Www.europeanpaymentscouncil.eu PRES EPCXXX_07 EPC Card Fraud Prevention & Security Activities Cédric Sarazin – Chairman Card Fraud Prevention TF 19. December.

Slides:



Advertisements
Similar presentations
1
Advertisements

Copyright © 2003 Pearson Education, Inc. Slide 1 Computer Systems Organization & Architecture Chapters 8-12 John D. Carpinelli.
Multiplication X 1 1 x 1 = 1 2 x 1 = 2 3 x 1 = 3 4 x 1 = 4 5 x 1 = 5 6 x 1 = 6 7 x 1 = 7 8 x 1 = 8 9 x 1 = 9 10 x 1 = x 1 = x 1 = 12 X 2 1.
Division ÷ 1 1 ÷ 1 = 1 2 ÷ 1 = 2 3 ÷ 1 = 3 4 ÷ 1 = 4 5 ÷ 1 = 5 6 ÷ 1 = 6 7 ÷ 1 = 7 8 ÷ 1 = 8 9 ÷ 1 = 9 10 ÷ 1 = ÷ 1 = ÷ 1 = 12 ÷ 2 2 ÷ 2 =
© fedict All rights reserved Legal aspects Belgian electronic identity card Samoera Jacobs – November 2008.
Orientation Session on International Public Sector Accounting Standards (IPSAS) September 1, 2009.
UNITED NATIONS Shipment Details Report – January 2006.
David Burdett May 11, 2004 Package Binding for WS CDL.
Business Transaction Management Software for Application Coordination 1 Business Processes and Coordination.
Business Transaction Management Software for Application Coordination 1 Business Processes and Coordination. Introduction to the Business.
Business Transaction Management Software for Application Coordination 1 Business Processes and Coordination. UN/CEFACT Business Collaboration.
The National Standards and Quality System Jean-Louis Racine The World Bank Cambridge, England April 19, 2007 Knowledge Economy Forum VI Technology Acquisition.
Jean-Michel DELAVAL 19 November 2009
1 FPEG Identity theft & payment fraud point December 2007.
What causes the commodity price boom? AGRI Green Team Seminar on the Health Check May 15, 2008 AGRI-G1 Agricultural Policy Analysis and Perspectives DG.
Planning and use of funding instruments
The European Qualifications Framework (EQF)
EC Fraud Prevention Expert Group - Brussels, 28 November Implementing the SEPA Cards Framework (SCF): Towards greater security for card payments.
Jeopardy Q 1 Q 6 Q 11 Q 16 Q 21 Q 2 Q 7 Q 12 Q 17 Q 22 Q 3 Q 8 Q 13
CALENDAR.
1 1  1 =.
1  1 =.
FACTORING ax2 + bx + c Think “unfoil” Work down, Show all steps.
Around the World AdditionSubtraction MultiplicationDivision AdditionSubtraction MultiplicationDivision.
1 Presentation to the Overseas Development Institute Friday, 30 January 2004 London Development Cooperation Report 2003 Presentation by Richard Manning,
The 5S numbers game..
1 The impact of important Single Market policies on the development of Pan- European Services and Products i2010 Conference Information Society at the.
1 STATISTICAL DATA ON THE BANKS PAYMENT SYSTEMS IN FINLAND May 2013.
Visa Youth Prepaid Cards and financial capability
WHAT IS EMV? A joint effort between Europay, MasterCard and Visa It is a security framework that defines the payment interaction at the physical, electrical,
TOWARD FAIRER AND COMPETITIVE PAYMENT SOLUTIONS IN THE EU.
Break Time Remaining 10:00.
PP Test Review Sections 6-1 to 6-6
EU Market Situation for Eggs and Poultry Management Committee 21 June 2012.
Look at This PowerPoint for help on you times tables
EIS Bridge Tool and Staging Tables September 1, 2009 Instructor: Way Poteat Slide: 1.
The European Lighting Industry Position on How to Maximise the Potential Benefits of European Policy on Energy Efficiency in Lighting January 2008.
CS 6143 COMPUTER ARCHITECTURE II SPRING 2014 ACM Principles and Practice of Parallel Programming, PPoPP, 2006 Panel Presentations Parallel Processing is.
TCCI Barometer March “Establishing a reliable tool for monitoring the financial, business and social activity in the Prefecture of Thessaloniki”
TCCI Barometer March “Establishing a reliable tool for monitoring the financial, business and social activity in the Prefecture of Thessaloniki”
Copyright © 2012, Elsevier Inc. All rights Reserved. 1 Chapter 7 Modeling Structure with Blocks.
Basel-ICU-Journal Challenge18/20/ Basel-ICU-Journal Challenge8/20/2014.
1 © 2004, Cisco Systems, Inc. All rights reserved. CCNA 1 v3.1 Module 10 Routing Fundamentals and Subnets.
MaK_Full ahead loaded 1 Alarm Page Directory (F11)
TCCI Barometer September “Establishing a reliable tool for monitoring the financial, business and social activity in the Prefecture of Thessaloniki”
OHT 5.1 © Marketing Insights Limited 2004 Chapter 5 E-business Strategy.
Before Between After.
Model and Relationships 6 M 1 M M M M M M M M M M M M M M M M
25 seconds left…...
Subtraction: Adding UP
Copyright © 2008 Pearson Addison-Wesley. All rights reserved. Chapter 10 A Monetary Intertemporal Model: Money, Prices, and Monetary Policy.
Converting a Fraction to %
Clock will move after 1 minute
PSSA Preparation.
Essential Cell Biology
Modular Urban Transport Safety and Security Analysis 1 SiT - Safety in Transportation 2012.
Select a time to count down from the clock above
Aviation Management System 1 2  Silver Wings Aircraft Aviation Management System represents a functional “high – end” suite of integrated applications.
Presented to: By: Date: Federal Aviation Administration FAA Safety Team FAASafety.gov AMT Awards Program Sun ‘n Fun Bryan Neville, FAASTeam April 21, 2009.
Credit Card Fraud The Scale of the Problem Michael Moore Regional Security & Fraud Investigation Manager 14 – 17 Nov 2005 Security & Safety – Middle East.
Fraud: What Happens When EMV Surfaces? Tracey Black GFH Group Inc. Cardware, June GFH GROUP INC.
Memorial University of Newfoundland An Update on Chip September 26, 2007.
POS/ATM Protection Profile for a Common European Banking Industry Approval Scheme Common Approval Scheme POI Working Group SRC Security Research & Consulting.
R U Ready? V M E EUROPAY MASTERCARD VISA EMVco was formed in 1999.
EPC Roadmap One year on, how are we doing? EPC Strategy Off-site, Durbuy, 2 October 2005 Gerard Hartsink, EPC Chair PRES.
Summary of Changes. General These are changes that have come up in many EMV migrations that I have assessed and been involved in. The changes are broken.
EMV.
Regular Payments First and Subsequent Payments
Presentation transcript:

