0% found this document useful (0 votes)
7 views10 pages

Biometric Authentication for Card Security

This study explores the feasibility of implementing biometric authentication systems to enhance security in South Africa's banking sector, particularly to combat card fraud. It found that while the existing banking and telecommunications infrastructure can support such systems, concerns about high transaction volumes and costs may hinder banks from adopting them. The research highlights the need for skilled IT personnel and suggests that biometric systems could significantly reduce card fraud if properly implemented.

Uploaded by

Cancel For u
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views10 pages

Biometric Authentication for Card Security

This study explores the feasibility of implementing biometric authentication systems to enhance security in South Africa's banking sector, particularly to combat card fraud. It found that while the existing banking and telecommunications infrastructure can support such systems, concerns about high transaction volumes and costs may hinder banks from adopting them. The research highlights the need for skilled IT personnel and suggests that biometric systems could significantly reduce card fraud if properly implemented.

Uploaded by

Cancel For u
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

South African Journal of Information Management

ISSN: (Online) 1560-683X, (Print) 2078-1865


Page 1 of 9 Original Research

A qualitative analysis of the feasibility of deploying


biometric authentication systems to augment
security protocols of bank card transactions

Author: Background: This study investigated the end-users’ perceptions about the feasibility of
Joel M. Chigada1
deploying biometric authentication systems as intervention solutions to ameliorate card
Affiliation: fraud in the South African payment card industry.
1
Department of Information
Systems, Faculty of Economic Objectives: The objective of the study was to determine if the existing banking technology and
and Management Sciences, telecommunications infrastructure were capable of supporting biometric payment systems.
University of the Western
Cape, Cape Town, Method: In this qualitative research, interviews were conducted with 30 sample elements
South Africa selected from commercial banks, telecommunications companies and other service providers.
Corresponding author:
The sample included individuals working with banking back-end technologies,
Joel Chigada, telecommunications service providers and credit card fraud experts.
chigadajm@[Link]
Results: The study established that banking technology and telecommunications infrastructure
Dates: were capable of supporting biometric payment systems. It was revealed that the deployment
Received: 29 Jan. 2020
of biometric systems would mitigate card fraud transactions. However, findings showed that
Accepted: 03 Aug. 2020
Published: 10 Dec. 2020 introduction of zero-floor limits led to high traffic volumes, creating congestion on the
telecommunications connectivity. Thus, there was a high likelihood that transaction processes
How to cite this article: would be slow during peak periods.
Chigada, J.M., 2020, ‘A
qualitative analysis of the Conclusion: The implementation of biometric systems required highly skilled information
feasibility of deploying
biometric authentication technology personnel to oversee and support these technologies. This was identified as a
systems to augment security potential hindrance for banks. The study established that existing banking and
protocols of bank card telecommunications infrastructure was capable and supported biometric systems. Banks were
transactions’, South African
not keen to invest in an outright biometric environment because of the huge costs that would
Journal of Information
Management 22(1), a1194. be incurred in implementing advanced technologies.
[Link]
sajim.v22i1.1194 Keywords: biometric authentication; card fraud; security protocol; telecommunications;
cybersecurity.
Copyright:
© 2020. The Authors.
Licensee: AOSIS. This work
is licensed under the Introduction
Creative Commons
The credit card industry in South Africa has grown at an enormous rate over the past 20 years.
Attribution License.
However, this rapid growth has created many new opportunities for cybercrime syndicates.
The rapid increase in bank card fraud and cybercrimes is worrisome for financial institutions,
merchants, credit card holders and issuers (whole economy). The South African Banking Risk
Information Centre (SABRIC) Reports (2016a, 2017a, 2018a, 2019a) state that more than R2.5
billion was lost through card fraud, during the 2016–2019 financial period. There has been an
exponential increase in all forms of card fraud transactions. Consequently, debit card fraud is
also on the rise despite Europay, MasterCard and Visa (EMV) compliance. This worrisome
trend is expected to continue unless there are stringent measures put in place to mitigate it.
Grant (2017) states that globally consumers lost more than $16b in 2016 through identity theft
and fraud. Criminals engaging in counterfeit debit and credit card fraud are circumventing
EMV (or personal identification number [PIN] or chip technology) by alternating their behaviour
to card jamming and swapping at automated teller machines (ATMs) to steal cards or engaging
Read online:
in shoulder surfing to get PINs (SABRIC 2018b). Technology-savvy consumers tend to spot
Scan this QR suspicious activities, and are thus able to minimise financial damages. However, criminals are
code with your
smart phone or
adept at understanding psychology and in most instances use social engineering tactics to
mobile device exploit human vulnerability leading to the criminals harvesting confidential information like a
to read online.
PIN or password.

