Showing posts with label atm. Show all posts
Showing posts with label atm. Show all posts

Thursday, March 13, 2014

White label Human ATMs a.k.a Business Correspondents

We should look at our inherent strengths to solve some of our pressing needs. As a country, there are a few things pretty peculiar about India. Take for instance, the sheer size of some of its problems. Some of our 'problems' are as large as a few other countries' entire populations put together. Herein lies the opportunity as well. We are also, a massive sea of humanity yearning to serve its unmet needs and earn our rightful place under the sun. Technology has a huge role to play as well; not at loggerheads but complementary.

October last year, Abhishek (Eko) and Ignacio (ex BMGF) published a post on IFMR blog titled 'Extending the third-party aggregator model from ATMs to Business Correspondents'. This was a revolutionary thought and got picked up by the Nachiket Mor committee on Comprehensive Financial Services for Small Business and Low Income Households. The report was released by RBI recently and has generated quite a few discussions for its take on how retail banking needs to evolve in India.

Just to set the context, Business Correspondents (BCs) are firms or individuals who provide banking services to customers on behalf of a bank. The RBI established the BC model sometime in 2006 to solve the financial inclusion needs of this country. The BC provides the last mile access, reaching where a bank could physically and economically not reach through traditional means. BCs are currently tightly coupled to a particular bank. The BC would feature the brand of its bank, offer products of its bank and liaise with the branches of its bank only. However, interoperability in transactions is conceptually promoted and to an extent implemented. The BC is therefore a human ATM (and more, since the BC can do much more than an ATM can) and the community banker/ an agent of the bank.

Most implementations of the BC network by the banks have only attempted to comply to RBI/ finance ministry mandates for financial inclusion and have been restricted to 'Open X accounts in Y villages' or 'Disburse X rupees of government benefits to Y people'. Most of these initiatives have therefore been seen as cost-centres and as regulatory obligations by the banks and rarely have these been viewed as profit-centres or even as viable business units.

After spending many years in mere obligatory compliances and having spent significant amounts of money to fuel these endeavours, a few banks like the State Bank of India and the ICICI Bank have realized the need to turn this model around. Someone in these banks has rightly put his/ her foot down and said that the whole movement needs to be viable, sustainable and scalable to have any real and meaningful impact.

A few BCs themselves have seen that they could not sustain with a fundamentally non-viable business model. Eko, for instance, has been a BC which has used technology to ensure that its costs were razor thin, invested in ensuring a great user experience and has innovated on the products along with the banks. In short, it is in the best interests of a BC also to ensure that more and more customers, transactions and products flow through their channel and that most of these activities generate enough revenues to sustain them and their partners in the value-chain.

White label ATMs are a relatively new phenomenon for India where a third-party owns and operates a network of ATMs under its own brand and not necessarily for/ by a particular bank. The Tatas and The Muthoot Group have already started setting up their WLATMs in India.

Lets assume that a typical ATM machine costs Rs. 10 lac to deploy, maybe cost a Rs. 1 lac to maintain (rental, electricity) annually. Also, the average life of an ATM would be 5 years. So 5 years on, we must budget for some amount to replace atleast some parts of this machine, lets say this is just Rs. 5 lac. Assume that the ATM earns Rs. 8 per transaction. Ignoring the cash management costs, and security costs (which would be significant) and any other overheads; to break-even, every ATM needs to process approximately 140 transactions per day, every day for the next 5 years.

Also, of course, to set up a network of say a 10,000 ATMs, the capital expenditure is going to be significant (Rs. 10,00,000 x 10,000) and that capital comes at some cost.

Again, the following articles provide some context: A recent article in Times of India pegs a deficit of 19,000 odd ATMs for the public sector banks India compared to the targets set. Also, interesting is this article which quotes officials from SBI, which operates the largest ATM network in India, saying that its ATM operations were loss making.

