Business
Conflicting with compliance: How the finance sector is struggling to implement GenAI
By James Sherlow, Systems Engineering Director, EMEA, for Cequence Security
GenerativeAI has multiple applications in the finance sector from product development to customer relations to marketing and sales. In fact, McKinsey estimates that GenAI has the potential to improve operating profits in the finance sector by between 9-15% and in the banking sector, productivity gains could be between 3-5% of annual revenues. It suggests AI tools could be used to boost customer liaison with AI integrated through APIs to give real-time recommendations either autonomously or via CSRs, to inform decision making and expedite day-to-day tasks for employees, and to decrease risk by monitoring for fraud or elevated instances of risk.
However, McKinsey also warns of inhibitors to adoption in the sector. These include the level of regulation applicable to different processes, which is fairly low with respect to customer relations but high for credit risk scoring, for example, and the data used, some of is in the public domain but some of which comprises personally identifiable information (PII) which is highly sensitive. If these issues can be overcome, the analyst estimates GenAI could more than double the application of expertise to decision making, planning and creative tasks from 25% without to 56%.
Hamstrung by regulations
Clearly the business use cases are there but unlike other sectors, finance is currently being hamstrung by regulations that have yet to catch up with the AI revolution. Unlike in the EU which approved the AI Act in March, the UK has no plans to regulate the technology. Instead, it intends to promote guidelines. The UK Financial Authorities comprising the Bank of England, PRA, and FCA have been canvassing the market on what these should look like since October 2022, publishing the results (FS2/23 – AI and Machine Learning) a year later which showed a strong demand for harmonisation with the likes of the AI Act as well as NIST’s AI Risk Management Framework.
Right now, this means financial providers find themselves in regulatory limbo. If we look at cyber security, for instance, firms are being presented with GenAI-enabled solutions that can assist them with incident detection and response but they’re not able to utilise that functionality because it contravenes compliance requirements. Decision-making processes are a key example as these must be made by a human, tracked and audited and, while the decision-making capabilities of GenAI may be on a par, accountability in remains a grey area. Consequently, many firms are erring on the side of caution and are choosing to deactivate AI functionality within their security solutions.
In fact, a recent EY report found one in five financial services leaders did not think their organisation was well-positioned to take advantage of the potential benefits. Much will depend on how easily the technology can be integrated into existing frameworks, although the GenAI and the Banking on AI: Financial Services Harnesses Generative AI for Security and Service report cautions this may take three to five years. That’s a long time in the world of GenAI, which has already come a long way since it burst on to the market 18 months ago.
Malicious AI
The danger is that while the sector drags its heels, threat actors will show no such qualms and will be quick to capitalise on the technology to launch attacks. FS2/23 makes the point that GenAI could see an increase in money laundering and fraud through the use of deep fakes, for instance, and sophisticated phishing campaigns. We’re still in the learning phase but as the months tick by the expectation is that we can expect to see high-volume self-learning attacks by the end of the year. These will be on an unprecedented scale because GenAI will lower the technological barrier to entry, enabling new threat actors to enter the fray.
Simply blocking attacks will no longer be a sufficient form of defence because GenAI will quickly regroup or pivot the attack automatically without the need to employ additional resource. If we look at how APIs, which are intrinsic to customer services and open banking for instance, are currently protected, the emphasis has been on detection and blocking but going forward we can expect deceptive response to play a far greater role. This frustrates and exhausts the resources of the attacker, making the attacks cost-prohibitive to sustain.
So how should the sector look to embrace AI given the current state of regulatory flux? As with any digital transformation project, there needs to be oversight of how AI will be used within the business, with a working group tasked to develop an AI framework. In addition to NIST, there are a number of security standards that can help here such as ISO 22989, ISO 23053, ISO 23984 and ISO 42001 and the oversight framework set out in DORA (Digital Operational Resilience Act) for third party providers. The framework should encompass the tools the firm has with AI functionality, their possible application in terms of use cases, and the risks associated with these, as well as how it will mitigate any areas of high risk.
Taking a proactive approach makes far more sense than suspending the use of AI which effectively places firms at the mercy of adversaries who will be quick to take advantage of the technology. These are tumultuous times and we can certainly expect AI to rewrite the rulebook when it comes to attack and defence. But firms must get to grips with how they can integrate the technology rather than electing to switch it off and continue as usual.
