Search This Blog

Sunday, 16 June 2019

Of Caution And Realistic Expectations: AI, ANN, BDA, ML, DL, UBI, PAYD, PHYD, PAYL...

A recent report into the use of data and data analysis by the insurance industry provides some excellent insights into the pros and cons of using artificial intelligence (AI) and machine learning (ML) - or Big Data Analytics (BDA). The overall message is to proceed with caution and realistic expectations...

The report starts by contrasting in detail the old and new types of data being used by the motor and health segments in the European insurance industry: 
  • Existing data sources include medical files, demographics, population data, information about the item/person insured ('exposure data') and loss data; behavioural data, frequency of hazards occuring and so on;
  • New data sources include data from vehicles and other machines or devices like phones, clothing and other 'wearables' (Internet of things); social media services; call centres; location co-ordinates; genetics; and payment data.
Then the report explains the analytical tools being used, since "AI" is a term used to refer to many things (including some not mentioned in the report, like automation, robotics and autonomous vehicles). Here, we're talking algorithms, ML, artificial neural networks (ANN) and deep learning networks (DLN) - the last two being the main focus of the report.

The difference between your garden variety ANN and DLN, is the number of "hidden" layers of processing that the inputs undergo before the results pop out the other end. In a traditional computing scenario you can more readily discover that the wrong result was caused by bad data ("shit in, shit out", as the saying goes) but this may be impracticable with a single hidden layer of computing in an ANN, let alone in a DLN with its multiple hidden layers and greater "challenges in terms of accuracy, transparency, explainability and auditability of the models... which are often correlational and not causative...".

Of course, this criticism could be levelled at the human decision-making process in any major financial institution, but let's not go there...

In addition, "fair use" of algorithms relies on data that has no inherent bias. Everyone knows the story about the Amazon recruitment tool that had to be shut down because they couldn't figure out how to kill its bias against women. The challenge (I'm told) is to reintroduce randomness to data sets. Also:
As data scientists find themselves working with larger and large data sets and working harder and harder to find results that are just slightly better than random, they will also have to spend significantly more time and effort in accurately determining what exactly constitutes true randomness in the first place.
Alarmingly, the insurers are mainly using BDA tools for pricing and underwriting, claims handling, sales and distribution - so you'd think it pretty important that their processes are accurate, transparent, explainable and auditable; and that they understand what results are merely correlated as opposed to causative...

There's also a desire to use data science throughout the insurance value chain, particularly on product development using much more granular data about each potential customer (see data sources above). The Holy Grail is usage-based insurance (UBI), which could soon represent about 10% of gross premiums: 
  • pay-as-you-drive (PAYD): premium based on kms driven;
  • pay-how-you-drive (PHYD): premium based on driving behaviour; and
  • pay-as-you-live (PAYL): premium based on lifestyle, tracking.
This can enable "micro-segmentation" - many small risk pools with more accurate risk assessments and relevant 'rating factors' for each pool - so pricing is more risk-based with less cross-subsidy from consumers who are less likely to make claims. A majority of motor insurers think the number of risk pools will increase by up to 25%, while few health insurers see that happening. 

Of course, micro-segmentation could also identify customers who insurers decide not to offer insurance (though many countries have rules requiring inclusion, or public schemes for motorists who can't otherwise get insurance, like Spain, Netherlands, Luxembourg, Belgium, Romania and Austria). Some insurers say it's just a matter of price - e.g. using telematics to allow young high risk drivers to literally 'drive down' their premiums by showing they are sensible behind the wheel. 

Increases in the number of 'rating factors' is likely to be more prevalent in the motor insurance segment, where 80% (vs 67%) are said to have a direct causal link to premium (currently driver/vehicle details, or age in health insurance), rather than indirect (such as location or affluence).

