| Guidelines This chapter describes risks and expectations for banks and supervisors related to electronic banking (e-banking) activities. The contents of this chapter are based on: |
| Related standards |
| Related guidelines
|
| Other related publications
|
Electronic banking, or e-banking, includes the provision of retail and small value banking products and services through electronic channels as well as large value electronic payments and other wholesale banking services delivered electronically. E-banking does not create inherently new risks, but may change the traditional risks associated with banking activities, including strategic, operational, legal and reputational risks. While existing risk management principles remain applicable to e-banking activities, such principles must be tailored, adapted and, in some cases, expanded to address the specific risk management challenges created by the characteristics of e-banking activities.
The following terms are used throughout this chapter and have the meaning given below:
This chapter sets out supervisory expectations and guidance for banks carrying out electronic banking (e-banking) activities, as well as to their home and host supervisors. Banks are expected to recognise, address and manage the risks associated with the provision of e-banking services.
Principle 1: Prior to engaging in cross-border e-banking activities, a bank should conduct appropriate risk assessment and due diligence and establish an effective risk management program for such activities.
Initial risk assessment, due diligence and ongoing risk management considerations should include, but are not limited to, such factors as country risk, compliance risk, regulatory requirements, local business practices, accounting standards and the legal environment, as well as the operational, security, privacy, and customer service challenges presented by the online delivery of banking products and services to foreign customers.
One of the major risks associated with cross-border operations is failure, whether inadvertent or otherwise, to comply with applicable foreign (and therefore possibly less well known) laws and regulations, and uncertainty over how “choice of law” principles can be applied in an e-commerce context. Banks should recognise that substantial differences might exist between jurisdictions with respect to bank licensing, supervisory and customer protection requirements. A bank’s due diligence reviews should also recognise that local authorities other than bank supervisors may exercise oversight on issues pertaining to the bank’s activities with local residents. Such authorities may include the central bank, consumer protection authorities, investment services regulators, or authorities responsible for preventing financial crime. The differences in licensing and other requirements in various jurisdictions, and the uncertainty with respect to how choice of law principles are applied could increase the complexity and cost of the bank’s due diligence.
A bank could be expected to define and generally mitigate its due diligence obligation by posting on its website a conspicuous disclaimer that limits its on-line product and service offerings to only the residents of specified countries. This type of disclaimer should be made in conjunction with the need for the bank to be transparent relative to its intentions. However, the bank should also recognise that the legal effect of such a disclaimer might be somewhat uncertain. In addition, its value may vary between jurisdictions, particularly if the disclaimer is not backed up by appropriate policies and internal controls that ensure that the bank does not inadvertently conduct e-banking business with residents of an excluded country.
Sound security control practices for e-banking include:
| 1 | Definitions of security and quality standards and reliance on certification schemes can be institution specific or standardised (ie within a national banking industry to enhance and foster the security level of e- banking activities). Banks can also choose to establish access rights in either a centralised or distributed manner. For example, there may be a single authorisation authority responsible for assigning access rights to specific identities, groups or roles within a bank, or there may be several authorisation authorities established to address the varying needs within the different business lines. |
| 2 | This should include controls guarding against unauthorised access by external parties such as visitors, contractors or technicians who may have access to the premises although they may not be directly involved in the e-banking service. |
Principle 2: Banks should take appropriate measures to authenticate the identity and authorisation of customers with whom it conducts business over the internet.
Banks should use reliable methods for verifying the identity and authorisation of new customers as well as authenticating the identity and authorisation of established customers seeking to initiate electronic transactions.
Customer verification during account origination is important in reducing the risk of identity theft, fraudulent account applications and money laundering. Failure on the part of the bank to adequately authenticate customers could result in unauthorised individuals gaining access to e-banking accounts and ultimately financial loss and reputational damage to the bank through fraud, disclosure of confidential information or inadvertent involvement in criminal activity.
