Purchase Card: Strategies for a Secure Program Bank of America Merrill Lynch City of Chandler. October 7, 2010

Similar documents
Identifying and Pursuing Non-traditional Equity and Leveraged Lending Sources for NMTC Transactions

<Insert Picture Here> Extreme Performance with In-Memory Database Technology Real Life Stories

Looking Forward: Private Placements in the Post Credit Crisis World

Are you ready for SEPA?

Focused on card fraud prevention

2017 GFOA of South Carolina: Financing Energy Efficiency Projects Creative Financing Approaches

Clark County Stadium Authority Financing Plan Discussion Materials August 17, 2017

SCTEM. Preventing Fraud and Misuse in Your Card Program. Presented By: Gonca Latif-Schmitt, Managing Director Citi

State of SC GFOA. October 14 th, 2014

Global Custody And Agency Services. Mitigate risk and increase effectiveness through end-to-end banking services.

Comprehensive Payables

Disruptive Innovation Change is Inevitable

Gaining Access to Capital

Anti-Bribery & Anti-Corruption Podcast

Automating Your Payables Process

Purchasing Card Policy

Citi Support: Techniques for Establishing a Successful Audit Process

CARBON COUNTY MASTERCARD PURCHASE CARD PROGRAM

Purchasing and Travel Services

McGILL UNIVERSITY PROCUREMENT CARD POLICIES AND PROCEDURES

CITY OF BOWLING GREEN PROCUREMENT CARD POLICY AND PROCEDURES SECTION 1 INTRODUCTION

Financial Transactions and Fraud Schemes

Prepared by Office of Procurement and Real Property Management. This replaces Administrative Procedure No. A8.266 dated September 2014 A8.

Maximizing epayables by Maximizing Supplier Acceptance of Card. Sam Sarin, CPCP Director, Senior Product Manager Bank Of America Merrill Lynch

Citi Support: Techniques for Establishing a Successful Audit Process

Expedited Processing and Settlement (EPS)

Doing Business in Latin America

Stetson University PCARD. MasterCard Purchasing/Travel Card Program

Procurement Card Program

NDSU P U R C H A S I N G C A R D T R A I N I N G

protect fraudulent against transactions your business Introduction What is a fraudulent transaction? Merchant Responsibilities Card Present

Purchasing Card Program

Working Capital Management: An Enterprise Endeavor. Deborah McSheffrey, CTP

Purchasing Card Policy and Procedure Manual

Arkansas Tech University Procurement Card (P-Card) Program Policies and Guidelines Manual

Purchasing Card Policies and Procedures Manual

PROCUREMENT CARD PROGRAM

State of West Virginia Purchasing Card Program. Presented by: Travis Mulanax Training Administrator

CONSUMER CREDIT CARD AGREEMENT AND DISCLOSURE

ADMINISTRATIVE PRACTICE LETTER

PURCHASING CARD MANUAL

Asia Corporate Travel Card and Corporate Purchasing Card. Programme Administrator Guide Australia

Five steps you can take today to prepare your treasury for an era of disruption

CONSUMER CREDIT CARD AGREEMENT AND DISCLOSURE

LICENSE AGREEMENT. Security Software Solutions

U.S. Consumer Privacy Notice Rev. 01/2014

Purchasing Card Policies and Procedures Manual

City of Burleson, Texas PROCUREMENT CARD POLICY

HABERSHAM COUNTY BOARD OF COMMISSIONERS EXECUTIVE SUMMARY

Vanderbilt One Card Policy

The City of Port St. Lucie. Procurement Card Policy & Procedures Manual

APPLICATION AND SOLICITATION DISCLOSURE

ADDENDUM TO BANGOR ONLINE INTERNET BANKING AGREEMENT:

Your Guide to. Credit Card Skimming: How to Spot and Avoid Fraudulent Charges

After that, your APR will be 12.40% to 21.40%, based on your. Visa Platinum N/A. Visa Platinum Variable. Visa Platinum.

To be eligible for a P-Card the applicant must meet the following criteria:

Credit Card Handling Security Standards

Payment Fraud Statistics

EASTERN MICHIGAN UNIVERSITY

11.00% to 18.00% when you open your account, based on your % to 18.00% when you open your account, based on

PCI Training. If your department processes credit card information, it is CRITICAL that you understand the importance of protecting this data.

