Written evidence submitted by TSB Bank (OPR0010)
Treasury Select Committee inquiry into IT failures in the financial services industry
TSB Bank response
TSB welcomes the opportunity to provide written evidence to inform the Treasury Select Committee’s inquiry into IT failures in the financial services industry.
As this Committee is aware, in April 2018, TSB completed a phased migration onto a new IT platform. This resulted in completely unacceptable levels of services for many TSB customers in the initial weeks that followed.
We deeply regret that a change which was intended to make banking with TSB better for our customers, had, for a period, the opposite effect.
Since April 2018, we have been focused on putting thing right for our customers, many of whom are now starting to experience the benefits of the new platform. We have resolved around 85% of all complaints received since our migration, and we remain focused on resolving the remaining migration related complaints over the coming weeks.
Although TSB’s migration was a once-in-a-lifetime event for our business, IT platform changes are an increasingly important issue for the financial services industry. This is why by sharing some of our initial learnings and observations, we hope to help build a stronger overall financial services IT ecosystem, and give consumers greater confidence in the banking services they receive.
We have sought to be as helpful as possible in answering the Committee’s questions. However, as the Committee is aware, there are a number of ongoing regulatory and independent inquiries into TSB’s IT migration, and it is important that we do not pre-empt the findings of those inquiries.
This evidence therefore sets out a number of initial learnings from TSB’s experience that are pertinent to the Treasury Select Committee’s inquiry. We await the completion of the ongoing regulatory and independent inquiries before reaching definitive conclusions as to the learnings from TSB’s migration last year.
The extent to which operational incidents are becoming more frequent, and how the prevalence of such incidents may change in future as consumers and firms come to rely more heavily on technology.
Consumers value new digital banking functionality for the ease and speed it affords and, as a result, are increasingly using digital services to meet their everyday banking needs. This means that when banks have technical problems more of their customers are likely to be impacted and be aware of the issue than ever before
We know that IT issues can cause significant levels of harm and inconvenience to customers, and can also cause significant damage to a bank’s reputation. Despite this, it is impossible to guarantee that all operational incidents can be avoided. This is why we have been focusing on reducing not only the frequency of incidents, but also their impact on customers. For example, we have given greater focus to planning for the “unhappy path” by investing even more in back-up services which ensure the continuous provision of services for a consumer during an upgrade or in the event of an incident. We are also focusing on, where possible, implementing small changes and upgrades without having to take down digital services, so that we can, where possible, meet our customers’ expectation of digital banking services, 24/7, 365 days a year.
However, as the digital economy becomes even more interconnected, problems at a relatively small number of technology suppliers can have a large impact on customers across a range of banks, businesses and other organisations.
For example, when one major mobile operator had an outage in 2018, which has been reportedly linked to its IT supplier, over 30 million mobile customers were reported to have been impacted across the operator and its affiliate networks. As a result, millions of consumers were unable to use digital services, including millions of customers who were unable to log-in to their online or mobile banking services.
In banking, problems with common componentry can also lead to customers of many different banks being impacted at the same time. For example, on the morning of 28 September 2018, a number of banks, including TSB, experienced service issues which started at the same time, and were all resolved a few hours later. For TSB, the cause was an incident at a third party supplier – a supplier common to all the banks encountering problems that morning.
Common causes of operational incidents in the financial services sector.
TSB’s data shows that the most common cause of any incident at TSB today is the implementation of planned system changes.
This is consistent with industry trends. For example, the FCA1 found that the most common causes of IT outages in 2017-18 came from IT changes (20%); cyber attacks (18%); and failures at important suppliers (15%).
As stated above, the causes of the problems which followed TSB’s 2018 IT migration, which included a mixture of failed IT changes and failures at important suppliers, are the subject of a number of ongoing inquiries. We await the findings of these inquiries and will be sharing them with the Committee once complete.
The extent to which there exist “single points of failure” and/or other sources of concentration risk in the financial services sector.
We observe four established clusters of concentration in the financial services sector.
First, the networks and connectors that enable banks to deliver services through branches and digital services right across Britain. In the UK, all banks use BT cables and are reliant on a small number of mobile networks.
Second, the central payments infrastructure.
Third, the IT systems integrators, these companies work with banks to make sure that the different systems that a bank operates on work together effectively. There are only a handful of companies with the right skills and experience to deliver this service to the banking sector, and they tend to be global. IBM and Accenture are two of the most prominent examples.
Four, the common technology suppliers, for example providers of security services, information feeds and back-office systems.
To better understand the location and nature of concentration risk, we think it would be helpful if regulators mapped the common systems and components in financial services.
The incidence of multiple old legacy systems and the nature of their connectivity, and the impact of retrofitting web based/mobile systems to legacy systems.
A long history of mergers and acquisitions in banking means that almost every bank faces a challenge of what to do with the multiple, interconnected platforms of merged and demerged banks.
The number of engineers with knowledge of the systems that support these legacy platforms is diminishing but the competitive pressure to develop and deliver more digital functionality has increased. The complexity and interconnectedness of these systems makes it difficult to gain 100% assurance of the impact of a change without live testing. This means that banks face a significant challenge in making legacy platforms sustainable in an increasingly digital world.
This is the reason why TSB chose to migrate away, in phases, from the legacy platform we were renting from Lloyds Banking Group (LBG). Operating on our own modern coherent platform will allow us to better serve the banking needs of our customers now and into the future.
The risks associated with integrating banks/systems, following takeovers and mergers, for example.
TSB was set up as a standalone retail bank following separation from LBG in 2013. This was as a condition of the European Commission approving the State aid that LBG had received during the financial crisis.
