The rise and development of FinTech: Accounts of disruption from Sweden and beyond
Abstract
EconStor is a publication server for scholarly economic literature, provided as a non-commercial public service by the ZBW.
Full text
Teigland, Robin (Ed.); Siri, Shahryar (Ed.); Larsson, Anthony (Ed.); Puertas, Alejandro Moreno (Ed.); Bogusz, Claire Ingram (Ed.) Book — Published Version The rise and development of FinTech: Accounts of disruption from Sweden and beyond Routledge International Studies in Money and Banking, No. 94 Provided in Cooperation with: Taylor & Francis Group Suggested Citation: Teigland, Robin (Ed.); Siri, Shahryar (Ed.); Larsson, Anthony (Ed.); Puertas, Alejandro Moreno (Ed.); Bogusz, Claire Ingram (Ed.) (2018) : The rise and development of FinTech: Accounts of disruption from Sweden and beyond, Routledge International Studies in Money and Banking, No. 94, ISBN 978-1-351-18362-8, Routledge, Taylor & Francis Group, London, https://doi.org/10.4324/9781351183628 This Version is available at: https://hdl.handle.net/10419/181978 Standard-Nutzungsbedingungen: Die Dokumente auf EconStor dürfen zu eigenen wissenschaftlichen Zwecken und zum Privatgebrauch gespeichert und kopiert werden. Sie dürfen die Dokumente nicht für öffentliche oder kommerzielle Zwecke vervielfältigen, öffentlich ausstellen, öffentlich zugänglich machen, vertreiben oder anderweitig nutzen. Sofern die Verfasser die Dokumente unter Open-Content-Lizenzen (insbesondere CC-Lizenzen) zur Verfügung gestellt haben sollten, gelten abweichend von diesen Nutzungsbedingungen die in der dort genannten Lizenz gewährten Nutzungsrechte. Terms of use: Documents in EconStor may be saved and copied for your personal and scholarly purposes. You are not to copy documents for public or commercial purposes, to exhibit the documents publicly, to make them publicly available on the internet, or to distribute or otherwise use the documents in public. If the documents have been made available under an Open Content Licence (especially Creative Commons Licences), you may exercise further usage rights as specified in the indicated licence. https://creativecommons.org/licenses/by-nc-nd/4.0/
THE RISE AND DEVELOPMENT OF FINTECH ACCOUNTS OF DISRUPTION FROM SWEDEN AND BEYOND Edited by Robin Teigland, Shahryar Siri, Anthony Larsson, Alejandro Moreno Puertas, and Claire Ingram Bogusz
The Rise and Development of FinTech This comprehensive guide serves to illuminate the rise and development of FinTech in Sweden, with the Internet as the key underlying driver. The multiple case studies examine topics such as: the adoption of online banking in Sweden; the identification and classification of different FinTech categories; process innovation developments within the traditional banking industry; and the Venture Capital (VC) landscape in Sweden, as shown through interviews with VC representatives, mainly from Sweden but also from the US and Germany, as well as offering insight into the companies that are currently operating in the FinTech arena in Sweden. The authors address questions such as: How will the regulatory landscape shape the future of FinTech companies? What are the factors that will likely drive the adoption of FinTech services in the future? What is the future role of banks in the context of FinTech and digitalization? What are the policies and government initiatives that aim to support the FinTech ecosystem in Sweden? Complex concepts and ideas are rendered in an easily digestible yet thoughtprovoking way. The book was initiated by the IIS (the Internet Foundation in Sweden), an independent organization promoting the positive development of the Internet in the country. It is also responsible for the Internet’s Swedish top-level domain .se, including the registration of domain names, and the administration and technical maintenance of the national domain name registry. The book illustrates how Sweden acts (or does not act) as a competitive player in the global FinTech arena, and is a vital addition to students and practitioners in the field. Robin Teigland is Professor of Business Administration with a specialization in Strategic Information Systems Management and Co-director of the Center for Strategy and Competitiveness at the Stockholm School of Economics (SSE), Sweden. Shahryar Siri is a Researcher and Project Manager at the Stockholm School of Economics Institute for Research (SIR), Sweden, where he is responsible for the three-year research project “The Innovative Internet” in collaboration with the Internet Foundation in Sweden (IIS). Prior to his role at SIR, he worked as a Consumer Insights Researcher at Ericsson and on a freelance basis.
Anthony Larsson is a Doctoral Candidate of Medical Science at Karolinska Institutet (KI), Sweden, and a Researcher at the Stockholm School of Economics Institute of Research (SIR), Sweden. He holds a MSc in Business & Economics, an MBA in Business, a MSc in Political Science, a MSc in Anthropology and an A.S. in Psychology. His research interests include management, organization studies, entrepreneurship, innovation studies, customer loyalty, digitalization, branding, stakeholder analysis, political science, anthropology, and qualitative research methods. Alejandro Moreno Puertas is a MSc finance student at the Stockholm School of Economics (SSE), Sweden. He has previously worked in Shanghai as a representative of Sociedad Española de Negocios en Asia y America SL for their Chinese business development. He graduated from Tilburg University with a BSc in economics. Claire Ingram Bogusz is a Researcher at the Stockholm School of Economics (SSE), Sweden. Her research interests are in how code-based technologies affect entrepreneurship and organizational change. Her PhD thesis examined FinTech entrepreneurship reliant on peer-to-peer technologies.
Routledge International Studies in Money and Banking For a full list of titles in this series, please visit www.routledge.com/series/SE0403 86 Wages, Bonuses and Appropriation of Profit in the Financial Industry The Working Rich Olivier Godechot 87 Banking and Monetary Policies in a Changing Financial Environment A Regulatory Approach Wassim Shahin and Elias El-Achkar 88 Modern Monetary Theory and European Macroeconomics Dirk H. Ehnts 89 Capital Flows, Financial Markets and Banking Crises Chia-Ying Chang 90 Banking and Economic Rent in Asia Rent Effects, Financial Fragility and Economic Development Edited by Yasushi Suzuki, Mohammad Dulal Miah, Manjula K. Wanniarachchige, and S.M. Sohrab Uddin 91 Finance at Work Edited by Valérie Boussard 92 The Development of International Monetary Policy Christopher Warburton 93 Pension Fund Economics and Finance Efficiency, Investments and Risk-Taking Edited by Jacob A. Bikker 94 The Rise and Development of FinTech Accounts of Disruption from Sweden and Beyond Edited by Robin Teigland, Shahryar Siri, Anthony Larsson, Alejandro Moreno Puertas, and Claire Ingram Bogusz
The Rise and Development of FinTech Accounts of Disruption from Sweden and Beyond Edited by Robin Teigland, Shahryar Siri, Anthony Larsson, Alejandro Moreno Puertas, and Claire Ingram Bogusz
First published 2018 by Routledge 2 Park Square, Milton Park, Abingdon, Oxon OX14 4RN and by Routledge 711 Third Avenue, New York, NY 10017 Routledge is an imprint of the Taylor & Francis Group, an informa business 2018 selection and editorial matter, Robin Teigland, Shahryar Siri, Anthony Larsson, Alejandro Moreno Puertas, and Claire Ingram Bogusz; individual chapters, the contributors The right of Robin Teigland, Shahryar Siri, Anthony Larsson, Alejandro Moreno Puertas, and Claire Ingram Bogusz to be identified as the authors of the editorial material, and of the authors for their individual chapters, has been asserted in accordance with sections 77 and 78 of the Copyright, Designs and Patents Act 1988. The Open Access version of the eBook, available at www.taylorfrancis.com, has been made available under a Creative Commons Attribution-Non Commercial-No Derivatives 4.0 license. Trademark notice: Product or corporate names may be trademarks or registered trademarks, and are used only for identification and explanation without intent to infringe. British Library Cataloguing-in-Publication Data A catalogue record for this book is available from the British Library Library of Congress Cataloging-in-Publication Data Names: Teigland, Robin, 1964- editor. Title: The rise and development of fintech : accounts of disruption from Sweden and beyond / [edited by] Robin Teigland [and four others]. Description: Abingdon, Oxon ; New York, NY : Routledge, 2017. | Includes bibliographical references and index. Identifiers: LCCN 2017045736 (print) | LCCN 2017051503 (ebook) | ISBN 9781351183628 (eBook) | ISBN 9780815378501 (hardback : alk. paper) Subjects: LCSH: Finance—Technological innovations—Sweden. | Internet banking—Sweden. Classification: LCC HG186.S85 (ebook) | LCC HG186.S85 R57 2017 (print) | DDC 332.10285/4678—dc23 LC record available at https://lccn.loc.gov/2017045736 ISBN: 978-0-8153-7850-1 (hbk) ISBN: 978-1-351-18362-8 (ebk) Typeset in Times New Roman by Swales & Willis Ltd, Exeter, Devon, UK
Contents List of figures x List of tables xii List of contributors xiii Acknowledgments xviii Foreword xix Introduction: FinTech and shifting financial system institutions 1 ROBIN TEIGLAND, SHAHRYAR SIRI, ANTHONY LARSSON, ALEJANDRO MORENO PUERTAS, AND CLAIRE INGRAM BOGUSZ PART 1 New regulations 19 1 A regulatory innovation framework: how regulatory change leads to innovation outcomes for FinTechs 21 ÅKE FREIJ 2 Information security in the realm of FinTech 43 GEORGIOS KRYPAROS 3 FinTech in Sweden: will policymakers’ (in)action nurture or starve its growth? 66 BJÖRN OLSSON AND MATTIAS HALLBERG 4 The future of cash 85 NIKLAS ARVIDSSON 5 The adoption of online banking in Sweden 99 MICHAEL BJÖRN
xiv Contributors Anna Felländer has extensive experience in analyzing how digitalization is changing society, business, and the economy. She has published a number of reports on the subject, one of which describes opportunities and challenges of the sharing economy. Felländer has been working with the Swedish government for 10 years, and is currently an advisor to the Swedish Minister of Digitalization. Also, she is a visiting fellow to the Swedish House of Finance at SSE. She is also a senior advisor to the Boston Consulting Group, as well as a board member and expert advisor to AI companies. In addition to her work with the Digitalization Commission, she was an expert advisor in the government’s official report on taxi and car sharing in 2016. From 2013 to 2016, she held positions as Chief Economist and Digital Economist at Swedbank. Felländer has a Master of Science in International Economics from the Stockholm School of Economics. Åke Freij is a researcher with focus on innovation, business models and regulations. He earned his PhD in 2017 at the Stockholm School of Economics. In his thesis Åke reported on what companies do to master the impact of regulatory change. He is currently Managing Principal at Capco, where he advises clients on the future of regulatory management and RegTech. In his research Åke wants to increase understanding of the interplay between regulatory compliance and digitalization to create innovation. Michal Gromek is a researcher on FinTech at the Center for Strategy and Competitiveness at the Stockholm School of Economics (SSE). As a former executive of Rocket Internet and FundedByMe, he is a rare breed in European academia. Recognized by both CrowdfundingHub and the European Equity Crowdfunding Association as an expert in the field of FinTech, he is the coauthor of the Pan-European Crowdfunding Report. Michal has launched digital financing platforms on three continents and seven countries, and performed a FinTech training session with the Malaysian Securities Commission in Kuala Lumpur. Currently halfway through his PhD in Business Administration, he has authored or co-authored four chapters in this book, and coordinates the Stockholm FinTech Report, which will be published by the end of 2017. Mattias Hallberg’s passions are economics and education policy, preferable both at the same time. He is currently working as a political advisor for the ranking member of the Committee on Finance at the Swedish parliament. Before that, he was studying economics at Stockholm University and works as a research assistant at IIES. Previously, he was the President of the Swedish Federation of Student Unions; the largest youth organization in Sweden. His latest publication was a policy report on higher education, research, and innovation in Sweden, commissioned by the Arvid Lindman Foundation. Håkan Holmberg is a data scientist specializing in the fields of psychometrics and blockchain technology. He is presently involved in projects at Uppsala University as well as the National Board of Health and Welfare. He has previously published on the topic of blockchain technology in Europaperspektiv 2017. Håkan holds a master’s degree in Mathematics from Stockholm University.
Contributors xv Claire Ingram Bogusz is a researcher at the Stockholm School of Economics (SSE), Sweden. Her research interests are in how code-based technologies affect entrepreneurship and organizational change. Her PhD thesis examined FinTech entrepreneurship reliant on peer-to-peer technologies. Katarzyna Jereczek is an entrepreneur, project manager, and speaker, focusing on the global disruption of the finance industry. As a project manager, she worked at the world’s largest company builder to develop and launch the first P2P lending platform in Poland. In recent years, she helped and worked with numerous companies implementing mobile banking solutions, cryptocurrency exchange platforms, and establishing global compliance and regulatory guidelines. Katarzyna holds a master’s degree in Project Management from Warsaw School of Economics, and dedicates her current research work to topics grouped around the development of FinTech globally, and regulatory changes and adjustments. Georgios Kryparos is an IT and information security specialist with more than 13 years of experience in the industry. He has an MSc in Information and Communication Systems Security from the Royal Institute of Technology (KTH) in Stockholm, as well as several IT and information security industry certifications. He currently works at Klarna as a lead security engineer, focusing on implementing and assessing the security architecture of products and services, as well as testing the security of internal and external applications and systems. He also frequently gives talks and presentations in internal and external events with the purpose of raising awareness around security among his colleagues and the general public. Anthony Larsson is a Doctoral Candidate of Medical Science at Karolinska Institutet (KI), Sweden, and a Researcher at the Stockholm School of Economics Institute of Research (SIR), Sweden. He holds a MSc in Business & Economics, an MBA in Business, a MSc in Political Science, a MSc in Anthropology, and an A.S. in Psychology. His research interests include management, organization studies, entrepreneurship, innovation studies, customer loyalty, digitalization, branding, stakeholder analysis, political science, anthropology, and qualitative research methods. Mats Lewan is an author, international keynote speaker, futurist, consultant, journalist, and research analyst focused on future and technology. He has been working for more than 15 years as a technology reporter for the leading Swedish technology magazine Ny Teknik. He also started the forward-looking Swedish digital magazine Next Magasin, for which he was Managing Editor. Previously, Mats worked internationally as a freelance journalist, and as a reporter for CBS CNET News in San Francisco while attending the Innovation Journalism program at Stanford University. Mats holds an MSc degree in Engineering Physics from the Royal Institute of Technology in Stockholm, Sweden. Agnė Mačijauskaitė is currently a Master in Finance student at the Stockholm School of Economics (Stockholm) and a private equity analyst at Nordic Real Estate Partners (NREP). She has two years’ experience in investment
xvi Contributors banking, and has worked on international projects within technology, pharma, and infrastructure. Agnė holds a BSc in Business Administration with a finance specialization from the Norwegian Business School (Oslo), as well as a BSc in economics with a political specialization from ISM University of Management and Economics (Vilnius). Her main research focus is on FinTech and behavioral and household finance. Timotheos Mavropoulos (Lic.) did his PhD in Finance studies at the Swedish House of Finance, Stockholm School of Economics and is a corporate finance researcher at Pinq Mango Capital Partners, the world’s first Behavioural Investment Bank. His research interests include real estate finance, behavioral finance, social finance, and FinTech. He has worked as a research assistant for Sweden’s Central Bank during its inquiry into the risks in the Swedish housing market, and has participated in completing the “Household Finance” chapter in the Handbook of the Economics of Finance. He has performed teaching assignments for corporate finance, behavioral finance, international financial management, corporate transition, and degree projects in finance courses. Alejandro Moreno Puertas is a MSc finance student at the Stockholm School of Economics (SSE), Sweden. He has previously worked in Shanghai as a representative of Sociedad Española de Negocios en Asia y America SL for their Chinese business development. He graduated from Tilburg University with a BSc in economics. Björn Olsson is a passionate economist currently working at the Swedish Bankers’ Association. Previously he has worked for the party leader of the Moderate party. He completed his MSc in Economics at the University of Lund and has studied Business and Finance at Cass Business School in London. Claudia Olsson is an innovation leader and speaker in the field of digital transformation. She is the founder and CEO of Exponential AB, a global consultancy specialized in providing strategic advice, analysis, and professional development related to the digital transformation. Her work focuses on the impact of new technologies on citizens, society, and global markets. In 2016, Claudia authored the Sweden 2030 future scenario for the Digitalization Commission at the Government of Sweden, focused on the digital, integrated, smart, and competitive society. She also co-authored the acclaimed report “Blockchain- Decentralized Trust” for the Entrepreneurship Forum. Claudia has served as Associate Faculty at Singularity University as well as Senior Advisor to the Office of Strategic Analysis at the Ministry for Foreign Affairs in Sweden. Claudia previously set up and managed the policy think tank ACCESS Health International in Singapore following her work for ACCESS in India and her assignment with the United Nations Economic and Social Council (ECOSOC). Elizabeth Press is the founder of D3M Labs, a consultancy focused on data monetization and creation of data-as-a-service products. Elizabeth has also worked as a consultant for federal ministries. As an intrapreneur at Dell, Elizabeth built up and managed advanced analytics functions globally. Before Dell, she
Contributors xvii worked in top-tier strategy consulting and quantitative finance. She has a BA in International Relations from Tufts University and an MSc in International Economics and Business from the Stockholm School of Economics. She has published numerous blogs and white papers on the topic of strategic uses of data and organizational transformation. Shahryar Siri is a Researcher and Project Manager at the Stockholm School of Economics Institute for Research (SIR), Sweden, where he is responsible for the three-year research project “The Innovative Internet” in collaboration with the Internet Foundation in Sweden (IIS). Prior to his role at SIR, he worked as a Consumer Insights Researcher at Ericsson and on a freelance basis. Robin Teigland is Professor of Business Administration with a specialization in Strategic Information Systems Management and Co-director of the Center for Strategy and Competitiveness at the Stockholm School of Economics (SSE), Sweden. Jochem van der Zande will finish his CEMS Master in International Management at the Rotterdam School of Management in February 2018. He also holds a BSc in International Business Administration from RSM and went on exchanges to the Stockholm School of Economics and BI Norwegian Business School. Before starting his Masters, Jochem spent a year doing internships at EY Transaction Advisory Services and AkzoNobel. From March onward, he will work at Danske Bank in Copenhagen as a strategy consultant. His research interests are mergers & acquisitions and technology. He is currently writing his Master thesis on the role of external advisors during the acquisition process. Outside of his studies, Jochem is a passionate badminton player.
Acknowledgments This edited volume constitutes the third and penultimate phase of the three-year project ‘The Innovative Internet,’ which is funded by the Internet Foundation in Sweden (IIS—Internetstiftelsen i Sverige). The editorial team, together with our co-authors, would like to extend our deepest gratitude to IIS, and in particular Danny Aerts and Jannike Tillå, who have supported and guided us throughout the project but equally allowed us the full freedom to take ownership and to keep an open and explorative approach to our research. We would also like to thank the Marianne and Marcus Wallenberg Foundation for funding research within the FinTech area by one of the Editors and some of the authors, which served as a catalyst for this volume. Furthermore, this volume would not have been possible without the dedicated team of co-authors, practitioners, and industry experts who, during the course of the year, researched, interviewed, and analyzed the Swedish FinTech ecosystem and its numerous interlocking parts. We would also like to thank Johan Söderholm at the Stockholm Institute of Research, as well as Kristina Abbots and Laura Hussey, along with the rest of the assisting staff at Routledge for their help and support throughout every step in the making of this volume. Last but not least, we would also like to extend special gratitude to our families and friends for their unwavering and invaluable moral support throughout this process. We on the editorial team welcome feedback of any kind on the volume as we believe that transparency and cooperation outside our research team is paramount to ensuring that our research is conveyed as thoroughly as possible. Feel free to reach out to us should you like to discuss any of the topics raised in this book or if you would like to discuss prospects for future collaborations. As this is an Open Access volume, we welcome you to freely spread it to any and all interested parties you may encounter. On this final note, we hope that you will enjoy reading this volume as much as we enjoyed working on it. The Editorial Team: Robin Teigland, Shahryar Siri, Anthony Larsson, Alejandro Moreno Puertas, and Claire Ingram Bogusz Stockholm, January 2018
Foreword The past decade has seen a global surge in the development of new financial technologies, both as a response to the financial crisis of 2008 and as a consequence of rapid advances in digitalization. Democratization of technology has enabled new market entrants and grassroots innovators to disrupt traditional industries and practices through decentralized financial solutions, increased transparency, and a higher degree of automation. These forces are in the process of revolutionizing the user experience while at the same time increasing the efficiency in the financial system. Sweden has taken an active role in the development of breakthrough financial technologies, in line with the country’s long history of embracing technological innovations. In 1968, Sweden launched the world’s first online ATM, and in 2003 a national system for electronic identification was introduced (BankID), which laid an important foundation for a rapid deployment of new FinTech and digital services ventures. Over the past decades, companies such as Klarna and iZettle have helped strengthen Sweden’s position as an influential player in the field of financial technologies. Following the larger successes, a beneficial ecosystem for FinTech startups is taking form, and several areas of the financial industry present opportunities going forward. Globally, Sweden is one of the few countries that has become a nearly cashless economy. Transaction fees have gone down and many banks no longer offer cash services nor ATMs, some stores and cafés do not even accept cash. The Riksbank, Sweden’s Central Bank, contributed to this development by eliminating the country’s highest denomination bill, the SEK 10,000 bill, in 1991. The implementation of this mobile payment system, Swish, in 2012, which enables frictionless, instant and free transactions for individuals to Swedish bank accounts, has been another important factor. Furthermore, many public services, such as buses and trains, no longer accept cash payments in favor of digital alternatives. As digital trust continues to grow, and the Millennials, mostly a “digital native” population, play a larger role in the economy, these trends are expected to continue. We are seeing the beginning of what some refer to as the Fourth Industrial Revolution, where exponential technology development is impacting a wide range of sectors. Digital, physical, and even biological areas are merging, and in the wake of the innovations, data are becoming an abundant and exponentially
xx Foreword increasing asset. For FinTech innovators, the data that can be accessed and analyzed constitute the base for new products and services related to financial transactions. As the Internet of Things further develops—with 5G enabling a smart and highly connected society—we can expect this trend to further accelerate. The value of data, which are continually identified, created, and stored in connection to the financial system, can largely be unlocked through automated and algorithm-driven services. Through advancements in artificial intelligence and related machine learning, automated systems will be able to actively help customers plan and invest their assets, taking over a role traditionally held by human brokers. By eliminating the human factor, the costs of trades will continue to decrease, and services previously only accessible to high net-worth investors will become increasingly available to the population at large. The new financial technologies have the potential to support a safer and more sound personal finance planning. This will become increasingly in focus as retirement saving schemes are being updated and shaped to meet the needs of the new global workforce as the number of freelancers and independent contractors continues to grow. One of the developments in financial technologies that is currently attracting the most attention is blockchain-based systems and related distributed ledger technologies. These technologies are expected to both have an impact within regulated financial markets, where they can provide a secure system for handling and tracking financial assets, and also outside regulated financial markets, where they can provide transparent and global decentralized financial mechanisms as well as digital alternative currencies. Swedish banks and other financial institutions are exploring the potential of applying blockchain technology within existing legal frameworks. The development of peer-to-peer computing globally has also given rise to platforms that connect borrowers directly to lenders and where the “crowd” is engaged to fund new entrepreneurial initiatives. The trend has gained momentum as it grants access to borrowers or entrepreneurs who would otherwise not be able to obtain investments from banks or traditional credit institutions. Further peer-to- peer innovations are expected in FinTech in the years to come. The establishment of the FinTech space is still in its early days, and further advancements are anticipated as artificial intelligence and abundant data shape the financial landscape. Some developments may be initiated by governments and central banks. One such possibility is the launch of the e-krona, a Swedish national digital currency that has been proposed and is under consideration by the Riksbank. Other developments will come from outside the traditional centralized financial system, for example through the expansion of public blockchain-based currencies and applications that enable direct peer-to-peer transactions on a global scale without intermediaries. Looking ahead, the adoption of financial technologies will also be further enabled by the European Union’s banking legislation, enabling open banking or the opening up of sets of customer data for third-party integration. As FinTech evolves, we can expect the role of traditional players in the financial markets as well as financial institutions to be affected, and many will have to
Foreword xxi change or modify their customer offerings and even their business models. The advancement of a cashless society, with decentralized financial mechanisms for transactions, lending, borrowing, and fundraising, may require new legislation and mechanisms for oversight. FinTech developments in Sweden are contributing to the formation of technological expertise, know-how, and experience that can be of significant importance for the growth of other Internet-related industries in Sweden. Many sectors will be able to learn from the innovations in FinTech, for example from the security and cryptographic solutions that the financial systems require. These can become of use in a variety of fields, ranging from supply chain management and property rights to the educational sector. The main developments and insights in the history and future potential of FinTech are presented in this book, The Rise and Development of FinTech: Accounts of Disruption from Sweden and Beyond. This book provides guidance for entrepreneurs, established actors, and policymakers both within the financial services sector as well as in other sectors both in Sweden and abroad on how to leverage the potential of the latest and future technological progress within FinTech. The collection of insightful articles and cases provides an important understanding for one of the fastest-developing technological fields, with significant impact on society at large. Claudia Olsson CEO Exponential AB Young Global Leader World Economic Forum Associate Faculty Singularity University
Introduction FinTech and shifting financial system institutions Robin Teigland, Shahryar Siri, Anthony Larsson, Alejandro Moreno Puertas, and Claire Ingram Bogusz Introduction It is, today, widely known that the financial system as we knew it was shaken to the core by the 2008 global financial crisis. Not only did consumers lose their homes and savings due to bankers’ disreputable—and sometimes illegal— practices, but governments also cracked down on this risk-taking. They did this by raising capital requirements, and in some cases requiring banks to ring-fence capital—a measure used by banks to protect assets from less favorable conditions and regulations in particularly hard-hit and high-risk countries. Therefore, it is not too surprising that financial system actors came to be viewed suspiciously by consumers, firms, and governments. Combined with advances in new technologies and commonplace digital tools such as smartphones, this lack of trust in established financial actors paved the way for new financial technologies, firms, and practices. The scale of this change, both in Sweden and globally, has been so large that one might say that what was once “taken for granted” in finance has changed. What consumers, bankers, and governments today consider to be normal is not what it once was. Studies of activities that are “taken for granted,” what are known as institutionalized activities, have long been conducted by institutional theorists. However, their starting point is that institutional change is difficult. Incumbents in a field, such as the financial services industry, benefit from things staying the same, and they often have the most power and resources at their disposal to prevent changes to the status quo (Scott, 1995). Moreover, all actors in a particular institutional field are influenced by sets of established norms, ways of thinking, and regulations. They therefore tend to gravitate toward similar business models and practices (DiMaggio and Powell, 1983). In so doing, they reinforce existing norms, ways of thinking, and regulations. Changes are therefore curious when they do occur. The “paradox of embedded agency” suggests that agents, or actors, operating in an established field can only exercise agency within the framework of existing norms, ways of thinking, and regulations (Greenwood and Suddaby, 2006). Institutional theorists are thus intrigued by how institutional-level changes occur, as has clearly been the case with the emergence of FinTech.
