NEW YORK: With five more US banks biting the dust this week, a whopping 78 entities have folded up their businesses so far this year.
Mirroring the financial woes faced by the American banking industry, an average of 15banks are going bankrupt every month.
Recently, the Federal Deposit Insurance Corporation (FDIC), which insures deposits at over 8,000 American banks warned of more failures in the coming months.
Authorities shut down five entities on May 28. They are Bank of Florida -- Southwest; Bank of Florida -- Southeast; Bank of Florida-- Tampa Bay, Sun West Bank and Granite Community Bank.
These failures are expected to cost the FDIC as much as USD 317 million.
The three Florida-based banks were owned by Bank of Florida Corporation.
In the first three months of 2010, the number of 'problem' banks climbed to 775, the highest in nearly 17 years. The same stood at just 702 at the end of 2009.
This month alone, 14 banks have gone out of business. The count of collapses are anticipated to rise in the wake of high unemployment levels, which is resulting in increased defaults at banks.
Last year, a whopping 140 banks in the US went belly up.
"There will be more failures, to be sure. The banking system still has many problems to work through and we cannot ignore the possibility of more financial market volatility," FDIC chairperson Sheila C Bair said recently.
Source: The Times of India, 30.05.10
A blog dedicated to the anti-fraud community towards creating awareness and preventing Fraud and all related fields and activities
Sunday, May 30, 2010
Monday, April 26, 2010
Make phone banking more secure: RBI -
NEW DELHI: Banks will have to soon put in place an additional authentication cover for their credit and debit card customers transacting over phone, or get penalized.
Taking forward its efforts to tackle identity frauds in non-branch banking transactions, the Reserve Bank has asked all the banks operating in the country to put in place by next year a system where credit and debit card customers would need to provide an additional password for IVR (interactive voice response) transactions.
IVR transactions are done over phone, wherein customers dial bank's customer care number and are prompted by a recorded voice to dial designated digits for different kinds of transactions such as balance enquiry, bill payment etc.
The customers would now need to key-in an additional password on their phone, besides prevalent details like card number, date of birth, card issue or expiry date and in some cases a telephonic password. As RBI has also noted, there has been a stupendous rise in banking transactions through channels other than traditional branch banking.
Source : Times Of India
Taking forward its efforts to tackle identity frauds in non-branch banking transactions, the Reserve Bank has asked all the banks operating in the country to put in place by next year a system where credit and debit card customers would need to provide an additional password for IVR (interactive voice response) transactions.
IVR transactions are done over phone, wherein customers dial bank's customer care number and are prompted by a recorded voice to dial designated digits for different kinds of transactions such as balance enquiry, bill payment etc.
The customers would now need to key-in an additional password on their phone, besides prevalent details like card number, date of birth, card issue or expiry date and in some cases a telephonic password. As RBI has also noted, there has been a stupendous rise in banking transactions through channels other than traditional branch banking.
Source : Times Of India
Saturday, April 24, 2010
IMP UPDATE : RBI Guidelines - Prohibiting alterations / corrections on cheques
Dear All,
Please go through the attached Notice/ Circular post the communication from RBI for Banks on Guidelines to follow in case of alterations on cheques. This will get implemented from July 01, 2010.
As per RBI Circular - DPSS.CO.CHD.No. 1832/01.07.05/2009-10 dated 22nd February 2010
Prohibiting alterations / corrections on cheques :
No changes / corrections should be carried out on the cheques (other than for date validation purposes, if required). For any change in the payee’s name, courtesy amount (amount in figures) or legal amount (amount in words), etc., fresh cheque forms should be used by customers. This would help banks to identify and control fraudulent alterations.
In view of the above guidelines, with effect from July 01, 2010 no alterations in cheque will be allowed (even if signature is made at the place of alteration on cheque). These kinds of altered cheques will not be honored by Bank.
Source : Reserve Bank Of India
Please go through the attached Notice/ Circular post the communication from RBI for Banks on Guidelines to follow in case of alterations on cheques. This will get implemented from July 01, 2010.