Tailoring prices ('price optimisation') has also been banned or restricted on the basis that it can be unfair - indeed the FCA has explained the factors it considers when deciding whether not price discrimination in unfair

Apparently 2% of firms apply BDA to the sales process, resulting in "robo-advice" (advice to customers with little or no human intervention).  BDA is also used for "chatbots" that to help customers through initial inquiries; to forcecast volumes and design loyalty programmes to retain customers; prevent fraud; to assist with post-sales assistance and complaints handling; and even to try to "introduce some demand analytics models to predict consumer behaviour into the claims settlement offer."

Key issues include how to determine when a chatbot becomes a robo-adviser; and the fact that some data is normally distributed (data about human physiology) while other data is not (human behaviour).

All of which begs the question: how you govern the use of BDA?

Naturally, firms who responded to the report claim they have no data accuracy issues and have robust governance processes in place. They don't use discriminatory variables and outputs are unbiased. But some firms say third party data is less reliable and only use it for marketing, while others outsource BDA altogether. But none of this was verified for the report, let alone whether or not outputs of ANN or DLN were 'correct' or 'accurate'.

Some firms claim they 'smoothed' the output of ML with human intervention or caps to prevent unethical outcomes.

Others were concerned that it may not be possible to meet the privacy law (GDPR) requirements to explain the means of processing or the output where ANN or DLN is used.

All of the concerns lead some expert legal commentators to suggest that ANN and DLN are more likely to be used to automate decision-making where "the level of accuracy only needs to be "tolerable" for commercial parties [who are] interested only in the financial consequences... than for individuals concerned with issues touching on fundamental rights." And there remain vast challenges in how to resolve disputes arising from the use of BDA, whether in the courts or at the Financial Ombudsman.

None of this is to say, "Stop!" But it is important to proceed with caution and for its users to be realistic in their expectations of what BDA can achieve...


Tuesday, 11 June 2019

New Rules For P2P Lending And Crowd-Investment

A year after consulting on its proposals, the FCA has issued new rules for P2P lending and crowd-investment platform operators from 9 December 2019 (and certain mortgage rules immediately). I'm trawling through the detail, but have summarised the changes below. Let me know if I can help.

Originally, the FCA proposed to:
  • set out the minimum information that P2P platforms need to provide to investors; 
  • clarify what systems and controls platforms need to have in place to support the outcomes platforms advertise - particularly on credit risk assessment, risk management and fair valuation practices; 
  • ensure arrangements are in place that take account of the practical challenges that platforms could face in a wind-down scenario; 
  • extend marketing restrictions that already apply to investment-based crowdfunding to P2P platforms; 
  • apply Mortgage and Home Finance: Conduct of Business sourcebook (MCOB) and other Handbook requirements to P2P platforms that offer home finance products, where at least one of the investors is not an authorised home finance provider - to address a potential gap in protections for home finance customers who undertake transactions through a P2P platform.
Sure enough, the new rules:
  • Clarify what governance arrangements, systems and controls must be in place to support advertised performance (especially credit risk assessment, risk management and fair valuation practices);
  • Strengthen plans for the wind-down of P2P platforms;
  • Apply marketing restrictions to protect less experienced investors in loans;
  • Introducing an appropriateness test for an investor’s knowledge and experience of P2P investments where no advice has been given to the investor, and what the assessment should include; and
  • Specify minimum information that P2P platforms need to provide to investors. 
In addition, P2P platforms that offer home finance products (where none of the investors is an FCA authorised home finance provider) must comply the FCA's Mortgage and Home Finance Conduct of Business sourcebook (MCOB) and other Handbook rules from now. 

Monday, 27 May 2019

Let's Not Confuse E-money Agents and Distributors

The European Banking Authority has issued an opinion that goes some way to clarifying when e-money institutions create an "establishment" when dealing through "agents" and "distributors", though it does not go far enough to be terribly useful (to be covered in another post...). In reaching that opinion, however, it has managed to create confusion over the distinction between agents and distributors. This is unfortunate, given the very significant difference in legal responsibility for the EMI and the time it takes to set up such arrangements - sometimes on a large scale, where chains of small retail outlets or multiple independent online retailers offer prepaid cards, top-up vouchers etc for the issuer.