[Link] Open Access


Page 2 of 9 Original Research

Debates have been ensuing between acquirers and issuers on 1967. Projections are that by the end of 2020, 10 million credit
the feasibility of biometric authentication systems (Payment cards will be in use, resulting in a R50b credit card debt. The
Association of South Africa [PASA] 2019). Chigada (2020) PCI has indeed become a colossus (Pillay 2016). The bank
highlights that key issues being debated include the following: card is a payment instrument through which purchases can
• the ability of the banking technology and be made utilising the customer’s funds and/or credit
telecommunications infrastructure to support biometric provided by the issuing bank. Bank card purchases are
payment systems approved by customers through the signature on the card
• the ability of telecommunications infrastructure to handle slip and/or by keying in the PIN on the point of sale (POS)
large transaction volumes in a zero-floor limit environment device keypad (PCI 2014). South African bank-issued cards
• the issuing banks’ ability to process voluminous bear the magnetic stripe which is easily compromised by
authorisation traffic in a zero-floor limit environment fraudsters and contains sensitive card and cardholder data
• merchants’ operational costs for increased authorisation (card number, expiry date, unique card identifiers) (SABRIC
requests. 2017b). Though, chip or PIN technology is fast replacing the
conventional bank card, the magnetic stripe is still vital in
Conducting transactions below the merchant’s floor limit card transactions in the event that the POS device fails to
perpetuates the fraud cycle as the issuing bank only sees the read the chip or the chip is damaged, in which case the
transaction after an average of 2 days once the settlement merchant resorts to swiping the card.
process has occurred (SABRIC 2019b). This occurs when the
settlement bank is not the same as the issuing bank. How the credit card works
MasterCard International Incorporated (2019) states that the
use of non-PIN or chip bank cards, high merchant floor limits The usage of the bank cards can only be conducted on EMV-
and the 2-day time delay settlement and clearance processes certified POS devices which read, validate, verify and
have significantly contributed to the growth of credit card communicate with the issuing bank’s POS software (Akers
fraud. With reference to escalating cybercrimes, the Payment et al. 2005). The illustration in Figure 1 summarises the
Card Industry (PCI) (2019) instructed the PASA to adopt processes involved in card transactions. The current EMV-
zero-floor limits for all merchants and stop issuance of non- certified devices on the market include 930 General Packet
chip or PIN credit cards. Suggestions have been made to Radio Services (930 GPRS), 930 Bluetooth (930B), PIN pads,
adopt more robust security solutions that enhance confidence smarts and integrated solutions which are deployed by
of the banking clientele, industry and economy as a whole. various merchants who sign service level agreements with
Chigada and Kyobe (2018) suggest that robust information the issuing bank that stipulate fees to be paid for all
systems solutions supported by moral principles and transactions (Nedbank 2018b).
coherent cybersecurity legislation might enhance technical
and technological security protocols in place. At the pay point, the cashier dips or inserts the chip into the
chip reader (it should remain in the device for the full
Despite the evolution of bank cards in relation to duration of the transaction) or swipes the magnetic stripe on
conventional value proposition and customer design, the reader, requests the cardholder to key in the PIN and
technological and aesthetic features, miscreants have then waits for authorisation from the issuing bank. If there is
devised and use various techniques and technologies to sufficient credit and daily limit has not been exceeded, the
defraud unsuspecting cardholders, acquirers and issuers transaction is approved, or else it is declined. After the
(VISA 2018). Reports suggest that cybercrime syndicates successful completion of the transaction, the POS device will
enlist the services of employees working in financial
issue both a customer and a merchant receipt. Card
institutions to gain unauthorised access to information and
transactions are approved through the Payment Clearing
information systems. Chigada and Kyobe (2018) reveal that
House (PCH) system operating on a real-time basis, but
deterring bank card fraud and other forms of cybercrimes is
an integral and critical component of a national information
infrastructure protection strategy that requires concerted
efforts from everyone in society. An avalanche of reports Card associaon (Visa/MasterCard, Diners, Amex)
shows that the financial services industry is losing a lot of
money through bank card fraud. However, there is a dearth Authorisaon Authorisaon Authorisaon
request response request
of information regarding any research projects that have
Issuing bank Acquiring bank
been undertaken to suggest security solutions to mitigate
bank card transactions. Monthly Authorisaon Transacon
statement response informaon

Literature review Cardholder


Account
Merchant

info
South African credit card landscape
Source: Adapted from Akers, D., Golter, J., Lamn, B. & Solt, M., 2005, ‘Overview of recent
Bank card use in South Africa has increased exponentially developments in the credit card industry’, FDIC Banking Review 17(3), 23–35
since the first credit card was introduced by Nedbank in FIGURE 1: Multi-card issuer model.

