No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Featured

Top Banking Regulations & Security Compliance Requirements for 2018

by Michael Magrath
August 28, 2018
in Featured, Financial Services
businessman struggling under weight of PSD2 block

The Developments Impacting Financial Institutions Now

It’s hard to wrap your head around all the myriad regulations for financial institutions, and these changes can directly impact an organization’s digital transformation initiatives. Many countries are calling for further regulation, while in the U.S. we’re seeing reform and deregulation, as evidenced by the repeal of the Dodd-Frank Act. Global regulation and standards expert Mike Magrath presents the top regulations, laws and standards you need to pay attention to.

There is a lot happening in regard to regulation for financial institutions (FIs) around the globe. In many countries, there is a drive for further regulation; meanwhile, in the U.S., we are seeing bank regulation reform and deregulation, as evidenced by the repeal of the Dodd-Frank Act. Below, we’ve compiled the top regulations, laws and standards impacting financial institutions this year:

Dodd-Frank Repeal

In May 2018, President Trump signed into law the Economic Growth, Regulatory Relief and Consumer Protection Act, commonly known as the Dodd-Frank repeal. While this law removes many of the regulations imposed on banks in the wake of the Great Recession, it also bears particular relevance to mobile banking and e-signatures.

The new law includes a provision called the MOBILE Act (Making Online Banking Initiation Legal and Easy). This provision makes it easier for banks to onboard new customers remotely without the need for the customer to travel to a branch to complete the process. Banks can now create an entirely digital onboarding process by verifying a scan or digital copy of a new customer’s government-issued identification, such as a driver’s license. While some states already allowed banks to accept a scanned driver’s license as proof of identity, the Dodd-Frank repeal makes it legal at a national level. From there, the customer can complete the necessary forms and enter data online or via mobile and even sign documents using an electronic signature to finalize the process.

In addition, e-signatures can also play a role in verifying key customer information. When a prospective client tries to open a new account, the client must provide his or her name, date of birth and Social Security number. The back office verifies this information with the Social Security Administration (SSA) through a program called the Consent-Based Social Security Number Verification (CBSV). Before the Dodd-Frank repeal, neither banks nor customers were able to submit an e-signature to initiate this process. They would be forced to download, print and sign a hard copy of the form; scan and upload the form to their computer; and finally email the form to a third-party provider or upload it to a third-party portal. The Dodd-Frank repeal directs the CBSV to accept electronic signatures for this process. This process is extremely important for preventing identity and fraud attempts, and now with the Dodd-Frank Repeal, it will also provide convenience for the consumer and efficiency for the bank.

PSD2: Payment Services Directive 2

Banks and third-party providers (TPP) have to comply with the Payment Services Directive 2 (PSD2) requirements on strong customer authentication by September 14, 2019. Following publication of the final PSD2 Regulatory Technical Standards (RTS), financial institutions are actively preparing and implementing their PSD2 compliance strategy. In doing so, FIs should be aware of these PSD2 criteria:

  1. Strong customer authentication: Authentication must be based on two or more factors, including passwords or PIN, tokens or mobile devices and biometrics.
  2. Transaction risk analysis: PSD2 mandates the use of transaction risk analysis to deter fraudulent payments.
  3. Dynamic linking: For payment transactions, the authentication code must be dynamically linked to both the amount and payee.
  4. Mobile app security: Payment service providers must adopt security measures to mitigate the risk resulting from compromised mobile devices. PSD2 also mandates the use of dedicated mobile app cloning countermeasures in applications, also known as replication protection.

GDPR: General Data Protection Regulation

On May 25, 2018, the GDPR became the main legal framework for data protection in the EU. The objective of the GDPR is to give control over personal data to EU citizens and residents. No matter where they are based, companies that handle data belonging to EU citizens must comply with the GDPR or face severe financial penalties.

To comply, the European Union Agency for Network and Information Security (ENISA) recommends implementing two-factor authentication, as well as mobile application security, to protect access to systems that process personal data.

In addition, for the GDPR consent requirement, e-signature technology is an appropriate means to comply. Electronic signature technology can be used to capture consent from customers. It can also be used to sign contracts between data controllers and data processors.

NYDFS: New York State Department of Financial Services

The NYDFS regulates approximately 1,500 banks and financial institutions. Many international institutions with operations in New York fall under the DFS regulation. The DFS published its Cybersecurity Requirements for Financial Services Companies, which includes 22 provisions requiring financial services organizations to better protect data. Through a risk assessment, financial institutions must implement effective controls to prevent unauthorized access to information systems or nonpublic information. These controls may include multifactor authentication, biometric authentication and risk-based authentication.