As per RBI Circular - DPSS.CO.CHD.No. 1832/01.07.05/2009-10 dated 22nd February 2010
Prohibiting alterations / corrections on cheques :
No changes / corrections should be carried out on the cheques (other than for date validation purposes, if required). For any change in the payee’s name, courtesy amount (amount in figures) or legal amount (amount in words), etc., fresh cheque forms should be used by customers. This would help banks to identify and control fraudulent alterations.
In view of the above guidelines, with effect from July 01, 2010 no alterations in cheque will be allowed (even if signature is made at the place of alteration on cheque). These kinds of altered cheques will not be honored by Bank.
Source : Reserve Bank Of India
Friday, April 23, 2010
Monday, March 1, 2010
How to Avoid Hiring a Bad Egg
As you begin recruiting and interviewing employees, you'll obviously be drawn to certain candidates because of their experience, educational background and personality. While it's easy to make a decision based on what you see in front of you, it's wise to consider what may be hidden from view, too.
Small businesses, unfortunately, are particularly vulnerable to embezzlement and other kinds of employee theft because they lack the checks and balances of big corporations. One report by the Association of Certified Fraud Examiners found that the median loss for small firms with fewer than one hundred employees was $190,000. The most common schemes? Employees fraudulently writing company checks, skimming revenues and processing phony invoices.
You can increase your chances of avoiding problems— and spotting dishonesty— by beefing up your hiring practices. Here's how to do it.
• Use a formal job application. Take a page from corporate America's book and supply job candidates with an application that requests full name, address, education, employment record (with years) and references. An application that includes all of this information can give you a clearer picture of someone's background than, say, a resume that he or she provides. Also, it's wise to state on the application that supplying false information can lead to dismissal. Documentation can help protect you in the event of an employee lawsuit.
• Ask tough questions. Carefully review the application, and during the in-person interview, ask probing questions, especially about gaps in employment. A candidate may certainly have any number of innocent explanations (such as attending school, reevaluating his or her career or caring for a child or other family member), but gaps between jobs can indicate an inability to hold down a position, a sudden dismissal or, at worst, a prison stay. Arrange for others at your company (or a trusted advisor, if you're a solo entrepreneur) to meet the person as well; getting a second or third opinion to confirm your impressions will help you make more solid hiring decisions.
• Call former employers and check references. Often, former bosses don't want to provide too much negative information, for fear that they could be sued for defamation. At the least, you should be able to verify the person's employment history and salary history. The best question to ask a former employer is simply, "Is this person eligible for rehire?" If the answer is no, that's a definite red flag.
• Perform a background check. Preemployment checks can screen out applicants who may be unfit (or dangerous) for your workplace because of a criminal record. Some states may require that employers in certain industries— say, child care or health care— conduct background checks. A background check also can confirm the accuracy of information that the candidate provided on the application. While a background check isn't necessary for all employees, it's smart to conduct one on a job candidate who will have access to sensitive data or your company's finances. The Fair Credit Reporting Act, which sets standards for employment screening, requires that you get consent from a potential employee before conducting a background check. Check the FTC's website to make sure you are in compliance. Also, you don't want to run afoul of state or federal laws concerning the kinds of information an employer uses to make employment decisions. If you do perform a background check, ask a business owner or your attorney for a referral to a reputable firm.
• Invite a potential hire for a paid tryout. You can learn a lot about potential employees, including how well they fit into your small business environment, by inviting them to work on a test project or spending a trial run in your office. A tryout may be a particularly good way to test an applicant's technical skills— say, a proficiency with a type of software— and may reveal far more than a reference or background check.
Source :- The Wall Street Journal, By Colleen Debaise
Small businesses, unfortunately, are particularly vulnerable to embezzlement and other kinds of employee theft because they lack the checks and balances of big corporations. One report by the Association of Certified Fraud Examiners found that the median loss for small firms with fewer than one hundred employees was $190,000. The most common schemes? Employees fraudulently writing company checks, skimming revenues and processing phony invoices.
You can increase your chances of avoiding problems— and spotting dishonesty— by beefing up your hiring practices. Here's how to do it.
