Using biometrics to prevent financial crime

Access & Identity Management Handbook 2018 Access Control & Identity Management, Integrated Solutions

Biometrics is about more than the fingerprint or retina terminal itself, it’s about storing data in forensically-signed databases, that is admissible in a court of law.

Wayne Olsen, Datacentrix security business unit manager.
Wayne Olsen, Datacentrix security business unit manager.

There’s no doubt that fraud in the workplace is a broad-ranging topic, but one of the most egregious kinds is surely financial fraud. It’s this type of fraud that directly hits the company’s bottom line. So let’s look at mitigating those cybercrime efforts that are directed at local organisations with financial crime as their primary strategy.

What is financially-motivated cybercrime?

Electronic fraud is really just the latest evolution of traditional crime. Many professional criminal syndicates have shifted their focus away from the old-world tactics of holding up banks, running black-market importing businesses or trading drugs, for instance. They’ve chosen an often far softer target: capitalising on the lack of security and stringent processes within many companies.

In recent years we’ve seen the art of social engineering become ever-more sophisticated, as fraudsters carefully gather data-sets from ‘helpful’ staff, building up this data to ultimately impersonate different parties. Armed with enough information, they may impersonate a supplier requesting that their bank details are changed; or they impersonate the CFO in requesting that payment orders are executed by his staff. Many have defined this kind of highly-targeted identity theft as ‘whaling’ – an evolved form of phishing.

The basics brilliantly

Many firms are investing tens of millions of rands in sophisticated security tools that deal with technical threats coming from all directions, but fail to effectively prevent financial losses because the basic processes are just not designed effectively.

Whatever the size of one’s company, in the finance department it is essential to segregate financial duties between different people. We often see firms stumbling due to a lack of basic rigour (such as mandating that a purchase order be checked with business unit managers before invoices are released for payment, or confirming that an employee has been fully off-boarded by implementing checks and balances across Payroll, HR, IT and other areas).

The solution

We’re generally familiar with the use of biometrics for basic, physical access and ‘time and materials’ record-keeping, but the opportunities for biometrics extend far further than this:

Each transaction can be biometrically-signed, so there is absolutely no doubt about who authorised a particular payment. With advanced biometrics solutions, full audit logs are created, tracing the journey of a particular transaction through its various stages of approval.

These audit logs can be introduced into a court of law if necessary, as they legally bind the actor (for example the financial administrator) to the transaction. This allows organisations to reach a level of certainty and accountability that was previously not possible with less-secure, password-based systems.

Irrefutable evidence

By positively connecting a physical person to each specific transaction, firms can eliminate the problems of passwords that are divulged or shared, or smartcards, tokens and one-time PIN numbers that can also be passed between individuals.

A biometrics approach can be used consistently across various enterprise applications – to deliver legally-valid transaction evidence, and essentially to act as an impartial witness to sensitive business transactions. By introducing this technology alongside policies (such as payment value thresholds for different members of staff), organisations can not only ensure that any fraud losses are traced back to particular individuals, but they can prevent fraud from happening in the first place.

For more information on Datacentrix’ fraud management offerings, please visit http://www.datacentrix.co.za/electronic-fraud-management.html





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Future trends for electronic safety and security in mining
Fang Fences & Guards Mining (Industry) Integrated Solutions AI & Data Analytics
The mining industry is ever evolving, driven by technological advancements and the growing need for enhanced safety and security measures, with significant innovation seen in turnkey electronic security for mining operations.

Read more...
Unlocking enhanced security for mining
Mining (Industry) Integrated Solutions
In the dynamic landscape of African mining, security remains of paramount concern as threats evolve and challenges persist, and mining companies seek innovative solutions to safeguard their operations, assets, and personnel.

Read more...
A constant armed struggle
Technews Publishing XtraVision Editor's Choice Integrated Solutions Mining (Industry) IoT & Automation
SMART Security Solutions asked a few people involved in servicing mines to join us for a virtual round table and give us their insights into mine security today. A podcast of the discussion will be released shortly-stay tuned.

Read more...
Defending against SIM swap fraud
Access Control & Identity Management
Mobile networks must not be complacent about SIM swap fraud, and they need to prioritise the protection of customers, according to Gur Geva, Founder and CEO of iiDENTIFii.

Read more...
Access Selection Guide 2024
Access Control & Identity Management
The Access Selection Guide 2024 includes a range of devices geared specifically for the access control and identity management market.

Read more...
Biometrics Selection Guide 2024
Access Control & Identity Management
The Biometrics Selection Guide 2024 incorporates a number of hardware and software biometric identification systems aimed at the access and identity management market of today.

Read more...
Smart intercoms for Sky House Projects
Nology Access Control & Identity Management Residential Estate (Industry)
DNAKE’s easy and smart intercom solution has everything in place for modern residential buildings. Hence, the developer selected DNAKE video intercoms to round out upmarket apartment complexes, supported by the mobile app.

Read more...
Authentic identity
HID Global Access Control & Identity Management
As the world has become global and digital, traditional means for confirming authentic identity, and understanding what is real and what is fake have become impractical.

Read more...
Research labs secured with STid Mobile ID
Access Control & Identity Management
When NTT opened its research centre in Silicon Valley, it was looking for a high-security expert capable of protecting the company’s sensitive data. STid readers and mobile ID solutions formed part of the solution.

Read more...
Is voice biometrics in banking secure enough?
Access Control & Identity Management AI & Data Analytics
As incidents of banking fraud grow exponentially and become increasingly sophisticated, it is time to question whether voice banking is a safe option for consumers.

Read more...