Overview of ATM Payment systems and Audit functions



Similar documents
Follow these five steps to make switching to Peoples First Savings Bank easy and hassle free:

We believe First Data is well positioned to take advantage of all of these trends given the breadth of our solutions and our global operating

BANKS AADHAAR ENABLED PAYMENT SYSTEM

VISA INTERNATIONALATM-CUM-DEBIT CARD. Your Visa International ATM-Cum-Debit Card brings to you convenience for your daily transactions.

SCHEDULE OF RATES AND CHARGES - CURRENT / SAVINGS ACCOUNTS (J$ TRANSACTIONS) RATES & CHARGES

Guidelines for Cooperative banks for implementing Payment Systems along with brief outline on Procedures

Euronet Software Solutions ATM Management System Maintain and Expand Your Automated Service Offerings with a Secure, Flexible and Powerful Solution

Service Level Agreement. Definitions

Reloadable Visa Debit Card. These are your Reloadable Visa Debit Card Terms and Conditions.

University of York Policy on the Management of Debit/ Credit Card Data

ING Vysya Bank Forex Travel Card is a pre-paid foreign currency chip card that offers you a safe, secure and

Driving License. National Insurance Number

WORLD TRAVEL CARD TERMS & CONDITIONS

E-commerce. ICICI Bank offerings

Ridge Tower Building, Sixth Avenue, Ridge-Accra, Ghana, West Africa. P.O. BOX CT 1003, Cantonments, Accra. Telephone: , fax:

Core Banking Solution (CBS) IT Modernisation Project

STATE BANK OF PAKISTAN

Travel Card. Cardholder Frequently Asked Questions. June 2014 T.FQ.S E

Visa Student Card Terms and Conditions. These are your Student Card Terms and Conditions.

General card terms for corporate customers

360 Federal Credit Union Reloadable Prepaid Card Terms and Conditions

Personal Account. Pricing Guide. August how can we help you?

Credit card: permits consumers to purchase items while deferring payment

NATIONAL COMMERCIAL BANK JAMAICA LTD. SCHEDULE OF FEES AND CHARGES

Credit Cards CARD TRANSACTIONS AND YOU. Credit Cards. A consumer education programme by:

BANK OF BARODA (NEW ZEALAND) LIMITED (BOBNZ) VISA CLASSIC DEBIT CARD. User Guide

ATM FRAUD AND COUNTER MEASURES

American Express. Merchant Services. Grow your business With POS terminals from American Express

Music Recording Studio Security Program Security Assessment Version 1.1

Banking Supervision Policy Statement No.18. Agent Banking Guideline

Vishwa Yatra Foreign Travel Card (VYFTC)

University Policy Accepting Credit Cards to Conduct University Business

SyndicateBank Global Credit Cards EXTRA Power in your purse

FAQ on EMV Chip Debit Card and Online Usage

POLICY INOPERATIVE AND UNCLAIMED ACCOUNTS

Visa Reloadable Frequently Asked Questions. EMV Travel Card

Internal Control Guide & Resources

Payments Industry Glossary

RISK. Outsourcing Risk Management How to Focus on Controlling and Managing IT Vendors under RBI Guidelines

TERMS AND CONDITIONS FOR THE ICICI BANK INDIAN RUPEE TRAVEL CARD

Electronic Payment Schemes Guidelines

INTEGRATED POINT OF SALE PAYMENTS

EMP's vision is to be the leading electronic payments processing company in the emerging markets of Africa and the Middle East.

Liberty County School District Purchasing Card Procedures

ONPOINT COMMUNITY CREDIT UNION International Prepaid Card Terms and Conditions

Access your bank account anywhere, anytime

SOC 2 Report Seattle, WA (SEF)

HEC Security & Compliance

The following information was prepared to assist you in understanding potential Electronic Value Transfer terminology.

EFT solution NOMAD. NOMAD (BankservAfrica) INFORMATION

Electronic Fund Transfers Disclosure

Secure Financial Transactions Any Time, Any Place

Caribbean Electronic Payments

Make the right move.. and let A.J. Smith Federal Savings Bank... Make it Easy for You!

Operational Risk Publication Date: May Operational Risk... 3

Banking Basics 101. How to Manage Your Finances and Still Have Money Left Over For Pizza. Course objectives learn about:

Pricing Guide. All prices include VAT and are effective as of the 1 st January 2015.

Information Technology General Controls Review (ITGC) Audit Program Prepared by:

Ambit Card Management Card Management Solution Suite

RETHINKING CARDS BUSINESS. Erick Ho, Head of Payment Services, SunGard 17 September Break through.

3. Establish direct deposit with your new account. Send Attachment A to your employer so they can begin processing your payroll to your new account.