University of South Alabama Procurement Card Policies and Procedures

TRAVEL CARD PROGRAM POLICY AND PROCEDURES. West Chester University

Payment Fraud Statistics

CONSUMER CREDIT CARD AGREEMENT AND DISCLOSURE

Purchase Card Policy. Revised: 2/19/2015. All University Faculty and Staff. Issued By: Office of the Vice President for Business and Finance

University of Arkansas at Monticello Procurement Card (P-Card) Program Policies and Guidelines Manual

Delaware State University

PROCUREMENT CARD PROGRAM POLICY AND PROCEDURES MANUAL

BERKELEY COUNTY FILE: DM

Extreme Visa 1.99% 15.90% Visa Secured 15.90% Extreme Visa. your creditworthiness. Visa Secured. Extreme Visa. your creditworthiness.

ISPFCU VISA PLATINUM PROGRAMS TERMS AND CONDITIONS The information about the costs of the card described is accurate as of July 14, 2017.

APPLICATION AND SOLICITATION DISCLOSURE

UC MERCED PROCUREMENT CARD APPLICATION

Posting Date: Page 1 of 11 FIN & INFO Procurement Card Policies & Procedures

PSD1 established, amongst other things, the following key principles:

Elizabeth City State University. Purchasing Card Manual

Purchasing Card Cardholder Training

PURCHASING CARD USER S GUIDE

California Resources Corporation. Business Ethics

These are your General Purpose Card Terms and Conditions

HP INC. COMPUTER & PERIPHERAL PRODUCTS PARTS ONLY TIER SELF- MAINTAINER AGREEMENT FOR UNITED STATES

Working Effectively: Training Guide for New & Experienced Travel Card A / OPCs

Card Services Policies & Procedures. Required Policy Approver: Senior VP, CFO, and Treasurer

DICKINSON COLLEGE PURCHASING CARD PROGRAM POLICIES AND PROCEDURES MANUAL

SCHOOL DISTRICT OF OKALOOSA COUNTY TECHNICAL ASSISTANCE MEMORANDUM PURCHASING

Supplement Dated April 24, 2018 To The NextGen

Credit Card Procedural Manual

Agreement means these Terms and Conditions, together with the Fee Schedule in accordance with 1.1.

State Bank Financial State Bank Shelby 4020 Mormon Coulee Road La Crosse WI ELECTRONIC FUND TRANSFER AGREEMENT AND DISCLOSURE

minimise card fraud in your business.

Credit Union Credit Card Disclosures

Year-end 2016 fraud update: Payment cards, remote banking and cheque

PURCHASING CARD PROGRAM

D A T A S E C U R I T Y, F R A U D P R E V E N T I O N A N D P C I C O M P L I A N C E. May 2015

PURCHASING CARD POLICIES & PROCEDURES Finance and Administration. Table of Contents

COMMUNITY FINANCIAL CREDIT UNION MasterCard CARD HOLDER AGREEMENT

Augsburg College. Wells Fargo Bank Commercial Card Program. Policy and Procedures Manual

PROCUREMENT CARD POLICY. Policy 570 i

Procedures. For. The State of Texas. Procurement Card Program

Transcription:

Purchase Card: Strategies for a Secure Program Bank of America Merrill Lynch City of Chandler October 7, 2010

David A. Randolph, Vice President Bank of America Merrill Lynch Sharon Brause, Procurement Officer, CPPB, CPCP City of Chandler Juan Martinez, Purchasing Specialist Juan Martinez, Purchasing Specialist City of Chandler

What is a Purchasing Card? Payment Tool Not simply a credit card Based on standard, Visa/MasterCard credit card Provides enhanced Internal controls & reporting Includes technology to streamline your purchasing process Purchasing Cards are given to employees to acquire goods and services for their organization Used to pay Accounts Payable invoices through ghost card application Central bill/central pay/corporate liability Most public and private organizations have Purchasing Card programs