• Use a formal job application. Take a page from corporate America's book and supply job candidates with an application that requests full name, address, education, employment record (with years) and references. An application that includes all of this information can give you a clearer picture of someone's background than, say, a resume that he or she provides. Also, it's wise to state on the application that supplying false information can lead to dismissal. Documentation can help protect you in the event of an employee lawsuit.
• Ask tough questions. Carefully review the application, and during the in-person interview, ask probing questions, especially about gaps in employment. A candidate may certainly have any number of innocent explanations (such as attending school, reevaluating his or her career or caring for a child or other family member), but gaps between jobs can indicate an inability to hold down a position, a sudden dismissal or, at worst, a prison stay. Arrange for others at your company (or a trusted advisor, if you're a solo entrepreneur) to meet the person as well; getting a second or third opinion to confirm your impressions will help you make more solid hiring decisions.
• Call former employers and check references. Often, former bosses don't want to provide too much negative information, for fear that they could be sued for defamation. At the least, you should be able to verify the person's employment history and salary history. The best question to ask a former employer is simply, "Is this person eligible for rehire?" If the answer is no, that's a definite red flag.
• Perform a background check. Preemployment checks can screen out applicants who may be unfit (or dangerous) for your workplace because of a criminal record. Some states may require that employers in certain industries— say, child care or health care— conduct background checks. A background check also can confirm the accuracy of information that the candidate provided on the application. While a background check isn't necessary for all employees, it's smart to conduct one on a job candidate who will have access to sensitive data or your company's finances. The Fair Credit Reporting Act, which sets standards for employment screening, requires that you get consent from a potential employee before conducting a background check. Check the FTC's website to make sure you are in compliance. Also, you don't want to run afoul of state or federal laws concerning the kinds of information an employer uses to make employment decisions. If you do perform a background check, ask a business owner or your attorney for a referral to a reputable firm.
• Invite a potential hire for a paid tryout. You can learn a lot about potential employees, including how well they fit into your small business environment, by inviting them to work on a test project or spending a trial run in your office. A tryout may be a particularly good way to test an applicant's technical skills— say, a proficiency with a type of software— and may reveal far more than a reference or background check.
Source :- The Wall Street Journal, By Colleen Debaise
Tuesday, February 23, 2010
Customer Vs. Bank: Who is Liable for Fraud Losses?
Comerica/EMI Case Raises Key Questions About Responsibility, Security
At first, this court case was a curiosity: Experi-Metal Inc. (EMI), a Michigan-based metal supply company, sued Comerica Bank, claiming that the bank exposed its customers to phishing attacks.
Now this story shapes up as a significant test case for the banking industry, raising several key questions that must be answered about fraud and responsibility.
"It will establish who is liable in the U.S. - the bank or the customer - for fraud losses that result from phishing," says Tom Wills, Senior Analyst, Security, Fraud & Compliance, Javelin Strategy & Research.
The Basics
The lawsuit, filed by EMI in a Michigan circuit court, alleges that Dallas-based Comerica opened its customers to phishing attacks by sending emails asking customers to click on a link to update the bank's security software. In January 2009, an EMI employee opened and clicked on links within a phishing email that purported to be from Comerica. The email duped the employee into believing the bank needed to update its banking software. Subsequently, more than $550,000 was stolen from the company's bank accounts and sent overseas.
EMI says even though the bank had two-factor authentication using digital certificates for its online banking portal, the phishing scam was able to circumvent these measures. The bank says its online security methods were reasonable "because they were in general used by other similarly situated customers of other banks." Now that this case is in the courts, observers say, several important questions will be debated re: trust, responsibility and security.
Among them:
#1: How Much Trust is Lost?
Clearly, Comerica has lost EMI's trust, but how much further can this costly loss of confidence spread among banking customers - even at other institutions? "Cases like this, when they hit the courts and the press, work at a macro level to erode the trust of all banks by all customers, even affecting those institutions with good anti-phishing programs in place," says Javelin's Wills. "It will make it that much harder for all banks to migrate their customer base to the highly cost-effective (from an operational standpoint) online channel."
