Showing posts with label mobile payments. Show all posts
Showing posts with label mobile payments. Show all posts

Mobile Payments have arrived


Just arrived during the early morning in Egypt, showered and had breakfast. As I walked into the conference hall of the Summit, I had such a positive experience. I have been working on this dream of mobile payments being available to all for so long. Sometimes, I almost got despondent, but this morning I knew: Mobile Payments have arrived. The level of interest and the seniority of the participants was an indication that this is now for real.
The conference was different to many in the past that I attended in the following ways:
a. Representatives were truly from everywhere. Previous conference had a very regional character. Either Asian, American or European. This time round it was from every continent. Interesting that it should be happening in Africa...
b. The level of participants were of a very senior level: CEO's of major corporations, Ministers and senior officials
c. A general spirit of: "Let's build the industry" rather than criticise each other prevailed.


Gartner is cautious

Gartner produced research indicating that mobile payment subscribers will increase from 33 million to 104 million subscribers in the next three years. This is quite conservative compared to some of the other recent results (see my blogs on this here and here) that were produced by other research companies. Especially their estimate of (only) 500 thousand mobile payment subscribers in Europe at the moment. I think companies like paybox in Austria would be surprised that they have more subscribers in Austria than those that Gartner counted in Europe... wait a minute, last I checked Austria was in Europe. Also the fact that they did not count African subscribers - does that mean that they do not know about the massive penetration of mobile payment subscribers in Africa (my estimate between 7 and 12 million), or that Africa does not exist?

I still remember a previous estimate that Gartner got terribly wrong: the "75% probability that 60% of companies were not ready for Y2K" predication. After all the angst that they produced during 1999, maybe policy now is that they should play everything down?

So what about NFC?

I have been critical of many things on my blog. I have highlighted the problems with premium SMS's, Internet payments, Chip and Pin and many other approaches to solving payment problems. In the same way I have discussed problems that I see with NFC solutions (As far as I can re-collect twice: here and here)

I don't think that we can ignore the growing interest in NFC payments and when today I was asked twice why I don't support NFC payments, I realised that I should post a firm position on this blog.

Card-based proximity payments is nothing new. We have stirling examples of these having been deployed successfully. I am the proud owner of a Oyster Card myself (even though I don't live in London). I really enjoy seeing how seamless everything work, each time I have to use the underground.

So here is my position: To merely replicate these kind of payments by replacing the card with a mobile phone does not add much value, and I believe that most business cases will be rickety. If we were to utilise the new NFC capabilities in phones, I think it is critical to be much more innovative about these features. Some of the things that we should possibly develop (not an exhaustive list) is:
  • On phone wallet applications
  • Phone to phone NFC interaction (I personally think that this is one potential killer app)
  • OTA issuing (another killer, but extremely complex and challenging)
  • Mobile data interactions between the application on the phone and back-office
At the end of the month, I will be speaking at a high-level NFC conference. I was invited...

Regional Regulations

This is something that have always intrigued me. Everyone that knows would agree that none of the countries that constitute the Eurozone is the same. Especially if one were to consider the different payment solutions and customer orientation towards these, one observe massive differences. Some countries are still heavily dependent on cash payments, while others have installed sophisticated PIN-based payment systems. In some it is acceptable to do Internet payments and in others cheques are still in circulation.

Especially, if one were to consider mobile payments, differences are even more distinct. Initiatives in Nordic areas are not at all comparable to what is happening in Austria nor some of the great work happening in the Iberia peninsula. The challenges regarding money supply and cost of doing business are all different from one country to another.

So here is my question: "How can you regulate all these different countries with the same banking regulation?"

The Emperor without clothes

This is something about the Mobile banking and payment (MB&P - I have decided to acronymise this term now, because I use it such a lot) industry. We have more than our fair share of people and companies that make claims that is so far removed from what is possible and also what they are obviously capable of. This is possibly because such a lot of people have turned MB&P into something romantic - the next big thing...

