Last year we used in our planning recommendations from your tech panel on technology issues to prepare for in 2007. Could your panel again provide a checklist of tech issues to be aware of, plan for in 2008?
Mobile banking seems inevitable. But there seems to be no uniformity in platforms and security and we’re hesitant about investing tech dollars here. Does your panel agree?
Christine Pearsall, VP-marketing and sales support, Summit Information Systems, Corvallis, Ore.
Employing technology to increase marketing ROI and improve risk monitoring are two strategic objectives that should be on every credit union’s radar for 2008.
Invest in technology to exceed the sales results of traditional marketing methods. The key is having the ability to tap data from many sources to identify members who are both qualified and likely to accept specific product offers. With this valuable information, offers can be delivered through existing electronic channels at every member interaction.
The goal is to deliver the right offer at the right time to maximize your investment of electronic channels, such as ATMs, IVR and Internet banking solutions. A Summit client who adopted our NEXT multi-channel marketing technology experienced a $5-million increase in their credit card portfolio, along with dramatic increases in investment referrals, and home mortgages through ATM offers–all within the first five months of operation.
Another goal for 2008–eliminate labor-intensive BSA compliance tasks. By investing in technology that automatically monitors transactions for any traces of suspicious activity this can be achieved.
Today’s best risk technology solutions such as Fiserv’s NetEconomy include tools for anti-money laundering, fraud detection, case management, investigation, and automatic report generation.
The time saved in monitoring, investigating and reporting can save hundreds of thousands of dollars each year. Best of all, staff are freed up to provide personalized services to your members.
Dan Chaney, VP-business development,
Teres Solutions, Austin.
We believe there are two big tech issues most CUs will need to be aware of.
1) As the credit crunch seeps into the auto market, credit unions will need to be even more careful when handling their auto loans. In order for them to compete without opening themselves up to too much risk, they’ll need software to automate and quickly weed out the good from the bad. Lending automation technology can handle the volume of applications without wasting your time. There are several credit unions who are already auto-approving/denying nearly 40% to 60% of the auto loans they receive electronically from DealerTrack and RouteOne. It’s essential to minimize risk and to handle the loan volume effectively.
2) In 2008, we’re hearing that many CUs will explore new forms of lending, such as Retail financing. In order to incorporate new lending businesses into their portfolios, they’ll need lending automation systems that can handle the particular nuances of these kinds of loans. We believe credit unions will invest in systems that are open and can handle such business expansion.
David McConney, EVP/General Manager, Credit Union Core Systems, Harland Financial Solutions, Pleasanton, Calif.
With the multitude of technology applications available to financial institutions, it can be difficult to wade through the choices and determine what to consider and what to bypass.
Popular technologies, such as mobile banking, should be considered if the demand exists within your membership. Tighter security measures, such as biometrics, should always be a consideration.
Following is a brief list of some things to think about as well as possible issues to be aware of in 2008:
* PCI Audit Execution Plans–requirement that no system can store card numbers without using encryption.
* Encryption of Data Execution Plans–field-level (e.g. PIN and card-level), back-up media, in-flight, and at rest data.
* Mobile Banking–(Bank of America “claims” 500,000 users) and the demand is coming.
* Biometrics–increasing in popularity for additional security measures.
* Phase II of Multi-Factor Authentication– the industry is 12-months smarter since the original roll-out.
* Staff Education and Training–ongoing staff training and retention programs as well as knowledge management are becoming more and more critical to the success of financial institutions.
* System Utilization–ensuring full system utilization of technology, particularly core systems, to fully leverage the investments and improve efficiency and growth potential.
* PCs being shipped with Vista–ensuring all existing and future applications function properly on Vista.
Tom DeSot, EVP of Vulnerability Research & Regulatory Affairs
Digital Defense, San Antonio, Texas
Probably the biggest issue I would watch for in 2008 would be the use of data encryption technologies within the institution. As data breaches make headlines more and more, it’s almost a sure thing that the regulators are going to start to take a harder look at what institutions are doing, and not doing, to protect member data while in transit or at rest.
While encrypting drives for remote users and on corporate laptops utilized by staff during SEG visits, etc. is a great first step, there are a multitude of other potential breach points that the institution should consider as part of their overall data protection strategy.
To ensure that these points are appropriately captured and analyzed, each institution should ensure that data encryption strategies are reviewed as part of their enterprise risk assessment process.
By doing so, they ensure that whether the data resides on their core processing system, a Blackberry utilized by the CEO, or in a vendor data center, that the appropriate measures have been taken to safeguard the information in the event of a breach.
Remember, an ounce of prevention is worth a pound of cure.