Now, technology moves ahead way faster than banking can. Mobile banking/ commerce is slowly but steadily getting popular. The RBI has also published that it envisions a less-cash (though not a cashless) society in the near future. For all we know, physical cash might actually become much less relevant in the next 5 to 10 years. Perhaps mobiles will take over where cards have not? While this seems implausible, take a look around; if 10 years ago, someone had told me that almost every economically active individual in India would have a mobile phone, I would have laughed. Video conferencing/ tele-presence used to be stuff from science fiction! My mobile phone has more processing power today than the all the computers in my school lab put together. I am not implying that ATMs would become irrelevant anytime soon- indeed these machines would themselves evolve in ways we may not anticipate today, but they are definitely under time pressure.

With access to one tenth the capital required for ATMs, we could set up a human ATM network that is a hundred times larger. Consider a human ATM network that uses mobile phones/ mPoS as access devices. Add to it the fact that it would not need to overheads that a normal ATM would need, including power, rental etc. Also significant is the fact that much leaner and efficient cash management systems could get deployed here. The result would be a low-Opex and very low-Capex network of banking agents who would not only do cash-in/ cash-out but also educate, solicit and facilitate enrolment to a range of financial products. Also, these costs are nothing but investments in people; in agents who are entrepreneurs. Any improvement in their livelihood would only have a positive rub-off in the community that they serve and the nation at large.

The white label BC model, would achieve a sort of decoupling for the banks where banks would be freed up from having a operationally heavy involvement in these activities. Having endorsements from multiple banks or the central bank itself would create an environment of trust as a legitimate banking channel even for existing customers across different banks and thus more footfalls. This could result in better returns for the agents involved and could lead to a viable and sustainable financial ecosystem designed for outreach and customer convenience.

This model is not without its short-comings though. Managing a huge network of agents is no easy task. Selecting and appointing them is no cakewalk either. Also, people, as they say, are more vulnerable to break-downs than machines are. Each of these risks can arguably be mitigated through appropriate processes, technologies and audit mechanisms.

Prevalent perception is that while technology makes things more efficient, it also causes banking to lose the human touch. Perhaps it is prudent to seek a middle ground here, especially as this also involves introducing hitherto unbanked people to a formal financial system. A little hand-holding and human touch should be welcome, right? Eager to see how this concept plays out.

Monday, August 27, 2012

ISO 8583. An introduction. Plain and Simple

This post is dedicated to all who have just stepped into the financial transaction processing technology world as we know it and want a primer on one of the most prolific protocols powering this world- the ISO 8583.

Introduction

Almost all of us would have swiped a card or two at an ATM or a PoS terminal (or a Square dongle ;)). At the very least, the card serves as an identity factor. Among other things , the magnetic stripe on each card stores something called the PAN (Primary Account Number). For most credit cards, it is the same as the credit card number printed on the front surface/ plastic.

The act of swiping a card on a card reader essentially involves passing this 'identity' of the card to the electronic sub-system and represents a Card Present type of transaction. Alternatively, one could have typed in this information (card number) on a screen of an online shopping interface but then this would effectively become a Card Not Present transaction.

Anyways, we now have the identity of the card in the electronic form. One of the most popular uses of this information is to let the system know which account to debit. (In case you get confused by 'debit' and 'credit': Debit = Deduct from your card/ account. Credit = Create money in your card/ account. In case you wish to find out more about the Latin origins of the words, start here:Why do accountants use debits and credits instead of simple pluses and minuses?)

Origin

Way back in 1987 (I think), The International Organization for Standardization (ISO) declared a standard called the 8583 to facilitate the flow of transaction information interoperably. I believe Visa and Mastercard had come into existence much before this and some form of interoperability existed even before this standard was declared. The important point is that both Visa and Mastercard had adopted this standard at some point in time. Also, the standard has gone through numerous iterations and various financial institutions have tweaked it to create many flavors/ variants.

What and Why?

So what is ISO 8583? It is one of the many standards describing how to pack certain data fields such that it could reliably be unpacked as well and is mostly relevant for the financial transaction processing world.

So this standard helps the electronic system which reads the card number, the transaction amount and other relevant data fields to pack it all up so that it could be transmitted electronically to a transaction processing system where it could then be unpacked back into individual data components and then processed. It also helps the transaction processing system pack and send the response back to the initiating device where it could again be unpacked and the customer be intimated of the transaction response.