Legitimate user authorisation can be misrepresented through a variety of techniques generally known as “spoofing." Online hackers can also take over the session of a legitimate authorised individual through use of a "sniffer" and carry out activities of a mischievous or criminal nature. Authentication control processes can in addition be circumvented through the alteration of authentication databases.
It is critical that banks have formal policy and procedures identifying appropriate methodology(ies) to ensure that the bank properly authenticates the identity and authorisation of an individual, agent or system (including the banks’ own websites) by means that are unique and, as far as practical, exclude unauthorised individuals or systems.3 Banks can us a variety of methods to establish authentication, including PINs, passwords, smart cards, biometrics, and digital certificates.4 These methods can be either single factor or multi-factor (eg using both a password and biometric technology to authenticate). Multi-factor authentication generally provides stronger assurance.
| 3 | Systems must ensure that they are dealing with an authenticated individual, agent or system and with a valid authentication database. |
| 4 | A bank may issue digital certificates using public key infrastructure (PKI) to a customer to secure communications with the bank. Digital certificates and PKI are discussed more fully in Principle 3. |
The bank must determine which authentication methods to use based on management's assessment of the risk posed by the e-banking system as a whole or by the various sub- components. This risk analysis should evaluate the transactional capabilities of the e- banking system (eg funds transfer, bill payment, loan origination, account aggregation etc.), the sensitivity and value of the stored e-banking data, and the customer's ease of using the authentication method.
Robust customer identification and authentication processes are particularly important in the cross-border e-banking context given the additional challenges that may arise from doing business electronically with customers across national borders. These include the greater risk of identity impersonation and the greater difficulty in conducting effective credit checks on potential customers.
As authentication methods continue to evolve, banks are encouraged to monitor and adopt industry sound practice in this area such as ensuring that:
| 5 | In some cases, the authenticated source may be an electronic source. |
Principle 3: Banks should use transaction authentication methods that promote non-repudiation and establish accountability for e-banking transactions.
Non-repudiation involves creating proof of the origin or delivery of electronic information to protect the sender against false denial by the recipient that the data has been received, or to protect the recipient against false denial by the sender to which the data has been sent. Risk of transaction repudiation is already an issue with conventional transactions such as credit cards or securities transactions. However, e-banking heightens this risk because of the difficulties of positively authenticating the identities and authority of parties initiating transactions, the potential for altering or hijacking electronic transactions, and the potential for e-banking users to claim that transactions were fraudulently altered.
To address these heightened concerns, banks need to make reasonable efforts, commensurate with the materiality and type of the e-banking transaction, to ensure that:
Banks employ various techniques, such as digital certificates using public key infrastructure (PKI), that help establish non- repudiation and ensure confidentiality and integrity of e-banking transactions.6 A bank may issue a digital certificate to a customer or counterparty to allow for their unique identification/authentication and reduce the risk of transaction repudiation.
| 6 | Each party in a PKI has a private/public key pair. The private key is secret so that only one person should use it. All parties use the public key. The private key generates an electronic signature on the document and the key pairs are designed so that a message encrypted with the private key can only be read by using the other key. A bank may act as its own certification authority (CA) or rely on another trusted third-party to associate a person or entity with the digital certificate. However, if a bank relies on a third- party digital certificate to establish authenticity, it should confirm that the CA, when issuing the certificate, used the same level of authentication that the bank would have used to authenticate the person. |
Sound authorisation practices for e-banking applications include:
| 7 | As this might not be feasible for system administrator users, other stringent internal controls and segregation of duties should be put in place to monitor the activities of those user accounts. |
Principle 4: Banks should ensure that appropriate measures are in place to protect the data integrity of e-banking transactions, records and information.
Data integrity refers to the assurance that information that is in-transit or in storage is not altered without authorisation. Failure to maintain the data integrity of transactions, records and information can expose banks to financial losses as well as to substantial legal and reputational risk.
The inherent nature of straight-through processes for e-banking may make programming errors or fraudulent activities more difficult to detect at an early stage. Therefore, it is important that banks implement straight-through processing in a manner that ensures safety and soundness and data integrity.
