DIGIOSK Payment Platform
Risk & Fraud Prevention Summary
- Year
- 2019
- Version
- 1.0
Program Summary
The purpose of this document is to provide a brief overview of the systems and controls that DIGIOSK has put in place to prevent fraudulent activities and ensure a safe and secure experience for buyers and sellers.
DIGIOSK is a leading online payment platform that specializes in e-commerce processing, corporate disbursements, and remittances for individuals and businesses around the world. The e-wallet/prepaid platform provides DIGIOSK members worldwide with convenient and flexible loading and withdrawal options, such as localized bank transfers, global bank wires, credit/debit card, checks, and prepaid cards among others.
With over 1 million members, DIGIOSK offers its services in India. In addition, DIGIOSK offers, email invoicing, mass and single remittances and business management tools. DIGIOSK also provides under-serviced and emerging markets with an affordable and convenient way to receive payments, thereby bolstering local economies in a global marketplace.
DIGIOSK understands and emphasizes the necessity of a holistic and robust security program that detects and prevents fraudulent transactions, including strict underwriting policies and procedures along with ongoing Individuals and merchants' monitoring.
DIGIOSK's Risk and Fraud Prevention operations can be broken down into the following primary categories:
- Fraud Prevention and Pre-emptive Measures
- Fraud Detection and Post-occurrence Measures
- Merchants On-boarding Review and Ongoing Monitoring
The DIGIOSK platform incorporates various risk and fraud mitigation services:
- Phone Validation Services
- Credit Card Fraud Alerts
- Credit Card Risk Scoring
- Credit Files Validation
- Customer's Real-Time Identity Verification
- Merchants' Websites Monitoring
- Global Financial Sanctions Screening
- Geo IP Location and Proxy Detection
- FraudMatrix – real time flagging and blacklisting technology.
Acceptable Use Policy
DIGIOSK lists specific merchant categories that it deems unacceptable in the DIGIOSK User Agreement (http://www.digiosk.in/Terms&Conditions). All new account holders must agree with the policy prior to account creation. The following is a direct excerpt from the User Agreement and encompasses the primary business industries that DIGIOSK does not allow.
Activities Not Allowed
The sale, solicitation, offering, exchange or service of the following are not allowed:
- Tobacco products and related paraphernalia
- Imitation and replica products, including, but not limited to, clothing and accessories
- Drugs and related paraphernalia (including but not limited to research chemicals and illicit herbal incense)
- Gambling and/or casinos (including but not limited to lottery, sweepstakes, horse and greyhound racing, sport betting, and virtual poker chips)
- Pre-adult content, such as pictures, videos, etc., of individuals under the age of 18
- Any goods or services infringing intellectual property rights of a third party, including but not limited to streaming video/audio, illegal downloads, modification chips, DVD and Blu-Ray Disc decryption devices
- Illegal downloads or any other goods and services infringing intellectual property rights of a third party, including streaming video/audio
- Credit card protection, credit repair services, applications for financial services or loans and/or collection services.
- Solicitation, marketing campaign, direct selling or any other comparative effort will be considered a violation of the User Agreement. If you are registered or licensed to take such action, you may be requested to present documentation demonstrating authority to do so from a Securities Exchange Commission, Commodities Futures Trading Commission or other equal and comparative agency.
- Any indication or demonstration of a literal rate of return on a contribution, payment or investment, while not being licensed to sell or solicit
- Selling of Unregistered/Unlicensed Stocks, bonds, securities, options, futures, or investments in any entity or property, including (but not limited to) corporations and partnerships or sole proprietorship, are prohibited through any of the DIGIOSK networks
- Payment processors or any aggregation type services
- Sites that promote hatred, racism, sexism, religious persecution and/or any other prejudicial views
- Nazi war memorabilia
- Services using credit card transactions as deposits or credits, including pre-loaded debit/credit/cash/virtual cards
- Hazardous materials, combustibles and/or corrosives
- Weapons (Including and not limited to firearms and ammunition)
- Stocks, bonds, securities, options, futures, or investments in any entity or property, including (but not limited to) corporations and partnerships
- Remote technical support services and computer virus software promoted using unsolicited emails or outbound telemarketing
- Adult content and pornography (Payouts for affiliate commission acceptable)
The following activities are also not allowed through or in relation to DIGIOSK:
- Money laundering
- Infringing on any third party's copyright, patent, trademark, trade secret or other property rights or rights of publicity or privacy
- Violating any law, statute, ordinance, contract or regulation, including but not limited to those governing financial services, consumer protection, unfair competition, anti-discrimination or false advertising
- Submitting altered verification documents
- Being misleading, false or inaccurate in respect to DIGIOSK or any other User
- Any activity similar to or consisting of giving yourself a cash advance from your credit card or bank account, factoring or helping others to do so
- Any defamatory, trade libelous, unlawfully threatening or harassing statements or information
- Spamming (including and not limited to spam-ware, spy-ware, etc.)