Anytime a company incurs a data breach that compromises personal information, the organization risks having its customers walk away for good. "That's why it's so important that, before an incident occurs, a company take proactive steps to implement a reasonable security program," says Alysa Hutnik, a lawyer at Kelley Drye & Warren, a Washington DC-based law firm that specializes in post-incident response. "Even after a breach, if a company handles the issue responsibly, those efforts can earn back trust bit by bit. But here, where a customer is out of pocket hundreds of thousands of dollars as a result of a breach and was compelled to file a lawsuit to redress the issue, yes, the trust is likely lost."
Because trust is so fundamental to banking institutions, they have to draw a distinct line, says Avivah Litan, an analyst at Gartner. "Either banks explicitly and visibly warn their customers that banking with them is not safe and that [customers] are held liable for hacking into their accounts through online banking," she says. "Or they assume liability."
#2: Is a Bank Liable For Phishing?
Should a bank be held liable for a customer's employee falling for a phishing email that supposedly represents the bank? The EMI/Comerica case highlights several hotly debated issues.
On the plaintiff's side, the employee's vulnerability to the phishing attack raises the core question of 'What is sufficient training?,' says attorney Hutnik. Most employees have been warned about phishing attempts, but even the most robust training does not protect against occasional human error. Does this training need to occur more frequently, or is it a matter of customizing the training to the evolving and specific types of phishing attempts? If a company is going to be responsible under the law for employees' vulnerability to phishing attempts, Hutnik says, that's a pretty good incentive to increase training.
Can a bank be held liable? Some security experts say emphatically 'No.' "The bank clearly could have made better decisions on how to update security information," says Branden Williams, Director of VeriSign's PCI Practice. "But judging by the timelines, they may have been ahead of their time with offering multi-factor authentication for online business banking."
Williams quotes an old saying: "I'll open the door for you, but only you can walk through it." Comerica did open the door with its security updates, he says, but a simple training issue would have prevented the employee from walking through that door. "Companies that become complacent with security become easy targets."
#3: What is 'Reasonable Security?'
In this case, was the bank's two-factor security token technology an unreasonable safeguard based on the information available at the time it was implemented by the company? Discovery and expert testimony on this point will be critical, says Hutnik. So too, will the surrounding facts on what information the bank provided to its customers about giving personal information online, or in response to an email alert, leading up to and after it transitioned away from the digital certificate security process.
Hutnik sees a third key issue, which is often a gap in many companies: What measures were in place to detect unauthorized, unusual activity involving this customer account, and did the bank act quickly enough in response to such detection? "All companies could benefit from evaluating and assessing how they compare the issues raised in this case against their own information security programs," she says.
David Navetta, a lawyer at the Information Law Group, a Colorado-based law firm, says one of the issues that will be key in this case is whether the bank has a legal duty to prevent these types of phishing attacks. And if so, whether the security measures it took were "reasonable" under the law. To the extent a bank has a general duty to protect client accounts, does that duty extend to preventing (or reducing the risk of) its customers from being duped by social engineering attacks such as phishing? "That will be the threshold legal question, and I don't know what the answer will ultimately be," he says.
Another point that Navetta says will be considered is "Reasonableness." Under the law for purposes of negligence, a defendant can avoid liability even if a plaintiff suffered harm, as long as the defendant did not breach its duty of care. "In this context, if the bank's security measures where 'reasonable' under the law, it would not be liable," Navetta says. "I think the fact that the bank used two-factor authentication will help its cause in this respect," he says. On the other hand, he adds, "Many security professionals I have spoken to/read have indicated that a phishing attack was a known weakness, or at least a theoretical weakness, of two-factor authentication."
Regulators Were 'Asleep at the Wheel'
While EMI and Comerica argue over liability, Gartner's Litan says the nation's legislators and banking regulators bear the bulk of the blame for such breaches. "It's their job to set the rules for soundness and safety of the U.S. banking system, and to enforce that the banks execute those rules," she says. "They are negligent here - in not passing legislation that protects business accounts (as Reg E protects consumer accounts) and in not enforcing security measures at the banks, as set forth by the FFIEC strong authentication guidance," Litan says.