How does the EMV Travel Prepaid Card work?

MERCHANT SERVICES, LEASING AND OPERATING AGREEMENT. ( Blackboard ). In this Agreement, the words; BbOne Card means a stored-value account

Service Organization Control (SOC 3) Report on a Description of the Data Center Colocation System Relevant to Security and Availability

Empowering Retails with Electronics and Mobile Payment

THE EVERGREEN STATE COLLEGE

Customer Compensation Policy

Lesson Description. Texas Essential Knowledge and Skills (Target standards) National Standards (Supporting standards)

Payment systems. Tuomas Aura T Information security technology

Supply Chain Security Audit Tool - Warehousing/Distribution

Oriental Bank of Commerce

Merchant Card Processing Best Practices

UTAH STATE UNIVERSITY POLICIES AND PROCEDURES MANUAL

ANZ Credit Card Conditions of Use CREDIT CARDS

SUBJECT: SECURITY OF ELECTRONIC MEDICAL RECORDS COMPLIANCE WITH THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 (HIPAA)

AP 571 PURCHASING CARD COMMERCIAL CREDIT CARD PROGRAM

Code of Banking Practice and the Specific Code of Conduct

(vi) Cheque / Cash pickup fee: Rs.200/- (available in cities having Bank Alfalah branches)

Checklist. Internal financial controls for charities. Contents. 1. Self-assessment checklist

POLICY & PROCEDURE DOCUMENT NUMBER: DIVISION: Finance & Administration. TITLE: Policy & Procedures for Credit Card Merchants

FIGHTING FRAUD: IMPROVING INFORMATION SECURITY TESTIMONY OF JOHN J. BRADY VICE PRESIDENT, MERCHANT FRAUD CONTROL MASTERCARD INTERNATIONAL

IMPORTANT ACCOUNT INFORMATION FOR OUR CUSTOMERS from

The Merchant. Skimming is No Laughing Matter. A hand held skimming device. These devices can easily be purchased online.

The New BANKOMATIKO (MAESTRO) smart card is an

ELECTRONIC FUND TRANSFERS AGREEMENT AND DISCLOSURE

Customer s FAQs For Immediate Payment Service

Transcription:

Overview of ATM Payment systems and Audit functions Mr.Babu.V Nodal officer- Cashtree /BANCS shared ATM groups- ( ex-dgm, Information Technology,Bank of India)

ATM Machines: Physical and environment control Site preparation ( LAN/WAN connectivity, Electricity, UPS power etc). ATM interface with the Banks / vendors (Facility Service provider)switch (FIS/FSS/ Euronet/Opus etc) Environment control ( Air conditioners, lighting etc). Security ( Cameras-CCTV, Alarm, access control, Guard etc) Others (Power Gen set, Fire extinguishers etc) Agreements with landlord, rentals / deposits, licenses etc 2

Types of ATMs Two types of ATMs: ATMs, Cash Dispensor Cash loading -Front /back side, Printer etc Transaction movement from ATM/ATM switch /CBS Main ATM vendors : Diebold, NCR,Wincor Nixdorf (AGS infotech),triton (Cashtech), Nautilas( Hyosong Nautilas) etc -Certification of the ATM machines -Anti virus. Encryption. -EMV standard -Bi-lingual, Biometric, Baille system etc. -Solar Power driven ATMs 3

ATM functions Functions available in ATMs: Cash withdrawal/ Cash deposits / mini statement/ balance enquiry/ transfer of Funds between connected accounts. Multiple ( added values ) functions in ATMs, Mobile recharging Ticket booking(railways etc), Bill payments incl. utility Bills ( electricity, telephone, Mobile, Credit card payments etc Off line/on line/ sites Routing of transactions from ATM. 4

In sourced/ Outsourced models of ATMs What is outsourcing? In-sourcing? Total activities setting up an ATM: Site identifications/preparation/site rentals, deposits/ Installation of ATMs/ ATM Switch activities/security arrangements/ Network/ Interface/cash replenishments/ reconciliation/ Debit card creations/pin mailers/ready kit /MIS/ settlement/help desk/reconciliation of transaction entries/atm consumables/ UPS/Air Conditioning/ Guard /Security camera/name Board etc. What are the functions which are out-sourced? Precautions to be taken in outsourcing different activities from audit point.( SLA) 5

ATM operations Cash Replenishments and other related functions. Sorting of Usable notes, Insurance, Cash balancing etc What is hot listing? MIS/ Reports / Data extraction. What is card swallowing? And what to do and what are the measures? Complaint management, types of general complaints Reasons for rejections /short delivery in ATMs? Error codes in the ATM slip 6