The EBA accepts that e-money institutions (EMIs) can operate through either:
  • 'agents' who provide regulated payment services on the EMI's behalf and must be registered by the EMI with the regulator; or
  • 'distributors' who do not provide regulated payment services on the EMI's behalf, so the EMI merely has to notify the regulator that the distributor is being used rather than register it.
But the EBA then states that: 
"...if a distributor receives funds from an end-customer in exchange for e-money, the funds are considered to have been received by the issuer itself, considering that the distributor is acting on behalf of the issuer. The safeguarding obligation of the issuer starts as soon as the distributor receives the funds from the customers, and remains with the issuer/EMI (not with the distributor), so that the customer does not bear any consequence of the funds not being transferred from the distributor to the issuer, including in the event of the distributor's insolvency."
I also notice this has also been picked up by the FCA in its guidance on safeguarding in the Approach document, for example:
"10.28 An institution may receive and hold funds through an agent or (in the case of EMIs and small EMIs) a distributor. The institution must safeguard the funds as soon as funds are received by the agent or distributor and continue to safeguard until those funds are paid out to the payee, the payee’s PSP or another PSP in the payment chain that is not acting on behalf of the institution. The obligation to safeguard in such circumstances remains with the institution (not with the agent or distributor). Institutions are responsible, to the same extent as if they had expressly permitted it, for anything done or not done by their agents or distributors (as per regulation 36 in the EMRs and regulation 36 in the PSRs 2017)...
10.34 Where relevant funds are held on an institution’s behalf by agents or distributors, the institution remains responsible for ensuring that the agent or distributor segregates the funds. "
Elsewhere, the FCA states that
5.6...In our view, a person who simply loads or redeems e-money on behalf of an EMI would, in principle, be considered to be a distributor.

However, the FCA states:
8.338 It is important to recognise that if an agent of an e-money issuer receives funds, the funds are considered to have been received by the issuer itself. It is not, therefore, acceptable for an e-money issuer to delay in enabling the customer to begin spending the e-money because the issuer is waiting to receive funds from its agent or distributor.
These passages might be read as supporting the notion that a distributor is entitled to hold funds on behalf of an EMI, albeit in a segregated bank account, and the EMI is entitled to rely on the distributor to transfer those funds to the EMI's account. 

But in my view, if a distributor were to act in that way it would be operating a payment service (e.g. money remittance) and would therefore need to be either authorised in its own right or registered as an agent of the EMI. In other words, there would be no distinction between an agent and a distributor.

In fact, the role of distributor was created in order to avoid the need for agency registration in a particular scenario (e.g. small retailers whom the EMI would find it difficult to be responsible for registering and supervising); or for the distributor to concern itself with regulatory risk and responsibilities. 

The EMI's obligation to register an agent (and, more importantly, liability for the agent's activities on the EMI's behalf) is avoided by requiring the distributor to keep a 'float' of a minimum amount of funds in an account which the distributor agrees the EMI will draw upon whenever the distributor's system reports to the EMI's system that a customer in one of the distributor's outlets has bought a prepaid card or otherwise loaded funds onto a card or wallet issued by the EMI. 

In that scenario, neither the customer nor the EMI is taking any risk at all that the distributor might fail to transfer funds paid by the customer. The EMI has instant access to the float of funds previously paid by the distributor, and safeguards those funds if the e-money issued to the customer is not spent within the next business day.  Meanwhile, the distributor retains any money paid by the customer as effectively reimbursement for the amount that the EMI has deducted from the distributor's float.



Trends In Digital Regulation

There are so many initiatives designed to control the digital world that I'm struggling to keep track. 

There's also plenty of overlap and commonality in the issues and regulatory solutions, as well as the digital environments and problems the solutions seek to address. 

So I put together a few slides for ready comparison. 

Interesting to see what leaps out...


Tuesday, 23 April 2019

Brexit Britain To Gold-Plate 5th EU Money Laundering Directive

Anyone who still dreams that Brexit spells the end of the UK's ménage à trois with bureaucracy and regulation must read the Treasury's plans to implement the fifth EU directive on anti-money laundering.