Litan also has strong words for bank examiners. "Frankly, they are also asleep at the wheel," she says. "And the banks are taking advantage of the current legislative and regulatory environment by not proactively securing business accounts."
No matter the outcome, this case will set a precedent, predicts Rohyt Belani, CEO of the Intrepidus Group, a New York City-based security firm. Banks and other e-commerce providers need to take some of the responsibility to help their customers mitigate the risk associated with phishing attacks - especially those that exploit the institution's brands. "Just posting information about phishing on the login page doesn't cut it," Belani says. "I believe banks need to work on enhancing their authentication mechanisms, changing the way they communicate with their clients (not embedding active links, etc.), and educating the customers using techniques that are proven to reduce susceptibility.
"Banks should view it as a wake-up call and work on mitigating phishing attacks."
Source: Bankinfo Security; By Linda McGlasson, Managing Editor
At first, this court case was a curiosity: Experi-Metal Inc. (EMI), a Michigan-based metal supply company, sued Comerica Bank, claiming that the bank exposed its customers to phishing attacks.
Now this story shapes up as a significant test case for the banking industry, raising several key questions that must be answered about fraud and responsibility.
"It will establish who is liable in the U.S. - the bank or the customer - for fraud losses that result from phishing," says Tom Wills, Senior Analyst, Security, Fraud & Compliance, Javelin Strategy & Research.
The Basics
The lawsuit, filed by EMI in a Michigan circuit court, alleges that Dallas-based Comerica opened its customers to phishing attacks by sending emails asking customers to click on a link to update the bank's security software. In January 2009, an EMI employee opened and clicked on links within a phishing email that purported to be from Comerica. The email duped the employee into believing the bank needed to update its banking software. Subsequently, more than $550,000 was stolen from the company's bank accounts and sent overseas.
EMI says even though the bank had two-factor authentication using digital certificates for its online banking portal, the phishing scam was able to circumvent these measures. The bank says its online security methods were reasonable "because they were in general used by other similarly situated customers of other banks." Now that this case is in the courts, observers say, several important questions will be debated re: trust, responsibility and security.
Among them:
#1: How Much Trust is Lost?
Clearly, Comerica has lost EMI's trust, but how much further can this costly loss of confidence spread among banking customers - even at other institutions? "Cases like this, when they hit the courts and the press, work at a macro level to erode the trust of all banks by all customers, even affecting those institutions with good anti-phishing programs in place," says Javelin's Wills. "It will make it that much harder for all banks to migrate their customer base to the highly cost-effective (from an operational standpoint) online channel."
Anytime a company incurs a data breach that compromises personal information, the organization risks having its customers walk away for good. "That's why it's so important that, before an incident occurs, a company take proactive steps to implement a reasonable security program," says Alysa Hutnik, a lawyer at Kelley Drye & Warren, a Washington DC-based law firm that specializes in post-incident response. "Even after a breach, if a company handles the issue responsibly, those efforts can earn back trust bit by bit. But here, where a customer is out of pocket hundreds of thousands of dollars as a result of a breach and was compelled to file a lawsuit to redress the issue, yes, the trust is likely lost."
Because trust is so fundamental to banking institutions, they have to draw a distinct line, says Avivah Litan, an analyst at Gartner. "Either banks explicitly and visibly warn their customers that banking with them is not safe and that [customers] are held liable for hacking into their accounts through online banking," she says. "Or they assume liability."
#2: Is a Bank Liable For Phishing?
Should a bank be held liable for a customer's employee falling for a phishing email that supposedly represents the bank? The EMI/Comerica case highlights several hotly debated issues.
On the plaintiff's side, the employee's vulnerability to the phishing attack raises the core question of 'What is sufficient training?,' says attorney Hutnik. Most employees have been warned about phishing attempts, but even the most robust training does not protect against occasional human error. Does this training need to occur more frequently, or is it a matter of customizing the training to the evolving and specific types of phishing attempts? If a company is going to be responsible under the law for employees' vulnerability to phishing attempts, Hutnik says, that's a pretty good incentive to increase training.