ATM Switch ATM switch is generally kept in a DC. DR may be t another place. DR drill is important. Major switching applications providers: -IST,Base24,Euronet,Narda, Opus,S1 Network LL/ISDN/Wireless/MPLS etc, Redundancy. Environment AC, UPS, Fire extinguisher Physical-Access control, Logical-HSM/ routing of transactions. Incident management. 7

Audit of ATM process/security systems RBI defines the standards from time to time.( manner of transfer of funds/criteria for member ship etc ) System provider once obtained the certification of approval cannot change the approved payment process without consulting RBI. RBI has the power to call any returns/ documents/ information from the participants. RBI has the power to access any information. Power to enter the premises of the participants and inspect. Confidentiality of information with the system provider. 8

Contd RBI has the power to conduct or get conducted the audit of system providers/participants and to point out the discrepancies. Audit of the functioning of the participants can be done by RBI once a year either themselves or through authorized third party auditors Audit includes the processes (Technical, business and information security aspects) Necessary directives are issued to the participants for taking remedial action./initiate suitable steps to rectify the audit remarks Compliance on the audit remarks. 9

Applicability of Act to ATM vendors Any service provider interested /already undertaking the payment settlement functions need to obtain the RBI approval. RBI calls for explanation if necessary and gives certificate of authorization under certain terms and conditions. Many clauses are mentioned along with the certifications which is to be adhered to. If the activities are carried out through an ASP the service providers activity is also audited ( ATM groups) 10

Audit of approved participants RBI gives the list of approved payment system operators in their website in categories such as : -Central counter party - CCIL,(security,CBLO,fores segment etc) -Cards payment networks- like American express, Diners, Master card, Visa world wide for affiliation credit cards, debit cards, prepaid cards etc -Cross border Money transfer- inbound only. Western Union,Money gram, Bahrain finance co, UAE exchange centre etc etc ( 10 companies) -ATM networks like NPCI- NFS, Bank of India Cashtree/BANCS ATM groups, Federal bank-sharing of ATMs, Euronet services- Cashnet ATM group, PNB- Bilateral with Everest Nepal, SBI- SBI group ATM network, Agency clearing for SBI group, Group payment systesm, SVC bank-cache24 ATM sharing arrangement. -Prepaid payment instruments- Airtel M commerce- Stored value card wallet, ATOM Technologies-Prepaid instruments, Edenred (Accor servcies) Meal vouchers and coupons, ITZ cash card, Muthoot vehicle and Asset finance ltd, Nokia Mobile- Nokia Money, Paymate India-Gift mate, Sodexo SVC India pvt ltd- Meal and gift vouchers, UAE exchange & financial services ltd- Silver and Gold card, Zip card services- Zip cash coupons ( 17 companies) ( Details taken from RBI site) 11

Audit functions ATM switching /Network. - ATM switching transactions/ networking done by the ASP vendor/bank. - Process and operation documentation - Network diagram - switch reports. - Down time reports for the switch(planned/unplanned -Fire drill, biometric access to DC/DR, Environment( temperature, humidity, fire extinguisher etc),monitoring -Process/procedure followed for test environment and production environment till the completion of life cycle -Changes in the production /process set up

Audit functions contd Settlement of transactions/ Claims / Dispute management RBI guidelines on various aspects like settlement of claims,process documentation, MIS reports etc Declines /unsuccessful transactions-business/technical with response codes. Other details: List of authorized persons to the switch with rights( switch,server, application administration. submission of monthly reports to RBI. Agreements between the member banks and the agreement between the banks /ASP. 13

Fraud prone areas. How the ATM card is generated? who does it? What is a pin mailer? Preparation/mailing Issue and Activation of cards How to handle Debit card and the pin mailer? What is a ready kit? How it helps in avoiding frauds? What is a EJ? How the settlement takes place? 14

ATM security threats Recent developments: -Skimming the magnetic strips remains the dominant threat, gas/explosion /malware. -Logical threats Participation of Insider involvement (employee/past employee) -EMV standards/biometric access/seismic detectors for checking the vibrations etc. -White listing in the switch /ATM, instead of back listing. (Allow what we want than, allowing only the known threats ) -Access control list (ACL) gives an exhaustive definition of processes system resources,permitted in the system. 15

contd Physical attack: -Attack on ATM infrastructure ( can be avoided by anti skimming devices /security camera/closure of access doors etc Technology attack : -Stealing credit card details,take control of ATMs through malware etc. Criminals are preferring physical attack on the ATMs rather than on malware now a days. Insider attack generally through dormant accounts. 16

Any Questions? Thank you V. Babu Ex-Dy. General Manager, Information Technology Dept, Bank Of India babv@hotmail.com. Mob: 98206 08700 17