RDC Risk Management in 2015

Similar documents
RDC Risk Management in 2013

RDC Risk Management & FFIEC Compliance May 2010 Update

RDC Risk Management Update 2011

Risk Management Technologies The Latest & Greatest from Throughout the Industry

RDC Audit & Compliance: Lessons from the Battlefield

Electronic Banking Remote Deposit Capture Third Party Payment Processors Automated Monitoring Systems Staffing & Resources

Auditing for Effective Training

NCR Passport for Commercial. Part of NCR s enterprise hub for remote deposit capture

ACING YOUR REMOTE DEPOSIT CAPTURE AUDIT:

Expand Remote Deposit & Mitigate Risk:

Consumer & Small Business RDC Opportunity & Case Study

Solutions. Cash & Logistics Intelligent and Integrated Solutions to Optimize Currency Levels, Reduce Expenses and Improve Control

Treasury Management Guide

NCR APTRA PASSPORT An enterprise hub for remote deposit capture

Products. Commercial Banking Attract, Retain and Grow Profitable Business Relationships in a Highly Competitive Environment

AML model risk management and validation

VISION MANAGEMENT SOLUTION

TREASURY MANAGEMENT. Dynamic Solutions. Superior Results.

Actimize Essentials. Cloud-based Solutions for Financial Crime Prevention & Regulatory Compliance

Enterprise RDC Risk Management

The New Rule on Customer Due Diligence Key Takeaways from Banker s Toolbox

Customer Due Diligence A Risk Based Approach. Dr Tony Wicks Director of AML Solutions NICE Actimize

Non-Banking Financial Institution (NBFI) Third Party Payment Processor (TPPP) AMLQuestionnaire

INTELLIGENT FINANCIAL CRIME DETECTION GETTING AHEAD OF FINANCIAL CRIME WITH AI THE POWER OF AI

Ruth A. Harpool, AAP, CTP Director, Treasury Operations Indiana University

RDC Risk Management and Compliance: Expert Update & Case Study

REGULATORY COMPLIANCE. Dynamic Solutions. Superior Results.

IIB - INTERNATIONAL BANKING ANTI-MONEY LAUNDERING SEMINAR

Payment Processor Buying Guide. How to prepare for sending out an RFP

Financing IBM Counter Fraud Management Solutions for Banking

Mobile Remote Deposit Risks, Rewards, and Deposits Presented by Kevin Olsen, AAP NCP SVP, Payments Education

ANTI-MONEY LAUNDERING SERVICES EXPERTS WITH IMPACT

Source Capture Solutions

User s Starter Kit. For Home or Small Office Use. fcbbanks.com

Introducing an easier way to manage your business

Effective Risk Management With AML Risk Assessment. January 25, 2017

Customer Due Diligence Risk-Based Approach. Dan Soto CCO Ally Financial

Juan Carlos Ramirez, VP, AML/ATF & Sanctions Audit, Scotiabank. Compliance and Risk Management

Retail Payment Systems Internal Control Questionnaire

REMOTE DEPOSIT CAPTURE (RDC) CHECK IMAGING AT THE ATM

Enroll Today! Annual Member Package Price: $2, Founder s Message TERRI SANDS CAMS AUDIT, CFE, AAP, ACT SPECIALIST

Anti-Money Laundering and Sanctions Compliance. You Can t Afford the Risks

Solutions. Card Risk Management Leverage Our Industry-Leading Solutions and Services to Fight the Rising Cost of Fraud

Defining and promoting excellence in the provision of mobile money services

JOB TITLE: VP, BSA Officer REPORTS TO: SVP, Deposit Operations and Regulatory Compliance/CRA Officer DEPARTMENT: Compliance

Actimize Essentials AML. Cloud Based Anti-Money Laundering Solutions

W H I T E PA P E R l The True Paperless Branch

NCR APTRA Vision The business intelligence you need to make smarter decisions today, so you can achieve your goals tomorrow. An NCR Buyer s Guide