- Using DIGIOSK as a virtual terminal
- Exchangers unless approved by DIGIOSK
- Using currency exchangers or aggregation, unless approved by DIGIOSK
- Transmitting personal information of other DIGIOSK members to third parties
- Using or selling any form of e-cash, web cash or other matter, tangible or not, that is redeemable by a Buyer for a product or service from a third party
- Abusing the Earn Money program in any way we consider inappropriate
- Using the DIGIOSK brand to market or advertise your product(s)/service(s) in any capacity
- Threatening legal action against DIGIOSK and/or DIGIOSK employees
- Diluting our traffic by using our Trademarks (including but not limited to Adwords)
The list of activities not allowed is not exhaustive and may be updated at any time in order to satisfy DIGIOSK's own risk management processes.
Furthermore, anything that causes us to lose or become liable for, in whole or in part, the services of our sponsoring banks, Internet Service Providers or other suppliers is not allowed. If you use or attempt to use the Service for purposes other than sending and receiving payments and managing your account, including but not limited to tampering, hacking, modifying or otherwise corrupting the security or functionality of the Service, your account will be terminated and you will be subject to damages and other penalties, including criminal prosecution if necessary.
Fraud Prevention and Pre-emptive Measures
The following controls are in place to minimize the risk of fraud occurrence.
Anti-Fraud Matrix
The FraudMatrix is rule-based monitoring tool, which is continuously adapted to include all possible suspicious patterns to identify suspicious transactions and activities and to flag the associated accounts. When an account is flagged by FraudMatrix, Fraud Team immediately reviews it and takes appropriate steps to terminate such activity.
Customer Profiling
The customer's name, email address, mailing address and IP address are screened through the entire database for possible matches against other customers and known fraudsters.
Geo IP tracking
With IP address geo-location tool, the system checks the consistency between customer's profile address and login's IP address; automatically blocks clients from creating accounts or logging in from banned countries; prevents the attempts of fraudulent users from reentering the system.
Device detection
Advanced device detection mechanisms such as cookies, HTTP headers, JavaScript and Flash objects are used to profile a customer with significant accuracy and allow to associate members who are attempting to conceal their IP address, true identity, or a relationship with fraudster's account. The tool is also utilized to prevent the attempts of fraudulent users from reentering the system.
Account limitations based on verification status
Based on regulatory requirements and its risk-sensitive approach, DIGIOSK has established transactional limits for each type of services and products that customers can use prior to becoming verified, as a part of its risk mitigation program. Business accounts/Merchants must be verified before the access to any DIGIOSK's services/products has been granted.
Financial Tool Validation
DIGIOSK requires its customers to confirm their payment methods in order to enable the use of these methods. To validate bank account, two micro deposits are sent to the customer's bank account, and the customer must have access to the bank account statement in order to be able to confirm the amount of deposits.
Automated account verification
The availability and types of automated verification methods vary by location. Users can be verified through the third party service provider, Aadhaar, PAN, Passport, Driving License, Voter ID by validating their credit files.
Manual account verification
Manual account verification is applicable to different jurisdictions as a primary verification method and in a number of other circumstances:
- A customer's account is flagged for unusual behavior (e.g. large value of transactions, irregular transfers, IP mismatch, etc)
- Suspicious information detected on the account
- As an alternative to automated verification features or for EDD purposes
- Use of additional DIGIOSK features (Localized banking, Prepaid card applications, BBPS, etc)
- Business account verification
- High Risk Accounts/Merchants
The manual verification of personal accounts includes review of Self Attested proof of identity and proof of address documents. Mailed documents are all also accepted but not advertised.
