HoC 85mm(Green).tif

 

Business, Energy and Industrial Strategy Committee 

Oral evidence: Fraudulent company registrations: Economic Crime and Corporate Transparency Bill, HC 862

Tuesday 8 November 2022

Ordered by the House of Commons to be published on 8 November 2022.

Watch the meeting 

Members present: Darren Jones (Chair); Bim Afolami; Ruth Edwards; Andy McDonald; Charlotte Nichols; Mark Pawsey.

Questions 39 - 63

Witnesses

II: Nick Van Benschoten, Director, International Illicit Finance, UK Finance; David Callington, Head of Fraud, HSBC; Donald Toon, Head of Risk Threat Mitigation, NatWest.


 

Examination of witnesses

Witnesses: Nick Van Benschoten, David Callington and Donald Toon.

Chair: We are now going to move to panel 2. All three are in the room. We have Nick Van Benschoten, who is the director of international illicit finance at UK Finance, the trade body; David Callington, who is the head of fraud at HSBC; and Donald Toon, who is the head of risk threat mitigation for NatWest.

Q39            Charlotte Nichols: We have heard some truly extraordinary evidence from our previous session this morning. On what scale are fraudulent companies getting access to existing customers bank accounts or setting up new bank accounts in their name?

David Callington: From what we see, and I can talk only for HSBC UK, the issue is not necessarily the identity theft issue. It is not somebody setting up a business account in your name. It is more accounts and lending being taken out by an individual, and their identity is absolutely verified. It is not an identity challenge; it is an intent challenge. As they are opening up their account with us, what is their intent to operate the account? Do they want to run and operate a legitimate business account and take legitimate lending, or is there intent from day one to defraud, to take out lending and not to pay it back?

It is not a challenge of just know your customer and the due diligence undertaken at the time the account is opened. So much of this depends on the ongoing monitoring of the activity of the account once it is opened, because typically the problem we see is that the identity of the people who are opening the account and opening the business is verified.

Nick Van Benschoten: As David set out, the banking checks are quite detailed. They go beyond the verification of the details, but the verification happens on a multilayered basis. The banks check against a number of databases including, importantly, fraud databases of known bad actors. There are additional checks such as screening for sanctions, anti-money laundering and so on. One of the key challenges is that the fraud databases are backwards looking. They will include known bad actors, but they will not necessarily include new bad actors, as we have seen in cases where peoples identity has been put together synthetically from stolen hacks and addresses that have been used without the owners consent.

One key point we would note is in terms of Companies House reform. We think that it is going to be much better if Companies House does the checks in the first place, because that would give the banks an extra source of data to verify against. It also allows us to apply our checks with less of a backwards-looking view and more as somebody who has done the checks first, upfront.

Q40            Chair: Are you willing to pay for that if you are not going to do the work? Will you give Companies House money as the banking industry to do the checks for you?

Nick Van Benschoten: The banking industry is already subject to a number of taxations and levies. We also work with the Government in partnership, going beyond our regulatory obligations, on information sharing. We have worked with Companies House in a number of information sharing working groups. In addition, there is an economic crime levy being posed on the whole regulated sector, not just banking and finance. That will be coming in for next year for £100 million a year. We hope the Government will look forward to match fund that with some ring-fenced funding for economic crime. That is yet to be determined.

I understand your point is about who is going to pay. On the previous evidence about the fees, £12 is unprecedentedly low. There are some other countries I have mentioned in the Bill Committee. They are not the kind of countries you would expect the UK to be benchmarked against. We think £50 to £100 is a perfectly reasonable amount. We do not see any appreciable impact on UK competitiveness.

Donald Toon: Could I just pick up a little bit on what Nick just said? When you talk about the amount of effort that we put in on these checks, be they from a counter-fraud or an anti-money laundering and anti-financial crime perspective, if you look at what we do as a bank, we have just shy of 6,000 people whose full-time job is the prevention and detection of economic crime. That is what they do all the time. That is pushing 9% of the total bank staffing who just do that. We spend about £500 million on economic crime prevention, and that is what we will spend this year. Please, do not go away with any suggestion that banks do not spend money and put a huge amount of effort into this. On top of that, we are going to be paying the new economic crime levy.