WELCOME. 1

OVERVIEW MAPR: THE CONVERGED DATA PLATFORM FOR FINANCIAL SERVICES

Are You Sure You Have the Right RDC Solution

E-Debit International Inc. Introduction to Transaction Processing. Basic Overview of our Payment & Processing Systems 08/13

Risk Management TRAINING AND EVENTS. aba.com/risktraining

Intelligent Payment Management for Today and Tomorrow Technology Advancement to Navigate the Converging Payments Landscape

2017 Conference Takeaways

NCR BRANCH TRANSFORMATION SOLUTIONS

SANTANDER TREASURY LINK Built for the way you do business

Excellence as a commitment, innovation as a goal. Flexibility and Experience

RSM ANTI-MONEY LAUNDERING SURVEY BEST PRACTICES AND BENCHMARKING FOR YOUR BSA/AML PROGRAM

CORE BANK PROCESSING MERIDIAN.NET. Dynamic Solutions. Superior Results.

REMOTE DEPOSIT CAPTURE (RDC) CHEQUE IMAGING AT THE ATM PART OF NCR S ENTERPRISE HUB FOR REMOTE DEPOSIT CAPTURE

HOW INTEGRATED RECEIVABLES OVERCOMES THE FOUR BIGGEST CHALLENGES IN ORDER-TO-CASH

Financial Institutions Consulting. Quality service. Personal attention.

An all-in-one risk management platform delivering fraud detection, transactions screening and customer due diligence capabilities

FRAUD MONITORING. Modern, comprehensive solution for fraud detection and prevention in banking systems.

Preventing Board and Management Liability for Violations of AML Rules

RISK MANAGEMENT IN ELECTRONIC PAYMENTS. Olutimilehin Oyesanya (Phillips Consulting) CISSP, CISA, COBIT 5 Assessor, PMP, ISO LA, ISO LI

Ten Payment Fraud Protections

Product Frontier Reconciliation

Key BSA/AML takeaways from the 2015 FIBA conference

LESSONS LEARNED FROM BSA ENFORCEMENT ACTIONS

Jen Wasmund, AAP, NCP Compliance Services Director

CORE BANK PROCESSING NUPOINT. Dynamic Solutions. Superior Results.

Remote Deposit Capture An Overview of how Technology and Legislation changed core banking

Fed Consultation Paper Association for Financial Professionals (AFP) Response

BSA/AML Self-Assessment Tool. Overview and Instructions

Omni-Channel Capture: An Evolving Strategic Direction

EMBEDDING THE PAYMENTS PROCESS: 3 STEPS FOR INTEGRATION AN EBOOK BY

How to discover ways to sustainable anti-money laundering operations*

BSA/AML Compliance in Acquisitions

You Don t Have to be Big to Get Operational Economies of Scale

Treasury Management Solutions

Anti-Money Laundering

OPERATIONAL TRANSFORMATION OF ANTI-MONEY LAUNDERING THROUGH ROBOTIC PROCESS AUTOMATION

REGULATORY HOT TOPICS FOR INTERNAL AUDITORS: EVALUATING THE USE OF AML TECHNOLOGY

Advanced Finance for Governing Board Members. Charter Schools: Advancing the Promise!! 2015 Annual Conference

Dealing with Duplicates 3-Part Session Series -Session #2- Operational Considerations

SMALL BUSINESS RDC: TAKING TRANSACTIONS OUT OF THE BRANCH

CONSULTATION DOCUMENT AML/CFT SUPERVISORY STRATEGY

RETHINKING WHAT RDC MEANS TO YOUR CUSTOMERS AND YOUR FINANCIAL INSTITUTION

Info paper Is your sanctions filter working?

