Apply FSD Tag
Analyzing recent trends from vintage analysis published in the Experian-Oliver Wyman Market Intelligence Reports.
In my previous three postings, I’ve covered basic principles that can define a risk-based authentication process, associated value propositions, and some best-practices to consider. Finally, I’d like to briefly discuss some emerging informational elements and processes that enhance (or have already enhanced) the notion of risk-based authentication in the coming year. For simplicity, I’m boiling these down to three categories: 1. Enterprise Risk Management – As you’d imagine, this concept involves the creation of a real-time, cross channel, enterprise-wide (cross business unit) view of a consumer and/or transaction. That sounds pretty good, right? Well, the challenge has been, and still remains, the cost of developing and implementing a data sharing and aggregation process that can accomplish this task. There is little doubt that operating in a more silo’d environment limits the amount of available high-risk and/or positive authentication data associated with a consumer…and therefore limits the predictive value of tools that utilize such data. It is only a matter of time before we see more widespread implementation of systems designed to look at a single transaction, an initial application profile, previous authentication results, or other relationships a consumer may have within the same organization -- and across all of this information in tandem. It’s simply a matter of the business case to do so, and the resources to carry it out. 2. Additional Intelligence – Beyond some of the data mentioned above, some additional informational elements emerging as useful in isolation (or, even better, as a factor among others in a holistic assessment of a consumer’s identity and risk profile) include these areas: IP address vs. physical address comparisons; device ID or fingerprinting; and biometrics (such as voice verification). While these tools are being used and tested in many organizations and markets, there is still work to be done to strike the right balance as they are incorporated into an overall risk-based authentication process. False positives, cost and implementation challenges still hinder widespread use of these tools from being a reality. That should change over time, and quickly to help with the cost of credit risk. 3. Emerging Verification Techniques – Out-of-band authentication is defined as the use of two separate channels, used simultaneously, to authenticate a customer. For example: using a phone to verify the identity of that person while performing a Web transaction. Similarly, many institutions are finding success in initiating SMS texts as a means of customer notification and/or verification of monetary or non-monetary transactions. The ability to reach out to a consumer in a channel alternate to their transaction channel is a customer friendly and cost effective way to perform additional due diligence.
In my previous two blog postings, I’ve tried to briefly articulate some key elements of and value propositions associated with risk-based authentication. In this entry, I’d like to suggest some best-practices to consider as you incorporate and maintain a risk-based authentication program. 1. Analytics – since an authentication score is likely the primary decisioning element in any risk-based authentication strategy, it is critical that a best-in-class scoring model is chosen and validated to establish performance expectations. This initial analysis will allow for decisioning thresholds to be established. This will also allow accept and referral volumes to be planned for operationally. Further more, it will permit benchmarks to be established which follow on performance monitoring that can be compared. 2. Targeted decisioning strategies – applying unique and tailored decisioning strategies (incorporating scores and other high-risk or positive authentication results) to various access channels to your business just simply makes sense. Each access channel (call center, Web, face-to-face, etc.) comes with unique risks, available data, and varied opportunity to apply an authentication strategy that balances these areas; risk management, operational effectiveness, efficiency and cost, improved collections and customer experience. Champion/challenger strategies may also be a great way to test newly devised strategies within a single channel without taking risk to an entire addressable market and your business as a whole. 3. Performance Monitoring – it is critical that key metrics are established early in the risk-based authentication implementation process. Key metrics may include, but should not be limited to these areas: • actual vs. expected score distributions; • actual vs. expected characteristic distributions; • actual vs. expected question performance; • volumes, exclusions; • repeats and mean scores; • actual vs. expected pass rates; • accept vs. referral score distribution; • trends in decision code distributions; and • trends in decision matrix distributions. Performance monitoring provides an opportunity to manage referral volumes, decision threshold changes, strategy configuration changes, auto-decisioning criteria and pricing for risk based authentication. 4. Reporting – it likely goes without saying, but in order to apply the three best practices above, accurate, timely, and detailed reporting must be established around your authentication tools and results. Regardless of frequency, you should work with internal resources and your third-party service provider(s) early in your implementation process to ensure relevant reports are established and delivered. In my next posting, I will be discussing some thoughts about the future state of risk based authentication.