You may like
Business
Overcoming intricacies of premium processing in the insurance industry
Source: Finance Derivative
By Piers Williams, Global Insurance Manager at AutoRek
Complexity is an unavoidable reality for the intricate world of insurance. For program administrators, including brokers, managing general agents (MGAs) and managing general underwriters (MGUs), accurate management of insurance premium payments and complex workflows like bulk payments and diverse data sources is essential – there cannot be room for error. Unfortunately, poorly executed and complex processes can lead to costly mistakes. This is especially true for essential financial control processes that directly impact the performance of insurance businesses such as premium payment processes – also commonly known in corporate industries as account receivable and payable processes.
In particular, the traditional, manual management of insurance premium payments is what can often lead to unresolved outstanding debt and large balances of unallocated cash. When you combine this with the 30% growth in delegated/program businesses (over 30%+ in the last 3 years), using Excel sheets and the ever-increasing policy volumes, the approach becomes unsustainable and inefficient.
This article will outline the transformative benefits automation offers and the key actionable strategies that will enable program administrators to optimise the management of insurance premium payments for greater efficiency and effectiveness in their financial operations.
Embracing automation: the future of insurance
The future of insurance lies in automation – this is where premium payment processing comes in. Automation enables businesses not to erode margins through write-offs but accelerate cash flow and protect revenue. The primary goal is to accelerate premium reconciliation and allocation by implementing an automated straight-through process, minimising the need for human intervention to ensure that minutes – not hours – are spent on the reconciliation process.
By leveraging automated systems and advanced data integration, premium payment processing has the potential to offer a more streamlined, accurate and effective insurance ecosystem. Automation minimises the likelihood of human error and delays in transaction times; ensuring that precision is at the forefront of the financial processes. This shift towards automation addresses one of the key challenges faced by the insurance industry – eliminating inefficiencies which can lead to costly mistakes and unnecessary delays.
Producing scalability in a competitive market
Program administrators are confronted with a multitude of pain points in their day-to-day operations. Given that program administrators handle a significant amount of insurance policies across multiple binders/programs in the market, considerable admin effort is required to process a vast number of internal and external data sources as well as payments and policy data. As a result, program administrators risk losing valuable time and resources – giving them less time for value-added tasks, like resolving breaks, addressing downstream issues, and creating better partnerships with insurance partners.
The impact of such operational inefficiencies can impact not only accounts receivable, collections and credit control processes but also business profitability, binder/program performance, competitiveness and reputation to name a few. Without the adoption of more advanced technologies like automation, program administrators are increasingly at threat of not being able to produce scalability in a competitive market.
Whilst automation offers huge efficiency upside for businesses there are also many benefits delivered by simply having a single premium data control platform. One of the most notable challenges with premium payment operations is the often-large numbers of internal and external data sources that must be managed and processed. This data needs to be continuously processed to ensure reporting is up to date and management has a comprehensive view of outstanding premiums, allocated premium and cash positions at any point in time. The management of this data, if not performed within a platform, presents a huge risk from a control perspective, as often premium payments will not be allocated for 30, 60 or 90 days, therefore needing a solution to keep track of all data automatically to ensure efficiency and control to ensure.
Identifying and addressing inefficient processes
Investing in modern technology like automation is often the first step in streamlining operations and eliminating inefficient processes. The goal is to encourage program administrators to focus less on manual administrative tasks that are time-consuming and instead, focus on key business decision making to improve financial gain – automating manual processes does exactly that.
Likewise, the insurance industry is constantly evolving so the adoption of premium payment processing will be crucial in remaining competitive in a shifting market dynamic. With this in mind, legacy systems, once the backbone of insurance operations, must go. These systems are outdated and unable to meet the demands of a data-driven, regulated market, leading businesses to embrace digital transformation and no longer depend on inefficient processes.
Business
Who’s Scared of Embedded Payments?
Source: Finance Derivative
Johannes Kolbeinsson, CEO at PAYSTRAX
Embedded payments have been swiftly integrated into the e-commerce ecosystem, showcasing their transformative potential in reshaping how we make transactions. There is a bright future for embedded payments, but we must emphasise the significant untapped potential within the space as it currently stands, as the user experience still isn’t quite seamless, and third-party payment processors still present a fraud risk to companies.
