Technology Risks in Digital Banking
Trust and Reputation in Digital Banking
Banking services are used out of necessity rather than desire. For customers to trust a bank's brand, they must achieve a state of "peace of mind" regarding the timely and safe fulfillment of their needs. This requires trust in the underlying institution. Technology is viewed not as an end in itself but as a facilitator for accessing products and services. Digital banks succeed when they provide confidence that customers and their money are in "good hands," backed by robust technology.
The Human Element of Trust
Steve Jobs, co-founder of Apple, famously stated: “It's not a faith in technology. It's faith in people” (Goodell, 2011). While technology, governance, and risk management are essential, they are only as effective as the individuals behind them. Bank staff must act ethically and responsibly, treating trust as a core business element.
Economical Framework of Trust
Economist Oliver Williamson (1993) identified three key drivers of trust:
Calculativeness: This is a rational, economic perspective where people estimate the degree of trustworthiness based on perception and past experience.
Incumbent Banks: Benefit from "legacy trust" and long-term familiarity.
Digital Banks: Build trust by contrasting themselves against incumbents and offering innovation.
Personal: This involves trust created through human bonds, shared experiences, and emotional connections. It is inherently unmeasurable. It is influenced by individual risk appetites, culture, geography, upbringing, and environment.
Institutional: This refers to the socio-organizational context, such as policies and regulations (e.g., trust in the laws that protect consumers). It is influenced by internal/external environments, economic shifts, and sectoral norms.
Williamson concluded that trust is a combination of these factors, and all are negatively impacted when a breach occurs.
Reputation in a Digital Age
Reputation is a primary source of competitive advantage and a key asset. Banks must manage reputational risk because operational errors can occur anywhere.
The Impact of Social Media
Technology increases the speed and reach of negative information. Social media and review sites provide public forums for denouncing banks, sometimes through unjustified or negative reviews.
Case Study: Silicon Valley Bank (SVB): The $2023$ collapse of SVB may have been fueled by social media. Because its customer base consisted largely of tech entrepreneurs—frequent social media users—the bank was highly susceptible to negative "chatter" (Jiang et al., $2023$).
Benefits and Risks of Social Media Usage
While banks use social media for marketing and PR (e.g., WeChat in China for payments), it entails specific risks:
Confidentiality Breaches: Staff may discuss customers in public arenas.
Misunderstandings: Irate users sharing out-of-context responses.
Regulatory Breaches: Fast-paced communication may bypass complex communication regulations.
Imitation: Fraudsters or pranksters creating fake profiles.
Risk Management in Banking
Risk management is an iterative four-step cycle aimed at balancing upsides (opportunities) and downsides (pitfalls).
Risk Identification: Searching for potential risks. Methods include beta testing for new tech and hiring ethical hackers to find system weaknesses.
Risk Evaluation: Assessing the potential impact and likelihood of occurrence (IRM, $2002$). Banks prioritize high-impact/high-likelihood risks and use simulations to gauge financial effects on balance sheets.
Risk Management: Risks are addressed by:
Eliminating
Reducing
Transferring (e.g., insurance agreements)
Accepting (if immaterial)
Risk Monitoring: An ongoing process of tracking known risks and identifying new ones in a changing environment.
The Three Lines of Defence
Operational risk arises from external events or flaws in people, processes, or systems (BIS, $2011$). The "Three Lines of Defence" model helps identify weaknesses:
First Line: includes everyone in the institution. Operational managers and teams apply policies and monitor for emerging risks.
Second Line: The risk management and compliance departments. They develop and communicate internal risk mitigation methods.
Third Line: Independent oversight. This includes internal/external auditors, the board's risk committee, and regulatory bodies.
Regulatory Requirements: The Basel Accord
The Basel Accord sets global standards, requiring banks to set aside capital (shareholders' funds) as a buffer.
Banks with superior risk management have lower capital requirements, providing a competitive advantage as more capital is available for investment.
Neobanks/Fintechs: At a disadvantage due to lack of historical data. They are often judged by sector averages until they establish a track record, leading them to focus on niche areas initially to build data.
Technology-Related Risks
Risks can emerge from non-tech factors (human error, theft, fire) or the adoption of new technology:
Strategic Risk: Strategy fails to deliver; entering a market too early (slow adoption) or too late (lost advantage).
Competition Risk: Loss of market share to new entrants.
Financial Risk: Cost of investing in AI, infrastructure, and training.
Contagion Risk: Adverse events in one bank transmitting to another. AI interconnectedness can increase this.
Market Volatility Risk: Unpredictable market changes; recruitment of external talent to complement internal resources can increase volatility (Grant Thornton, $2023$).
Operational Risk: Includes cybersecurity, third-party risk, fraud, and system failures.
Example: Singaporean bank DBS suffered a multi-hour outage due to a coding error (Yu, $2023$).
Cybersecurity Risk
Cybercrime is committed by "bad actors" (criminals, hackers, disgruntled employees, or state-sponsored entities). Digital theft is often easier than physical theft due to system vulnerabilities.
