Supplementary memorandum submitted by
BBA
Thanks for giving me a little time to consult
with my members. I can now provide some further details of the
authentication and validation checks we believe it would be helpful
for Companies House to undertake: These are:
Lock down Companies House recordsRecords
should be protected so they can only be changed by the authorised
person. The Metropolitan Police Service's Operation Sterling resolved
this issue from an online perspective (now requiring a password)
but this is still unresolved through other channels. There needs
to be further changes to standardise the process and ensure any
change to data held at Companies house is adequately controlled.
Limit publicly available informationThere
is currently too much information publicly available at Companies
House. Any information that can be used in identity fraud should
not be publicly available and access to this data should be limited.
Amendments were being made to allow business addresses to be registered
as an alternative to a home address. Other details such as Signature
and Date of Birth which currently remain publicly available are
prime sources of data for identity fraud. Access to data such
as this should be restricted. The conflict of interest posed by
removing access to detailed address information etc needs to be
managed carefully so that this anti money laundering tool is not
removed in the desire to remove opportunity for fraud.
Cross reference of Identification
and Verification dataThere is currently no cross referencing
of data to that used in past fraud activity. This allows the same
details to be used in multiple frauds making it easier for fraudsters
to use companies to commit fraud eg MTIC fraud. This allows fraudulent
new accounts to be opened. There should be a warning list of director
names and addresses that have previously been used in a fraudulent
way available to cross reference against.
At the simplest level, the information that
could be verified would be name and home address of those people
notified as Directors, these could be verified against voters
roles, mortality files, VAT records etc. This would have to be
done on first creation of a record as well as when any changes
are made. In addition a call back/ write back system could be
introduced to validate changes for those companies who don't use
the online system for updating/ changing their information where
letters are issued to previous named individuals at previously
registered address. If this was combined with the promotion of
the current tools available to do this then the number of call
back/ write backs are likely to be a reducing number as it becomes
more convenient to make changes on line. From our point of view
it is very important that we retain the ability to access home
addresses of directors for the know your customer process.
On a related matter I mentioned that we have
identified significant issues and impacts on the way organisations
undertake their financial crime prevention work as a result of
changes to the Companies Act 2006Directors and Shareholders
Addresses.
Basically, this legislation prevents credit
reference agencies or Companies House passing on details of Company
Directors, Shareholders and Company Secretary. The reason for
the change in the law came about following the Directors of certain
companies, linked to the pharmaceutical sector, being at risk
from people such as animal rights activists.
From what I understand, the new Companies Act
allows for:
Company Director to provide a service
address and country of residence, rather than the usual residential
address.
A Director may give the company's
registered office as the service address.
The Director's residential address
will not be on the public record but is considered "protected
information" for the purposes of the Act, as is any statement
that his residential address is the same as his service address.
The provisions relating to the register
of Directors, including the introduction of service addresses
for Directors, are expected to come into force on 1 October 2009.
Private companies no longer need
to have a secretary. Public companies must still have a secretary.
The company is required to keep a register of secretaries which
shall include a service address for an individual, which may be
the company's registered office.
The Registrar must not permit disclosure
of protected information ie a director's residential address,
unless it is permitted to do so under section 243(permitted use
or disclosure by Registrar) or section 244 (disclosure under a
court order) or the 2006 Act.
Section 243 provides that the Registrar
may disclose protected information to a:
Public authority (as specified).
A Credit Reference Agency (CRA)however
the CRA can not disclose to the bank/lenders.
It seems that only the main CRA agencies will
meet the conditions set in place for them to receive the information
but again they will not be able to share the information with
us the lenders, they will not even be able to tell the banks if
our information is the same as theirs.
This exposes BBA members to significant risk
and will threaten how banks will meet their Customer Due Diligence
requirements for the following reasons:
Banks will not be able to link Directors
by the addresses usedit is often the case in fraud syndicates
that the link is the addresses used.
Banks will not be able to protect
ourselves at front end should these Directors make personal applications
for finance.
Banks will not be able to have any
access to addresses of the companies shareholders so will not
know who is behind the companies they are dealing with or in fact
where they live (Sanctioned Countries).
Banks will not be able to obtain
any documents from Companies House to confirm when and how someone
was added as a Director nor compare signatures.
If someone is a Personal Guarantee
on an agreement and they have moved since the date the agreement
was taken out the bank will not be able to locate them to enforce
the Personal Guarantee.
Access to limited information will
negatively impact Risk and Underwriting decisions.
Banks' investigations into individuals
who are added to companies as Directors will be frustrated as
they will not be able to contact them to confirm that they are
directors of the companies concerned and if their involvement
is genuine and if not protect them and advise them to have their
details removed.
Banks will not be able to contact
the genuine directors of companies that have been cloned.
22 October 2008
|