Welcome back to the latest installment of our "Scam Likely" series, where we examine recent scams, frauds, and other financial crimes. It has been some time since our last installment, but just when you thought you were out, the risk of fraud loss pulls you back in.
This installment of our series was prompted by a recent Summer Threat Spotlight Alert issued by the FDIC. In that Alert, the FDIC warns banks to take a close look at their fraud insurance policies. The insurance industry has been busy updating their policies to narrow the instances of what is, and what is not, covered in the case of a fraud loss. If a bank unwittingly fails to satisfy its policy’s requirements, it risks losing coverage.
The Set Up
It is early Wednesday morning. Your bank customer cannot remember their online banking password, so they submit a reset request. Your online banking system applies its multi-factor authentication procedure and the customer successfully changes their password. A few days later, the customer initiates a $100,000 wire transfer through online banking – the size of this wire transfer is typical for the customer. As always, your trusty team applies its normal wire transfer security procedures (e.g., a callback, MFA, dual control, etc.) and processes the payment.
On Monday morning, you get a phone call from a very upset customer that last week’s wire transfer was unauthorized and fraudulent. As you likely guessed, the customer was the victim of a business email compromise or account takeover, and the wired funds are long gone. Your customer is now looking to the bank to cover the loss and recredit their account. You think to yourself: “Even if this is on us, we have insurance for this… right?”
The Actors
We have seen this scam before. The actors involve the fraudster, your customer, and the bank. However, there is one crucial actor that played no role in the transaction: your insurer. If the bank makes a claim on its fraud policy, it may run into a surprise.
The Grift
Blanket bond policies typically require very specific transaction-verification and authentication procedures a bank must follow. These procedures are often very strict and require more than the bank’s own policies and procedures can deliver. For example, a bank may authenticate a wire transfer with a username, password, and callback, while its fraud policy requires a hard token, soft token, dual control, or other security procedure. Even if your bank followed its established security procedures, you may find that your policy required more.
Importantly, a system limitation is not necessarily an excuse. For example, if a service provider’s platform cannot support the security procedures required under a policy, the FDIC warns that the failure to satisfy the terms of the policy may also compromise a fraud claim.
The FDIC has identified several other common provisions that banks may be missing, such as:
- Waiting Periods. A minimum waiting period before the bank relies on an updated customer telephone number or other contact information for callback verification (or other authentication method).
- Clear Verification Methods. Clear and predetermined methods for verifying the identity of a customer and/or a funds-transfer request (and confirming those predetermined methods are expressly agreed to with the customer).
- In-Branch Updates. Requiring a customer to physically visit a branch to update contact information (and to present government-issued identification).
- Information Comparison. Verifying any updates to a customer’s contact information against the information the customer originally provided at account opening.
- Prior Approval of Multi-Factor Authentication. Obtaining a policy underwriter’s approval before implementing any multi-factor authentication methods.
- Record Creation and Retention. Maintaining records of calls and other communications requesting funds transfers and properly preserving those records.
The Pain
After a fraud event, the bank submits its insurance claim. The insurer then begins examining whether the bank satisfied every applicable condition in the policy. For example, did the bank wait long enough before relying on a recently changed telephone number? Did it use the verification method required under the insurance policy? Was the authentication method approved in advance? Did it preserve adequate records of the transfer request?
As you can see, although a bank may have followed its own security procedures faithfully and acted reasonably under the circumstances, it may not be enough. Where those security procedures diverge from the fraud policy’s requirements, the insurer may deny or limit coverage, leaving the bank on the hook to absorb a loss it believed was insured.
The Reality
Banks should carefully review the language in their insurance policies against their internal policies, procedures, and practices. In conjunction with that review, a bank should also confirm that its customer agreements and disclosures align with those policies, too – for instance, the bank should update any treasury management agreements, online banking agreements, wire / ACH transfer agreements, and similar agreements to align with policy requirements.
At a minimum, this review should focus on authentication methods, callback and verification procedures, contact-information changes, record-retention practices, and any advance-approval requirements imposed by the bank’s policy. If there are any gaps, they should be addressed immediately. And, if the terms of a policy require controls that a bank’s system simply cannot support, the bank should discuss and address those limitations with its underwriter and the service provider before moving forward without a safety net.
Do not sleep on the requirements of your insurance policy. The last thing a bank needs after a fraud loss is a second surprise from its own insurer.
← Previous: Scam Likely: New Phone, Who's This?
This article is provided for informational purposes only—it does not constitute legal advice and does not create an attorney-client relationship between the firm and the reader. Readers should consult legal counsel before taking action relating to the subject matter of this article.