Types of Cyber Attacks
Injection of Malware: For blackmail or ransom.
Distributed Denial of Service (DDOS): Overwhelming a system with requests to crash it.
Data Breaches: Stealing digital currency or personal data.
Individualized Attacks
Identity Theft: Exploiting human error to extract personal info (e.g., mother's maiden name) to reset passwords.
Phishing: Social engineering via email. Variants include Vishing (voice) and Smishing (SMS).
Investment Management Fraud: Scammers posing as intermediaries in "boiler rooms" using high-pressure tactics or selling worthless cryptocurrencies.
Merchant Fraud:
Swipe and Snatch: Employees copying card details for later use.
Bust-out Fraud: Fake businesses taking payment for services never rendered.
Transaction Laundering: Legitimate merchants processing for fake ones.
Triangulation Fraud: Stealing details from customers to use at a legitimate merchant.
Identity Swap: A merchant account used as a front for money laundering.
Attacks on Bank Systems
Money Laundering: Obscuring criminal sources by passing funds through complex products.
Ransomware: Malware that holds a system "hostage" for payment.
Example: In $2023$, the Chinese bank ICBC suffered an attack disrupting US government bond settlements (Kharpal, $2023$).
Data Theft: Injecting data-harvesting code or internal staff abusing access.
Cybersecurity Management
Risk Awareness: Senior management oversight and role-specific training for staff. Customer education (e.g., Santander UK warning about remote access scams).
Proactive Oversight: Using machine learning to detect anomalies. Caution: Incorrect calibration leads to "false positives."
Red Teaming: Hiring consultants for "ethical hacking" to find vulnerabilities.
Verification: Biometrics (fingerprints, voice) and two-factor authentication.
Technical Controls: Firewalls, encryption, and tracking GPS/Time zones for detectivbe monitoring.
Cloud and Artificial Intelligence Risks
Cloud Computing Risks
Architectural Complexity: Combining cloud with legacy systems creates outages and oversight gaps.
Third-party Risk: Dependency on external providers. Citibank in Singapore went offline in $2023$ due to an issue at cloud provider Equinix.
Skill Shortage: Difficulty recruiting qualified cloud developers (Accenture, $2022$).
Data Security: Difficulty ensuring data deletion or security on the provider's hardware.
AI-Related Risks
Biased Data: Algorithms trained on discriminatory historical data can amplify unfair lending or hiring.
Incongruent Objectives: Miscalibrated rules.
Example: ChatGPT's tendency to create credible-sounding but false answers because its objective was word prediction, not truth (Loeffler, $2023$).
Infrastructure Issues: Legacy systems were not designed for the volume of data AI requires.
Reputational Issues: Perceived bad intentions.
Example: Apple's credit card ($2019$) was accused of gender discrimination. An investigation cleared the algorithm (NYSDFS, $2021$), but the reputational damage remained.
Customer Engagement: Loss of the "personal touch," leading to detachment.
Staff Morale: Fear of being "replaced by robots" leading to redundancy.
AI in Risk Management and Support
Credit Risk
AI assesses the risk of non-repayment by predicting default risk using application data and historical performance. This allows banks to adjust the "loan acceptance threshold."
Fraud and AML
Fraud: Detecting patterns and anomalies to block transactions pre-emptively.
Anti-Money Laundering (AML): Algorithms operate behind the scenes to detect the movement of criminal funds without alerting the suspect.
Customer Support
AI monitors interactions for quality assurance and uses predictive models to identify customers at risk of closing their accounts.
Climate Change and Sustainability
$91\%$ of Chief Risk Officers view climate change as a top issue through $2026$ (Sutcliffe, $2021$).
Physical Risks: Extreme weather impacting operations or rural economies.
Transition Risks: Shift to a green economy impacting specific customer bases.
Modeling: AI provides powerful simulations for transition scenarios (orderly vs. disorderly transition).
TCFD: The Task Force on Climate-related Financial Disclosures framework requires massive data collection, which supports AI implementations.
Financing: The global transition requires approximately annually, providing a massive opportunity for bank innovation.
Brand Identity and Satisfaction
Visual Identity
Colours: Incumbents use solid blues/purples for stability. Challengers use red (provocative) or green (sustainability).
Typeface: Simple fonts convey confidence/simplicity; complex fonts convey history/wealth.
Images: Squares for stability; animals (e.g., ING's Lion) for strength.
Brand Risk Management
Group Brands: Using multiple brands to diversify risk.
Customer Brands: Avoiding association with "unethical" industries like tobacco or oil/gas.
Partner Brands (White Labelling): Placing the bank's brand on third-party products. Risk: the bank is blamed for the partner's service failures.
Recommender Engines
Banks use machine learning to suggest products in four steps:
Data Collection: Transaction history/demographics.
Data Processing: Filtering duplications.
Machine Learning: Matching customer patterns to products.
Recommendation Generation: Delivering personalized suggestions via email or apps.
Measuring Satisfaction
Banks monitor "drop-off rates" (uncompleted transactions) and account closure trends to gauge interface effectiveness and customer trust.