The UK has always created an EU rod for its own back not only by adding its own weight to the regulatory burden, but also by effectively insisting on literal interpretation of EU law that was only intended to be construed according to its purpose.

This results in directives having a broader impact than they would otherwise have done (known as 'regulatory creep'), saddling British businesses - and ultimately British consumers - with costs they could otherwise avoid.

That is not to say that the UK's approach is always wrong - or is necessarily wrong on this occasion - but the 'blame' for this approach should land in Westminster not Brussels.

In this case, the government proposes to amend the The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 ("MLRs") in the ways I've summarised below. Responses to the consultation paper are due by 10 June 2019 and new regulations must take effect in the UK by 10 January 2020.

Tax advisors
  • The definition of “tax advisor” in the MLRs to include firms and sole practitioners who by way of business provide, directly or by way of arrangement with other persons, material aid, assistance or advice about the tax affairs of other person.
 Letting agents
  • There are numerous options for applying the MLRs to letting agents.
 Cryptoassets
  • The MLRs will apply to service providers engaged in exchange services between cryptoassets and fiat currencies, and wallet providers in a way that includes exchange tokens, security tokens and utility tokens and so would also capture crypto-to-crypto exchange service providers; peer-to-peer exchange of both fiat-to-crypto and crypto-to-crypto between prospective “buyers” and “sellers”); cryptoasset ATMs; issuance of new cryptoassets (including ICOs); and the publication of open-source software (which includes, but is not limited to, non-custodian wallet software and other types of cryptoasset related software).
 High Value Dealers
  • High value dealers are to include art intermediaries for transactions exceeding €10,000, including art galleries, auction houses and free ports/zones (currently none in the UK) regardless of whether they are paid for in cash (raising many questions in the consultation).
 E-money
  • Exemptions for low value e-money instruments will be narrower, as all of the following conditions must be met: the maximum amount that can be stored electronically is €150; it either can't be reloadable or must have a maximum limit on monthly payments of €150 which can only be used in that Member State; used exclusively to purchase goods and services; can't be funded with anonymous e-money; and any single cash redemption or remote payment cannot exceed €50. In addition, EEA acquirers can only accept payments made with anonymous prepaid cards issued in non-EEA countries that impose equivalent AML requirements; and Members States may prohibit payments carried out using anonymous prepaid cards.
E-identification services
  • The new requirement for electronic identification processes is for them to be “regulated, recognised, approved or accepted at national level by the national competent authority” which raises questions about which forms in the UK are implicitly within scope.
Companies and officers
  • Firms will be required to determine and verify the law to which a body corporate is subject, its constitution and the full names of the board of directors and the senior persons responsible for the operations of the body corporate.
Where beneficial owner cannot be identified
  • If a firm has exhausted all possible means of identifying the beneficial owner of a body corporate and hasn’t succeeded, the firm must keep written records of its actions, but such firms will now need to take further measures to verify the identity of the senior person in that body corporate and keep written records of those actions.
Understanding the customer's business/structure
  • Firms will be required to understand the nature of their customer’s business and its ownership and control structure (rather than just being required to take "reasonable measures" to do so).
Filing SARs when due diligence fails
  • Firms must cease transacting and file a suspicious activity report (SAR) when they cannot apply their due diligence or additional or enhanced measures.
Proof trust/company register was searched
  • Firms must also collect proof of registration or an excerpt of the register from the company or the trust that is subject to beneficial ownership registration requirements before a new business relationship is established.
Apply due diligence when beneficial ownership must be reviewed
  • Firms must apply due diligence when they have any legal duty in a calendar year to contact the customer for reviewing their relevant beneficial ownership information.
Enhanced due diligence where high risk countries involved
  • Firms must apply a newly defined set of enhanced due diligence measures, and monitoring, to business relationships and transactions involving high-risk third countries.
Lists of PEP functions to be taken into account
  • The responsibility to apply enhanced due diligence on Politically Exposed Persons (PEPs) will be able to be be discharged by applying the FCA’s July 2017 guidance on how firms should take into account a list of functions in determining whether an individual is a PEP for the purposes of the MLRs.
Information on beneficial owners to be publicly available
  • The government must ensure that information on the beneficial ownership of corporate and other legal entities is accessible by members of the general public and “mechanisms” must be in place to ensure that the information held on the central register is adequate, accurate, and current; while the UK must also take appropriate actions to resolve any reported discrepancies in a timely manner and, if appropriate, include a specific mention in the central register in the meantime.
Trusts to be registered
  • Trustees or agents of all UK and some non-EU resident express trusts must register those trusts with the Trust Registration Service, whether or not the trust has incurred a UK tax; and the government must share data from the register with a range of persons under certain circumstances.
Bank account registries
  • The UK must establish a centralised registry or online retrieval mechanism which allows identification of natural and legal persons who hold or control bank accounts; payment accounts; or safe-deposit boxes held by credit institutions within the UK - including names and account/identification numbers.
Pooled client accounts of unregulated operators
  • The government wants further evidence on the administration of checks relating to the use of pooled client accounts (PCAs) under the MLRs, especially those held by non-regulated businesses and any evidence of abuse; and the practical barriers industry face in implementing the current framework and it could be 'enhanced'.
AML risk assessments for new products, practices and channels
  • Firms will need to undertake AML risk assessments prior to the launch or use of new products, new business practices and delivery mechanisms.
Provision of Information by branches and subsidiaries
  • Firms must have policies relating to the provision of customer, account and transaction information from their branches and subsidiaries.