Business verification includes the confirmation of accuracy of the following information:
- Name of the corporation
- Corporation's registration number
- Business address/where the business is registered
- Nature of business
- Names of all directors of the corporation
- Authorized number of shares and ownership structure
- Names, addresses and occupations of all beneficial owners/shareholders who own or control, directly or indirectly, 25% or more of the entity
- Corporate bank account information
- DIGIOSK account holder's name, address, date of birth, occupation and business relationship to the corporation
- The intended purpose of use of the DIGIOSK platform
Credit Card Bank Identification Number (BIN) Check
Bank Identification Number (BIN) list is used to assess the type of card used, such as standard credit card, gift card, or one-time used credit/prepaid card. BIN list is used to detect the suspicious patterns. A high volume of fraudulent activities coming from credit cards issued by the same bank can trigger a permanent or temporary blocking of this BIN.
Visa 3D-Secure / Mastercard Secure Code / RuPay
Secure Code/3D-Secure requires a user to provide a private code or password for transactions. Password is not visible for DIGIOSK personnel, and the transaction is declined if the user fails the additional authentication requirement.
Negative Databases
The internal and external negative databases are used to verify that the card details, was not previously associated with any type of fraudulent activity or chargeback.
Physical Prepaid Debit Cards Restrictions
PPC services are provided only to verified accounts. Disregarding of the verification method that has been applied to the account, a proof of identity and proof of address documents must be supplied. DIGIOSK has established a daily combined limit for transfer in and out.
Additional controls are in place:
128-bit SSL Encryption
- All transactional data is filtered through a 128-bit Secure Sockets Layer SSL encryption. DIGIOSK's encryption system secures the personal and financial data of its members to prevent fraudsters from intercepting and exploiting this information.
PCI/DSS Compliant
- The DIGIOSK platform is PCI-DSS Level 1 compliant.
AML/CFT Compliance
- DIGIOSK is fully committed to conducting due diligence on its clients and to ensuring the compliance with all applicable anti-money laundering law and regulations to detect and report money laundering and terrorists financing activities. DIGIOSK takes its responsibilities to analyze potential threats and vulnerabilities to money laundering and terrorist financing very seriously. To assess the potential risk that a customer can pose to the company, DIGIOSK has developed and implemented its AML/CFT Risk Assessment Program.
- The information the customers provide when setting up their DIGIOSK account is also screened against the global Financial Sanctions and Politically Exposed Persons lists maintained by the Office of Superintendent of Financial Institutions Canada (OSFI), the Office of Foreign Assets Control (OFAC), Reserve Bank of India and other relevant authorities. This screening is completed by using Bridger Insight XG tool provided by LexisNexis, a third party provider.
Fraud Detection and Post-Occurrence Measures
DIGIOSK utilizes a combination of different controls along with Fraud Prevention Team's manual review to detect fraud after it has occurred in the system. These controls fall into two major categories: early stage and late stage detection.
Early Stage Fraud Detection
Using the combination of different control tools, Fraud Prevention Team identifies potentially suspicious behavior and high risk activities occurred in the system. Each type of transactions is thoroughly reviewed by Fraud Prevention Team. Based on various criteria, the transactions may be blocked, flagged or allowed. The following types of transactions are reviewed:
- Bank transfer deposits and withdrawals
- Credit card transactions
- Prepaid card loads
- Transfers between accounts
The transactions are assessed based on the following risk factors:
- Account Risk Score — Each customer is assigned a risk score upon registration.
- Transaction Velocity — The spending patterns or the payments receiving velocity of the customers are the factors used to identify suspicious or high risk accounts. Excessive transactions originating from a single IP, Device ID, or credit card are blocked or flagged (on a tiered velocity basis).
- Account Age & History — Based on the age and the transactional history of the customers' account, the risk is appraised.
- Account Activity — The following items are monitored by Anti-Fraud Matrix to identify and flag suspicious accounts:
- Matching information between accounts sending funds to or receiving funds from
- Multiple accounts detection (device fingerprinting)
- Adding multiple payment methods in a short period of time
- Proxy detection
- Historical IP transaction or login mismatch
- BIN to IP or address mismatch
- Adding two or more of the same BIN credit card on an account
- Maximum or near maximum value transactions
- Login from foreign countries
- Same device logging into multiple accounts in a predetermined amount of time
- Same device creating multiple accounts in a predetermined amount of time
Late Stage Fraud Detection
Late stage fraud detection serves as an additional review that takes place prior to allowing funds to leave the DIGIOSK system. All withdrawal transactions are reviewed by the Fraud Prevention Team in order to prevent the exit of fraudulent funds from the company's system. DIGIOSK has established appropriate systems and controls allowing to trace the funds back to the originating account to ensure that no fraudulent activity was associated with these funds.
