Microenterprise Access to Banking Services Program General Security and Internal Control



Similar documents
Bangko Sentral ng Pilipinas. Bangko Sentral ng Pilipinas

Catching the Technology Wave: Mobile Phone Banking and Text-a-Payment in the Philippines

What are the kind transactions I can perform on Ecobank MobileMoney?

Money, fees and payment

MOBILE MONEY SERVICES PRODUCT GUIDE

BANK OF UGANDA MOBILE MONEY GUIDELINES, 2013 ARRANGEMENT OF PARAGRAPHS

HEAD OFFICE Information Technology Department

Technical Innovation for Expanding Outreach: Mobile Phone Banking in the Philippines

Overseas Filipinos Remittances: Regulatory Framework and Policy Directions By Ruth C. Gonzaga 1

SOLVE THE PROBLEM OF IDENTITY THEFT. An online, real-time solution for KYC, POPI, RICA and FICA compliance. May

FBZ General Information. Cloud Mobile Banking 13,10,14-5. Copyright FBZ All rights reserved

Introduction to the similar solutions and compare with the proposed system.

Int l Money transfer Receive on PocketMoni

Instant Money Transfer. VLE User Manual

SESSION 2: POLICIES AND REGULATION FOR FINANCIAL INCLUSION

Mobile phone based business models. Sundar Murthi CAB

Read this first. Copyright

Version 2.3. Operations Manual for Users, Agents and Merchants

RESERVE BANK OF MALAWI GUIDELINES FOR MOBILE PAYMENT SYSTEMS

Mobile Money User Guide. All you need to know

Systems Upgrade Information Frequently Asked Questions

How do I sign up for Mobile Banking? Login to consumer Online Banking and click on manage Mobile Banking settings. Follow the instructions provided.

Answers to Cardmember questions about Online Services and statement delivery.

Code of Conduct for Mobile Money Providers

Please make extra copies of the blank Independent Review Form and do not use your last blank one.

Online Banking Customer Awareness and Education Program

Words importing only the singular shall include the plural and vice versa.

Presented By Greg Baldwin

IMPORTANT ACCOUNT INFORMATION FOR OUR CUSTOMERS from

Mobile MasterCard PayPass UI Application Requirements. February Version 1.4

u.s. bank focus card Frequently Asked Questions The Focus Card What is the Focus Card? How does the Focus Card work?

How To Pay A Customer In European Currency (European)

Frequently Asked Questions (FAQs) IDBI Bank PayApt

OPERATING GUIDELINES FOR THE SPONSORSHIP OF ROSS PRINCIPAL SECURITIES ACCOUNTS FOR PESO DENOMINATED GOVERNMENT SECURITIES

PayPal Account User Guide

ReliaCard THE RELIACARD FREQUENTLY ASKED QUESTIONS

THE ROLE OF THE ANTI-MONEY LAUNDERING COUNCIL (AMLC) IN IDENTIFYING, FREEZING, CONFISCATING, AND RECOVERING PROCEEDS OF CORRUPTION

MOBILE MONEY FAQ.

Maldives Internet Banking and BML Mobile Banking TERMS & CONDITIONS. 1 Features and Benefits of Maldives Internet Banking and BML Mobile Banking

LANDBANK weaccess FREQUENTLY ASKED QUESTIONS

Application for Bank of Pontiac NetTeller Services Internet Banking and Bill Pay

D- To keep all the papers and documents justifying all transactions and operations for 10 years.

Personal Internet Online Banking Frequently Asked Questions

Frequently Asked Questions About Mobile Banking/Deposit App

Bank to Bank Transfer Application

PNC PayCard Program Cardholder Website How-To Manual

AML / CFT Anti-money laundering and countering financing of terrorism

Mobile & Connect. Cellphone Banking - Frequently Asked Questions. USSD &.mobi Namibia

Mobile Banking Applications Premier Members Mobile User Guide

A Simple How-To Guide for Your Banking Needs

Electronic Funds Transfer Disclosure Electronic Fund Transfers

BACK OFFICE MANUAL. Version Benjamin Bommhardt DRAGLET GMBH Bergsonstraße München - Germany

TERMS AND CONDITIONS GOVERNING THE ISSUANCE AND USE OF BANK OF COMMERCE CREDIT CARD

Online Registration PayPal Manual

PAYROLL CARD FREQUENTLY ASKED QUESTIONS

Your Step by Step Guide Follow these simple steps when using our alternative channels

IMPORTANT ACCOUNT INFORMATION FOR OUR CUSTOMERS from. State Bank 25 North Chestnut Ave New Hampton, IA (319)

Make your account KYC compliant

ELECTRONIC FUND TRANSFERS YOUR RIGHTS AND RESPONSIBILITIES

Anti-Money Laundering and Counter- Terrorism Financial Policy

MTN Mobile Money 2012

Broker-Dealer Concepts

How To Trade Us Stocks In Hong Kong

The University of Texas Rio Grande Valley. Network Security. Create a Virtual Private. Network (VPN) Connection. Network Security How-to:

CanMobile. CanMobile is mobile banking service provided by Canara Bank. It helps you to do following banking transactions:

POLICY OF AMLA - ANTI MONEY LAUDERING POLICY (STOCK BROKING INTERMEDIARY)

Frequently Asked. Questions. Cash Solution TM PIN Prepaid Debit Card

Frequently Asked Questions (FAQs) on Credit Cards

ELECTRONIC FUNDS TRANSFERS AGREEMENT YOUR RIGHTS AND RESPONSIBILITIES

e Z Want it? To use ezapps you ll first need to register for ezbanking and you can find those steps in the previous ezbanking section.

APPROVAL AND REGISTRATION OF FOREIGN LOANS AND OTHER RELATED TRANSACTIONS

LIVINGSTON COUNTY CREDIT CARD PROCEDURES

Uneasy about getting started? Not to worry. SageLink Credit Union has trained employees to help you every step of the way.

BANK SECRECY ACT POLICY

Section A: Definitions (What we mean) 1. You/the Customer : means the person who has registered for FNB Swaziland s Cellphone Banking service.

Business Online Banking Client Setup Form

Country Club Bank- Mobile Banking FAQs

FNB Zambia. Cellphone Banking for Individuals Terms and Conditions

FNB Tanzania Cellphone Banking for Individuals Terms and Conditions

An easy guide to bank services and charges. As of 03 October Issued by The Hongkong and Shanghai Banking Corporation Limited

IRD and Bank Account scheduled sessions at NZSki. As you are all aware you need an IRD (Tax) number to live, work and to receive wages in New Zealand.

Prairie State Bank & Trust ELECTRONIC FUND TRANSFERS YOUR RIGHTS AND RESPONSIBILITIES

STANDARD OPERATING PROCEDURES FOR BROKER OPERATIONS

Electronic Questionnaires for Investigations Processing (e-qip)

DBS Bank (China) Limited Debit Card Users Guide

Visa Debit Card Agreement and Disclosures

First Citizens' Federal Credit Union 200 Mill Road, Suite 100 PO Box 270 Fairhaven, MA

FNB Lesotho Cellphone Banking for Individuals Terms and Conditions

BANK OF JAMAICA 1 February Guidelines for Electronic Retail Payment Services

Online Banking Service Agreement

Transcription:

Microenterprise Access to Banking Services Program General Security and Internal Control Accreditation and Implementation Training On Mobile Phone Banking Services 1

Objectives Provide security features for mobile phone banking pursuant to the Bangko Sentral ng Pilipinas (BSP) - regulations on electronic banking circulars 240 and 269 To provide security and internal control requirements to secure mobile phone banking transactions; To provide overview on the roles and responsibilities of bank personnel involved in the implementation and operation of mobile phone banking services Define internal process control using audit trails and reports for all mobile phone banking transactions which includes compliance to Anti Money Laundering Act (AMLA) Regulate movement of electronic money to conform with existing Philippine Laws and standard banking practices 2

General Security Features A one-time over-the-air (OTA) registration is required by Globe Telecom to access the GCash services A downloadable GCash Menu is required for mobile phone banking transactions A Mobile Personal Identification Number (MPIN) is required for all mobile phone banking transactions All clients availing of mobile phone banking services must enroll at their respective bank branch. Customers are required to sign a Mobile Phone Banking Agreement listing all terms and conditions GCash uses Two-factor authentication process requiring customers to use their own registered mobile phone number (linked automatically to their SIM) and confirm their identity using a Mobile Personal Identification Number (MPIN) increases security for all mobile phone banking transactions 3

General Security Features (cont.) Know your customer (KYC) procedures are followed for all clients. All clients are required to submit proper identification (government issued IDs with photo) photographs and references and background checking when necessary AMLA requirements are followed for all covered and suspicious transactions Approved BSP mobile phone wallet and transaction limits are in place Accredited Banks are required to perform Users Acceptance Test (UAT) before offering mobile banking services to the general public 4