The UK will not require that "whenever a customer makes their first payment involving a designated high-risk third country, that payment is carried out through an account in the customer’s name with a credit institution subject to the Directive’s customer due diligence standards."




Tuesday, 9 April 2019

The EU Boosts Consumer Protection For The Digital Age

Next week, the European Parliament will significantly boost consumer protection in the EU by approving changes to 4 directives on consumer rights. Member states will have 2 years from publication in the Official Journal to implement the changes. The Enforcement and Modernisation Directive amends:
  • The Unfair Commercial Practices Directive (implemented in the UK by the Consumer Protection from Unfair Trading Regulations 2008);
  • The Consumer Rights Directive (implemented in the UK by the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013);
  • The Unfair Contract Terms Directive (implemented in the UK by the Consumer Rights Act 2015);
  • The Price Indications Directive (implemented in the UK by the Price Marking Order 2004). 
Online traders and marketplaces. 

There are new information obligations for online traders and marketplaces. These include pre-contract disclosure obligations for online marketplaces; and failure to include the information in an invitation to purchase is both a misleading omission and a blacklisted commercial practice (in some cases for all traders and in some cases just for online marketplaces). 

Traders must provide the criteria used to rank search results (a misleading omission for all traders offering search facilities, and required pre-contract information for online marketplaces). Failure to clearly indicate that search results have been paid for is a blacklisted commercial practice. 

The trader must state whether it verifies reviews (and, if so, how). Submitting fake reviews is a blacklisted commercial practice. 

The status of the seller must be disclosed (a misleading omission and pre-contract information requirement for online marketplaces). 

Whether the consumer will benefit from consumer protection law and how contractual obligations are divided between the seller and the online platform are pre-contract information requirements for online marketplaces. 

All traders must state whether there is any personalisation of the price on the basis of automated decision-making.

Dual Quality Products

The practice of selling dual quality products can be deemed misleading, i.e. where the product is marketed in one member state as being identical to the goods marketed in other member states, while the composition or characteristics are significantly different (unless justified by legitimate and objective factors). Dual quality has been identified as an issue in fish fingers, instant soup, coffee, soft drinks, detergents, cosmetics and baby products.
 
Ticket bots

There is a ban on the use of ticket bots to bulk buy tickets for resale (a practice already dealt with in UK legislation).

Digital services and good with digital elements

To align the Consumer Rights Directive with the draft Digital Content Directive there are new definitions of “digital services” and “goods with digital elements”. These are caught even where they are provided only in exchange for personal information; and there are provisions dealing with the use of personal data and user generated/contributed content after cancellation.