[Link] Open Access


Page 3 of 9 Original Research

clearance and settlement happens in batch mode directly through card not present (CNP) to the tune of more than
between participating banks (PCI 2016). The acquirer is the R1.6b. The (SABRIC 2018b) indicates that mobile banking
institution where a merchant has a bank card account to or online applications are experiencing an unprecedented
process transactions and card payments. The acquirer rate of card fraud, resulting in a total loss of R260 007 285m
transfers card and other purchase information to a card for the 2018–2019 period. More than R2.2b was lost during
association which in turn forwards the information to an the 2016–2019 period and it is reported that with the advent
issuing bank. The acquirer will then credit the merchant for of the coronavirus disease of 2019 (COVID-19) global
the sales (subject to cleared effects) and send the settlement pandemic, cybercrimes are rising exponentially.
files to the issuing banks (whose cardholders transacted at Cybersecurity experts in South Africa state that there is a
the merchant) who in turn will financially reimburse the sharp increase in cybercrimes such as carding, romance
acquirer and financially account to their respective schemes and compromised business emails (Mbopane
cardholders’ accounts (PCI 2016) (see Figure 1). 2020). Cybercriminals are asking for financial donations on
the pretext of procuring medical treatment, personal
Settlement delay protective equipment and gear. The (SABRIC 2018b) states
that high card and online fraud transactions were mostly
The acquirers engage in commercial relationships with recorded in Gauteng, Western Cape and Kwa-Zulu Natal
merchants to accept credit cards on the acquirers’ POS (KZN) and in all three provinces, CNP accounted for the
devices. But before the relationship commences, the acquirer largest card fraud.
has to be fully satisfied that the merchant has a bona fide
business, technology, infrastructure, goods and/or services
before signing any contract (PCI 2018). Settlement delays
Floor limits
take on average 2 days if the acquirer and issuer are separate A floor limit is a cleared transaction that cannot be matched to
entities. The delay is attributed to two separate batch runs, a previously approved or partially approved authorisation –
where the acquirer runs one batch to obtain a merchant’s or it is transaction submitted without authorisation
sales and create a settlement file for the issuer. On the other (VISA 2014). If large volumes of transactions are submitted
hand, the issuer runs a batch file to adjust cardholders’ without authorisation, there is possibility of stressing the
back-end processors. Floor limits are generally assigned to the
accounts (PASA 2016). The 2-day settlement delay process
merchant categories with POS devices based on the nature of
creates loopholes for fraudsters because it takes time to detect
the products they sell, average ticket value (ATV) of goods
the transaction, especially if issuer and acquirer are two
and services and the risk propensity of the business. The
different institutions.
acquiring bank determines the floor limit based on the
merchant category and the current industry standards as
Fraud statistics governed by the local card association (MasterCard
SABRIC’s Commercial Crime Office, ‘Card Fraud Statistics International Incorporated 2019). On the other hand, the
Reports’ (2016b, 2017b, 2018b, 2019b) state that Credit Card issuer funds the risk on the product they issue. The risk-
Fraud has soared in South Africa over the past three years, funding is inherent within the interchange that the acquirer
resulting in the loss of more than R600 million a year. Gross pays the issuer for everyday sale. The two types of risks
fraud losses (from 2016 to 2019) perpetuated by South involved are fraud and credit (De Klerk 2015).
African-issued credit cards are illustrated in Table 1. In
summary, over the 2016–2019 period, a loss of R201 Biometric authentication
302 223m was generated through lost or stolen card fraud, Ross et al. (2008) define a biometric system as a pattern
R8 502 532m through Not Received Issued (NRI) and R21 recognition system that operates by acquiring biometric data
598 954m through false application card fraud. Counterfeit from an individual, extracting a feature set from the acquired
card fraud contributed the second most losses amounting data, and comparing this feature set against the template set
to R469 559 032, while account takeover losses amounted to in the database. These physiological or behavioural traits
R19 521 784m. The highest fraud losses were committed include fingerprints, hand geometry, iris, retina, face, hand

TABLE 1: Fraud statistics (2016–2019).


Fraud Type 2016 (R) 2017 (R) 2018 (R) 2019 (R) Total (R)
Lost and/or stolen cards 15 800 000 25 700 000 81 497 606 78 304 617 201 302 223
Not Received Issued (NRI) 3 100 000 987 000 1 846 630 2 568 902 8502532
False Application 1 900 000 5 500 000 10 294 741 11 304 213 21 598 954
Counterfeit 99 000 000 83 600 000 143 300 000 143 659 032 469 559 032
Account takeover 2 900 000 2 500 000 7 365 437 6 756 347 19 521 784
Card Not Present (CNP) 250 000 000 318 400 000 531 900 000 528 890 000 1.6bn
Mobile Banking fraud Figures not available Figures not available 129 002 523 131 004 762 260 007 285
Total losses 372 700 000 436 687 000 873 394 351 902 487 873 2 585 269 224
Source: Adapted from SABRIC Annual Reports (2016a; 2017a; 2018a; 2019a)