There is an absolutely legitimate question about who should pay for the checks to be done. That is fair, but at the moment our concern is that we are paying to deliver our obligations under the law and under regulation. We voluntarily go above and beyond that.

As Nick said, we work very closely with law enforcement and with other public sector bodies. There is a UK economic crime plan. We are currently working on the redraft of that. We are developing a joint data strategy about how we share information so that it addresses some of these problems. We do work under a joint structure, led by the National Crime Agency, on public-private operational activity. That means we share information directly with law enforcement over and above what we are obliged to report. Then we work with them to get not only effective intelligence to support enforcement, but information back to help us strengthen our systems and controls.

We do a huge amount of work in this space. One of the major weaknesses is the point that is being addressed, and has been addressed by colleagues and by the previous panel, which is the weakness that exists around the ability to register companies and to do so with very little check. Can I just give one simple example?

Q41            Charlotte Nichols: Laudable though what you have just described is, my question was on the current scale of fraudulent companies getting access to existing bank accounts. Effectively, for us to be able to say whether the future legislation we are talking about is going to make an appreciable impact on that, we need to know what the scale of the issue is at the moment. We will get into what banks are or are not doing in my later questions. I am interested in knowing how big the issue is at the moment.

Donald Toon: I would say exactly the same as you heard from David. If we are talking about people having fraudulent access, that is not something we see as a significant issue. We see very little of that as a problem at all from that direct perspective. There is then the question of intent and the abuse of a company that has been created and verified. That may be because the company is taken over by others, or because there was always that illicit intent. That is where all of the ongoing monitoring comes in. There is this point of onboarding when we provide people with an account. Then there is all the ongoing monitoring that we do from a fraud and an anti-money laundering perspective to look to identify problematic behaviour.

I am in exactly the same position as HSBC in terms of scale. That kind of direct issue is not what we see. What we see is verified identities and verification that then leads us to provide an account, and then a behaviour that follows thereafter.

Q42            Charlotte Nichols: To follow up on that, we have spoken about what the banks are doing. How effective are current “know your customer checks for financial institutions in combatting fraudulent bank account registrations?

Nick Van Benschoten: As I mentioned before, the checks go beyond “know your customer”. They also include monitoring. The activity we undertake includes collaboration across other sectors. We see quite a lot of the driver of fraud being information that has been hacked or people who have been scammed through online websites or spurious text messages.

Companies House is definitely one of those enablers of fraud. As you have heard, it does not necessarily have the main impact, but one of the key points to note is that it also undermines consumer confidence. If consumers are unable to check the bone fides of companies they see, it makes it harder for them to maintain the proper standards of control and to keep themselves safe from purchase scams and investment scams. That is another form of fraud the banks are trying to fight.

In terms of effectiveness, we take a systems approach. We are very heavily regulated, but we work with partners in other sectors that are less heavily regulated. The key thing is getting everyone incentivised to manage the risk they bring into the system. The more we do that, the more effective we can get. I would commend the Government for bringing forward this Bill.

One of the points we have not touched on is the information-sharing powers in the regulated sector. That would not extend to online platforms, social media or telecoms, but it does extend across the financial sector and to e-money, crypto, lawyers and accountants. That is also helpful and will make us more effective by working more broadly together. We are not yet there. If Companies House was able to join us as a proactive gatekeeper, it would help us on that collaborative basis.

Q43            Charlotte Nichols: You have spoken about some of the risks there, including Companies House being one of the vulnerabilities. What would you identify as one of the other vulnerabilities within that systems approach you have mentioned?

Nick Van Benschoten: One of the key things is that it is sometimes very hard to do the right thing, because you have a hedge of different bits of legislation that are not necessarily aligned. The information-sharing protections for the regulated private sector in this Bill address one of those barriers, which is breach of confidence, but it does not go as far as the ability we have to share information with the National Crime Agency. We are doing the same thing. We are trying to prevent, detect and investigate economic crime. That is part of the purpose of the National Crime Agency. The banks and others are allowed to share information under the Crime and Courts Act without any civil liability, as long as it is for that purpose.

