Eng. Machua NjorogeOne of the key measures is the mandatory waiting period after a SIM card is replaced. Once a SIM swap has been completed, mobile money services can only be activated after the lapse of 48 hours. This delay is intended to prevent fraudsters from immediately accessing victims' mobile money accounts.
Banks have also implemented several additional safeguards. It is important to understand that those behind SIM swap fraud are often operating from a different geographical location from the legitimate customer. In most cases, the new SIM card is inserted into a different phone from the one normally used by the account holder.
Recognising this risk, many banks require customers seeking to instal a banking application on a new phone to either visit a branch physically or undergo identity verification before they are allowed to successfully log into their banking application. Some financial institutions also require a waiting period—sometimes up to 48 hours after a customer contacts the bank—before access on the new device is activated.
As customers, we also need to appreciate that these measures are designed for our own protection. While they may appear inconvenient, they should be viewed as safety precautions rather than unnecessary hurdles.
Going forward, there is a need to strike the right balance between sensitising customers on the security measures that exist and protecting information that should remain confidential. The reality is that fraudsters are also legitimate customers of financial institutions. If banks and other financial service providers disclose every security control they have put in place, they also risk informing criminals how those systems operate.
Addressing SIM swap fraud is therefore a shared responsibility. Government has a role to play by putting in place legislation that supports the fight against these crimes, including frameworks that allow information sharing on individuals who are identified as likely to be involved in such fraud.
Financial institutions must continue strengthening the measures already in place while also educating customers on how to protect themselves. They should also share information on emerging fraud cases so that patterns can be identified early and mitigation measures put in place before more customers fall victim.
Kenya's grey listing has also brought greater focus to financial crime. The country was grey-listed because of what can broadly be described as weaknesses in anti-money laundering and counterterrorism financing controls. However, in response to the grey listing, the government has passed a raft of legislation aimed at addressing these weaknesses and strengthening the country's framework for combating financial crime.
Kenya is on the grey list for what can be termed as weak anti-money laundering and counter-terrorism controls.
However, in light of the grey listing, the government has passed a raft of legislation to combat these. These include the Virtual Asset Service Providers Act and regulations as per Financial Action Task Force (FATF) recommendations 15 and 16. This is important as one of the ways proceeds of cybercrime are moved is through virtual assets.
By regulating and putting controls here, it makes it harder and less lucrative for cybercriminals to move their money through this means.
Further, training around anti-money laundering (AML) and conter terrorism financing has been elevated, with even the boards fo fiancial instituation being required to undergo this training. What this does is set the tone for this and ensure that controls to combat AML and CFT have utmost support. Other measures include ensuring that while money is moving across borders, the details of both the sender and beneficiary have to be captured.
Anyone dealing in anything illegal is not particularly eager to share their details. Whereas things like hiding companies exist, due diligence and enhanced due diligence measures have been put in place to know exactly who owns these companies. With these measures, we are in a path to be removed from the whitelist.
It is important to note that Africa lost approximately KES 650billion to cybercrime, with Kenya losing about KES 0.5 billion to SIM swap fraud. This indicates that we do have working controls in place, put in place by financial institutions, be they banks or telcos.
That being said, it means that as we continue to drive financial inclusion, it means that we are bringing the most vulnerable into the financial ecosystem. With our financial inclusion measures, controls to protect customers can’t and are not being treated as an afterthought.
Parameters for financial inclusion now must include financial security now and going into the future. Financial institutions must and will continue to sensitise their customers on fraud and cybercrime.
Similarly, as customers, we must embrace these controls. The same way we go out of our way to get better testing medication because of its benefits, we must embrace controls put in place to protect us, despite minor inconveniences.
Machua Njoroge is an engineer and a payments expert