[Link] Open Access


Page 4 of 9 Original Research

vein, facial thermogram, signature or voice to validate or In South Africa, Capitec Bank has embraced and uses
determine an identity. A biometric system may operate either biometric systems in the credit or loan application system.
in the verification or identification mode (Biometrics Systems, Capitec Bank introduced the first banking biometric system
2018). In the verification mode, the system validates the in 2009 to provide increased security for client transactions
person’s identity by comparing the captured biometric data and lower banking fees (Capitec Bank 2018). Customers
with their own biometric template stored in the database present themselves to the customer sales representative and
(Kumar et al. 2009). Under the identification mode, the whilst sitting in front of a web camera, the customer’s facial
system recognises an individual by searching the templates features are captured. The bank’s system is linked to the
of all users in the database for a match. DHA which is the custodian of national identification
database, which validates the client’s biometric features with
When conducting a card transaction, cardholders do not the information in its database (identity number, facial and
have to carry any bank cards, remember their passwords or fingerprint information). The system allows immediate
secret codes and keep them secured, which can be stolen or verification and instant account access in real time, assuring
lost, thus, exposing the card details to criminals (Chigada & clients that only they can transact on their accounts. The bank
Kyobe 2018). The use of biometrics is gaining popularity in receives a response from DHA and decides the next step in
the payment system as a safer and ideal method to combat the business transaction (Capitec Bank 2018).
card fraud and identity theft. In 2009, Walmart and Costco
used biometric payment systems that could scan people’s ‘Hot’ card files
fingers to identify and call up payment information. This
Credit cards can be used fraudulently to transact below the
system was coined ‘Pull My Finger…For Payment’ and it
merchant’s floor limit because the issuers are at risk as they
virtually replaced the use of debit and credit cards at the two
do not see or acknowledge the transaction(s) until they are
chain stores (Kumar et al. 2009). But over the years, with
settled 2 days later (PCI 2014). In an effort to control the risk,
technological advancements, Comstock (2018) states that
‘hot’ card files are created by terminal vendors of POS devices
Amazon and Walmart were granted patents for the use of
which enable a predetermined number of compromised
biometric sensing-systems that detect signs of illnesses and
cards to be stored within the POS host (FastNet 2013). Issuers
recommend remedies. Walmart’s biometric systems for a
communicate this information to acquirers who in turn
connected shopping cart handle detect heart rate, palm
update the POS host with ‘hot’ card files.
temperature, grip force and walking speed. The Walmart
biometric sensing system is designed to monitor customers
Figure 2 illustrates that the cardholder reports the stolen or
running into the store to grab a product, capture a customer’s
compromised credit card to the issuing bank which then
data and relay it back to the central server to check if the
blocks the card on its system to avoid any further transactions
customer was or was not satisfied, depending on which the
that can be done. If the issuer is also the acquirer, it places the
server sends an alert message to a shop assistant to go and
card on its ‘hot’ card file to be downloaded to its merchant
help the customer (Comstock 2018).
(Nedbank 2018a). If the issuer is not the acquirer, the issuer
notifies the acquirer, who will then place the card on the
Rao et al. (2009) state that the use of biometric payment
acquirer’s ‘hot’ card file to be downloaded to its merchants.
systems is a major milestone in the PCI; even though there
The merchant receives the ‘hot’ card file overnight and
are many electronic payment systems, a system is used when updates its POS.
users have trust and confidence in it. A system will be
accepted if it supports several properties such as atomicity, The issuing bank has to prioritise the listing of its ‘hot’ cards.
consistency, isolation and durability, and various other Some of these ‘hot’ cards may not necessarily be South
security measures. In 2017, Thales Gemalto introduced the African-issued cards but might be foreign cards as well. As
biometric credit card that combines a fingerprint sensor and with the 2-day time delay settlement, there is a 2-day delay
EMV technology. The card has a design similar to the normal when the ‘hot’ card file is loaded and updated on the
credit card, except that it has a fingerprint sensor which is merchant’s POS if the issuer is not the acquirer as well (PCI
compatible with all EMV card options, and will include 2014). The card can only be loaded on the South African
dynamic code verification with an e-link display on the card merchant’s ‘hot’ card files for a period not exceeding 60 days,
body in future (Thales 2018). after which it purges. This means that the POS channel
cannot be permanently closed and automatically reopens
Initiatives have been taken by the Department of Home after 60 days. Fraudsters are very much aware of this
Affairs (DHA) in conjunction with SABRIC, who made a joint constraint and use the card for its 4-day life cycle until it is
proposal to the PCI in 2008 (SABRIC 2016a). The project was loaded on each merchant’s POS (Standard Bank 2018).
signed by SABRIC, on behalf of South African Banks and the
DHA, to allow banks to conduct online fingerprint verification
of their clients’ identities, thus allowing banks to have access Chargebacks
to the DHA’s Home Affairs National Identification System As part of the commercial agreement between the acquirer
(Hanis). The Hanis database contains South African citizens’ and merchant, if the merchant transgresses their
identity numbers, fingerprints and photographs (DHA 2010). commercial agreement with the acquirer, the merchant

[Link] Open Access


Page 5 of 9 Original Research

Cardholder Issuer blocks The issuer


reports The acquirer will
the card on nofies the place the card
compromised their system. acquiring
card to issuer. on its ‘hot’ card
bank. file to be
downloaded to
its merchants.

If the issuer is an acquirer


as well, it will place the The merchant receives the
card on its ‘hot’ card file ‘hot’ card file for
to be downloaded to its transacons conducted
merchants. below its floor limit.

Source: Nedbank, 2018a, Card fraud detection training, Nedbank, Sandowns, Sandton
FIGURE 2: ‘Hot’ card file process.

may incur a financial loss attributed to the disputed sale 2014). Tesch (1994:147) opines that in qualitative research, the
(Standard Bank 2018). The issuer also has financial researcher and participants work together to arrive at the
recourse to the acquirer in cases where the merchant did heart of the matter. The nature of this research included a
not follow the prescribed association rules. This financial strong component of exploration and interpretation of events
recourse to the acquirer or merchant is called a chargeback. and situations, resulting in the conducting of face-to-face and
For instance, if a merchant picks up that the credit card is focus group interviews. Inductive reasoning was used in
a ‘hot’ card and still decides to process the transaction, this some cases based on interviews and observed events.
is an outright violation of association rules, hence a Saunders et al. (2016) concur with Leedy and Omrod (2014)
chargeback. The merchant will have no recourse to this in that qualitative research is also used to answer questions
transaction (Standard Bank 2018). about relationships amongst measured variables with the
purpose of explaining, predicting and controlling
Methodology phenomena. During data collection, the researcher suspended
any preconceived notions or personal experiences that could
An interpretivist research paradigm was adopted to elicit unduly influence the research as participants could say
the views of subjects who worked with the information anything any time.
communication infrastructure and platforms discussed in
this article. Creswell (2014) states that paradigms in human
and social sciences help human beings understand a Target population
phenomenon and advance assumptions about the social Saunders et al. (2019) define population as the group of
world. Literature suggests that paradigms enable us to elements or objects of interest to the researcher from whom
understand how science should be conducted and what data is collected to address a management problem. The
constitutes legitimate problems (Kuhn 1970). The author population comprised systems engineers, telecommunications
was keen to hear the personal voice, accept qualitative engineers, card fraud experts, business systems analysts,
words and understand personal experiences (Ngulube network engineers, strategy specialists, biometric
2014). An exploratory research design was adopted, and it
authentication systems experts and Visa and MasterCard
acted as the framework of inquiry to complete this study.
International consultants. Sample elements were from Capitec,
The exploratory research design helped to explain this
Nedbank, First National Bank, Absa, Standard Bank and
study because there was a high level of uncertainty and
telecommunication services providers. A total of 120 experts
ignorance about the subject. The problem under
made the population for this study. However, in this qualitative
investigation was not well researched in the South African
research project, 10 participants were selected using non-
PCI, therefore, it was not well understood (Saunders, Lewis
& Thornhill 2016). The aim was to identify boundaries of probability purposive sampling and convenience sampling
the environment in which the problems, opportunities or techniques to partake in the face-to-face interviews. Another
situations of interest were likely to reside, while identifying 20 participants were selected using probability random
salient variables that might be found and be of relevance to sampling for the study.
the research project (Romm & Ngulube 2014).
Creswell (2014), Ngulube (2014) and Romm and Ngulube
Qualitative research is typically used to answer questions (2014) state that face-to-face interviews are time consuming.
about the complex nature of phenomena, often with the Therefore, in qualitative research between 6 and 12
purpose of describing and understanding the phenomena participants suffice for face-to-face interviews, while between
from the participant’s perception, perspective and 6 and 20 participants are ideal for a focus group. Bryman
understanding of a particular situation (Leedy & Omrod (2010) differs with the authors above and recommends