PRES EPCXXX_07 EPC Card Fraud Prevention & Security Activities Cédric Sarazin – Chairman Card Fraud Prevention TF 19. December 2007, FPEG Meeting - Brussels

Page 2 EPC and a SEPA for cards The timelines EPC Cards Working Group (Chair: Claude Brun) EPC SEPA Card Framework (SCF) Cards Standardisation TF (Chair: Peter Blasche) Minimumrequirements Recommendedspecifications Card Fraud Prevention TF (Chair: Cédric Sarazin)

Page 3 SEPA Cards Framework (SCF) The SCF was approved by the EPC Plenary on 8 March 2006 The SCF spells out high level principles and rules which when implemented by banks, schemes, and other stakeholders, will enable European customers to use general purpose cards to make payments and cash withdrawals in euro throughout the SEPA area with the same ease and convenience than they do in their home country. There should be no differences whether they use their card(s) in their home country or somewhere else within SEPA. The SCF creates the potential for any SCF terminal to accept any SCF card with a SEPA based acquirer of the merchants choice. SCF only covers euro card payments and cash withdrawals Provides a single framework for banks, for schemes and for processors/infrastructures to become SEPA compliant (self-assessment procedure with EPC monitoring)

Page 4 Highlights from the SCF Acquirers will offer merchants the option to acquire SCF compliant card transactions from one or more SCF compliant schemes from 1 January 2008 onwards. As fraud prevention is one of the priorities, the SCF indicates that the EMV chip will be the supporting technology for cards as well as the support of PIN on the acquiring side. The SCF sets out the high level principles to foster the competition between providers of technical infrastructure and payment services and to remove legal and technical barriers. SCF compliant card schemes will separate governance from processing functions. The SCF contains both a number of short term objectives and a longer term vision on the standardisation of the elements of the payment chain. The European Central Bank recently commented the proposed migration towards a SEPA for card and recently acknowledged the importance of the SCF.