Transaction Flow Authorization Authorization ti Associations (Visa/MasterCard) (Visa/MasterCard) Total Systems Systems (TSYS2) (TSYS) Merchant Merchant Works/VIM/SDOL Works/VIM Paper Statements Paper Statements

Why Purchasing Card? If you are going to spend, spend smart! Reduce costs associated with traditional fee-based payment types Typically, 80% of transactions only represent 20% of total dollars spent Streamline purchasing and payment procedures through less paperwork and processing time Reduce the administrative burden Extends float increasing cash flow Provides cash payout incentive when rebate terms met Rebate payout based upon annualized AZ Public Sector Group program spend Payment control benefit through improved transaction risk management and decrease in Payment control benefit through improved transaction risk management and decrease in misuse and fraud

Why the Focus on Fraud? The nature of the threat has evolved Organizations operate in an open and highly networked online environment The nature of fraud threats is changing to take advantage of this operating context Fraudsters have shifted focus to end users, i.e., your employees and their computer desktops. Costs to protect the system are increasing Trust in the system is eroded by fraud and data compromises Fraud prevention requires a new level of collaboration between banks and their clients.

Fraud, Abuse, & Misuse: What are the Differences Fraud The theft card information by fraudsters Account takeover (information change) Skimming Mail thefts Counterfeit cards Lost/Stolen cards Mail order/telephone order Database Hacking Franchise Software Hacking Sniffing Phishing Abuse Intentionally or unintentionally violating policies and procedures for personal gain Misuse Intentionally or unintentionally violating policies and procedures for work related gain

And An Old Favorite The Handheld Skimmer This device can capture over 2500 credit card account numbers, expiration dates and CVV codes in the palm of your hand. The unit can operate continuously for 40 hours on a single 3V battery (6000 swipes). Skimmed data can be downloaded to any PC with software provided. d At a moment s notice, or the moment of arrest, the contents can be deleted with the press of a button to avoid prosecution. Cost = $500 8

ATM Skimmers False fronts on ATM terminals with built in magnetic stripe readers. Hidden camera captures PIN and transmits the information to a nearby crook Increasingly common 9

Phishing 10

Card Program Control Practices Strategies for success: Organization Policies Procedures Technology Audits 11

Card Program Control Practices Strategies for Success: Organization Defined Roles and Responsibilities Develop, implement, maintain, and enforce Card Policy & Procedures Program Administrator New and Refresher cardholder training Segregation of Duties Identity who will review transactions ti and who will approve Cardholders should not be their own approving managers Separate individuals should be identified for responsibilities related to: Request (new card, increase in limit, approval to purchase) Approval and execution Audit 12

Card Program Control Practices Strategies for Success: Policies Guides proper card use Critical policies include guidelines on: Card Issuance Transactions Controls Usage Guidelines Record Retention 13

Card Program Control Practices Strategies for Success: Policies Card Issuance Identify appropriate cardholders Admin Assistant Technology Support Department/Facility Managers Project Leaders Buyers / AP Managers Maintenance Fleet Principals / Teachers Police / Fire Employee Travel Mandatory cardholder training Test Cardholder agreement 14

Card Program Control Practices Strategies for Success: Policies Transaction Controls Monthly / Annual Limits / Declining Balance Transaction Spend Amounts MCC Restrictions Usage Guidelines Outline how Cards should be used Permitted Transaction: Hardware / software Prohibited Transactions: Cash Advances 15

Card Program Control Practices Strategies for Success: Policies Record Retention Length of time Ensure card transactions are in compliance Cardholder Statements / Receipts Changes in cardholder status Written justification to exceptions to organization policy Document packing slips Confirmation emails Packing slips 16

Card Program Control Practices Strategies for Success: Procedures Implement procedures to enforce policy Account Maintenance Transaction Controls Out of policy spending Transaction review and reconciliation 17

Card Program Control Practices Strategies for Success: Technology Transaction control Transaction reconciliation Transaction visibility 18

Card Program Control Practices Strategies for Success: Audit Ongoing (weekly) Card Program Reviews Split Transactions Unusual increases in average spend or highest spend amount Transaction amounts close to spending limits Declines Due to MCC Due to Spend limits Full Audits Within 60 to 90 days of transaction 100% audit Communicate audit findings 19

