Friday, August 20, 2010

Robbing Peter to Pay Paul? NACHA vs Reg E

Randy Davis, VP (egisticsinc.com)

Looking for winners and losers
On September 1, 2009 NACHA issued a Request for Comment on a proposal to amend the NACHA operating rules regarding the time frame for ACH adjustment entries. In brief the proposed rule change would extend the period during which a Receiving Depository Financial Institution (RDFI) may transmit an adjustment entry to its ACH Operator from 60 calendar days to 90. The rationale of the extension is to give RDFIs enough time to submit adjustment entries for "virtually all" credits owed to consumers under Reg E. The goal is to narrow/close the time gap between NACHA re-credit obligations and Reg E re-credit obligations. The rule change is proposed (though it has yet to be balloted) for implementation in March 2011.

Currently Reg E theoretically could allow a credit to the consumer as many as 38 days past what the NACHA rules allow. Within the Reg E 90-day period, the RDFI is obligated to credit the consumer, but could be left holding the bag if the NACHA 60-day period has expired, resulting in expiration of the automated adjustment period with the ODFI. After that, the RDFI must pursue a warranty claim against the ODFI manually and outside the ACH network. Possible outcomes are as follows: A) Both the RDFI and ODFI incur costs to settle the RDFI's claim against the ODFI's warrant; B) The RDFI could request proof of authorization, which results in costs to the ODFI and Originator; C) The RDFI could decide not to pursue the claim and take the loss.

The Hoped-for Benefits
NACHA believes the rule change will 1) avoid RDFI losses, 2) avoid manual claim costs, and 3) reduce or avoid write-offs.

The Dreaded Costs
ODFIs will have to ensure that their systems can accept adjustments up to 90 days beyond the settlement date of the original entry.

Originators will be subject to more automated adjustments.

Everyone -- RDFIs, ODFIs, Originators and ACH Operators -- may need to store ACH records for "additional periods of time."

Who Wins and Loses?
Possible Loser: The ODFI loses because it will receive more automated claims that off-set any cost reductions.

Possible Winner: The RDFI wins because it reduces costs and write-offs.

Possible Winner: Originators win because it reduces the requirement to provide proofs of authorization.

Possible Winner: The ACH network wins as productivity and efficiency is improved.

Chime In
Do you agree with my assessment of winners and losers? Use the Comment box to let me know what I've missed, and to contribute to the discussion.

Take our poll at the bottom of this page to vote on who you think is the winner from the rule change!

Thursday, July 29, 2010

Beyond SAS 70

By R. Edwin Pearce (www.epearce@egisticsinc.com)

A new study from Gartner confirms something that eGistics (www.egisticsinc.com) has known for some time: there's a lot more to effective security, privacy and continuity than compliance with Statement on Auditing Standards (SAS) 70.

"SAS 70 is basically an expensive auditing process to support compliance with financial reporting rules like the Sarbanes-Oxley Act (SOX)," says French Caldwell, research vice president at Gartner. "Chief information security officers (CISOs), compliance and risk managers, vendor managers, procurement professionals, and others involved in the purchase or sale of IT services and software need to recognize that SAS 70 is not a security, continuity or privacy compliance standard."

Published by the American Institute of Certified Public Accountants (AICPA), SAS 70 provides a service provider's auditor with guidance on how it should report on process-related risks relevant to financial statements and transaction processing. Intended for use by the customer's auditor, the result of a SAS 70 is either a Type I attestation that the processes as documented are sufficient to meet specific control objectives, or a Type II attestation, which additionally includes an on-site evaluation to determine whether the processes and controls actually function as anticipated.

Gartner believes a SAS 70 Type II evaluation does provide a very high degree of assurance that the examined controls are effective. The performance of controls is evaluated over a period of time; it is not just a snapshot of control effectiveness. However, customers should never assume that the provider has implemented all the appropriate controls, Gartner says.

"To ensure that vendor controls are effective for security, privacy compliance and vendor risk management, SAS 70 ... and other national audit standard equivalents should be supplemented with self-assessments and agreed-upon audit procedures," Caldwell explains.

Interested in learning more? E-mail me at epearce@egisticsinc.com.

Tuesday, July 20, 2010

Cloudy with a chance of Microsoft


Microsoft CEO Steve Ballmer, known for his eyebrow raising antics at company-wide employee meetings, is raising eyebrows again with his provocative and far-reaching statements about Microsoft and the cloud. On July 12 Ballmer told 9,500 attendees at the annual partners’ conference that “if you don’t want to move to the cloud, we’re not your folks.” The cloud, he says, is “inevitable.” Whew.

