Written evidence submitted by Visa Europe
This submission follows a request from the Work and Pensions Committee for Visa Europe to submit evidence to its inquiry into fraud and error in the benefits system.
Without knowledge of the detail of the DWP’s processing approach, it is difficult to provide specific recommendations for risk management in the benefits system. We have therefore attempted to offer a flavour of how risk is typically managed from a commercial perspective – providing insight into how error and fraud may be minimised within any system, based on our experience of working with the many financial organisations across Europe involved in card payments.
Risk management in concept is simple, once the correct framework has been set. Without an appropriate framework risk management will not operate effectively. The suggestions set out below are generally applicable, but will need adaptation for deployment within the benefits system.
Our core recommendation is that risk management should be primarily process-driven rather than judgement-led, with performance tracked against key metrics to enable the system to be responsive and agile. Deploying data effectively will significantly improve outcomes, although there is a balance to be struck between analysis in real time against its costs.
The submission was drafted by Peter Bayley, Executive Director of Risk Management at Visa Europe.
Visa Europe is a payments technology business owned and operated by member banks and other payment service providers from 37 countries across Europe. Visa Europe works at the forefront of technology to create the services and infrastructure which enable millions of European consumers, businesses and governments to make electronic payments. Its members are responsible for issuing cards, signing up retailers and deciding cardholder and retailer fees.
Visa Europe operates a high volume, low cost business model that provides services to its members. Its surplus is reinvested into the business and used to improve capital and reserves. In the last six years, Visa Europe has invested over €1 billion in new technology and infrastructure.
There are 500m Visa cards in Europe – of which 124m are in the UK where £1 in every £3 spent is on a Visa card. Almost 80% of Visa Europe’s business in on debit cards, and in the year to September 2013, total expenditure on Visa cards across Europe reached €2 trillion. Despite the challenging economic climate, total spend by Visa cardholders in the UK grew by 9.2% to £145bn. E-commerce grew by 18% with £110bn spent online at UK merchants, equating to £3,488 being spent every second with a Visa card.
For more information, visit www.visaeurope.com or contact Rebecca Parsons, Head of UK Corporate Affairs (parsonsr@visa.com; 0207 795 5396).
Within a commercial business with a strong risk management focus, one would expect to see a comparatively clean risk management model, which whilst not necessarily articulated exactly as per the diagram below – in effect describes how the organisation manages its risk.
It is worth running through these elements in turn.
Any organisation involved in financial money movements must anticipate that losses are inevitable within its business.
It is neither sensible, nor useful to assume that a nil risk is achievable, and there must be the means for the organisation to determine a maximum risk appetite and a means to assess a sensible investment strategy for its risk control tools (if it costs £50 to stop £100 of fraud, this may be desirable, but it could also be desirable to spend £200 to stop £100 of fraud – but it depends on the risk appetite set and return expected).
As such, any organisation involved in money movements should determine its appetite so that the risk management can understand the goal they are expected to achieve and the financial performance of any risk strategy.
Metrics are critical in this area – defining exactly what is being measured and doing so consistently. This is discussed in some further detail at 2e.
These activities relate to the infrastructure processes defined to minimise risk. They tend to relate to the core business processes, IT configuration and customer interaction.
These may include: how individuals are identified, what steps they need to take in order to access or move funds and the channels and approaches open to them. Typically prevention activities are those that are slow to change, but are your primary controls in day to day activities.
Prevention is never fully effective – it usually cannot change as quickly as the attacks being made against it, but it remains the primary defence against systemic attacks.
To address the gaps in the prevention policy, it is normal for an organisation to make use of detection systems. These look to determine unusual activity which indicate fraud, error or misuse.
The logic of detection is described in more detail below – and systems can be developed that highlight and profile the detail of individuals, staff, sectors, geographies etc.
However, all depend upon a robust ‘bad’ data population to focus on the risk activity to be identified together with a team of staff able to review the alerts that the system creates and be able to decide when payments should not be made or other action taken.
In the card payments world, fraud is easily identified because if the bank systems don’t identify the problem a customer will eventually advise that funds are missing from their account. The fraud system is therefore largely self-reporting.
Within a benefits environment, this situation will occur on occasions (such as when payments are made to the wrong individual) in which case a claims process must exist to review the claim being made and judge whether it is fair and redress made.
However, it is likely in the benefits world that often the beneficiary is aware that they have no right to make a claim and are unlikely to self-confess. As such, a proxy to self-reported fraud is required to understand which activity is likely to be fraudulent, whether confirmed or not. This is discussed further below.
The cardinal sin in risk management is not having in place robust metrics to allow data to be tracked - whether positive or negative.