Program Administrator Tips to Prevent/Detect Fraud Monitor declined authorizations for signs of merchant fraud. Ensure cardholder reconciliation is performed in a timely manner Ensure Audit process and procedures are in plan and being adhered to Have cards mailed to a central location for distribution to individual cardholders to insure receipt If mailed directly to cardholders, follow up with in 10 days of the request to insure card was received Report non-received cards to Bank of America immediately Examine cards received for evidence of tampering during transit If merchant fraud is detected or suspected, alert all cardholders immediately Keep cardless account numbers in a secure location and provide only to authorized individuals who have a business need.

Cardholder Tips to Prevent/Detect Fraud Review card activity frequently Keep your credit card in a secure location Keep signed receipts in a secure location Keep card statement and reports in secure location Do not provide your individual account number to a merchant to keep on file unless approved by your program administrator Report unrecognized transactions, lost, or stolen cards to Bank of America immediately and notify the Program Administrator to insure user profiles are updated Beware of Phishing Attempts

Best Practices to Identify Phishing emails Banks will not ask cardholder to provide account numbers and/or personal information in an email Most fraudulent communications convey a sense of urgency by threatening discontinued service Many fraudulent emails contain misspellings, incorrect grammar, and poor punctuation Links within the email may appear valid, but deliver you to a fraudulent site Phishing emails often use generic salutations like Dear Customer, or Dear account holder instead of your name If concerned, contact the Bank

Remember this email?

Visa/MasterCard Liability Waiver Program The Visa/MasterCard misuse protection program is automatically provided with all Bank of America purchasing card programs free of charge. In the event that abuse occurs, members will be protected. This coverage will be subject to the terms and exclusions of the misuse protection program The Visa/MasterCard Liability Waiver Program protects members against eligible losses that may be incurred through card misuse by a terminated employee. This will provide up to $100,000 reimbursement of eligible losses per cardholder. The Visa/MasterCard Liability Waiver Program applies to all transaction types Internet Mail-order Telephone order Face-to-face Ghost account Departmental card

Bank of America Merrill Lynch Arizona Public Sector Group Link to the City of Chandler Nine state programs, 600 political subdivisions More than 1.8 million cards to public sector clients Broad base of more than 8,800 Purchase, Travel, and Corporate Card clients $12 Billion in annual cardholder transaction volume Over 44 years of experience in the card industry, beginning with the consumer credit card, Bankamericard which once sold became Visa Bank of America s size and strength allow us to continually invest in our Treasury and Card services infrastructure.

David A. Randolph, Vice President Bank of America Merrill Lynch david.a.randolph@baml.com 602.523.6996 Sharon Brause, Procurement Officer, CPPB, CPCP City of Chandler sharon.brause@chandleraz.gov h 480.782.2407