FMS New York/ New Jersey Chapter Meeting January 14, The Impact of Models. by: Scott Baranowski

Virtual Currency and Electronic Money Movers: AML Red Flags. John A. Beccia, Circle Internet Financial

THE ARCG CHARTER. Issued in March 2008

Fraud Controls to Tackle the Mobile Revolution

STAR Network Overview

Statement on Risk Management and Internal Control

The Changing Check Deposit Landscape: An Obstacle Course for Fraud Management. Copyright 2016 NICE Actimize. All rights reserved.

BSA Risk Assessments and Transaction Monitoring Systems: Partners in Crime Prevention and Detection

Emergency Preparedness: Financial Resiliency When Disaster Strikes

Transcription:

RDC Risk Management in 2015 John Leekley, Founder & CEO RemoteDepositCapture.com Be sure to tweet about the #RDCSummit and mention @RDCTweet

Setting the Stage Discussion Objectives Definition of RDC Risk Management Guidance Tools of the Trade Risk Management Tactics & Strategies Leveraging KYC, System Functionality Enterprise Risk Management Trends & Developments Kicking the Tires Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 2

But What Has Changed?? Evolution of Risk Management Enterprise Approach Technology External Impacts EMV Migration (Cards) New Products / Services Legislation & Regulation Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 3

RDC is a Payments Platform RDC Applies to a family of related products & services most often differentiated by location of payment capture. Remote Deposit Capture Corporate Merchant Consumer Mobile Teller Branch Lockbox ATM Correspondent The term Remote Deposit Capture refers to the process of electronically capturing check images and data, transmitting that information for deposit and clearing, and truncating the original paper checks. This definition is evolving to include additional payment types, including card payments. RDC is becoming an integrated technology platform increasingly used to process different types of payments and data with the ability to feed that data to systems both internal and external to the organization. Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 4

FFIEC Guidance: RDC is a Delivery System RDC is a Payments & Data Processing System Scope of implementation and exposure Should be incorporated into existing risk management process Governance, Oversight & Tactics will, and should, vary by institution Non-Public Personal Information Complexity of Risk Identification will vary Internal IT systems, Third-Party Solution Providers Involve relevant stakeholders FFIEC Guidance Mitigate Monitor Measure Actionability & Sustainability Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 5

RDC is Safe! RDC is NOT a new payment type, just an enhanced channel Leverages online & mobile technologies Leverages Processes and Risk Management Better ability to identify risks Traditional Fraud reduced through faster clearing Better, Automated Data than pre-rdc Risks Unique to RDC: Managing the Original Bait & Switch Duplicates Original Document Alterations The greatest risk unique to RDC lies in the use and handling of the original document. These risks can be mitigated with sound risk management practices. Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 6

Regulatory Guidance Overview 1. FFIEC RDC Risk Management Guidance released January 14, 2009 RDC risk management process in an electronic environment Focusing on RDC deployed at a customer location Principles of RDC risk management discussed are applicable to: FI s Internal deployment ATM, Branch, Cash Vault Other forms of electronic deposit delivery systems (e.g., mobile banking and automated clearing house [ACH] check conversions). 2. Retail Payment Systems Booklet {& RPS Examination Procedures (N), (M)} February 10, 2010 3. 2010 Version of the Bank Secrecy Act/Anti-Money Laundering Examination Manual Updated April 29, 2010 4. Authentication in an Internet Banking Environment October 12, 2005 1. Supplement to Authentication in an Internet Banking Environment June 22, 2011 Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 7

Three Pillars of the FFIEC Guidance Responsibility Senior Management Board Risk Identification & Assessment Internal External Process Mitigation & Controls Planning Measure Monitor Report Risk Identification Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 8

Risk Environment Identification Identify Key elements of the RDC environment Internal Third-Party Markets/Customer/Capture Devices Identify Responsible staff members and risk management team Internal Staff: Product Manager, Risk, Treasury, Sales, etc External: Technology Provider, Processor, etc. Review: Volume reports ($ s and Transactions) Network design at the FI, Service provider and customer Dataflow maps and logical system diagrams The risk management process Report review process Establish Relevant Contracts & Agreements Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 9