There exist numerous methods for packing and unpacking data. It could be as simple as comma separated fields. Eg: I could choose to send the transaction information as simple comma separated values as:
"1234123412341234,1000,INR,987" (Card Number, Amount, Currency, Merchant ID).

The issue with such a simplistic model of data packing is that it lacks meta information. That is, the message itself does not contain any information on what exactly is being packed in it. Not that it could not have been overcome even with a comma separated version- just that it could get cumbersome. Also, I guess at that point in time, it was important to consider that the packing and unpacking could be coded easily into mainframes, not sure about this one.

Many folks have already begun writing obituaries to the ISO 8583 protocol thanks to the advent of the younger and dynamic (but not leaner) ISO 20022. However, thanks to its proliferation, ISO 8583 will be a difficult one to get rid of soon and hence one way or the other, in this industry you will need to know this veteran.

Principles

The ISO 8583 message is based on the principles that:
a. In a transaction message, you only get to pick any number of fields from a predefined set of fields. So, if you need a field called 'My girlfriend's phone number', sorry, ain't possible.
b. The meta information of which fields are present in the message are also a part of the message payload in a data structure called the 'bitmap'.

Structure

Most implementations contain a few bytes dedicated to a fixed header (eg: ^A^TISO016000010) after which the actual ISO 8583 message starts.

MTI

The Message Type Indicator.
The first 4 bytes describe the message type. Eg:

02 00
which tells that the message is actually a financial transaction request. (The response to this request would also be in ISO 8583 and would carry an MTI: 02 10). Various MTIs exist and can be found on the web.

Bitmap

Now that we know that this is a financial transaction, we would naturally expect a few important fields to be present. But which ones exactly? This is where the bitmap comes into play. It is almost a visual representation of which fields are actually present in this message and which fields are not.

Imagine a switchboard with 64 ON/OFF switches arranged one after the other from left to right. Lets assume that each switch represents each of the 64 main pre-defined fields. (The 1st field is interesting, we will come to that later). For every field that is present in the message, assume that we turn that particular switch ON and for every field that is absent, we ensure that the switch at that position is turned OFF.

For example, assume we had only one field present and if that field was field no. 3, all other switches except the third one from the left would be in OFF position.

If we write 1 for every switch that is ON/ field that is present and 0 for every switch that is OFF/ field that is not present, we get a series of 1s and 0s. This series of 1s and 0s is called the binary bitmap. It is, as I'd mentioned, a linear visual map of which all fields are present in the message payload.


Data Element Map, B64. Binary. 64 bits

Eg:
F2 38 80 01 08 E0 80 0F

11110010  00111000  10000000  00000001  00001000  11100000  10000000  00001111


(all the bit positions that are 1 implies the corresponding fields are present)
Hex  Binary           (Positions that have 1)
F2= 11110010  ->  (1,2,3,4,7)
38= 00111000  ->  (11,12,13)
80= 10000000  ->  (17)
01= 00000001  ->  (32)
08= 00001000  ->  (37)
E0= 11100000  ->  (41,42,43)
80= 10000000  ->  (49)
0F= 00001111  ->  (61,62,63,64)

Bingo, we've just read the map! Therefore the fields that will be present in this message are field numbers: (1,2,3,4,7,11,12,13,17,32,37,41,42,43,49,61,62,63,64)



Note the first bit. Field 1 is a special field which indicates the presence of an extended bitmap. Since this sample message contains 1 on the 1st position, it means that this message contains another bitmap with another 64 bits.

Extended bitmap, b64. Binary 64 bits

80 00 00 00 00 00 00 00
(=hex .extended bitmap field)
(80)10000000 -> (position 64+1=65)

This extended bitmap shows that field number 65 is also present in this message.

Data elements

Immediately after the bitmap, the data elements start serially. From the bitmap we know that fields 2,3,4,7 are present one after the other. All that we need to do is to read them one by one. Each field number has a predefined type in the ISO 8583 definition and has a predefined length. Some fields have variable length in which case the first N bytes provide the length of the field.


Example:

Data Element 2. Length 16. Value : 0000011319353459 = Primary account number
Data Element 3.  Length 6. Value : 011000 =Processing code. 011000 = cash withdrawal
Data Element 4. Length 12. Value : 000000020000 =Amount 200.00
Data Element 7. Length 10. Value : 0804030013 =DateTime DDMMhhmmss
Data Element 11. Length 6. Value : 051028 =Systems Trace number
Data Element 12. Length 6. Value : 083013 =Time, hhmmss
Data Element 13. Length 4. Value : 0804 =Date, MMDD
Data Element 17. Length 4. Value : 0804 =CaptureDate, MMDD
Data Element 32. Length 6. Value : 123456 =Acquiring institution ID code 123456
Data Element 37. Length 12. Value : 192165102801 =Retrievel Ref. No.
...
Data Element 65. Length 50. Value : Customer Withdrawal   =Statement narrative, right pad spaces.


Thats all folks! You've been hereby introduced to the venerable ISO 8583 :). I have only scratched the surface and the intent was a friendly introduction to its structure. There are many more layers involved in actual implementations of the protocol. The following lines could help you learn further.

Additional resources

1.The Wikipedia on ISO8583
2. jPOS - an open source implementation started by Alejandro Revilla and a default choice for many developers
3. (paid) ISO specs: 2003


Saturday, November 19, 2011

On mediated usage

The developing world, as the term seems to suggest; is at a stage that the developed world had crossed (or in some cases, even entirely skipped) being in at some point in time. I believe, mediated usage is a stage that most human interactions pass through initially.

Lets start from a simple but overkill-ish example. Ever heard of Bill Gates? The influential figure whose contributions range from the technology world to global policy world. Once upon a time, even he was a little baby in a diaper who could barely say 'ga-ga' and had to be fed, cleaned, clothed and taught by someone. The point I am trying to make is that doing things on our own, is not as natural or as normal as it seems. Self-transaction (of any kind) is a stage of evolution that is built upon multiple previous and related instances of mediated transactions. While mediated usage is like experiencing things using basic arithmetic, self-usage is more like calculus. In ones arrogance of context and experience, solving a differential equation might seem 'obvious' and 'simple'; try imagining what you'd have made of it as a fourth grader (if you were a calculus prodigy, sorry, this example does not apply to you). There is a certain threshold that one needs to cross before being able to be autonomous.

Let me now move to another example. Vending machines. Modern vending machines have apparently been around since the 1880s in the west! The first time I saw a vending machine was a Chocolate/ Magazines (Cadbury's?/ Malayala Manorama - don't remember which one) vending machine at an Indian railway station in the 1990s. Interestingly, there was a chair (with a person sitting) right next to it! To get a Dairy Milk bar, one had to give this person the money, he'd hand back the change from his cash-till and he would put in some kind of a special token into the machine, punch some buttons and hand over the goods that the machine spit. More often than not, he had to put in his key, open the beast up and manually retrieve what he had to from its innards. Something drove the company to invest in a layer of mediation while transplanting something that seemed to simply work by itself in the west. You'd note that the vending machine was actually made redundant by this layer of mediation. The company might as well have put a dumb shopping-shelf instead! Well, I think there is a reason to it- a longer term purpose- we'll come to that.

My most recent sighting of vending machines in India was in the new International Terminal of the New Delhi Airport. I guess these were from Pepsi co. Just for the heck of it, I tried following the instructions for a fruit-drink pack. Try as I might, the thing wouldn't take my ten rupee note! Finally, a guy came around with a bunch of keys, opened the machine up and gave me what I wanted :). Note the guy wearing a cap with a bunch of notes? He's the 'vending machine mediator'.


ATMs in India are a great example of how mediated usage has over time, evolved into self-transactions. Quite a few ATMs in India had and continue to have security guards posted outside them. Many a times, when first time users get stuck, they actively seek the help of these guards. It is interesting to note how an immediate need (for cash) or the aspirational need for becoming an ATM user drives people to trust near-strangers. We human beings are inherently 'social' and at times take decisions based on emotional reasons and relative perceptions of risk vs. reward rather than rational algorithmic ones.
(Dude: "Siri- should I ask the security dude outside this ATM to help me with my withdrawal?"
Siri: "Of course not! Your mom says, don't talk to strangers!")

