Chip and Pin, from today's FT.

Dec 23, 2004 10 Replies

NATIONAL NEWS BUSINESS & ECONOMY: FT041223 #153 Fraud liability threat over chip and pin RETAIL WARNING:



By ISABEL BERWICK



Retailers that have failed to put new chip and pin equipment into place could find themselves responsible for fraudulent transactions in their stores in the new year.



On January 1 the liability for card fraud shifts from banks to retailers if they have failed to install chip and pin equipment on their premises.



About 85 per cent of retailers have installed chip and pin so far, with some shops still waiting for banks to deliver the machines. Others, mostly luxury retailers, have decided to take the risk, claiming that they know their customers and that the cost of running the machines is expensive.



However, it remains unclear who will take responsibility for frauds committed in shops that have installed the machines but whose customers insist on using the old signature-based technology.



I've observed a spokesman from APACS being grilled on this recently. If a customer uses a signature-only card then the bank takes responsibility. If a customer uses a C&P card but is unwilling or unable to enter the PIN, the retailer should contact the bank (it wasn't clear whether this meant a phone call or use of an online terminal) and the bank would then decide whether to accept responsibility or to leave it with the retailer. The APACS spokesman was repeatedly asked how the bank made that decision, and merely hinted that an important factor would be whether or not the card had been reported as stolen.

Matti

Seems something of a 'no-brainer' to me. If the card has been reported as stolen, why would the bank even be discussing accepting responsibility with the retailer?

Surely the bank would mention this to the retailer, who would then abandon the transaction, and where practical attempt to detain the person presenting the card, and call the police.

Rgds

Rgds,

__ Richard Buttrey Grappenhall, Cheshire, UK __________________________

I agree -- it didn't make much sense to me at this point, and I concluded that the APACS chappie didn't want to answer the question for "security reasons". He did seem a bit more open than the usual APACS spokesperson, Sandra Quinn, who never gives a straight answer to any question if she can help it. It must be something in the water there.

Matti

"Richard Buttrey" wrote

... and if it has *not* been reported as stolen? What is your 'no-brainer' answer in that case?

I didn't see any mention of it here, but did anyone else notice that our entire discussion here about the increased possibility of fraud with Chip and PIN was summarised and presented by some knob-headed academic in the financial section of the Times as if it were his own work?

Not the point I was making. I was simply questioning why the APACS chappie needed to make that sort of point at all, as if there were some subtle diffence between a stolen / not stolen card which would affect who should take liability.

Seems to me that it's reasonable enough to discuss who accepts liability, but as soon as the question of a stolen card arises, at the point of sale and before the transactions is concluded, this should immediately take it out of the realm of discussion about liability, and it should become a completely different subject matter, i.e. how to deal with a fraudulent user of the card.

Rgds __ Richard Buttrey Grappenhall, Cheshire, UK __________________________

"Richard Buttrey" wrote

Possibly it is an automated system (online terminals) where the answer from the bank is simply either "yes, we'll take liability" or "no, we won't take liability" - without any ability to give an answer of "hold on, the card's stolen - confiscate the card & call security!" ... ?

"Richard Buttrey" wrote

Isn't it less of a matter of *who* will take liability, but rather a matter of simply *whether* the bank will?

In other words, they don't negotiate between retailer & bank and then decide who will take liability - the retailer simply asks the bank "will you?" and the bank answers. If the bank says "yes", then the retailer will probably go ahead with the transaction. If the bank says "no", then the retailer will think hard about whether they will or not!

Actually the bank can also answer with a "retain card" instruction or a "referal" instruction. In the "referal" case the cashier must phone their merchant's call centre before the transaction can be processed, to which any verbal instruction can then be given to the cashier.

tell you what , my estimation of the times is definetly going down

maybe we can put it down to the tea boys running the paper over december / jan period

I think what the APACS spokesman is talking about is not happening at the point that a credit/debit card is being used at point of sale, but once the fraud has been discovered, and liability has to be determined. I'm pretty sure the system doesn't let you use a stolen credit card!

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required