Sunday, July 03, 2022

Amazon in financial services - Thanks to CB Insights - Part 1

 From payments and lending to insurance and cash deposits, Amazon is attacking financial services from every angle without even applying to be a conventional bank. In this report, we break down how these efforts impact merchants and consumers. We also dive into various initiatives Amazon is pursuing, ranging from cashierless payment terminals to health insurance for sellers.

In 2017, Andreessen Horowitz general partner Alex Rampell said that of all the tech giants that could make a major move in financial services,

“Amazon is the most formidable. If Amazon can get you lower-debt payments or give you a bank account, you’ll buy more stuff on Amazon.”

While the anticipation for Amazon’s plunge into banking builds each year, it’s important to first understand Amazon’s existing strategy in financial services — what Amazon has launched and built, where the company is investing, and what recent products tell us about Amazon’s future ambitions.

Based on our findings, it’s hard to claim that Amazon is building the next-generation bank. But it’s clear that the company remains very focused on building financial services products that support its core strategic goal: increasing participation in the Amazon ecosystem.

As a result, the company has built and launched tools that aim to:

1. Increase the number of merchants on Amazon, and enable each merchant to sell more.
2. Increase the number of customers on Amazon, and enable each customer to spend more.
3. Reduce any buying/selling friction.

In parallel, Amazon has made several fintech investments, mostly focused on international markets (India and Mexico, among others), where partners can help serve Amazon’s core strategic goal.

In aggregate, these product development and investment decisions reveal that Amazon isn’t building a traditional bank that serves everyone. Instead, Amazon has taken the core components of a modern banking experience and tweaked them to suit Amazon customers (both merchants and consumers).

In a sense, Amazon is building a bank for itself — and that may be an even more compelling development than the company launching a deposit-holding bank.

TABLE OF CONTENTS:

  1. Amazon’s product strategy

2. Amazon Market strategy outside the US

3. Rumors: What will Amazon do next?
4. Closing thoughts

Product strategy: Amazon takes on financial services

Amazon is notorious for spreading its bets before going all in on a new product, and the financial services space is no exception. Through trial and error, the company has set up key financial pillars across payments, cash deposits, and lending. As we’ll explore below, all are related to Amazon’s broader growth and product strategies.

Amazon Payments

Amazon has aggressively invested in payments infrastructure and services over the last few years. That’s unsurprising, given that the payments experience is so close to Amazon’s core e-commerce business. Making payments more cash-efficient for Amazon and frictionless for customers is a key priority.

AMAZON PAY: A DIGITAL WALLET AND A PAYMENTS NETWORK

Today, Amazon Pay has evolved to include a digital wallet for customers and a payments network for both online and brick-and-mortar merchants. Since 2019, Amazon has invested in growing Amazon Pay’s marketplace, including forming a partnership with acquiring bank Worldpay.

While Amazon Pay is the company’s latest iteration on payments, Amazon has experimented with payments functionality for over a decade. Below is a timeline of some of the major Amazon Pay milestones:


Amazon’s first known payments product, Pay with Amazon, launched in 2007. That same year, the company acquired TextPayMe, a peer-to-peer (P2P) mobile service that was re-launched as Amazon Webpay in 2011.

Webpay failed to gain user traction and was shut down in 2014, unlike up-start Venmo (now a part of rival payments processor PayPal). It’s likely that Amazon was too early to P2P payments.

In 2007, the company also invested in Bill Me Later (fka I4 Commerce). Bill Me Later was one of the earliest fintech payment platforms on the market and gave big retailers the ability to offer flexible financing programs. Although Bill Me Later was scooped up by PayPal in 2008, Amazon remained ever focused on reducing payment friction for customers.

Over the last few years, Amazon has used a variety of techniques to strengthen its payments experience, including launching digital wallets through Amazon Pay, acquiring tech talent of failed mobile payments startup GoPago, building a variety of tech in-house, and most recently opening up to partnering with merchant acquirers outside of Amazon’s marketplace.

Today’s iteration is Amazon Pay, a digital wallet for customers and a payments network for both online and brick-and-mortar merchants and shoppers.