PCI DSS 3.2: Payment Card Industry Data Security Standard

PCI DSS 3.2 is an information security standard for organizations that handle branded credit cards from the major card brands. The standard was put in place to address security threats to customer payment information. All entities involved in payment card processing are regulated by the PCI DSS, including acquirers, issuers, merchants, processors and service providers. It also applies to all other entities that store, process or transmit cardholder data.

Requirement 8.3, which became mandatory on February 1, 2018, requires organizations to incorporate multifactor authentication for all nonconsole access to the cardholder data environment, as well as remote network access originating from outside the entity’s network.

Trends and Highlights Across the Rest of the World

In addition to the regulatory changes in Europe and North America, we are also seeing a growing trend toward open banking initiatives around the world. Countries such as Australia, Hong Kong, Singapore, and Japan have all moved to an open banking policy.

Beyond this trend, there are a number of legislative and regulatory highlights to mention in other areas of the globe.

Recent Latin American Regulations:

  • Brazil: The House of Representatives Bill of Law No. 53/2018 was passed by the Senate in July 2018. The law regulates the processing of personal data in both the public and private sector.
  • Chile: Chile passed significant amendments to Law No. 19,628 on the Protection of Private Life. The amendment was passed in August 2018 and regulates the protection and processing of personal data. Furthermore, the law creates a new agency responsible for data protection.
  • Bermuda: The country passed an ICO Bill and Digital Asset Business Act as part of their strategy to attract cryptocurrency and blockchain companies. This law revises the Banks and Deposits Companies Act 1999 with provisions more agreeable to tech industries. It also classifies these companies under a new category, called restricted banks.

Recent Asia-Pacific Regulations:

  • Australia: Australia will be implementing a phased rollout of the open banking regime beginning July 1, 2019. Australia’s four major banks (with nonmajor banks to follow) must give consumers access to, and control over, their banking data. This includes data related to mortgages, credit and debit cards, deposits, personal loans and more.
  • Singapore: The Monetary Authority of Singapore (MAS) has directed all financial institutions to tighten their customer verification processes. Effective immediately, additional information beyond name, NRIC number, address, gender, race and date of birth must be used for customer verification before undertaking transactions with the customer. This extra information could include a one-time password, PIN, biometrics, last transaction date and other authentication information.
  • Malaysia: As part of an anti-money laundering and counter-terrorist financing initiative, reporting institutions are now required to perform ongoing due diligence on their business relationships with their customers.

Legal Regulations and Opportunity

We’re in a period of flux in the regulatory stance of countries around the world. Whether heading toward greater restrictions or deregulation, change is coming in one form or another. For that reason, it is imperative to stay current on the latest regulatory changes as well as new proposals being discussed in the jurisdictions in which you operate. They may have a crucial impact on your digital transformation initiatives.


Tags: BankingDodd-Frank ActGDPR
Previous Post

CompliancePoint Announces New White Paper on Data Breach Security Measures

Next Post

8 Realities in Managing Cyber Risk

Michael Magrath

Michael Magrath

Michael Magrath is vice president of global standards and regulations at OneSpan and is responsible for aligning OneSpan’s solution roadmap with standards and regulatory requirements globally. He is co-chair of the FIDO Alliance’s government deployment working group and is on the board of directors of the Electronic Signature and Records Association (ESRA). He also served as a member of the board of directors for the Identity Ecosystem Steering Group’s (IDESG) and was chair of the Health Information Management Systems Society (HIMSS) identity management task force. Prior to OneSpan, he served as director for identity solutions for DrFirst, a leading U.S. health IT solution provider and focused on streamlining and securing the identity management process for healthcare providers nationwide and increasing the adoption of electronically prescribing controlled substances (EPCS).

Related Posts

sudden change

When Deregulation Means More Work: The Compliance Professional’s Paradox

by Elaine F. Duffus
June 3, 2025

Whipsaw changes can multiply workload for compliance teams

boundary line on roadway

Reckless or Just Unprepared? How UK Tribunals Are Drawing Lines on Financial Integrity

by David Hamilton
June 2, 2025

Courts increasingly distinguish between personal failings and systemic compliance gaps when assessing whether financial professionals acted with integrity

cfpb building sign

What Does Weakened CFPB Mean for FinServ Compliance?

by Carrie Pallardy
April 30, 2025

State-level enforcement, private rights of action & public perception all call for staying the course

origami tiger

Paper Tigers Won’t Protect You: The Reality of Effective NIS2 Compliance

by Hans Kayaert
March 24, 2025

Why Belgium's early adoption model could prevent another round of ‘compliance theater’ across Europe

Next Post
cybersecurity concept padlocks on binary code

8 Realities in Managing Cyber Risk

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights