Showing posts with label fraud. Show all posts
Showing posts with label fraud. Show all posts

Wednesday, January 13, 2010

Top 5 Business Resolutions for 2010

I am in the midst of trying to stick to my New Year's Resolutions and this year also decided to put together my 2010 Business Resolutions.

Resolution 1: Be More Authentic

In the world of webcasts, email barrages, etc. it is difficult to come across as being authentic. People are tired of the "in your face" selling approach hidden behind the veil of a blog or information rich webinar. I have resolved to treat each communication with our clients and prospective clients as one that provides valuable information in a style that reflects who we are.

Resolution 2: Happy Hour

We need more happy hours - The name says it all! I am not resolving to drink more, but rather to celebrate more. I haven't run this by my wife Kelly yet, but if it is a Business Resolution - I think I have a chance.

Resolution 3: Start Writing that Book

For years, I thought about starting a company, and I finally did. The other topic I have pondered is to write a book. I keep bouncing back and forth between a business book, a children's book or fiction. The titles will range from "Building a Business out of Bubble Gum and Shoestring" to "Mr. Magoo Goes Bananas". As you can see - I have some work to do on the focus, but resolve to finally figure that out and at least write the introduction.

Resolution 4: Twitter

I can now spell it, so that's a start. I resolve to finally figure this out and make it part of my day and our communications strategy. I am a GenX guy, and looking to get with the times and this whole social networking world.

Resolution 5: Lunch

I resolve to make enough time each day for lunch. Try as I might, I many times find myself skipping lunch. I am going to start by putting an Outlook Reminder on my calendar, so that nice lady on my Blackberry will remind me "Adam - time for lunch". I am trying to figure out how I can super-impose my Mom's voice into that message. Of course, that is too technical and I will hold on that one until 2011.

I am a little worried about this resolution as it is in direct conflict with my personal resolution to lose some weight. Kelly tells me that I can eat nuts, berries and salads and kill two birds with one stone. I hate it when she's logical. Dang!

A.E>>>

Friday, December 18, 2009

Beware the "Black Box"

Throughout the course of my career I have developed hundreds of analytical models that have been or are being used by many of the banks, credit issuers and direct marketing companies in the country. Statistical modeling is not a topic that I typically bring up at cocktail parties or in general conversation - as it it is the equivalent of administering a few doses of vicodin mixed witha shot of bourbon....zzzzzzzzzzzzzzzzz.

However - there is one topic of modeling that has interested me for many years and should be of interest to the general model consuming public. That topic is that of the "Black Box" approach to selling model based solutions.

Back in the 90's when modeling solutions were coming out of the woodwork, a variety of companies begin marketing their models and scores as their differentiator. The typical tagline was that their solutions were superior because their analytics and analytic teams were "better".

A prime example of this was the Falcon product from HNC which today still is the modeling platform for the majority of all card transactions world-wide. HNC brought neural networks to the industry and they positioned their solution as superior because of those deep analytics. And guess what - it worked! The positioning catapulted their solution to the top and they never looked back. However - if you ever asked HNC what was behind the modeling, they would tell you it was a "Black Box". That is, it was the secret sauce and could not be divulged.

A couple years later, I was presented with a similar situation. I was jointly developing a model with the old Fair Isaac (now FICO). While it was supposed to be a joint effort, when I asked to review the models and codes, their lead analyst informed me that he could not divulge. I asked why not, and he told me that it was a "Black Box", could not be divulged and I probably could not understand anyway. As a trained statistician, all I heard was - "We're smart and you are stupid".

That is when I began to become fixated on the implications of the "Black Box" approach to marketing scoring based solutions. At the time, FICO positioned themselves as the "Gold Standard" in modeling. However, their prospects, clients and competition were referring to them as the "Four Letter F Word". I do think that over time, this has led to their market erosion and loss of credibility.

Most of the people I have ever met from HNC or FICO are, indeed, very smart people. However, when you take the "Black Box" approach to positioning scoring solutions - I think you are jeopardizing your brand and doing a disfavor to your people. After repeatedly hearing "We're smart - you're stupid", eventually people grow tired of it. After all - I don't think anyone likes to be told that they're stupid or incapable of understanding. Especially when it is not true. There are tens of thousands of modelers out there who know exactly what I am talking about.

I have always been a firm believer in transparency in the modeling and scoring process. As solutions providers, we exist to solve problems and provide value. When we throw up the "Black box" it undercuts our value proposition and opportunity to be collaborators. That is why we always work closely with our clients and give them deep understanding of what it is that drives those models. This does not mean that I have to pull out the source code or hand over the actual model on a silver platter. We all need to protect our Intellectual Property. However, this transparency secures a position of collaborator and partner. It also leads to deeper understanding from our clients about what is driving their business.

Transparency in modeling and scoring is becoming more routine over time, as model developers and users understand that it is one piece of the solution. However, it still amazes me that there are some select companies today that are positioning the "Black Box". I welcome that competition. I have to say that I don't mind my competitors positioning themselves as "We're smart - you're stupid".

