Tuesday, 20 January 2009

Learning old lessons about fraud

With "Ponzi" schemes and "rocketing levels of discovery" of insider fraud that has gone undetected for years finally being exposed by the credit crisis, corporate fraud will be an area of renewed focus this year as companies go back to basics to defend themselves against malicious and non-malicious attacks perpetrated by insiders.

With so much press and industry focus on the multitude of threats looming outside the corporate firewall, until recently insider fraud attracted few column inches. Given the impact exposure of corporate fraud has on a company's brand and reputation, it is not surprising perhaps that most incidences of insider fraud (50% in the case of insider fraud in banks, according to Celent) goes unreported.

Yet, with figures published by analyst firm Celent indicating that insider fraud accounts for 60% of all bank fraud cases involving a data breach or theft of funds, corporate fraud is an endemic problem and fraud experts anticipate it will be ratcheted up a notch or two by the recession.

Richard Abbey, managing director, Financial Investigations, for risk consulting company, Kroll, says the recession could give rise to the "non-malicious" corporate fraudster - those that commit fraud not for personal gain, but to save their company and employees' jobs. "It's misplaced loyalty if you like as they do not really think they are committing fraud," says Abbey. While anti-fraud measures tend to be focused on new employees, Abbey says the typical fraudster is the long-serving, loyal employee that knows their way around a company's systems.

Despite the introduction of Sarbanes-Oxley in the US, which placed more rigorous reporting requirements on a company's financials in the wake of the Enron and WorldCom corporate accounting scandals, Abbey expects to see more financial accounting scandals in the wake of the recession as corporate executives falsely inflate profits and cover up debts in an effort to maintain core ratios or to protect themselves from breaching banking covenants.

"We will see a significant increase in that type of fraud, however the jurisdiction is shifting from the more regulated markets where Sarbanes-Oxley, independent audit committees and the significant level of oversight make it more difficult to get away with, to emerging markets where supervision and broad oversight is not as advanced," says Abbey.
No surprises then that the latest accounting scandal has rocked Indian IT outsourcing firm, Satyam Computers, where the company's chairman has admitted to a $1 billion fraud, which is being billed as "India's Enron". Kroll is also seeing more companies reporting allegations of corporate bribery and corruption, which if proved true can attract hefty fines far in excess of the original bribe.

Given the threat landscape, it may be tempting for corporate executives and chief risk officers to reach for the latest gadgets: biometrics; enterprise anti-fraud systems; software that detects the potential for fraud in emails; however, fraud experts caution that brandishing the sword of technology is not necessarily the answer.

According to Abbey most corporate fraud is detected not as a result of controls companies put in place, but by accident or whistle blowers. There are, however, more immediate measures firms can put in place to protect themselves against insider fraud, segregation of duties being the main one, to ensure that no single person, regardless of how long they have been with the company, has "end-to-end" control over a business processes or processes.

In its latest Global Fraud Report, Kroll concludes that the financial crisis will lead to more fraud claims, legal disputes and regulatory action. Greater due diligence and levels of corporate governance will also be required and cross-border transactions are likely to increase exposure to "complex fraud and corruption".

“There are some wonderful technologies that can help solve fraud,” says David Porter, head of security and risk at consultancy, Detica, “but it is not just about wielding the sword of technology. It is about con artists scamming people. There is a soft human element to combating fraud. This year, companies are going to be learning a lot of old lessons about fraud.”

Monday, 12 January 2009

Corporate fraud - The revelations keep coming

As I mentioned in my previous post with the tide well and truly out as the credit crisis deepens, some unsightly corporate 'flotsam' is being washed up on our shores. But can we extrapolate from the increased disclosure of high profile corporate fraud cases in recent weeks and months that corporate fraud and the credit crunch go hand in hand?

Well the answer to that is yes and no. David Porter, head of security and risk at consultancy, Detica says corporate fraud was a major problem before the credit crisis began and that we are unlikely to see rocketing levels of fraud as a result of the crisis. "But we will see rocketing levels of discovery," he says. "When things are going well, people don't bother looking at fraud. Now that times are hard, what was previously non-pressing has become more pressing.”

In other words the scarcity of capital and renewed focus on corporate governance is helping shine the light on incidences of fraud that were less likely to be uncovered when everyone was drowning in liquidity and economic conditions were perhaps more conducive to inflating profits in financial statements.

Kroll's 2008-2009 Global Fraud Report says that 85% of companies were affected by at least one fraud in the past three years, up from 80% in its previous survey. The most common forms of corporate fraud according to Kroll's survey were theft of physical assets, which impacted 37% of companies, compared to 34% in the previous survey. Information theft also increased from 22% to 27%; and regulatory and compliance breaches from 19% to 25%.