Risk Reporting and Monitoring Checklist Examples Develop a Risk Audit Checklist Example Written RDC Policies and Procedures Document Legal Agreement needs periodic review Customer Selection, rules and limits Establish thresholds and limits for volume, velocity and value Monitoring and review of accounts for duplicates, rejected and returned items Monitor internal, partner and customer processes: Security and Access Separation of responsibilities Establish procedures for regular reporting Deposit history and to identify patterns Periodic training, emails or letters to customers RDC included in audit process Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 10

Key Information: Know Your (Biz) Customer Understand Business Finances, Customers, Processes CDD (Customer Due Diligence, EDD (Enhanced Due Diligence, CIP (Customer Identification Program) Understand Deposits Obtain History Volumes & Values of Items, deposits, returns, Velocity Use this data to custom-fit RDC Thresholds, Limits, Holds & Availability Schedules Separation of Duties, Approvals Functional Capabilities Pricing, Balances, monitor deposit & data trends. RDC Should be customized to each individual client. Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 11

KYC While KYC requirements may differ between jurisdictions and regulatory regimes, organizations are generally required to understand their clients : Circumstances Business type Source of funds and wealth Purpose of specific transactions Expected nature and level of transactions Regulators expect that client information is maintained, current and valid which implies that organizations should revisit their KYC procedures regularly. Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 12

KYC Challenges Multiple lines of business doing redundant processes On-boarding and activation delays KYC processes inefficiencies in due diligence and assessment Regulatory changes and requirements CDD (Customer Due Diligence, EDD (Enhanced Due Diligence requirements for location, type of business and/or person Domestic and International, Risky business, Customer Request Incremental Request for existing client (RDC, Cash, ACH,, etc.) New Customer Onboarding Client Due Diligence Collect details Request client documentation as required Perform regulatory AML and KYC Complete Additional documents Checks (geographic, business type specific Credit/Risk Review Perform credit due diligence Establish credit/deposit limits Assess and manage additional risk across lines of business Set Up Account Complete Account Setup Deposit Agreement Additional Agreements as required by Legal Enable Account Monitor Account Report on activity vis-à-vis established limits Review changes in credit/risk exposure due to changes in credit report and new products Treasury/Branch/Online KYC/Risk Credit Legal/Operations Operations Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 13

Leverage the KYC you ve already done Customer selection and KYC Review process at the FI who is involved and what level of management Risk rating system Elements included in decision criteria User / Location / Account Parameters - Identify & Prevent Fraud & Mistakes. Client Deposit Trends Ensure metrics, safeguards are relevant. Availability Schedules & Holds - Don t blindly make short-term loans, allow for returns, effective way to deal with questionable items. Balances Competitive advantage, strengthens balance sheet, maximizes revenues and minimizes losses. Even with minimal KYC, risks can be adequately handled through effective employment of standard risk management techniques. Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 14

RDC & Enterprise Risk Management ERM begins with KYC, understanding your risk tolerance & requirements, and having the right technology, process and oversight to balance Risk & Reward. OFAC Compliance Automate Suspicious Activity Reports Adhere to Sanctioned Country List BSA / AML Logical Approach to Enhanced Due Diligence Know Your Customer & KYCC Integrate Check with Enterprise Monitoring Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 15

BSA / AML & OFAC Bank Secrecy Act/ Anti-Money Laundering Examination Manual New RDC Highlights 1. Senior management should identify BSA/AML, operational, information security, compliance, legal, and reputation risks. 2. Conducting appropriate customer CDD and EDD. 3. Obtaining expected account activity. Case Studies: Wachovia: $160MM Fine Dallas Community Bank, T-Bank: $5.1MM Zions, HSBC, FL, etc. RDC must be integrated into a bank s AML / BSA risk management and reporting activities. Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 16