A.E>>>

Tuesday, June 2, 2009

Examinations In Process

We are finally beginning to get some good information regarding how banks and credit unions are doing coming out of their initial FACT Act Red Flag audits. The great news is that our clients are being given a passing grade by the auditors for using our Safe2Change solution to meet the address change provisions of FACT Act. Great news, because they deloyed Safe2Change as a much more cost-effective solution to complying versus sending out letter confirmations. At a time when costs are more critical than ever, saving some dollars here is very important, and our customers are able to realize these savings.

More interestingly, we are seeing a couple of general trends emerging from these audits that are worth thinking about.

Looks like the auditors are being somewhat lenient in this first pass. Clearly there are the handful that completely ignored the regulation and are getting it with both barrels. However - in the first round we are hearing that they are generally not having many issues.

The one gap that we are hearing now repeatedly is that the examiners are beginning to scrutinize compliance strategies where financial institutions are mailing letters to the customer's old and new address to achieve compliance. The issue is sufacing not because of the letter mailing strategy, but because FACTA requires that the institution not fulfill subsequent requests credit cards, debit cards, checks, etc. until the consumer has had enough time to receive and respond to the letter. This makes sense. If the institution sends out a letter and then sends the requested card to the new address (where the fraudster is waiting) - then this strategy will still still result in identity theft.

We are finding that most institutions have deployed the letter mailing strategy. However - we are also finding that these same institutions are not putting a "hold" on the account to block the request for cards and checks. This is not allowed per the FACT Act, which states that you can send letters, but not fulfill these additional requests until enough time has passed.

In these early examinations, we are hearing this issue being brought up repeatedly. While the examiners are being a bit lenient in round 1, we see this as being an issue that will be scrutinized much more and that financial institutions will need to plug this hole.

A.E>>>

Thursday, May 14, 2009

Subscription Pricing?

For years, the largest banks have deployed fraud tool after fraud tool. In doing so, the typical end result is a combination of many tools that overlap in form and function.

This makes it difficult for institutions to bring in additional tools or functionality to improve their fraud detection capabilities. One of the major barriers is price. As more and more tools are deployed - the incremental benefit is reduced - yet it is rare for the fraud solutions provider to alter their price based on this.

One of these new tools is what can be referred to as "Velocity" or Link Analysis". Most institutions know that an important piece of their overall strategy is to monitor repeat activity at the same address, phone number or Social Security Number. Eg. why have 5 unique people all applied at 123 Main ST in the last week? However - most insitutions have either not deployed that or are doing it in a rudimentary way.

We have developed a new technology that takes velocity and link analysis to a new level allowing our clients to expose fraud rings that they have not been able to see before.

However - while the value can be realized - we run into this dilemma described above. Because of this - we are beginning to think about a subscription based pricing model that incentivizes more volume not less. End result - better detection - less cost.

Wednesday, November 19, 2008

Verified?

Today, we just got done analyzing the confirmed fraud addresses from the United States Postal Inspection Service, which is the law enforcement agency of the Post Office. We went back and looked at all the confirmed fraud addresses over the past 12 months. In doing so, we categorized all of the records into the category of fraud.

What we found was that 48% of the confirmed frauds were due to re-shipping schemes and that 41% of the confirmed frauds were due to a fraudulent change of address. Together - they represent 89% of all confirmed frauds.

What is interesting is that for both of these cases, any ID Verification service would have very likely indicated that the Name Matched the Address! For fraudulent address changes - the fraud artist changed the address from the victim's address to an alternate address. This would then be picked up by the third party verification providers as a confirmed address change. In the second situation - unsuspecting "mules" would receive merchandise that was being shipped to the actual person listed at the address.

Point is - in both cases, any traditional ID Verification service would confirm that the name and address matched! Over the past few years - a culture has developed that when we "match" the name to address that it must be "good". This matching would be considered sufficient or "reasonable" to any examiner as meeting USA Patriot Act, Bank Secrecy Act or Fact Act guidelines. As we can see above - it isn't that simple. Makes you wonder?

Thursday, January 17, 2008

UK Fraud Likely Could Have Been Prevented

The story keeps getting louder. Last week the chairman of England’s Barclays Bank, Marcus Agius, became the latest victim of identity theft. A thief posing as Mr. Agius called the bank and requested that a new card be sent out. As in most account takeover cases, the fraudster no doubt requested that the card be sent to an alternate address that was easily accessible. From there, he racked up almost $20,000 in fraudulent charges, with little chance of getting caught.

Unfortunately, this story is not a surprise to us at ID Insight, as most banks still do not protect against fraudulent changes in address. This crime would most likely have been prevented had Barclays taken action when the caller asked that the card be delivered to that alternate address. My guess is that if we would have analyzed Mr. Agius’s real address versus the one the thief “moved Mr. Agius to” using our Safe2Change process, we would have seen some major red flags.