Bank of America Merrill Lynch is the marketing name for the global banking and global markets businesses of Bank of America Corporation. Lending, derivatives, and other commercial banking activities are performed globally by banking affiliates of Bank of America Corporation, including Bank of America, N.A., member FDIC. Securities, strategic advisory, and other investment banking activities are performed globally by investment banking affiliates of Bank of America Corporation ( Investment Banking Affiliates ), including, in the United States, Banc of America Securities LLC and Merrill Lynch, Pierce, Fenner & Smith Incorporated, which are both registered broker-dealers and members of FINRA and SIPC, and, in other jurisdictions, locally registered entities. Investment products offered by Investment Banking Affiliates: Are Not FDIC Insured * May Lose Value * Are Not Bank Guaranteed. These materials have been prepared by one or more subsidiaries of Bank of America Corporation for the client or potential client to whom such materials are directly addressed and delivered (the Company ) in connection with an actual or potential mandate or engagement and may not be used or relied upon for any purpose other than as specifically contemplated by a written agreement with us. These materials are based on information provided by or on behalf of the Company and/or other potential transaction participants, from public sources or otherwise reviewed by us. We assume no responsibility for independent investigation or verification of such information (including, without limitation, data from third party suppliers) and have relied on such information being complete and accurate in all material respects. To the extent such information includes estimates and forecasts of future financial performance prepared by or reviewed with the managements of the Company and/or other potential transaction participants or obtained from public sources, we have assumed that such estimates and forecasts have been reasonably prepared on bases reflecting the best currently available estimates and judgments of such managements (or, with respect to estimates and forecasts obtained from public sources, represent reasonable estimates). No representation or warranty, express or implied, is made as to the accuracy or completeness of such information and nothing contained herein is, or shall be relied upon as, a representation, whether as to the past, the present or the future. These materials were designed for use by specific persons familiar with the business and affairs of the Company and are being furnished and should be considered only in connection with other information, oral or written, being provided by us in connection herewith. These materials are not intended to provide the sole basis for evaluating, and should not be considered a recommendation with respect to, any transaction or other matter. These materials do not constitute an offer or solicitation to sell or purchase any securities and are not a commitment by Bank of America Corporation or any of its affiliates to provide or arrange any financing for any transaction or to purchase any security in connection therewith. These materials are for discussion purposes only and are subject to our review and assessment from a legal, compliance, accounting policy and risk perspective, as appropriate, following our discussion with the Company. We assume no obligation to update or otherwise revise these materials. These materials have not been prepared with a view toward public disclosure under applicable securities laws or otherwise, are intended for the benefit and use of the Company, and may not be reproduced, disseminated, quoted or referred to, in whole or in part, without our prior written consent. These materials may not reflect information known to other professionals in other business areas of Bank of America Corporation and its affiliates. Bank of America Corporation and its affiliates (collectively, the BAC Group ) comprise a full service securities firm and commercial bank engaged in securities, commodities and derivatives trading, foreign exchange and other brokerage activities, and principal investing as well as providing investment, corporate and private banking, asset and investment management, financing and strategic advisory services and other commercial services and products to a wide range of corporations, governments and individuals, domestically and offshore, from which conflicting interests or duties, or a perception thereof, may arise. In the ordinary course of these activities, parts of the BAC Group at any time may invest on a principal basis or manage funds that invest, make or hold long or short positions, finance positions or trade or otherwise effect transactions, for their own accounts or the accounts of customers, in debt, equity or other securities or financial instruments (including derivatives, bank loans or other obligations) of the Company, potential counterparties or any other company that may be involved in a transaction. Products and services that may be referenced in the accompanying materials may be provided through one or more affiliates of Bank of America Corporation. We have adopted policies and guidelines designed to preserve the independence of our research analysts. These policies prohibit employees from offering research coverage, a favorable research rating or a specific price target or offering to change a research rating or price target as consideration for or an inducement to obtain business or other compensation. We are required to obtain, verify and record certain information that identifies the Company, which information includes the name and address of the Company and other information that will allow us to identify the Company in accordance, as applicable, with the USA Patriot Act (Title III of Pub. L. 107-56 (signed into law October 26, 2001)) and such other laws, rules and regulations as applicable within and outside the United States. We do not provide legal, compliance, tax or accounting advice. Accordingly, any statements contained herein as to tax matters were neither written nor intended by us to be used and cannot be used by any taxpayer for the purpose of avoiding tax penalties that may be imposed on such taxpayer. If any person uses or refers to any such tax statement in promoting, marketing or recommending a partnership or other entity, investment plan or arrangement to any taxpayer, then the statement expressed herein is being delivered to support the promotion or marketing of the transaction or matter addressed and the recipient should seek advice based on its particular circumstances from an independent tax advisor. Notwithstanding anything that may appear herein or in other materials to the contrary, the Company shall be permitted to disclose the tax treatmentt t and tax structure t of a transaction ti (including any materials, opinions i or analyses relating to such tax treatment or tax structure, but without disclosure of identifying information or, except to the extent relating to such tax structure or tax treatment, any nonpublic commercial or financial information) on and after the earliest to occur of the date of (i) public announcement of discussions relating to such transaction, (ii) public announcement of such transaction or (iii) execution of a definitive agreement (with or without conditions) to enter into such transaction; provided, however,thatif such transaction is not consummated for any reason, the provisions of this sentence shall cease to apply. Copyright 2009 Bank of America Corporation. Bank of America Merrill Lynch 27