2013年-世界发展银行全球_Risk_Management_in_Mobile_Money___Observed_Risks_and_Proposed_Mitigants_for_Mobile_Money_Operators_22页_321kb
报告摘要
Summary of Risk Management in Mobile Money
Core Content
This document provides an overview of the risks associated with Mobile Money operations and proposes mitigants to address them. It outlines the different models of Mobile Financial Services (MFS), including the Bank Model, MNO Model, and Hybrid Model, and categorizes the risks into five main types: Systemic, Operational, Reputation, Legal, and Liquidity. The document emphasizes the importance of formalized risk management in the context of rapid growth and increasing customer adoption of Mobile Money services.
Main Products and Services
The following are the main products currently being sold within Mobile Money operations:
- Deposit and transact products
- Over the counter bill payments
- Intra-country remittances (both over the counter and via Mobile Transaction accounts)
- International remittances
- Savings products
- Lending products (secured and unsecured)
Each of these products introduces unique and shared risks that need to be managed effectively.
Mobile Financial Services Model Definitions
- Bank Model: A bank or licensed deposit-taking institution holds customer funds. The service allows mobile access to balance inquiries, transfers, and payments. It may also use agents for account opening and cash in/out services, with the bank assuming responsibility for these agents.
- MNO Model: A mobile network operator (MNO) provides payment services using its agent network, without requiring the customer to have a bank account. Funds are managed in segregated accounts with banks, and the MNO does not perform credit evaluation or risk management.
- Hybrid Model: Combines features of both the Bank and MNO models. Examples include:
- MNO/Bank Model: MNO provides payment services, while the bank offers formal financial products like savings and loans.
- Government Provider/Bank Model: A government-sponsored interbank clearing system, with the MNO providing communications and the government managing the payment switch.
Risk Definitions
The document defines five key risk categories:
- Systemic Risk: Risk that could cause collapse or damage to the financial system or lead to adverse public perception.
- Operational Risk: Risk that damages the ability of stakeholders to operate effectively or results in financial loss due to internal or external failures.
- Reputation Risk: Risk that damages the image of stakeholders, the mobile system, or specific products.
- Legal Risk: Risk of unforeseeable lawsuits, judgments, or contracts affecting MFS business practices.
- Liquidity Risk: Risk of not meeting cash obligations upon demand.
Key Risks and Proposed Mitigants
| Risk Name | Risk Description | Risk Impact | Basel Risk Category | Mitigant |
|---|---|---|---|---|
| Identity theft | Unauthorized replication of customer identity to conduct fraudulent transactions | Agent – Reputational; Bank – Reputational and Fraud; PSP – Reputational; Client – Fraud | Operational (L1 – Internal and External Fraud; L2 – Theft and Fraud) | Limit one account per customer, implement PIN protection, and educate clients |
| Impersonation of provider status | Unauthorized agents charge fees or access customer information | Agent – Reputational; Bank – Reputational and Fraud | Operational (L1 – Internal and External Fraud; L2 – Theft and Fraud) | Publish fee structure, consistent agent branding, and educate clients |
| Inability to transact | Delays or failures in message delivery through the network | Agent – Reputational; Bank – Reputational; PSP – Reputational; Client – Inconvenience | Operational (L1 – Execution, Delivery and Process Management; L2 – Transaction Capture, Execution, and Maintenance) | Disable SMS retry patterns, prioritize message delivery, and define clear transaction boundaries |
| Transaction delayed by network | Delays in balance updates due to message handling chains | Agent – Reputational; Bank – Reputational; PSP – Reputational; Client – Inconvenience | Operational (L1 – Execution, Delivery and Process Management; L2 – Transaction Capture, Execution, and Maintenance) | Shorten message paths, prioritize network components, and implement clear confirmation and rollback mechanisms |
| Insufficient points | Limited access to existing payment systems leading to low usage | Agent – Reputational and commercial; Bank – Commercial; PSP – Reputational and commercial | Strategic Operational (L1 – Execution, Delivery and Process Management; L2 – Vendors and Suppliers) | Roll out agents and payment points in a geographically harmonized manner |
| Lack of cash or electronic float | Agents unable to perform transactions due to insufficient funds | Agent – Reputational and commercial; Bank – Commercial; PSP – Reputational and commercial | Liquidity | Ensure agents are adequately funded and monitor systems for outages |
| Abuse of customer details | Unauthorized use of customer information for fraudulent purposes | Agent – Reputational; Bank – Reputational; PSP – Reputational | Operational (L1 – Execution, Delivery and Process Management; L2 – Transaction Capture, Execution, and Maintenance) | Collect original documentation quickly, vet agents, and implement strict customer detail management |
| Receipt of counterfeit notes | Agents lose electronic float due to counterfeit money | Agent – Commercial; Bank – Commercial | Operational (L1 – Internal and External Fraud; L2 – Theft and Fraud) | Train agents to detect counterfeit money |
| Burglary of cash float | Increased risk of theft due to large amounts of cash at agent outlets | Agent – Commercial; Bank – Commercial | Operational (L1 – Internal and External Fraud; L2 – Theft and Fraud) | Keep cash stocks low but sufficient |
| Split transactions | Clients circumvent AML restrictions by splitting large transactions | Bank – Fraud; Client – Fraud | Operational (L1 – Internal and External Fraud; L2 – Theft and Fraud) | Use AML software to flag suspicious transaction clusters |
| Spoofed transactions | Unauthorized notifications to merchants for cash withdrawals | Agent – Fraud; Bank – Commercial / Fraud | Operational (L1 – Internal and External Fraud; L2 – Theft and Fraud) | Implement end-to-end encryption, block SMS header spoofing, and train staff |
| Teller counting errors | Errors in cash transactions leading to financial loss | Agent – Commercial; Bank – Commercial | Operational (L1 – Execution, Delivery and Process Management; L2 – Transaction Capture, Execution, and Maintenance) | Ensure tellers are vigilant |
| Mobile money program fails to reach sustainability | Inability to sustain the program leads to sponsor withdrawal | Agent – Reputational and commercial; Bank – Reputational and commercial; PSP – Reputational | Strategic Operational (L1 – Execution, Delivery and Process Management; L2 – Vendors and Suppliers) | Ensure suitable growth pace |
| Too many short term deposits | Rapid growth attracts short-term deposits, increasing liquidity risk | Bank – Liquidity | Liquidity | Diversify products to include savings and short-term lending |
| Insolvency of the underlying float provider | Risk of financial difficulties in the bank holding customer funds | Agent – Commercial; Bank – Commercial; PSP – Reputational; Client – Loss of funds | Credit | Partner with responsible banks, diversify deposits, and monitor capital adequacy |
Key Information
- Mobile Money has seen significant adoption in countries like Uganda, Kenya, India, and Brazil.
- The rapid growth of Mobile Money operations highlights the need for formalized risk management.
- The document includes real-world examples, such as a $3.5 million fraud incident in Uganda, to illustrate the risks.
- The risk matrix is based on Basel Committee guidelines and is a working document that will be updated as new risks are identified.
- Risk management is not only about preventing fraud but also ensuring operational efficiency, customer trust, and regulatory compliance.
Conclusion
This document serves as a critical reference for Mobile Money operators, highlighting the importance of understanding and mitigating the risks associated with their operations. It provides a structured approach to risk management, emphasizing the need for clear roles, strong security measures, and effective communication with stakeholders.
试读结束,高清完整版pdf/doc/ppt,请点下载