Technology review 2010: Controlling fraud – Digital Indentities

One solution to person-not-present fraud when making a payment is the use of digital identity certificates (DIs) and signatures to verify an individual really is who (s)he claims to be and is authorized to make the transaction. DIs are already successfully used in a number of applications, for example, by companies in the UK for the approval of file transmissions to the local ACH, by the pharmaceutical industry in the US, and by the Norwegian ACH for its internet banking customers. But their use is not yet widespread.

Also in this section:
Controlling fraud – payment cards
Controlling fraud – Digital Indentities
Minimizing reputational risk
Improving connectivity
Automating bank relationship management
Treasury Management – Efficiency and compliance
Treasury Management – In-house versus ASP and SaaS solutions

The IdenTrust Trust Network is an example of the growing success of these schemes. It issues DIs through some 30 banks worldwide providing eSignatures to companies, ACHs, governments and banks, which are interoperable across geographies, industries, products and supply chains. IdenTrust has already issued 1 million DI certificates and is now experiencing considerable growth as businesses worldwide introduce higher levels of security. Citi’s new electronic banking system, Citi Direct BE, offers users the option to log on with its IdenTrust eSignature. IdenTrust multi-bank DI certificates can be used for signing on to all of a company’s electronic banking (EB) banks. The Trust Prime application, shown in Figure 2, is an example of how DI certificates can both help improve fraud control and streamline day-to-day corporate treasury department operations.

Figure 2 – Use of Multi-Bank Digital identities in bank connectivity

View the chart (will open in a new window)

Source: IdenTrust, Inc.

Multi-application DIs are also available and appear to be well placed to become a normal feature of the everyday life of the corporate treasury department. RBS already issues triple application DIs to its corporate clients, for user authentication and payment signing, for secure access to document exchange in the management of card ordering and for the control of machine-to-machine linking for direct submission of bulk payment files. RBS is a leading force in the introduction of DIs to the corporate banking world, with 5,000 corporate customers using DIs for submission of payment files to the UK’s ACH BACS and supplying five other banks with digital identity services. George Evers, head of TrustAssured business within RBS’s Global Transaction Services, believes, “Companies need to take a multi-layered approach to security and fraud prevention. RBS Trusteer Rapport provides protection against online fraud. Companies need controls over internal use of high-risk systems, including password protection, security devices and effective perimeter security.”

As the use of digital identities grows, interoperability between the different ID issuing schemes will become essential. Unfortunately this will inevitably bring with it additional risk but, as IdenTrust‘s global ambassador John Bullard explains, “Banks are uniquely placed to help their customers in managing the operational risks associated with the issuance and reliance upon electronic IDs. Indeed banks issuing such credentials based upon the IdenTrust Trust Network are already enabling their customers to use these same credentials both inside and outside of the network itself.”