key

• Payment: more than just cards

• Fraud: more than just payments

• Know your business, know your customer

• Mobile context: news risks, new chances

• Choose the right partners

38 EMS Risk event 2013 – The broader scope of payment risk – September 2013 © Innopay BV. All rights reserved.

Are you ready?

tomorrow’s transactions today

Thank you for your attentionContact

jacob@innopay.com , +31 6 150 76 228