Memorandum submitted by the British Bankers'
Associatione
The BBA is grateful for the opportunity to offer
comments from a financial crime perspective to help to inform
the Committee's inquiry into Companies House.
The BBA is the leading UK banking and financial
services trade association and acts on behalf of its members on
domestic and international issues. Our 228 banking members and
35 associate members are from 60 different countries and collectively
provide the full range of banking and financial services. They
operate some 130 million accounts, contribute £50 billion
to the economy and together make up the world's largest international
banking centre.
GENERAL
There have been a number of incidences of Companies
House records being altered by corporate identity fraudsters with
attempts made fraudulently to open lines of credit or to obtain
other goods and services. Typically, a company would have its
Registered Office relocated to a different location without its
knowledge, in effect having its identity and credit rating stolen.
Estimates produced by the Metropolitan Police Service Operation
Sterling put the cost of this fraud in excess of £50 million
per annum.
There are two main types of fraud using Companies
House data:
1. Third Party Fraudwhere a fraudster
seeks to imitate the account holder using information publicly
available at Companies House. Some examples of modus operandi
below include:
Fraudsters take advantage of the
"one-stop-shop" identity data held at Companies House
(signature, date of birth and address of Director along with bank
account details and address of Company) to facilitate fraud in
conjunction with false/stolen supporting documentation:
One BBA member investigated this
type of fraud where total losses were found to be in the region
of £200,000 against 23 customers.
The fraudster was arrested in the
process of committing the fraud at a branch.
When searched by police prints of
open source Companies House documentation were found on his person.
Directors' signatures found at Companies
House can be cross referred to stolen business account cheque
books.
Counterfeit documents have been created
based on Companies House dataA professional counterfeiter
arrested earlier this year had opened 29 accounts with false passports,
council tax bills etc.
A fraudster uses false signature
gleaned from Companies House to give written instruction to bank
to pay away funds, sell assets or change an address to which a
statement is sent.
Companies House data used in support
of a telephone or internet banking fraud attempt.
Companies House data not directly
used to commit fraud, but rather to obtain further identity documentation.
2. First Party Fraudwhere company
assets are hidden from creditors through front companies and non-existent
Directors:
False names, corruptions of names
used, unwitting or collusive distant family members held up as
Directors.
Property and assets sold on under
value to "front" companies.
Such corporate identity fraud occurs because
the process for updating the records of a company is "loose".
The protective measures to mitigate against details being fraudulently
modified appear weak. Any individual can download the appropriate
forms and make changes unchallenged. The extent of the disclaimer
published by Companies House does not go beyond validating that
the form has been completed properly and that it contains a signature
(genuine or otherwise).
Companies House was set up as a repository of
information and, it would argue, it has a duty to act upon whatever
information it is provided. The continuing problems really stem
from the misconception that Companies House "checks"
the authenticity of all submissions rather than simply "recording"
the information contained in the submissionthe latter being
its actual role as a Public Records body. It is highly improbable
that the Government would wish to fund additional resources for
the purposes of simply authenticating submitted data.
Following increased instances of companies having
their identities stolen, Companies House (in consultation with
the Operation Sterling initiative) did bring in additional controls/safeguards
including the introduction of the electronic filing of data under
password control and the facility for companies to be alerted
by email to any attempts to change their records by the paper
rather than electronic route. Notwithstanding this there remains
a gap in the system as the paper process could still successfully
change a company's details.
Company formation agents are registered against
the introduced company and could also present a risk in that they
have the ability to register and modify company details.
Whilst it is public domain information access/modifications
to details should be better regulated, specifically:
remove Director Date of Birththis
would significantly deter id-theft or application fraud;
remove Director Date of Appointment;
and
where possible, encourage business
address rather than personal address for Directors.
(NOTE: the benefits of these three specific
fraud reduction proposals would have to be measured against the
new anti-money laundering requirement to identify and take risk
based measures to verify beneficial owners or controllers of firms
and partnerships, holding more than 25% of share ownership or
control. Currently beneficial owners are readily identified by
reference to Companies' House data, and date of birth and residential
addresses are valuable data elements for those purposes. Clearly
there is a conflict of interest here which could be overcome by
a more secure access to data for statutory purposes such as anti-money
laundering compliance).
the general public should be restricted
to viewing company's details;
the electronic method should be strengthened
and promoted as the only and most secure method of effecting changesmandatory
implementation;
remove the paper process;
organisations who can demonstrate
a business need to support increased permissions eg download key
data should be given broader permissions in a controlled environment;
the disclaimer should permit Companies
House to challenge any proposed changes into the company formation;
and
controls need to be established around
company formation agents but the licensing of Company Formation
Agents would not, in our opinion prove to be of any significant
benefit as it is our perception that most fraud of this type is
perpetrated once a company has "established" itself
and earned it's respectability in the marketplace.
Companies House tools, "Proof" and
"Monitor" both have the potential for assisting in the
prevention of financial crime.
Proof is the online filing service (PROtected
Online Filing) introduced by Companies House in early 2005. Essentially
businesses that sign up for the service commit to only ever filing
certain submissions to Companies House online, via a password
protected account and thereafter Companies House will not action
paper based submissions for that business. The obvious prevention
benefit is that this makes it much harder for the criminal to
hijack that businesses identity via false paper based submissions.
Monitor is a service that allows businesses
to be automatically advised of changes made to any businesses
records. This service is marketed by Companies House as a competitive
edge tool inviting businesses to keep an eye on their competitors,
apparently ignoring the potential fraud prevention benefits. This
could be utilised by both customers and banks for early identification
of hijack attempts etc eg Corporate Relationship Manager is notified
of a sudden change of Directors for which his/her business customer
had not provided prior notice.
However, there appears to be limited awareness
of these tools in the wider business community and much less the
potential fraud prevention benefits. One BBA member reports that
during a number of presentations to small, medium and large business
customers, when asked only a very small percentage demonstrated
any knowledge of the Companies House tools. We consider Government
should implement a high profile awareness campaign that encourages
all company dealings to be handled electronically through designated
company representatives supported by "strong" password
controls.
In conclusion, the BBA would urge Government
to give thought to changing the status of Companies House, from
a pure repository of information about companies to include an
information authentication and validation role. In the meantime,
the view of BBA members is not to rely upon Companies House information
in isolation but to place it in context with details obtained
through other independent sources.
10 March 2008
|