In its 2008 Financial Risk Outlook, UK financial services regulator, the Financial Services Authority (FSA) identified financial crime as one of the key priority risks stating that “tighter economic conditions may lead to an increase in the incidence or discovery of some types of financial crime.”

Kroll anticipates that as a result of the credit crunch there is likely to be an increase in "non-malicious" corporate fraud committed by those "misguided" employers or employees who are not out for personal gain, but to save their company and employee's jobs. It also expects to see an increase in false accounting practices as companies look to inflate profits in order to maintain their core ratios or protect themselves from breaching banking covenants. We also understand that corporate bribery and corruption where business contracts are awarded on the basis of financial rewards and employees being coerced into collusion with outside gangs are also on the rise.
Below I have compiled a rough list of frauds or alleged frauds that have come to light since the credit crisis began 18 months ago. While these frauds are not necessarily the direct result of the credit crisis, the scarceness of capital has perhaps helped bring them to light or resulted in more exposure and heftier fines or closer regulatory scrutiny:

  • January 2008: Trader Jerome Kerviel incurred $7 billion in losses as a result of "rogue trades" at French bank Société Générale.
  • Also in March 2008, the now defunct Lehman Brothers suspended two London equity traders after "issues" were discovered on share valuations.
  • May 2008: Merrill Lynch suspends a trader for "overstating the value" of some equity derivatives.
  • Also in June 2008: Two former Bear Stearns hedge fund managers were arrested on charges of securities fraud pertaining to allegations of misleading investors regarding two funds they ran that were exposed to subprime mortgages.
  • October 2008: The US Federal Bureau of Investigation launches an investigation into Lehman Brothers, insurer AIG and mortgage providers Fannie Mae and Freddie Mac as they fall victim to the credit crisis. The investigation is believed to be looking at whether these firms unduly influenced agencies to "inflate" their ratings and misled investors about the true state of their assets.
  • December 2008: European banks reveal their exposure to ex-Nasdaq chairman Bernard Madoff's alleged $50 billion Ponzi scheme
  • January 2009: B.Ramalinga Raju chairman of Indian IT outsourcing firm, Satyam Computers, admits fiddling the books to the tune of $1 billion. It has since been described as "India's Enron".
  • 8, January, 2009: In the largest financial crime related fine, the FSA in the UK fines Aon Ltd, £5.25 million for failing to take reasonable care to establish and maintain effective systems and controls to counter the risks of bribery and corruption associated with making payments to overseas firms and individuals.
  • Also in January of this year: Police reveal they have arrested Kabir Mulchandani, the chairman of Dynasty Zarooni, a Dubai real estate company, on allegations of fraud.
This is by no means an exhaustive list and does not take into account the myriad of fines imposed against individuals and firms for fraudulent activity such as insider trading and mortgage-related fraud.

However, the list does appear to support Kroll's view that in worsening economic conditions, employees or company executives, particularly in beleaguered industry sectors such as the financial services industry, may be tempted to falsely inflate profits, mismark the value of securities, or attempt to cover up substantial losses.

These incidences also appear to highlight a range of motivational factors ranging from personal gain in the form of seeking generous end of year bonuses by falsely inflating figures to making more money for the company concerned, or in the case of the alleged Madoff Ponzi scheme, the attainment of personal kudos through the accumulation of wealth.

Wednesday, 7 January 2009

Who has been swimming naked?

As celebrated financier Warren Buffett once said, "Only when the tide goes out, do you discover who has been swimming naked." Thanks to the so-called credit crunch, a handful of high-flying financiers, traders and company executives have been caught with their pants down.

There were the former Bear Stearns hedge fund managers arrested on securities fraud, the exposure of Bernard Madoff's alleged Ponzi scheme, and now the chairman of Indian IT outsourcing firm, Satyam Computer Services has admitted to "fixing the books" for the past several years.

While these frauds are not the direct result of the credit crunch; as capital has become scarcer, frauds perpetrated some years ago have become more difficult to cover up. Quoted in the Financial Times explaining how the fraud had spiraled out of control, Satyam's chairman, B. Ramalinga Raju said: "It was like riding a tiger, not knowing when to get off without being eaten."

While corporate fraud is not a new phenomenon, it is difficult to determine how endemic it is as it can go undetected for years. However, according to analyst firm Celent, internal fraud accounts for 60% of bank fraud cases involving a data breach or theft of funds. While malicious insider fraud, as opposed to accidental fraud caused through employee negligence or error, accounts for a much smaller percentage(9%)of all data breaches in financial services, Celent estimates that up to 50% of all insider fraud incidents go unreported.

With capital scarce and a high number of employee redundancies on the cards, most fraud experts anticipate the credit crunch will provide the perfect breeding ground for some employees to try and defraud the company they work for. But what is more likely to emerge is that tight availability of credit will expose those frauds that have been going on for some time. Madoff and Satyam Computers are only the tip of the iceberg.