Can a bank be held liable? Some security experts say emphatically 'No.' "The bank clearly could have made better decisions on how to update security information," says Branden Williams, Director of VeriSign's PCI Practice. "But judging by the timelines, they may have been ahead of their time with offering multi-factor authentication for online business banking."
Williams quotes an old saying: "I'll open the door for you, but only you can walk through it." Comerica did open the door with its security updates, he says, but a simple training issue would have prevented the employee from walking through that door. "Companies that become complacent with security become easy targets."
#3: What is 'Reasonable Security?'
In this case, was the bank's two-factor security token technology an unreasonable safeguard based on the information available at the time it was implemented by the company? Discovery and expert testimony on this point will be critical, says Hutnik. So too, will the surrounding facts on what information the bank provided to its customers about giving personal information online, or in response to an email alert, leading up to and after it transitioned away from the digital certificate security process.
Hutnik sees a third key issue, which is often a gap in many companies: What measures were in place to detect unauthorized, unusual activity involving this customer account, and did the bank act quickly enough in response to such detection? "All companies could benefit from evaluating and assessing how they compare the issues raised in this case against their own information security programs," she says.
David Navetta, a lawyer at the Information Law Group, a Colorado-based law firm, says one of the issues that will be key in this case is whether the bank has a legal duty to prevent these types of phishing attacks. And if so, whether the security measures it took were "reasonable" under the law. To the extent a bank has a general duty to protect client accounts, does that duty extend to preventing (or reducing the risk of) its customers from being duped by social engineering attacks such as phishing? "That will be the threshold legal question, and I don't know what the answer will ultimately be," he says.
Another point that Navetta says will be considered is "Reasonableness." Under the law for purposes of negligence, a defendant can avoid liability even if a plaintiff suffered harm, as long as the defendant did not breach its duty of care. "In this context, if the bank's security measures where 'reasonable' under the law, it would not be liable," Navetta says. "I think the fact that the bank used two-factor authentication will help its cause in this respect," he says. On the other hand, he adds, "Many security professionals I have spoken to/read have indicated that a phishing attack was a known weakness, or at least a theoretical weakness, of two-factor authentication."
Regulators Were 'Asleep at the Wheel'
While EMI and Comerica argue over liability, Gartner's Litan says the nation's legislators and banking regulators bear the bulk of the blame for such breaches. "It's their job to set the rules for soundness and safety of the U.S. banking system, and to enforce that the banks execute those rules," she says. "They are negligent here - in not passing legislation that protects business accounts (as Reg E protects consumer accounts) and in not enforcing security measures at the banks, as set forth by the FFIEC strong authentication guidance," Litan says.
Litan also has strong words for bank examiners. "Frankly, they are also asleep at the wheel," she says. "And the banks are taking advantage of the current legislative and regulatory environment by not proactively securing business accounts."
No matter the outcome, this case will set a precedent, predicts Rohyt Belani, CEO of the Intrepidus Group, a New York City-based security firm. Banks and other e-commerce providers need to take some of the responsibility to help their customers mitigate the risk associated with phishing attacks - especially those that exploit the institution's brands. "Just posting information about phishing on the login page doesn't cut it," Belani says. "I believe banks need to work on enhancing their authentication mechanisms, changing the way they communicate with their clients (not embedding active links, etc.), and educating the customers using techniques that are proven to reduce susceptibility.
"Banks should view it as a wake-up call and work on mitigating phishing attacks."
Source: Bankinfo Security; By Linda McGlasson, Managing Editor
Monday, February 22, 2010
‘Whistle-blower policy the best way to check frauds’
FINANCIAL EXPRESS:
As corporate India debates ways and means to strengthen the corporate governance framework for the listed companies, post the Satyam scandal, an international expert says a whistle blower policy is the best way to prevent corporate frauds from blowing up. The rider: it should be implemented in spirit, and not just in form.
“Whistle blower policy is the best way to check corporate frauds,” says Marc Duchevet, global head for governance risk & internal control, Mazars. Mazars is one of the world’s largest audit firms with a turnover of more than $1.2 billion and 12,500 professionals in over 55 countries. Duchavet also made the point that in any organisation, where fraud develops with management collusion, there will be at least one good, solid whistle blower. "In addition, there will be several others who will be able to smell the rat that is feeding on the business and who would be in a position to raise a red flag”.
