Importance of IT and data protection in finance
By Kim Yoo-mi

Kim Yoo-mi
Visit a bank branch in the United States and you will find a coffee shop. American banks have started refurbishing their local branches where staff can help the customers use banking services and address inquiries.
This is a complete transformation; not simply having space for a coffee shop. In the U.S., it is deemed a fresh attempt to attract customers when there is a higher preference for electronic banking on the Internet and mobile devices, leading to lower demand for face-to-face transactions at the teller’s window.
Korea is also seeing rising demand for Internet and mobile banking services, causing financial branches to diminish. Up until 2011, Korea was one of the few countries without any signs of a decrease in branches, but the number started falling in 2012.
In contrast, the number of registered online banking customers at home exceeded 100 million as of March this year. Among them, mobile banking users steadily rose to 64.1 million. Non face-to-face transactions are growing fast as demonstrated by the fact that money deposits, withdrawals and transfers on the Internet are twice that of those teller’s windows, and balance and transaction inquiries five times more.
This changing landscape is characterized by the emergence of diverse banking channels such as ATMs, PCs and mobile devices, which is in stark contrast to the past when money and checks were the major means of financial transactions.
Moreover, there is a widespread use of smartphones, along with the advent of new technologies ― for example, social networking, cloud computing and big data. Fin-tech is recently driving financial innovation that enables services totally different from existing ones.
Over the years, IT has performed back-office functions to allow automatic and efficient administration of financial services, but is now at the forefront as the competitiveness of a business depends on its ability to elicit valuable information from large amounts of consumer data that it has accumulated thanks to advances in IT.
Given the vast pool of data that is playing a central role, and an increasing number of people who want to obtain such information, it is now time to remind ourselves of the importance of IT and data protection.
“Information about money has become almost as important as the money itself,” said Walter Wriston, former chairman and CEO of Citibank. His remarks emphasize the significance information holds for financiers, as they handle information about money, not just money itself.
It is natural that information is valued in an information society and thus it is inseparable from technology that enables its use for valuable insights. Then, it should be just as natural that the value of technology changes, depending on the value of information and the speed at which it grows.
In the aftermath of a personal information leak by three major credit card companies at home, the importance of customer data protection has become greater than ever.
In the past, financial companies placed an emphasis on protecting customers’ assets entrusted to them, but now are increasingly aware of the importance of keeping financial transaction information safe.
This recognition also comes amid public concern that insufficient data protection and internal control measures at financial companies could lead to the theft and abuse of personal financial information.
When the leak by the three credit card companies became a serious issue, numerous people, fearful of incurring losses, scrambled to a customer service center waiting in line to cancel their credit cards.
This clearly demonstrates that customer confidence in the financial system is ultimately based on safety, not just convenience. Even though more and more financial services and a wide variety of access channels continue to make financial transactions easier, the overriding principle that we must not forget is that “financial services without information security guaranteed will eventually turn out to be a house of cards.”
The Financial Supervisory Service (FSS) has so far endeavored to prescribe detailed methods and procedures regarding customer data protection for financial companies.
It is, however, hard to deny that these regulatory rules have discouraged financial companies from developing their own information security solutions and improving their own ability to deal with financial “accidents,” against the backdrop of advances in hacking techniques and rapid changes in the IT environment.
Also, the rule-based regulation could mislead financial companies that they are only responsible for complying with these rules, and use it as an excuse for failure to protect customer information.
To address this issue, the FSS is now shifting the regulatory paradigm away from rule-based regulation to principle based, emphasizing financial companies’ accountability to undertake more meticulous efforts to protect consumers.
As customer expectations for electronic financial services are becoming increasingly high, financial companies will need to make diverse efforts to provide services that are not just convenient, but also safe.
Thus, it is vital they adopt a fraud detection system and reinforce internal verification processes in order to prevent financial accidents such as an information leak.
They should devise their own IT security strategy and implement stronger internal control measures effectively. It is also critical to make these efforts continuously via close cooperation and information sharing with relevant agencies and financial companies.
Kim Yoo-mi is a senior director general at the Financial Supervisory Service.