This Bill does not go that far, so we think there is scope to go a little further. Again, we welcome the fact the Government have looked to include the whole regulated sector. In future, perhaps we might also look to go to other sectors that bring risk into the system. My colleagues can probably give you a bit more practical detail, if that is of use.

Donald Toon: There are a couple of issues here. Nick absolutely identifies the issue around information sharing. It is quite a complex area of legislation at the moment. It does make it hard to identify the mechanisms that will enable you to share information and the protections you have for doing so in good faith, because there are clear protections against peoples personal information being shared.

He also identifies the issue around the totality of the system. The tech companies, the social media space and the large telecoms companies all hold relevant information and can be gateways into fraud and financial crime. Getting into a situation where we have effective regulation and effective provisions that encourage information sharing to tackle crime is absolutely where we want to be.

We know we can do that with the National Crime Agency. There is a very strong piece of legislation and a legislative gateway that gives us protections there. There is a particular carve-out at the moment in the Data Protection Act for sharing information for the purposes of the prevention, detection and investigation of fraud. We want to see that broadened because there are arguments around whether that means there is a restriction on sharing information for other forms of financial and economic crime.

There is a piece of DCMS legislation due to come through shortly, the DPDI Bill, which should have the provisions to extend that gateway. We have provisions in this Bill to extend protection, but we would like to see that go further with the necessary safeguards.

It is about clarity. There has to be a system that has a purpose, which is the prevention and detection of economic crime, and then there are the necessary safeguards against doing the right thing. That is the bit where it is out of kilter at the moment. You can talk about the different pieces of legislation, the different roles of different Departments from a government perspective and the different players in the private sector. It is about trying to knit all of this together into a single coherent system that is part of the issue.

That is a point we have made to Government, to law enforcement and to regulators in the work we are doing at the moment around the economic crime plan. What is the guiding line? How does this really get co-ordinated to that end? That has been a problem. My background is public sector law enforcement and tax fraud. That is what is missing. It was missing at that end and it is still missing today.

David Callington: Just to build on what Donald said, I would draw your attention to a report issued by Stop Scams UK in conjunction with RUSI. It was launched here a couple of weeks ago on 20 October. That does draw out some of the key challenges around cross-sector data-sharing.

As Donald said, the legislation allows it, but do the tone and intent of the legislation need to be tuned a little more to allow organisations to take a more balanced view of the risk of the data-sharing elements? Data sharing is absolutely key.

There is a good track record in the UK of data sharing for the prevention of fraud. We have Cifas and other bodies. As Nick said, a lot of them are backwards looking. These work cross-sector. Mobile network operators, telecoms companies and banks all use the same sorts of datasets to look for those bad actors and bad addresses.

One of those data sources that we refer to is a list of known fraudulent registered addresses of businesses. When we see a fraud committed, we will load it to that database and we will prevent that moving forward. I do not know the reach that has outside of the body that operates that dataset. Do others come in and make use of that dataset?

Q44            Charlotte Nichols: What rights of recourse do victims have if a loan is obtained or money is taken from their account by a fraudulent company or individual? How easy is the process for victims to get their money back? We heard a lot in the first session about the fraudulent loans that it has been possible to obtain—something that must be deeply distressing for those it impacts. How much work is being done within your organisations to make the process as straightforward as possible for victims to get that restitution?

Donald Toon: There are two separate issues here. When we are talking about customers who have been defrauded directly, there is a particular code within the industry for authorised push payments, the contingent reimbursement model code. That has a set of tests within it, which require the parties to the code—the large banks are essentially all parties to this code—to reimburse. There is an issue behind that about the determination of sending and receiving bank repayments and where responsibility may lie for repayment, but the fundamental position is that reimbursement takes place.

There is an entirely separate position when you are talking about the situation where someone may have had a false loan taken out. The previous panel referred to their house being stolen, essentially. In those situations, certainly speaking from the NatWest perspective, if we were shown that there was no connection, we would absolutely not be looking to enforce in those circumstances, because it is the demonstrable position that the person has never had any connection with the company that has taken out the loan. They are two very different things. There are false loans and there are frauds.