"The general rule of thumb is that 20% of fraud companies know about, the other 40% they are aware of but don't know how to deal with and the remaining 40% they know is happening, but they are unsure where it is happening," says Bart Patrick, head of risk at business intelligence firm, SAS UK.
According to Patrick in the wake of the credit crunch, more and more companies are waking up to the threat corporate and insider fraud poses, and with capital scarcer than ever before, no company can afford to let criminal gangs or employees walk off with a few million.

More importantly perhaps, customers are likely to take an even dimmer view of those firms that do nothing to prevent internal fraud, as it is ultimately the customer that ends up paying for the higher incidence of fraud in the form of increased margins on insurance policies, for example.

Tuesday, 6 January 2009

AML programs should be tailored to business models

"Brokerage firms' AML programs must be tailored to their business models," said Susan L. Merrill, executive vice president and chief of enforcement at US-based regulatory agency, FINRA (Financial Industry Regulatory Authority). Merrill was commenting on the $1 million fine it recently imposed against E*Trade Securities, LLC and E*Trade Clearing, LLC, collectively, for failing to establish and implement anti-money laundering (AML) policies and procedures that could reasonably be expected to detect and cause the reporting of suspicious securities transactions.

While E*Trade provided trading customers with online electronic access to the securities markets, according to FINRA, it did not apply the same levels of automation when it came to monitoring trading acccounts for suspicious or "manipulative" trading activity.

According to FINRA, E*Trade relied on its analysts and other employees to manually monitor for and detect suspicious trading activity without providing them with sufficient automated tools, which was deemed to be insufficient given E*Trade's online business model, which requires "computerized surveillance of account activity to detect suspicious transactions and activity."

Financial service providers have invested millions in automated solutions for detecting suspicious account activity, but AML is still largely viewed as a 'box ticking' exercise, with some academics questioning the large number of Suspicious Activity Reports that have been generated, with few resulting in actual prosecutions.

The British Bankers Association has previously said that law enforcement officials need to take AML more seriously by following up on reports and information gathered by banks whilst monitoring account activity.

Monday, 15 December 2008

Banks reveal exposure to alleged fraud

The financial papers are abuzz with the news of leading European banks' exposure to the alleged fraud committed by Bernard Madoff of Bernard L. Madoff Investment Securities, headquartered in the US.

HSBC, RBS, Spain's Santander and France's BNP Paribas reportedly have varying levels of exposure to Mr Madoff's "alleged $50 billion pyramid scheme", which according to the Financial Times, prosecutors allege operated on the basis of paying old investors with money raised from new investors.

RBS, a recipient of the UK government's bail out package in October, reported a potential exposure of £400 million to the alleged pyramid vehicle. According to the Financial Times report, HSBC's potential exposure may be considerably higher (approximately $1 billion). Not good news at a time when banks are already experiencing a significant reversal of fortunes thanks to their exposure to subprime assets. And with counterparty risk high on everyone's agenda, this revelation will come as yet another blow for an already beleaguered banking industry which is likely to face some pointed questions from investors regarding the due diligence they undertook before placing money with Bernard L. Madoff.

It appears that the regulators (in this case the US Securities and Exchange Commission) have also come under fire for ignoring early warning signs pertaining to Bernard L. Madoff Investment Securities. If there had been no credit crisis, then perhaps Madoff's alleged "pyramid scheme" would never have come to light. It also highlights the increasing number of links being made between fraud and the credit crisis.

Before the Madoff incident, a couple of Bear Stearns hedge fund managers were arrested on securities fraud charges and since the subprime meltdown, the US Federal Bureau of Investigation has launched investigations into the collapse of Lehman Brothers, the insurer AIG, and mortgage providers Fannie Mae and Freddie Mac.

According to newspaper reports, the FBI is investigating whether these firms unduly influenced agencies to "inflate" their ratings. It is also looking at whether these firms misled investors about the true state of their assets. The FBI is also believed to be investigating a number of firms over what it terms "subprime lending practices".

The following is taken from a Financial Crimes Report published in 2007 by the FBI and alludes to the potential for fraud in light of the subprime meltdown:

"As publicly traded subprime lenders have suffered financial difficulties due to rising defaults, analyses of company financials have identified instances of false accounting entries, and fraudulently inflated assets and revenues. Investigations have determined that many of these bankrupt subprime lenders manipulated their reported loan portfolio risks and used various accounting schemes to inflate their financial reports. In addition, before these sub prime lenders' stocks rapidly declined in value, executives with insider information sold their equity positions and profited illegally."
The FBI's 2007 Financial Crimes Report shows that the incidence of pending cases related to corporate and securities and commodities fraud has been steadily increasing every year since 2003. The Serious Fraud Office in the UK is also reported to be targeting corporate fraud in the wake of the crisis, calling on bankers and City "whistle blowers" to come forward with any information.