Oversight and Audit Guidance by local FDIC examiner: Think of the spirit of RDC guidance and apply to this new channel. Adding mobile RDC to Board-level RDC Policy Use automated routines that will address KYC and risk management Account activity review Limits Holds Duplicate check detection KYC Know Your Customer is Always Key Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 17

Validation Rules and Work Types Define Systemic Rules & Thresholds Image Quality Field Validation Item type acceptance Balancing Rules Target Functionality by Client Group Excellent Customers New Customers Risky Customers Source: Fiserv Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 18

Oversight and Monitoring Locations Financial institution Vendor Customer Operational benchmarks Key risk metrics Performance metrics Management Review Who and how Frequency &Timeliness Accurate Point-in-time Trend RDC Product Individual customer Aggregate customers Type of Reports Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 19

Education & Training Education & Training FI associates and customers Most customers will want to protect themselves System Operation & Process Safekeeping & Destruction of original items Risks & the role of the customer and the FI Duplicate Presentment Information & Data Problem Resolution Periodic emails or letters to customers to remind them of their responsibilities for: training, security, process, check retention, endorsements, adequate safeguards for storage of checks and account information AML / BSA Training Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 20

Separation of Duties Split responsibilities and procedures for: Account set up and Deposit review, approvals and reconciliation at the FI System security review procedures At the customer location separation of duties Capture (scan) and send deposits or for review of reports of deposits sent and for reconciliation. Other controls Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 21

RDC Systemic & Targeted Risk Management Systemic Risk Management Enterprise Risk Management AML / BSA / Payment Validation & Reporting System-Wide Risk Management Duplicate Detection, Image Quality / Usability Reporting & Audit Functionality Legal Agreements Targeted Risk Management Source Merchant, Consumer, Mobile, Branch, ATM etc. Domestic, International Trend Analysis & Patterning Item / User Limits & Thresholds Holds, Availability, Balance Requirements, Customer Selection, etc. Optimal RDC Risk Management should be tailored to each end-user, location and device, yet leverage system and enterprise risk management capabilities. Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 22

Enterprise Risk Framework Establish a Risk Framework Planning, Risk identification and assessment, Controls, Measuring and Monitoring Determine appropriate level of governance, oversight, and risk management Size and complexity of the financial institution, Relative scale and impact of RDC to overall activities Management must: Approve plans, policies, and significant expenditures, Review periodic performance and risk management reports on implementation and ongoing operation and services. Management is responsible for the RDC system Risk Activities Planning Risk Assessment Risk Discipline Risk/Event Identification Response Controls Communication Monitor & Report RDC Risk Framework Technology COSO Integrated Framework (Modified) Customer Internal 3 rd Party Risk Granularity Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 23

Enterprise Risk Management Framework Source: Wipro Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 24

Tactics for RDC Risk Management Traditional Client Selection Credit Relationship Balances History Thresholds Daily and Monthly Deposit $ & Volume Limits Availability Evolving Client Selection Leverage KYC, History & Monitoring, Balances Availability Real-time Monitoring Thresholds (Dynamic) Daily and Monthly Deposit $ & Volume Limits Endorsement Identification Verification & Guarantee Enhanced Duplicate Detection Location Awareness Risk Scoring Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 25

Fraud Monitoring & Prevention Monitoring Process to identify potential fraudulent items Real-time Systems Mitigate Risk before / as it happens Return Item Monitoring Adjustments! Some Duplicate Items returned this way. Functionality duplicate detection, deposit limits, pattern identification, safeguarding check Restrict Functional Capabilities by location Minimize Fraud Opportunities. Foreign location identification and monitoring Mobile Deposit Positive / Negative Databases The data is out there! Internal: Build Track Record External: Developing Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 26