Most organisations involved in risk management would look to track their performance against three core groups:
How much is being lost each month (as a minimum) and to what trend – i.e. did we lose more this month than last etc. This can drop to some detail in addition to the high level trends; how are these differing by payment type, what is the geographic split, how much is down to employee error or fraud etc. Most organisations actively managing fraud loss will review their losses daily and weekly, with a formal report to their management at least monthly.
ii. Operational Cost
What cost is being created in terms of systems, people, external activities etc. in order to manage the fraud being incurred. This ensures that costs are not being incurred inappropriately, and that where they are incurred they are in line with expectations set for the level of loss being booked.
iii. Customer Experience
Fraud processes always tend to create a negative impact on the ultimate customer. By default, a detection process will typically stop a payment being made, or temporarily suspend such while enquiries are made. Whenever such a system identifies a genuine claim as a potential fraud, this will have a negative impact which must be recorded.
Any risk process needs to actively understand that it will create negative impacts on the ultimate consumer and should look to understand these impacts. These should also be reflected in the agreed risk appetite.
It is imperative that the Fraud, Cost and Customer impact metrics are all appropriately defined, independently audited, and regularly reported.
No risk process is ever optimal. As such the risk management need to recognise that they must adapt where new risk threats appear, major losses or new loss trends are uncovered and poor customer impacts are being seen.
Risk processes must always be agile. A stagnant risk process is by default broken. Fraud attacks against any system will by default adapt and evolve.
Within a good risk management environment core risk approach, policies and methodology will be reviewed in light of the core risk metrics at least weekly and changes be progressed as a result.
Any risk system that reflects the core concepts described above will be half way to creating a strong risk capability.
Understanding the core metrics is arguably the most critical element in risk management. Without sensibly defined and timely metrics, it is impossible to understand the risks facing the enterprise or monitor how effectively the enterprise is managing these risks.
Within a benefits system, fraud and error will result in the beneficiary being unjustly enriched and as such it is likely that most of the loss will be undeclared.
As a result reporting is necessary to identify incorrect payments after they have been completed whether they can be recovered or not, to understand what has been missed.
The approach should include the following:
a. High risk reviews
Where detection and prevention systems identify high risk activity, these should be reviewed and a determination made of whether the claim is genuine or not.
Any process will create mis-reporting, and so some cross validation should be undertaken, but this will provide confirmed bad population data.
b. Formal claims, complaints and investigations
In the normal course of business it will become apparent that claims are invalid or rightful recipients will declare they have not been paid. Such errors and fraudulent behaviour should all be recorded.
c. Third party co-operation
Working with third parties such as banks, other agencies etc. will allow high risk and known fraud to be reported.
As always with shared data, all information received regarding potential fraud should be treated with caution and independently verified (e.g. just because a Bank granted lending to an individual that involved a high level of fabricated claims which amounted to fraud, does not automatically mean that the same individual receiving a benefit is not due that benefit. The fact that the individual defrauded one organisation may be indicative that they are prepared to defraud another – but it is not conclusive that they have done so).
However, where non-fraud data is shared this can be highly enlightening, even if applicability may not immediately be apparent. Understanding that a building is a single person residency is meaningless in and of itself, but finding 15 individuals claiming benefits from it, could be indicative of a problem.
d. Analytics
It is often possible to determine that claims are fraudulent, based on the length of time claimed, the other claims received and comparing payments made between individuals (if multiple claims are paid to a single bank account does this make sense?) etc.
The analytical assessment of claims via a single simple database does not require huge complexity or cost – keeping data down to what is available rather than worrying about capturing everything makes sense, but allowing review of data is essential so that trends and irregularities can be found.
All identified fraud, error or related incorrect payments should be recorded in a single data repository and broadly marked by type, to allow different incidents to be managed using different strategies.
Understanding what the fraud / error (bad) data is compared with the understanding of non-fraud / non-error payments (good) data – is absolutely critical for running any scientific fraud controls and detection.
Without it, it is impossible to understand the effectiveness of strategies, detection, investigations etc. or whether the money spent in preventing loss or the sub-optimal customer experience created is justifiable.
Detection systems reflect the agile element of the risk strategy and are used to identify high risk behaviour for review and investigation. They are now common practice in most payment business and are subject to monitoring and metrics to ensure that the detection system operates optimally.
A detection system will typically operate along the following lines:
All transactional data would be passed through the system – which would be used to create variables that the system uses to assess risk (e.g. number of claims against this account, total value of claims in 7, 14, 30 days, post code, telephone number etc.).
This data is then used to profile the claimant against their normal activity and against known fraud profiles. This is then assessed against a statistical model (scorecards, neural networks or similar – the technology is a detail) designed to assess the risk that this payment represents.
A series of rules are then supported to allow an approve/decline decision to an individual claim and/or to refer a claim to an individual for investigation.