8 Robin Teigland et al. still challenged and impeded by an asymmetrical regulatory system that has the traditional banks at a disadvantage (Larsson, Chapter 7, this volume). As an industry transforms, one of the main areas of changes in cognition relates to the definition and understanding of the core value-creation activities within the industry. Traditional core banking activities fall under four subcategories: lending, payments, insurance, and savings. While these categories are well accepted across the globe, the emergence of FinTech and what exactly constitutes a FinTech company has led to a state of confusion. For example, Citibank has extended the four categories to seven categories: lending, payments, blockchain, insurance, wealth management, enterprise finance, and RegTech. Furthermore, two recent reports on British FinTech differed in the size of investment rounds in FinTech ventures by USD 80 million, and two reports on Stockholm FinTech 2015 investments displayed a discrepancy of USD 50 million, or 20 percent of the total investment. The reasons for such a variety of outputs are traced back to a lack of unified definition of FinTech and clarification of what branches of business can or cannot be counted as parts of FinTech industry (Gromek, Chapter 9, this volume). Recently, a joint effort by representatives from the leading FinTech actors in Stockholm—Stockholm FinTech Hub, the Nordic Tech List, NFT Ventures, PA Consulting, and researchers from the Stockholm School of Economics—led to a classification of FinTech firms within Sweden into four categories for retail banking: wealth and cash management; payments and transfers; capital, debt, and equity; and InsurTech, as well as five categories for corporate banking: wealth and cash management; payments and transfers; capital, debt, and equity; InsurTech; and trading and exchange. In total, 69 subcategories were also developed (Gromek, Chapter 9, this volume). Moving forward, while regulations are put in place to ensure a safe business environment and provide protection for customers, information security remains an integral part of the operations of a financial service provider, regardless of its size, to ensure customer trust and loyalty (Kryparos, Chapter 2, this volume). New norms enabled by new technologies and standards How—and from where—sources of influence come to change institutions varies. New technologies and standards can serve to challenge existing norms related to how “things are done around here” by enabling new value-creating activities. New technologies in particular are often championed by outsiders of a field, and thus can be considered to be an exogenous force that coerces organizations to change. For example, in a study of Sun Microsystems’ commercialization of the software Java, the open-source technology destroyed existing “taken-for-granted” standards and enabled new norms to emerge when it came to developing software for the Internet (Garud, Jain, and Kumaraswamy, 2002). This shift in norms, however, was not smooth. Existing software developers and the sponsors of other technological standards fought back, forcing the new open-source standard and
Introduction 9 associated new rules to compete with established standards for supremacy. Yet over time, the momentum behind open-source software not only initiated institutional change, but also started a chain of events that would lead to institutional changes for years to come. A parallel to this can be seen in the phenomenon of crowdfunding. One of the earliest areas for FinTech startups, crowdfunding platforms enable entrepreneurs to obtain funds through the Internet from a wider variety of individual investors. As noted above, four forms of crowdfunding have emerged: donation, reward, lending, and equity, thereby creating an additional source of funding beyond the traditional sources of business angels, venture capitalists, banks, and pension funds (Gromek and Dubois, Chapter 12, this volume). Furthermore, the nascent robo-advisory industry has emerged to tackle investors’ demand for a more transparent wealth management service with low commission fees. Robo-advisors replace traditional human investors with algorithm-based platforms to provide personalized financial advice on financial instruments, reducing its expenses, and thus associated commission fees (Mačijauskaitė, Chapter 14, this volume). The speed with which new technologies influence norms differs across countries. For the adoption and uptake of online banking services, Sweden may not be the most technologically advanced; however, Sweden does have the largest population share that actively uses online banking services. This is due to Swedish consumers being quick to adopt new technologies and standards, thereby creating a test bed for new products and services (Björn, Chapter 5, this volume). Sociologists have pointed to the fact that it is not just the creation of a new technology that can prompt institutional change, but also its diffusion and utilization by new actors within and across new fields. The importance of smartphones, for instance, lies not just in the fact that they were invented, but in the fact that the possibilities that they afford have varied across fields. Gaming, for instance, has not been affected by mobiles in the same way as finance has (although, of course, it too has been revolutionized). One norm that is being challenged is the use of credit cards and cash in society as mobile payments are rapidly overtaking as the standard form of payment in Sweden (Arvidsson, Chapter 4, this volume). This can also be described by the relatively early and swift uptake of mobile banking by Swedes (Björn, Chapter 5, this volume). The diffusion of technologies, such as big data analytics enabled by digital traces and blockchain, has therefore meant that these technologies have affected different actors in finance. Digital traces have opened doors for data analysts to map human behavior and offer tailor-made services. These tailor-made services, based on user behavior, have proven to be successful and revolutionized the advertising industry. Currently, the same methods are being applied to a wider variety of businesses, such as credit scoring, fraud detection, asset management, and insurance, and they are taking a bigger role in our society. As their diffusion and adoption increase, they will continue to be important drivers of change. For example, the blockchain technologies that were previously known and used only by a small fraction of the population in 2007 are
10 Robin Teigland et al. now being piloted by some of the leading international banks, for example, to facilitate settlement processes, payment transactions, enable electronic shareholder voting systems, and corporate governance (Moreno Puertas and Teigland, Chapter 15, this volume; Holmberg, Chapter 16, this volume). A view of the actors One key element that affects how changes occur is whether the changes are driven by endogenous or exogenous forces. While exogenous forces, particularly actors—such as entrepreneurs—that are completely new to a field, are commonly associated with institutional changes (Battilana, Leca, and Boxenbaum, 2009), incumbent firms have also been known to drive changes when they see this as necessary. The changes that result may therefore be completely different in different locations or in different organizations; the activities could be hybrids of one another, variations on the same, or new activities entirely. Within Sweden, FinTech startups have been the initial drivers of transformation. Not only have changes in regulations and changing customer beliefs and behaviors enabled the emergence of FinTech startups, but also an exponential decrease in the financial resources required to start up a business has occurred. Today, there are more than 100 FinTech startups in the Stockholm area, with well over 240 in Sweden as a whole (Gromek, Chapter 9, this volume). As noted above, many incumbent banks have started to realize the potential threat that inaction in the wake of these new entrants could hold. However, as heads-on competition with the new entrants is proving to be an expensive endeavor due to the relative advantage of the new entrants in terms of smaller organizational size and speed of innovation, the banks have started to look for alternative ways to approach these new companies and technologies (van der Zande, Chapter 17, this volume). In addition to incumbent actors and startups, one other set of actors that has been found to play a vital role in the transformation of the financial services industry is that of business angels and venture capitalists (Press, Chapter 18, this volume). For example, the number of Swedish angel investments in FinTech in Sweden more than doubled from 2015 to 2016, from around 200 to 400. This group of investors began to notice the potential of high return in the industry, and many of these investors were from the traditional financial services industry and were looking to find the next disruptor. Additionally, many incumbent firms developed their own VC activities investing in FinTech startups in order to develop their businesses and better understand the disruptive forces in the industry. Even foreign actors have influenced the transformation as the amount of foreign investment in Sweden’s FinTech has increased. As FinTech startups enter their expansion phase, foreign investors have in many instances joined domestic investors on the investor roster of a FinTech startup. These foreign actors provide not only money for growth, but they also enable cross-pollination across their many global locations, thus further accelerating the rate of change (Press, Chapter 18, this volume).
Introduction 11 One example of a geographic shift that has implications for institutions lies in the UK’s exit from the European Union. “Brexit,” as it has been called, and the potential exodus of financial institutions and firms from the UK, could be a boon for continental Europe, as well as for the Nordics (Gromek and Mavropoulos, Chapter 22, this volume). Lastly, although these drivers have been catalysts for change, the resulting changes are unlikely to be identical everywhere in the world—nor even identical in different parts of a country as small as Sweden. Instead, institutional theorists have highlighted that differences in environment, namely through different societies, fields, and organizations, lead to a diversity in activities. As Dacin, Goodstein, and Scott (2002) point out, “organizations and managers are not sponges or pawns, but actors responding to challenges under the guidance of existing institutions.” When it comes to crowdfunding, for instance, proximity has been seen to be of lasting importance: even with the advent of the Internet, investors are more likely to engage with local actors when it comes to investment and financing opportunities (Dubois and Gromek, Chapter 19, this volume). Moreover, there are both opportunities and costs to being located in a hub of economic activity, for instance inside or outside a cluster such as Stockholm (Jerezcek, Chapter 21, this volume). Having examined in detail some of the extant theory around institutional changes and how these lead to change in the field of FinTech, we turn now to presenting summaries of the chapters contained in this book. Chapter summaries Part 1: New regulations 1 Åke Freij: Successful FinTech innovation is dependent on a number of key factors that comprise the financial services industry ecosystem, such as customer demand and new technologies. However, a less explored driver for FinTech innovation is the role of regulatory change. In the chapter “A Regulatory Innovation Framework: How Regulatory Change Leads to Innovation Outcomes for FinTechs,” Åke Freij explores six strategies for realizing the benefits from regulatory change both for incumbents and FinTechs, and exemplifies an innovation opportunity by discussing the upcoming PSD2 directive (the Second Payment Services Directive). 2 Georgios Kryparos: While regulations are put in place to ensure a safe business environment and provide protection for customers, information security remains an integral part of the operations of a financial service provider, regardless of its size, to ensure customer trust and loyalty. In the chapter “Information Security in the Realm of FinTech,” Georgios Kryparos examines the current landscape for FinTechs with regard to the relationship between information security and customer trust, and further looks into recent trends and developments that can pose as either threats or opportunities, and associated response recommendations.
12 Robin Teigland et al. 3 Björn Olsson and Mattias Hallberg: Another key component of a successful FinTech ecosystem, arguably supporting the above-mentioned key drivers, such as customer demand, technological leadership, and an effective regulatory landscape, stems from innovation policy. In the chapter “FinTech in Sweden: Will Policymakers’ (In)action Nurture or Starve Its Growth?” Björn Olsson and Mattias Hallberg explore the current policy landscape that is fueling the FinTech ecosystem in Sweden, and look at future threats and opportunities for Sweden to remain a competitive location for FinTechs to start, develop, and thrive. 4 Niklas Arvidsson: After the bankruptcy of the first Swedish bank, Banco Stockholm, in 1664, the Swedish government took a prominent role by establishing the first central bank in the world, in 1668, and issuing the first state-supported bills and coins. Today, Sweden is on track to becoming the first cashless society in the world. In the chapter “The Future of Cash,” Niklas Arvidsson tracks the development of the Swedish monetary system over the centuries, discusses the proposed changes in legislations, and offers an insightful perspective on how Swedish cash may evolve over time. 5 Michael Björn: As discussed previously in the chapter, a key driver for innovation is customer demand. Sweden has a reputation for being a test bed for new products and services, and this is arguably due to the fact that Swedish consumers are quick to adopt new technologies and standards. In the chapter “The Adoption of Online Banking in Sweden,” Michael Björn contrasts the adoption and uptake of online banking services compared to that of a selection of other developed countries, and argues that while Sweden may not be the most technologically advanced of them, Sweden has the largest population share that actively use online banking services. Part 2: Cognition: legitimacy and views 6 Mats Lewan: Trust plays an essential role in the functioning of a capitalistic society (Hosking, 2014). However, trust is a dynamic concept that is perceived differently across cultures, industries, and time. Firms need to permanently adjust to fit the narrative in order to maintain and gain investors and clients. The narrative has been changing over time, and our introductory chapter aims to answer the question of what the current narrative is: how firms build trust as of 2017 and what the narrative of tomorrow could be. In the chapter “The Role of Trust in Emerging Technologies,” Mats Lewan interviews some of the key players in the financial sector, the Scandinavian tech and startup community, to gain insights on how people perceive trust across different industries. Then he briefly investigates the new technologies that are changing the role of trust, such as the blockchain and the Trustnet. 7 Anthony Larsson: The Internet has changed the classical interaction between financial firms and their clients. In the past, firms needed to invest in subsidiaries in order to gain access to new clients. The reason was that consumers valued spatial convenience, and banks competed by establishing nearby
Introduction 13 subsidiaries. However, the Internet has allowed consumers to interact with financial institutions directly through their computer or smartphone. As a result, the spatial competition transitioned toward a digital one. The digitalization of financial services also enabled a new wave of FinTech startups to compete against the established financial institutions. In the chapter “Responding to the FinTech Challenge: A Study of Swedish Bank Managers’ Perceptions of FinTech’s Effects on Digitalization and Customer e-Loyalty,” Anthony Larsson explores the key challenges that FinTech firms have posed to Swedish banks in terms of securing customer loyalty through a series of interviews with managers representing different banks. The chapter also investigates the Bell Doctrine, in which large firms (traditional banks) in regulated industries are able to dominate non-regulated industries (FinTech). 8 Anna Felländer, Shahryar Siri, and Robin Teigland: The financial industry used to be characterized by high entry costs and required a high level of trust, which prevented other newly established companies from entering the market. However, the 2008 financial crisis revealed inefficiencies within the financial industry and decreased the level of trust deposited in them. This, combined with faster Internet, smartphones, and big data, allowed entrepreneurs to enter the market and challenge the established financial firms. In the chapter “The Three Phases of FinTech,” Anna Fellander, Shahryar Siri, and Robin Teigland explain the redistribution of power from larger, established banks to FinTech firms. The chapter is divided into three phases, starting from 2008 and ending with a forecast of the relationship between the financial industry and FinTech startups in 2020. 9 Michal Gromek: The term “FinTech” is widely used in the media, yet there is no clear framework on what can be considered as FinTech. In the chapter “Clarifying the Blurry Lines of FinTech: Opening the Pandora’s Box of FinTech categorization,” Michal Gromek attempts to create a comprehensive guide for categorizing FinTech firms and provides a visualization of companies adopting a model from the area of social sciences to FinTech industry needs. 10 Mats Lewan: The FinTech revolution in Sweden wouldn’t have happened without a specific set of conditions and innovations that allowed entrepreneurs to enter financial markets. The Swedish government played an important role in the early introduction of the Internet by designing the right incentives and effectively deregulating the telecom market in 1998 (Konkurrensverket, 1998). The resulting infrastructure also allowed mobile Internet to be introduced rapidly across the country. The early introduction of both the Internet and mobile Internet was essential to create a comfortable environment for FinTech startups to offer their services. The BankID, which was developed by Finansiell ID-Teknik BID AB, also played an important role, allowing third parties—FinTech startups—to use their system in exchange for a small fee. In the chapter “The Internet as an Enabler of FinTech,” Mats Lewan aims to discover the key enablers of FinTech in Sweden by conducting a series of interviews with renowned people in the Scandinavian tech community.
14 Robin Teigland et al. Part 3: New norms enabled by new technologies and standards 11 Claire Ingram Bogusz: Digital traces have opened doors for data analysts to map human behavior and offer tailor-made services. These tailor-made services, based on user behavior, have proven to be successful and revolutionized the advertising industry. Currently, the same methods are being applied to a wider variety of businesses, such as credit scoring, fraud detection, asset management, and insurance, and they are taking a bigger role in our society. As the collection of data increases and the methods become more accurate, a new legal framework is necessary to ensure that we are comfortable sharing our data. In the chapter “Digital Traces, Ethics, and Insight: Data-Driven Services in FinTech,” Claire Ingram Bogusz explores the ethical implications of collecting such data, and provides a detailed overview of the data-gathering industry and the data-driven services within the FinTech and banking landscape. 12 Michal Gromek and Alexandre Dubois: The revolution of the Internet has enabled entrepreneurs to obtain funds from a wider variety of investors. This has given rise to a new type of fundraising called crowdfunding. The chapter “Digital Meetings: Real Growth, Better Funding? An Introduction to Swedish Crowdfunding” describes the development of crowdfunding platforms with a focus on Sweden, gives a detailed view of the different types of crowdfunding, summarizes its key benefits and challenges, and proposes future scenarios for this industry. 13 Niklas Arvidsson: Sweden was the first country to issue central bank statebacked bills and coins. However, it is experimenting a transition toward a cashless society. A new wave of entrepreneurs are offering cash payment services that provide the simplicity and convenience that most users demand. The chapter “The Payment Landscape in Sweden” offers an overview of the current trends in payment systems in Sweden and promotes a payment landscape that is characterized by innovation and competition. 14 Agnė Mačijauskaitė: The financial crisis in 2008 revealed inefficiencies and a lack of transparency in the financial industry. As a result, the nascent robo-advisory industry has emerged to tackle the investors’ demand for a more transparent wealth management service with low commission fees. Robo-advisors use algorithm-based platforms to provide personalized financial advice on financial instruments, reducing its expenses, and thus its associated commission fees. The chapter “Introduction to the Robo- Advisory Industry in Sweden” describes the development of the young robo-advisory industry, provides a qualitative analysis of the Swedish market, and offers insights into future trends. 15 Alejandro Moreno Puertas and Robin Teigland: Peer-to-peer networks were popularized by the famous, and now defunct, file-sharing service called Napster. The same concept was combined with cryptographic proof to create a new type of (crypto)currency called Bitcoin. The infrastructure of Bitcoin has proved to be efficient as it deals with over USD 1 billion in transactions per day without a clear centralized oversight. The chapter “Blockchain: The
Introduction 15 Internet of Value” describes the history of Bitcoin, explains the key concepts of its underlying infrastructure and of other similar cryptocurrencies, such as Ethereum, Ripple, Hyperledger, and RSCoin, provides an overview of blockchain applications, and examines the wider discussion on the principles of blockchain technology. 16 Håkan Holmberg: As of 2017, bitcoin is the leading cryptocurrency in terms of market value. The original idea was to provide a decentralized electronic cash system with low transaction costs. However, the network was designed to only accept two to seven transactions per second. As the demand for transactions has grown over the last years, the network cannot process transactions in time. This has increased the transaction costs and the processing time, diminishing Bitcoin’s advantages. In the chapter “How to Scale Bitcoin: A Payment Network That No One Controls,” Håkan Holmberg explores the current challenges that the Bitcoin community is facing, and describes the two alternatives proposed by Bitcoin Unlimited and SegWit to solve the scalability problem. Part 4: A view of the actors 17 Jochem van der Zande: A case in point of exogenous forces impacting the financial services sector, slowly but steadily capturing more of the traditional banks’ customers and activities, many incumbent banks have started to realize the potential threat that inaction in the wake of these new entrants could result in. However, as head-on competition with the new entrants is proving to be an expensive endeavor due to the relative advantage of the new entrants in terms of smaller organizational size and speed of innovation, the banks have started to look for alternative ways to approach these new companies and technologies. In the chapter “Banks and Digitalization,” Jochem van der Zande engages with the four major banks in Sweden to illustrate different strategies to respond to organizational change resulting from these exogenous change forces. 18 Elizabeth Press: A key enabling factor for new entrants is access to financing and willingness of these financiers to take risk in ventures that in many, if not most, cases do not turn profitable over their lifetime. In the chapter “The Role of Venture Capital in the Success of the Swedish FinTech Industry,” Elizabeth Press discusses the role of venture capital in the Swedish FinTech landscape, and also looks at some of the future threats and opportunities for Swedish FinTech investments. 19 Alexandre Dubois and Michal Gromek: As argued previously, the resulting changes from an industry transformation are not evenly distributed across organizations, users, and geographies. In the chapter “How Distance Comes into Play in Equity Crowdfunding,” Michal Gromek and Alexandre Dubois exemplify the discrepancy by looking at the continued importance of proximity in equity crowdfunding. Thus, pointing to the fact that even
16 Robin Teigland et al. with the advent of the Internet enabling us to communicate over great distances, we are still more likely to engage with our local communities, particularly with regard to investment and financing opportunities. 20 Catharina Burenstam Linder: While the rise of the FinTech sector can be seen both as a threat and an opportunity to the traditional banking sector, the fact that the industry, as a whole, is undergoing a transformation remains. In order for the ecosystem to be able to come together, discuss, plan, and collaborate for the continued success of the Stockholm FinTech cluster, and championing Sweden in the global FinTech community, a common space was needed. In the chapter “The Stockholm FinTech Hub,” Catharina Burenstam Linder discusses the recently launched Stockholm FinTech Hub and how the hub works to assist and accommodate the continued growth of the local ecosystem, as well as develop the potential of Stockholm within the global finance ecosystem. 21 Katarzyna Jereczek: Referring to the above chapter on the importance of distance in crowdfunding, and the establishment of a physical hub for the growth of the Stockholm ecosystem, it becomes more evident that being close to the ecosystem is likely to increase the chances for success of a new FinTech startup. However, in the chapter “Geographic Decentralization of FinTech Companies in Sweden,” Kata Jereczek looks into the rising FinTech activity in smaller cities in Sweden, and contrasts the advantages and disadvantages of starting up inside or outside a cluster such as Stockholm. 22 Michal Gromek and Timotheos Mavropoulos: Again, as Dacin, Goodstein, and Scott (2002, p.50) note, organizations are “actors responding to challenges under the guidance of existing institutions.” In the wake of the 2016 UK referendum on leaving the EU, many have debated the future prospects for London remaining the world’s strongest financial center, and arguably also the world’s leading hub for FinTech and financial innovation. In the chapter “When Britain Leaves the EU, Will FinTechs Turn to the Vikings?” Michal Gromek and Timotheos Mavropoulos look at the arguments put forth for and against an exodus of financial institutions and firms from the UK to continental Europe, to the Nordics, and particularly to Stockholm. Bibliography Battilana, J., Leca, B., and Boxenbaum, E., 2009. How actors change institutions: Towards a theory of institutional entrepreneurship. Academy of Management Annals, 3(1), p.65 LP-107. Benwell, M., 2014. Stockholm is rivalling Silicon Valley with a hotbed of technology start-ups. The Independent. [online] Available at: www.independent.co.uk/life-style/ gadgets-and-tech/features/stockholm-is-rivalling-silicon-valley-with-a-hotbed-of- technology-start-ups-9931876.html [Accessed January 16, 2018]. British Banking Association, 2016. BBA briefing: Reforms since the financial crisis. [online] Available at: www.bba.org.uk/news/reports/bba-briefing-reforms-since-the- financial-crisis/#.WbFTrNOg-_B [Accessed January 16, 2018].