One of the best know examples of a nude emperor were of course Simpay. While this organisation were busy with grand schemes in Europe, many were modeling their strategies on what Simpay was supposed to deliver. Many millions of dollars were spent on this grand plan that most of the industry was expecting to come true. I recall companies that were basing their whole product strategy on the assumption that Simpay would have dictated the standards for mobile payments. Yet for a lot of us (especially those that were intimately involved with the industry), we did not see any clothes. We did say so, but not too loudly, because others were looking strange at us.

There are other examples, I believe. Some with grand plans and ever more spectacular visions. Who will be brave enough to name them this time round. Well, let me give you a clue: A nude emperor this time round have a name that starts with F and have just been acquired by a company with a name that starts with Q.

What do you think?

Killer applications

Most would agree that doing payments or banking is not fun. It is not something that we would do if we could help it. (Well, maybe with the exception of receiving payments!). To provide sexy banking services is a contradiction in terms in my book. This is one of the reasons why mobile banking and payments will never prove to be successful unless it can be used for something, ... well sexy.

The mobile banking and payment industry refer to these things that you can do with mobile banking and payments as the "killer applications". Giving access to your consumers to "killer applications" that they can pay for easily on their mobile phone is the trigger (and key) to a successful mobile banking/payment implementation. In this blog-post, I list a few categories of what applications have been "killing" and which ones are likely to "kill" in the future.


The most frequently quoted killer application is the ability to buy pre-paid airtime directly from your bank account using a mobile phone. I have heard some observers talk of this as being not that sexy, but some of the case studies are immense and only thing I would say is:"ignore air-time purchases at your own peril"

Others that have already been implemented and have proved to be successful are bill payments (low margins are the biggest challenge here), cash on delivery (big money here), payment for parking (requires enough cars and less parking to work - not the case in many countries), some examples of retail payments, payments for content and other pre-paid (e.g. pre-paid electricity).

Payment for the purchase of lottery tickets and other gambling applications have been implemented by a few operators, but it is my opinion that this has not proved to be that successful. I am of the opinion that this is because we have not yet figured out how to do this effectively on mobile phones - so that it works for the new form factor. Many people have ideas on how to turn this into killing applications, but I have not seen them yet.

Others that should also be mentioned in this blog are of course money remittance. Many examples of this type of application have been deployed with good successes. The challenge in this area is working with regulatory constraints and to turn localised deployments into global deployments.

Other killers that I sense are lurking will come from micro lending, export/import, other financial services and many niche applications (like transport, medical, content etc.)

Once again, what do you think?

Where is the money?

Mobile payments is an interesting concept. I have heard a lot of people talking about how making payments from a cellphone could be earth-shattering - how it would change the way that people shop and do business for ever. And I believe that they are right, but in order to make this vision happen we have to solve a difficult problem... where is the money?

No, I don't mean, how we are going to make money by running a mobile payment scheme. I mean, what are people going to use as money to pay with. If they complete a transaction and they hit "send" (or "pay") where will the money come from to do this payment. To put it in another way: "which account will be debited". Many different solutions have been suggested and implemented, but all have significant challenges. Below is a summary of some of the Value Stores that could be used as the money in mobile payments:
  • Using an existing credit card as the source for doing a mobile payment would seem to be the most obvious approach. This has successfully been implemented, but suffers from the following challenges: A relatively small percentage of people with mobile phones have credit cards globally, the transaction can be expensive as credit card fees must be paid before any other revenue can be generated and the rigid (but sound) rules regarding fraud places a very big risk on such an approach.
  • Using the mobile operator's billing engine as the source for payments have been proposed, but this approach can even be more expensive than credit card transactions. (See one of my previous blogs) . In addition, expect regulatory problems and significant challenges to extract cash out of the system. It is also unlikely that the mobile operator would be happy with sharing money earmarked for telecommunications with other retailers.
  • Utilising existing bank accounts could be interesting, but integrating telecommunication systems to core banking systems can be expensive and time-consuming. Also the strain on a banking system when millions of small transactions starts hitting it, can be outside the design limits of such a system.
  • A new dedicated mCommerce account may be the way to go. Remember that when credit cards (a new payment system) were launched in the 1970's, it came with its own dedicated account management system. Why should that not be the case for mobile payments?