Page 5 Impacts of EPC activities on the different elements of card payment schemes Certification Authorisation Switching Clearing & Settlement Product Definition & Rules Security & Risk Management Technical Standards Interlinking (Gateways to other systems) Card Fraud Prevention TF SEPA Cards Framework (separation of the gouvernance from processing functions & EMV) Cards Standardisation TF

Page 6 Card Fraud Prevention TF Mission, Work & Resolutions 1 Two-days Forum "Fighting Card Fraud across Europe" (Paris 8-9 October 2003) 1 Resolution on "Preventing and Fighting Card Fraud across Europe" (Approved by the Plenary in December 2003) 1 Resolution "Preventing Card Fraud in the New SEPA Environment" (Approved by the Plenary in March 2007) The mission of the Card Fraud Prevention Task Force is to promote card fraud prevention tools within the banking industry and to develop tactical initiatives to fight against card fraud across SEPA. To complete its mission the Task Force will follow a continuous process of: - Identification of issues (sharing of information about new threats) - Prediction of trends (sharing and development of statistics) - Promotion of prevention tools (Chip/PIN, databases, authentication methods…) - Development of innovative tactical initiatives - Commitment of industry (EPC resolutions and recommendations)

Page 7 Card Fraud Trends in SEPA In most of SEPA countries: –Counterfeit fraud –Magstripe skimming compromission cases (& subsequent fraud outside of chip countries) –Card Not Present fraud (e-commerce notably) –Fraudsters targetting weak point / sector / environment –See (next slides) examples in a few countries

Page 8 Evolution of Fraud on CB Cards , , CB SystemWorldwide out of which EU CB System Worldwide out of which EU CB SystemWorldwide out of which EU CB System Worldwide out of which EU Lost/StolenMS Skimming "Yescard"MOTO * Million Most important evolutions: Dynamic Data Authentication Fight against skimming Securing e-commerce Fraud Rate CB: 0,034% 0,033% 0,035% 0,034% Fraud Rate-Cross system: 0,71% 0,49% 0,47% 0,50%

Page 9 Chip and PIN successfully combating targeted fraud types In 24 months: losses at UK high street retailers down £147mn Initial impact of chip and PIN on fraud on UK cards Benefits of EMV being starting to be realised Source: APACS Statistics

Page 10 Fraud to sales turnover at UK retail Fraud to sales levels at UK high street retailers their lowest for six years. For all card products combined the rate is below 10 basis points Source: APACS Statistics

Page 11 Card Fraud Prevention TF Current Priorities Preventing the use of counterfeit cards at SEPA terminals –Completing EMV migration – Monitoring EMV migration => Currently 56% of cards, 59% of POS, 72% of ATMs in EU –Eliminating magstripe fallback at EMV terminals Combating Card Not Present (CNP) fraud –E-commerce environment: CVX2 full implementation –MO/TO environment: CVX2 –E-commerce environment: 3D-Secure implementation Collecting aggregated statistics on card fraud in SEPA … and also: –Work on card anti-skimming measures –Fraud in specific environments (such as airlines) –Work on cardholder authentication methods in e-commerce

Page 12 Examples of Anti-Fishing/ Anti-Skimming (AFAS) Devices

Page 13 Securing e-commerce CVX2 Mandatory in all e-commerce transactions (EPC Resolution: by 1st January 2008) 3D Secure : liability shift on card issuers if the merchant is 3D-Secure equipped (EPC Resolution: by 1st January 2009) Strong authentification of cardholders to be promoted, notably using EMV chip.

Page 14 Strong Authentification using Chip: Some pilotes or tests

Page 15 SEPA Card Standardisation Activities, including Security Requirements Cardholder Acceptor EPAS Consortium ( Harmonised Acquirer to Terminal Exchanges at SEPA Level ) ERIDANE Project (Harmonised Terminal Architecture at SEPA Level) ISO8583 / ISO20022 EPC Expert Group (Harmonised Issuer to Acquirer Exchanges at SEPA Level) EMV Standard + CIR Working Group (Harmonised EMV Implementations at SEPA Level) Issuer Acquirer + CAS Project ( Harmonised Security Requirements and Evaluations at SEPA Level ) PCI Standards EPC as Project Coordinator CIR: Common Implementation Requirements – EPAS: Electronic Protocols Application Software - PCI: Payment Card Industry – CAS: Common Approval Scheme PSP

Page 16 EPC Standards for Card Terminals Terminal Architectur e Terminal Architectur Applicatio n n Terminal Architectur e Terminal Architecture Applicatio n Application EPAS CIR / TWG (SEPA-FAST) Electronic Cash Register EPAS Acquirer Terminal Manager Transaction: Acquirer Protocol EPAS Terminal Management Issuer Terminal : ERIDANE Acquirer-to-Issuer Protocols Retailer Protocol CAS (Security & Certification)

Page 17 EPC Card Standards Implementation Plan SCF implementation Application of Recommended Specifications Only minimum reqs elements All schemes SCF compliant Promotion by schemes Promotion by schemes Schemes include support SCF is the framework for all SEPA cards schemes Minimum reqs available Recommended specs available Application of Minimum Requirements 2010 Implemen- Implemen-tation

Page 18 Thank you for your Attention