Hi, I'm Tom Field, Senior Vice President of Editorial with Information Security Media Group. I'm talking today about authorized push payment fraud. And to address this, I'm speaking to Rob Farle, fraud and authentication subject matter expert with NICE Actimize EMEA. Rob, thank you so much for joining me today.
Pleasure, Tom. Rob, let's talk about authorized push payment fraud, the challenge it presents, and why this is getting noticed now in particular. Sure. So it's a really interesting space, and it's getting noticed really heavily in the UK, but some of the other jurisdictions as well, the US and the Nordics.
And the reason is, is the really large amount of money that customers are losing and the potentially life-changing consequences to them. And that's the regulator really picking up on that and wanting the financial industry to do something to help those consumers out. I want to follow up on that, Rob. How have regulators responded to this trend that you've seen?
So the UK regulators, particularly the payment services regulator and the FCA in the UK, are focusing in on protecting the consumer and making sure they get refunded. Authorized push payment fraud differs than the normal types of fraud perhaps we're used to, account takeover fraud, in that the customer has authorized that payment as opposed to a fraudster authorizing it. And that means that under the most laws, the consumer is liable for it and the bank doesn't have liability. And so they don't get refunded.
And the types of fraud that are involved, so romance scams, investment scams, or business email compromise payment frauds, mean that the sums of money involved are very large and, as I said, life-changing. So the UK regulators have just had the UK banks voluntarily agree to implement something called the contingent reimbursement model. And this means that they will reimburse these customers in certain circumstances if they've been a victim of authorized push payment fraud. So Rob, in terms of security controls, what types of multi-layered defensive tactics do you recommend that institutions adopt?
Well, there's a number of actions, and these particularly align with the contingent reimbursement model. But I think the key ones are looking to protect customers both outbound and inbound, so both as a receiving bank and a paying bank. And they can improve their customer messaging to help the customers protect themselves more. So it's education campaigns, but then also very specifically within various payment journeys, putting up risk-based warnings to them that something might be amiss and trying to trigger that important response in the customer to think rationally and go, does this make sense?
Because most of the time these things don't make sense, and the fraudsters instilled a sense of urgency and or fear to bypass their rational thought processes. Then also, use all the digital tools they've got available to them, device profiling, behavioral biometrics, malware detection, and layer that with a good fraud platform and advanced analytics so that they can build specific models to identify customers who are at risk of these sorts of frauds and the payments themselves, and indeed, cans receiving those payments. And I think one of the key ones from this is very much for the beneficiary banks, who I think in the past have not had the right incentives to invest properly in this space, and that's to undertake real-time profiling of inbound payments and freeze those where required. Putting all those things together with a really good case management system that can allow banks to look at the entities involved, highlight unusual behaviors and network links as well, means they can identify all these sorts of frauds in an efficient way, only really impacting that the fraudsters are not the genuine customers going about their business.
Well, beyond stopping fraud, it strikes me there could be some business benefits realized from these defensive tactics as well. Would you agree? Definitely. And I think that's really where there's some good things to happen here.
The banks who choose to invest in the right systems and take the right approach to this, but this is about protecting customers and building out their business, will get those rewards. And so protecting customers from these frauds and scams, as well as impacting their bottom line and reducing their liabilities and their fraud losses, it will also create a hostile environment for the fraudsters, reducing further the costs on their business, but also reducing management time they're spending dealing with the regulators on these matters. But it also helps support giving trust, putting trust back into the system. So all the new innovations coming down the pipe, whether that's through open banking or voice first with the payments via Alexa and things, customers will then trust and want to build that out and give those organizations a head start over everyone else into reaping those benefits.
Rob, final question for you. Talk to me a bit about NICE Actimize. What are you doing to bring this to your customers' attention and assist them in putting up an appropriate defense? So we can provide the sorts of systems that allow customers to do this, both with out-of-the-box models and also advanced analytics, working with those customers to build those sorts of profiles they need to do all of the things that I talked about earlier.
That can be purely on the paying away side or indeed on the inbound payment side as well. So very much building out a platform and a hub for customers to put all their data in and make good quality decisions in real time to protect their customers and their own P&L as well and do that in an efficient way so that they're not having an army of people to work all the alerts that are generated. They can do that in a cost-effective fashion. Rob, again, I appreciate your time and insight today.
Thank you so much. Pleasure talking to you, Tom. Again, the topic has been authorized push payment fraud. I've been speaking with Rob Farl, he's the fraud and authentication subject matter expert with NICE Actimize EMEA.
For Information Security Media Group, I'm Tom Field. Thank you very much.