A Rapidly Expanding Market
The growth of embedded payments is undeniable. Driven by the rise of digital wallets and one-click checkout systems, the global market for embedded finance as a whole is projected to grow from $92 billion to $228 billion between 2024 and 2028. Recent shifts in consumer behaviour, especially toward frictionless digital experiences, have been accelerating the adoption of these solutions across sectors. Embedded payments offer that seamless one system approach, not only quickly processing payments on app, but building a one app relationship with consumers that develops brand loyalty.
This trend directly mirrors the business strategies of the major players in the tech world. Companies such as Apple, with its mobile wallet and credit card ventures, and Shopify, combining e-commerce with embedded payments, have demonstrated that blending payments directly into platforms can drive user engagement and boost conversions. The logic is plain and simple: by keeping consumers within the app, businesses streamline the purchasing process, increasing the likelihood of finalising transactions, and building brand and customer loyalty.
The Embedded Payments Boom
Embedded payments have become the latest hot topic in fintech. In fact, just a few years ago, in 2020, embedded finance payments were generating around $16 billion in revenue. Looking ahead to next year, forecasts suggest that number will skyrocket to over $140 billion. The success of platforms like Uber with one-click payments and the buy-now-pay-later (BNPL) models from companies like Klarna are clear indicators of this shift. Consumers increasingly seek ease and convenience, and embedded payments are meeting those demands head-on.
However, for all the excitement, embedded payments still face challenges in adoption. Fraud prevention, authentication, and user experience remain key barriers that need to be addressed on an industry wide level to truly deliver the seamless, instant payments these systems promise consumers.
Addressing the Friction
While the promise of embedded payments is enticing, friction remains. One of the most critical challenges for businesses adopting embedded payments is ensuring robust risk management. Creating an online experience that feels as secure as an in-store transaction should be a top priority, especially as financial fraud becomes more prevalent.
Currently, many companies are jumping into embedded payments without fully understanding the complexities involved. The lack of in-house expertise in building the necessary infrastructure across digital services, transaction processing, and enablement layers can lead to implementation issues and security vulnerabilities. Businesses need to conduct proper due diligence to avoid potential pitfalls, as hasty implementations can compromise both functionality and security.
User experience is another key factor in determining the success of embedded payments. Historically, we’ve seen how PayPal revolutionised online payments with its email-and-password system, setting a new standard. Embedded payments, while advanced, are still evolving to achieve a truly frictionless experience. Authentication processes frequently occur outside of the platform or app, and the range of payment options can be limited. To fully realise the potential of embedded payments, businesses must balance security, usability, and convenience.
Trust and Security Concerns
Security and trust are paramount when it comes to anything finance related, and these are areas where embedded payments must improve to gain widespread consumer adoption. With growing concerns about data privacy and the rise in online fraud (40% of all reported crime in the UK last year were fraud), it’s clear that consumers need reassurance before embracing embedded payments.
While embedded payment systems offer unparalleled convenience, their inherent vulnerabilities could make them a prime target for cybercriminals. The lack of standardisation and regulation in the sector, coupled with a general shortage of expertise that comes with a new industry, poses significant risks for users. Nevertheless, history suggests that consumers are willing to trust new technologies over time. Just a decade ago, saving card details online was met with hesitation; today, it’s commonplace. Similarly, as security concerns are addressed, embedded payments will likely gain traction as consumer trust grows.
The Path Ahead for Embedded Payments
Despite the array of payment methods available today, the potential for embedded payments to dominate the future of finance is undeniable. Their speed, ease, and ability to facilitate in-app purchases with a simple click make them an attractive option for both consumers and businesses.
Yet, for embedded payments to live up to their promise, key challenges remain. User experience and authentication are the primary obstacles. Truly embedded payments should enable users to complete transactions within the app, without being redirected elsewhere for authentication. As instant payments become the norm, any requirement to leave an app to verify a purchase could deter adoption. Addressing these issues will be critical to the future success of embedded payments as they continue to evolve and reshape the digital landscape.
In the coming years, as innovations like AI-driven fraud detection and biometric authentication become more integrated, the potential for embedded payments to achieve a truly seamless experience will grow. This could be the defining shift that cements embedded payments as the default mode of financial transactions in our increasingly digital world.