As e-banking is transacted over public networks, transactions are exposed to the added threat of data corruption, fraud and the tampering of records. Accordingly, banks should ensure that appropriate measures are in place to ascertain the accuracy, completeness and reliability of e-banking transactions, records and information that is either transmitted over the internet, resident on internal bank databases, or transmitted/stored by third-party service providers on behalf of the bank. Common practices used to maintain data integrity within an e-banking environment include the following:
Principle 5: Banks should ensure that clear audit trails exist for all e-banking transactions.
Delivery of financial services over the internet can make it more difficult for banks to apply and enforce internal controls and maintain clear audit trails if these measures are not adapted to an e-banking environment. Banks should ensure that effective internal controls can be provided in highly automated environments, and that the controls can be independently audited, particularly for all critical e-banking events and applications.
A bank's internal control environment may be weakened if it is unable to maintain clear audit trails for its e-banking activities. This is because much, if not all, of its records and evidence supporting e-banking transactions are in an electronic format. In determining where clear audit trails should be maintained, the following types of e-banking transactions should be considered:
Sound audit trail practices for e-banking systems include:
Principle 6: Banks should ensure that adequate information is provided on their websites to allow potential customers to make an informed conclusion about the bank's identity, home country and regulatory status of the bank prior to entering into e-banking transactions.
To minimise legal and reputational risk associated with e-banking activities, banks should ensure that adequate information is provided on their websites to allow customers to make informed conclusions about the identity and regulatory status of the bank before they enter into e-banking transactions.
Examples of such information that a bank could provide on its own website include:
| 8 | For instance, the bank may wish to specify those countries in which the bank intends to provide e-banking services or, conversely, those countries in which it does not intend to provide such services. |
Principle 7: Banks should take appropriate measures to ensure adherence to customer privacy requirements applicable to the jurisdictions to which the bank is providing e-banking products and services.
Maintaining a customer’s information privacy is a key responsibility for a bank. Misuse or unauthorised disclosure of confidential customer data exposes a bank to both legal and reputational risk. To meet these challenges concerning the preservation of privacy of customer information, banks should make reasonable endeavours to ensure that:
The bank’s standards for customer data use must be met when third parties have access to customer data through outsourcing relationships.
| 9 | In some jurisdictions, laws and regulations may not require banks to seek the customer’s permission to use customer data for internal purposes. However, they may require that banks give customers the option to decline permission for the bank to share such information with a third party or an affiliate. In other jurisdictions, customers may have the right to prevent the bank from using their data for either internal or external purposes. |
Sound practices to help maintain the privacy of customer e-banking information include:
Principle 8: Banks should develop appropriate incident response plans to manage, contain and minimise problems arising from unexpected events, including internal and external attacks, that may hamper the provision of e-banking systems and services.
Effective incident response mechanisms are critical to minimise operational, legal and reputational risks arising from unexpected events such as internal and external attacks that may affect the provision of e-banking systems and services. Banks should develop appropriate incident response plans, including communication strategies, that ensure business continuity, control reputational risk and limit liability associated with disruptions in their e-banking services, including those originating from outsourced systems and operations.
To ensure effective response to unforeseen incidents, banks should develop:
| 10 | Monitoring of help desk and customer support activities and regular review of customer complaints may help to identify gaps in information being detected and reported through established security controls versus actual intrusion activities. |
This module describes expectations to combat money laundering and terrorist financing.
This module describes expectations and practices relating to capital adequacy.
This module describes expectations for corporate governance.
This module describes expectations for credit risk and counterparty credit risk management.
This module describes expectations for external audit and sets out references related to public disclosure.
This module describes expectations for banks’ internal audit and compliance functions.
This module describes expectations for liquidity risk management.
This module sets out references related to market risk and interest rate risk.
This module describes expectations for the management of operational risk and operational resilience.
This module describes expectations for the management of problem assets and expected credit losses.
This module describes the application of proportionality in prudential regulation and supervision.
This module describes expectations for risk management.
This module describes the nature and application of prudential supervision.