Site Visits?? When Warranted Site Visit Define risk levels (Define When Warranted ) Returns, Duplicates, Availability Assignment, Deposit Thresholds, Volumes, New Clients, combination of metrics, etc. Leverage Monitoring & Reporting (Actionability) When Appropriate Self-Assessments Apply same evaluation items as a site visit Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 27

The Importance of Endorsements Endorsements can help prevent duplicates Restrict deposit to a specific bank & account Legal & Regulatory implications Appropriate endorsement can be identified Teller Payor Systemic Identification Decreases likelihood item will be used Criminals can also see the restrictive endorsement Systemic Capabilities are evolving Hardware & Software Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 28

New Tricks of the Trade Legal Protection Endorsement Detection Operational Performance Scanner Read Rates / Image Quality Scanner Cleaning & Maintenance OFAC Compliance Location Awareness Mobile, Scanner, PC Monitoring, Alerts and Actionability The move towards Real-Time processing Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 29

Greatest Threat: Duplicates Duplicates / Cashing Fraud One Check, Multiple Deposits Depository FIs Clearing Returns Paying / Bank Final Step, Check Cashed Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 30

Potential RDC Losses: Duplicates RDC Deposit ( Duplicates ) Fraud Definition: Process by which criminal is able to deposit the same legitimate or fraudulent item at several FIs, then withdraws the funds before items are returned. Criminals Look For Minimal KYC No Balance Requirement No Holds Immediate Availability No / High $$$ Limits Risk Management Beware of Customers who don t keep balances. Require Balances! Holds on New Customers, High $$$ Availability Schedules $$$ Thresholds Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 31

Risk Management Duplicate Detection Duplicate Detection should ideally be done across all levels & accounts, channels and products. Levels & Accounts User, Location, Account Channels RDC Location, Lockbox, ATM, Branch, Mail Drop, Kiosk & Inclearings, etc. Products Check and ACH (for converted items) Network All banks using a specific service provider Industry Recent Industry Developments / Early Solutions Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 32

Potential RDC Losses: Bait & Switch The Con: 1. Obtain Legitimate Check From Victim. 2. Deposit Using RDC 3. Return Original to Victim 4. Ask Victim to provide funds via alternate method Result: Criminal gets paid twice by legitimate payment types, once by check, once by wire. Prevention: Stop Payments on Check, Positive Pay, Client Education, delayed availability, deposit limits, endorsements Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 33

mrdc Risk Management Tools Risk Management Tools Used % of Respondents 90% 80% 70% 60% 50% 40% 30% 84% 71% 59% 54% 49% 47% 47% Source: 2014 mrdc Industry Study 43% 25% 20% 10% 16% 14% 13% 9% 0% Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 34

Funds Availability 60% 50% Funds Availability of Deposited Items 51% Source: 2014 mrdc Industry Study % of Respondents 40% 30% 20% 19% 16% 17% 10% 9% 9% 0% Immediate Same day if deposited is made before specified time Next-Day 2-Day Availability 3-days+ Availability Other Availability Almost 80% offer same, or next-day availability, and many offer multiple options. Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 35

Multi-Faceted Risk Management Risk Control / Risk Type Operational Error Check Kiting Duplicate Error Duplicate Fraud Value Fraud Volume Fraud FIs should have at least 150 Total Points per risk type, 200+ for Fraud Risk Types. Return Items IQU / IQU / CAR / LAR 75-50 - - - - Value / Volume Thresholds 25 25 25 50 50 50 25 RDC System DD 25-75 50 25 - - Cross-Channel DD 25-25 25 - - 25 Industry DD - - 50 50 - - 25 Balances 25 50 50 50 75 25 50 Holds - 75 75 75 75 25 50 Availability Schedules 25 75 50 50 50 25 25 Monitoring & Actionability 25 50 50 75 25 50 50 Verification & Guarantee - - - 50 50 50 50 Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 36