Introduction 17 Dacin, M.T., Goodstein, J., and Scott, W.R., 2002. Institutional theory and institutional change: Introduction to the special research forum. Academy of Management Journal, 45(1), pp.45–57. DiMaggio, P.J. and Powell, W.W., 1983. The iron cage revisited: Institutional isomorphism and collective rationality in organizational fields. American Sociological Review, 48(2), pp.147–160. DiMaggio, P.J. and Powell, W.W., 1991. Introduction. In: W.W. Powell and P.J. DiMaggio, eds. The new institutionalism in organizational analysis. Chicago, IL: University of Chicago Press, pp.1–40. DiMaggio, P.J., Hargittai, E., Neuman, W.R., and Robinson, J.P., 2001. Social implications of the Internet. Annual Review of Sociology, 27, pp.307–336. Flint, D., 2014. Business ethics in banking: Time for a second chance? [online] Available at: www.hsbc.com/news-and-insight/media-resources/speeches/2014/business-ethics- in-banking [Accessed January 16, 2018]. Garud, R., Jain, S., and Kumaraswamy, A., 2002. Institutional entrepreneurship in the sponsorship of common technological standards: The case of Sun Microsystems and Java. Academy of Management Journal, 45(1), pp.196–214. Greenwood, R. and Suddaby, R., 2006. Professional service firms. Oxford: Elsevier JAI. Hosking, G., 2014. Trust and financial markets. European Financial Review. [online] Available at: www.europeanfinancialreview.com/?p=3523 [Accessed September 7, 2017]. IIS, 2017. E-handel, betaltjänster och delningsekonomi [E-purchase, payment services and shared economy]. [online] Available at: www.soi2016.se/e-handel-internetbank-och- betaltjanster/mobilt-bankid-och-swish/ [Accessed January 16, 2018]. Klarna, 2017. Klarna statistics. [online] Available at: www.klarna.com/uk/about-us/ klarna-statistics [Accessed January 16, 2018]. Konkurrensverket, 1998. Deregulated markets in Sweden: A follow-up study. [online] Available at: www.konkurrensverket.se/globalassets/english/publications-and-decisions/ deregulated-markets-in-sweden.pdf [Accessed January 16, 2018]. Lee, K. and Pennings, J.M., 2002. Mimicry and the market: Adoption of a new organizational form. Academy of Management Journal, 45(1), pp.144–162. Lounsbury, M., 2002. Institutional transformation and status mobility: The professionalization of the field of finance. Academy of Management Journal, 45(1), pp.255–266. Oliver, C., 1992. The antecedents of deinstitutionalization. Organization Studies, 13(4), pp.563–588. Scott, W.R., 1995. Institutions and organizations. Thousand Oaks, CA: Sage. Selznick, P., 1996. Institutionalism “old” and “new.” Administrative Science Quarterly, 41(2), pp.270–277. Sine, W.D. and David, R.J., 2003. Environmental jolts, institutional change, and the creation of entrepreneurial opportunity in the US electric power industry. Research Policy, 32(2), pp.185–207. Skog, A., Lewan, M., Karlström, M., Morgulis-Yakushev, S., Lu, Y., and Teigland, R., 2016. Chasing the tale of the unicorn: A study of Sweden’s misty meadows. [online] Available at: https://www.hhs.se/en/about-us/news/2016/new-research-explores-the-success- of-swedish-high-tech-startup-companies [Accessed January 16, 2018]. Smets, M., Morris, T., and Greenwood, R., 2012. From practice to field: A multilevel model of practice-driven institutional change. Academy of Management Journal, 55(4), pp.877–904. Stockholm FinTech Hub, 2017. Swedish FinTech in numbers. [online] Available at: http:// data.stockholmfin.tech/ [Accessed January 16, 2018].
24 Åke Freij Product design The products designed and sold by financial services firms are an important area of impact from regulatory change. Regulators can target transparency of products by demanding improved disclosure (Richard and Devinney, 2005). Products are designed to define firms’ offerings to the market and customers (Fixson and Park, 2008). A regulatory change can present requirements for new products, as in the cars developed toward zero-emission rules (Dyerson and Pilkington, 2000). The company needs to understand the regulatory change and how it creates demand for new products, and also how it influences the existing products. One example of a regulation affecting product design is the fund-based life insurance introduced in Sweden in 1990 and in several other countries in the late 1900s. The regulation presented requirements for new components to be assembled into innovative products with a higher degree of flexibility than before. A second example is the regulations concerning securities funds (Undertakings in Collective Investments in Tradable Securities, UCITS). This regulation defines the role of the financial product called “investment fund.” When the UCITS regulation was updated to version 5 in 2016, products were influenced due to changes in the ability to remunerate providers of funds. Service processes Service processes are necessary to deliver the promise of functionality offered in products. Due to the visibility of processes, regulators target them to increase efficiency in an industry. Processes are required over the entire life cycle of the product (Jacobides, 2005). A change in regulations influences how firms modify their internal processes (Cabigiosu and Camuffo, 2012). A proactive company can offer services to customers whereby the requirements from regulations are supported as a process delivered to the market. An example of a regulation influencing service processes is Foreign Account Tax Compliance Act (FATCA) for reporting on US tax status for customers in non-US banks. The regulation implied that new information was captured in the process of establishing a customer account. A second is the implementation of “best execution” regulations concerning trading of securities in the EU regulation Markets in Financial Instruments Directive (MiFID). New processes were required to analyze the consequence of buying and selling specific securities across multiple markets.
A regulatory innovation framework 25 Customer relationships A key rationale for regulators to address regulatory change is to strengthen the protection of customers. Regulations can contain requirements for increased transparency, and clarification of roles in connection with the customers. Such regulations are prominent in, for example, the building industry (Cacciatori and Jacobides, 2005) and in the airline engine industry (Brusoni, Prencipe, and Pavitt, 2001). Thereby, the roles of actors interfacing the customer, across the processes of sales, advice, distribution, and maintenance, are often changed as a result of new regulations. One example of a regulation influencing the customer relationship is the European Union directive MiFID2 (the second Markets in Financial Instruments Directive), including requirements for Know Your Customer (KYC). Demands are presented in this new regulation of how the advisory relationship with the customer is to be documented. In addition, there are instructions for the use of external intermediaries, and how such partners are remunerated. Numerous variations of regulations concerning financial advice exist in different countries. Another example of a regulatory change that will alter customer relationships is PSD2, which will be addressed later in the chapter. Technology platforms Regulatory changes with impact on technology can be either technical specifications, where requirements are infused to certify a new technology (Teece, 1986), or a broad regulation, which puts entirely new obligations onto the platforms of an industry (Tee and Gawer, 2009). Technology also plays a role in addressing the requirements of regulations across products and processes. The use of platforms to manage regulatory requirements has proven viable in the financial services industry (Meyer and Dalal, 2002). The Payment Card Industry Data Security Standard (PCI DSS) is an example of a detailed and specific requirement for technology. Even if it is formally not a government regulation, it can be regarded as a de facto regulation for payment cards. An example of regulatory change with impact on technology is Solvency 2 for insurance. This regulation covers capital requirements, risk management, and reporting, and thereby drives new technical foundations for information management. A corresponding regulation is the existing Basel 2 rules for banks, which is currently superseded by the Basel 3 framework.
26 Åke Freij Opportunities when regulations change Discontinuities due to an external source, such as regulatory changes, can lead to significant changes in how an industry organizes itself, with important implications for the control or profitability of a firm. The results of regulatory evolution can lead to different outcomes in the ownership of assets (Tee and Gawer, 2009). Evidence of the innovation effects from regulations has been presented by contributions from previous research (see e.g. Ferraro and Gurses, 2009). For example, firms that are in possession of production assets, such as platforms, can leverage these to create new services that support common regulatory compliance processes across different business units. Four main areas (as depicted in Figure 1.1) have been found where firms can achieve innovation, representing clear windows of entrepreneurial opportunity. The first area is dominant design, or the evolution of well-defined approaches to the design of products and services, such as through standards. The second area is that regulatory demands can change conditions for how firms collaborate due to challenges with requirements in the interface between actors. A third area is the modification to technical requirements arising from regulatory change. Finally, in the fourth area, firms can explore the expiry of legal protections. I discuss each of these in turn below. Establish advantages from dominant designs As industries evolve, there are certain ways of performing business and designing products and services that become dominant. Such practices are called dominant designs, and they emerge as widely adopted ways to configure products and systems (Anderson and Tushman, 1990). These designs emerge as a trial-and-error process after breakthrough innovations, as manufacturers, suppliers, customers, and regulatory agencies compete to decrease the uncertainty in a market that is related to a significant variation in products, processes, customer relationships, and technology. Dominant designs evolve in a process that includes social, political, technological, and economic aspects (Abernathy and Utterback, 1978). One particular type of dominant design is standards. Standards contribute to the establishment of stable industry conditions. Government regulation often compels the adoption of standards, and firms could contribute to the development of these standards. From another perspective, the lack of agreement of a dominant design can hinder innovation evolving in a market. For example, in a market such as the mobile payments segment, innovation investments will be made under unclear criteria, and hence may hamper business innovation as resources are spent Figure 1.1 Four innovation opportunities when regulations change
A regulatory innovation framework 27 inefficiently (Ozcan and Santos, 2015). Firms that can interpret and implement such unclear requirements can become winners in the emerging market. Exploit changed conditions for firm collaboration Regulations can limit the conditions for collaboration between firms. Such collaboration involves interaction through interfaces between the firms, and the regulatory forces can create requirements to those interfaces that may constrain the innovative activities of firms. Certain actors might be concerned about security and reliability imposed by regulations when collaborating with other firms. These concerns arise since violations of specific regulations might risk hurting the trustworthy image of a company. Such regulations may limit the combination of complementary resources and capabilities, especially in cases of collaboration across industry boundaries (Jaspers, Prencipe, and Ende, 2012). The cooperation between firms has benefits against which coordination costs, including legal circumstances that mandate governance structure, have to be offset. Understand the modification to technical requirements New regulations imposed on an existing industry may establish new technical requirements or demand changes in performance standards that favor revolutionary or architectural strategic development (Abernathy and Clark, 1985). Deregulation may have the same effect. Industry incumbents, constrained by regulatory and institutional logics, react to external events such as new technical requirements, and their actions (or lack thereof) create a space for newcomers to acquire mispriced resources (Ferraro & Gurses, 2009). Government or regulators can influence the development of market infrastructure, and thereby affect the role of firms and generate innovation for some actors (Jacobides, 2005). Changes in regulations might escalate or kick-start the diffusion of a technical requirement under development. Utilize the expiry of legal protection Over time, products and processes become well understood as the technology supporting them becomes widely available through the diffusion of knowledge and as legal and regulatory protections such as patents expire (Teece, 1986). The integration of regulatory compliance into product offerings can expand the role of a firm. The interpretation of regulatory requirements can as a result be moved from the firm’s internal processes to outside vendors and partners. This could mean that regulatory frameworks enable new markets between private firms to emerge, and as such prompt the development of a new mode of organizing (Teece, 2006). Regulation tends to either institute or legitimize new rules, such as vertically cospecialized arrangements. As players in each part of an industry try to lobby for their interests, they promote an industry structure that is maximally profitable for them. Deregulation is freeing companies to divide the market in new ways. In the financial services industry, previously integrated sectors have been taken apart, partly as a result of changed regulations.
28 Åke Freij Based on the above observations, it could be argued that actions related to regulatory change will impact the position of firms vis-à-vis other firms, customers, and regulators, and thereby create significant opportunities to benefit from innovation. The relevant ecosystem for this innovation process includes not just firms, but also regulators, educational institutions, standard-setting bodies, and the courts. Regulations can be seen as a type of technology, and therefore new regulations could be positioned as a new technology, especially in services industries (Rogers, 1995). A regulatory innovation framework Below, I present the regulatory innovation framework used to understand the impact of changes in regulations. The framework is developed from my research combining theoretical and empirical findings from studying what actions firms take to implement regulatory change requirements. First, I present the six strategies that emerged in my research before presenting a “checklist” of actions to help guide firms in executing this strategy. Strategies for regulatory innovation In order to determine how to focus the work with innovation in connection with regulatory change, the four areas of impact are juxtaposed with the four areas of opportunities. When merging this juxtaposition with theory, six innovation strategies emerged from a detailed analysis of the concepts and themes inherent in the respective dimensions (see Figure 1.2). One conclusion from my research is that the impact of regulatory change can benefit both established financial companies (incumbents) and FinTechs. Thus, below, I discuss each of these strategies in turn and illustrate them with an example from both an incumbent and FinTech startup. Regulatory change impact focus: Company opportunity: Products Service processes Customer relationships Technology Dominant designs Firm collaboration Technical requirements Expiry of legal protection Standards designer System integrator Business model innovator Infrastructure platform builder Technology wrapper Advisor & co-creator Figure 1.2 Regulatory innovation strategies
A regulatory innovation framework 29 Standards designer This strategy involves using regulations as a way to determine the forms for doing business in the industry. Large firms could even push for higher regulatory demands in order to define intricate criteria for the establishment for new entrants. This strategy needs careful work with architecture (for both products and processes), reference models, and common standards (internal and external). Examples of successful standards designers Incumbent: SWIFT My Standards By establishing the unit My Standards, the global payments network organization SWIFT has taken a proactive stance in the process of defining the standards for transactions. The active consideration of new standards connected to new regulations has proven valuable for the actors in the industry. The developed solution claims to support current and emerging regulations impacting the payments industry. FinTech: Ant Financial Ant Financial, the spin-off from Alipay providing online payment services, is a good example of a standards designer that has established a secure platform for processing payments (and analyzing credit scores) for large volumes of transactions. In the wake of the upcoming regulation for payment services in the EU, this company can claim account information from incumbent banks and payment providers. System integrator A system integrator applies practices to enable ecosystem constellations across firm products and service processes boundaries. This strategy involves the use of automated processes, API design, and concepts covering the “systems of engagement” (i.e., processes where different actors meet across boundaries in an ecosystem). Examples of successful system integrators Incumbent: Skandia In the wake of several major regulatory changes, the company Skandia has shown capabilities of system integration. The most prominent example is the introduction of the new regulation for fund-based life insurance. (continued)
30 Åke Freij Here, Skandia was the only firm that introduced externally managed funds and combined this with the use of external sales and service providers. FinTech: Tink The personal finance aggregator Tink has established processes that support system integration. This strategy is beneficial considering existing and new regulations such as PSD2, AMLD4, and MiFID2, which both require extended insight into the data and behavior of customers (a concept often described as Know Your Customer, KYC). Advisor and co-creator This strategy calls for a proactive stance toward customers and ecosystem partners. It is essential to establish processes to co-create solutions with customers, as well as internal assembly of combined solutions that meet customer needs. Examples of successful advisors and co-creators Incumbents: large banks arranging “hackathons” Several large financial institutions attempt to leverage their customer relationships, experience of collaboration arrangements, and their dominant position in the industry. They do this by collaborating with entrepreneurs in so-called “hackathons.” Examples of such events are those hosted by Nordea and CitiBank. When partnerships are established between existing and new actors, the result could be new solutions that support requirements introduced by changed regulations. FinTech: Sparplatsen/Insurance Simplified Several interesting examples of FinTechs applying this strategy exist. Two cases from the insurance industry in Sweden are Sparplatsen and Insurance Simplified. The first is focusing on life insurance and the balance to give advice without incurring high costs for assuring quality and compliance with regulations related to transparency of advice (such as MiFID2). The second focuses on transparency in the property insurance segment. This can prove to be a valuable solution in the wake of the new EU directive for insurance distribution (Insurance Distribution Directive, IDD). Infrastructure platform builder The foundation for innovation in connection with regulatory change is a solid infrastructure platform. This platform contains flexible delivery of infrastructure (continued)
A regulatory innovation framework 31 capabilities and the functions needed to understand regulatory change and to deliver solutions in production. This strategy will include approaches toward the opening of APIs1 for internal and external consumers. Examples of successful infrastructure platform builders Incumbents: Swedish bank collaborations The joint work of the banking industry in Sweden has over recent years resulted in widely adopted solutions for infrastructure. Two examples are the “peer-to-peer” payments solution Swish, and the security and identification foundation technology BankID. As a result of the above two projects, the incumbent banks have kept a central position in the industry, despite the emergence of FinTech challengers. The solutions developed will also support change required due to upcoming regulations concerning payments transactions and treatment of individual security online (such as the emerging EU data privacy regulation GDPR). FinTech: Betalo/PayPal A Swedish FinTech venture with the potential to establish a platform in the wake of upcoming changes in the payment industry is Betalo, which is focused on simplified and cheaper global payments. The requirements for open APIs in the wake of the PSD2 regulation can influence this venture. A global example that has established an infrastructure platform is PayPal. Technology wrapper There is an opportunity to integrate the changing requirements for regulatory compliance into products and services. This can save the trouble for the bank and insurance company’s end customer to consider these requirements. Niche challengers that enter the market with a specific solution for a regulatory requirement can also take this role. Examples of successful technology wrappers Incumbent: cyber insurance (Swiss Re) The increasing risks (and associated compliance demands) with cyberthreats have promoted firms to support their customers with processes concerning risk and compliance in the form of insurance products. Such solutions have been designed and marketed by Swiss Re as Cyber Solutions, in collaboration with the technology provider IBM. Extended solutions for insurance (continued)
32 Åke Freij coverage can be relevant when companies struggle to support the technical requirements inherent in the EU data privacy regulation GDPR. FinTech: iZettle The solutions from the FinTech company iZettle are an example of a technology wrapper. The new requirements from regulations in payments and data privacy can drive demand for products and services that influence customer relationships where iZettle can mitigate difficulties for incumbents to be compliant. Business model innovator The change in conditions for achieving value from innovation calls for new business models to emerge. This strategy incorporates models for defining the constituting parts of the business, as well as approaches to defining how these parts belong together and relate to the existing business of the company. Examples of successful business model innovators Incumbents: European Multilateral Clearing Facility (EMCF) The establishment of the clearing facility EMCF by the two Dutch banks Fortis and ABN Amro was a radical approach to capturing value in the changed industry structure around securities settlements. This change was driven by the implementation of the MiFID directive and specific regulations concerning “best execution” of securities trading transactions. FinTech: M-PESA Introduced in several African countries by a group of telecommunications providers, this company changed the business models in the payments industry by applying existing mobile networks to channel transactions. Since M-PESA is not a fully regulated financial institution, they can avoid certain details concerning regulations such as KYC but also gain detailed insight into customer behavior needed to support regulations. Checklist for developing a regulatory innovation strategy In addition to developing six innovation strategies, I have also developed a “master list” of 160 action steps that can be divided across the six innovation strategies (this is 10 per cell in the framework). The action steps are found by combining the four (continued)
Explore new technical requirements Exploit collaboration Expiry of legal protection Establish dominant design Product Design Service Processes Customer Relations Technology Platforms Innovation actions Figure 1.3 Innovation action list derived from the regulatory innovation framework
40 Åke Freij Available at: www.hhs.se/contentassets/574f17c1efcf48daa6c6974a4dad5740/disscover_ ake-freij-master-file-161231_korredit_3.pdf [Accessed January 6, 2018]. Jacobides, M., 2005. Industry change through vertical disintegration: How and why markets emerged in mortgage banking. Academy of Management Journal, 48(3), pp.465–498. Jaspers, F., Prencipe, A., and Ende, J., 2012. Organizing interindustry architectural innovations: Evidence from mobile communication applications Journal of Product Innovation, 29(3), pp.419–431. Levitt, T., 1968. Why business always loses. Harvard Business Review, 46(2), pp.81–89. Liker, J., 2015. Assessing the sins of Volkswagen, Toyota, and General Motors. Harvard Business Review. [online] Available at: https://hbr.org/2015/09/assessing-the-sins-of- volkswagen-toyota-and-general-motors [Accessed January 6, 2018]. Meyer, M. and Dalal, D., 2002. Managing platform architectures and manufacturing processes for nonassembled products. Journal of Product Innovation, 19(4), pp.277–293. Moreno, K., 2014. For the financial sector, regulations are here to stay—time to make the best of them. Forbes. [online] Available at: www.forbes.com/sites/ forbesinsights/2014/10/09/for-the-financial-sector-regulations-are-here-to-stay-time- to-make-the-best-of-them/#38713693cc73 [Accessed January 6, 2018]. Ozcan, P. and Santos, F., 2015. The market that never was: Turf wars and failed alliances in mobile payments. Strategic Management Journal, 36(10), pp.1486–1512. Richard, P.J. and Devinney, T.M., 2005. Modular strategies: B2B technology and architectural knowledge. California Management Review, 47(4), pp.86–113. Rogers, E.M., 1995. Diffusion of innovations. 4th ed. New York: Free Press. Schrage, M., 2015. Is VW’s fraud the end of large-scale corporate deception? Harvard Business Review. [online] Available at: https://hbr.org/2015/09/is-vws-fraud-the-end- of-large-scale-corporate-deception [Accessed January 6, 2018]. Smith, K. and Grimm, C., 1987. Environmental variation, strategic change and firm performance: A study of railroad deregulation. Strategic Management Journal, 8(4), pp.363–376. Tee, R. and Gawer, A., 2009. Industry architecture as a determinant of successful platform strategies: A case study of the i-mode mobile Internet service. European Management Review, 6(4), pp.217–232. Teece, D., 1986. Profiting from technological innovation: Implications for integration, collaboration, licensing and public policy. Research Policy, 15(6), pp.285–305. Teece, D., 2006. Reflections on “profiting from innovation.” Research Policy, 35(8), pp.1131–1146. Valcke, P., Vandezande, N., and Van de Velde, N., 2015. The evolution of third party payment providers and cryptocurrencies under the EU’s upcoming PSD2 and AMLD4. [online] Available at: www.swiftinstitute.org/papers/the-evolution-of-third-party- payment-providers-and-cryptocurrencies-under-the-eus-upcoming-psd2-and-amld4/ [Accessed January 6, 2018]. Wessel, D. (2012). Bank balance: Regulation and innovation. The Wall Street Journal. [online] Available at: www.wsj.com/articles/SB1000142405270230407200457732350 0303451074 [Accessed January 6, 2018].
A regulatory innovation framework 41 List of regulations included in the text AMLD4 (the Fourth Anti Money Laundry Directive): In order to limit the use of the financial system for criminal activities, there have been regulations established to prevent such use. AMLD4 is the recent extension of regulations, and rules such as Counter Terrorist Financing (CTF) and Politically Exposed Persons (PEP) are included in the regulation. Basel 2 and 3: The need for banks to understand the level of capital needed to support their business, as well as the processes in place to manage risk, are developed over time to be more stringent. The reason is to avoid support by society once the company is in trouble. FATCA (Foreign Account Tax Compliance Act): A regulation introduced by the US to track the flow of funds by US citizens with accounts in other jurisdictions. GDPR (General Data Protection Regulation): A major strengthening of the rights of individuals against the firms that collect and process personal data. Requirements include right to erasure, notification of breach, and the balance of data collected relative to the purpose of use. IDD (Insurance Distribution Directive): This regulation is increasing demands on insurance companies to be transparent about relationships with distributors and sales channels. The transparency includes conflicts of interest, bundles of products, and remuneration schemes. IFRS (International Financial Reporting Standards): A series of rules for how to compile financial statements. Current projects of relevance for the financial industry are IFRS9 (reporting of financial instruments) and IFRS4 (accounting for insurance contracts). KYC (Know Your Customer): This is not a specific regulation, but a term used in connection with regulations dealing with customer relationships, such as MiFID2 and AMLD4. MiFID2 (the Second Markets in Financial Instruments Directive): The extension of the first MiFID increases demand for documenting financial advice and increases transparency of relationships around the financial institution. PCI DSS (Payment Card Industry Data Security Standard): This standard applies to companies of any size that accept credit card payments. If your company intends to accept card payment, and store, process, and transmit cardholder data, you need to host your data securely with a PCI-compliant hosting provider.
42 Åke Freij PSD2 (the Second Payment Services Directive): A major change to the payment services industry that will drive requirements for (so-called) open APIs where account data can be accessed, and also better control over levels of fees included in products and solutions. Solvency 2: A major regulatory change to the insurance industry. The EU regulation consists of three pillars. The first contains demands on capital required to run the business, the second instructs the firm how to manage risk, and the third is related to processes and data to be reported to regulators. UCITS (Undertakings in Collective Investments in Tradable Securities): With focus on investment funds, this regulation increases requirements of transparency and control over management of the capital in such funds.