AMAZON PAY’S TRACTION AND METRICS

In addition to serving Amazon’s core customers, payments is an attractive revenue line when thinking about the scope of the payments market. Swipe fees paid by US merchants alone are more than a $110B-a-year business for banks, card networks like Visa, and payment processors like Stripe.

Amazon is finding ways to attract merchants to the Amazon Pay network beyond its experimentation with swipe fees. The company announced it would pass on the special card savings Amazon gets from card networks (because of the volume of purchases they can guarantee) to retailers that adopt Amazon Pay. Leveraging scale and competing on fees is a classic customer acquisition strategy in Amazon’s playbook.

And while the company is famously secretive about reporting customer growth and business metrics, a 2021 survey revealed that Amazon Pay has grown into a major online payment provider with a 24% user share in the US. Payments made with Amazon Pay spiked following service expansion to new geographies — France, Italy, and Spain — and to new verticals, including government payments, travel, insurance, entertainment, and charitable donations.

However, Amazon has had some missteps with Amazon Pay. Its most famous failure was Amazon Local Register. With the talent acquired from GoPago, Amazon launched Amazon Local Register, a card reader for small- and medium-sized businesses (SMBs) in August 2014. At the time, the company charged competitive rates (a full percentage point less than Square). Each reader cost $10, and it seemed like a formidable rival to PayPal’s and Square’s readers.

But in October 2015, the company announced it would be shut down. Despite charging lower fees, the company failed to gain enough traction with merchants who feared giving Amazon detailed data on their overall business operations.

Eventually, Amazon launched a “Pay with Amazon” button for mobile and created a team with the goal of expanding payments across the web and on apps.

To lead this team, Amazon hired ex-PayPal employee Patrick Gauthier. In reference to failed payments projects, Gauthier said:

“What people never realize or truly understand about Amazon is that part of the recipe for success is daring to try things you have no idea whether will succeed or not, and if you think that you have a notion of how to succeed … you try again.”

FUTURE DEVELOPMENTS OF AMAZON PAY: PIVOTING FROM E-COMMERCE TO OMNICHANNEL ENABLEMENT

In March 2019, Amazon announced an integration with Worldpay, which serves as a back-end intermediary between banks and credit card companies and is one of the largest payment processors in the world.

It is a notable pivot from Amazon’s IP strategy, where the playbook has been to build, patent, and keep proprietary technology in-house to fuel Amazon’s marketplace. However, keeping Amazon’s customer-centric “day one” philosophy in mind, Amazon Pay’s top priority is reducing payment friction for customers to buy goods and services and for merchants to sell more things. This is also a second attempt to build distribution with merchants, picking up where Amazon Local Register failed to gained trust.

To achieve this, Amazon Pay set up a rare independent domain and is expanding from e-commerce to omnichannel — across web, mobile, and IoT devices.

The partnership is significant because of its potential to put Amazon’s Quick Payment button in front of millions of consumers and boost distribution with merchants.

At the time of the deal, Worldpay processed more than 40B transactions worth about $1.7T annually, supporting more than 300 payment types across 120 currencies. In July 2019, FIS announced it was acquiring Worldpay in a $43B cash-and-stock deal, indicating a strategic move to grow its merchant solutions business. Patrick Gauthier, VP of Amazon Pay, was reserved about the implications of the partnership:

“Today the announcement is about the extension of our footprint. It will lead us into more opportunities to grow the value proposition for buyers and merchants, but I will reserve discussion about that for the future.”

For Amazon, the combination of FIS and WorldPay is aligned with the company’s goal of reducing friction in payments for consumers and merchants, subsequently boosting commerce.

FIS could also be valuable for financial services pursuits as its suite of technologies ranges from POS systems to integrated card payments to cross-border payments, and covers both online and offline commerce. FIS is also one of the biggest providers of core banking processing and has integrations with Q2 technologies. Both are key elements that non-bank-chartered tech firms in the US have been leveraging to launch banking services, like checking and savings accounts.

Commerce has expanded well beyond desktop into mobile apps, IoT devices such as smart speakers, and other channels where Amazon does not have as formidable a position.

