ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

The Steps to Managing MFS Risk

December 15, 2016
Reading Time: 4 mins read

By Ruth Razook

It goes without saying that mobile financial services (MFS) are here to stay. The majority of consumers—including millennials—use some type of digital payment service for all of their monetary transactions. Some of them may not have ever experienced something like manually depositing a check at a bank. According to the Consumers and Mobile Financial Services 2016 study completed by the Board of Governors of the Federal Reserve System, 43% of all mobile phone users with a bank account had used mobile banking in the 12 months prior to the survey. This number is up from 39% in 2014 and 33% in 2013.

While some people claim that statistics like these point to the coming extinction of traditional bank branches, it can be argued that banks actually play a key role in MFS risk management. It is important for financial institutions to not only keep up with the times by offering MFS, but to also identify the unique risks associated with such services and establish a plan to mitigate those risks for their own safety, as well as the safety of their customers.

Until recently, identifying MFS risks was a huge problem. In 2015, more than 50 financial institutions were surveyed by Transaction Directory and 97% of them reported having no strategy on how to address internet purchasing. Luckily, new guidance for mobile banking was released this year when the Federal Financial Institutions Examination Council (FFIEC) updated its Retail Payment Services Handbook and added Appendix E – Mobile Financial Systems. These guidelines examined what risk assessments should look like, how financial institutions should monitor risk, what tools should be used, and more.

Step 1: The first step in the MFS risk management process is risk identification. This must include risks associated with mobile devices where the customer implements and manages security settings; unique risks associated with specific devices; and associated risks in the areas of strategy, operations, compliance, and reputation. For example:

  • Short message service (SMS) messages are easily fraudulent as they are unencrypted over widely-used networks.
  • Mobile apps may be unauthorized or contain malware.
  • Mobile payments may be compromised if portable devices are misplaced or stolen.

In addition, financial institutions must identify how providing MFS may create reputational risks, especially in the context of privacy and data security, as public scrutiny of the treatment of customer information continues to grow.

Step 2: After the potential risks have been identified, financial institutions need to begin the process of measuring those risks. They must develop consistent risk criteria and have it published for all decision makers to review, as well as periodically review that risk criteria for potential environmental changes and share their findings with the board.

Along those lines, financial institutions must implement the measurement of the level and types of risks involved in offering MFS, in addition to the measurement of potential risks across all applicable risk categories. It is important to note that this process is ongoing and requires updates whenever a change is implemented.

Step 3: Finally, financial institutions should determine whether their controls are effective and their goals are compatible with the company’s strategic plan in order to best mitigate the identified risks. Implementing effective controls includes communicating policies and procedures during enrollment, authenticating users of MFS, and using well-constructed contracts developed with legal counsel to provide necessary security for both the financial institutions and their customers.

This also requires developers to follow a secure development life cycle, determining whether mobile browsers have available safeguards implemented, employing tools like device fingerprinting, and performing security testing at all post-design phases of the system development life cycle.

Of course, all policies and procedures implemented must comply with laws and regulations. MFS must be included in retail payments systems audits. And security awareness materials must be provided to customers so that they understand their role in security. This includes things like the use of anti-malware and PIN protection. Additional security settings can be added to the digital login process—such as a list of previous account activity with the date, time, and type of device that initiated the login. This allows the consumer to audit all transactions that have taken place from their account.

MFS risk management is much more than installing “safe” digital payment software. It includes identifying potential risks, measuring them effectively, and establishing a plan to mitigate those risks. Not only does taking this seriously allow financial institutions to remain in compliance with the updated FFIEC guidelines, but it also protects their customers and the institutions themselves from multiple types of harmful fraud.

Ruth Razook is founder and chief executive officer of RLR Management Consulting, a consulting firm servicing community banks nationwide in four primary categories: technology, regulations/compliance, operations and M&A. RLR’s clientele includes community and regional banks of all sizes. RLR has offices in both Reno, Nev. and Palm Desert, Calif. LinkedIn. Twitter.

Tags: ComplianceDigital bankingMobile banking
ShareTweetPin

Related Posts

FinCEN, OFAC and FBI issue alert about timeshare fraud linked to organized crime

Treasury Department seeks to sever U.S. financial ties to 10 Mexican casinos

Compliance and Risk
November 13, 2025

The Treasury Department announced a joint effort with Mexico to target several Mexico-based gambling establishments involved in alleged cartel-related money laundering and other criminal activities.

Agencies form strike force to target cryptocurrency scams

Agencies form strike force to target cryptocurrency scams

Compliance and Risk
November 12, 2025

Federal law enforcement agencies announced the formation of an interagency “strike force” to target Southeast Asian cryptocurrency-related investment scams and confidence schemes.

ABA, associations object to CFPB ‘junk fee’ label for mortgage-related fees

CFPB proposes changes to fair lending enforcement

Compliance and Risk
November 12, 2025

The CFPB is proposing to remove disparate impact from its enforcement of the Equal Credit Opportunity Act, clarify the prohibition on discouraging prospective applicants, and establish new limits on special-purpose credit programs offered by lenders.

CFPB launches ‘tip line’ to report on bureau employees

CFPB proposes to streamline small-business data collection rule

Ag Banking
November 12, 2025

The CFPB is proposing revisions to its small-business lending data rule to scale back the scope of data collection, saying that adopting a “longer-term” approach that allows for the future addition of more data points would be the...

ABA Fraudcast: The bank that breaks the spell

ABA Fraudcast: The bank that breaks the spell

Compliance and Risk
November 12, 2025

Santander UK’s scam-interruption team confronts delicate issues for customers in difficult moments.

Fed releases agenda for upcoming conference on large bank capital requirements

Fed finalizes revisions to rating system for large banks

Compliance and Risk
November 5, 2025

The Federal Reserve finalized revisions to its supervisory rating framework for large banks to address the “well managed” status of the institutions.

NEWSBYTES

Mortgage rates slip

November 13, 2025

Treasury Department seeks to sever U.S. financial ties to 10 Mexican casinos

November 13, 2025

FASB issues guidance on purchased loans

November 13, 2025

SPONSORED CONTENT

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

November 1, 2025
5 FedNow®  Service Developments You May Have Missed

5 FedNow® Service Developments You May Have Missed

October 31, 2025

Cash, Security, and Resilience in a Digital-First Economy

October 20, 2025
Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

October 1, 2025

PODCASTS

Podcast: The Erie Canal at 200

November 6, 2025

Podcast: Why branches are top priority for PNC

October 23, 2025

Podcast: From tractors to drones, how farming tech affects ag lending

October 16, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2025 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2025 American Bankers Association. All rights reserved.