2 Information security in the realm of FinTech Georgios Kryparos Introduction Two of the most easily demonstrated advantages of FinTech companies comparing to traditional financial institutions, such as banks, are their focus on simplifying the customer experience of existing or new financial products and their responsiveness with regard to addressing customer needs. It is this very customer focus combined with the broad adoption of the Internet by the general public that has been the driver for their business success (International Telecommunication Union, 2016). However, for this success to be capitalized to its full potential, retention and expansion of this customer base is a key factor. Research has shown that even a mere 5 percent increase in customer retention can increase profits by 25 to 95 percent (Reichheld and Schefter, 2000). What is essential for this to be achieved is customer loyalty, and therefore trust in the company, its products, and its commitment to prioritize and safeguard these customer needs. Given how receptive customers are to experimentation today, and businesses eagerness to challenge the established status quo, it seems very possible that an innovative new concept or solution can rather easily have a positive or even enthusiastic first response from customers. Achieving such an emotional reaction to a product or service is an essential step for every business, albeit one that mainly focuses on attracting the customer. In order to retain that customer, though, loyalty and trust are needed—values built over years of consistency to a company’s vision and its ability to deliver on this vision and its promises. Most FinTech companies have not existed for 10 years, so it is self-evident in most cases that they have not reached this point yet. By trust in this case, we refer to the confidence that customers show to FinTech companies in their ability to ensure the integrity of their customers’ assets in case the customers decide to use their services. On the other hand, trust in traditional banks has been declining steadily since the financial crisis of 2008 (IBM, 2012). By trust in this case, we refer to the confidence the bank customers have to their banks that they have their customers’ best interest as a priority. There are obviously different types of trust. In this chapter, we will focus on the first type since this is what FinTech companies currently miss, and this is what prevents most of these customers from fully abandoning the traditional financial institutions, no matter how dissatisfied they might be with them.
44 Georgios Kryparos With the exception of the Asian markets due to their different social and political circumstances, even customers who are considered as fully embracing digitalization have a hard time completely disengaging from their relationship with traditional financial institutions—banks and such (KPMG, 2016). One aspect of this trust is the assurance that customers require for their financial assets to always remain both secure and private. Customers do not want their personal and financial data to leak into the public domain, be abused by different threat actors, or, even worse, get lost. Historically, the business domain that has been dealing with these issues is information security. As defined by ISO 27001 (ISO and IEC, 2013), “the purpose of information security is to protect and preserve the confidentiality, integrity, and availability of information.” In other words, this means that information must remain secret and unaltered by unauthorized parties, and that it must be available to those who need to consume it at all times, though this is easier said than done in the current hyperconnected society, where almost anything is accessible via the keyboard and screen of a computer without the restrictions of physical access. Even though customers cannot always translate their desire for security and privacy into specific information security requirements, they can always verbalize their desire to know that the company they entrust their data with is trustworthy and safe from attackers. So even if customers may not be aware that what they demand is better security for their data by the FinTech companies, they are well aware that they demand trust. Therefore, any FinTech that prides itself in being customer-focused needs to have the ability to translate these demands into concrete technical and organizational security assurance requirements. Current state of affairs After the Snowden revelations in 2013, information security has become a topic of increasing interest and importance (Greenwald, MacAskill, and Poitras, 2013). The extensive coverage that security incidents and breaches receive in online and offline media, and the consequences of these events, have turned information security into one of the top business priorities, especially for companies in the financial sector (Newman, 2016a; Perez, 2016). This has been a growing trend in the past few years, and 2016 has been no exception, most recently with the allegations of the 2016 US elections having been influenced by illegal hacking. New stories of large-scale attacks and high-profile breaches of computer networks and systems surged during 2016 on a monthly basis, revealing the compromise of sensitive customer and corporate information by unauthorized parties, resulting in direct and indirect financial losses of millions of dollars for the corporations involved. The frequency of such events has increased comparing to previous years, but it is not the increase that is the most noteworthy event of 2016 (PwC, 2016). What changed during 2016 is the scale of these network attacks and the medium that was used to deliver them. The most prominent example is the attack against the personal website of technology journalist Brian Krebs on September 20, 2016 (Krebs, 2016c). One single
Information security in the realm of FinTech 45 individual, going by the nickname “Anna-senpai,” initiated and executed the largest distributed denial of service (DDoS) cyberattack seen to date (Krebs, 2016d). A Denial of Service (DoS) attack is a type of cyberattack where the attacker or attackers manage to render a computer machine or network unavailable due to an overload of its computing resources. This is usually achieved by “flooding” the target with an excessive amount of network connection requests. When such an overload occurs, legitimate user requests cannot be “served” by the machine or the network, rendering the service unavailable. A DDoS attack is based on the same concept, with the difference that the source of the excessive and illegitimate requests is not a single attack launch point, but multiple, controlled by the attacker or attackers (hence “distributed”). The reason Krebs became the target of such an attack was that he had recently exposed criminals who were offering such attacks as a service to their illegal clientele (Krebs, 2016b; see also Krebs 2016a, 2016c). What made this attack exceptional and particularly interesting were two things. First of all, the “launch points” were not hacked servers on the Internet or even personal computers of unsuspecting customers who clicked on an email link or mistakenly installed a malicious program, as is usually the case in these types of scenarios. Anna-senpai succeeded in this attack by taking control of possibly hundreds of thousands of misconfigured Internet-connected devices such as IP cameras, home routers, digital video recorders, or even baby monitors—the ones that anyone can buy and install in their home (Krebs, 2016d). These devices are nowadays commonly referred to as the Internet of Things (IoT). The misconfiguration was the simple fact that these devices had default passwords for their remote administration that their owners had not changed, and therefore allowed access to the computing resources of these devices to anyone on the Internet. The sophistication of this attack method is quite low and definitely not requiring advanced skills to exploit. At the same time, the capabilities required by these devices are absolutely minimal. All they need to be able to do is transmit very little network traffic toward their target—the equivalent of much less than what is required to download a very poor-quality image from the Internet via a web browser. Despite the simplicity of the attack method, it is actually difficult to defend against it since the only way to mitigate this risk is for all the different users who own such devices to actively change their passwords. Unfortunately, the reality is that most people who buy such devices are not aware that there are such features and definitely cannot imagine or even know that their devices are used as part of an illegal network of attacking devices used against different targets upon request of an attacker, commonly referred to as botnets. This specific botnet became known as the “Mirai botnet,” named after a Japanese manga TV series (The Future Diary, 2010). The second interesting point with this attack was the fact that a few days after, either in fear of being discovered or for whatever other unknown reasons, the attacker decided to publish the tools that were used on the Internet, making it possible for anyone to download, adapt, and use them (Krebs, 2016d). Consequently, anyone now has the power to control and command an “army” of unprotected IoT devices without necessarily having the technical skills that are usually required.
46 Georgios Kryparos The motivation for Anna-senpai is that the noise generated by multiple people possibly performing such attacks can help him/her remain undetected during the current and future investigations. But how is this relevant for FinTechs? How can a few baby monitors affect the financial industry? This question can be addressed if we imagine that an “army” of devices and the associated attackers who hide behind them were not interested only in simply taking revenge against a single individual. What if instead they were collectively and in an automated fashion exploiting software vulnerabilities of payment systems, causing money to change hands or get lost in the process? What if every baby monitor was shifting a few cents of payment transactions to different bank accounts, and doing that constantly in a way that remains undetected by fraud monitoring systems? Such an attack would probably stay under the radar of detection, it would happen extremely fast due to its scale, and it would also be impossible to stop due to its geographically distributed nature, without blocking all transactions or even closing down the FinTech service until the problem is resolved. This is not a concern only for companies in the financial sector. All industry sectors can be affected by the same type of attacks if adopted to the business context of every industry. It is understandable, though, that an attacker has a higher incentive to focus his/her energy on targets on the financial sector. According to the 2017 Verizon Data Breach Investigations Report (DBIR), the industry with the most security data breaches during 2016 has been that of the financial services (471 breaches), even though it was not the industry with the highest number of security incidents (998 incidents) (Verizon, 2017). This shows that the attacks against financial services are more organized, and therefore more successful (circa 47 percent success rate). As a comparison, companies in the public sector seemed to have been the primary target during 2016, with 21,239 incidents but only 239 confirmed breaches (circa 1 percent success rate). The entertainment industry had the second biggest number of incidents (5,534), but with only 11 confirmed breaches (circa 0.2 percent success rate). These statistics show that when there is money to be gained, there is always a higher incentive. The traditional solution to software vulnerabilities of financial systems was to limit access to the potentially vulnerable systems in the first place. The easiest way to defend a system is to make it unreachable for the attacker. A lot of established financial institutions relied on creating isolated silos where these business-sensitive systems would be available only to a very small number of employees. These employees would either execute transactions on behalf of customers or perform other types of maintenance and administration activities by using proprietary technology in most cases, reassuring the security of the system by the secrecy surrounding the technology used. This approach is often referred to among the circle of information security specialists as “security through obscurity”; instead of ensuring the security of a system based on the defending technical controls, its monitoring procedures and the appropriate access policies, companies relied, and in some cases still do, on the illusion of “others not knowing how the system works or where it is.”
Information security in the realm of FinTech 47 With the rise of the Internet and the recent usage explosion of open network protocols and web technologies, this is not feasible anymore. FinTechs have correctly embraced the principles of “always on” and “open standards design,” and in their case this old-fashioned mentality of silos and technological secrecy is simply not an option. Services and products always have to be available, they have to be on the Internet because this is where their customers are, but at the same time they have to be resilient and secure by design, expecting and assuming that anyone who can use them can also abuse them. The concept of trust therefore reappears, but in this case on the customer side. Just because someone can reach a service or a website, it does not mean that this person can be trusted at face value. His/her access rights have to be assessed by the service and granted only if their validity is proven. Traditional institutions have understood this business requirement, but they are facing a philosophy transition where they need to embrace a new way of working and at the same time retain the same level of assurance. Unfortunately, in many cases, they do not know how to reach that compromise, either by being too conservative or by being too optimistic that things will be as safe in the new way of working, simply because they have been safe for them in the past. FinTechs, on the other hand, have learned to live with these risky realities of “always on” and potentially “always under attack.” This reality makes them by definition more vulnerable, but without necessarily making them less or more secure. It is true, though, that by doing so, they have acquired the ability to adapt faster to a changing landscape where in many cases they are not in full control. The question is not who has been in the past or is currently more secure, FinTechs or the traditional banks. The question is who will be more secure in the financial landscape that is being shaped now with the penetration of new technologies and the rise of customer demands. And the solution now is not to hide; the solution is to be highly available and highly responsive, but at the same time highly secure, in order to also be highly successful. Drivers Different business functions are concerned about different business risks. Information security is concerned with the way the information of a company and its customers is safeguarded from misuse or abuse, and the risks that the company is willing to take while dealing with this information. Information security helps businesses make informed and risk-based decisions as early as possible, and this is the reason why it is important for the business sustainability of any company, and even more for financial institutions. Some arguments have already been briefly discussed about why this will become even more crucial in the coming years, but in this section we will further explore the business needs and market expectations that drive investments in information security. First of all, the main driver for implementing information security tools and processes in FinTechs is the ever-increasing need for trust, both from the customer and the company’s perspective. Due to the very nature of the business, customers require a very high level of assurance in knowing that their personal
48 Georgios Kryparos and financial information is safeguarded at all times. A potential leak or unintentional change in their accounts will harm the company’s reputation not only in the eyes of the affected customers, but also the prospect ones. There is no point for a customer to use a financial service that might be innovative and easy to use if he/ she cannot trust the outcome of their financial transactions and the potential monetary loss. At the same time, the FinTech company needs to be able to trust that the customer intentionally used its services in the intended way without impersonating someone else or denying that he/she executed a certain transaction. The need for integrity of the transactions, privacy of the customer’s personal and financial information, and traceability of every performed action is of vital importance. These requirements can only be fulfilled with the use of information security processes such as access control, encryption, and authentication, just to name a few. A lot of these requirements usually stem from the need for legal compliance. Demonstration of compliance to the requirements of regulatory bodies has always been an issue of great concern for financial institutions. The risk of losing the business right to operate in the regulated environment of financial services often creates uncertainty, fear, and discomfort to business owners. Information security is used as the tool to bridge the gaps between how business operates and what the regulatory authorities require from them. During 2017 and 2018, one of the main focus areas for all businesses operating in the financial services realm within the European Union, FinTechs or not, will be to implement the requirements imposed on them by new regulations such as the Second Payment Services Directive (PSD2) (European Commission, 2007) and the General Data Protection Regulation (GDPR) (European Commission, 2016). Both regulations have a strong focus on protecting customers within the EU and helping them safeguard and even take control of their data. The technicalities of how this is done from the financial services side (with requirements such as the one for strong user authentication and open but secure communication between companies) falls very much under the domain of information security. Especially for FinTechs, security expertise will be key in order to implement these requirements in a scalable way that the business fulfills its regulatory obligations and at the same time strengthens its security posture without making the wrong investments and stifling innovation. If done correctly and promptly, these obligations might very well turn into a competitive advantage for many FinTechs. One of the reasons why the regulations, and especially GDPR, are of particular concern is because the penalties in case of a security breach will be dramatically increased. In case of customer data being leaked or having their privacy violated, the fines for the involved company will be up to 4 percent of its annual global turnover or EUR 20 million, whichever is greater. By many, this requirement alone is considered a game changer that will prompt a lot of businesses to pay much closer attention to how they design and implement their internal processes and tools so that the customer’s security and privacy are always assured. Costs can be imposed not only as a result of noncompliance to laws and regulations, but also as a result of a security attack against a company’s infrastructure. In case of a security incident during which a threat actor compromises the system
Information security in the realm of FinTech 49 and starts manipulating its information, the impact of taking this system offline for any FinTech will be potentially damaging not only to the reputation and brand of the company, but also to its revenue. For a FinTech company, being always online and offering its services 24/7 is the very reason for its existence. In this sense, the availability of the service is directly correlated to the revenue of its business. On the other hand, and in case of such an incident, keeping the system online might also not be the best course of action either. If the attack is focused on stealing information or even money, the longer it goes on, the greater the monetary loss for the business. Therefore, a decision to keep the system running during a security breach might generate more cost than profit. It is easy to argue about these direct costs, but what is often overseen are the indirect costs. As outlined in the 2016 Verizon DBIR, the majority of money spent during and after a security breach is for legal guidance and forensics investigations (Verizon, 2016). Not to mention the brand reputation damage and the potential loss of customer base. The obvious solution is never getting in that situation in the first place, and this is where information security helps. Nevertheless, no matter how strong, strict, and enforcing your security program is, you cannot mitigate all risks from all possible threats, but what information security can and should cater for is the speed in which a risk is remediated, and business returns to being fully operational. The motivations for a cyberattack can be numerous and diverse: profit, reputation damage, industrial espionage, cyberterrorism or simple cyberbullying (Verizon, 2016). The threat actors can be equally diverse. As mentioned earlier, the wide adoption of the Internet and its democratization created the conditions where every person in the world, regardless of their economic situation, geographical location, and social status, has access to the nearly unlimited resources of the Internet and the companies that conduct business over it. The benefits of this democratization are obviously vast, but one cannot forget the challenges that come along with the created opportunities. Every person has the right to access, but not every person conducts him/herself under the legal boundaries that the current legal frameworks provide. This makes tracing and identifying the source of a cyberattack a technically difficult problem to solve, especially if the right investment in security monitoring, incident management, and forensic investigations has not been made. The democratization of technology and its advancements have contributed to an ever-growing number of new business ventures and at the same time of consumer demands. These demands dramatically impact the need for businesses to continuously innovate and do it at a pace that the competition is outrun. “Time to market” is the number-one requirement for most businesses, including those in the FinTech world (Kahn, 2005). A product or service has to be innovative, useful, and solve a real-world problem, but it also has to be launched onto the market as fast as possible, before any other competitors capitalize on being first in solving that problem. In any aspect of our life, when trying to go fast, there is always the risk of an “accident,” and this is true for business as well. Going fast is important, but too fast might actually lead to the opposite results, especially when considering that this usually means “cutting corners.” Cutting corners on any feature has
56 Georgios Kryparos misconfiguration of other supporting components. Furthermore, even if most of the abuse cases can be identified, performing the tests usually requires specialized tools, trained security professionals, and a significant amount of time due to the numerous combinations of tests that need to be performed before ensuring that the product does not work in a way that it was not designed for. As Albert Einstein once said, “No amount of experimentation can ever prove me right; a single experiment can prove me wrong” (Calaprice and Einstein, 2005, p.291). For these reasons, companies avoid security testing, or perform the absolute minimum required by authorities for compliance reasons, though the value that security testing offers is underestimated. The first step for a security tester to successfully identify abuse cases is to know how the product works, which means that functional testing is also included, even if not explicitly mentioned. This also implies that some documentation or design description is also given as part of the initial discussion. While doing so, it is not uncommon for the product owners and software developers to identify problems themselves simply as part of the need to describe their product to someone external. This documentation work is therefore adding value by itself. Finally, security testing prevents identifying problems at a later time, saving valuable time and money. Research has shown that the cost of fixing a software deficiency early in the development phase, or at least during testing, is significantly less than fixing it after it has been released to the public (Morana, 2006; Grossman, 2009; Cornell, 2012). The cost savings are even greater if one considers the possibility of this security deficiency becoming a security incident—monetary loss, branding damage, incident handling costs, operational costs, disaster recovery costs, etc. Solutions Every business faces challenges daily. It is the response to these challenges that defines their success or failure. The challenges are always greater when never faced before, having no predetermined path of how to deal with them. This is the situation that most FinTechs find themselves today. By breaking ground in business and technology, FinTechs end up having to deal with problems that are not common and require creative thinking in order to find solutions. In this chapter, we will look into ways of dealing with the challenges mentioned previously, and propose solutions that usually address more than one of them at a time, given that most of the challenges are tightly coupled. The most important thing that any startup should keep in mind regarding information security is that it is not an add-on; it is not a patch that can be applied when something goes wrong. If there is one thing that will contribute the most to FinTechs’ security, it is to adapt a company culture that includes information security at its core. Processes, documentation, and tools are important, but nothing beats a company culture that understands the risks and works in a proactive and systematic way toward addressing them. First, both employees and executives have to be aware of the risks and threats that exist and have a mindset that takes security into consideration every step of the way. Considering the risk
Information security in the realm of FinTech 57 scenarios while building a system or creating a business partnership will increase the chances for success of such a system or partnership, instead of doing so as an afterthought. For example, a development team should not wait for the security personnel to intervene at the end of the development life cycle to test the final product; they should consider the most frequent abuse cases while building the product, and prevent it from being built in an insecure way, or at least take an informed decision that has the support of the business if an introduced feature will knowingly increase the security risk exposure. Moreover, an executive should always consider the regulatory and security requirements that might need to be considered while signing a business partnership, in order to avoid putting customer data at risk. Usually, a security culture such as this is fostered only after a severe security incident has taken place and the importance of security is vividly demonstrated to all involved parties (Associated Press, 2014). However, the remaining question is why companies should have to wait until an incident such as that takes place. In many cases, this might be the last incident they will ever have to deal with, as the impact can be disastrous for the company’s reputation and even existence. Security culture is usually built not with the purchase of tools and systems. It is built by people who can be trusted promoting and applying this mindset in daily business tasks without becoming blockers, but rather educators. This can be achieved either with awareness and hands-on training or documentation regarding the accepted policies, instructions, and guidelines, or both. There is no right or wrong. Every company will have to choose their preferred method. Both can be done correctly and both can be done wrongly. This is why having security personnel and top-level management with a direct understanding, interest, and responsibility in security is of key importance. The second recommended solution is having a high level of preparedness for security incidents. The maturity and responsiveness of an organization to such an event defines its potential to handle it successfully and remediate it correctly, efficiently, and with the least possible impact. FinTechs, like all companies, must learn to respond to an incident, not react. This is easier said than done when the human factor is involved. Different people react differently in moments of stress, depending on their character, emotional status, or knowledge of the subject. The solution to this is to have a well-communicated and rehearsed incident response plan. An incident plan helps in different types of incidents, but there are some things that are particular with security incidents which may require more careful handling due to the sensitivity of the situation; for example, someone might need to involve the authorities or make sure to collect forensic evidence before informing the involved parties. This is why the presence of people trained in such operational tasks is important, but most important of all is the ability for upper management to correctly weigh the criticality of incidents without downplaying their significance, be open about them to the organization when possible, and communicate correctly without ever creating an environment where scapegoats are sought. People make mistakes and systems sometimes fail. This is the reality in the world of technology, and what needs to be done is to learn to adapt to it instead of trying to eliminate it completely, as this is simply impossible.
58 Georgios Kryparos In order to be able to respond to incidents and at the same time be able to demonstrate compliance toward nearly any regulatory standards, monitoring is of vital importance. If you do not know what happens in your company, your networks, your systems, and your assets, it would be impossible to detect an incident. Not knowing what is happening at any given moment in your company, even if nothing bad happens, is worse than something bad actually happening while monitoring the situation. Monitoring is essential but it has to be done correctly. It should not violate in any way the privacy and integrity of the employees or the customers. Any collected information should be accessible only by those on a need-to-know basis, and this information should, if possible, be anonymized. Monitoring systems should be centralized, receiving data from as many collecting points as possible and maintained by dedicated personnel so that important events can raise alarms when needed and not get lost in the “noise” of excessive information. Monitoring is arguably even more important than prevention (Hanson et al., 2015). FinTechs can accept the risk of allowing risky behavior in their products, systems, or networks, but in this case they must have good compensating monitoring processes that allow them to respond accurately and fast when something happens, instead of blocking every possible risk just in case something happens. This might be more expensive since it requires a high level of automation and competence in dedicated personnel, but it might be worth the price that a company needs to pay in order to allow experimentation and exploration of different technologies, without being blockers of human behavior. Freedom might eventually boost productivity and also creativity, but of course it always has to be combined with accountability and a sense of responsibility. As noted earlier, awareness and the presence of a strong security culture is of strategic importance. The discussion about monitoring brings to light the issue of automation. In modern agile environments, this is absolutely critical. Automation is encouraged and sought after in every part of agile development, and it should therefore also be adopted when it comes to security processes. Speed and continuous delivery of new software, features, and products is the raison d’être of agile development, and information security cannot become the inhibitor to it. For this reason, autogenerated security alarms, automated and closely embedded security testing as part of the development life cycle, and continuous security auditing of access to systems are some of the procedures and tools that FinTechs could employ in order to be able to handle information security in an effective and efficient manner without needing to continuously scale up their security personnel as time progresses. More transactions, more software, more systems, and more employees should not necessarily lead to a proportional increase of security personnel. One more benefit to point out here is that the existence of automated and continuous testing as part of the delivery pipeline of software can dramatically reduce or eliminate both the time needed for security testing before the launch of a product as well as the unintentional and unknown exposure to security risks after its launch (Humble and Farley, 2010).