On the web, the infamous one-click patent helped boost the company’s payments prowess. But when the patent expired in 2017, it opened up the market for competitors to launch off-marketplace payment solutions.

To compete, Amazon is investing in its products, including by hiring product managers for device solutions. This has helped Alexa move from the home and office into brick-and-mortar or point-of-sale (POS) environments.

Further, Amazon recognizes the need to diversify its dependence on third parties for its marketplace, even if that means enabling them off-platform.

While a short-term goal of the partnership seems to be to capture market share and reduce the processing fees charged by incumbents, in the long run, Amazon may look to close the loop and keep customers within the Amazon ecosystem.



Sunday, May 29, 2022

SWIFT

 


The Society for Worldwide Interbank Financial Telecommunication (SWIFT) is the main secure 𝐦𝐞𝐬𝐬𝐚𝐠𝐢𝐧𝐠 𝐬𝐲𝐬𝐭𝐞𝐦 that links the world’s banks.

The Belgium-based system is run by its member banks and handles millions of payment messages per day. The diagram below illustrates how payment messages are transmitted from Bank A (in New York) to Bank B (in London).

Step 1: Bank A sends a message with transfer details to Regional Processor A in New York. The destination is Bank B.

Step 2: Regional processor validates the format and sends it to Slice 

Processor A. The Regional Processor is responsible for input message validation and output message queuing. The Slice Processor is responsible for storing and routing messages safely.

Step 3: Slice Processor A stores the message.

Step 4: Slice Processor A informs Regional Processor A the message is stored.

Step 5: Regional Processor A sends ACK/NAK to Bank A. ACK means a message will be sent to Bank B. NAK means the message will NOT be sent to Bank B.

Step 6: Slice Processor A sends the message to Regional Processor B in London.

Step 7: Regional Processor B stores the message temporarily.

Step 8: Regional Processor B assigns a unique ID MON (Message Output Number) to the message and sends it to Slice Processor B

Step 9: Slice Processor B validates MON.

Step 10: Slice Processor B authorizes Regional Processor B to send the message to Bank B.

Step 11: Regional Processor B sends the message to Bank B.

Step 12: Bank B receives the message and stores it

Step 13: Bank B sends UAK/UNK to Regional Processor B. UAK (user positive acknowledgment) means Bank B received the message without error; UNK (user negative acknowledgment) means Bank B received checksum failure.

Step 14: Regional Processor B creates a report based on Bank B’s response, and sends it to Slice Processor B.

Step 15: Slice Processor B stores the report.

Step 16 - 17: Slice Processor B sends a copy of the report to Slice Processor A. Slice Processor A stores the report.

Monday, May 02, 2022

Payconiq and iDEAL

 Dutch association Currence, the brand owner of iDEAL, has partnered with Payconiq International to deliver a major upgrade version of the Dutch online payment scheme, iDEAL 2.0. The upgrade is expected  claims to provide significant benefits to consumers, payment service providers, and merchants.

iDEAL is responsible for more than 900 million transactions per year. On the other hand, Payconiq International is expected to handle more than a billion iDEAL payments per year in the long term. 

Payconiq's infrastructure was chosen very quickly and it delivers a 2.0 version of Ideal from 1 January 2022.

The new solution is based on Payconiq International’s payment platform and aims to optimise payment flows to boost the user experience and facilitate merchant integration.

Besides, Payconiq will handle iDEAL payment traffic in the Netherlands, providing an application programming interface (API) that will enable merchants, banks, and other service providers to connect to the new iDEAL platform via a common access point.

As for iDEAL 2.0, it aims to improve the purchase conversion ratio by providing a new UX design and features for value-added services provided by Payconiq. Furthermore, the solution’s technical infrastructure aims to boost how issuers, acquirers, payment service providers, merchants, and consumers connect to iDEAL.

Payconiq claims to be the first European payment company to offer multi-country payment solutions that allow consumers to pay invoices online, in-store, and other individuals using smartphones.

The company aims to become a leading technology provider in Europe and expects this partnership with iDEAL to be a significant contribution towards that goal. With this development, Payconiq, Currence iDEAL, and affiliated payment service providers can develop new value-added services, such as a fast check-out service.