Actually, even in the summer of 2008 Microsoft recognized that on-line delivery of critical business applications and services was, in fact, “a sea change” in the way businesses and corporations want to be served. On-line delivery was then and is now recognized as part of a “services wave” that is causing some to criticize the traditional software-based delivery model and on-premise execution of business applications as growing “antiquated.”

Maybe yes, maybe no.

Ballmer acknowledges what corporations have been concerned about since the cloud began to form: security and compliance. He implies that companies that get this right are “way ahead” in providing a viable offering to the market.

This brings up a good point in the use and selection of on-line services companies: Choosing one that provides an on-line service is one thing; choosing one that has invested the time, cost, expertise and infrastructure required to provide world-class security, and that supports a variety of compliance mandates, is quite another.

It is our experience that large, security- and compliance-conscious institutions are taking advantage of the growing maturity of cloud services, especially in the area of the management of documents, transactional data, payment images, and reports. As institutions become more comfortable with, and confident in, selective cloud providers, expectations will increase regarding the use of such information for fraud detection and prevention, data mining, analysis, legal discovery, research and customer service.

Is your company catching the wave, dipping its toes in the water, or staying high and dry? 

Tuesday, July 13, 2010

Trends in ACH Dispute Management

Trends in ACH Dispute Management
Thursday, August 12 at 1 p.m. eastern

As ACH volumes have grown, so too have the number of ACH transaction disputes that processors must manage. Expensive to handle, these disputes are subject to a complex mix of rules and regulations, and can lead to hefty charge-offs if improperly managed. Just how big a problem are ACH disputes? This webinar will share the results of an exclusive survey of ACH processors on trends in ACH dispute management, including volumes, costs, levels of automation, future plans and more. Attendees will be able to benchmark their operations, gain actionable insights from our panelists, and learn what some processors are doing to automate their ACH dispute processing.

To register, click this link https://www1.gotomeeting.com/register/589842392 or e-mail Dave Nitchman of IAPP-TAWPI at dnitchman@tawpi.org.

Panelists:
Rossana Salaris, principal, Radix Consulting
Amer Khan, senior vice president, product and sales support, eGistics

Moderator:
Mark Brousseau, facilitator, IAPP-TAWPI Payments and Receivables Council

Monday, July 12, 2010

Economic risks of data overload

By Ed Pearce (epearce@egisticsinc.com) of eGistics (http://www.egisticsinc.com/)

When data pours in by the millisecond and the mountain of information builds continuously, professionals inevitably cut corners and go with their 'gut' when making decisions that can impact financial markets, medical treatments or any number of time sensitive matters, according to a new study from Thomson Reuters. The study indicates that when faced with unsorted, unverified "raw" data, 60 percent of decision-makers will make "intuitive" decisions that can lead to poor outcomes.

Many government regulators have flagged increased financial risk-taking, which can be traced in some degree to imperfectly managed data, as a contributor to the recent financial crisis. Moreover, the world is awash with data -- roughly 800 exabytes -- and the velocity of information is increasing, Thomson Reuters says.

The challenge is that the staffing and investment needed to ensure that information and information channels are trusted, reliable and useful is not keeping pace. In fact, it is estimated that the information universe will increase by a factor of 44; the number of managed files by a factor of 67; storage by a factor of 30 but staffing and investment in careful management by a factor of 1.4.

"The solution to data overload is to provide decision makers with what Thomson Reuters calls Intelligent Information: better organized and structured information, rapidly conveyed to the users preferred device," says David Craig, executive vice president and chief strategy officer.

Fortunately, as the Thomson Reuters study notes, the same technological revolution that has resulted in the explosion of information also opens the way to new and improved tools for providing intelligent information: better organized and structured information, rapidly conveyed to the user's preferred device.

"We must use the benefits of the information technology revolution to minimize its risks. This is a joint task that the private sector and governments must closely focus on if we are to avoid systemic crises, in the future, whether we speak of finance, healthcare delivery, international security and a myriad of other areas," comments Craig.

How is your organization managing information overload?

Saturday, July 10, 2010

Same-day ACH settlement highlights need for better dispute management tools

By Ed Pearce (epearce@egisticsinc.com)

Last week's announcement by the Federal Reserve Board of posting rules for a new same-day automated clearing house (ACH) service brought the topic front and center. Everyone from industry analysts and bloggers to trade publications and associations have expounded the pros and cons of same-day settlement. But virtually unmentioned in the all the hubbub is the potential for more ACH disputes as a result of accelerated settlement -- a scenario most banks are ill-prepared to manage.