Recourse is Essential In the worst-case scenario, how can the FI retrieve funds? Availability Schedules Key: Provide availability to account for potential returns based upon Client Risk Profile. Required Balances Key: Can enable FI to actually earn more revenues while also providing a reserve against returns. Adds to Deposits, Capital, Liquidity, Loan Capabilities. Credit Relationship? Interesting concept, but does not enable FI to have access to funds. Customer already owes FI $$$. Verification & Guarantee Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 37

Client RDC Risk Management Top Ten 1. Control the Original, leverage the system, establish a process. 2. Understand the Cons 3. Utilize Duplicate Detection 4. Setup Automated Reports & Alerts 5. Separation of Duties 6. Have a Backup Plan 7. Restrictively Endorse All Items 8. Deposit Items QUICKLY! 9. Safekeep / Destroy all items (& Reconcile) 10.Implement Positive Pay Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 38

Optimal Risk Management 10 Steps to Minimize RDC Risk: 1. Client Selection / KYC Leverage KYC Information to setup parameters. 2. User / Location / Account Parameters - Identify & Prevent Fraud & Mistakes, manage exceptions 3. Education & Training - Most customers will want to protect themselves. 4. Functionality Restrictions Minimize Fraud Opportunities. 5. Availability Schedules & Holds - Don t make short-term loans, allow for returns, effective way to deal with questionable items. 6. Positive / Negative Databases Think Duplicates, Closed Accounts, etc. 7. Integration & Reporting Monitor client deposit trends, integrate into bankwide risk management systems (AML / BSA for example). 8. Real-time Systems Manage systems, Mitigate Risk before / as it happens 9. Balances Competitive advantage, strengthens balance sheet, maximizes revenues and minimizes losses. 10. Payment Verification & Guarantee The next gen of Risk Management.. Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 39

The Road Ahead Mass Adoption of Mobile RDC FIs, Third-Parties & Consumers Increasing Role of 3 rd -Party Solutions Paypal, Intuit, ISOs, ISVs, AFS (Alternative Financial Services), etc. RDC as a Payments Platform Checks, Cards, ACH, Cash Data: The final frontier? Questions: Does a Check even need to be paper?? Will a centralized database for duplicates evolve? Will checks regain popularity? Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 40

Join the discussion As the RDC Industry continues to evolve, so too must the approach to RDC Risk Management. Visit RemoteDepositCapture.com for the latest & greatest on this topic, and everything RDC. We ve even setup a dedicated discussion forum to help the industry continue the conversation. Click Here to join the discussion. Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 41

A Unique Perspective RemoteDepositCapture.com is an independent information & services resource for the Payments Industry. We are NOT a reseller, solution provider, etc. We ARE experts in, and an open resource for the industry. We work with the vast majority of leading solution providers, FIs, processors. Thousands of FIs, corporations, businesses and consumers visit the site each month. We are supported by many industry-leading organizations. We were involved in the formulation of the FFIEC RDC Risk Management guidance and training of over 1,200 auditors. Services News & Research The RDC Solution Finder Solution Provider Directories RDC Overviews White Paper Central FREE Webinars The RDC Summit and much, much more. Contact: John.Leekley@RemoteDepositCapture.com Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 42

RDC Risk Process Component RDC Process Business Process Risk Register for each RDC Process & Account Level Sources of Risk Risk Assessment Account Risks Contract Compliance Anomaly Detection Internal Audits Incidents Reporting Customers Complaints Control Objective mapped to Business Objectives Risk Can Be Mitigated No Yes Attributes to be Captured Key Risk Indicators (KRI s) with probability and impact Mitigation Plans Risk tolerance levels Mitigating Controls Approval Process for accepting risks or thresholds Reporting and Monitoring Exception Reporting Deviation from Approved Risks, Thresholds Control Testing, Audits, Anomaly detection, Self-Assessment Source: Wipro (Modified) Copyright 2015, Remote Deposit Capture, LLC RDC Risk Management in 2015 43