Payconiq

 Payconiq is a payment method in EU that can be used via an application. It allows you to pay in shops, online and between friends, but also to pay bills and restaurant bills. It's very popular because end-users benefit from fast and easy payment via their smartphone, while merchants reduce checkout duration and pay lower fees per transaction than any other payment method.

Using Payconiq for mobile payments is simple – all your customer needs to do is scan a QR code with an Apple or Android smartphone. The transaction is conducted directly through the Payconiq app, which is already linked to your customer’s bank account.

How it works

Paying with Payconiq is fast and user-friendly. First of all, your customer downloads the free Payconiq app for iOS or Android. They then link their bank account to the app with a simple, one-off action that works for all Dutch banks. Once the bank account is linked, your customer can use Payconiq immediately to make a payment!

Payconiq allows you to pay easily in a physical or online shop, simply by scanning a QR code:

  1. The QR code appears on a display or PIN terminal;
  2. Your customer scans the code with a smartphone and then approves the payment in the Payconiq app with a four-digit code, fingerprint scan or face ID. This completes the payment, and the transaction will appear on the screen of your payment device or in your online shop. Your customer has paid!

Sunday, March 06, 2022

Few Facts - About Cards Transactions

 To date 2022, credit debit cards accounts for nearly a huge percent of all retail non-cash payments, possible a fivefold increase in just a few years.

Growth has been sharp in both online (PIN-based) and offline (signature-based) debit.

ATM or POS processing can occur across multiple paths, either directly (through a bank's owned ATM, typically called "On Us"),

Or through one of many shared networks where the card holder is using a terminal that is owned and operated by a another entity is called "Not-On-Us" trasanctions.

An example of the cooperative networks is STAR, which is owned by First Data Corporation.

With more than 1.7 million locations across the United States, handling over 5,700 financial institutions with over 134 million cards,

STAR is just one of the many networks that are available to banks and other financial institutions that can be used to project their financial services to their customer base.

Other industry competitors in this marketplace worldwide are VisaNet, MasterCard, Pulse, NYCE, Multibanco, Interac, LINK, JCB, and others.

In total, there are more than 60 major networks worldwide available to both consumers and financial institutions

Transaction Switching and Routing - In BASE24-eps

 BASE24-eps provides a highly flexible routing structure for transactions.


This flexibility not only routes transactions to the appropriate network, card association, processor or internal system for authorization, but it also helps users gain lower interchange charges by factoring in the total path when determining the authorization destination.

Determining the card issuer using a Card prefix lookup is decoupled from choosing the destination. The Card prefix lookup determines the destination profile which is then used to determine the destination along with the:

  • Source Profile
  • Destination Profile
  • Transaction Type
  • Account Type 1 (FROM account type)
  • Account Type 2 (TO account type)
  • Method of consumer authentication (PIN present, chip card, and so on)

This flexibility in transaction routing accommodates different account types that might reside on different systems and different platforms.

  • Users can customize their transaction processing at various stages in the transaction life cycle, which includes:
  • Pre-screening before transactions are sent to an external authorizer
  • Defining the processing steps for real time internal authorization
  • Defining the processing steps for stand-in authorization
  • Specifying the destination of advice messages following authorization
  • Specifying how the database should be impacted during the post-authorization process

The first step in this process was decoupling the logic to determine the issuer from the routing logic. This allows one source to route differently than another source. Routing means how to get to the issuer.

An issuer could be a back-end host system, payment network (e.g. Visa or MasterCard), or authorization provided by BASE24-eps.

The routing logic had to be robust and provide functionality for all possible channels, including alternate paths if the issuer was unavailable.

Initially the logic to determine the issuer used the prefix (up to the first 11 digits of the PAN) to determine the issuer.

The outcome of this was the Destination Route Profile which was used by the routing logic to determine how to get to the issuer.

Each source of transactions in the system was assigned a Source Route Profile allowing sources to be grouped together when the same routing logic should be used.

This would allow a different way to determine the issuer to be used without having to change the routing logic.