[Link] Open Access


Page 6 of 9 Original Research

between 8 and 15 participants for face-to-face interviews. In helps to convert qualitative data into meaningful information
this study, the suggestions by Creswell (2014) and Romm and because the researcher is able to extract rich sets of data and
Ngulube (2014) were adopted. Kumar (2005:179) states that describe events as they occur in a natural setting. From a total
the use of purposive sampling is determined by ‘the of 30 participants, 13 (43%) respondents were female, while
judgement of the researcher as to who can provide the best the majority (57%) of the respondents were males.
information to achieve the objectives of the study’. This
assertion by Kumar (2005) is corroborated by Leedy and Banking technology and telecommunications
Omrod (2014) who state that the use of purposive sampling infrastructure’s ability to support biometrics
depends on the researcher’s judgement as who to include or The study established that most of the commercial banks’
exclude from a sample. The subjects selected for this study transaction manager (Base 24 and Base 26) systems were
possessed the technical knowledge of how banking scalable and could incorporate biometrics and Alieno
technologies and telecommunications infrastructure work. authentication systems. The configuration of the Transaction
Therefore, the data required to address the problem resided Manager Base 24, an enterprise resource planning (ERP)
in the selected subjects. system concurs with the views raised during the interviews.
The consensus from respondents was that:
Data collection ‘The banking ERP systems were scalable and could be integrated
with other platforms.’ (PB02, Systems engineer, 2019)
Interviews are an important part of any research project as
‘The challenge confronting all banks is the cost of implementing
they provide the opportunity for the researcher to investigate
new and managing multiple technologies. The cost entails hiring
further, to solve problems and to gather data which could not
SAP consultants, IT professionals and acquisition of software
have been obtained in other ways (Cunningham 1993:93). and hardware.’ (PB01, Focus group, 2019)
Saunders et al. (2019) state that an interview is essentially a
‘It is important to acquire and implement technologies aligned to
qualitative data collection technique where the interviewer
organisational strategy, to generate customer and shareholder
directs the interaction and inquiry in a very structured or
value.’ (PB04, IT Strategist, 2019)
unstructured format. An interview guide was designed in
line with research objectives, whose main aim was addressing
The BankServ Annual Report (2011) highlights that as part of
the banking and telecommunications infrastructure, ability
security measures, banking platforms should be designed to
to sustain and process high volumes of transactions in a zero-
incorporate and integrate with other cybersecurity and
floor limit environment and the costs incurred by merchants.
information systems especially in the dispensation of rising
The interview guide comprised five sections. Section A
information, information systems and cyberattacks and
included demographic variables such as age, position (or
title), years of experience, gender and race. This information threats. Chigada and Kyobe (2018) concur with the assertions
was paramount to mitigate any bias that could have risen in in the BankServ Report (2011) in that various interventions
the event of exclusivity occurring. Section B focused on including legislation, technical and technological systems
the ability of banking technology and telecommunications and moral standards play an important role in combating
infrastructure to support biometric authentication systems. cybercrimes. Systems Applications and Products (SAP)
In Section C, the study sought to determine the ability of (2015) argues that most of its ERP systems in the market are
telecommunications infrastructure to sustain zero-floor limit scalable and can incorporate other systems; however, a huge
transactions arising from high request volumes. In Section D, financial investment would be required to develop an
the aim was to establish the issuing banks’ ability to process integrated and complex architecture. The report by SAP
high transaction volumes in a zero-floor limit environment. (2015) disputes the notion that has been widely spread that
The last section (Section E) sought to establish the additional current banking technologies cannot integrate biometric
costs incurred by merchants for telephone services when systems; however, it is the cost element that impedes
requesting authorisation. All questions were open-ended, integration of such systems.
creating opportunities for subjects to explain viewpoints in
their own words (Stangor 2011). Secondary data, in the form Telecommunications infrastructure’s ability to
of industry reports, were provided by SABRIC, PASA and the sustain high transaction volumes
Internet.
Interviews were conducted with participants providing
telecommunications services such as GPRS for POS devices,
Ethical consideration telephone lines, asymmetric digital subscriber line (ADSL)
The study received ethical clearance from the Faculty and other services. However, the telecommunications
of Commerce, University of Cape Town (REF: services providers indicated that merchants should be
REC2018/001/005). prepared for high telephone service costs to ensure that best
equipment was installed to mitigate time-out problems
which might persist. The findings showed that the scarcity
Discussion of findings of information technology and telecommunications
Thematic data analysis (TDA) was performed through the engineering skills was a major impediment in the country.
lens of Atlas Ti. v6. Braun and Clarke (2012a) posit that TDA That response was least expected in the study, but it was