David Callington: Building on that, Donald has touched on the loan aspect. If a customer suffers unauthorised payments leaving their account, there is a regulatory obligation for us to provide an immediate refund, subject to the customer not being grossly negligent. If you have somebody compromise your account and move money out of it, you will get that money back. Typically, most banks will process the refund within 24 hours. That is a regulation that we have to follow through on.

As Donald said, we have the authorised push payment piece. I want to touch on an element of authorised push payments. There is a lot of media interest and focus on that. This is about consumers falling victims to scams. What happens regularly—I do see this regularly—is that customers will be approached by someone; they will go on to Companies House; they will see the company they are purported to be dealing with is registered; and they will take some solace that it is a legitimate company, registered on Companies House.

It is not just the horrific impact it has on those consumers and people who have their properties and identities used. It is other consumers and businesses that are falling for scams. They are effectively taking false assurance that a company is registered on Companies House. Those companies will fall under the code, as Donald said, because it is the customer making the payment themselves. There is a direct link to Companies House.

Nick Van Benschoten: It is very important to look at the damage this does to consumer confidence, but it is also worth thinking about the damage it does to business confidence. The BEIS impact assessment addresses but does not weight the cost to business confidence of not being able to rely on Companies House.

There is also an international dimension in terms of the UK reputation. There have been press reports of the US and German authorities seeing Companies House as a concern. That is a problem. We think Companies House is an opportunity for the Government to reinforce the UKs international reputation and our future prosperity, but we must not forget the current opportunity cost of this damage to confidence. That is not just consumers; it includes business.

That might be something for the Committee to consider, if you are thinking in terms of the business environment. Companies House is supposed to be a key part of the information infrastructure underpinning the business environment. At the moment it is a dysfunctional part, and other people cannot compensate for that, I am afraid. The Government need to get it right first time. Then we can help; then we can build on it. At the moment, I am afraid it is not an efficient feature.

Q45            Andy McDonald: There has been a lot of discussion about detection and prevention, and we have just had a discussion about victims. I just want to return our attention to the perpetrators of these frauds. I am just trying to think through the immediate responses of banks in circumstances where they discover that an individual or a company has committed a fraud.

We talk about the intent. The clear inference is that they were always intending to set up these companies or individual presences to defraud somebody, either the bank or customers. I am really interested to know what measures the bank takes when information comes to its attention. What happens? What steps are taken?

Nick Van Benschoten: On an industry basis, fraud generally, not necessarily this type of fraud, is a daily event. Banks share information with each other on an industry basis. They will also share information with law enforcement. Operationally, we work with the dedicated card and payment crime unit, which operates on an information-sharing basis with the banks.

Q46            Andy McDonald: Do you shut them down?

Nick Van Benschoten: We are not law enforcement. We would provide suspicious activity reports. Those would have implications in terms of activity on the account. My colleagues can explain about this. I just wanted to make the point that, on an industry basis, this is not an isolated example. This type of fraud may not be the main one, but fraud generally is something the banks manage on a day-to-day basis. Is there any particular aspect that you are thinking about?

Q47            Andy McDonald: Say somebody has set up a company with bad intent and extracted significant moneys from a bank for an alleged purpose, which turns out to be totally and utterly improper. They might have salted those funds away, in the way the first panel described to us, with outgoings regularly and the money gone.

I wanted to know what a bank would do in those circumstances with somebody who was banking with them. Does it just report that as suspicious fraudulent activity to the NCA or wherever? Are there other actions the bank takes to say, “Up with that we are not going to put”?

Donald Toon: The short answer is that the banks will take actions themselves. We will report. We will report to the National Crime Agency. Under certain circumstances, we may also report through Action Fraud. We might do that with an affected customer in the right circumstances. We will certainly take action as an organisation.

The main contact we have with the business or the individual concerned is through their bank account. The first thing that is likely to be done would be the freezing of the bank account and the exiting of the customer from the account relationship. We will certainly not wish to be in any way associated with the providing of bank account services to anyone who is involved in crime. Our starting point will be to report and then to take steps to move that company or account out of a relationship with the bank. Essentially, we are exiting them.