PCO or the Public Call Office phenomenon is another uniquely Indian one. Long before mobile phones got in vogue and when there used to be year-long waiting lists for getting dumb rotary dial land-line phones, the then visionaries had a brainwave: That of entrusting atleast one phone line in every village with a local entrepreneur and enabling him to meter and charge for the call. Not very long ago (when mobile phones were a super luxury), when I was an engineering student at NIT J, we used to go to the village right next to our college ('Bidipur') and queue up outside the STD PCO booth there once every week (late night- they had discounted tariffs then ;))  to make a long distance phone call to our parents. Thankfully, we are in a different era/ planet now! PCOs still exist and still continue to be relevant in some parts of the country. What was interesting about the PCO was the way many of the villagers used it. They carried a paper chit with the destination number scribbled on it. They would dutifully hand it over to the booth operator who would dial the number on their behalf and once the call was connected; make an introductory announcement and hand over the mouthpiece to the caller to proceed with whatever publicly private conversation he/ she had to make.

The point is; that the option of having that mediated transaction enabled the poor villager to access a service he/ she needed which the person otherwise would not have. Over a period of time, (as is evident with the mobile telephony boom we are witnessing now), people do get over their barriers and learn whatever minimum viable product/ service that they need to use. But having an external spark, sure helps start the fire.

The last example I'd like to give shows cultural inclinations for mediated usage. India has millions of small mom-n-pop shops (grocers, chemists, textile vendors, 'paan' shops et al). Unlike the west, where people drive down to the closest mall once a month and stuff their cars with all the super-sized things they think they might need; in India, a mother would send her son/ daughter with a small list and the list could be as small as a single item ("Son, please go and get 200g sugar- hurry, I have already put the porridge on the pan!") The son would then run (or cycle) to the friendly next-door grocer (usually, no fake smiles or smile-badges here, strictly and simply business-friendly), buy the stuff wrapped in an old newspaper (+ two candies bought slyly with the spare change) and run back home- just in time for the mother to add it to the heating brew.

Self-service larger format stores are a very recent addition to the Indian retail landscape. But despite their discount offers and the promise of getting everything under a single roof, its been difficult for them to threaten the well-entrenched next-door shop's mediated shopping model. This is because culturally, we have been used to this kind of shopping (with the bargaining sessions, touch and feel instances, recite-the-shopping-list and someone hands you the goods in a jiffy shopping, mental arithmetic/ scribbled bills, moles and warts and everything that comes with it). Simply because it seems more human to us. Perhaps the next generation in the urban context may not share this perception.

Eko also leverages mediated usage to the hilt. Its promise of simplified banking and financial transactions presents a HUGE trust barrier that potential customers need to cross. While we believe that self-transactions are but a natural extension to enabling such an access, mediation of transactions through these trusted shops (where people have been buying their groceries/ medicines for years) is a great base to build on.

An important principle we've always believed in is that customers are not stupid. While this might sound like a strong statement to make, it is relevant in the context that many people still design services and solutions for the less-privileged as if they were lesser people! They might not be very educated and may not tote an iPhone but they are smart and nothing implies that they are stupid. The fact that they use mediation is not a measure of the weakness of the customer, but rather a measure of the strength of the mediator. The act of mediation represents a basic human-bond of symbiotic needs; customers' trust in the shopkeeper and the shopkeeper's need to have customers. There would of course be bad apples, people who could misuse their position of trust. The antidote is in having efficient selection and monitoring systems to weed them out.

Gist:
Mediation is natural and human.
Mediated usage helps in facilitating customer adoption of new services.
Mediated usage is a good stepping stone towards self-reliance.
Mediated usage has a social, cultural and economic context.

Further reading:
Jan Chipchase,
  CGAP Blog on mobile banking mediated use
  Shared Phone use
  Designing Mobile Money use
Microsoft research, on inter-mediated usage