Information security in the realm of FinTech 59 Finally, a subject of high sensitivity among security professionals is that of access. Who can access what data and from where? Where do we set up the perimeter? For decades, people have been relying on the physical barriers of systems—on locked rooms, secure buildings with tall walls and cameras, etc. All these measures are still relevant, but more so for data center hosting facilities and top secret government agencies, not so much for FinTech companies. The expansion of cloud services, the outsourcing to server hosting providers, and the need for employee mobility have made the need for a network perimeter almost irrelevant. What is more important instead is a more granular level of access control, where each employee gets access to the services and information needed to perform his/her work tasks based on the job function that person serves, and not the geographical location or the type of device that access is requested from. Access should be given based on an employee’s identity and current job function, and not based on which system that person has been granted access in the past (who they know and under which branch of the organizational chart they belong). Access should be granted on a need-to-know basis, it should be time-limited, and preferably transparent. These requirements are technically possible, but do require some more upfront investment in order to ensure secure and at the same time simple access to the information needed. What also needs to be considered are the benefits in terms of administration of granting and revoking access, boosting productivity, and reducing friction and annoyance from the employee’s side. 2018 trends Up to this point, we focused our attention on existing problems and existing solutions. In a fast-moving world, though, this is not enough. In order to advance and evolve, one must always look ahead and try to anticipate what lies ahead. Change is inevitable, and one must prepare for it instead of worrying about it. The best tools for someone to use so that the anticipation does not lead to unpleasant and unexpected surprises are the facts of the present and the experiences of the past. The information security challenges that the FinTech industry has been experiencing until today, and the solutions that have been implemented up to now, can give signs of where things might be going. So when one wishes to understand what the future might be holding for FinTech companies during 2018, there is no need for a crystal ball. The facts of the present, if interpreted correctly, can lead to safe estimations. The order in which the suggested trends are presented in this chapter are not indicative of their priority or importance. It is expected that 2018 will be the year influenced the most by regulations. PSD2 and GDPR will have an indisputable impact on FinTechs for better or worse. Regardless of their objective, whether it is to better protect customers’ data and privacy, or to foster innovation and competition among payments, they impose stricter security and privacy requirements toward FinTech companies. Most requirements under the scope of information security are for the best, but that does not mean that some of them might not be possible to be challenged either in the political arena or by introducing innovative solutions that
60 Georgios Kryparos take advantage of the frequent ambiguity and non-descriptive nature of the law. What is to be expected, though, is a drive toward multi-factor authentication for customer-facing applications, the need for an established and structured information security framework inside FinTechs, and finally the enforcement of better data protection mechanisms, even inside the virtual network boundaries of a company, for example with the use of encryption or more granular access control to data. Information security improvements might also take place as a matter of competition between FinTechs and traditional financial institutions. Under the scope of PSD2, financial service providers are expected to cooperate so that they can exchange data for the benefit of their customers. The issue of trust will become relevant, and how financial service providers can better safeguard these data. For example, if the originating party A needs to make its data available to the receiving party B, then it is in the best interest of A to demonstrate that it uses secure technologies to sufficiently verify the identity of B, so that it protects these data before they are accessed, as well as to make sure that their transmission is secure. On the other hand, B will probably want to demonstrate compliance with the new regulations and market itself to the customers of A as a secure and trustworthy alternative. Given that FinTechs get deeper and deeper into the most technically challenging products of traditional financial services, some of the traditional regulatory requirements such as those of bank secrecy, “know your customer” (KYC) and “anti-money laundering” (AML) will become more relevant for them. FinTechs have always focused their business models by being available only in the digital world for reasons of cost-efficiency, accessibility, and convenience (European Commission, 2015). One of the best features of the Internet from a customer perspective, but not from a business perspective, is the anonymity it offers, despite the recent technological advancements against it, as well as the different scandals that concern state-sponsored surveillance activities of citizens around the world. Anonymity makes the job of FinTechs to fulfill their legal obligations for KYC and AML harder. One solution would be to take the step that banks have been following for years: a customer must first go to a local bank branch, prove his/her identity by showing some sort of legal document identification, and then get access to the financial services offered by the bank. But this would decrease FinTechs’ competitive advantages of cost-efficiency, customer convenience, and speed. The solution might come from two different sides: either from the side of the corporate world, where online identification technologies might innovate the way a customer can prove his/her real identity without leaving the convenience of his/ her computer, or from the side of the national governments stepping in and granting virtual identity credentials that could be used by a variety of online services, including financial ones. Examples of the first option could be online document scanning or biometric identification technologies with the help of artificial intelligence and machine learning. Examples of the second option could be the issuing of an electronic national identity, such as the one promoted by the eIDAS regulations of the European Union (European Commission, 2014), or the equivalent of a financial identity issued by consortiums of banks, such as the BankID initiative in
Information security in the realm of FinTech 61 Sweden (BankID, 2003). Such eID solutions will obviously increase the level of trust toward the customer, making it possible for FinTechs to offer more advanced services with less risk. In this case, secure identification, which is a vital part of the information security domain, becomes the business enabler and the competitive advantage for a company that decides to implement it. Initiatives such as the eIDAS might bring an end to the potentially insecure, untrustworthy, and errorprone process of account sign-ups with a username and password. Driven by regulations again, it is very possible that 2018 will bring the proliferation of cybersecurity insurances (The Economist, 2014). GDPR, for example, introduces much higher fees toward financial institutions in case of a security breach; a business may be held liable for up to EUR 20 million or 4 percent of their global turnover. In most cases, such a breach, and therefore the associated fee, will have a great financial impact on the affected FinTech company. The mitigation measures for the company are either to increase the level of their information security posture or purchase a cybersecurity insurance, which might help cover the costs in such a scenario. One, of course, does not exclude the other, and it is up to the FinTechs to evaluate which option best fits their needs and establish a business continuity plan. What one needs to be aware of and careful with in terms of cybersecurity insurances is the same as with any type of insurances. The contractual details might have conditions that imply either a very limited liability or a requirement for an already tightened information security posture. Undoubtedly, though, there are business opportunities in the insurance sector to cooperate and find synergies with the finance sector, even more than before. Finally, any 2018 prediction would be incomplete if we did not take into consideration the big story of 2016 and 2017: IoT devices. The DDoS attack against Brian Krebs on September 2016 revealed the explosion of IoT devices in the world and how they can easily be abused to launch attacks. The Mirai botnet was not the first of its kind, but it was the first where its author published the software’s source code publicly for anyone to copy, edit, and improve (US-CERT, 2016). It is therefore very probable to come across clones of the Mirai botnet. We have actually already seen the same or similar vulnerable devices being used to mine bitcoins, attack critical national infrastructure, become money mules, so why not target FinTechs for financial profit (Newman, 2016b)? Not all FinTechs have the same level of information security posture as banks do, but they might have the same type of wealth. Therefore, they qualify themselves as a very lucrative target for an attacker. Monetization of IoT attacks should consequently come as no surprise to anyone in the near future. Every random or opaque software vulnerability, which would normally attract limited attention, should be evaluated from a different risk exposure perspective. Summary FinTechs are building and launching a wide range of new products that significantly improve the customer experience, accessibility, and reach of financial services by leveraging the capabilities of modern technology. This brings progress in a
62 Georgios Kryparos conservative sector dominated for years by a very small, closed group of individuals and companies, and thus democratizes the financial services to the benefit of the end customer. The future looks bright for FinTechs, but one of the few potential threats to this aggressive expansion is neglecting the importance of information security. The technological benefits and the road to progress usually outweigh the security risks, but right now FinTech companies are in a position where they can make informed decisions and find the right balance between speed and security. They cannot afford to ignore that opportunity since the impact can be detrimental to those who choose to do so. Threats cannot be controlled; they will always be there, lurking for a window of opportunity. Risks, on the other hand, can be managed, and in the case of software vulnerabilities of FinTech services, they can also be treated. The difficulty in this is to find the right balance between the possibility of such threats becoming tangible risks, and the cost and complexity that the mitigating solutions might potentially generate. The answer can usually be found by bringing together the technology, the people, and the processes so that all aspects of a problem can be considered when seeking solutions. It is important for FinTech companies to embrace a risk-based approach where the identified risks are not understated or remain unhandled. It is also equally important for information security professionals to stop relying on scare tactics, and instead provide concrete advice to businesses by finding smart, or at least smarter than before, solutions. Continuous monitoring and testing with the use of automation, a security culture of inclusiveness without blaming or shaming, a tested plan of business continuity, and technologies that embrace and adapt to a more decentralized IT environment can be tools that empower that change. Information security professionals should not be there to fulfill a compliance requirement or to simply be assigned the responsibility for information security. Information security is after all the responsibility of everyone in any company, and information security professionals should eventually be there so that a company will never really need to use them. Conclusively, not every risk can be prevented, and for every such risk there is always an exposure window that cannot be avoided. What matters the most is how fast and successfully we work in decreasing that window and remediating the risk by simultaneously improving the security of the company and the product itself. Ensuring that any implemented defenses work in accordance with the business needs of agility and speed, and not hamper innovation or creativity by becoming blockers or “speed bumps,” is of essence here. This is where information security can become the differentiating factor, and even the competitive advantage for a FinTech, by helping to build trust toward its customers and partners. Bibliography Associated Press, 2014. Companies tightening up data security after Sony Pictures hack. [online] Gadgets 360. Available at: http://gadgets.ndtv.com/internet/news/companiestightening-up-data-security-after-sony-pictures-hack-636877 [Accessed August 27, 2017].
Information security in the realm of FinTech 63 BankID, 2003. This is BankID. [online] Available at: www.bankid.com/en/om-bankid/ detta-ar-bankid [Accessed August 27, 2017]. Beck, K., Beedle, M., van Bennekum, A., Cockburn, A., Cunningham, W., Fowler, M., et al., 2001. Manifesto for agile software development. [online] Available at: http:// agilemanifesto.org/ [Accessed August 27, 2017]. Butler, S., 2014. Scammers pose as company execs in wire transfer spam campaign. [online] Symantec Official Blog. Available at: www.symantec.com/connect/blogs/scammerspose-company-execs-wire-transfer-spam-campaign [Accessed August 27, 2017]. Calaprice, A. and Einstein, A., 2005. The new quotable Einstein. Princeton, NJ: Princeton University Press. Cornell, D., 2012. Remediation statistics: What does fixing application vulnerabilities cost? [online] RSA Conference 2012. Available at: www.rsaconference.com/writable/ presentations/file_upload/asec-302.pdf [Accessed August 27, 2017]. European Commission, 2007. Directive 2007/64/EC of the European Parliament and the Council. [online] Available at: https://ec.europa.eu/info/business-economy-euro/ banking-and-finance/consumer-finance-and-payments/payment-services_en [Accessed August 27, 2017]. European Commission, 2014. Regulation (EU) No 910/2014 of the European Parliament and of the Council. Official Journal of the European Union. [online] Available at: http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32014R0910&fr om=EN [Accessed August 27, 2017]. European Commission, 2015. Directive (EU) 2015/849 of the European Parliament and of the Council. Official Journal of the European Union. [online] Available at: http:// eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:JOL_2015_141_R_0003&fro m=EN [Accessed August 27, 2017]. European Commission, 2016. European Commission – press release – capital markets union: Commission supports crowdfunding as alternative source of finance for Europe’s start-ups. [online] Available at: http://europa.eu/rapid/press-release_IP-16- 1647_en.htm [Accessed August 25, 2017]. Greenwald, G., MacAskill, E., and Poitras, L., 2013. Edward Snowden: the whistleblower behind the NSA surveillance revelations. The Guardian, [online] p.1. Available at: www.theguardian.com/world/2013/jun/09/edward-snowden-nsa-whistleblower- surveillance [Accessed August 23, 2017]. Grossman, J., 2009. Mythbusting: Secure code is less expensive to develop. [online] Jeremiah Grossman Blog. Available at: http://blog.jeremiahgrossman.com/2009/05/ mythbusting-secure-code-is-less.htm [Accessed August 27, 2017]. Hackett, R., 2015. What to know about the Ashley Madison hack. Fortune. [online] Available at: http://fortune.com/2015/08/26/ashley-madison-hack/ [Accessed August 27, 2017]. Hanson, M., Johansson, T., Lindgren, C., and Oehme, R., 2015. Information security – trends 2015: A Swedish perspective. [online] Stockholm: Myndigheten för samhällsskydd och beredskap (MSB) [Swedish Civil Contingencies Agency]. Available at: www.msb.se/ RibData/Filer/pdf/27584.pdf [Accessed August 27, 2017]. Humble, J. and Farley, D., 2010. Continuous delivery: Reliable software releases through build, test, and deployment automation. Upper Saddle River, NJ: Addison-Wesley Professional. IBM, 2012. Rebuilding customer trust in retail banking. [online] IBM Financial Sector: Thought Leadership White Paper. Available at: www-935.ibm.com/services/multimedia/ IBM1049_Trust_White_Paper_05.pdf [Accessed August 27, 2017].
64 Georgios Kryparos International Telecommunication Union, 2016. Measuring the Information Society Report. [online] Geneva: ITU. Available at: www.itu.int/en/ITU-D/Statistics/Documents/ publications/misr2016/MISR2016-w4.pdf [Accessed August 27, 2017]. ISO and IEC, 2013. ISO/IEC 27001:2013, information technology – security techniques – information security management systems – requirements. [online] Geneva: ISO and IEC. Available at: www.iso.org/standard/54534.html [Accessed August 27, 2017]. Kahn, K.B., 2005. Approaches to new product forecasting. In: K.B. Kahn, G. Castellion, and A. Griffin, eds.The PDMA handbook of new product development. 2nd ed. Chichester: Wiley, pp.173–187. KPMG, 2016. The pulse of FinTech, Q3 2016: Global analysis of FinTech venture funding. [online] KPMG Insights. Available at: https://home.kpmg.com/xx/en/home/ insights/2016/03/the-pulse-of-fintech-q1-2016.html [Accessed August 27, 2017]. Krebs, B., 2016a. DDoS mitigation firm has history of hijacks. [online] Krebs on Security. Available at: https://krebsonsecurity.com/2016/09/ddos-mitigation-firm-has-history- of-hijacks/ [Accessed August 27, 2017]. Krebs, B., 2016b. FBI: $2.3 billion lost to CEO email scams. [online] Krebs on Security. Available at: https://krebsonsecurity.com/2016/04/fbi-2-3-billion-lost-to-ceo-email- scams/ [Accessed August 27, 2017]. Krebs, B., 2016c. KrebsOnSecurity hit with record DDoS. [online] Krebs on Security. Available at: https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with-record- ddos/ [Accessed August 27, 2017]. Krebs, B., 2016d. Source code for IoT botnet “Mirai.” [online] Krebs on Security. Available at: https://krebsonsecurity.com/2016/10/source-code-for-iot-botnet-mirai- released/ [Accessed August 27, 2017]. Morana, M.M., 2006. Building security into the software life cycle: A business case. [online] Black Hat, USA. Available at: www.blackhat.com/presentations/bh-usa-06/ bh-us-06-Morana-R3.0.pdf [Accessed August 27, 2017]. Newman, L.H., 2016a. Hack brief: Hackers breach a billion Yahoo accounts. A billion. Wired, [online] December 14. Available at: www.wired.com/2016/12/yahoo-hack- billion-users [Accessed August 27, 2017]. Newman, L.H., 2016b. The botnet that broke the Internet isn’t going away. Wired, [online] December 9. Available at: www.wired.com/2016/12/botnet-broke-internet-isnt-going- away [Accessed August 27, 2017]. Perez, S., 2016. 117 million LinkedIn emails and passwords from a 2012 hack just got posted online. [online] TechCrunch. Available at: https://techcrunch.com/2016/05/18/117- million-linkedin-emails-and-passwords-from-a-2012-hack-just-got-posted-online [Accessed August 27, 2017]. PwC, 2016. Toward new possibilities in threat management: How businesses are embracing a modern approach to threat management and information sharing. [online] The Global State of Information Security Survey 2017. Available at: www.pwc.com/gsiss [Accessed August 27, 2017]. Reichheld, F.F. and Schefter, P., 2000. E-loyalty: your secret weapon on the web. Harvard Business Review, 78(1), pp.105–113. The Economist, 2014. Defending the digital frontier: Special report on Cyber security. The Economist. [online] Available at: www.economist.com/news/special-report/21606416- companies-markets-and-countries-are-increasingly-under-attack-cyber-criminals [Accessed August 27, 2017]. The Future Diary, 2010. Mirai Nikki. [online] Available at: www.future-diary.tv [Accessed August 27, 2017].
Information security in the realm of FinTech 65 US-CERT, 2016. Alert (TA16-288A): Heightened DDoS threat posed by Mirai and other botnets. [online] United States Computer Emergency Readiness Team. Available at: www.us-cert.gov/ncas/alerts/TA16-288A [Accessed August 27, 2017]. Verizon, 2016. 2016 Data Breach Investigations Report: 89% of breaches had a financial or espionage motive. [online] Available at: www.verizonenterprise.com/resources/ reports/rp_DBIR_2016_Report_en_xg.pdf [Accessed August 27, 2017]. Verizon, 2017. 2017 Data Breach Investigations Report. [online] Available at: www.veri zonenterprise.com/verizon-insights-lab/dbir/2017/ [Accessed August 27, 2017]. Walker, R., 2003. The guts of a new machine. The New York Times Magazine. [online] Available at: www.nytimes.com/2003/11/30/magazine/the-guts-of-a-new-machine.html [Accessed August 27, 2017].
72 Björn Olsson and Mattias Hallberg the world after the US, Canada, and Switzerland, respectively (Ács, Szerb, and Lloyd, 2017). If we dig deeper in the indicators that make up the index, we realize that even though we outperform most countries in the world, we have some obvious areas where we can improve. Startup skills, human capital, and high growth2 are the most important. The fact that we score below the European average on startup skills is surprising, considering our favorable position on the Global Entrepreneurship Index (Ács, Szerb, and Lloyd, 2017). The indicator is defined as the share of the able-bodied population claiming to possess the required knowledge/skills to start a business. As evidenced by the World Bank Group’s (2017) Doing Business reports, starting a business in Sweden has become significantly easier in the last decade. Today, Sweden is among the best nations in terms of ease of starting a business (see Figure 3.3). Our conclusion is that the proportion of the self-employed population needs to increase to make entrepreneurship more visible in society. Educational programs such as Ung Företagsamhet (Junior Achievement Sweden), where high school students get a hands-on experience in starting a business, should thus be expanded (Nykvist, 2017). In our experience, most people perceive employment as the chief indicating factor of job security and economic stability. In a welfare system such as Sweden, where the social safety net is built around employment and negotiated via large collective bargaining processes, self-employment and SME ownership is regarded as very risky. However, the economy is changing, and the social welfare system that most Swedes cherish and want to keep must develop to stay up to date. At various “career opportunity” theme days on campuses all over Sweden, the aim is to match students with the right employer, and the possibility of entrepreneurship is mostly overlooked (Drivhuset, 2013). This practice is effectively discouraging educational aspirations from an education policy point of view. As we can see from the above analysis, the Swedish ecosystem for entrepreneurs is 0.00 0.20 0.40 0.60 0.80 1.00 Opportunity perception Start-up skills Risk acceptance Networking Cultural Suppor t Opportunity start-up Technology absorption Human capital Competition Product innovation Process innovation High growth Internationalization Risk capital Opportunity perception1,00 Start-up skills 0,51 Risk acceptance0,75 Networking 0,74 Cultural support 0,90 Opportunity start-up 0,95 Technology absorption1,00 Human capital0,63 Competition0,83 Product innovation 0,81 Process innovation1,00 High growth 0,61 Internationalization 0,87 Risk capital0,62 Figure 3.3 Entrepreneurship score profile for Sweden
FinTech in Sweden 73 comparatively good, but we make a poor job of selling it to our own population, possibly due to our labor laws having made it too comfortable to be employed. Talent pipeline Education and academic networks The next segment is the talent pipeline. For the FinTech sector to grow, there must be effective channels to foster employees and entrepreneurs with all those talents described above. Here, the outlook is far from perfect. Today, there are no master’s programs at universities that explicitly combine the three key talents needed in FinTech. Even though there is something called the Stockholm School of Entrepreneurship, a joint project for all major HEIs in Stockholm, it cannot compete with, for instance, the Copenhagen Business School’s strong commitment to entrepreneurship, which was ranked fifth best in the world according to the Eduniversal (2017) masters ranking of 2017. Further up in the pipeline, we have problems with STEM skills in Sweden. Our position in the international PISA assessment, which measures and monitors 15-year-olds’ skills in STEM, math, and reading, has been declining for years. In 2016, Sweden was below the OECD average in STEM (OECD, 2016a). This has led to a shortage of students with the right skills to attend more advanced tech programs at universities. Foreign talent In a global world where specialization is one key aspect of success in most sectors, no country can be a completely self-sustaining ecosystem. To be able to import talent from abroad is just as important as fostering your own talents. We could even take it one step further by claiming that it is critical to mix domestic and foreign influences to achieve a creative melting pot of innovation. Since the liberalization of labor force migration policies in Sweden in 2007, the number of high-skilled laborers from outside the EU permitted residency in Sweden has increased. This is potentially a very important aspect of the Swedish regulatory landscape. The most common position among the high-skill labor migrants is computer scientist (Swedish Migration Agency, 2017). At a time when right-wing populism and neo-nationalism is on the rise in most Western countries, it is more important than ever to keep our liberal system for labor migration. However, after the refugee crisis that befell Sweden in the fall of 2015, multiple tech companies have complained that the migration agency has become stricter in its application of the law and that the waiting time has been prolonged (Wisterberg, 2016). When it comes to international mobility, it is safe to say that Sweden probably is a net contributor of talent in all the three key areas. Sweden struggles to attract enough young people with high potential and large aspirations. An eye-opener for this development was an open letter written by the Spotify co-founders Daniel Ek and Martin Lorentzon in the spring of 2016. They warned that they would have
74 Björn Olsson and Mattias Hallberg no choice but to quit Sweden if politicians did not act to address the Stockholm housing shortage, the limitations of the education system, and tax laws. As they wrote in the letter: Today we have employees from 48 countries working in Stockholm. To demand that young people coming to a new country immediately buy expensive apartments decreases our attractiveness and is no longer sustainable. Compare this to cities like New York, London and Singapore where rental apartments are cheap. There is, unlike Stockholm, flexibility. There are among experts and decision-makers a broad insight that factors like rental control, the tax structure and current regulations result in a shortage of rentals being built and that the market basically is not working. (Ek and Lorentzon, 2016) Since then, Spotify has been expanding in New York rather than in Stockholm. Other entrepreneurs witness the same thing. Henrik Bergqvist, CEO and co-founder of Pickit, stated in an interview that “Swedes grew up with the Internet, meaning we’re a digitally savvy nation. However, it will be difficult for companies to remain in Sweden in the long run, particularly with skilled employees moving to the US” (Sheffield, 2016). Retaining and attracting talent is one crucial challenge that businesses and government have in common, and there should therefore be joint initiatives in this area. We should not just preserve our liberal rules, but instead expand them and make it easier for foreign nationals to contribute to our economy and culture. Policy recommendations First of all, as shown by both the FinTech investment data and the OECD, access to capital does not seem to be a major issue for Swedish FinTech firms. Interest rates are low and the latest years have shown that investors dare to invest in often abstract and low-security ideas (Riminton, 2016). However, as described above, Sweden has some potential problems down the road. The declining performance of the primary and secondary school system is influencing the skill level in the young adult population, as confirmed by the OECD’s PIAAC studies (Bussi and Pareliussen, 2015). The decline in skills that students get from primary school has decreased across the board, but most dramatically in both ends of the skill distribution. For instance, Sweden had fewer high-performing students in 2016 compared to 2006 (Henrekson and Jävervall, 2016). Combine this with the fact that the large corporations that have guided R&D in Sweden are divesting, and a structural problem emerges. What is then needed to counteract these macro-trends to revitalize the innovation landscape? Our main conclusion is that Sweden has spread itself too thin and now needs to focus its ambition of world-class positions into fewer fields in terms of research, innovation, and business.