John Schooler, SVP, General Manager Real Time Systems, Fidelity National Information Services, Jacksonville, Fla.
1. Any initiative that can be labeled as “green” will be increasingly popular going forward. Certainly, the elimination of paper statements and notices via e-delivery methods will continue to gain popularity along with “green branches,” etc.
2. Mobile banking is clearly at the top of everyone’s holiday list this year.
3. Microsoft Vista seems to be ready for prime time. Expect to roll it out enterprisewide. There are some really cool features to take advantage of. Same with Office 2007.
4. While U-Deposit (home banking commitment to mail in a deposit) has had some adoption, the better approach will be Remote Deposit Capture, enabled by maturing image exchange technologies. This will entail the member using a home device to capture the check image and transmit it directly to the credit union instead of depositing a paper check.
5. Workflow automation will continue to grow in demand as products, services and credit union processes become more complex and under increasing regulatory scrutiny.
6. The push for fully integrated small-business deposit and lending isn’t exactly new, but most credit unions haven’t started integration, and they are one of the few engines to fuel future growth.
David Turner, CIO
IntegraSys, Frisco, Texas
One major technology issue we’re seeing is the need for automated tools that support regulatory requirements, particularly those associated with BSA/AML.
The amount of detail required for these regulations has become too complex for most any institution to manage manually and we expect to see a rise in sophisticated technology support tools.
We think regulatory compliance will quickly become both an industry issue and a technology issue since the tedious investigation processes are not only taxing for the credit union’s staff to accurately perform manually, but can also result in errors and potential penalties.
To address this complex industry problem, we’re making it a priority in 2008 to deliver advanced, integrated tools that enable our clients to automate workflows, assignments and task check lists–ultimately saving them time and money as well as helping ensure compliance.
Our NetEconomy solution will also feature electronic imaging capabilities that support case management requirements so credit unions can eliminate inefficient paper filing systems.
And the new tools will support automation for structuring and trend analysis–one of the key areas where credit unions are falling short with examiners–enabling our clients to show the flow of funds to and from accounts within their credit union and beyond with the click of a button.
Doug True, President of FORUM Solutions, Indianapolis
Mobile banking in some form is going to be a table-stake for credit unions, meaning that it is going to be the same as internet banking in the future–a must have. However, today I see so much hype around mobile banking that I am worried credit unions are going to jump in without asking their members what they want to accomplish with such access. A recent study by Forrester Research found that 72% of online consumers have no interest in having financial information on their mobile device.
Sixty-nine percent of online banking and bill pay consumers say they are not interested. The Forrester data reports that 16% of text-messaging Gen Y are interested in having financial information on their mobile device, but at this time this represents a small niche.
My suggestion, and the approach FORUM Credit Union is taking, is to engage in a low-cost pilot to experiment with how mobile banking will be used by your members. FORUM’s first step in mobile banking will be to offer a text messaging service that leverages our online chat staff to deliver a high touch option for members wishing to perform transactions such as balance inquiries, last five debit transactions, funds transfer, etc.
This affords us to get in the game without making a large technology investment and to gather real time market intelligence to make better decisions on this channel. I would even suggest looking outside the credit union industry to see how other industries are embracing the mobile channel (Papa John’s Pizza, for example).
Frank Catucci, First Bristol FCU
Bristol, Conn.
Mobile banking is growing beyond being just a curiosity for many credit unions and banks alike. The reality is our members and consumers are going to be expecting this type of account access in the near future. This is a new technology that is getting closer each day for mainstream implementation, but in my opinion maybe just not quite yet. My main hesitation is the amount of time this new technology has been available and running in a live production environment.
I believe a little more time testing and weighing security risks and counter-measures will be beneficial. I feel it will become an accepted method of access that will have proven itself given just a bit more time and testing. We are close and getting closer each day. This is something we need to keep in mind as the inevitable implementation edges closer. Planning and discussion should not fall behind.
Security and uniformity is a concern I have heard people having and maybe rightfully so, but there is hope. As for uniformity in platforms and security, there is definitely progress being made. Understanding just how mobile banking works can be confusing as well. As of right now there are only really three different ways in which mobile banking can take place: SMS-based, browser-based, and application-based. In my opinion the battle here is between browser-based and application-based access.
The first assumption may be that browser-based access is the natural choice, but as Internet browsing and online access from your PDA or cell phone increases so does the risk. Risks of mobile malware and viruses are real and will increase. This is a factor that may help application based access edge out the competition.
