亚开行-金融科技风险管理:政策和监管启示(英)-2023.5-12页
报告摘要
ADB Brief: Managing Fintech Risks: Policy and Regulatory Implications
Key Points
- Adaptive Regulation: Regulatory authorities must adjust regulations to keep pace with rapidly developing fintech providers, products, and services, driven by factors like the COVID-19 pandemic.
- Risk Mitigation through Flexibility: Updated, flexible licensing, regulation, and oversight of fintech providers are essential to minimize associated risks.
- Regulatory Sandboxes & Innovation Offices: Mechanisms like regulatory sandboxes allow regulators to monitor developments and conduct "test-and-learn."
- Innovation Enablement: Regulators need to develop new skills, capabilities, and an innovation-friendly organizational culture, aided by regulatory technologies (regtech) and supervisory technologies (suptech).
- Consumer Protection Updates: Financial consumer protection regulations must be updated to cover new fintech risks, including operational issues, cybersecurity, and consumer vulnerabilities.
- National & International Coordination: Effective management of fintech risks requires both national regulatory coordination and international cooperation.
Introduction
Fintech development has grown rapidly globally, lowering costs, boosting service variety, and expanding financial inclusion. However, this growth also necessitates enhanced risk management to address financial sector risks, operational risks, cybersecurity risks, and consumer risks.
The Evolving Fintech Landscape
- Fintech involves technology-enabled innovation with significant effects on financial services.
- Growth has been accelerated by events like COVID-19 and supportive regulatory changes (e.g., flexible KYC, higher transaction limits).
- Major areas include payments, lending, insurance, investment, and personal finance.
- Big Tech companies and mobile financial services (e.g., digital e-wallets) represent significant growth drivers.
Main Fintech Risks
- Financial Risks: Relate to credit or liquidity issues. Differentiated risk-based regulatory approaches are being developed.
- Operational Risks: Stem from deficiencies in internal processes, human error, IT system failures, inadequate capacity, third-party interconnectivity issues, and poor risk management/governance. Lead providers of examples:
- Chime neobank outages (2019)
- Lending Club scandal (fraud, weak internal controls)
- Cybersecurity Risks: Top threats include malware, identity theft, data breaches, denial of service, and attacks exploiting interconnected systems. Fintechs' smaller size makes them potentially more vulnerable.
- Risks to Consumers: Include improper product design, overindebtedness, lack of transparency, unfair treatment, data privacy concerns, weak complaint mechanisms, and fraud (illustrated with Venmo example).
Case Studies
- People's Republic of China (PRC): Implemented stricter controls on Alipay and Tenpay (higher reserve ratios, dedicated accounts, payment platforms) and issued a comprehensive Fintech Development Plan.
- Republic of Korea: Utilized a regulatory sandbox and open banking platform to manage risk while fostering innovation.
- Singapore: Employed risk-based regulation, regulatory sandboxes, and clearer payment service legislation (PSA).
- European Union (EU): Leverages PSD2 and GDPR to manage open banking and data privacy, emphasizing consumer protection.
- United Kingdom (UK): Focuses on strengthening consumer authentication and investor protection in fintech credit markets.
Policy Considerations and Recommendations
- Promote Regulatory Flexibility:
- Use regulatory sandboxes and innovation hubs.
- Ensure existing regulations accommodate new fintech developments.
- Build Regulatory and Supervisory Capacity:
- Develop technical capacity to understand and manage fintech-related data and risks.
- Utilize regtech (facilitates compliance) and suptech (enhances supervision) tools appropriately.
- Strengthen Oversight of Payment Service Providers:
- Implement risk-based regulations covering capitalization, consumer fund safety (escrow/trust accounts), AML/CFT, cybersecurity, and authentication.
- Establish Guidance and Requirements to Mitigate Risks:
- Bridge the gap between fintech activities and regulations; clarify licensing requirements, capital or reserve requirements (tiered), and internal controls.
- Update Consumer and Data Protection Regulations: Address product risks, data privacy concerns, and consumer harm mitigation.
- Promote Standardization: Develop open standards, especially for APIs and QR codes, enhancing interoperability and reducing risk.
- Foster National and International Regulatory Coordination: Coordinate to prevent regulatory arbitrage, ensure a level playing field, and address cross-border fintech and data privacy risks.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载