24.02.2009
By: Paul Sheldon Foote and Reena Hora, California State University, Fullerton
The global financial meltdown has littered the financial landscape with an ever growing list of casualties. Among the reasons for their death are not least internal frauds and control system failures. These failures can be prevented by implementing a biometric system.

Certified biometric solution bioLock from realtime North America (Photo: realtime North America Inc.)
Biometric systems make it more difficult for dishonest employees to repudiate in court the evidence against them. Companies need systems for detecting and holding accountable persons who are violating security and internal control system standards.
Following the billions of dollars of losses caused by dishonest or irresponsible employees, investors and voters should become suspicious in the future whenever executives or audit committees claim their companies cannot afford better security systems.
The International Organization for Standardization (ISO) has published a new standard ISO 19092:2008 Financial services-Biometrics-security framework. “This standard establishes the security requirements for the implementation and management of state-of-the-art biometric identification technology within the financial industry.” It will make transactions more secure in the electronic era for the financial sector. (Ref 1)
SAP users can mitigate fraud by using bioLock (from realtime North America), the certified biometric solution using fingerprints.
Even if log-in passwords were obtained, the fraudster would not be able to do anything with the passwords because the biometric authentication system would deny him access to perform transactions.
If an ERP system uses multiple passwords for each user to control access to specific modules, that approach is no match for a biometric system able to control access even to the transaction, field or data level. The biometric approach is crucial for maintaining segregation of duties when employees gain new responsibilities.
The fraud at Societe Generale Bank is a classic example of how the fraud could have been prevented if they used SAP and a biometric system like bioLock for protection.
What went wrong?
Jerome Kerviel worked in the back office and in the middle office from 2000 to 2005, prior to becoming a trader. He had in-depth knowledge of their systems and procedures. (Ref 2 & Ref 3)
He made a lot of effort for his fraudulent trades to be undetected by the system. He used:
There were 75 warnings regarding Kerviel’s rogue trading. Yet, the authorities failed to detect Kerviel’s rogue trading until it escalated to such a high level. (Ref 5)
According to Diamond Management and Technology Consultants, Inc. this fraud was due to deficiency in Societe Generale’s operational risk management. To avoid this situation Societe Generale needs to have automated processes, an internal controls culture, and IT access controls. (Ref 6)
Banks and financial institutions need to build an internal controls culture which spans the business from top to bottom and also extends across businesses. They need to improve:
To prevent a recurrence of a fraud like this, financial institutions can improve security by adding biometric systems to their ERP systems or by replacing their legacy systems with SAP and bioLock. Most biometric systems are used for access control, but bioLock goes beyond access control and is even able to control a field, function or value within the ERP system, such as the amount of an outgoing wire transfer.
The technology offers control for changes to transactions within SAP ERP and will prevent unauthorized changes. The special committee for investigating Societe Generale’s fraud recommended that to prevent traders from using one another’s accounts the bank should use a stronger biometric authentication system. A system like bioLock would be the solution.
In today’s world, banks are required to comply with regulations and standards to protect them from fraud. To mitigate fraud, they need to supplement their internal controls compliance with biometric authentication. Biometrics will prevent data breaches of security. Fraudsters will not limit their fraudulent activities trying to perpetrate frauds using only an ERP system. Users of ERP systems must also secure email systems and any trading systems interfacing with an ERP system. This would tighten security and improve accountability.
Beitrag kommentieren
cforms contact form by delicious:days