In order to launch TSB at pace, and with minimal disruption to customers, TSB was set up renting the LBG IT platforms that we already operated on, despite LBG and TSB becoming competitors. The rental agreement between TSB and LBG for the IT platform had no option to renew.
There was a risk that unless TSB moved onto its own platform, we would not be able to effectively compete, innovate and deliver for customers in the long-term. Although the short-term rental arrangement had enabled TSB to be set up as a standalone bank rapidly, making changes to TSB products and services was very slow, and the cost, timing, design and pace of executing these changes were all determined by a competitor.
For these reasons, developing and migrating to a new IT platform was critical to TSB’s long-term ability to compete, innovate and deliver for customers. Following Sabadell’s acquisition of TSB in July 2015, the comprehensive building and testing of the new platform began, and lasted nearly three years. The phased migration onto the new platform began in 2017, ahead of the main migration event in April 2018.
Mergers and migrations of banking systems are complex and no two are the same. TSB’s migration was one of the most complex in UK banking history. It involved moving around eight million customer records onto a new consolidated platform. This involved replacing every technology system and every piece of hardware across the bank – from the complex software that banking requires, to the physical printers in every branch and head office, and the devices that each of our workforce operate on.
TSB now operates on a more coherent, responsive and modern platform which has 50% fewer systems than the platform we previously rented, and offers us greater transparency over the data we receive. This new platform provides the foundation for TSB’s future success, and offers us the ability to deliver the latest functionality to meet the needs of our customers faster and more simply than before.
For example, our mortgage brokers can submit mortgage applications in half the time compared to pre-migration. They can also now upload documents in real time, whereas previously it took 48 hours. Market leading personal current accounts can be opened in our branches in half the time compared with pre-migration. Product changes can now take place in days, whereas this would have taken several weeks if we were still using the old system.
The impact of outsourcing on operational resilience.
All banks rely on outsourced suppliers to deliver critical hardware, software, security, support and services.
The onset of ring-fencing, the move towards a cloud-based support model, and increasing consumer demand for digital functionality has led to greater use of outsourcing –often structured within a bank itself when ring-fencing occurs – and as a result, a larger, more interconnected financial services ecosystem.
As we have said above, in order to better understand this ecosystem, we think it would be a helpful for regulators to map the common componentry and systems used across financial services firms.
The FCA found that 15% of IT outages in 2017-18 resulted from failures at important suppliers, and failures at critical suppliers contributed to TSB’s 2018 IT issues. Therefore, although banks cannot outsource responsibility for the provision of their services, the overall resilience of financial services could be further improved by bolstering the operational resilience of their outsourcing partners.
We recognise the scale of the regulatory challenge and we support the work being done to tackle the current imbalance of liability and power between financial services firm and suppliers.
Banks already have detailed legal contracts, as well as expert advisers and data monitoring services, so they have taken reasonable measures to ensure the services they receive are fit for purpose and to minimise operational risk. However, even if all of these steps are followed to best practice, the underlying risk of a failure at a core supplier can still not always be avoided.
To address this gap, the Committee may wish to consider whether the development of mandatory common standards for critical and common suppliers could improve overall operational resilience. Suppliers would have to meet and maintain these standards in order to supply financial services companies.
The ways in which consumers typically lose out as a result of operational incidents, including inconvenience and vulnerability to fraud.
The majority of TSB customer complaints as a result of our IT issues in 2018 were the result of problems accessing their accounts through internet or mobile banking. These customers often had the inconvenience and cost of travelling to a branch, or telephoning TSB. As a result, our branches and call centres also experienced higher than expected levels of demand, often creating a poor experience for the customer, despite the very best efforts of those TSB’s Partners trying to serve them.
Some TSB customers were also the victims of a subsequent significant fraud attack. It should be noted that this was not caused by a failure in our fraud defences, but by fraudsters exploiting the confusion caused by the IT issues. TSB has apologised to all of our customers and is remediating complaints.
We believe that closer co-operation across multiple industries, more targeted funding of front-line policing and better, more effective customer education will make a real difference by turning fraud into a difficult and high-risk crime, particularly at times when banks make IT changes. For example, we would recommend that telephone network operators should only allow sim swaps to be made by way of the customer being in branch and the operator being in the receipt of proof of photo ID.
Given our experience last summer, TSB is committed to stepping up its efforts to take the fight to fraudsters. We are working closely with all stakeholders, forging a direct alliance with telephone network operators (to fight attacks such as SIM swaps), retailers (to strengthen data security) and charities (to educate customers and support victims) – enlisting these organisations in our fight against fraud.
We have also stepped up our support for enforcement agencies. In December 2018, TSB launched a new partnership with the Metropolitan Police, to bolster London’s fight against fraud. This included an initial investment of £200,000 in the Met’s anti-fraud programmes, with a focus on three key areas: increased resourcing for the police, fraud prevention and awareness and innovation.
What should be learned from the operational incidents witnessed in recent years.
Firstly, having a branch network, with staff who had been trained on the IT changes being made, was undoubtedly a key factor in supporting our customers through the changes and ensuring we met customers’ banking needs when we had issues with online banking after migration.
We know that TSB customers rarely access their banking services through just one channel, and the majority like to use a combination of digital, face-to-face, and telephone banking. In an industry like banking, which people rely on for essentials on a daily basis, it is important that steps are taken to ensure that when one access channel is down, another is available.
Secondly, social media, for example Down Detector and Twitter, often report issues at the same time as bank data reports, presenting operations and communications challenges of dealing with emerging issues and trying to update customers at the same time. This is why TSB is investigating whether we can incorporate elements of social media reporting into our bank operations data. This will help us pick up the consumer experience in our data, rather than predominantly relying on bank data to understand the impact of an issue. This approach will in turn allow us to better communicate with customers in a timely, factual and personalised manner.
Submitted January 2019