RemoteDepositCapture.com - The Independent Authority on Remote Deposit Capture.
The Independent Authority on Remote Deposit Capture.
Advertisement
RDC Marketplace
May 17, 2012
Search forums: 

Advanced search

Welcome to the Remote Deposit Capture Forums


Go back to Forums
Risk & Fraud Discussion Forum
Legal & Regulatory Discussions > Risk & Fraud Discussion Forum > MFA View modes: 
User avatar
Guest
jking - 3/6/2008 2:56:55 AM
   
MFA
Is MFA required on Remote Deposit Capture? Our software limits the information provided about our customer, but images of deposited checks are stored on the software for up to 60 days. It seems to me that the information and the risk posed would be high and should require MFA on the user side; however there are varying opinions in my institution regarding the necessity. Any help that you could provide would be appreciated!

User avatar
Site admin
Site admin
ed.mclaughlin - 4/8/2008 12:21:16 AM
   
Re: MFA
We all know that the Federal Agencies involved are in the process of  developing their guidelines around RDC authentication and how those fit with the definition of “high risk transaction” in the strong authentication guidance issued in October of 2005 by the FFIEC agencies. We have, however, not received the RDC guidance as of today, but what we do know is that remote deposit was classified as an electronic bank function (August of 2007 FFIEC BSA/AML Examination Manual. The rules for testing whether the transaction is high risk, as defined/used in the Manual, and/or exposes consumer or business account data, in my opinion, should be used; and if the transaction involves the movement of money and or use of account information then it is considered high risk and, therefore, single factor authentication is not adequate and it requires “strong authentication”.

Strong Authentication means using either, multi factor authentication (two factor or more) and/or a layered security approach to authentication in addition to single factor. The layered approach is used to define an approach where different types of technology are used for authentication/security and can employ “in band” as well as “out or band” (e.g. telephone follow-up) techniques to insure the identity of the user and of the host server (bank).  The FFIEC guidance specifies that “where risk assessments indicate that the use of single factor authentication is inadequate, financial institutions should implement multifactor authentication, layered security, or other controls reasonably calculated to mitigate the risk…”

These requirements not only apply to the deposit but also to the online reporting of deposits taken by remote capture where confidential data is displayed. What authentication is required for administrative procedures, accessing reports as well as for processing deposits?  It appears to me that the same level of authentication/security as described above is required.

1

Latest forum posts

Manage, Optimize and Secure your check capture devices with Panini Avantor™

Panini Avantor gives you professional asset management, performance optimization, and device security all in one modular and extensible system adaptable to the widest possible business requirements.   To learn more about AVANTOR™, Click Here  MANAGE. Avantor asset management...
Posted on 5/16/2012 1:57:15 PM


Just Published: The RDC Summit 2012 Agenda & Session Descriptions

Please visit the RDC Summit website ( www.RDCSummit.com ) to view the 2012 Agenda & Preliminary Session Descriptions. For the first time, we established a Conference Steering Committee comprised of experts from throughout the RDC Industry to help ensure insightful, on-topic, value added sess...
Posted on 5/15/2012 5:46:23 PM


Create ICL Files From A Folder Of Scanned Document Images

Create ICL Files From A Folder Of Scanned Document Images All My Papers  (AMP) develops and distributes a software application,  All My Checks™, that processes a folder of scanned documents to automatically create Check Image Cash Letter (ICL) files formatted for check ima...
Posted on 4/24/2012 2:39:01 PM


The RDC Network on LinkedIn – Over 2,000 members and growing!

The Remote Deposit Capture Network on LinkedIn has hit yet another milestone: 2,000 members! If you are not yet a member, you are missing some great benefits: Pulse on the market: News, articles & Press Releases posted to RemoteDepositCapture.com are automatically included in the RDC Net...
Posted on 4/23/2012 10:14:14 PM


RE:USAA / MITK Patent Dispute – Impacts for the Mobile Remote Deposit Industry?

Good post and like any fledging industry the mobile deposit industry is finding its feet - the market needs balance and a choice of technologies to choose from in order for each FI to make their own jusdgement as to which best suits their business - i think the RDC summit in September will help F...
Posted on 4/18/2012 10:05:48 AM


RE:USAA / MITK Patent Dispute – Impacts for the Mobile Remote Deposit Industry?

Today Mitek filed its response/counter claim to the USAA lawsuit ( http://remotedepositcapture.com/news/news.aspx?aid=43800 ).
Posted on 4/11/2012 10:03:23 AM


RE:USAA / MITK Patent Dispute – Impacts for the Mobile Remote Deposit Industry?

We just created a poll to survey our site visitors... For Bankers and Credit Unions: Will the Mitek / USAA patent dispute impact your plans for Mobile RDC? Click Here to take the poll.
Posted on 4/9/2012 4:41:01 PM


The importance of BSA/AML SAR Reporting with RDC

Copied from the Managing Risk with RDC and mobileRDC forum. http://remotedepositcapture.com/community/Forums.aspx?forumid=16&threadid=1149  In the post it mentioned SAR reporting activity related to RDC and BSA/AML.Today, the OCC issued a cease and desist order (NR 2012-57, April 5...
Posted on 4/5/2012 3:20:13 PM


RE:Managing Risk with RDC and mobileRDC while expanding adoption

In the previous post, it mentioned SAR reporting activity related to RDC and BSA/AML. Today, the OCC issued a cease and desist order (NR 2012-57, April 5, 2012) against Citibank N.A for deficiencies in its BSA/AML program and controls, and failure to submit timely SAR reports for suspicious activ...
Posted on 4/5/2012 3:06:28 PM


RE:USAA / MITK Patent Dispute – Impacts for the Mobile Remote Deposit Industry?

The provisional patents filed by Mitek were public the day they were filed in 2008. Did the USAA patent attorneys just miss them? It appears that the two have had a successful and award winning relationship over the years. In 2010 at a BAI conference in Chicago USAA and Mitek were individually aw...
Posted on 4/3/2012 12:50:45 PM