For withdrawals attempted for the first time or initiated after a period of inactivity, a quality assurance process is in place to ensure that the funds have been received for a legitimate reason, the client is satisfied with the product and service, and the activity is in accordance with DIGIOSK's User Agreement. A Fraud Prevention Analyst contacts the senders of the payment through telephone or email to determine if they received the product or service as advertised prior to releasing the funds.
Few communication channels are available to the customers to report suspicious activities. The reporting can be done through an email, by calling in or via live chat. DIGIOSK's Fraud Response team persistently reviews suspicious activities, phishing attacks, and unauthorized transactions reported from the customers.
All activities and actions taken by the Risk and Fraud Prevention Team are internally audited on a weekly basis to assure consistency and quality control.
Merchant Risk and Ongoing Monitoring
Merchants are thoroughly reviewed during the onboarding stage and then continuously monitored during the life term of their accounts.
Merchant Onboarding
User Agreement
- The applicant reviews and agrees to not conduct business that contradicts to the activities/industries supported by DIGIOSK and disclosed in the User Agreement located on https://www.DIGIOSK.com/legal-agreements/
Merchant Review and Underwriting
- During this process all business information is collected; business documentation, business model and associated website(s) are reviewed prior to rendering a decision on the account.
- Upon a successful review and approval of the merchant application, account's limitations, hold periods and reserves are assigned to the merchant account.
Ongoing Monitoring
A multifaceted approach is used for the ongoing monitoring of the merchants' accounts.
G2 Web Services Monitoring
Merchant reports are sent, on a monthly basis, to G2 and include all websites accepting payments though a DIGIOSK 'Buy Now' button. G2 persistently monitors all websites on this report for any Business Risk Assessment and Mitigation (BRAM) violations including:
- Gambling
- Tobacco
- Pharmaceutical sales
- Replica products
- Child pornography
- Rape/violence
- Hate
- Bestiality
These key BRAM are of most concern to Card Associations, DIGIOSK and its Partners. In addition to such violations, DIGIOSK uses G2 to monitor for User Agreement violation such as:
- Alcohol
- Pornography and adult content
- Drugs
- Weapons
- Electronic fund exchangers
- Credit repair services
- Remote technical support services
- Timeshares
- Lotto tickets
Utilizing G2 Web Services assures that after the initial website review and approval, merchants continue to remain compliant and do not alter content that would put DIGIOSK or any of its partners at risk.
Merchant Risk Analysts review reports of violations and terminate the associated DIGIOSK accounts that are in violation of the DIGIOSK User Agreement.
As well, DIGIOSK will use a merchant risk agent that is dedicated to searching for prohibited items associated with DIGIOSK that G2 may miss.
Keyword Monitoring
- The DIGIOSK Merchant Risk Team searches major search engines for the keywords indicating major violations.
Quality Assurance/Customer Satisfaction Survey
- When a new seller begins an activity (or recommences after a period of inactivity) using DIGIOSK services, a minimum of 3 emails or phone calls are placed to his/her buyers to assure that the products and services are delivered, are satisfactory, and fall within acceptable business categories and guidelines.
Internal Audits
- The Merchant Risk Team conducts a comprehensive weekly review of accounts with high transaction, refund and chargeback volume and undertakes appropriate actions based on the investigation's results.
Employee reports
- DIGIOSK encourages and promotes an internal reporting process for all employees that detects or observes any suspicious activity on any DIGIOSK account that may be in violation of the DIGIOSK User Agreement. All flags & emails are reviewed on a daily basis by the Merchant Risk Team; an appropriate investigation and actions are taken.
Chargeback Monitoring
Merchants exceeding the following thresholds are entered into the DIGIOSK excessive chargeback program:
- Merchants exceeding a chargeback to sale ratio of 1.5%
- Merchants exceeding a chargeback to sale ratio of 1% for two or more consecutive months
- Action plan developed with merchant and reviewed by DIGIOSK Merchant Risk Analyst
- Acceptable timelines for improvement established
- Continued monitoring
- Account review completed after established timelines
Resolutions/disputes
All users of DIGIOSK are entitled to utilize the internal dispute process. This process allows recourse for buyers who are unsatisfied with their purchase. The process includes the reason for the dispute, item purchased, and location of purchase (URL).
DIGIOSK does still encourage members to resolve their disputes directly. If, however, the buyer and the seller cannot reach a mutually agreed upon decision, the customer may file a dispute via the Resolution Center. The Resolution Center is an area dedicated to filing, responding to and resolving disputes between DIGIOSK members and is accessible via the DIGIOSK member's account.