Are the New FFIEC Guidelines Enough to Stop ACH Fraud?
Friday, January 20th, 2012
We all know cold remedies are made to treat the symptoms, not kill the virus. In a way, reactive anti-fraud solutions work the same way. They’re good at cleaning up the mess or correcting the problem once fraud has occurred, but have difficulty preventing cyber crimes from happening in the first place, or worse, stopping them from reoccurring over and over again.
The truth is, even diligent businesses running the latest security software remain vulnerable to the growing number of new and unknown forms of online fraud and abuse. Take it from Mark Patterson, co-owner of PATCO Construction Inc: when it comes to fighting ACH fraud the new FFIEC authentication guidance falls short. He says that until banks become legally liable and accountable for such online crimes, businesses will remain susceptible to online fraud.
In the BankInfoSecurity article, “Fraud: The Victim’s Perspective,” Patterson, whose small residential and commercial construction company lost over $550,000 to fraudulent ACH transactions, said that while he’s glad updates have been made to the security guidelines, they don’t go far enough. In order for small businesses to protect themselves from online crimes like ACH fraud and account takeover, they need to take it upon themselves to also incorporate their own internal policies and processes to detect fraud and abuse. Some of his recommendations include:
- Talk to your bank about the ACH fraud policy to understand if fraud losses are covered
- Monitor all online transactions for bad IP addresses, anomalies, and suspicious activity
- Run and analyze reports to recognize patterns and velocities
- Educate yourself about online threats and how bad they really are





Every second, someone is sharing personal information about themselves over the Internet. For most online users, this data is meaningless except to the friends and well-intended recipients of the sender. But the truth is, others are watching; and they’re watching closely. For online fraudsters, personal information is carefully pieced together and used to answer security questions that allow them to break into other peoples’ online accounts to perpetrate identity theft and steal from their bank accounts.