One of the issues we are looking to address at the moment is the possibility of that risk just bouncing down the high street. At the moment, unless we are talking about confirmed fraud, in all of the other areas of financial and economic crime there is no mechanism for us to identify that an individual or a company has been exited by another bank for financial crime. As an industry, we are working with the Information Commissioners Office and the Home Office to develop a pilot to create a database that would enable banks to identify those who have been exited by others due to concerns about financial crime and, therefore, to take that into account when considering whether they wish to offer account services. In some circumstances, it is possible that we would take forms of litigation to recover funds.

David Callington: Just building on what Donald says, as well as notification to the NCA, Action Fraud and law enforcement, we would load the individual’s details on to the industry-confirmed fraud databases, which I referenced earlier. From a fraud perspective, that should prevent them bouncing down the high street and going from one bank to the next because their details will be there. It is the broader financial crime and money laundering concerns where that is not in place.

Q48            Andy McDonald: That would extend beyond the high street banks.

David Callington: It should do, if they signed up to use those databases, yes.

Donald Toon: Again, it is a systems issue. We have one approach that we are able to use from a fraud perspective. If we are talking about the other forms of financial crime, such as money laundering, we have no mechanism to prevent that risk of banks becoming exposed to a known problem.

Q49            Andy McDonald: Just turning our attention back to the fraudulent bank account registrations in the first instance, what is your assessment of the impact the Economic Crime and Corporate Transparency Bill will have on that? Are you satisfied? Is there more to do? Does it adequately address the problem?

Nick Van Benschoten: I can maybe give some context and then make some quick points, and then my colleagues can follow up. The Bill is definitely a step in the right direction. Companies House needs to become a proactive gatekeeper, and the Bill gives it those objectives and some powers. The problem is that it does not go far enough.

The key point I would like to note is that there are new international standards for company registries, which the Government pushed for in their recent G7 presidency. Those are the latest standards, and Companies House needs to be assessed against those. That is worth looking at. In two or three areas, we think it falls short.

The first thing to note is that company registries need to be controlling risk. That includes the whole environment. In the UK, you do not need a bank account to register a company. In the UK you can register online in 15 minutes, and you can register as an overseas entity. There are a lot of things that add to the risk. That is a decision to be made in the round, but the public policy determination needs to be, “How do we mitigate those risks?” The controls need to be commensurate with those risks.

While the current controls at Companies House look okay compared to some other countries, those countries do not have these risks. They have much tighter controls. They are less open; they are less innovative. That is fine, but you need to will the means and not just the ends. That is a key point of context: a risk-based approach.

Specifically, Companies House is not being given the powers to verify the status of directors or beneficial owners. We recognise that this is an enabling Bill in many ways. There will have to be further consultation and further regulations. That debate is forestalled by the lack of order-making powers to verify status. The example would be that you could verify an individuals identity, but, as for whether they are actually a nominee director or a spoof beneficial owner, Companies House is given the power to query information only on the basis of risk and concern, i.e. an exception basis. That is almost a circular question. “How do I know there is a concern? I have not looked”.

We think there is a legitimate debate about how you would do it in terms of volume. You have heard from previous witnesses how modern technology is partly addressing that problem. From the banking perspective, as we deal with very high volume business as a matter of routine, we think there is a way around it. Again, it is a risk-based approach. We do not think it should be ruled out of court by the lack of an order-making power.

I will just finish off with the third thing. It has been mentioned before, but the reliance on company formation agents is a bold move when you consider the concerns about not just supervision but also criminal activity in that sector. We worked under the economic crime plan with law enforcement and Government to do a joint threat assessment of the UKs company formation and trust service provider sector. That led to the Government agreeing a range of mitigating factors. That work is still ongoing, and we are also carrying on with ongoing intelligence sharing about that sector through the Joint Money Laundering Intelligence Taskforce. We are not at liberty to disclose that, but it is going on.

It is a very bold move. I would just go back to the first point. Where is the risk-based approach? How is the risk being managed? I would say it is a good start, but we are not there yet.

