
[av_one_full first min_height=” vertical_alignment=” space=” custom_margin=” margin=’0px’ padding=’0px’ border=” border_color=” radius=’0px’ background_color=” src=” background_position=’top left’ background_repeat=’no-repeat’ animation=”]
[av_heading heading=’ AN INDEPENDENT VIEW ‘ tag=’h3′ style=’blockquote modern-quote’ size=’30’ subheading_active=’subheading_below’ subheading_size=’15’ padding=’10’ color=” custom_font=”]
BY NEIL HONEYMAN
[/av_heading]
[av_textblock size=” font_color=” color=”]
LAST WEEK, I discussed aspects of the banking system and found that banks no longer have the undoubted probity that its pre-electronic systems provided. It seems that banks are accepting that Automated Teller Systems (ATM) have been compromised because technologically obsolete ATM cards are still being used. These are easily “skimmed” so that fraudulent ATM withdrawals are being made. This creates a potentially adversarial relationship between banks and their customers since disputes can arise as to why the debatable transactions have happened.
One of the concomitants of a financial institution operating with complete probity is that there should be no doubt as to what transpired so that disputes between the bank and its customer should be extremely rare.
On Aug. 16, 2007 I was quietly commemorating Elvis’ thirtieth death anniversary. Unknown to me, at 10.30.30 somebody using terminal number 6654, at a Banco de Oro Unibank Inc (BDO) office, illicitly hacked into my telebanking account and withdrew P50,000. Two days later I found this out and made representations to my local BDO branch. I was concerned that the bank knew nothing about it. The reflex of the area manager was that we had done something wrong which caused this to happen. During the following week the bank deigned to refund the money that had been stolen. It was not clear to me that the bank had the controls to prevent the hacking from taking place. In fact, it was clear that the system had been compromised. What was not clear was that the bank had the necessary “firewalls” to afford the essential protection if probity is to be ensured.
What concerns me is that banks are good at keeping Bangko Sentral ng Pilipinas (BSP) at arm’s length. This means that BSP is not an effective backstop when bad things happen. In my case, I made representations to BSP saying that I had no secrecy concerns relating to my account. Nevertheless, BDO fobbed off BSP’s enquiry citing RA 1405, the bank Secrecy Act, even though I waived any rights. It is wrong that RA 1405 is being used to cover up impropriety within the bank. BSP was not able to find out what went wrong.
In June, the Department of Information and Communications Technology (DICT) initiated a formal investigation of the online systems failures encountered by both the Bank of the Philippines Islands (BPI) and BDO.
Recently resigned DICT secretary Rodolfo A. Salalima who chaired the Cybercrime Investigation and Coordinating Center (CICC) asked National Privacy Commission (NPC) Chairman Raymund E. Liboro to look into the incidents involving the two banks.
Were authoritative conclusions found?
Can we be sure that the “glitches” at BPI and BDO will not happen again?
Or were the representatives of government instrumentalities unable to complete their inquiries due to the banks who like to deal with their own problems internally?
I think we should be told./PN
[/av_textblock]
[/av_one_full]