Thursday, 11 December 2008

Anti-fraud technologies get smarter

With card fraud and other forms of fraud reportedly on the rise during the economic downturn, anti-fraud management software vendors are having to up their game to play catch-up to the fraudsters.

Business intelligence and analytics vendors such as SAS, focus on not just looking at fraud in terms of monitoring card transactions, but the ability to match seemingly unrelated events across different parts of the business. Its real-time card fraud detection system which is used by banks such as HSBC, reviews card transactions alongside other changes in customer behaviour and then based on that analysis advises in real time as to whether a card transaction should proceed or be flagged for further investigation. Using such a system, HSBC claims to have reduced false positive rates, which is one of the biggest bug bears of any fraud detection system.

But while banks may deploy a system to try and combat the different forms of fraud that are prevalent today, it needs to be flexible enough to predict and detect changes in fraudsters' behaviour patterns in order to avoid detection. Analytics and decision management vendor, Fair Isaac Corporation, is trying to do this in the debit and credit card space with version 6.0 of its Falcon Fraud Manager scoring server, which
uses recent advances in fraud analytics and profiling to help banks more quickly identify changing fraud patterns.

Using what it calls, "adaptive analytics", Fair Isaac provides "dynamic, real-time self-calibration of fraud detection models" to help firms more quickly identify changing fraud behavior patterns and improve fraud detection performance.

Another software provider, Actimize has incorporated IBM InfoSphere's Global Name Recognition (GNR) technology into its risk management platform. GNR is designed to help firms overcome challenges in matching names across different cultural and language barriers as part of their financial crime fighting efforts and works by analysing the order of a name, cultural spelling variations, nicknames and different spelling variations.

"[Global Name Analytics] ... can help to identify and correct names that may have been presented in non-standard or incorrect sequential order." It can also identify the "cultural classification" of a person's name using linguistic and statistical tools, which can be useful for Know Your Customer regulations and anti-fraud projects that entail matching names against lists or databases of suspected terrorists or Politically Exposed Persons.



Risk management in your Xmas stocking

This post first appeared on FinancialTech Insider

Go to a Christmas lunch these days and most people will be talking about what they are filling their Christmas stockings with or how they are looking forward to eating turkey yet again for the fourth time in a week. While the conversation at business intelligence and analytics vendor, SAS's Christmas press lunch may have been peppered with such conversational tid bits, the real subject of today's lunch was for SAS to publicise its recent foray into the capital markets space.

Building on its already strong base in the retail banking sector, particularly in the areas of operational risk, credit risk, market risk and financial crime, SAS has put together a team based in the UK that is wholly focused on selling its analytics and risk management solutions to capital markets firms.

2009 is likely to see increased regulatory oversight, particularly when it comes to the overlooked areas of liquidity and counterparty risk; and not one too miss an opportunity, SAS is eager to sell its solutions to a business that is drowning in information, but not quite sure what to do with it or how to make sense of it in order to determine risk, fraud liability etc.

It seems the poor old trader is likely to come under increasing surveillance with intelligent software algorithms monitoring their every move and looking for unusual patterns of behaviour (the ability to match seemingly unrelated events across different parts of the business). The technology certainly exists to provide such surveillance, but the cynic in me says most banks are only likely to embrace these technologies as a 'box ticking' exercise in order to comply with regulation, rather than seeing it as good business per se.

Risk management is suddenly the business to be in, but one has to wonder where was all this wonderful bells and whistles technology when things started going wrong in capital markets? And at the end of the day technology can only do so much.

If the people in charge still view "betting on the bank" as a necessary part of making money, or don't want to listen to those 'little voices' in their risk department warning them that something bad is about to happen; then no amount of technology can account for the fact that the culture within firms has to fundamentally change if risk management is to be viewed as a strategic asset and not something that is ferreted away in a back office somewhere filing reports to regulators that no one really concerns themselves with.

Interestingly, while we only get to hear about the multi-billion dollar losses racked up by rogue traders like Jerome Kerviel, there are plenty of other million dollar losses within banks, which occur on an almost daily basis (be they the result of human error or internal fraud) that we don't get to hear about.

Mark Hudson, industry consultant, Capital Markets, SAS, believes if firms can start minimising those million dollar losses we don't get to hear about via market or trader surveillance technologies then perhaps the industry will have achieved something.

Surely saving the bank a few 'mill' from combating accidental or internal fraud is going to make a CFO's ears prick up in this challenging business climate? And even if it doesn't, then Hudson believes the banks' customers and may be even their shareholders (which lets face it is the government these days) may insist on more risk management oversight.
Posted by Anita Hawser