On a tour to India recently, he was charitable enough to accept that it is the fear of possible abuse which may have held back corporate India from implementing the policy with zeal. “Often there is discomfort among the management over the confidentiality and requisite protection offered to such a whistle blower under the policy. Fear of abuse of such a framework by people out to settle scores or working on a personal vendetta keeps management from implementing the policy,” he said.
Whistle blower policies have become a matter of concern in the corporate sector. An area of concern, the Mazar expert said, is that once the implementation of the policy starts, there is no choice but to address "all the incidents that come to your attention".
According to him, experience shows that corporate India does indeed recognise the value of good governance. There are, of course, a large number of corporations that believe that there is a direct relationship between business governance and business valuation.
To the extent this consideration is applied by drivers of corporate governance in the right spirit, this is an positive sign. But where emphasis is on mere paper disclosure, it is a concern. International companies are focusing on key areas like risk management, values and ethics and internal control. These three go together.
The truly best or effective monitoring does not come from the number of bodies exercising oversight. Rather, it comes from those who are willing to accept full accountability and are duly empowered to take necessary punitive action.
Though the government moved fast to protect investor interests after the Satyam promoters’ frauds came into light in 2008, India’s image as a favourite investment destination was hurt. This led experts to question the effectiveness of the section 49 of Sebi’s listing guidelines in protecting investor interest.
Significantly, it is still not mandatory for listed companies here to implement the whistle blower policy. However, some companies like ONGC and GAIL India have adopted it on a voluntary basis. But, the government is seriously considering making it mandatory for the PSUs.
Source: The Financial Express
As corporate India debates ways and means to strengthen the corporate governance framework for the listed companies, post the Satyam scandal, an international expert says a whistle blower policy is the best way to prevent corporate frauds from blowing up. The rider: it should be implemented in spirit, and not just in form.
“Whistle blower policy is the best way to check corporate frauds,” says Marc Duchevet, global head for governance risk & internal control, Mazars. Mazars is one of the world’s largest audit firms with a turnover of more than $1.2 billion and 12,500 professionals in over 55 countries. Duchavet also made the point that in any organisation, where fraud develops with management collusion, there will be at least one good, solid whistle blower. "In addition, there will be several others who will be able to smell the rat that is feeding on the business and who would be in a position to raise a red flag”.
On a tour to India recently, he was charitable enough to accept that it is the fear of possible abuse which may have held back corporate India from implementing the policy with zeal. “Often there is discomfort among the management over the confidentiality and requisite protection offered to such a whistle blower under the policy. Fear of abuse of such a framework by people out to settle scores or working on a personal vendetta keeps management from implementing the policy,” he said.
Whistle blower policies have become a matter of concern in the corporate sector. An area of concern, the Mazar expert said, is that once the implementation of the policy starts, there is no choice but to address "all the incidents that come to your attention".
According to him, experience shows that corporate India does indeed recognise the value of good governance. There are, of course, a large number of corporations that believe that there is a direct relationship between business governance and business valuation.
To the extent this consideration is applied by drivers of corporate governance in the right spirit, this is an positive sign. But where emphasis is on mere paper disclosure, it is a concern. International companies are focusing on key areas like risk management, values and ethics and internal control. These three go together.
The truly best or effective monitoring does not come from the number of bodies exercising oversight. Rather, it comes from those who are willing to accept full accountability and are duly empowered to take necessary punitive action.
Though the government moved fast to protect investor interests after the Satyam promoters’ frauds came into light in 2008, India’s image as a favourite investment destination was hurt. This led experts to question the effectiveness of the section 49 of Sebi’s listing guidelines in protecting investor interest.
Significantly, it is still not mandatory for listed companies here to implement the whistle blower policy. However, some companies like ONGC and GAIL India have adopted it on a voluntary basis. But, the government is seriously considering making it mandatory for the PSUs.
Source: The Financial Express
Subscribe to:
Posts (Atom)