Q50            Chair: There was quite a wide-ranging discussion in that panel. The specific purpose of this Committee hearing today is to think about the fraudulent registration of companies at Companies House and how some of those companies have been able to access finance through banks.

I just want to just check whether I have understood two points correctly. First, I think I heard you say that, of the scale of the fraud activity you have to combat, fraudulently registered companies is a very small percentage. Is that right? Yes, okay.

You have also said that, as part of the know your client processes for setting up a bank account and accessing financial products, you verify companies. What does that actually mean? Do you go to the Companies House register and say, “Yes, this is a company”? Explain that to me. What do you mean by verifying a company?

Nick Van Benschoten: Under the money laundering regulations, we are required to check the information against independent sources. That will not just be Companies House. There will have to be other sources of information. Typically, it will be information provided by the customer, but also other sources such as public databases, private databases and data providers. There are a number of private sector providers that provide information from a wealth of sources.

Q51            Chair: This process is similar to a credit check. You look at databases of information from lots of sectors and see whether it verifies.

Nick Van Benschoten: It is a layered approach and it is a risk-based approach. In terms of what we are proposing that Companies House should do, we think there are a lot of tools out there to do this.

Q52            Chair: Why did we hear in panel 1 that fraudulent companies were set up, accessed bank accounts and got access to loans? How could that have happened if you had done all those checks?

Nick Van Benschoten: In terms of the checks we would have done, we would have taken the information we were provided and verified that it was accurate against the information we had been receiving.

Q53            Chair: Can I just break that down a little bit? I am a criminalI am not, but I am for the purposes of this question. I find an address from somewhere; I go to one of these service providers; I set up a company against someones address; I have no connection to that address. I then come to one of your banks and I register as a company with that address on your website. Presumably, you give me an account pretty quickly online because you want to do that.

How at that point can you know I am not a criminal using someone elses address? How can that possibly be verified as being accurate?

Nick Van Benschoten: Again, there are a number of checks we apply in terms of monitoring the account for the activity we have been told about. That is a key part of know your customer checks.

Q54            Chair: Mrs Jones in a terraced house outside Leeds sets up a company called Asda Ltd. I do not understand how that can happen without something triggering in your systems that says, “This is probably not right”. Is the problem that it is an automated computer system, which cannot spot these things?

Nick Van Benschoten: The cases we are discussing, as I understand it, are specific cases. They have got through the system.

Chair: How?

Nick Van Benschoten: I do not know the detail of the individual cases.

Q55            Chair: Could either of the banks give me some idea as to how these things can get through the system?

David Callington: From a fraud perspective, if there are no indications of any previous fraud associated with the addresses, and the identities of the directors et cetera are all validated—

Q56            Chair: How is it validated? Mrs Jones in a terraced house outside Leeds sets up Asda Ltd. How do you verify that Mrs Jones in a house outside Leeds is a legitimate director of the fake company Asda Ltd?

David Callington: It is those additional data sources that we would access.

Q57            Chair: What does that mean? Name the data sources for me. Who are they? Where do they come from?

David Callington: A lot of them are hosted by the credit reference agencies. We will do the validation through those or we will look to Cifas.

Q58            Chair: Is that not a credit rating? Mrs Jones in the terraced house outside Leeds might have a good credit rating.

David Callington: No, there are fraud databases that we will access.

Q59            Chair: She has never committed fraud. She is a victim of fraud. Do you see the question I am trying to understand?

David Callington: Yes, yes.

Nick Van Benschoten: If it is helpful, we would be happy to give some further evidence in writing on the sorts of tools we use.

Q60            Chair: I would like you to give it now. Surely you know what tools you use.

Nick Van Benschoten: Some of those tools will vary by bank. There are a number of commercial providers. I understand the question you are asking. It is how things go wrong, if I understand what you are getting at.

Chair: Yes.

Nick Van Benschoten: The point I am trying to make is that you have brought up a number of individual cases. They are all deplorable. There are many others we prevent. We are not claiming to be perfect. The systems we apply are risk-based.