[Link] Open Access


Page 7 of 9 Original Research

paramount because it confirmed one challenge confronting To augment the argument, Capitec Bank introduced
South Africa – skills shortage in the sciences disciplines biometrics with the aim of increasing security for client
(StatsSA 2018). It was revealed that South Africa’s transactions and lower banking fees (Capitec Bank 2018). The
telecommunications infrastructure was one of the most system allows immediate verification and instant account
stable, reliable in the region, therefore, had the capacity to access in real time, assuring clients that only they can transact
sustain large transaction volumes (Telkom SA 2014). The on their accounts.
most basic idea about telecommunications is that the
electronic signals are sent on the network as either analogue Issuing banks’ ability to process huge
or digital depending on the type of the network. Most of authorisation requests
the POS smart devices used by merchants in South Africa,
It was established that issuing banks’ front-end processors had
use the telephone network (analogue) to process card
the capacity to process huge authorisation requests. During a
transactions.
2-h observation at one of the research sites, more than 2 million
banking sessions (authorisation requests) were processed. At
The volume of data that is transmitted per unit of time
that load level, the banking platforms were processing more
constitutes the speed of transmission. Gillwald, Moyo and
than eight times as many banking sessions per hour. De Klerk
Stork (2012) point out that it is important to consider the
(2015) states that the unused capacity of bank’s front-end
speed of transmission between the merchant’s POS device
processors is used to accommodate intra-day spikes. Literature
and response from the bank. The bandwidth or capacity to
points out that banks can process millions of banking sessions
transmit large volumes should be used as a determining
in a 24-bankable-hour period (BankServ 2016). Furthermore, it
factor on the ability of telecommunications infrastructure.
was revealed that setting merchant floor limits to zero was
The Secure Socket Layer (SSL) 128 bit is a good example of
welcome despite huge transaction requests processed;
leased and secure line for data transmission. These lines are
however, merchants would be expected to pay high telephone
mainly used to transmit data where high security levels
services costs.
are envisaged (Gillwald et al. 2012). Therefore, the
telecommunications infrastructure was capable of
The study revealed that there was need to redesign
sustaining high transaction volumes. Some of the responses
architecture of front-end processors and increase their
from the study that support the above narrative were:
capacity to cater for huge transactions (Blue Label Data
‘South Africa’s telecommunications technology and infrastructure Solutions 2017). This would envisage a complete overhaul
is of global standards. It is benchmarked against that of Germany, of the hardware and software to ensure there is smooth
Australia, United Kingdom, therefore, it can sustain high processing of transactions. In the absence of increased CPU
transaction volumes.’ (PB01, Telecoms engineer, 2019) capacity, time-out problems will persist and this will affect
‘Our telecommunications infrastructure is capable to handle merchants and cardholders. It was also revealed that most
large transactions. It can support biometrics and zero-floor banks used the Transaction Manager Base 24, an ERP
limits, however, banks should reconfigure their models and scalable system that supports Alieno and biometric
architectures. Some amount of redesigning is required where IT authentication. These revelations are supported by the
experts and engineers are required.’ (PB05, Telecoms service following response:
provider, 2019) ‘Banks can handle large transaction volumes. However, there
can be a challenge if there is an influx of zero floor limits. The
The narratives above also reveal that the telecommunications system can be clogged and slowed down. This is also good
infrastructure was suitable for supporting and carrying because it allows the bank to conduct due diligences on each
biometric authentication requests. However, banks were transaction before authorisation. The downside is that
required to redesign their existing systems. The study merchants become angry at the speed of their POS devices. At
times merchants unplug and plug telephone cables to the POS.’
revealed that the DHA, Capitec Bank and other institutions
(PB01, Focus group, 2019)
in South Africa were at the forefront of using biometrics,
using the same telecommunications configurations. Capitec
Bank introduced the first banking biometric system in 2009 to
High operational costs incurred for telephone
provide increased security for client transactions (Capitec
services when requesting authorisation
Bank 2010). The system allows immediate verification and With reference to the discussions relating to processing of
instant account access in real time, assuring clients that only huge transaction requests, the study also revealed that the
they can transact on their accounts. introduction of zero-floor limits is a welcome strategy to
mitigate credit card fraud. However, the downside was that
The ability of banks to sustain and process large transactions merchants were expected to pay more for telephone services
is attributable to redesigning or configuration of front-end (De Klerk 2015). High costs would be incurred when the
processors and hardware (Blue Label Data Solutions 2017). merchant calls the acquirer, who then dials the issuer
Evidence from the study showed that in 12 bankable hours, through BankServ for authorisation and back to the
millions of banking sessions are processed by banks; merchant with a response. Huge transaction volumes are
therefore, banks have the capability to process huge involved in such cases, resulting in merchants paying
transaction volumes that arise in zero-floor limit environment. higher fees. If biometrics are involved, merchant costs are