In my last blog posting, I presented the foundational elements that enable risk-based authentication. These include data, detailed and granular results, analytics and decisioning. The inherent value of risk-based authentication can be summarized as delivering an holistic assessment of a consumer and/or transaction with the end goal of applying the right authentication and decisioning treatment at the right time. The opportunity, especially, to minimize fraud losses using fraud analytics as part of your assessment is significant. What are some residual values of risk-based authentication? 1. Minimized fraud losses involves the use of fraud analytics, and a more comprehensive view of a consumer identity (the good and the bad), in combination with consistent decisioning over time. This analysis will outperform simple binary rules and more subjective decisioning. 2. Improved consumer experience. By applying the right authentication and treatment at the right time, consumers are subjected to processes that are proportional to the risk associated with their identity profile. This means that lower-risk consumers are less likely to be put through more arduous courses of action, preserving a streamlined and often purely “behind the scenes” authentication process for the majority of consumers and potential consumers. In other words, you are saving the pain for the bad guys -- and that can be a good thing. 3. Operational efficiencies can be successful with the implementation of a well-designed program. Much of the decisioning can be done without human intervention and subjective contemplation. Use of score-driven policies affords businesses the opportunity to use automated authentication processes for the majority of their applicants or account management cases. Fewer human resources will be required which usually means lower costs. Or, it can mean the human resources you possess are more appropriately focused on the applications or transactions that warrant such attention. 4. Measurable performance is critical because understanding the past and current performance of risk-based authentication policies allows for the adjustment over time of such policies. These adjustments can be made based on evolving fraud risks, resource constraints, approval rate pressures, and compliance requirements, just to name a few. Given its importance, Experian recommends performance monitoring for our clients using our authentication products. In my next posting, I’ll discuss some best practices associated with implementing and managing a risk-based authentication program.
The term “risk-based authentication” means many things to many institutions. Some use the term to review to their processes; others, to their various service providers. I’d like to establish the working definition of risk-based authentication for this discussion calling it: “Holistic assessment of a consumer and transaction with the end goal of applying the right authentication and decisioning treatment at the right time.” Now, that “holistic assessment” thing is certainly where the rubber meets the road, right? One can arguably approach risk-based authentication from two directions. First, a risk assessment can be based upon the type of products or services potentially being accessed and/or utilized (example: line of credit) by a customer. Second, a risk assessment can be based upon the authentication profile of the customer (example: ability to verify identifying information). I would argue that both approaches have merit, and that a best practice is to merge both into a process that looks at each customer and transaction as unique and therefore worthy of distinctively defined treatment. In this posting, and in speaking as a provider of consumer and commercial authentication products and services, I want to first define four key elements of a well-balanced risk based authentication tool: data, detailed and granular results, analytics, and decisioning. 1. Data: Broad-reaching and accurately reported data assets that span multiple sources providing far reaching and comprehensive opportunities to positively verify consumer identities and identity elements. 2. Detailed and granular results: Authentication summary and detailed-level outcomes that portray the amount of verification achieved across identity elements (such as name, address, Social Security number, date of birth, and phone) deliver a breadth of information and allow positive reconciliation of high-risk fraud and/or compliance conditions. Specific results can be used in manual or automated decisioning policies as well as scoring models, 3. Analytics: Scoring models designed to consistently reflect overall confidence in consumer authentication as well as fraud-risk associated with identity theft, synthetic identities, and first party fraud. This allows institutions to establish consistent and objective score-driven policies to authenticate consumers and reconcile high-risk conditions. Use of scores also reduces false positive ratios associated with single or grouped binary rules. Additionally, scores provide internal and external examiners with a measurable tool for incorporation into both written and operational fraud and compliance programs, 4. Decisioning: Flexibly defined data and operationally-driven decisioning strategies that can be applied to the gathering, authentication, and level of acceptance or denial of consumer identity information. This affords institutions an opportunity to employ consistent policies for detecting high-risk conditions, reconcile those terms that can be changed, and ultimately determine the response to consumer authentication results – whether it be acceptance, denial of business or somewhere in between (e.g., further authentication treatments). In my next posting, I’ll talk more specifically about the value propositions of risk-based authentication, and identify some best practices to keep in mind.