Multi-level Security Level 1 GCash wallet is linked to the mobile phone SIM. All balances and transactions are maintained within the Globe Telecom s GCash system Level 2 GCash wallet is protected with a four-digit Mobile Personal Identification Number (MPIN) which provides the same security offered by Automatic Teller Machines (ATMs). The MPIN is required for all mobile phone banking transactions. Note that the MPIN can be changed at anytime using the mobile phone Level 3- Confirmation Message is automatically sent following each transaction to both the bank and the client 5

Multi-level of Security (cont.) Level 4 - Suspension of Service allows customers to immediately deactivate or suspend their GCash services after calling the Globe customer service hot line (2882) using any landline or mobile phone Level 5 Menu Driven all banking transactions are required to download and utilize a Menu Interface to protect MPIN which is masked and not stored on the mobile phone Level 6 Customer Service Inquiries follow appropriate verification procedures to determine the identity of the GCash subscriber 6

Anti-Money Laundering Compliance GCash is BSP and AMLA compliant and it is recognized as an electronic payment platform under Monetary Board Resolution 116 Customer Verification procedures are in place for all GCash accredited partner establishments for converting money to GCash or vice versa All GCash accredited partner establishments are required to report covered and suspicious transactions to Anti-Money Laundering (AML) council on a monthly basis 7

Anti-Money Laundering Compliance (cont.) Globe/GXI also tracks and reports any covered or suspicious transactions to the AML council The GCash wallet is automatically limited to 40,000 pesos and daily and monthly transactions are automatically limited to 40,000 and 100,000 respectively. These limits are within the ranges set for ATMs transactions All GCash Cash-in/Cash-out transactions require a valid ID to be presented 8

Customer Verification Flow Diagram: REQUIREMENTS RECEIVE AND VERIFY Client fills-out enrollment and GCash service forms and present Valid Identification (ID) documents Bank in-charge/teller receives and verifies enrollment forms, GCash service forms, valid IDs and/or Cash CHECKING AND APPROVAL RELEASE/SEND RECORDING & POSTING Bank officer counter checks documents and approve the transaction Bank teller/in-charge sends copies of the forms, GCash and/ or Cash to the Client Bank records enrollment and post transactions in the system 9

Internal Control Features Client information are verified when using the banking services Audit trail is kept for all mobile phone banking transactions All messages related to transactions are logged Daily Transaction Reports are maintained Mobile Phone is kept at the Vault at the end of the day. Officers of the bank are custodian of the mobile phone and MPIN Internal documentary and procedural requirements are followed to ensure appropriate Dual Control for all transactions in terms of Making and Approving authorities 10

Security and Internal Control Requirements (Bank Level) 1) The custodian of the mobile phone must be an officer of the bank (Cashier/Manager/Designated Officer of the Bank) 2) M-PIN (Mobile Personal ID No.) and security code of the mobile phone must be secured and should not be known to anyone other than the designated custodian of the mobile phone. 3) It is required that GCash Menu-Driven Interface must be used. To access Menu-Driven Interface in your cellphone, go to Globe Services (Globe Svcs+) then click on myfavorites>gcash 4) All mobile banking transactions (incoming/outgoing) must be checked and approved by officers of the bank 11

Security and Internal Control Requirements (Bank Level) 5) Withdrawal (Text-A-Withdrawal) must be drawn against Cleared/Withdrawable Balance 6) Phone-to-Phone (P2P) Fund Transfer transactions must be supported by receipts and recordings in the Logsheet and GCash Journals 7) The bank s mobile phone must be used only for purely GCash/RBAP Text a Payment related activities. 8) Branch s Mobile Phone Phonebook/SIM must contain Head Office s mobile phone number in case of a branch or branches mobile phone numbers in case of a Head Office 12

Security and Internal Control Requirements (Bank Level) 9) Bank In-charge must explain to the client the terms and conditions of the mobile phone banking service during client s enrollment including security and risk involved 10) Follow enrollment procedure and requirements if enrollment is required for a particular mobile phone banking service 11) Any internal/security control violations should not be tolerated and must be reported immediately for proper action (Please see information security policy manual). 13

Security and Internal Control Requirements (Client Level) 1) Complete KYC (Know-your-customer) procedure must be followed in all clients availing of mobile phone banking services - Valid ID is required upon opening an account and/or enrolling to the service - Background/Credit checking is performed when necessary - References must be asked and checked when necessary 2) Clients must be oriented/briefed in each mobile phone banking service he/she is availing including security and risk involved. 3) Ensure that client understands the terms and conditions of the service and client must agree and sign to the service enrollment form if enrollment is required. 14

End of Presentation 15