FinTech in Sweden 75 From a FinTech perspective, R&D is a core activity of their work. FinTechs are heavily reliant on skilled workers and must be able to apply innovations fast and continuously. But R&D looks different in a tech startup compared to a multinational corporation with large teams of researchers. R&D is much more collaborative in the tech world. Patents are becoming less important since in a world of infinite scalability, the first mover advantage is more important. R&D also relies heavier on human capital, and not machines or physical investments in research facilities. The policy recommendations that we make in this chapter are presented from a sequential perspective. We have, first, the startup phase, implementing the business idea and gaining proof of concept; next, the talent phase, where it is crucial to find the right people to develop the product; then, the growth stage, where the firm solidifies its market position; and last, the global phase, where the firm has a chance of gaining world leader status. Startups A Swedish sandbox model To lower barriers for FinTech startups, we suggest that regulatory bodies change their mindset from just being an administrator of the regulation to working proactively with innovators to help them navigate existing regulation. This approach has already been implemented in the UK with the FCA’s regulatory sandboxes (Jonsdottir et al., 2017). London is today the biggest FinTech hub in the world. The explanation is not one-sided, but the development of the “sandbox model” might well be a key factor. The Financial Conduct Authority (FCA) has implemented a “regulatory sandbox,” which is a limited environment enabling FinTechs and incumbents to build and test their products and services in a less restricted environment. If the outcome is positive, then the firms can apply for full licenses and grants. Since it started, the FCA has received over 600 requests, and over 50 percent have so far been accepted as a part of the sandbox model (Jonsdottir et al., 2017). The process can be described as in Figure 3.4. The sandbox model is effectively a way to signal to highly skilled entrepreneurs that the UK is willing to help them succeed with their projects. Through this model, the UK government attracts a lot of talent. On a practical level, the Swedish sandbox model would have to be based on different legislative systems than in the UK. The FCA does not only monitor the market participants’ compliance with regulation; it also serves to legislate the market. The sandbox model is based on this dual role, as the FCA can permit exceptions from the regulation for a certain limited time (Jonsdottir et al., 2017). Enhanced know-your-customer process Know-your-customer (KYC) schemes enable customers to choose which banks can gain access to their credit information. This allows customers to easily apply
76 Björn Olsson and Mattias Hallberg for loans at banks that have no previous information on the specific customer’s creditworthiness. Today, the Swedish Bankers’ Association is investigating the possibility of enhanced KYC norms (Swedish Bankers’ Association, 2017a). It is essential that such a system is available not only to established banks, but also to small FinTech firms. If KYC norms are relaxed, arguably the financial intermediaries could focus on what they are best at—financial innovation. Programming in school To increase the labor skills and make IT and FinTech a field for vision and entrepreneurship for all, programming should be taught as one of the basic mandatory languages in school. It is indeed a large commitment to ensure that future generations have access to opportunities. Policymakers have an ambivalent approach to digital skills and digital literacy in the national curriculum. As Asp (2016) shows, digital skills were introduced as early as 1980, but then removed in 1994, to enter again in the early 2000s. Now, with the new curriculum from 2011, schools and teachers have a pronounced task to teach digital skills; however, we are far from teaching code to every school child. It is rather something picked up in one’s pastime, should one have the passion and interest. This means a lot of young people never encounter programing languages, and if they do, it might happen rather later in life. We need to capture the curiosity of children and youth, and show them that there are endless opportunities to use sandbox FCA assesment Collaboration to find a testing approach Testing and monitoring Final report and review Firm proposal FCA delivers Sandbox option Figure 3.4 The regulatory sandbox model, as used in the UK
FinTech in Sweden 77 in this field. This especially applies to girls, since the “computer nerd” personality has traditionally been a male stereotype (Cheryan et al., 2013). In her study, Asp (2016) also showed that teachers requested more concrete guidance from the government and more opportunities for professional development in this field. The problem for Sweden is not access to machines; our schools are well equipped with computers and tablets. What is lacking is the pedagogical and technological skills among the educators (Swedish National Agency for Education, 2015). Here, the municipalities in Sweden who oversee primary and secondary education must take their responsibility and invest in the skills needed by their staff. Incentivize company-founded higher education In general, the higher up in the education hierarchy you move, the more advanced and applied skills are taught. The idea is that those skills will be directly applied in the business sector to create growth and prosperity. It is our opinion that a larger economic commitment to higher education from the business community is needed to bridge the skill gap we see today. In the US, 83 percent of organizations surveyed by the International Foundation of Employee Benefit Plans (2015) offered some sort of educational assistance or tuition reimbursement to their employees. It is not unusual for employers in the US or UK to sponsor their promising employees’ graduate school education, but then they are heavily involved in ensuring that the skills taught match the skills needed. This is exactly what is missing in the Nordic “government pays all” education environment. The government should try to take a step aside and allow the markets equivalent to the professional master’s degree develop. This could be accomplished within the existing HEI framework, or alternatively within a completely new framework. The crowding out and matching problem that the current funding system causes is poorly understood today, and deserves more attention from both academia and politicians. A master’s degree in FinTech Today, there are no master’s programs that explicitly combine the three key talents needed in FinTech. In Sweden, universities have tended to train students to study entrepreneurship rather than training them to become entrepreneurs. Why can there not be a joint program involving KTH and the Stockholm School of Economics (SSE), the two leading HEIs in FS and tech in Stockholm? Just as Swedish universities began early on to educate a combination of business and engineering, they could again take such a new, innovative step. Lowered government tax The Swedish tax rate on high incomes today is among the highest in the world (OECD, 2017). Over time, this has caused talents and high performers to
78 Björn Olsson and Mattias Hallberg relocate to other countries where the tax system rewards rather than punishes high-skilled labor. Throughout the years, different governments have sought to soften these taxes by reducing and imposing different deductions and loopholes. Such have been the different tax rules, including a tax relief for entrepreneurs, and today staff stock options are debated, particularly to the benefit of young startups that often do not have enough capital to take on full-time employees. Yet these are arguably mere excuses to avoid the structural problem. Recent research has even shown that an abolishment of the temporary austerity levy, an additional surtax on high-income earners known as “värnskatt,” would not only be fully financed in itself, but result in an increase in government revenue by around EUR 0.3 billion (Lundberg, 2016). Such a reform would send a strong signal that talent will be rewarded in Sweden in the future. Hanushek et al. (2015) showed that Sweden has the lowest return to skills in the whole OECD. Increased housing As Ek and Lorentzon (2016) have cautioned, the lack of affordable rental property in Sweden, and particularly in Stockholm, makes it difficult to attract new talent from overseas, and results in Swedish talent moving abroad to cities such as Berlin, London, and Prague. Although housing today is one of the major topics up for debate in Sweden, little is being done. From an economist’s perspective, the dynamics of the housing market are easy to explain. A high demand and low supply result in a substantial increase in real estate prices. In a well-functioning economy, this encourages and increases housing investments, as more companies want to sell expensive homes. However, in Sweden, this has not been the case, as regulations and standards have caused a structural deficit in housing investment, resulting in even higher housing prices. The solution is technical yet simple: regulators and local politicians need to not only encourage housing, but also enable it. This means both a reduction in regulations on environmental issues and the rights to appeal. But it also means that each and every housing project should aim for greater height and a larger number of apartments. As pointed out by others (e.g., Ek and Lorentzon, 2016), the market for rental apartments is dysfunctional in Stockholm, mostly due to an outdated rent control scheme. In May 2017, the Swedish Fiscal Policy Council endorsed a move to a more market-based approach to prices for rental apartments in Stockholm. We support their recommendation. Growth Swedish FinTech council within the FSA The Swedish government has ordered the Swedish financial services authority to conduct, overview, and evaluate its organization and to facilitate the growth and development of FinTech firms (Government Offices of Sweden, 2017b).
FinTech in Sweden 79 However, there is an impending risk that it is not taken seriously, as such government products tend to lack necessary political backing. Instead, the FSA should implement a special FinTech council where stakeholders from the regulatory bodies, startups, and large banks can discuss together how existing regulations might need to be adapted to fit with future innovative technology. Stockholm FinTech is obviously a natural partner in such an enterprise. This approach has already been implemented in the UK with the FCA’s Project Innovate. Moderation of compliance processes A major difficulty of running a financial company is often the tight compliance processes that have been mandated by the regulators. The FinTech sector increases rapidly, as will regulation and compliance. It is essential that this is done in a controlled and cooperative manner where the new regulations are presented easily and in harmony with the industry—without resulting in further obstacles for new business models and innovation. Global Free enterprise zone for FinTech Hong Kong and London are two of the world’s most successful examples of free enterprise zones (FEZs). In today’s hard international competition for talent and successful companies, Sweden must play an active role. Just recently, when Spotify moved into their new office in New York, expanding from 900 to 1,900 employees, the rent was reduced because of a decision by the state of New York (New York State, 2017). This type of government-led competition for fastgrowing companies will most likely increase. In this competition, Sweden needs to play an active role. Therefore, Sweden should consider establishing a special FinTech-focused FEZ, which was already considered in 2013 by the previous government. An FEZ could take the Swedish FinTech sector to the next level. Scandinavian FinTech council Realistically speaking, Sweden is not particularly big, and faces global competition for talent. However, the Scandinavian countries combined would equal the world’s eleventh largest economy in terms of GDP (World Bank, 2017). The differing policy and regulatory environments across the Nordics have made cross-border collaboration very difficult. In fact, little to no communication occurs between the Nordic financial authorities. Fostering this dialogue and striving for regulatory interoperability across the Nordics would not only reduce barriers for innovation, but also make it easier for FinTech startups to scale across borders. This is especially important in Nordic countries, which are by default small markets.
80 Björn Olsson and Mattias Hallberg If Scandinavia would cooperate and ease access to each other’s markets, it could be the largest FinTech hub in the world. Offering a proof of concept that a firm’s product works under different countries’ regulatory frameworks and that it can attract different consumers enables firms to expand more quickly and internationalize. Regulatory improvements The new Second Payment Services Directive (PSD2) legislation, as previously described in Chapter 1 in this volume, forces banks to open their infrastructure for payment initiations, as well as for requests for customer account information by third parties. It is intended to increase competition and innovation within the payments area. It is crucial that this new directive, like similar regulations ahead, is reviewed, meets its objective, and does not discriminate against the often smaller third parties. Such a review process is especially important in countries where cases of banks discriminating against smaller FinTech firms have been witnessed. Conclusion Right now, there is a momentum for FinTech in Sweden. This is not the only part of the economy where things are happening and new profitable ideas are generated, but it is surely one of the most exciting. The sector combines many of the aspects of Swedish society that can be transformed into competitive advantages in relation to other countries and markets. Even though this chapter is aimed specifically toward policymakers, we are in general pessimistic about governments’ capacity to “create” business opportunities. In terms of supporting the business sector, the government must understand what is moving. Which sectors are catching speed and which are dying? Policy cannot stop or reverse the inherent process of creative destruction that capitalism brings with it, but it can be a midwife for the new economy. We have tried to make the case that Swedish FinTechs are ready to take the next step and go global, but that they cannot do it without support from policymakers. Fortunately, many of the policy recommendations that we have outlined are not FinTech-specific; rather, they are sound policies that many aspects of Swedish society would benefit from. In our mind, the cost–benefit analysis weighs over in the direction of reform. Sure, there are risks involved, but the pathway down a spiral of stagnation and lost dynamism is a very unattractive alternative. The beauty of the beast is that Sweden is filled with potential areas to reform. Programming skills should be taught at a young age and developed in a master’s degree. Talent should view Sweden as a country of low taxes and cheap apartments. Regulation should enhance rather than discourage innovation and entrepreneurship. In conclusion, we would like to reform the way we produce, incentivize, and reward human capital all the way from primary school to business and bonuses. With such a policy agenda, FinTech in Sweden can progress to become outstanding.
FinTech in Sweden 81 Notes 1 R&D intensity, manufacturing value-added, productivity, high-tech density, tertiary efficiency, researcher concentration, and patent activity. 2 The high growth indicator is a combined measure of: (1) the percentage of high-growth businesses that intend to employ at least 10 people and plan to grow more than 50 percent in five years; (2) the availability of venture capital; and (3) business strategy sophistication (Ács, Szerb, and Lloyd, 2017, p.79). Bibliography Ács, Z.J., Szerb, L., and Lloyd, A., 2017. Global Entrepreneurship Index 2017. Washington, DC: CreateSpace Independent Publishing Platform. Asp, L., 2016. Digital litteracitet i svensk grundskola Digital litteracitet enligt svenska styrdokument och lärares praktik [Digital literacies in Swedish Schools: Digital literacies in the Swedish curriculum and the teachers’ perspective of the assignment]. [online] University of Gothenburg. Available at: http://hdl.handle.net/2077/48089 [Accessed August 30, 2017]. Beck-Friis, U., 2014. Val utan skiljelinjer [Choice without demarcation lines]. [online] Finansliv. Available at: http://beck-friis.net/wp-content/uploads/2014/04/andersson-o- borg.pdf [Accessed August 30, 2017]. Bussi, M. and Pareliussen, J.K., 2015. Skills and labour market performance in Sweden. [online] OECD Economics Department Working Papers. Paris: OECD. Available at: www.oecd-ilibrary.org/economics/skills-and-labour-market-performance-in-sweden_ 5js0cqvnzx9v-en [Accessed August 30, 2017]. Cheryan, S., Plaut, V.C., Handron, C., and Hudson, L., 2013. The stereotypical computer scientist: Gendered media representations as a barrier to inclusion for women. Sex Roles, 69(1–2), pp.58–71. Drivhuset, 2013. Studenter är framtidens entreprenörer [Students are the entrepreneurs of the future]. [online] Attityd 12/13. Available at: www.drivhuset.se/aktuellt/studenter- ar-framtidens-entreprenorer [Accessed August 30, 2017]. Eduniversal, 2017. Top 100 2017 Eduniveral Best Masters Ranking: Entrepreneurship. [online] Available at: www.best-masters.com/ranking-master-entrepreneurship.html [Accessed August 30, 2017]. Ek, D. and Lorentzon, M., 2016. Vi måste agera eller bli omsprungna! [We have to act or be outrun!]. [online] Medium. Available at: https://medium.com/@SpotifySE/vimåste-agera-eller-bli-omsprungna-383bb0b808eb [Accessed August 30, 2017]. European e-Skills, 2014. e-Skills in Europe: Sweden – country report. [online] Available at: http://eskills-monitor2013.eu/fileadmin/monitor2013/documents/country_reports/ country_report_sweden.pdf [Accessed August 30, 2017]. EY, 2016. UK FinTech: On the cutting edge. [online] Available at: www.ey.com/ Publication/vwLUAssets/EY-UK-FinTech-On-the-cutting-edge-Executive- summary/$FILE/EY-UK-FinTech-On-the-cutting-edge-exec-summary.pdf [Accessed August 30, 2017]. Görnerup, E., 2015. Kunskapsekonomi på sluttande plan? En undersökning av företagens FoU i Sverige [A slippery slope for the knowledge economics? An investigation of the corporations’ R&D in Sweden]. [online] Available at: www.svensktnaringsliv. se/fragor/forskning/kunskapsekonomi-pa-sluttande-plan-en-undersokning-av-fore tagens-f_616081.html [Accessed August 30, 2017].
88 Niklas Arvidsson The US economist Kenneth Rogoff has tackled the issue of cash for many years, and not only discusses, but actually advocates a motion toward, a cashless society in his book The Curse of Cash (Rogoff, 2016). As an economist, he addresses the question with a focus on economic and financial policies. His two main arguments behind a move toward less cash include benefits as discouragement of tax evasion and crime, as well as enabling governments and central banks to more effectively handle economic crises by abolishing the “zero lower bound” interest rates that the existence of cash ensures. In addition, he argues that the existence of cash and the ability to pay wages and salaries to unemployed people for temporary jobs is one factor that stimulates illegal immigration and consequential social challenges. This must be weighed against the risk of financial exclusion of people that are dependent on cash and will have problems accessing electronic payment services, as well as the loss of seignorage1 by central banks when cash is not issued to the market. Rogoff (2016, p.81) defines seignorage as “the difference between the face value of coins minted by the government and the cost of inputs, including both materials and production costs.” It thus constitutes the profit a central bank receives when selling cash to the market for the nominal value of bills and coins, while the production cost of those bills and coins are rather small compared to the nominal value. The level of seignorage differs substantially between countries, depending on how much cash is used. In countries such as Sweden, Mexico, Norway, and Denmark, it is close to zero, while in countries such as Hong Kong and Russia, it can amount to well over 1 percent of GDP (Rogoff, 2016). Sweden actually had a negative seignorage during the period 2006–2016 (Rogoff, 2016). The existence of seignorage is seen to ensure a stream of revenues to a central bank, and therefore enable the central bank to pursue its tasks independently from the government (Rogoff, 2016). If a central bank was entirely dependent on finances from the government, some fear it would lose its independence. This statement is heavily debated, however. Rogoff (2016) also shows that even if the outstanding share of US dollars fell by 50 percent, the seignorage for the US Federal Reserve would still by far cover its operating budget. In addition, central banks can still make money on margins between lending and borrowing, and thereby ensure its independence from governmental funding. All in all, even if a reduced seignorage will harm the financial independence of central banks, it would not disable them to run open market operations, perform independent analysis, and pursue independent research. Researchers at the Swedish Central Bank—the Riksbank—argue that it is reasonable to address the issue of whether cash should be legal tender or not. In an economic commentary, Segendorf and Wilbe (2014, p.7) ask the question if cash has a future as legal tender, and conclude that given the small use of cash in Sweden: it would be wise if the legislator begins to investigate now whether a new and technology neutral regulation is needed to determine the method of payment when there are no agreements on this and if there are situations in which it will continue to be necessary to pay in cash.
The future of cash 89 There is a review of the Central Bank Law, where the issue of cash is one of several other issues to be reviewed during 2017–2019 (Government Offices of Sweden, 2016). Segendorf and Wilbe (2014) contrast two alternatives: 1 to strengthen the obligation by market actors to accept cash; and 2 to abolish the status of cash as legal tender. The first alternative—to strengthen the obligations by banks, merchants, and other actors to accept cash—would mean that the market actors would be pushed to follow the current Central Bank Law stating that cash is legal tender. This would have strong positive effects for those that are dependent on cash, even if that group is not large and other actions—such as the legal right to a bank account—are aiming to handle this problem (Segendorf and Wilbe, 2014). The disadvantages of this alternative are that it is not technology-neutral, but rather locks the system in a cash-related technological path instead of stimulating innovation. This in turn could become costly from a socioeconomic perspective (see Segendorf and Jansson, 2012a, 2012b) if the decreased use of cash continues. Segendorf and Wilbe (2014) argue that the second alternative—to abolish the status of cash as legal tender in Sweden—offers two advantages: (1) the legislation would better reflect the actual use of payment services; and (2) market actors would be able to more freely decide which payment services they prefer to accept and use. The authors also note that this is a long-term process. Hence, such change in the legislation would need to be complemented by measures that help the groups facing negative effects should cash disappear. This includes categories as people with physical and/or cognitive disabilities, the elderly, immigrants/ refugees, small cash-dependent companies in rural areas, and smaller organizations (Ehrenberg and Jansson, 2016). In my previous study of whether or not Sweden may become a cash-free society (Arvidsson, 2013), I concluded that a cash-free society is possible. There are, of course, many factors that influence this development, and the development is therefore difficult to predict. The report concludes that Sweden may become a cash-free society, but not before 2030 (Arvidsson, 2013). The main determinant if Sweden will stop issuing cash in krona is of a political nature. Even if the Riksbank researchers conclude that it is possible to envision that Sweden will stop issuing cash (Segendorf and Wilbe, 2014), there are no signs of Swedish politicians and political parties arguing in this direction. In fact, we are now seeing an opposite development, as one of the parties in the Swedish parliament—the Center Party—contends that the Riksbank ought to be given a formal and official duty to ensure that all companies and households throughout Sweden have access to cash withdrawal and cash deposit services (Dagens Nyheter, 2014; Centerpartiet, 2017a, 2017b). The party argues that the legal cash regulations in the Sveriges Riksbank Act (1988:1385), subject to new review during 2017–2019 (Government Offices of Sweden, 2016), must be changed to provide for these stipulations.
90 Niklas Arvidsson Other critical factors affecting or indicating the use of cash in Sweden include: •Demographical changes since cash tends to be preferred more by elderly and less by young people. •New companies, technologies, and services that can replace cash payments, such as iZettle, PayPal, Swish, WyWallet, and services from, for example, Kivra, Klarna, Seamless, and Trustly (Arvidsson, 2016). •The continued growth of card payments (see Chapter 13 in this volume). •An increase of stores that do not accept cash, as well as an increased use of e- and m-commerce, instead of shopping in traditional retail stores. This means fewer outlets accepting cash, while access to ATMs will continue to be stable, albeit with a reduced number of transactions (Swedish Bankers’ Association, 2016). At the same time, the bank offices offering cash-handling services were around 40 percent of all retail banks, with increased fees for cash-handling services and a remaining fear of robberies by merchants, etc. (Ehrenberg and Jansson, 2016). One other interesting factor affecting the use of cash in Sweden was the introduction of new bills and coins in krona. In 2010, the Riksbank motioned to launch new bills and coins in Sweden throughout the period 2015–2017 (Riksbank, 2010). The process (Riksbank, 2017b) was organized in a way that new bills in the denominations of SEK 20, 50, 200, and 1,000 were introduced October 1, 2015, and new bills in the denominations of SEK 100 and 500, as well as coins denominated in SEK 1, 2, and 5, were introduced on October 3, 2016. The older SEK 20, 50, and 1,000 bills were invalidated by June 30, 2016, while the older SEK 100 and 500 bills, as well as the coins denominated in SEK 1, 2, and 5, were declared invalid as of June 30, 2017. The decision to launch the new cash made sense, as it was taken before the rapid decline of cash had started and was motivated by the ambition to decrease the risk of forged cash. The paradox is that the introduction of new cash seems to have motivated different actors to actually stop accepting and/or using cash before the new bills and coins are introduced. Even if this is somewhat speculative, one may wonder why so many bank offices no longer offer cash-handling services and why an increasing number of merchants have stopped accepting cash. One reason could be that the introduction of new cash has led decision-makers in banks and merchants to address the strategic decision whether to stop accepting cash or not, and that companies such as Telia, Tele2, KungSängen Digital Inn, and the Abba museum, among others, came to the conclusion that it is wise to stop accepting cash and/or offering cash-handling services. Paradoxically, it is not unlikely that instead of stimulating a renewed interest in cash, the new bills and coins may have led to a decreased interest in cash. The potential route toward a cash-free society A top-down driven plan In Chapter 7 of his book, Rogoff (2016) outlines a plan for how central banks and governments can address the move toward a cash-free society. The first part
The future of cash 91 involves phasing out paper currency in different steps, where the large bills are the first to be phased out, which is then followed by lower and lower denominations until only small bills remain. In this phase, it is even a possibility to replace small bills with coins to limit the benefits of using cash. The second part involves a political scheme for universal financial inclusion to ensure that the most cashdependent people and companies do not suffer when cash is phased out. This could be based on universal access to electronic accounts operated by the central bank or commercial banks, as well as debit cards for all—perhaps even via governmental subsidies. In addition, all forms of state-based payments, such as unemployment benefits, welfare, pensions, child provision, and other forms, would be paid directly to these electronic accounts. The third part is to enforce strong regulations and laws to protect privacy and integrity for people making electronic payments. This aims to ensure consumers trust the systems behind payments. The last part is to build clearing and settlement systems that realize real-time payments—or close to real-time payments—in order to create a functionality of electronic payments that is close to the functionality of cash payments. It should be noted that Rogoff sees this as a gradual and long-term process where the definite end date of cash— where it is not legal tender anymore—is not defined. The slow process will also enable the system to deal with challenges as they occur. Given Rogoff’s plan, it is interesting to note that the parliament (Finansutskottet, 2014) or the Riksbank did not decide to stop the largest bill—the SEK 1,000 bill—when they decided to launch new cash in Sweden. This is not in line with what Rogoff argues. Had the politicians in fact been driven by a political ambition to get rid of cash in Sweden, they would have been likely to decide not to launch a SEK 1,000 bill, but instead withdraw it totally. This is a strong sign that the reduced use of cash in Sweden is primarily driven by market actors such as banks, other technology and service providers, merchants, and consumers. Still, it should be noted that the Riksbank has issued commentaries on the future status of cash as legal tender. The Central Bank Law stipulates that cash is legal tender (The Riksbank Act (1988:1385)), but—as discussed above—this is, as of 2017, being reviewed. Researchers from the Central Bank of Sweden have also acknowledged the need to review the law, and do not exclude the possibility that the law is changed in a way so that cash is not legal tender anymore (Segendorf and Wilbe, 2014). A sociotechnical development of the cash system In addition to a top-down approach, we need to understand other factors such as technologies, demand, societal values, business strategies and interest, and other issues to get a complete picture. It is clearly the case that Rogoff discusses the route toward a cash-free society from a macroeconomic and central bank perspective, and consequently does not discuss other relevant dimensions. In a study of the sociotechnical system behind cash payments and how this is likely to affect the use of cash in Sweden (Arvidsson, 2016), several critical factors deciding the development were identified. The strongest factors moving the system toward less use of cash included technological solutions that can replace cash (such as Swish), the debate in society on how to understand cash and its
92 Niklas Arvidsson implications (where both see an increasing campaign saying that cash is needed and others arguing we should get rid of cash), the development of interoperable platforms for new payment services (including platforms for identification, processing, clearing, and settlement), demographical development (since elderly people generally are the most cash-intensive group), and political and societal efforts to detect and handle crimes related to cash. The same study (Arvidsson, 2016) also identified factors that will lead to a continued use of cash. These were: •The time it takes for consumers to change habits and values related to payments. •The strategic games between banks, FinTech, telcos, and others that sometimes make the development more connected to strategic ambitions of providers than to the actual value for payers and payees. •That different payment services (e.g., cash, cards, invoicing, mobile payments) compete in radically different ways in terms of fees, and that the actual use of services is somewhat biased toward services not having clear consumer fees. •The role that politicians and lawmakers take in this issue, and the public debate that it creates. In this scenario, factors related to competition and to the public debate are the most important ones. It is also interesting to discuss the process from a value-in-use perspective. The value of a payment service is highly dependent on network effects and interoperability, where the value of the service as such, both for payers and payees (i.e., payment receivers), depends on the number of users in the system (Economides, 1996; Hagiu and Wright, 2015). A service with few payers and/or few payees is naturally less useful than a service with many payers and many payees. The international card payment systems are good examples of this. A Visa or Mastercard payment can be made in a large number of stores globally and by a large number of consumers. Interoperability is very high, and the value of the service is therefore high. The development in Sweden for cash during the last decade is characterized by a gradual reduction of interoperability, and the value of the service is therefore decreasing. One can then speculate if there is some point—a “tipping point” (Gladwell, 2000)—at which a slow gradual decline leads to a situation where more and more payers as well as payees stop using or accepting cash since the network value is too low in relation to the costs of continuing to use or accept cash. It is not unlikely that Sweden is nearing the tipping point when it comes to the use of cash.2 We should also acknowledge that there are opponents to the reduction of cash-based services in Sweden. There are initiatives such as “Kontantupproret” (Cash Uprising) and several Swedish senior citizen interest organizations such as PRO and SPF3 that perform lobbying with the aim of keeping cash services in Sweden (Eriksson, 2015). “Kontantupproret” was, as of 2015, led by former national police chief Björn Eriksson, and can be understood as an interest
The future of cash 93 organization for the industry providing services related to protection and handling cash, while PRO and SPF are consumer organizations focusing on senior citizens. “Kontantupproret” has also lobbied for the government to take the concept of access to cash more seriously as the reduction of cash services has impeded many consumers and business owners (Eriksson, 2015). PRO has also acted in this matter by collecting names of people that want to keep cash in Sweden (PRO, 2017). Even if I have not discussed all factors affecting the use of cash in Sweden, we can conclude that there are a number of factors leading the payment system toward less use of cash, but there are also factors that work in the opposite direction. Having weighed these together, we can predict a development where the use of cash continues to decrease and eventually becomes less important for the payment system as such. Fewer merchants are likely to accept cash4 and fewer consumers are likely to use cash. The rapid decrease of the use of cash in Sweden may lead to a situation where Sweden has become a cash-free society within five years (i.e., one where cash is legal tender but where few payers and payees use and accept cash). The role of a central bank in a cash-free society An interesting question concerns which role a central bank should have in a cashless society. As discussed by Rogoff (2016) and others, the role of a central bank will also be central in a cashless society, even if the task of issuing money may change drastically. Should governments decide to continue to issue money with the backing of a nation or a supranational body such as the European Union, be it in the form of traditional cash or not, the central banks will continue to have a critical role in the payment system. Central banks—for instance, from Canada, Sweden, and the UK—are studying whether and how they may provide “electronic cash” (i.e., electronic money that is supported by the national state). This is called central bank digital currencies (CBDCs), and is seen being similar to traditional cash in a legal and functional sense, even if it is electronic. The idea is to launch electronic money that in concept resembles and functions like cash. The Riksbank of Sweden has studied the possibility of launching an “e-crown,” while the Bank of England and the Bank of Canada have been looking into the possibility of introducing a central bank-issued digital currency. The discussion of CBDC focuses on its relation to payments, but there are in addition studies indicating positive macroeconomic gains if a central bank introduces a “central bank digital currency” (Barrdear and Kumhof, 2016). The Bank of England has been running a program focusing on the implications for a central bank should it issue a digital currency (Bank of England, 2017b). To this point, the Bank of England has been studying the role of digital currencies in challenges related to macroeconomic effects that such a shift may have on the economy as a whole. The Bank of England has also studied how it could affect the financial system, how it could affect policies related to monetary and financial stability, and how it will be realized. One particular question concerns whether
94 Niklas Arvidsson a blockchain-based system may function jointly with the existing infrastructure (Bank of England, 2017a). To conclude, the Bank of England, which was one of the first central banks to launch cash, is also one of the first to address the possibility of launching digital cash. To this end, the bank has also put extra effort into understanding how blockchain technology can be used in this endeavor. The Bank of Canada has also been pursuing the question of whether or not they should issue a digital currency. To this extent, they have developed several arguments as to why this may be a good idea (Bank of Canada, 2017; Engert and Fung, 2017). In a discussion paper by two researchers at the Bank of Canada (Fung and Halaburda, 2016), it is argued that the three main reasons behind introducing a digital currency by a central bank are: (1) it may improve the efficiency of issuing money; (2) it may improve the efficiency and safety of both retail and largevalue payments; and (3), it may also give a possibility to handle monetary policy goals and to promote financial stability better in a digitalized payment system. The report also proposes a framework to be used to evaluate desirable properties of such a digital currency (Fung and Halaburda, 2016). They first outline some characteristics that are predetermined or seen as nonnegotiable. These include: •the fact that the unit of account is the national currency; •that the central bank continues to issue bank notes and to provide settlement balance or reserve accounts to banks; •that the central bank offers the possibility to exchange the digital currency to paper currency at par; and •that the supply of digital currency is decided by the central bank and is consistent with its monetary policy framework.5 Other important properties include high efficiency in handling transactions, wide adoption or high interoperability, efficient markets and allocation of resources in the technology and business system, as well as the need to comply with legal requirements such as anti-money laundering (AML) and counterterrorist funding (CTF) requirements.6 The Riksbank in Sweden has also been looking at the possibility of introducing a digital currency, or an “e-crown” (Riksbank, 2016). The bank has communicated that it is studying this challenge, and that the development in Sweden with the rapid decline in use and access to cash has led to a need for the Riksbank to address the challenge now. They have outlined three different areas in which they need to make decisions. The first concerns which technologies—both centralized and decentralized—as well as devices may be used. The second concerns which policies—including areas such as the Central Bank Law, the payment system as such, financial policies, financial stability, and other policies—need to be in place when a digital currency is issued. The third concerns which legal requirements must be addressed. The Riksbank has clearly stated that this has been a challenging project, and that it will take time before it can reach a decision in the matter. However, the Riksbank has also pointed out that similar changes have been made previously. An example of which was when paper-based archives for registering ownership of
The future of cash 95 shares were digitalized. As such, there is deep experience and competence that can be deployed in order to meet this challenge. Concluding remarks and summary There has been a swift decline in the use of cash in Sweden that does not appear to have lost its momentum. We can therefore foresee a development where the value of cash-based payments—both for payers and for payees—continues to decrease as the interoperability of cash is reduced. In addition, the demographic development will continue to put pressure on cash in favor of electronic and mobile payments. We can expect a future where a decreasing number of payers as well as payees use and accept cash, whereas specific groups in society, such as the elderly, physically and/or cognitively impaired people, etc., still depend on cash. In addition, there may be regions with unreliable telecommunication systems and Internet access, prompting these regions to favor cash. One critical role and responsibility for the state and its agencies is therefore to make sure these groups are helped in this transition. Another task for the state, as well as for market actors, is of course to develop and supply electronic payment services that create value for payers as well as payees in the situations where cash dominates today. The technological development and digitalization cannot—and should not—be stopped, but there are actions that can be taken to reduce negative effects for certain groups during this transformation. Perhaps an e-crown—or a central bank digital currency (CBDC)—can become another way to enable people to benefit from digitalization and development in the payment industry. One thing that is very apparent is that central banks are continuously searching for and learning to understand their future role should cash disappear. Notes 1 Seignorage is, in short, the difference between the nominal value of cash—let’s say SEK 100—and the production costs of that bill. Seignorage is therefore a windfall gain a state receives when issuing new bills and coins. 2 To receive an answer on this, a consortium of researchers from the Royal Institute of Technology (KTH), Copenhagen Business School, and the Riksbank are, in 2017, conducting a large study of Swedish merchants’ views on accepting cash. 3 Such as Pensionärernas Riksorganisation (www.pro.se) and SPF (www.spfseniorerna.se). 4 We are currently pursuing a study, due for publication in 2018, on when Swedish merchants will stop accepting cash. 5 This last requirement is very different from most cryptocurrencies, where the supply is—for natural reasons—not at all connected to a nation’s monetary policies. 6 The list of relevant properties that must be handled is long, and includes, for instance, level of anonymity, limits on accounts and spending, fees, technological interface, access devices, distribution channels, verification systems, speed of settlement and reversibility, and ecosystem management, including business models. Bibliography Arvidsson, N., 2013. Det kontantlösa samhället: Rapport fran ett forskningsprojekt [The cash-free society: Report from a research project]. Stockholm: Kungliga Tekniska högskolan.