A perspective on Mobile Payments in Europe


Europe’s venture into mobile banking is characterised by many small initiatives that all failed. A case in point is the example of small Dutch company Global Payways with a product called Moxmo launched during 2003 with a mild take-up in the Netherlands. During the collapse of Paybox, Global Payways acquired the subscriber base of Paybox in Germany. This small company was soon in financial difficulties and had to disband services within six months of having taken over the larger subscription base. (Many reference, but read the following blog.)

Soon afterwards major mobile operators announced the Simpay alliance. Simpay endeavoured to provide a common payment platform between Vodafone, T-systems, Telefonica and Orange. While the European industry waited, Simpay had the central stage for three years and produced… nothing. This fiasco had a lasting impact on the European mobile payment industry.


A company that is quite visible at the moment is a company called Monitise. An initiative started by Morse with a Java based service on top of the ATM network is now being deployed by 1st Direct, HSBC and Alliance & Leicester. The company is very visible (because of a large marketing budget?) and is making big headway from a brand building perspective, but the technology offer little functionality to the subscriber. Recently Monitise listed on the LSE raising a substantial amount to fund the current burn-rate. Another company with a similar profile is the Finnish company called Meridea. With backing from Nokia and Accenture this company was the technology behind amongst others Standard Chartered mobile banking initiative. Unfortunately it closed its doors a few months ago when they ran out of funds.


A noteworthy deployment is the mobile payment solution supported by Banksys in Belgium. Banksys is the central ATM and POS switching company owned by the major banks. Banksys recently announced a SIM card based solution supported by all the major mobile operators that allows subscribers to make payments from their existing bank cards utilising the mobile phone.


The deployment of Paybox in Austria is still operational today and very successful. The service is available on more than one network, provides excellent functionality and utility and is used by close to half a million people on a regular basis. (This is quite a big coverage considering the size of Vienna where most of the subscriber services are available). The service is claimed to be profitable and is one of the best examples of a mobile payment solution that ultimately became successful because of dedication of management.

PCI compliance for mobile payments

Many research reports and experts warn about the risks of allowing fraudsters and criminals access to sensitive credit card details. It is especially operators of financial and payment services that tend to be the biggest targets. Quoting Jon Kerr from Verisign: "It's no surprise that online banks and retailers are some of the most popular targets for identity theft since so many personal details are required by users,... With the average UK consumer worth over £10,000 to criminals, it's clear that each of us is a target."

It is because of this threat that the industry decided to publish a standard that a bank or payment processor should adhere to in order to provide acceptable protection to cardholders. This certification is known as the PCI compliance and is being driven by the Credit Card Associations. The objective of PCI compliance - to protect the consumer - is commendable and should be accelerated. Customers should be educated and should take their business away from banks and payment operators that do not comply.

An interesting question is how the providers of mobile payment solutions should (or should not) comply with PCI standards. In as much as mobile payment solutions touches card information the application of the standard is clear: None of the card information must be in the clear and it must not be possible for an un-authorised person to get access to this information. But what if no credit card information is used? What if the routing of payments are made on the basis of a subscribers telephone-number (as is often the case)? What should the minimum conformance be.

This topic is much more complex to deal with in the space of a short blog, but it is clear that the mobile payment industry should develop unique compliance requirements. Obviously this would be very similar to Card PCI compliance (catering for instance for access, un-authorised actions, reporting, physical protection etc.). But what about not displaying a telephone number when you could potentially see phone numbers of some-one just call you? What about look-up tables and what should the controls be around security elements?

It could be worthwhile to develop some of these rules pro-actively.

INCSR getting involved


I didn't know that the US Department of State pay good money for people with complex names like the Bureau of International Narcotics and Law Enforcement Affairs to produce reports like the International Narcotics Control Strategy Report (the INCSR). I cannot comment on the rest of the report, but the section that talks about "mobile payments - a growing threat" triggered my interest and I read it with attention.

