Select Committee on Business and Enterprise Written Evidence


Memorandum submitted by the British Bankers' Associatione

  The BBA is grateful for the opportunity to offer comments from a financial crime perspective to help to inform the Committee's inquiry into Companies House.

  The BBA is the leading UK banking and financial services trade association and acts on behalf of its members on domestic and international issues. Our 228 banking members and 35 associate members are from 60 different countries and collectively provide the full range of banking and financial services. They operate some 130 million accounts, contribute £50 billion to the economy and together make up the world's largest international banking centre.

GENERAL

  There have been a number of incidences of Companies House records being altered by corporate identity fraudsters with attempts made fraudulently to open lines of credit or to obtain other goods and services. Typically, a company would have its Registered Office relocated to a different location without its knowledge, in effect having its identity and credit rating stolen. Estimates produced by the Metropolitan Police Service Operation Sterling put the cost of this fraud in excess of £50 million per annum.

  There are two main types of fraud using Companies House data:

  1.  Third Party Fraud—where a fraudster seeks to imitate the account holder using information publicly available at Companies House. Some examples of modus operandi below include:

    —  Fraudsters take advantage of the "one-stop-shop" identity data held at Companies House (signature, date of birth and address of Director along with bank account details and address of Company) to facilitate fraud in conjunction with false/stolen supporting documentation:

    —  One BBA member investigated this type of fraud where total losses were found to be in the region of £200,000 against 23 customers.

    —  The fraudster was arrested in the process of committing the fraud at a branch.

    —  When searched by police prints of open source Companies House documentation were found on his person.

    —  Directors' signatures found at Companies House can be cross referred to stolen business account cheque books.

    —  Counterfeit documents have been created based on Companies House data—A professional counterfeiter arrested earlier this year had opened 29 accounts with false passports, council tax bills etc.

    —  A fraudster uses false signature gleaned from Companies House to give written instruction to bank to pay away funds, sell assets or change an address to which a statement is sent.

    —  Companies House data used in support of a telephone or internet banking fraud attempt.

    —  Companies House data not directly used to commit fraud, but rather to obtain further identity documentation.

  2.  First Party Fraud—where company assets are hidden from creditors through front companies and non-existent Directors:

    —  False names, corruptions of names used, unwitting or collusive distant family members held up as Directors.

    —  Property and assets sold on under value to "front" companies.

  Such corporate identity fraud occurs because the process for updating the records of a company is "loose". The protective measures to mitigate against details being fraudulently modified appear weak. Any individual can download the appropriate forms and make changes unchallenged. The extent of the disclaimer published by Companies House does not go beyond validating that the form has been completed properly and that it contains a signature (genuine or otherwise).

  Companies House was set up as a repository of information and, it would argue, it has a duty to act upon whatever information it is provided. The continuing problems really stem from the misconception that Companies House "checks" the authenticity of all submissions rather than simply "recording" the information contained in the submission—the latter being its actual role as a Public Records body. It is highly improbable that the Government would wish to fund additional resources for the purposes of simply authenticating submitted data.

  Following increased instances of companies having their identities stolen, Companies House (in consultation with the Operation Sterling initiative) did bring in additional controls/safeguards including the introduction of the electronic filing of data under password control and the facility for companies to be alerted by email to any attempts to change their records by the paper rather than electronic route. Notwithstanding this there remains a gap in the system as the paper process could still successfully change a company's details.

  Company formation agents are registered against the introduced company and could also present a risk in that they have the ability to register and modify company details.

  Whilst it is public domain information access/modifications to details should be better regulated, specifically:

    —  remove Director Date of Birth—this would significantly deter id-theft or application fraud;

    —  remove Director Date of Appointment; and

    —  where possible, encourage business address rather than personal address for Directors.

  (NOTE: the benefits of these three specific fraud reduction proposals would have to be measured against the new anti-money laundering requirement to identify and take risk based measures to verify beneficial owners or controllers of firms and partnerships, holding more than 25% of share ownership or control. Currently beneficial owners are readily identified by reference to Companies' House data, and date of birth and residential addresses are valuable data elements for those purposes. Clearly there is a conflict of interest here which could be overcome by a more secure access to data for statutory purposes such as anti-money laundering compliance).

    —  the general public should be restricted to viewing company's details;

    —  the electronic method should be strengthened and promoted as the only and most secure method of effecting changes—mandatory implementation;

    —  remove the paper process;

    —  organisations who can demonstrate a business need to support increased permissions eg download key data should be given broader permissions in a controlled environment;

    —  the disclaimer should permit Companies House to challenge any proposed changes into the company formation; and

    —  controls need to be established around company formation agents but the licensing of Company Formation Agents would not, in our opinion prove to be of any significant benefit as it is our perception that most fraud of this type is perpetrated once a company has "established" itself and earned it's respectability in the marketplace.

  Companies House tools, "Proof" and "Monitor" both have the potential for assisting in the prevention of financial crime.

  Proof is the online filing service (PROtected Online Filing) introduced by Companies House in early 2005. Essentially businesses that sign up for the service commit to only ever filing certain submissions to Companies House online, via a password protected account and thereafter Companies House will not action paper based submissions for that business. The obvious prevention benefit is that this makes it much harder for the criminal to hijack that businesses identity via false paper based submissions.

  Monitor is a service that allows businesses to be automatically advised of changes made to any businesses records. This service is marketed by Companies House as a competitive edge tool inviting businesses to keep an eye on their competitors, apparently ignoring the potential fraud prevention benefits. This could be utilised by both customers and banks for early identification of hijack attempts etc eg Corporate Relationship Manager is notified of a sudden change of Directors for which his/her business customer had not provided prior notice.

  However, there appears to be limited awareness of these tools in the wider business community and much less the potential fraud prevention benefits. One BBA member reports that during a number of presentations to small, medium and large business customers, when asked only a very small percentage demonstrated any knowledge of the Companies House tools. We consider Government should implement a high profile awareness campaign that encourages all company dealings to be handled electronically through designated company representatives supported by "strong" password controls.

  In conclusion, the BBA would urge Government to give thought to changing the status of Companies House, from a pure repository of information about companies to include an information authentication and validation role. In the meantime, the view of BBA members is not to rely upon Companies House information in isolation but to place it in context with details obtained through other independent sources.

10 March 2008





 
previous page contents next page

House of Commons home page Parliament home page House of Lords home page search page enquiries index

© Parliamentary copyright 2008
Prepared 21 November 2008