2015-06-30

Added · Updated

Operational Incidents Watch Issue No. 3

The Hong Kong Monetary Authority issued this newsletter to highlight lessons from three operational incidents involving misappropriation of dormant account funds, fabrication of loan documents, and pricing basis deviations. The document details how staff circumvented maker-checker controls, exploited inadequate segregation of duties in SWIFT messaging, and relied on poor IT system communication to commit fraud or errors. It urges authorized institutions to strengthen fraud risk evaluations, enforce strict dual controls for free format messages, and implement comprehensive checks to ensure IT pricing aligns with client agreements.

Hong Kong Monetary Authority logo

Hong Kong

Hong Kong Monetary Authority

Click to view thumbnail

Hong Kong Monetary Authority Page 1 Issue No. 3 30 June 2015 Operational Incidents Watch is a periodic newsletter published by the Banking Supervision Department of the Hong Kong Monetary Authority (HKMA). It summarises the major lessons learnt from selected operational incidents1 that have happened in the banking industry and led to impact on relevant customers or material financial losses of the authorized institutions (AIs) concerned. It aims at facilitating AIs and the members of the public in Hong Kong to stay alert and to take appropriate measures to prevent similar incidents from happening to them. In this newsletter, the modus operandi or the factors and key control loopholes leading to three types of operational incidents are summarised: (i) misappropriation of customers’ funds in dormant accounts by a staff member; (ii) fabrication of loan documents and unauthorized modification of remittance instructions; and (iii) deviation from pricing basis agreed with clients. The incident involved fraudulent funds transfers from dormant customer accounts in an AI, which were made possible by a back-office team leader via misleading his team members or using their system login credentials. Modus operandi / factors leading to the incident The team leader was in charge of a back-office team which handled balance transfer and account closure of dormant customer accounts. The team leader managed to conduct unauthorized funds transfers from some dormant accounts to the bank accounts of certain companies maintained in the AI. While the AI implemented maker-checker dual controls over funds transfers from dormant accounts, the team leader circumvented the maker-checker controls by misleading 1 Due to sensitivity considerations, certain details of the relevant operational incidents were omitted. Operational Incidents Watch Misappropriation of customers’ funds in dormant accounts by a staff member

Operational Incidents Watch Issue No. 3 (June 2015) Hong Kong Monetary Authority Page 2 his team members to effect the concerned funds transfers or use other team members’ system IDs and passwords to effect the transfers (which might involve sharing of passwords, or failure of individual team members to promptly logout the system). Control loopholes and lessons learnt i. Workflow of the back-office team had not been subject to adequate fraud risk evaluation. In particular, excessive authority had been delegated to the team leader. There was also a lack of proper reconciliation on the funds transfers between dormant accounts and the AI’s ledger account. Moreover, monitoring of large-value funds transfers from dormant accounts was insufficient. ii. Fraud awareness and risk culture of the team members were also weak. For instance, some team members were asked by the team leader to conduct the suspicious funds transfers without questioning their validity, whereas others might have failed to logout their systems in a timely manner or even shared their login credentials with the team leader. The incident involved an AI’s staff member fabricating certain loan documents and modifying the relevant remittance instructions so as to obtain approval for loan disbursement and to subsequently remit the proceeds to her personal bank account. Modus operandi / factors leading to the incident A clerk of the AI’s loan processing team was responsible for collecting customers’ loan applications and processing loan disbursement. At the time of the incident, the clerk experienced financial stresses and she fabricated certain loan documents by referring to old documents or modifying genuine documents (e.g. falsifying a higher loan amount) and then obtained management’s approval for disbursement of Fabrication of loan documents and unauthorized modification of remittance instructions

Operational Incidents Watch Issue No. 3 (June 2015) Hong Kong Monetary Authority Page 3 the loan proceeds related to fake loan applications. After the SWIFT remittance instructions for the approved loan disbursement transactions were duly authorized and sent to the correspondent banks for disbursing the loan proceeds to the customers’ bank accounts, the clerk created and authorized free format SWIFT messages (e.g. MT199) in the AI’s system2 to amend the remittance instructions so that the loan proceeds were transferred to her bank account. During the process, she also created certain free format SWIFT messages for amending the relevant remittance instructions (e.g. to recall the funds transferred to her bank account) and removed the falsified documents to cover up the incident. Control loopholes and lessons learnt i. Checker-maker dual control was not established in the AI’s system for the creation, authorization and transmission of free format SWIFT messages. ii. There was inadequate segregation of duties in the AI’s handling of customers’ loan applications where the concerned clerk was allowed to collect customers’ applications, confirming with the customers the loan details, and creating the records in the system. iii. Control over the receipt and distribution of inward SWIFT messages was inadequate, and hence a series of SWIFT messages exchanged between the AI and its correspondent banks regarding the amendments of remittance instructions were not routed to the supervisors for attention or review. iv. The supervisors did not exercise due care in reviewing the loan applications/documents before approving the loan disbursements, especially because there was a shortage of staff during the relevant time. They did not scrutinize the underlying reason for the returned loan proceeds after the clerk sent a free format SWIFT message to a correspondent bank to recall the loan proceeds transferred to her personal account. 2 In the AI’s system, a single user was allowed to create, authorize and transmit free format SWIFT messages.

Operational Incidents Watch Issue No. 3 (June 2015) Hong Kong Monetary Authority Page 4 There had been discrepancies between the pricing arrangement agreed with clients and the actual prices applied for conducting and pricing certain financial transactions for a number of years before it was discovered. A similar incident also happened to another AI regarding other financial products offered to its clients. Modus operandi / factors leading to the incident In one case, the inconsistency was resulted from the AI applying changes to the pricing basis for certain financial products in its IT system and incorrectly changing the agreed pricing basis for other clients as well. Furthermore, the inconsistency was not uncovered at that time due to a lack of control to ensure that any change in pricing calculation applied to the system followed the terms agreed with the relevant clients. In another case, the original design of the AI’s IT system adopted a pricing basis different from the terms agreed with the clients concerned, potentially due to ineffective communications between the relevant business department and the department that designed the IT system. In both cases, the AIs took steps to rectify the inconsistencies in their computer systems and arranged compensations for affected clients. Measures were also implemented to prevent similar incidents from happening again. Control loopholes and lessons learnt i. There was insufficient communication among the relevant departments in designing or making changes in the AIs’ IT systems. ii. No comprehensive checking or periodic sample checking had been performed after system change between pricing basis and the terms agreed with clients. Deviation from pricing basis agreed with clients

More like this from HKMA

HKMA published 11 documents in the last 30 days. We email you each new one the day it's published.

Share