I must say that the sentiments expressed and the conclusions reached is so far removed from the practices or the intention of the mobile payment and remittance industry. Very few of the statements regarding risks and lack of controls have been verified or tested against the existing practices employed by mobile payment vendors. Compliments to the authors for publishing the report on the Internet. (Read it here). Unfortunately, I could not find any feedback mechanism that would have enabled me to communicate with the authors in order to rectify many of the inaccuracies.

In practice, great care is taken to ensure that subscribers are enrolled with proper KYC compliance. The implications of the Patriot act and FinCEN are carefully researched and deployed to ensure compliance. Most of the vendors in the industry (and I know most) have a genuine intent to build an accessible electronic financial infrastructure for the poor, but that will also eliminate (and block) the actions of criminals and terrorists. These vendors work with the Worldbank and associated agencies (like CGAP) and reputable banks and other financial organisations to try and build well-governed solutions to the massive problem of the poor that is effectively eliminated from modern financial services.

The statements in the report not only harm the delivery of financial services worldwide, but also delay the deployment of electronic tools that would enable legit agencies to monitor transactions and to identify fraudulent and illegal activities. I would like to urge the author of the above report to contact representatives from the mobile payment industry so as to clarify mis-understandings, but also to assist the industry to build better (for all) financial instruments.

Value Store System

It is impossible to provide a payment system (any payment system) without connecting (or being able to access) some kind of value store. A credit card based payment system must debit a credit card account and an EFT payment system must debit a bank account somewhere along the line. This is the case for mobile payments too. Without being able to debit (or credit) some kind of value store, it would be impossible to deploy a payment system.

Most mobile payment solutions provide a mobile payment experience that integrate into an existing value store. For instance, mobile banking solutions that provide a mobile channel to existing bank accounts or mobile payment solutions that mobile enable an existing credit card. The challenge with these solutions is to ensure a seamless integration to the existing systems. Some of the challenges is to ensure that the registration process (when a mobile phone gets linked to a credit card for instance) does not create an opportunity for fraud. Also the boundaries and rules related to liabilities and disputes are not always easy to implement consistently.

Other solution providers (only a few) provide the ability to open a new type of value store that can be utilised to perform mobile payment transactions with. This facility is particularly interesting in markets where more people have mobile phones than does have bank accounts or credit cards. The advantage of this approach is that the value-store can be designed in such a way that it is much more tightly integrated with the mobile payment solution. At the same time many challenges must be overcome, like conformance to regulations, compliance with international protocols and the ability to perform audits and reconciliations that will be acceptable to a central bank.

The selection of and deployment of the value store element of the solution is probably the most important decision that can be taken. The different components that must ideally be present in a mobile enabled value store are:
  • Real-time clearing
  • Push and pull payment support
  • Support for a multitude of primitive transaction types
  • Security paradigms compatible with mobile enablement
  • Ease of use
  • Transparency
The key to deciding on a value store strategy should not be dictated by available technology, but rather be based on market realities and business objectives.

Premium SMS futures

I have often been asked why Operators don't drop the share of Premium SMS's, so that this is not such an expensive payment instrument. The fact of the matter is that they can't. Many cost elements are built into SMS's that must be recouped by the Operator and they just don't have the lee-way to discount more. One may argue that it does not cost the Operator anything to deliver an SMS from a technology perspective and this is of course correct.

But a review of the other cost elements (especially regarding distribution, billing and in-built inefficiencies), have created a cost structure that represents (according to my calculations) in the region of 25% of the amount billed to the customer. It is therefor impossible for the operator to reduce their portion of a premium SMS billing much below 30%.

As such, a premium SMS is a highly inefficient payment mechanisms (for the operator, the service provider and the subscriber). As a matter of fact, the availability of an alternative payment mechanism will benefit the total mobile payment eco-system. It would be interesting to see the development of this into the future.