96 Niklas Arvidsson Arvidsson, N., 2016. Framväxten av mobila, elektroniska betalningstjänster i Sverige: n studie av förändring inom betalsystemet [The growth of mobile, electronic payment solutions in Sweden: A study on the change within the payment system]. [online] Konkurrensverket [Swedish Competition Authority]. Available at: www.konkurrens verket.se/globalassets/publikationer/uppdragsforskning/forsk-rapport_2016-4.pdf [Accessed August 27, 2017]. Bank of Canada, 2017. Bank of Canada. [online] Available at: www.bankofcanada.ca [Accessed August 27, 2017]. Bank of England, 2017a. Bank of England. [online] Available at: https://www.bankofengland. co.uk/research [Accessed January 9, 2018]. Bank of England, 2017b. Digital currencies. [online] Available at: https://www.bankofengland. co.uk/research/digital-currencies [Accessed January 9, 2018]. Barrdear, J. and Kumhof, M., 2016. The macroeconomics of central bank issued digital currencies. [online] Staff Working Paper. Available at: https://www.bankofengland.co.uk/ working-paper/2016/the-macroeconomics-of-central-bank-issued-digital-currencies [Accessed January 9, 2018]. Capgemini and BNP Paribas, 2016. World Payments Report 2016. [online] Available at: www.capgemini.com/service/world-payments-report-2017-from-capgemini-and-bnp- paribas [Accessed January 9, 2018]. Centerpartiet, 2017a. Centerpartiet: Riksbanken måste se till att kontanter finns [The Center Party: The central bank must ensure the availability of cash]. [online] Available at: www. centerpartiet.se/lokal/fyrbodal/uddevalla/startsida/nyheter/nyheter/2017-01-28-center partiet-riksbanken-maste-se-till-att-kontanter-finns.html [Accessed August 27, 2017]. Centerpartiet, 2017b. Så får fler tillgång till kontanter [How to make cash more accessible to people]. [online] Available at: www.centerpartiet.se/media/nyhetsarkiv- 2017/2017-01-26-sa-far-fler-tillgang-till-kontanter.html [Accessed August 27, 2017]. Dagens Nyheter, 2014. Centerpartiet: Riksbanken måste se till att kontanter finns [The Center Party: The Central Bank must ensure the availability of cash]. Dagens Nyheter. [online] Available at: www.dn.se/ekonomi/centerpartiet-riksbanken-maste-se-till-att- kontanter-finns/ [Accessed August 27, 2017]. Economides, N., 1996. The economics of networks. International Journal of Industrial Organization, 14(6), pp.673–699. Ehrenberg, S. and Jansson, J., 2016. Bevakning av grundläggande betaltjänster 2016 [Monitoring the basic payment solutions 2016]. [online] Available at: www.lans styrelsen.se/Dalarna/Sv/publikationer/rapporter-2016/Pages/Betaltjanster-2016.aspx [Accessed August 28, 2017]. Engert, W. and Fung, B.S.C., 2017. Central bank digital currency: Motivations and implications. Staff Discussion Paper 2017–16, Bank of Canada. [online] Available at: http://www. bankofcanada.ca/wp-content/uploads/2017/11/sdp2017-16.pdf [Accessed January 9, 2018]. Eriksson, B., 2015. Yrkande om att Riksbanksfullmäktige markerar mot bankernas agerande i kontantfrågan [Request to the Riksbank General Council to denounce the banks’ actions in regards to the cash question]. [online] Kontantupproret. Available at: www. kontantupproret.se/wp-content/uploads/2014/11/Skrivelse-till-Riksbanksfullmäktige- från-Kontantupproret-dec-2015.pdf [Accessed August 28, 2017]. Ferguson, N., 2008. The ascent of money: A financial history of the world. New York: Penguin Press. Finansutskottet, 2014. Ogiltigförklarande av vissa sedlar och mynt [Invalidation of certain banknotes and coins]. [online] Available at: www.riksbank.se/Documents/
The future of cash 97 Protokollsbilagor/Fullmaktige/2014/probil_fullm_bilaga_B2_140822.pdf [Accessed August 28, 2017]. Fung, B.S.C. and Halaburda, H., 2016. Central bank digital currencies: A framework for assessing why and how. [online] Staff Discussion Paper. Available at: www.bankbanque-canada.ca [Accessed August 27, 2017]. Gladwell, M., 2000. The tipping point: How little things can make a big difference. Boston, MA: Little, Brown. Government Offices of Sweden, 2016. Översyn av det penningpolitiska ramverket och riksbankslagen [Review of the monetary framework and the Riksbank Act]. [online] Kommittédirektiv [Committee Directive]. Government Offices of Sweden. Available at: www.regeringen.se/rattsdokument/kommittedirektiv/2016/12/dir.-2016114 [Accessed August 28, 2017]. Hagiu, A. and Wright, J., 2015. Multi-sided platforms. International Journal of Industrial Organization, 43, pp.162–174. Kärrlander, T., 2011. Malmö Diskont – En institutionell analys av en bankkris [Malmö Diskont: An institutional analysis of a bank crisis]. [online] Doctoral Dissertation. Kungliga Tekniska Högskolan. Available at: www.diva-portal.org/smash/get/ diva2:443847/FULLTEXT01.pdf [Accessed August 28, 2017]. PRO, 2017. Kontanter behövs [Cash is needed]. [online] Available at: www.pro.se/pension/ Nyhetsarkiv/Kontanter-behovs/ [Accessed August 28, 2017]. Riksbank, 2010. Riksbanken förnyar sedel- och myntserien [The Riksbank renews the banknote and coin series]. [online] Available at: www.riksbank.se/sv/Press-och- publicerat/Pressmeddelanden/2010/Riksbanken-fornyar-sedel--och-myntserien/ [Accessed August 28, 2017]. Riksbank, 2016. Skingsley: Borde Riksbanken ge ut e-kronor? [Should the Riksbank distribute e-crowns?]. [online] Available at: www.riksbank.se/sv/Press-och-publicerat/ Riksbanken-Play/Skingsley-Borde-Riksbanken-ge-ut-e-kronor [Accessed August 28, 2017]. Riksbank, 2017a. Statistik [Statistics]. [online] Available at: www.riksbank.se/sv/Sedlar-- mynt/Statistik/ [Accessed August 28, 2017]. Riksbank, 2017b. Tidplan för sedel- och myntutbytet [Time plan for the banknote and coin exchange]. [online] Available at: www.riksbank.se/sv/Sedlar--mynt/Sedlar/Tidplan/ [Accessed August 28, 2017]. Rogoff, K.S., 2016. The curse of cash. Princeton, NJ: Princeton University Press. Segendorf, B. and Jansson, T., 2012a. Cards or cash: How should we pay? Sveriges Riksbank Economic Review, [online] 3, pp.1–17. Available at: www.riksbank.se/ Documents/Rapporter/POV/2012/rap_pov_artikel_5_121017_eng.pdf [Accessed August 28, 2017]. Segendorf, B. and Jansson, T., 2012b. The cost of consumer payments in Sweden. Sveriges Riksbank Working Paper Series. [online] Available at: www.riksbank.se/documents/ rapporter/working_papers/2012/rap_wp262_120619.pdf [Accessed August 28, 2017]. Segendorf, B. and Wilbe, A., 2014. Does cash have any future as legal tender? Economic Commentaries, [online] 9, pp.1–8. Available at: www.riksbank.se/Documents/ Rapporter/Ekonomiska_kommentarer/2014/rap_ek_kom_nr09_141125_eng.pdf [Accessed August 28, 2017]. Swedish Bankers’ Association, 2016. Bank and finance statistics 2015. [online] Available at: https://bf-swedishbankers.azurewebsites.net/media/2661/2015_bankfinans_eng_. pdf [Accessed August 28, 2017].
104 Michael Björn as 29 percent of Internet users were doing online banking by 2004, it took Japan around 10 years to reach phase 3 when 50 percent of the population were already using the service at least once a month. To this day, banking in Japan is still conducted primarily through traditional offline channels by a large share of its inhabitants. One obvious reason for this is the well-documented aging population issue, and the lack of Internet penetration and resistance to Internet services by this demographic, but there may also be other reasons. Finally, although the Sweden line might not be as “eye-popping” as the Japanese one, it provides some interesting insight into the Swedish market. By the 2004 time frame, the “knee” between phases 2 and 3 had already reached 50 percent of the population. Although the incline of the curve is not very steep for the next few years, this indicates that online banking is already the default way of banking as the majority of the population is engaging in this activity after 2004 and onwards. By the time that both the UK and the US manage to reach approximately the same population share and approximately the same daily time spent doing online banking (15–20 minutes) as Sweden, the majority of Swedes had been doing this for the previous 12 years. In other words, online banking in Sweden reached phase 3 with a stable majority user base already in early 2005, whereas a similar situation was not reached in the UK or the US until 2008. That suggests that Swedish consumers, by and large, were forerunners when it came to the use of online banking, a trend that has been continued as new FinTech services have been introduced. Share of Internet population using service at least monthly Minutes per day 0% 20% 40% 60% 80% 100% 0510 15 20 0% 20% 40% 60% 80% 100% 0510 15 20 0% 20% 40% 60% 80% 100% 0510 15 20 Sweden USA Japan UK 0% 20% 40% 60% 80% 100% 0510 15 20 2001 2004 2008 2012 2015 2000 2004 20082012 2016 2000 2004 2008 2012 2016 2000 2004 20082012 2016 Base: Internet users aged 15–69; Sample size 1,000–4,000 respondents per country Figure 5.4 Online banking
The adoption of online banking in Sweden 105 Turning to the emerging markets of Brazil and China in Figure 5.5, we find significantly different-looking lines than in Figure 5.4, with the knee between phases 2 and 3 considerably lower. Our interpretation is that the underlying Internet penetration was evolving so quickly during these years that the uptake of specific services becomes overshadowed by the market evolution of Internet access overall. The effect of mobile phone usage on online banking In each of these markets, there is a sharp upward turn in penetration of the service between 2012 and 2016. The sharpness of this line is not something that could be expected from the approach outlined above. Instead, this shows the effect of a new base technology entering the market. In this case, the new technology is of course the smartphone. As it happens, financial technology and the smartphone actually have a long prehistory worth noting. As documented in Mari Matsunaga’s book i-Mode Jiken, the precursor to the smartphone was introduced in Japan already in February 1999 by NTT DoCoMo and was called i-mode (Matsunaga, 2000). The first “app” that was developed for that phone was a banking app; however, it failed miserably. In 2001, the i-mode creator Mari Matsunaga revealed to me in a discussion that the whole purpose of starting with a banking app was actually not to create a mass market application. Instead, there was something of a hidden agenda. By getting a bank on board, it was possible for the i-mode team to go to other companies and show them that their system was so safe and secure that even banks were creating applications. Thereby, there would be no risk involved for anyone else to join either. The strategy worked. The first app to be a smash hit on i-mode and the first one to top a million downloads during the first year was not the banking app, but a character screen app called “Chara-pa” by the toy company Bandai. Minutes per day Base: Internet users aged 15–69; Sample size 1,000–4,000 respondents per country Share of Internet population using service at least monthly Brazil 0% 20% 40% 60% 80% 100% 0510 15 20 2016 2012 2008 2004 2001 China 0% 20% 40% 60% 80% 100% 0510 15 20 2016 2008 2004 2001 2012 Figure 5.5 Online banking in emerging markets
106 Michael Björn In Europe and elsewhere, however, WAP phones were struggling to get off the ground, and although banking applications were also part of the initial phase, they had just as little success as in Japan—although it is difficult to say how much of that was part of WAP itself failing to build a sustainable user base (Palomäki, 2004). In 2007, eight years after the i-mode, a new i-device was launched, the Apple iPhone. From that point onwards, the mobile phone’s influence on the creation and uptake of Internet services was quick and massive. As shown in the Ericsson ConsumerLab report Interactivity Beyond the Screen, it would take only about four years from 2007 until iPhones and Android phones created sharp upward trends in mass market uses of various Internet services on a global scale (Ericsson ConsumerLab, 2014). Thus, since mobile banking was not in any way different than a host of other consumer applications, and was more the result of a maturing mobile technology than the cause of it, our interpretation of the upwards slant in Figure 5.3 between 2012 and 2016 is that this is the result of the mass market effect of mobile banking on overall online banking. Smartphones enabled the late majority to begin using online banking. However, they limited their use to simple transactions, similar to when the early majority began using online banking in phase 2, thereby reducing the average time used per person. Mobile banking in Sweden Turning to mobile banking in Sweden as an example, as recently as in 2012 only about one-third of Internet users were using mobile banking. Furthermore, they only used it 1.9 times a week on average, as can be seen in Figure 5.6. Three years later, the situation looked quite different. At this point, more than half of the population was using mobile banking—and at the same time, they were doing it almost twice as frequently, or 3.6 times every week according to the Ericsson ConsumerLab survey results. In terms of the diffusion of innovation model extension introduced earlier, it appears that penetration has skipped over phase 2 and moved directly into phase 3 with market growth slowing down, whereas average time spent on the activity is still increasing. Currently, mobile banking has become part of the socially normative way of doing bank-related activities. One explanation might be that mobile banking penetrated society so quickly that a more fine-grained analysis should be performed (i.e., using monthly instead of biannual data). Although Sweden exhibits a high penetration in terms of the percentage of users doing mobile banking at least once a month, Sweden lags behind the US when it comes to the average frequency of use, which might be surprising given the high level mobile usage. One factor may be that recent mobile payment solutions have been driven as much by IT companies and mobile handset manufacturers as by banks and credit card companies—and that such players have focused more on extending their services in the US than in Sweden. Another contributing reason is that our biannual data sets include only 2015 for Sweden, whereas the US data are for 2016. Mobile banking is still very much developing as we speak!
The adoption of online banking in Sweden 107 Conclusion In summary, what does this maturity imply for the future of FinTech services in Sweden? There are probably at the very least two important conclusions to draw from this. On the one hand, the fact that such a broad share of the Swedish consumer base has been engaging with online banking for such a long time implies that their online financial literacy is high and that their corresponding ability to judge the relevance and applicability of new financial technology will be quite advanced. In other words, they may not jump at just any new service, but they could be expected to be reasonably able to separate the useful services from those that are more of technology experiments. On the other hand, online banking does not exist in a vacuum, and neither will new FinTech services. Given that Sweden—as has been argued in this chapter— is relatively mature across a broad range of Internet usage perspectives, and not just banking, Swedish consumers are already engaging in a broad range of other online or Internet-related activities where those services can be tried out and potentially also used on a mass market scale. In other words, new financial services will naturally become part of a plethora of ecosystems that are already evolving as we speak, and those services that are good enough will not only become successful, but in their own turn continue to feed the ongoing maturation process in the market. Base: Internet users aged 15–69; Sample size 1,500–4,000 respondents per country Share of Internet population using service at least monthly Average frequency of use per week 0% 03 2012 69 20% 40% 60% 80% 100% Sweden 2015 2014 0% 036 9 20% 40% 60% 80% 100% USA 2012 2016 2014 0% 0369 20% 40% 60% 80% 100% UK 2012 2016 2014 0% 0369 20% 40% 60% 80% 100% Japan 2016 2012 2014 Figure 5.6 Mobile banking
108 Michael Björn Bibliography Ericsson ConsumerLab, 2014. Interactivity beyond the screen. [online] Ericsson. Available at: www.ericsson.com/assets/local/news/2014/6/interactivity-beyond-the- screen.pdf [Accessed August 27, 2017]. Ericsson ConsumerLab, 2016. Primary data from 2000–2016 Ericsson ConsumerLab surveys [Unpublished report]. Stockholm. Matsunaga, M., 2000. I-mode Jiken. Tokyo: Kadokawa Shoten. Palomäki, J., 2004. Case WAP: Reasons for failure. In: S. Luukainen, ed. Innovation dynamics in mobile communications. Espoo: Helsinki University of Technology, pp.98–101. Rogers, E.M., 1962. Diffusion of innovations. New York: Free Press. Swedish Post and Telecom Authority, 2006. Fact sheet: 3G in Sweden PTS-F-2005:5. [online] Swedish Post and Telecom Authority (PTS). Available at: www.pts.se/en-GB/Documents/ Fact-sheet/2005/Fact-sheet-3G-in-Sweden-PTS-F-20055/ [Accessed August 27, 2017].