Communicating with traders
 
Traders must provide pre-contract information about online means of communication including use of chat bots or other technology (but reference to fax numbers is deleted) and the technology must enable the consumer to store any written correspondence, including the date and time, on a durable medium. But where the trader is contracting via means with limited time or space to communicate (e.g. text) the trader need not provide the model withdrawal form.

Reference prices for discounts

Any reference price used to indicate a discount must have been in use for at least a month (subject to  exceptions/derogations.

Complaints/redress

The European Commission must use the single digital gateway to inform consumers of their rights and enable them to submit cases to the Commission’s Online Dispute Resolution Platform. Consumers will also have new rights to seek redress directly from traders

Penalties for breach

Member states must impose penalties for breaches of the national consumer protection law implementing the amendments, including the ability to fine businesses up to 4 % of the trader’s annual turnover in the member state or member states concerned, or, if turnover information is not available, up to at least €2 million. 

Where national law may differ 

The Unfair Commercial Practices Directive and the Consumer Rights Directive are 'maximum harmonisation' directives, meaning member states cannot depart from them except in ways that are expressly permitted ('derogations').  New permitted derogations (provided they are proportionate, non-discriminatory and justified by consumer protection) relate to:
  • Online marketplaces: member states can impose further information obligations on these; 
  • Contracts concluded as a result of unsolicited home visits or excursions organised by a trader: a longer cancellation period for contracts agreed in these situations, from 14 to 30 days; and/or removing exceptions to the right to cancel where the services begin early with the consumer’s consent, the price depends on fluctuations in the financial market, the goods are made to the consumer’s specification or clearly personalised or the goods are sealed for health or hygiene reasons have been unsealed;
  • Solicited visits for home repairs:  the consumer's right to cancel can be removed for contracts involving repairs carried out on a solicited home visit where certain conditions are met.

Friday, 15 March 2019

E-commerce Marketplaces, Commercial Agents and PSD2

E-commerce marketplaces are now common in most sectors, enabling suppliers and consumers of all types of goods and services to find each other, contract directly, pay or be paid, arrange delivery and download their transaction data. But action being taken by some payment service providers (PSPs) suggests that many marketplace operators who offer this service in the European Economic Area may not have realised that the payment step needs to be structured in a way that avoids the need for the operator to be authorised by an EEA financial regulator as a payment institution or e-money institution under the Payment Services Directive or E-money Directive (depending on whether the supplier or customer is able to hold a balance in their 'account').

Some financial regulators, like the UK's Financial Conduct Authority, take the view that offering a payment service or e-money service has to be the operator's regular occupation or business in itself to fall within the scope of the PSD or EMD in the first place (the "business test"), although the payment step would need to be a small, ancillary part of the service offered and this is open to interpretation. But less pragmatic or experienced regulators around the EEA might apply the Directives simply because the operator is running a business of any kind. 

This means operators should err on the side of structuring their activities to avoid holding balances and to take advantage of an exclusion under the Payment Services Directive (e.g. for commercial agents authorised to negotiate or conclude contracts on behalf of either the payer or payee); or involve a PSP to handle the receipt and distribution of funds (or become the registered agent of a PSP). 

Other exclusions under the PSD or EMD may also be helpful. But even relying on an exclusion can be somewhat tricky because the interpretation of exclusions can vary from regulator to regulator across the EEA; and there is no 'passport' for one regulator's interpretation as there is for regulated PSPs who can offer their service across the EEA from under authorisation in their home member state. 

That means an operator should seek legal advice on how to structure its activities appropriately under the law of its home EEA member state; and if that involves relying on the local regulator's interpretation of the business test or an exclusion, the operator should check that analysis works under the law of each member state where the operator has a presence or significant numbers of participants (whether suppliers or their customers).  Acting on formal legal advice should also make it less likely that a regulator will take action for acts or omissions consistent with that advice, although it will not necessarily stop a regulator requiring a different structure going forward.