By: Kennis Wong As I said in my last post, when consumers and the media talk about fraud and fraud risk, they are usually referring to third-party frauds. When financial institutions or other organizations talk about fraud and fraud best practices, they usually refer to both first- and third-party frauds. The lesser-known fraud cousin, first-party fraud, does not involve stolen identities. As a result, first-party fraud is sometimes called victimless fraud. However, being victimless can’t be further from the truth. The true victims of these frauds are the financial institutions that lose millions of dollars to people who intentionally defraud the system. First-party frauds happen when someone uses his/her own identity or a fictitious identity to apply for credit without the intention to fulfill their payment obligation. As you can imagine, fraud detection of this type is very difficult. Since fraudsters are mostly who they say they are, you can’t check the inconsistencies of identities in their applications. The third-party fraud models and authentication tools will have no effect on first-party frauds. Moreover, the line between first-party fraud and regular credit risk is very fuzzy. According to Wikipedia, credit risk is the risk of loss due to a debtor's non-payment of a loan or other line of credit. Doesn’t the definition sound similar to first-party fraud? In practice, the distinction is even blurrier. That’s why many financial institutions are putting first-party frauds in the risk bucket. But there is one subtle difference: that is the intent of the debtor. Are the applicants planning not to pay when they apply or use the credit? If not, that’s first-party fraud. To effectively detect frauds of this type, fraud models need to look into the intention of the applicants.
Vintage analysis, specifically vintage pools, present numerous useful opportunities to further understand the risks within specific portfolios.
By: Kennis Wong When consumers and the media talk about fraud and fraud risk, nine out of ten times they are referring to third-party frauds. When financial institutions or other organizations talk about fraud, fraud best practices, or their efforts to minimize fraud, they usually refer to both first- and third-party frauds. The difference between the two fraud types is huge. Third-party frauds happen when someone impersonates the genuine identity owner to apply for credit or use existing credit. When it’s discovered, the victim, or the genuine identity owner, may have some financial loss -- and a whole lot of trouble fixing the mess. Third-party frauds get most of the spotlight in newspaper reporting primarily because of large-scale identity data losses. These data losses may not result in frauds per se, but the perception is that these consumers are now more susceptible to third-party frauds. Financial institutions are getting increasingly sophisticated in using fraud models to detect third-party frauds at acquisition. In a nutshell, these fraud models are detecting frauds by looking at the likelihood of applicants being who they say they are. Institutions bounce the applicants’ identity information off of internal and external data sources such as: credit; known fraud; application; IP; device; employment; business relationship; DDA; demographic; auto; property; and public record. The risk-based approach takes into account the intricate similarities and discrepancies of each piece of data element. In my next blog entry, I’ll discuss first-party fraud.
Understanding vintage pools in reference to vintage analysis
In addition to behavioral models, collections and account management groups need the ability to implement collections workflow strategies in order to effectively handle and process accounts, particularly when the optimization of resources is a priority. While the behavioral models will effectively evaluate and measure the likelihood that an account will become delinquent or result in a loss, strategies are the specific actions taken, based on the score prediction, as well as other key information that is available when those actions are appropriate. Identifying high-risk accounts, for example, may result in strategies designed to accelerate collections management activity and execute more aggressive actions. On the other hand, identifying low-risk accounts can help determine when to take advantage of cost-saving actions and focus on customer retention programs. Effective strategies also address how to handle accounts that fall between the high- and low-risk extremes, as well as accounts that fall into special categories such as first payment defaults, recently delinquent accounts and unique customer or product segments. To accommodate lenders with systems that cannot support either behavioral scorecards or strategies, Experian developed the powerful service bureau solution, Portfolio Management Package, which is also referred to as PMP. To use this service, lenders send Experian customer master file data on a daily basis. Experian processes the data through the Portfolio Management Package system which includes calculating Fast Start behavior scores and identifying special handling accounts and electronically delivers the recommended strategies and actions codes within hours. Scoring and strategy parameters can be easily changed, as well as portfolio segmentation, special handling options and scorecard selections. PMP also supports Champion Challenger testing to enable users to learn which strategies are most effective. Comprehensive reports suites provide the critical information needed for lenders to design strategies and evaluate and compare the performance of those strategies.
We’ve stopped taking phone applications and are using the out-of-wallet questions for Internet credit applications. Are we going overboard?The Red Flags Rule does not preclude phone applications or otherwise limit the manner in which you m ay accept applications for covered accounts. However, different methods to open covered accounts present different identity theft risks, and you must consider those differing risks in identifying the relevant Red Flags for each type of covered account that you provide.