[Link] Open Access


Page 8 of 9 Original Research

reduced because no dialups are required to authenticate the to the qualitative research method used. A large sample size
transaction. Some responses that demonstrated the high would be achieved if a quantitative or mixed method was
telephone costs were: used. The study suffered as a result of lack of prior research
‘Merchants pay high transaction costs for large transaction on the topic in the South African context, which would have
volumes because they consume high bandwidth. In addition, laid the foundation for understanding of the discourse
duration for each transaction is prolonged.’ (PB05, Telecom investigated. This study depended on having access to
service provider, 2019) people, organisations and data. The researcher could not
‘In the event of deploying biometrics systems, it would mean access some of the resources required to accomplish the
that banks will incur reconfiguration/redesigning costs, which study. For further research, an area of interest would be
are in turn passed on to merchants. Overall, the switch to interrogating employees’ ethical behaviour in information
biometrics will be costly because merchants are already paying sharing. This might uncover pertinent issues that exacerbate
high telephone costs.’ (PB08, Business analyst, 2019) card fraud and identify theft transactions. Researchers might
also look at the effects of COVID-19 on card fraud and online
Telkom SA (2017) acknowledges that South African transactions amidst lockdown.
telecommunication services are some of the most expensive
services in the world due to high interconnection rates. The
Independent Communications Authority of South Africa
Acknowledgements
(ICASA) (2020) states that major cellular operators – This article would not have been successful had it not been
Vodacom, MTN, Virgin Mobile and Cell C – have engaged in for a number of people who contributed to it. I would like to
discussions to reduce call and data rates. Merchants using thank all participants for participating in the face-to-face
telecommunication services from cellular firms are affected interviews. Thank you all for the insights shared during the
by a fluctuation in off-peak and peak internetwork call costs. period of this study.
Both banks and merchants carry the costs, but the greater
part of the costs is carried by merchants (Nedbank 2018a). Competing interests
The author has declared that no competing interests exist.
Setting merchant floor limits to zero is a welcome initiative
for the PCI, however, both telecommunication service
providers and merchants should have stable and reliable Author’s contributions
telecommunications systems in place to mitigate time-out The author developed the article and confirms he is the sole
problems which are synonymous in high transaction author.
environments (Chigada 2020).

Funding information
Conclusion This research received no specific grant from any funding
This was a pioneering academic study that showed the agency in the public, commercial or not-for-profit sectors.
importance of curbing and mitigating credit card fraud. The
objective of the study was to determine the feasibility of
deploying biometric authentication and zero-floor limits as a
Data availability statement
way of eradicating card fraud. In addition, the study sought Data sharing is not applicable to this article as no new data
to establish if the existing banking technology and were created or analysed in this study.
telecommunications infrastructure were capable of
supporting biometric payment systems. The objectives of the Disclaimer
study were achieved by gathering relevant data from a
The views and opinions expressed in this article are those of
diverse spectrum of individuals working with banking and
the author and do not necessarily reflect the official policy or
telecommunications infrastructure. Their experiences,
expertise and knowledge addressed the problem at hand. position of any affiliated agency of the author.
Some responses were cited verbatim, demonstrating
participants’ experiences with different systems and References
challenges. The study confirmed that integration of biometric Akers, D., Golter, J., Lamn, B. & Solt, M., 2005, ‘Overview of recent developments in
authentication systems was partially feasible. Bank back-end the credit card industry’, FDIC Banking Review 17(3), 23–35.
and telecommunications infrastructure were capable of BankServAfrica, 2011, Card fraud and identity theft on the increase: Challenges for the
payment card industry, Selby, Johannesburg.
handling large transaction volumes. However, integration of
BankServAfrica, 2016, Africa reports big jump in digital and card fraud, Blue Label
biometric authentication will increase transaction costs and Data Solutions, Annual Report, Sandton, Johannesburg.
merchants are not keen on accepting these extra costs. Biometric Systems, 2018, Biometrics in retail banking, viewed 10 July 2019, from
[Link]

The research study was exposed to methodological and Blue Label Data Solutions, 2017, Data Explosion and data governance in South Africa,
viewed 18 December 2019, from [Link]
research limitations. The sample size was not large enough to
Braun, V. & Clarke, V., 2012a, ‘Thematic analysis’, in Encyclopedia of quality of life and
be representative of a large population. This was attributable well-being research, pp. 6625–6628, Springer, Dordrecht, the Netherlands.

[Link] Open Access


Page 9 of 9 Original Research

Braun, V. & Clarke, V., 2012b, ‘Teaching thematic analysis: Overcoming challenges and Payment Card Industry, 2019, Compliance challenges, Payment card industry
developing strategies for effective learning’, The Psychologist 13(2), 12–23. compliance workshop, Johannesburg.
Capitec Bank, 2010, Transforming the banking sector: Challenging the status quo, Pillay, K., 2016, Card fraud stats 2016, SABRIC, Cape Town.
Stellenbosch, Cape Town.
Rao, B.T., Vedavalli, E., Aditya, K. & Bindu, D.R.S., 2009, ‘Major milestone in the
Capitec Bank, 2018, Revolutionary paperless identification system, Stellenbosch, payment card industry’, International Journal of Computer Science and Network
Cape Town. Security 9(9), 123–133.
Capitec Bank South Africa, 2018, Biometrics authentication, viewed 17 June 2019, Romm, N. & Ngulube, P., 2014, ‘Mixed methods research’, in E.R. Mathipa &
from [Link]
M.T. Gumbo (eds.), Addressing research challenges: Making headway for
Chigada, J., 2020, ‘Towards an aligned national cybersecurity framework for South emerging researchers, Mosala-Masedi, Sandton.
Africa’, Unpublished PhD dissertation, University of Cape Town, Cape Town.
Ross, A., Murdoch, S.J., Drimer, S. & Bond, M., 2008, ‘Chip and PIN is broken’, in IEEE
Chigada, J. & Kyobe, M., 2018, ‘Evaluating factors contributing to Misalignment of the Symposium on Security and Privacy, IEEE, Berkeley/Oakland, CA.
South African National cybersecurity policy framework’, in Conference Proceedings
for the Conf-IRM 2018, Ningbo, China, June 04-06, 2018. Saunders, M., Lewis, P. & Thornhill, A., 2016, Research methods for business students,
10th edn., Prentice Hall, Harlow.
Comstock, J., 2018, Walmart and Amazon patents could take biometric monitoring to
new level, viewed 26 May 2020, from [Link] Saunders, M., Lewis, P., Thornhill, A. & Bristow, A., 2019, Research methods for
business students, 12th edn., Pearson Publishers, Harlow, UK, viewed 03 October
Creswell, J.W., 2014, Research Design: Qualitative, quantitative and mixed methods,
4th edn., V. Knight (ed.), Sage, Lincoln. 2019, from [Link]