The next step was providing an authorization engine that was flexible enough to process transactions from both the ATM and Point-of-Sale channels along with potentially other existing channels and new channels to come.

This was accomplished by creating a script engine to orchestrate the authorization logic. Scripts could be written for each transaction type and even by channel.

Routing determined the script to execute if the transaction was authorized by BASE24-eps, either as the initial destination or an alternate destination (stand-in).

Because the input to routing was the Source Route Profile and the Destination Route Profile different scripts could be executed based on the destination as well as the source.

This allows any slight difference between the logic for a channel to be managed by the script. Now one might be thinking each script will contain quite a bit of duplicate logic; read the Card, validate the Card, verify the PIN, etc.

Shared logic is written in sub-scripts which can be shared across the scripts

Reciprocal and National Bridge Transactions - Definition

Reciprocal Transaction - The card holder initiates a transaction at a device that is owned by a bank that is a member of a different regional network.

In this case, a gateway is used to switch the transaction. Example: A London resident attempts to withdraw money from an ATM or POS in Edinburgh, Scotland. An agreement between the network in Scotland and the network in London England allows the transaction to be switched from one regional network to another.

National Bridge Transactions - The card holder uses a device at a bank that is not their own, and the two banks belong to different regional networks that do not have any agreement. Both banks must belong to the same national network.

The transaction is handed from the ATM or POS regional network to the national network, and finally to the authorizing bank's regional network. In this case, there are three switches involved. 

Saturday, February 05, 2022

ACI UPF Framework - An Overview

 The UP Framework is at the core of ACI’s Universal Payments strategy to enable end-to-end enterprise payments. It is a set of technologies and frameworks that orchestrate all aspects of payments processing for any payment type, any channel, any currency and any network. Combined with ACI’s leading solutions, it delivers an innovative architecture that bridges existing systems and future needs.

               ACI’s UP Framework enables customers to adopt an enterprise payments strategy, moving beyond monolithic applications to loosely coupled, service-oriented solutions. Both flexible and functionally rich, the UP Framework enables institutions to evolve their payments processing from legacy platforms to a new, componentized architecture that is capable of managing payments of all types and from all channels in a consistent, efficient and profitable manner. 

How does it work?

                The UP Framework extracts core payments functionality from applications and exposes the business logic as well-defined, standards-based service interfaces. These service interfaces unlock the intrinsic value of the business logic and allow it to be more easily shared across ACI’s products and existing payment solutions. Approaching payments in this manner radically reduces process duplication, which reduces the need for duplicate infrastructure and ultimately leads to lower overall costs, better reuse and greater processing efficiency. Well-defined service interfaces also enable more streamlined interaction between ACI solutions and existing customer assets, preserving IT investments and shortening the delivery cycles for implementation and new product innovation.

             ACI’s Universal Payments Platform paves the way to true enterprise payments. Common business logic inherent in ACI’s payment solutions, along with shared data models based on ACI’s Payment Information Model (PIM), are incorporated into the UP Framework. The result is an enterprise platform that allows financial institutions to view payments corporate-wide and implement a service-oriented architecture that optimizes business processes regardless of payment type, currency, entry channel or settlement mechanism.

            ACI UPF provides a flexible and functionally rich framework based on a componentized architecture that is capable of providing a robust, consistent and efficient payment platform.

This Architecture, depicted above, is composed of 4 main areas that are described in subsequent sections.

            ·       Platform – the payments processing and business operations servers

            ·      Tools – applications for extending and testing the platform

            ·      Horizontal Frameworks – underlying technology components used within the platform

            ·      Cartridges – application modules developed for use within the platform

The UPF technology provides a common platform through which payments services can be orchestrated. These services can be from ACI’s existing solutions, or any financial institutions provided services that are needed across the full workflow of any payment. 

The platform provides a common layer for integration, eliminating inefficient point-to-point interfaces, the solution provides endpoints that needs to be defined only once, but can be re-used many times for different services allowing for agility to respond quickly to new business initiatives and importantly new customer demands. Each endpoint protects other core systems from changes, and makes adoption of new services, products and technical requirements simple. 