Starting next month, the Federal Reserve Banks will be offering a same-day settlement service for certain ACH debit payments through its FedACH service. FedACH customers may opt-in to the service by completing a participation agreement. The service will be limited to transactions arising from consumer checks converted to ACH and consumer debit transfers initiated over the Internet and phone. Same-day forward debit transfers will post to a financial institution's Federal Reserve account at 5 p.m. eastern time, while same-day return debit transfers will post at 5:30 p.m.

As a result of the faster settlement, banks undoubtedly will see more consumers coming into their branches complaining of unauthorized transactions. The limitations of traditional in-house ACH systems and the strict time constraints and complex processing requirements imposed by NACHA rules and Regulation E already have led to sharp increases in operations expenses and higher charge-offs associated with ACH disputes. A new influx of consumer disputes will require financial institutions to implement a more centralized, more streamlined approach to dispute management.

Several features will be critical:
  • Real-time distributed data access to any authorized user, anywhere
  • Intuitive search capabilities
  • The ability to annotate comments to disputed transactions
  • The ability to export data
  • Expanded search capabilities
  • Filtering capabilities to block and restrict access to certain transactions
  • Unlimited data storage
It may be some time before same-day ACH settlement achieves critical mass. But the next generation of consumers will demand it. This means that banks must begin adapting their ACH infrastructure today or risk even higher operations costs, as well as falling behind the competition. And this includes deploying sophisticated solutions to manage the inevitable spike in ACH disputes.

Friday, July 9, 2010

No pennies from heaven: controlling technology costs

GEORGE BAILEY: You don’t happen to have eight thousand bucks on you?
CLARENCE: Oh, no, no. We don’t use money in heaven.
GEORGE BAILEY: Oh, that’s right. I keep forgetting.
Comes in pretty handy down here, bub.
IT’S A WONDERFUL LIFE


By Randy Davis (rdavis@egisticsinc.com)

While lost on Clarence the angel, the need for capital is obvious “down here.” It you are not raising capital, you are preserving it. Whatever is preserved can help manage cash flow or can be used for other purposes. Cost control is one means of preserving capital.

To my way of thinking “cost control” requires at least the following three things:
  • Keeping total cost of ownership as low as possible (including maintenance and upgrades)
  • Paying for something only once if possible
  • Keeping costs predictable yet variable based on current factors
It is difficult if not impossible to achieve 2 and 3 above with traditional software/hardware or do-it-yourself cost models. Hardware and software require on-going maintenance, upgrade and replacement costs. Although maintenance costs may be predictable, they are in fact a perpetual payment protecting the use of hardware and software. Upgrades and replacement costs are not entirely predictable partly because there are simply too many external factors (end of life, advances in technology, merger/acquisition or divestiture, etc.) controlling the timing of their expenditure. As things stand now, technology approaches obsolescence every three years.

(If you don't think this is a hot -- even emotional -- issue, see my blog below, "Putting the kibosh on the soaring software maintenance and upgrade costs.")

As an example of cost requirements, here are the findings of a Global Concepts study on the cost breakdown of an in-house digital archive:
  • Explicit base costs (such as servers, communications, disk storage, long-term storage, software, maintenance) are only half the total cost 
  • Staffing adds another 40% on top of the base costs 
  • Replication (disaster recovery/business continuity) requires an additional 36% above base costs 
  • Implementation and Development adds another 24% to base costs
Once you have added all your costs together for a secure and reliable in-house archive, the total cost percentages break down as follows:


Rather than a solution that requires fixed and sunk costs, what would be helpful is a solution with an entirely predictable “pay once” fee structure. A “pay once” fee structure should be the simplest, most predictable and controllable fee structure you can get from any of your vendors – partly because of what is avoided, namely on-going costs for users, hardware, software, and maintenance.

The critical difference between using such a fee-based solution and any other cost structure, is that while all other cost structures require on-going, perpetual costs to keep things going, “pay once” does not. You avoid paying – every day for the life of the solution – for the privilege of using that solution. More importantly, you don't pay for excess capacity that either is waiting to accommodate future requirements or becomes unused because of a contraction in business.

I'm certainly not naive enough to think that a "pay once" fee structure is applicable to all, or even most, hardware, software or services. However, it appears that more and more businesses are demanding such a choice.

What is your experience with fee-based solutions?