Introducing new anti-fraud measures including name and account number checking would make it far more difficult for scammers to get away with “big haul” investment frauds, a personal finance commentator says.
Parliament’s Finance and Expenditure Committee recommended last week that name and account number checking, or confirmation of payee, should be introduced by New Zealand banks as scammers were “actively targeting New Zealanders”.
Financial commentator Janine Starks said there are “gaping holes” in New Zealand banks' fraud security without confirmation of payee, which allows people to check the details of who they are paying before they make a transaction.
She said New Zealand “doesn’t have a choice” in introducing it.
“Once it’s in, scammers have to make the name and account number match. That means they can still scam people, but they need to change the type of fraud they commit. Investment frauds which are big haul are far more difficult to commit.”
Starks said scammers would need to open an account in the name of a firm which sounded like a financial intermediary to make their scams work if name and account checking is in place, and it removed scammers' ability to use personal accounts for money mule activities.
There have been a number of high-profile investment scams perpetrated against New Zealanders where payments were made to “Citibank” accounts for fake term deposit investments, but the accounts were actually mule accounts used to shift funds, held with New Zealand banks.
“Getting a business account name will likely mean registering a company and getting through a bank's KYC rules ( know your customer). If they manage that, the bank has again failed in security,” Starks said.
NZ’s big four banks say they support confirmation of payee, but have warned it hasn’t stopped frauds in the UK.
ASB Chief Executive Vittoria Shortt said the UK had name and account matching, but frauds and scams had "escalated even further".
She said this didn't mean it wasn't worth doing, but New Zealand banks should "go after the biggest beneficial option which I think is the centralised capability".
Shortt said ASB was very supportive of an industry-backed scheme to bring in confirmation of payee, which was being discussed with bank-owned payments system Payments NZ — but the banking industry hasn't said when it could be achieved.
Westpac's Head of Fraud and Financial Crime, Peter Barnes, said there were several ways name and account checking could be managed, but it would require an agreement from all banking entities on what the model would look like.
"Implementation of this initiative would have to be carefully considered as it has the potential to disrupt many legitimate day-to-day transactions."
ANZ said it was supportive of the recommendations made by the Finance and Expenditure Committee, "and continued to carefully review and learn from what’s working in other countries and what isn’t".
Starks said confirmation of payee “isn’t weak or pointless”.
“It is a hole that needs plugging, but once that's done fraud is still viral and innovative and it will morph into other schemes that ensure the account number matches, or they attack frailty in other parts of the system like the weak security around two-factor codes sent via text message. Fraudsters always attack the fraud-hole banks haven’t fixed. That doesn’t mean that we should say the plugs we put in place are now pointless. They absolutely aren’t.”
Starks said failure to act meant New Zealand could end up with “hyper-viral fraud”.
She said NZ banks’ current fraud systems were at least 10 years behind the UK, and “the UK regulators keep insisting their own banks must do more”.
“Given the technology banks use — more security is a constant, not a goal with an end point.”
The UK now has a Contingent Reimbursement Code, which means people who are tricked into making payments to scammers will likely get their money back from banks, “if the combination of a person’s individual circumstances and the scam itself mean that it wasn’t reasonable to expect that person to have protected themselves then they should always be given their money back”.
NZ's Finance and Expenditure Committee recommended investigating a similar system.
The UK’s code has consumer protection standards for banks to reduce “authorised push payment” (APP) scams, where people are conned into authorising payments to accounts they believe are legitimate.
It is voluntary. Those who sign up commit to protecting customers with with procedures to detect, prevent and respond to APP scams, to provide a greater level of protection for customers considered to be vulnerable to this type of fraud and greater prevention of accounts being used to launder the proceeds of APP scams, including procedures to prevent, detect and respond to the receipt of funds from this type of fraud.
It also means banks must reimburse customers "who are not to blame for the success of a scam".
The United Kingdom introduced confirmation of payee in 2020, and an Australian bank had brought in its own checking system this year.
Commonwealth Bank, which owns ASB in New Zealand, introduced NameCheck earlier this year, "an Australian banking first".
It said NameCheck had helped over 11,000 of its customers and saved over A$11 million in mistaken payments since March 31.
In the UK, Lloyds Banking Group said confirmation of payee had helped to reduce bank transfer scams by 31% within the first couple of months of its introduction in 2020.
Banks across the Tasman have also launched a fraud reporting exchange, which has “near” real-time reporting of fraudulent transactions between member banks and the ability to halt multiple fraudulent transactions taking place as part of the same scam.
Australia also launched a National Anti-Scam Centre recently, bringing together regulators, police and banks to work together to identify and combat financial frauds.
It appears introducing an anti-scam centre in NZ has momentum. The Financial Markets Authority said recently it was looking at a national anti-scam centre.
The FMA said in an emailed statement that along with fellow agencies in the financial sector it was looking at ways to achieve greater coordination and cooperation around tackling scams.
This was on the agenda for the Heads of the Council of Financial Regulators (the Chief Executives of the Reserve Bank, the Treasury, MBIE, the Commerce Commission, and the FMA) at their next meeting, it said.
"We are also talking with industry groups on the same theme to encourage more coordination in the private sector with Government agencies.”
A number of agencies were involved in protecting New Zealanders from scammers including the Department of Internal Affairs, NZ Police, Cert NZ, the Commerce Commission and the FMA.