Typically:
a. Value Detection Rate (VDR)
How much of the total potential fraud is being detected by the system (typically shown as a percentage - e.g. 70% VDR would identify that the system identifies 70% of the fraud whether it stops the fraud or not
b. False Positive Rate (FPR)
An assessment of the system’s efficiency in respect of finding bad behaviour without impacting genuine claimants. This is typically shown as a ratio e.g. 1:4 – which would imply for every 5 cases alerted for investigation 4 were determined genuine for every error/fraud identified
c. Customer Impact (CI)
The extent to which the entire detection system is impacting the system. Again typically shown as a percentage, e.g. a CI of 1% would show that 99% of the claims were process clean but 1% required review before approval.
As such, a detection system with a VDR of 70%, a FPR of 1:5 and a CI of 0.8% gives a specific performance that can be tracked over months and years to ensure that performance is improving or is being maintained.
Building detection systems is a science in its own right. It does not have to be an expensive process, but this depends very much on the performance required, the speed of operation and the availability of underlying data.
A detection system which runs once a day, where data is already available and is only used for post event investigation will be far cheaper than something where the data is not readily available and operates real time to actively approve and decline every payment requested. As a rule of thumb the closer to real time a detection system is, the more effective it can be – but also the more expensive it is to build and maintain.
It is critical to have staff that are able to deal with high risk payments / claims to assess whether they should proceed or should be stopped (this payment or future ones).
It is not unusual for these staff to be labelled “Investigations”, but in truth their role should be as logical and as pre-defined as possible as judgemental processes tend to lead to inconsistent outcomes.
As such investigations staff should by and large be looking to determine whether a payment or claim is valid or not based on high risk referrals from a detection or prevention strategy. The approach to investigation should be clearly defined and clear bad outcomes defined.
Where an outcome is unclear, or where circumstances arise that raise the question as to whether the operational process is adequate, then referral to more senior staff with a proven track record to decision a case should exist. But judgement is expensive and prone to error, so should be kept tightly controlled.
Staff decisioning, whether judgemental or process driven should always be monitored and subject to metrics – both to assess efficiency and to ensure that no member of staff is misusing their judgemental authority and/or to confirm process is being followed correctly.
Referral to law enforcement is important where criminal activity is identified or strongly suspected. A strong relationship with law enforcement staff is useful.
However, the law enforcement role primarily exists in an environment where the prevention and detection systems have failed and losses have occurred. The opportunity to recover payments from a criminal case are often small and the criminal prosecution is primarily there as a strong disincentive for others looking to defraud the enterprise.
The focus should therefore be upon creating systems that minimise referrals to law enforcement, as they in and of themselves will not minimise the risk, fraud or errors occurring.
It should be noted that both criminal and civil action may be used on occasions to achieve seizure and repayment of funds paid away in error. This approach should be considered for all substantial losses, but subject to a cost benefit assessment, in line with any other control or mitigation.
Any system handling the movement of funds is prone to staff fraud and misuse.
The business approach needs to be alert to the risk that staff may be operating fraudulently and / or making errors which create the same outcome (the only difference between a staff fraud that causes a loss and a staff error that causes a loss is that staff member’s intent).
As such, tracking staff decisions, payments, credits touching their own accounts or via their own addresses or ones to which they are associated is advisable.
This area needs to be approached with sensitivity and care, as all parties become sensitive around staff fraud – but it is almost inevitable that some element of staff malfeasance is occurring and should be recognised.
Including metrics that identify the total level of losses that include some element of staff error, whether intentional or not, is a good first step to tracking staff fraud.
It is usually recommended that any staff member engaged in fraud should be prosecuted as a matter of policy.
While educating the public on fraud is unlikely to radically affect rates of incidents without significant investment to change the public impression of fraudulent claims, it remains important to ensure clarity on what is and is not permitted as fraudulent activity. This will help avoid attempts to explain fraudulent activities as misunderstanding where payments are complex or subject to interpretation.
A risk function must be focussed, accountable and agile. The management and team need to understand why they are doing what they are doing and the core metrics showing improvements and deterioration in performance need to be communicated and discussed.
The risk team need to be agile in outlook, and be looking for continuous improvement to the work approach to improve losses, efficiency and customer experience – as such the sharing of the metrics and the problems incurred is critical.
The head of the risk function should be focussed on the core risk goals, typically split into the areas described in 2e above and should be based on material performance outcomes.
Investigations, arrests and prosecutions are relevant events and should be shared, but the risk organisation should not focus on these as core outcomes as they primarily provide a deterrent effect.
The risk management should be held accountable for their performance and be required to report to appropriately senior management at least monthly.
This submission is intended to provide an indication of how risk is managed in the private sector. These lessons should be applicable to the benefits system although we recommend that sufficient thought is given to the detail of implementation.
If supplied with further detail about the DWP’s current approach, we are happy to provide additional commentary if that would be helpful to the Committee.
17 March 2014
9