Donald Toon: Chair, we have to be slightly careful about this. As a simple example, we have recently been dealing with the fallout from the registration of a company at Companies House. That company is registered in the name of NatWest Bank plc. It is in a three-bed suburban house. It has a registered subject code at Companies House of central banking.

That would never have got a bank account from us. It is unlikely that it would have got a bank account from any major bank using the right tools because it does not ring true. It astonishes us, frankly, that it got registration at Companies House. The system might suggest that there are companies with that sort of name.

There is an issue often with us being able to check and identify the relationship between an individual and a registered address. We do look to identify the individual or individuals who are responsible for the company, when we are talking about the account opening process. We are talking about identifying them through things like the reference checks you heard but also through verification of their passport and the relationship between the individual and the documentation. We can identify who they are.

One of the problems up for us very often is identifying their relationship with what may not be down as their home address but may be down as a registered company address. Almost anything can be a registered company address.

Can I just make one final point? We have a real issue here. We are obliged to verify. We look at Companies House data as part of that verification process. The obligation is then on us to tell Companies House where there is a difference between what we are told and what is on their database, rather than rely on Companies House.

Q61            Andy McDonald: I am just trying to get my head round this. Surely it is a matter of gumption and common sense. If somebody is registering a property at 2 Westminster Street in Pudsey as Asda Ltd, the question is, “Is it likely? Is it really likely that that is a legitimate concern?”

These people have bank accounts. I am struggling to get my head round how on earth that could happen. I know you have referred to databases. If that landed on my desk, I would have thought, “Something called Asda Ltd is now registered to a terraced house”.

Donald Toon: We would want to look at the details of individual cases. I just gave you that example. I would not be surprised if most of the large banks, certainly, were in a position where very clear names were being used and they were obtaining bank accounts. It might be possible there are some. I cannot speak for the industry as a whole. You are right, but that is the extreme case.

Andy McDonald: We have heard evidence that that has happened.

Donald Toon: I know.

Q62            Chair: That is the thing we are struggling with. In panel 1, we were told, “This is a really big problem”. There are thousands and thousands of fraudulent companies being registered. There is testimony after testimony of victims, in their homes, being told that a company has been registered to their address. There are case studies and examples of some of those people then having loans or overdrafts spent in the name of the company at that address and some of them then having real trouble trying to fix all of that. What you have essentially told us today is, “It is not that big a problem. We do lots of checks”.

Nick Van Benschoten: Can I just clarify? There are a number of things there. First of all, there are a large number of accounts being registered where questions have been raised. You have heard the information from previous witnesses. There are a number of cases—I do not know the total, but the cases we have heard are a small number—where that has been used to open a bank account. That is regrettable.

There is a third point about people then being caused a lot of distress, a lot of concern, because they have been chased up for the debts that have been raised against those companies. We have said we will not be pursuing debts against people who did not open a business account. I get the point you are making entirely. I understand your concern. How was it possible that these individual cases happened? There is a difference between the number of companies that have been fraudulently registered at Companies House and how many of them got a bank account.

You are raising a legitimate point. I just wanted to distinguish those three different things.

Q63            Chair: I am very clear on the three different points. What I am not clear on is what you are doing about this. You have basically told me that this is Companies Houses problem.

Nick Van Benschoten: I did not mean to give that impression. We are saying that we are doing a lot about it, but we cannot do it effectively enough under the current regime. We welcome the Government’s commitment to reform Companies House. We are saying that we all need to do a lot better.

The points we are making are building on a lot of existing practice. The cases you are talking about are individual ones. We are happy to look into those, but I do not want to leave the impression that we are not doing something about it. I thought we had set out the range of activity we are currently doing, but we do not think it is enough. We think everyone needs to do more.

Donald Toon: Please do not assume that people automatically get accounts in these circumstances. If you were to look at the data we have as one bank—I will not go into absolute numbers—this year to date we have declined almost a fifth of applications for business banking accounts for a whole range of reasons. That will include concerns about fraud and financial crime. It is not an automated process that says, “You apply, you get”.

Chair: I am afraid we have timed out. Thank you to all three of you for giving evidence today.