The UP Framework provides a central repository of payments data, and can interact with customer channels to provide real-time, personalized data. 

The UP Framework forms the core of the applications and it is being widely adopted in every ACI solution offerings such as transaction banking, consumer solutions and other ACI solutions.

Benefits

·      Provides a holistic view of the customer’s payments activity, regardless of how they decide to interact.

·      Enables new customer channels to be supported through configuration which enables rapid deployment as new devices come to market.

·      Provides a common service across devices, allowing customers to start a transaction on one channel, and complete it on another.

·      Enables new ‘products’ to be configured rapidly, either by the use of new orchestrated services, or by the definition of existing services specific to the customer needs (e.g. special FX tiers).

·      Drives specific customer outcomes via attributes within the payment flow by accessing other enhanced services that can be exposed through the UPF.

·      Provides a tool for the management of different payment input formats that the customer might want to provide to you; enabling the customer to interact with you under their own needs not driven by the restrictions.

·      Provides interface to CRM and loyalty applications to support enhanced authorization based on customer class or status.

ACI UPF Product integrated into Azure DevOps

 


Wednesday, December 29, 2021

Cryptography – Examples

 1.WhatsApp Encryption:

End-to-end encryption in WhatsApp is a notable example of cryptographic encryption these days. This functionality is available in WhatsApp via the asymmetry model or through public-key techniques. Only the intended recipient is aware of the real message. After installing WhatsApp, public keys are registered with the server, and messages are sent.

2. Digital signatures:

Digital signatures are another real-time application of cryptography. When two clients need to sign paperwork for a commercial transaction. However, if two clients never meet, they may not believe each other. Then, encryption in digital signatures guarantees improved authenticity and security.

3. Email Encryption/Decryption:

Email encryption protects the content of emails from anyone outside of the email discussion who wants to access a participant’s information. An email is no longer readable by a human when it is encrypted. Your emails can only be unlocked and encrypted with your private email key.

4. Authentication of SIM cards:

The SIM must be authenticated before it may be used to access the network. The operator generates a random number and sends it to the mobile device. This random number, together with the secret key Ki, is fed into the A3 algorithm (it is this Ki that recently has been compromised). The result of this computation is returned to the operator, who compares it to the result of the calculation he performed himself.

5. Disk Encryption:

Disk encryption software encrypts your whole hard disc, eliminating the need to worry about leaving any traces of unencrypted data on your disc. PGP may be used to encrypt data as well. In this example, PGP encrypts the file with IDEA using the user’s private key and a password given by the user. To unlock the file, the same password and key are needed.

Types of Cryptography

1. Secret Key Cryptography (Symmetric Cryptography)

2. Public Key Cryptography (Asymmetric Cryptography)

3. Hash Functions

1. Secret Key Cryptography (Symmetric Cryptography):

Secret Key Cryptography, also known as symmetric cryptography, encrypts data with a single key. Because symmetric cryptography uses the same key for both encryption and decryption, it is the simplest kind of cryptography.

The cryptographic method encrypts the data using the key in a cypher, and when the data has to be retrieved again, a person entrusted with the secret key can decode the data. Secret Key Cryptography may be used on both in-transit and at-rest data, although it is most often employed on at-rest data since revealing the secret to the message’s receiver might lead to compromise.

Secret-key or symmetric-key encryption algorithms generate a predetermined number of bits known as a block cypher with a secret key that the creator/sender uses to encrypt data and the receiver uses to decrypt it.

It is written as P = D(K,E( P) )

Where,

K = Encryption and decryption key

P = Plain text

D = Decryption

E§ = Encryption of plain text

Some of the examples of Secret Key Cryptography are as follows:

  • AES
  • DES
  • Caesar Cipher

2. Public Key Cryptography (Asymmetric Cryptography):

The Public Key to encrypt data, cryptography, also known as asymmetric cryptography, employs the use of two keys. The first key is used for encryption, while the second key is utilized to decode the communication.

One key is kept secret and is known as the “private key,” while the other is released openly and may be used by anybody, therefore the “public key.” The keys’ mathematical relationship is such that the private key cannot be deduced from the public key, while the public key can be deduced from the private key. The private key should not be disseminated and should be kept only by the owner. Any other entity can be granted the public key.

Public-key or asymmetric-key encryption algorithms encrypt information with a public key associated with the creator/sender and decode that information with a private key known only to the originator (unless it is exposed or they want to share it).

It is written as P = D(Kd,E(Ke,P)).

Where,

Ke = Encryption key

Kd = Decryption Key

D = Decryption

E(Ke,P) = Plain text encryption using an encryption key

P = Plain text

Some of the examples of Private Key Cryptography are as follows:

  • ECC
  • Diffie-Hellman
  • DSS

3. Hash Functions:

Hash functions are one-way, irreversible functions that secure data at the expense of not being able to recover the original message. Hashing is a method of converting a given string into a set length string. A decent hashing algorithm will provide distinct outputs for each input. The only method to crack a hash is to test every conceivable input until you obtain the same hash. A hash can be used to hash data (for example, passwords) and in certificates.

Some of the most well-known hashing algorithms are as follows:

  • MD5
  • SHA-1
  • SHA-2 family which includes SHA-224, SHA-256, SHA-384, and SHA-512
  • SHA-3
  • Blake 2
  • Blake 3
  • Whirlpool

Monday, December 27, 2021

Card Tokenization

In India, RBI announced new rules for Tokenization, which is going to effective from Jan 1st 2022. Lot of my colleagues, friends are asking whats the impact to end users. Just wanted to write few things about Tokenization and that impact.

What is card tokenisation?

When you shop online or even book tickets on travel portals, you tend to save your credit card details in those websites. So, you just don’t need to remember your card details each time you shop. Just enter the CVV and you check out in a matter of seconds.

But that was risky. If your online site or travel portal gets hacked, your card details could be leaked. Besides, you may have also saved your card details on some website years ago and forgotten all about that. “There is a high chance some of the merchants will not know how to store secure card information,”

Enter tokenisation. This is a process of converting your card details into a unique token that is specific to your card and only to one merchant at a time. This code masks the true details of your card, without which no one can misuse your card. This token can be saved on the online portal’s server.

The new tokenization rule that comes into effect from January 1 2022, prohibits all online shopping portals from saving your card numbers, CVV, expiry date etc. on their servers. So, you either make a token before you buy an item and save that token on the particular website (for future use) or enter your card details every time you buy stuff off the internet.

“In the past, there have been instances of data leaks from merchant websites; digital transactions are also growing significantly, requiring added safety. So, this is a precautionary step mandated by the regulator to enhance card data security,” 

How does this card tokenisation work?

At check-out time on an online shopping portal, enter your card details and opt for tokenisation. Your merchant forwards it to the respective bank or the card networks (VISA, Rupay, Mastercard, etc). A token is generated and sent back to your merchant, which then saves it for you. Now, the next time you come back to shop, just select this saved token at check-out time. You will see the same masked card details and last four digits of your card number. You will need to enter your CVV and complete the transaction. Tokenisation is not mandatory, but it makes it easier to shop repeatedly.

“As a customer, you don’t need to remember the token. The end-customer experience is not changing while making the payment,” 

Is the tokenization service free?

Yes, tokenisation of card is absolutely free, and can be availed by anyone. Currently, tokenisation is applicable only to domestic cards. International cards are not covered by this guideline. You can request for tokenisation on any number of cards to perform a transaction. “If a merchant has not integrated with the card network and bank issuing the cards by December 31, you will have to enter the card details every time, as you cannot store your card details in the token format,” 

Does a card have different tokens for different merchants?

One token is limited to just one card and one merchant (online portal). For instance, if you have, say, an ICICI Bank credit card tokenised on Amazon, then, this same card will have a different token on Flipkart. However, as a customer you don’t need to know or remember the token linked with the card. You can tokenise multiple cards with the same merchant, or tokenise the same card with multiple merchants.

What is the best way to manage my tokens?

If you have multiple cards and like to shop online frequently, there’s a better way to manage your tokens. Say, you want to remove some tokens you had got long ago from a specific website. Mathur of Razorpay says that an issuer bank will now provide a dedicated portal (on its own bank’s website) to manage tokenised cards. In simple words, your dashboard would now show you a list of your cards and where (merchants) you have tokenized them. Delete the tokenised cards of websites you do not use frequently.

What will happen to the token once the card gets replaced or renewed or reissued or upgraded?

You need to visit the merchant page and create a fresh token. That is because your new card (credit or debit) comes with a new number and CVV. 

Sunday, December 19, 2021

BaaS - How Banking as a Service works

 


Digital Payments - In Future

Digital payments must be 

  • Faceless, 
  • Cashless and 
  • via completely electronic means of end to end transaction 

without compromising availability, provenance and traceability, repudiation and of course information security. 

Since last decade digital payments have garnered a lot of interest and adoption from the users and positively influenced the digital agenda for enterprises and governments.

According to Gartner,

  • 5 countries will launch digital initiatives to remove cash from circulation by 2023 fully replacing cash by digital means
  • Global cash in circulation will reduce after decades of year-on-year increases by 2024
  • Consumers using mobile proximity payment methods will be almost 2 billion, up from 2019’s figure of less than 1 billion, by 2024

Future Technologies of Digital Payments
Use of Biometric - Using unique fingerprints and facial recognition, digital payments can be enabled via authenticating the users and authorizing the transactions, offering accurate, secure, instant and hassle-free way, rather than remembering various PINs and passwords from multiple entities and keeping track all the time. Most of the digital payment players leverage device based authentications and tokenize the transactions without need of user interventions. Most of the payment wallets running on the mobile devices have successfully paved way of this method and good amount of research and development is happening in this area.
Use of Voice/Speech Analytics and AI/ML based algorithms - They have been around for few years now and are driving the way we control our home appliances, even interact while driving, etc. As these technologies will become more efficient and accurate the digital payments would be the ones to leverage them in real life. This will help create more secure and simple way to trade and transact within the digital payment domain.
Near Field / Contactless - Using proximity of device via EVM & RFIDs, POS machines via NFC - there are many ways embedded workflows can be built to provide easy and secure way to transact. There are major credit card players already issuing the contactless that will work with ATMs and POS terminals and even interact with the mobile devices by and between the stakeholders involved in the workflow.
DLT's – Digital Ledgers / Blockchains’ foray with digital currency is well known and many regulators are finding ways to strike a balance between autonomous currencies and digital payments, which is significantly decentralized, anti-fraud and business continuity driven DLT’s will surpass our expectations and establish the technological governance to fool proof the digital transactions in years to come.
AI/ML and Data Science – It will substantially improve the insights on the volume and velocity of digital transactions which is a common barrier for fraud detection, risk management and regulatory mandates etc. Use of AI/ML coupled with established data science practices will pave way for governments and banks for traceability, customer acquisition and retention, royalty management, credit scores, marketing etc., expanding the canvas of intelligence of digital payment transactions.
The first wave of the digital payments started a few years ago. Users can no longer be constrained by banking hours, type of devices, physical cards etc., to transact by and between entities. 

AI - In Banking

 


Sunday, November 07, 2021

Revenue Streams for Financial Sectors/Banks

 Its NOT that easy to define revenue model for Financial Sectors and Banks. There are 5 Main streams for Financial sectors. Its also applicable to Banks

  1. Interchange
  2. Interest
  3. Payments
  4. Financing
  5. Software
Interchange is the portion of spend that the card issuer gets after cardholders use the cards to spend.

Interest paid on balances is perhaps the most obvious revenue stream in banking: simply park funds in a bank and let it pay you at the end of the month.

Just like banks, Financial Companies also, can get revenues from payment fees. Building a banking experience means offering payments in the form of ACH, wire, checks and bill pay.

Financing means giving your customers funds today and expecting them to pay them back in the future, potentially with an added fee or interest. 

Software revenues are the last (and often most overlooked) type of revenue associated with financial features. As the features become an important pillar in your software, you may choose to offer them at an extra cost.

Rise of Alternative Payments

 


Data -> Information -> KNOWLEDGE -> Wisdom