Cunningham, J.B., 1993, Action research and organisational development, Praeger, South African Banking Risk Information Centre (SABRIC), 2016a, Annual report,
London. SABRIC, Midrand, Johannesburg.
De Klerk, H., 2015, ‘Card operations & processing manager’, Personal Interview, South African Banking Risk Information Centre (SABRIC), 2016b, Release of Card Fraud
13 October 2010, Braampark, Braamfontein. Stats 2016, viewed 10 December 2019, from [Link]
FastNet, 2013, Concerns around bank biometrics systems, ITWEB, Midrand. South African Banking Risk Information Centre (SABRIC), 2017a, Annual report,
SABRIC, Midrand, Johannesburg.
Gillwald, A., Moyo, M. & Stork, C., 2012, Understanding what is happening in ICT in
South Africa: Evidence for ICT Policy Action, Policy paper, 2 of 2012, Research ICT South African Banking Risk Information Centre (SABRIC), 2017b, Card Fraud Booklet
Africa, Cape Town. 2017, viewed 10 December 2019, from [Link]
Grant, K.B., 2017, Identity theft, fraud cost consumers more than $16 billion, CNBC South African Banking Risk Information Centre (SABRIC), 2018a, Annual report,
News, viewed 10 November 2019, from [Link] SABRIC, Midrand, Johannesburg.
Independent Communications Authority of South Africa (ICASA), 2020, Bi-annual South African Banking Risk Information Centre (SABRIC), 2018b, Card Fraud Booklet
report: Analysis of standard prepaid data tariffs and data bundles, ICASA, Pretoria. 2018, viewed 12 December 2019, from [Link]
Kuhn, T.S., 1970, The structure of scientific revolutions, 2nd edn., University of Chicago
Press, Chicago, IL. South African Banking Risk Information Centre (SABRIC), 2019a, Annual report,
SABRIC, Midrand, Johannesburg.
Kumar, A., Hyun-Joo, L. & Youn-Kyung, K., 2009, ‘Indian consumers’ purchase intention
toward a United States versus local brand’, Journal of Business Research 62(5), South African Banking Risk Information Centre (SABRIC), 2019b, Crime Statistics 2019,
521–527. [Link] viewed 10 December 2019, from [Link]
Kumar, D. & Ryu, Y., 2009, ‘A brief introduction of biometrics and fingerprint payment Standard Bank, 2018, Chargebacks training, Standard Bank, Johannesburg.
technology’, International Journal of Advanced Science and Technology 4, 25–38.
[Link] Stangor, C., 2011, Research methods for the behavioural sciences, 4th edn.,
Wadsworth, Cengage Learning, Belmont, CA.
Kumar, R., 2005, Research methodology: A step-by-step guide for beginners, 1st edn.,
Sage, New Delhi. Systems Application Products, 2015, Annual report, viewed 12 May 2018, from http://
[Link].com_comany_sap-ag.
Leedy, P.D. & Omrod, J.E., 2014, Practical research, planning and design, 12th edn.,
Pearson Education International, Hoboken, NJ. Thales, 2018, ‘Biometrics payment card (fingerprint authentication)’, Discover the new
biometric card from Gemalto, viewed 02 January 2020, from [Link]
MasterCard International Incorporated, 2019, Annual reports on payment solutions, [Link]-cards.
Purchase, New York, NY.
Tesch, R., 1994, ‘The contribution of a qualitative method: Phenomenological
Mbopane, L., 2020, SA to lose billions of Rands from Cybercrimes during COVID-19,
viewed 10 July 2020, from: [Link] research’, in M. Langenbach, C. Vaugn & L. Aagaard (eds.), An Introduction to
billions-of-rands-from-cybercrimes-during-covid-19-experts-warn/ Educational Research, Allyn and Bacon, Needham Heights, MA.
Nedbank, 2018a, Card fraud detection training, Nedbank, Sandowns, Sandton. Telkom SA, 2014, Group annual results for the year ended 31 March 2014, Telkom
SA, Centurion.
Nedbank, 2018b, Steps when conducting a chip/pin credit card transaction, viewed
02 December 2019, from [Link] Telkom SA, 2017, Integrated Report for the year ended 31 March 2017, Telkom SA,
Centurion.
Ngulube, P., 2014, Research methods in information science, University of South Africa,
Pretoria. Unisys, n.d., Fingerprint authentication, viewed 18 May 2019, from [Link]
[Link]/biometrics_fingerprints.
Payment Association of South Africa, 2016, Annual report, Payments study tour
report, Reserve Bank of South Africa, Pretoria. Unisys, 2019, Consumers’ views and perceptions on biometrics payments, viewed
Payment Association of South Africa, 2019, Annual report, The National payment 01 December 2019, from [Link]
system framework and strategy, Reserve Bank of South Africa, Pretoria. biometrics.
Payment Card Industry, 2014, Data security standard, Payment card industry VISA, 2014, Financial inclusion and literacy, viewed 13 March 2019, from [Link]
compliance workshop, Johannesburg. [Link]/html/.
Payment Card Industry, 2018, Information security standards, Payment card VISA, 2018, Annual report: Card Fraud Soaring, viewed 31 October 2019, from https://
industry compliance workshop, Johannesburg. [Link]/html.

[Link] Open Access


Copyright of South African Journal of Information Management is the property of African
Online Scientific Information System PTY LTD and its content may not be copied or emailed
to multiple sites or posted to a listserv without the copyright holder's express written
permission. However, users may print, download, or email articles for individual use.

You might also like