There are multiple vendors currently offering application based solutions that are compliant to NCUA and FFIEC two-factor authentication guidelines. Right now it appears as if AT&T is an early leader in it’s application based cell phone solution although other appear to be close on their heels.
Surely Verizon and other major carriers will have their own version to follow. This very competition and version evolution will naturally strengthen the product and therefore speed up its readiness for future implementation.
In conclusion, you may not be ready to take the risk or spend the dollars on this new technology, but maybe planning for it in the next one to three years should not be out of the question.
David Turner, IntegraSys
Certainly mobile banking is the next big thing for the Internet banking industry. “Online Banking Report” predicts that one-million households will leverage the convenient service by the end of 2007, and 10 million households will be using mobile banking by 2010 with rapid adoption continuing thereafter.
For credit unions, it can be daunting to take on the task of selecting a mobile banking provider. But since mobile banking should be a seamless extension of a credit union’s Internet banking services, it’s best to work directly with your existing Internet banking provider, or find a new provider who can offer a broad portfolio of online services, including mobile banking.
Since members will most likely be accessing the credit union’s mobile banking services from a wide range of devices, including cell phones and PDAs from disparate service providers, we can’t expect much uniformity in platforms and there’s no question that a credit union’s Internet banking provider must have the connection points and security controls in place to deliver Internet banking data to the broadest range of personal devices.
Our Virtual Branch team has been offering mobile banking for more than a decade, so we can offer the support a credit union needs today and in the future.
John Schooler,
Fidelity National Information Services
There are a lot of emerging players and approaches in the mobile commerce space. Member adoption is inevitable, with convenience being the primary driver. Best advice–start small, and start simple, but get started.
Capitalize on a strategy to win over consumers to mobile banking. Begin by offering limited services such as automated account alerts set by the consumer.
Expand services to payments as demand grows and the technology matures. Look for ways your institution can offset costs as mobile payments begin to catch on.
The main approaches today, from a technology standpoint, are short messaging service (SMS), commonly known as text messaging; wireless application protocol (WAP) and stand-alone mobile-application clients.
At FIS, we believe the latter holds the highest likelihood for consumer adoption. With this technology, the mobile banking application either is preloaded into a cell phone or PDA or downloaded from a website.
One day soon, you’ll be paying for a cappuccino at your favorite coffee house, using a cell phone that emits a radio signal beamed to a contactless card reader, while also deducting 10% off the price with a virtual coupon that was downloaded to your cell phone when you entered the store.
Tom DeSot, Digital Defense
Mobile banking is still in the early stages of adoption. As such, just like any other new technology, there is a great deal of flux in the industry as it pertains to platforms and security.
For some institutions, implementing may be necessary due to the nature of your members, or it could simply be that every competitor in your market has already bought in, and you’re beginning to see a resulting membership loss.
Regardless, institutions should take a hard look at any mobile banking technology prior to moving forward with implementation. At a minimum, the following topics should be discussed with your vendor(s) to determine if it is the right time to move forward:
* Security should be top of mind for your vendor. If the security of their platform is slide number 38 out of a 40-slide PowerPoint, that should tell you something.
At a minimum they should be able to outline for you how data is protected as it moves from the member’s phone, or other mobile device, through their software, and ultimately to your core processing system.
Remember, many of these implementations will require the member authentication credentials, and data, to pass through their platforms long before it is ever seen in your institution.
Additionally, they should be able to describe how their software prevents the storage of authentication credentials on the member’s phone or other mobile device. We’ve all lost phones before and fretted over it because it had all of our family and friends’ contact information stored on it. Imagine losing one that has your home banking credentials stored on it and the picture gets much, much worse.
* As with any new technology where there is no set platform standard, the institution needs to worry about platform obsolescence. For those of us old enough to remember the BetaMax/VHS battle, you already know what it’s like to invest in a technology that doesn’t make the grade. And as the philosopher George Santayana once stated, “Those who cannot remember the past are condemned to repeat it.”
Make sure that the vendor can describe to you how their platform can and will evolve to meet the changing needs of the market. Does it run on a proprietary platform? What happens if that platform is “end-of-lifed” by the maker? Then what? Is the software you are evaluating so customized that only three people on the planet would be able to continue with enhancements if the vendor’s principal developer left? How would they cope?
In closing, as with any other new technology, a full analysis needs to be conducted by the institution to ensure that the technology is really filling a need, and that the vendors that are providing the service are ready to bring their product to market in a solid, secure fashion.
Readers: Ask CUJ Technology Panel Experts
Readers can leverage the Credit Union Journal’s panel of technology experts by submitting any technology-related questions to the panel Managing Editor Lisa Freeman at lfreeman