Champion/Challenger strategy testing is performed using … This allows strategies to be tested before rolling them out across the entire portfolio. The purpo
Regardless of the specific checks and overall processes incorporated into your Red Flags Identity Theft Prevention Program, the use of an automated decisioning strategy or strategies will allow you to: Deliver consistent responses based on objective authentication results, while eliminating subjectivity often found in more manual review processes. Save time and money associated with a manual review process currently attributed to Red Flag Rule referrals. Provide examiners a detailed process flow including decision elements. Create champion / challenger flows to test, compare and alter new strategies over time. Revise, over time, the specific elements used in your decisioning to appropriately weight each from a fraud detection and/or compliance perspective. Experian's consumer authentication products provide hosted decisioning strategies that alleviate the burden on our clients associated with maintenance and development of those processes. Whether you facilitate your own strategies or use a service provider's hosted strategies, it is important to ensure you are maximizing their ability to balance pass rates, fraud detection and compliance requirements.
Part 3 Reducing operational and overhead costs starts with the automation of tasks that would otherwise be performed by a human resource. By leveraging an advanced segmentation approach, it is possible to better identify accounts that will not require collector intervention. While automation is not a new concept to collections, significant benefits of modern systems include: • enabling more functions to be automated; • effectiveness of the automated functions to be validated; and • more changes made per year versus legacy systems. Fixing a bad phone number: The old way To illustrate effective automation, let’s use an example where an account is found to have a bad phone number. A common approach to this problem might be for the outbound collector to route the account to a skip specialist who can perform research. This often has the receiving party starting the process after the nightly batch process has transferred the account across departments. If a phone number is found, the account may be manually routed back to an outbound queue and if not, a no-contact letter may be generated. Additionally, there are tasks that need to be performed such as noting accounts that consume a collector’s time. Fixing a bad phone number: The new way A more efficient and cost-effective approach would be for the employee identifying the need for a new number to click a pre-defined button to let the collections system know of the issue. The system could then automatically call out to an external data source to: • collect the new number; • repopulate the appropriate field; • reroute the account back to the most appropriate outbound queue; • log a history of all automated functions performed, and • do all of this within just a few seconds! If the appropriate number cannot be located, the system would know which letter to send and then route the account to the most appropriate holding queue. Reducing operational costs After automation, the operational costs are further reduced by identifying which actions can be effectively replaced by lower-cost options that yield the same results, or even eliminating actions that present no substantial value. For example, why make a call when a letter will suffice? And what happens if we subsequently replace that letter with a text message or take no action at all? Intelligent features of modern systems such as champion/challenger testing can be employed to support a continuous learning process that increases the financial benefits of automation as experience and knowledge is gained. As new automation is introduced and validated as beneficial, other improvement theories can be tested and subsequently abandoned or adopted. Considering the possible impact of automation and action reductions on cost savings let’s assume that three dial attempts are made on the average delinquent account in the first 30 days at a cost of 25 cents each and on the fourth attempt there is a right party contact, which costs an additional $2.50 (assuming the talk time is five minutes). Adding one letter at 75 cents, we have a total cost to collect of $4.00 before the account hits 31 days past due. With 250,000 customers entering collections each month, we can save $200,000 each month in the early stage alone with just a 20 percent improvement. This result could easily be achieved by reducing talk time and eliminating unnecessary actions or unproductive call attempts. Annually that adds up to approximately $2.5 million dollars in savings, in this example. Champion/challenger tests, as well as, the improved functionality of modern systems can also be extended beyond the in-house work stream. Evaluating and comparing external agencies can significantly improve agency performance as well as enable the lender to better manage placement costs. For example, if a lender allocates 1,000 accounts to an external agency each month, with an average balance of $3,000, the total dollars allocated annually is $36 million. If 22 percent of the debt is collected and a 25 percent commission is charged, the net to the lender is nearly $6 million. Improving that return by a mere 4 percent through better allocation strategies, which is a conservative goal, we add another million to the bottom line each year. By factoring in the ability of next generation collections systems to automate most aspects of the placement process itself, including recalling accounts, we further improve efficiencies, free up valuable resources and allow management greater control of the process. Additional benefits of functionally rich modern systems also enable management to grant external resources various levels of remote access to the collections systems to better monitor activities and ensure that transactional data is properly captured. In addition to granting external agencies remote access, modern collections systems can also enable collectors to work from home-based workstations to further reduce operational costs. Many industry analysts see this as an emerging trend over the next few years, particularly when productivity can be monitored in real-time. My next blog will continue the discussion on the benefits of next generation collections systems and will provide details on improved change management processes.
Market risk and credit risk are different. The bank can offset market risk by purchasing interest rate swaps or other interest rate derivatives.