Business
The need for speed: Why fintechs must supercharge background checks to stay competitive
Source: Finance Derivative
By Luke Shipley, Chief Executive Officer and co-founder at Zinc
In the fast-paced world of finance, and particularly where finance and technology intersect, hiring candidates with the right skills is crucial for staying ahead of the competition. For fintech firms, conducting fast yet thorough background checks is key to balancing regulatory compliance with the need for speed.
However, financial regulations in the UK demand rigorous oversight to safeguard consumer data, prevent fraud, and maintain financial stability. As part of these regulations, fintech companies must conduct thorough background checks to ensure new hires align with compliance standards, mitigating risks to both the company and its customers. These checks involve verifying critical information such as financial history, credit reports, criminal records and employment history, which are essential for determining the suitability of candidates handling sensitive financial data. These checks are both time-consuming and resource-intensive, slowing down the hiring process.
Fintech firms can sustain rapid growth and meet regulatory obligations without sacrificing operational efficiency by streamlining this crucial part of the hiring process with the right tools. This also enables HR teams to focus on creating a positive experience for new hires, rather than burdening them with additional administrative tasks. Implementing efficient systems that reduce these checks from weeks to days allows companies to swiftly onboard talent, maintain customer trust, and stay competitive.
Challenges of traditional background checks
Traditional background checks in the fintech industry are complex and time-consuming due to the stringent regulatory requirements that financial organisations must follow. Verifying candidates’ financial history, running credit reports, conducting Disclosure and Barring Service (DBS) checks, and confirming employment history for the past several years are all critical tasks. These checks are not only meticulous but also require coordination with external agencies, which often slows down the process.
Manual handling of these background checks can extend the hiring timeline by weeks or even months, creating operational inefficiencies for fintech companies that need to scale quickly in a competitive industry. Prolonged hiring cycles can also lead to delays in onboarding vital talent, putting added pressure on already stretched teams.
For HR departments, managing these extensive checks manually places a heavy administrative burden. The time spent gathering documentation, verifying information, and coordinating with third parties diverts HR professionals from focusing on more strategic initiatives, such as talent acquisition and improving the candidate experience. As a result, the manual process not only hinders recruitment efficiency but also affects the company’s ability to attract top talent in a timely manner.
Role of technology in streamlining background checks
Here, technology plays a crucial role as it revolutionises the background check process in fintech by reducing manual interventions and simplifying time-consuming tasks. Automated platform systems now handle complex steps like identity verification, credit checks, and employment history validations far more efficiently than traditional methods. These technologies not only speed up the process but also provide one centralised place for employee documentation and improve accuracy by reducing the risk of human error in verifying critical information.
Automation also allows fintech companies to complete thorough background checks in a fraction of the time, continuing to ensure global compliance without delaying the hiring process. HR teams are freed from the burden of manual data gathering by automating repetitive tasks and reminder emails so they can focus on higher-value activities, such as candidate engagement and talent strategy.
Moreover, integrating background check platforms with existing HR systems streamlines recruitment workflows. This integration ensures a seamless transfer of data, and provides real-time updates on the status of each candidate’s background check. The result is a faster, more efficient hiring process that allows fintech firms to onboard new employees quickly, creating a positive reflection of their brand at every stage of the onboarding process.
Improved candidate experience
Technology in recruitment not only benefits HR teams but also significantly enhances the candidate experience. Automated systems cut down lengthy waiting periods, helping candidates move through the hiring process more swiftly.
From digital applications to real-time status updates, candidates enjoy a seamless, transparent process, which minimises stress and uncertainty. This streamlined approach improves communication and ensures that candidates are informed at every stage of their check progress, fostering trust and keeping them engaged. Additionally, modern tools like AI-driven assessments or automated interview scheduling save time, allowing candidates to focus on showcasing their skills rather than dealing with logistical hassles. Fintech companies can improve their overall employer branding by providing a more efficient and organised hiring process, attracting top talent who appreciate a modern and tech-forward experience.
It is why speeding up background checks is crucial for fintech companies aiming to stay competitive. By leveraging modern technology, these companies can benefit from greater efficiency, regulatory adherence, and an enhanced candidate experience. Fintech firms should embrace tech-driven solutions to balance speed and regulatory requirements, ensuring a smooth, transparent, and efficient hiring process.