Part 2 Cognition Legitimacy and views
6 The role of trust in emerging technologies Mats Lewan Introduction The scope of this chapter is to investigate the role of trust in emerging technologies, particularly with regard to FinTech. The concept of trust is often defined in terms of reliability and truth, for example “firm belief in the reliability, truth, or ability of someone or something” (Oxford University Press, 2017). But ultimately, from a functional point of view, particularly in business, you could also define trust in terms of predictability, for example as discussed in the piece The Power of Predictability (Stevenson and Moldoveanu, 1995), where the authors note that “predictability built the trust that allowed people to synchronize their actions in mutually productive ways.” One such definition of trust could also be “possibility to predict a desirable outcome from interactions with someone or something,” where high trust equals “high possibility to . . .” Given that the financial industry deals with people’s money, and presuming that people and organizations want to be able to predict what a financial service will do with their money, the definitions of trust above would imply that trust has a particular importance in the financial industry and also for FinTech startups. This is the first hypothesis that I aim to investigate. The second hypothesis is that ways of building trust might be subject to change due to Internet-based and digital technologies that fundamentally change the conditions for doing business, for interacting, for communicating, and for analyzing information. Method The aim of this study was to gain knowledge on the views on trust from people with understanding and experience of various functions with regard to the Swedish FinTech industry—regulation, startups, funding, and infrastructure. In order to gain this knowledge, interviews were conducted with a group of renowned people selected to represent players having these functions. Interviews were semi-structured and focused on a limited number of questions: the importance of trust in the financial industry; how startups are building trust
112 Mats Lewan toward the market and toward customers; how trust depends on security; how Internet-based technologies are affecting trust; what kind of players users have trust in today compared to before; and new ways of building trust by using digital technology such as blockchain. Interviews were conducted during February through April 2017, with the following individuals: Cecilia Skingsley, Deputy Governor of Sweden’s Central Bank, the Riksbank Henrik Rosvall, CEO of the savings app Dreams Johan Lundberg, co-founder at the FinTech-focused VC firm NFT Ventures Daniel Kjellén, CEO at the integrated bank information app Tink Ulf Ahrner, CEO at the investment digital advising company Primepilot Danny Aerts, CEO at Internetstiftelsen (IIS) Lan-Ling Fredell, Head of Operations at Stockholm FinTech Hub Sofie Blakstad, CEO and founder at the financial trust platform Hiveonline Frank Schuil, CEO and co-founder at the Bitcoin-focused startup Safello Jonathan Jogenfors, researcher at the University of Linköping Most interviews were recorded, but two of them, with Kjellén and with Lundberg, were not. In those cases, uncertain quotes have been controlled by the interviewees at a later occasion. Report from the interviews The different aspects of trust brought up by the interviewees are not easily divided into separate parts, but rather reflect each individual’s experiences and views on the topic. The following interview report will therefore be divided by person. Cecilia Skingsley, Deputy Governor of the Riksbank Skingsley discussed how FinTech startups manage to build trust in a short time frame, operating on a digital market where everything moves at a very high pace: How come people willingly provide credit card numbers and other information to companies that they have never heard of or that they know very little about? I’ve been thinking about this, because it doesn’t say Volvo or Ericsson or Astra Zeneca or any other well-known company name. And I think it’s a combination; you don’t hear that much about casualties—if you’re exposed to fraud on the Internet, you’re most often compensated.
The role of trust in emerging technologies 113 And you don’t hear bad stories about people buying things on the Internet. The security measures seem to be secure, and I think that’s important for the perception that there’s trust. Then there’s the aspect of integrity. It’s possible that there’s a different view on integrity in the young generation than in the older ones—that they are less worried about others being able to follow your consumption behavior, or even how you move geographically in the country or abroad. Perhaps younger people are as fond of their integrity online as their older peers, but nevertheless think it is worth giving some of it up in return for the ability to buy and sell and do banking errands wherever and whenever they want. A necessary evil, if you will. Skingsley also gave her view on blockchain technology: That’s one of the examples of technological change that we at the Riksbank have to understand and follow for several reasons. So far, however, it’s difficult to draw any extensive conclusions on which advances blockchain technology can contribute to. I think you need to be humble about that. But potentially you could build a kind of trust machine, and that’s of course interesting to follow. Daniel Kjellén, CEO at the integrated bank information app Tink Kjellén explained how Tink addressed the issue of building trust with users: First, we asked who we would like to have as angel investors. Our analysis was in short that we couldn’t just say, “Welcome to Tink, we’re secure,” and then invite people to seminars, explaining our security solutions. Instead, we had to find markers, communicating trust. For example, our chairman of the board is Nicklas Storåkers, and people understand that he cannot take that position if he’s not comfortable with the company. I definitely believe that such factors have an influence. We also hired a consultancy firm, Cybercom, that assessed our security level, and we tried to get exposure in important media outlets. That’s also a marker: “Journalists have met them and they seem clean, intact, and professional.” If there were a silver bullet for making people trust you, it would be to remain clean, intact, and professional every day. Now, four or five years later, we are perceived as trustworthy and secure in our groups—external parties, the public, journalists, the finance industry, etc. Also, Mobile BankID, which doesn’t influence our security at all, has significance—there are both false and true markers. We use BankID only to allow you to log in at your Internet bank, but Tink’s security has very little to do with Mobile BankID. Another marker was to get an ISO 27001 certification, which is the highest-level standardization certification we could possibly achieve. But
120 Mats Lewan Another perspective on the use of contextual trust that Blakstad brought up was with regard to fake news and fake information on the Internet: People do trust a critical mass of information, whether it’s true or not. But if you bring contextual records that are based on facts, my belief is that people will trust those as well, if not more, knowing that they are based on facts. I think the reason that people trust fake news is obviously because it confirms their personal biases, but also because there’s a vacuum of contextual trust. How can I validate that what I’m being asked to believe is true? If there’s no fact-based validation for it, you reach for whatever sources that are available. Ulf Ahrner, CEO at the investment digital advising company Primepilot Ahrner discussed the conditions for new companies gaining trust: Trust is an issue for all new companies, regardless of the Internet. But for the finance industry, this issue is larger for two reasons. The first is that you deal with people’s money; the second that there are many individuals pretending to be part of the finance industry but who in fact are imposters. And that’s a problem, of course, because firms that steal money do not belong to the finance industry, they are simply criminals. But often media describe them as “finance companies fooling people,” which is a strange confusion. Unfortunately, this means that the trust in new companies in this industry is low. The way we address this is appointing key persons to the board, start collaborations with established companies—everything that our customers deposit with us, for example, is kept on accounts at our bank [the SEB bank]. Initially, you have to build on collaborations with well-known brands and on individuals considered to be trustworthy in the board, in our case the chairman of the board. After having operated for a few years, it’s more about the fact that you’re still in the business, that you haven’t been reported, and maybe also how many customers you have. Ahrner also answered the question on how trust can be built more quickly today: For example, in the App Store, when our app is published there, it has to be approved by Apple. People know this, and therefore they trust that if it’s approved, it’s probably also good to use since Apple has checked the background, that the company is real, that there’s no malware, no phishing or other problems. And it will continue to be like that as long as Apple and Google manage to maintain that track record. This is specific for the app economy. On the Internet, which is not controlled, you don’t have the same level of trust. And this was the business idea behind Klarna, to bridge the lack of trust between the consumer and e-commerce websites by taking the credit risk and guaranteeing delivery to the customer. In this way, you could have a web shop with no history, and if
The role of trust in emerging technologies 121 you managed the payments through Klarna or another established payment provider, you knew that there would be no problem, because they would take the risk. And now it’s so accepted that people don’t even care any longer. Transactions today are managed by fairly large and established brands, and you won’t provide your card details to just anyone. Then if there’s no delivery, you will go to the bank and say that you have been defrauded and they will give you the money back. So there’s a security built on larger companies that you have trust in. On a question regarding the possibilities of building trust with blockchain-based applications, Ahrner answered: There’s a substantial hype around blockchain, unfortunately making it a bit overrated. The problem with blockchain is that it is designed to be the technology supporting cryptocurrencies. And what many people don’t understand is that the basis of the technology is being a currency. Thus, they are the same thing, and you cannot just take blockchain and apply it to something else. Because blockchain is an ordinary distributed database solution, which is something that has existed for 15 years, but with the only difference that it has a unique time stamp [on each block] that you have achieved by awarding a little bit of the currency to who puts the time stamp on the next block [in the database]. The problem is what you should award if you use the blockchain for shares in an incorporated company. Should you award new shares in this company every 10 minutes? Maybe theoretically, but I have never heard anyone discuss this issue [about how those putting on the time stamp should be awarded if the blockchain application is not a cryptocurrency]. Blockchain is designed for currencies, not for, let’s say, deed letters. You could put a distributed database on a secret computer somewhere, but then it’s not blockchain. In blockchain, you don’t have any secret computer, and the data is not encrypted. As soon as you encrypt the data, it’s no longer blockchain. So if you can make a distributed share register without encryption, that would be blockchain, but I don’t think anyone will do that, because then you have to reward shares every 10 minutes to who puts on the time stamp [which requires a difficult computation]. Ahrner then discussed if another financial infrastructure could emerge, beyond the existing traditional infrastructure: Yes, certainly. You have Swift—I don’t even remember when it was built— and Euroclear and other centralized database solutions that the banks, through banking licenses, have exclusive rights to manage and to use for transferring money and assets. Klarna, by becoming a bank, can now access these systems directly. So the first wave of FinTech would be that companies grow and get banking licenses, and in that way can circumvent the need for using the banks as a basis. That’s mostly an economic issue.
122 Mats Lewan A second wave would be that we replace Swift and Euroclear, and of course that will happen. Those systems are ancient so I’m convinced that it will happen, but it will probably take another 20 years, I think. Because I’m not convinced that blockchain is the solution that will replace those systems. But something will do it. It’s too deep-seated. It will take a very long time, because it’s so incredibly complicated. It’s difficult to explain. I’ve been working with so many parts of it and I have seen it live. Swift is a system which makes it possible to transfer money between every single bank account in the whole world, several times a day. To replace that, you need to achieve a network effect.1 For a long time, Facebook was alone having achieved a network effect. And the problem is that this kind of network effect exists for the payment infrastructure—Swift and the card infrastructure have an incredibly strong network effect, and replacing them will take a very long time, or will have to be completely ingenious. The thing is Bitcoin doesn’t go well with political control of the economy. Then you can claim that it will prevail anyway. No, it’s not like that. If countries make something prohibited, it won’t exist. You just need a stroke of a pen by policymakers and it’s gone. Danny Aerts, CEO at Internetstiftelsen (IIS) Aerts’ take on trust was particularly focused on security: I think that the field that people talk the least about but that will emerge more and more is security—can I trust that my money is still there? It has become so easy and cheap to hack almost anything. In my position, I see lots of attacks, and it’s just a question of time before we have really nice examples of things going radically wrong. Banks today have a philosophy that they know they’re not secure, they know that they get hacked, but it’s too expensive to solve, so they prefer to compensate those who have been exposed. Theft of ID is one example. Banks know that they are not secure, and that BankID or Swish leads to large-scale fraud. The solution would then be a stronger ID, with cryptography plus pin code and biometrics, for example, but they do not want to give up the strong position with the current BankID solution. Another problem is the banks’ limited interest in DNSSEC2— without it, a man-in-the-middle attack is possible, and thus theft of the customer’s ID. But if you want to support the trend with new players, new technology, new ways to produce your services, then you cannot afford large security problems. As I assess the market now, there’s a significant probability that we’re going to have fairly large security holes where your money and my money will disappear. I think it’s an underestimated issue. There’s too much focus on front-end app development and too little on fundamental information security activity to protect user data. And this will affect trust. It can influence a whole industry in a negative way since there might be large-scale effects. If you manage to enter a
The role of trust in emerging technologies 123 database, you can bring a lot with you. Recently, it became known that the NSA was able to read files and transactions in the Swift system,3 and my guess is that they can also make changes. Who says that others cannot do that too? Here we are talking about large-scale effects. What if banks cannot trust each other and clearing does not work? And there’s a fundamental issue— what is money today? It doesn’t exist. It’s just a number. Aerts did not agree that it’s easier and quicker to build trust today: No, I don’t think so. It goes up and down. There’s much inertia, and I would say that you trusted new services more 10 years ago than you do today. We’re a bit wounded today, too much has happened. Ten years ago, there were many optimistic people, a bit naïve, thinking that everything with the Internet was just positive. But we hadn’t yet been hit by what we know now—Snowden hadn’t reported everything that the US does behind the curtains, and we feel that there’s more surveillance today than there was 10 years ago. So I would say that there’s a steeper uphill today regarding trust. And if you get a situation where you remain longer with established players, then it will become more difficult for new players to get started. Personally, I believe that established brands such as Amazon and Facebook have built so many practices with their customers that it will be easier for them to integrate new services than it would be for a new player that arrives from outside to build and introduce new service, even if their service is better and more user-friendly. The large global players didn’t have that power 10 years ago. It was more open in one way. Aerts then discussed what would happen if a real security crisis arrives: People will be lost. They won’t know what to do. You don’t have any money in your wallet and you can’t trust that the money is in the bank, so you will become insecure. And how will people behave then—I don’t know. It might be that you will try to have several currencies at home. And the banking system might fail. Therefore, I’m positive about Bitcoin, and about blockchain technology too. From a security point of view, it’s more robust. If you want a technological solution that is difficult to attack, then that technology is better, since you don’t have any single point of failure, you have lots of instances controlling and calculating, being able to see if something is happening. And you can already see it—as soon as something happens, if there’s unrest on the market, the Bitcoin value increases. I think people use it as a last resort. Therefore, it’s only a question of time before it becomes more accepted too. Then I don’t know if there will be other kinds of cryptocurrencies—it doesn’t have to be Bitcoin. I think it’s fully possible that Amazon, Google, or Facebook provide their own cryptocurrency that would offer customers advantages over Bitcoin—a modern customer loyalty program that becomes an independent currency.
124 Mats Lewan Frank Schuil, CEO and co-founder at the Bitcoin-focused startup Safello As a CEO and co-founder of the Bitcoin-focused company Safello, Schuil discussed the topic of trust related to Safello’s business field: We realized from day one that trust was going to be the most important part of our business, hence the name “Safe Fellow—Safello.” And particularly, it related to our industry in 2013 when we started—there were a lot of hacks and scams, and headlines were centered on the negative aspects of cryptocurrencies. So the whole premise of our company was that we wanted to do it by the book and cooperate with existing financial institutions instead of fighting them. We chose to incorporate the company in Sweden since Sweden is a trusted country around the world, and we registered as a financial institution. We were able to get cooperation with one of the top four banks, Handelsbanken, and we then looked at the biggest failures in our industry, which regarded erosion of trust, typically when people were losing their money, their bitcoins. Therefore, we set up our company so that we’d never store our customers’ funds, but instead connect them to third-party suppliers for storage. So unlike pretty much all other players in the market, we have never lost any of our customers’ bitcoins, we have never been breached, and we have never been scammed. Schuil explained the dilemma with registering as a financial institution or not: On the one hand, registering as a financial institution gives you trust, but on the other it makes it harder to move in a certain direction and to be a global company. Our position and our strategic choice to be “the trusted company,” doing everything by the book, also meant that we are not able to compete in a lot of local geographies around us, where other companies are doing only fraud prevention to make sure that they don’t have losses on the book that could bankrupt them. And it’s fundamentally different following the European anti-money laundry legislation, doing the ID verification, doing the sanction list screening, doing the politically exposed person screening, the know your customer questionnaires, and all the checks and balances on the behavior of the customer, or just doing an implementation of fraud prevention. Schuil then discussed the importance of identity: Identity is going to be the most important thing going forward. Because the core of my ability to move around freely is identity and all the information that I have attached to my identity. Putting your information on the blockchain, making it decentralized, and giving partial access to relevant parties where you are in control, allows for a global ID, a global citizenship if you will.
The role of trust in emerging technologies 125 This empowers the customer, or the citizen, to independently move around the world—which could then become a borderless world. Bringing that back to something as simple as Mobile BankID, it’s geographically restricted in Sweden, it’s a collaboration between the banks, so it makes sense to them, but ultimately you need to have a global system for this. So I don’t know for the Nordics how they would transition to that, it’s kind of hard to see. Now it’s a great trust mechanism and it’s a new type of social login, a Facebook login but for financial institutions. But if you look at identity as a whole, it’s so much more. Discussion Cultural differences The concept of trust is a wide field, involving subtle human reactions and observations, which may vary not only between individuals, but also more significantly between different cultures. A good and thoughtworthy overview of such cultural differences is reported in the piece Getting to Si, Ja, Oui, Hai, and Da (Meyer, 2015), covering how different approaches with regard to trust in various parts of the world make negotiations and agreements between people from different countries more complicated. One fundamental distinction that Meyer makes is between cognitive and affective trust, where cognitive trust is based on the confidence you feel in someone’s accomplishments, skills, and reliability, whereas affective trust arises from feelings of emotional closeness, empathy, or friendship: In most emerging or newly emerged markets, from BRIC to Southeast Asia and Africa, negotiators are unlikely to trust their counterparts until an affective connection has been made. The same is true for most Middle Eastern and Mediterranean cultures. That may make negotiations challenging for taskoriented Americans, Australians, Brits, or Germans. (Meyer, 2015) He also notes that “Americans draw a sharp line between cognitive and affective trust. (. . .) Mixing the two risks conflict of interest and is viewed as unprofessional” (Meyer, 2015). Another aspect of trust reported in the article is that Americans often rely heavily on written contracts, making it possible to do business with people that you otherwise maybe would not trust, whereas in countries where the legal system is traditionally less reliable, and relationships carry more weight in business, written contracts are less frequent, and pushing a written contract could even be seen as a lack of trust. While the interviews reported in this paper show that our way of building trust is under influence from a strong technological shift brought by the Internet, and while visions of new Internet-based and automated mechanisms for building trust
126 Mats Lewan are explored, it is probably wise to keep in mind the cultural and geographical differences with regard to trust mentioned above. This should be particularly important since Internet-based solutions by their nature aim for global reach. The Trustnet One such global vision that has not been mentioned in the interviews is the concept of what could be called the Trustnet. The idea is touched upon in the book The Inevitable: Understanding The 12 Technological Forces That Will Shape Our Future by Kevin Kelly (2016). Kelly discusses the issue with tracking or surveillance, and comes to the conclusion that it is pointless to try to stop tracking since the Internet by its nature is a surveillance machine. Instead, he argues, we should embrace it, while trying to address what he sees as the main problem with today’s surveillance—asymmetry. Kelly notes that in a small village, everyone often knows everything about everybody, which makes surveillance less threatening—it is symmetric. And one way of achieving symmetry at a global scale in the highly effective detailed and continuous surveillance made possible by the Internet would be to create a Trustnet—a part of the Internet that you can only access if you publicly identify yourself electronically through a distributed system not controlled by any entity, state, or government. Since everyone has to be identified, individuals working for governmental agencies and authorities will also be identified, and the Trustnet thereby becomes symmetric, meaning that if anyone is tracking you, you will know who it is (and vice versa). The open question would then be if people would “vote with their feet” and move some of their online activities to the Trustnet or not, a movement that governments could not influence since the identification system is independent. One possible outcome is that people would spend their time online divided between the Trustnet, where people are identified, and the Internet, where people can be anonymous, depending on the character of their activities. At the other end of the identification scale, you could also consider the “Darknet,” for people wanting to be both anonymous and invisible. A little-discussed security issue with blockchain and the Internet There is an important security issue with blockchain technology, and actually with security on the Internet as a whole, which is surprisingly little discussed. Several of the interviewees in this report refer to blockchain technology as a potential framework for an independent platform for trust, and as such, blockchain applications could also be imagined for the independent identification system, which would be fundamental for the “Trustnet” discussed above. However, any such application must be designed with the existence of the following fundamental cryptographic issue in mind. Blockchain, as well as a vast majority of all secure applications on the Internet, such as online banking, encrypted connections to email services, and digital signatures, make use of asymmetric cryptography, which essentially means that
The role of trust in emerging technologies 127 encryption and decryption is made with two different keys, one of which might be public, as in public key cryptography. Asymmetric cryptography is based on the huge difficulty to solve certain mathematical problems with conventional computers, such as finding the prime factors of large integers. But in 1994, the American mathematician Peter Shor showed that such problems could be effectively solved by large quantum computers, using an algorithm now called Shor’s algorithm. The algorithm does not yet present any immediate security threat on the Internet since development of actual quantum computers is still in its infancy, but the discovery of Shor’s algorithm is generally considered to have increased the efforts for building quantum computers significantly. “Shor’s algorithm struck down like a bomb in the crypto world because in principle, it makes all today’s asymmetric cryptography insecure,” says Jonathan Jogenfors, researcher on quantum computing, blockchain, and Bitcoin at the University of Linköping, Sweden. Jogenfors continues: The impact on Bitcoin and on blockchains is that one of the cornerstones of the system—the digital signatures that guarantee the authenticity of the transactions—is falling apart. Anyone will be able to initiate transactions from any account and the system collapses. But you have to see this from an even bigger perspective. If [the public key cryptography systems] ECC and RSA fail, we will basically lose the Internet. We will not be able to guarantee secrecy and accuracy in encrypted communication, mobile phones can be hacked, healthcare data becomes public, etc. etc. Me and my colleagues here at LiU, and our partner in this field, Sectra, are worried about the future. Almost worse is the almost total lack of interest from society at large. Quantum computers are not available today; however, there is an incredible development currently going on, both in terms of excellence and width, in the efforts to building quantum computers. As an example, it can be noted that the European Commission is preparing the ground for the launch in 2018 of a EUR 1 billion flagship initiative on quantum technologies (European Commission, 2016). Jogenfors also pointed out that there is research going on at LiU on quantum resistant algorithms for asymmetric cryptography (disclaimer: after concluding his PhD in 2017, Jogenfors will start working as a research director at Sectra). Ownership of personal data Finally, one important aspect of trust that has been mentioned only briefly is about who has access to our personal data, and who controls it. In one part of his interview, which is not reported above, Danny Aerts gave his view on this topic. Aerts answered the question on what kind of regulation he thought will be important in the coming years: “What I find most interesting is regulation that
128 Mats Lewan would make you own your personal data, which would be good both for privacy reasons and for data protection, giving you the possibility to move your data where you want.” Aerts noted that personal data have a value, and that this value should benefit the user. He described a situation where a user brings his or her personal data to a kind of a membership service, or a broker, that will then continuously negotiate insurances, banking deals, transportation subscriptions, and other services with service providers, receiving an economic value from the service providers based on the richness of the user’s data, a value that would be given back to the user. “The regulation has to make it possible for me not to get locked in, but to keep my bubble of data and bring it with me. Then we can design enormously exciting services,” Aerts said. Conclusions There are good reasons to believe that the two hypotheses—that trust has a particular importance in the financial industry and also for FinTech startups, and that ways of building trust might be transformed due to Internet-based and digital technologies—are valid. The interviewees agreed that trust was fundamental in the financial industry and for FinTech startups. They also agreed on a number of seemingly natural steps to build initial trust—appointing well-known key persons to the board, starting collaborations with established brands, and aiming for appearance in relevant media—and in a longer perspective, always taking care of the customers and being reliable to them. Today, trust also depends increasingly on people’s friends and personal network, according to many of the interviewees. Some of them also made a distinction between different kinds of trust, such as trust in security and trust in institutions’ ability to give good advice, where banks, at least according to one of the interviewees, still enjoy much of the first kind and maybe less of the second. In contrast, Internet giants such as Amazon and Facebook were considered by the interviewees to enjoy high trust among young users, and some expected new financial services to be successfully introduced by those companies. Blockchain was highlighted as an interesting technology for building a neutral and independent infrastructure, but the divergent opinions among the interviewees on blockchain’s potential was significant and noteworthy. In a discussion, the cultural aspects of trust, the fundamental security issue with the entire Internet if large quantum computers can be built, and the concept of a Trustnet—a part of the Internet only accessible for users publicly identifying themselves, making anonymous tracking and surveillance impossible—were brought up. Lastly, another interview mentioned the importance of letting users own their personal data, bring it with them, and benefit from its value.
The role of trust in emerging technologies 129 Notes 1 Network effect—a phenomenon whereby a product or service gains additional value as more people use it. 2 DNSSEC is a suit of specifications to make the DNS system, which translates between ordinary web addresses and IP numbers, more secure. 3 SWIFT provides a network that enables financial institutions worldwide to make transactions between bank accounts. Bibliography European Commission, 2016. European Commission will launch €1 billion quantum technologies flagship. [online] Available at: https://ec.europa.eu/digital-single-market/en/ news/european-commission-will-launch-eu1-billion-quantum-technologies-flagship [Accessed August 25, 2017]. Kelly, K., 2016. The inevitable: Understanding the 12 technological forces that will shape our future. [online] Available at: www.worldcat.org/title/inevitable-understanding-the- 12-technological-forces-that-will-shape-our-future/oclc/925398078?referer=di&ht=ed ition [Accessed August 25, 2017]. Meyer, E., 2015. Getting to si, ja, oui, hai, and da. Harvard Business Review. [online] Available at: https://hbr.org/2015/12/getting-to-si-ja-oui-hai-and-da [Accessed August 25, 2017]. Oxford University Press, 2017. Trust – definition of trust in English. [online] Oxford Dictionaries. Available at: https://en.oxforddictionaries.com/definition/trust [Accessed August 25, 2017]. Stevenson, H.H. and Moldoveanu, M.C., 1995. The power of predictability. Harvard Business Review. [online] Available at: https://hbr.org/1995/07/the-power-of-predictability [Accessed August 25, 2017].
232 Michal Gromek and Alexandre Dubois Service Act (2010:751), it is not clear if the responsibility for the supervision falls to the Swedish Financial Supervisory Authority or the Swedish Consumer Agency (Finansinspektionen, 2015). In case an equity crowdfunding platform specifies to act as an intermediary and does not trade transferable securities in Sweden, the law8 does not require the platform to apply for a license or registrations, and is not supervised by financial supervision authorities (Crowdfunding Hub, 2016a). This is important for equity crowdfunding companies, because the Swedish Private Limited Liability Company, called Privat Aktiebolag (Privat AB), is the most common SME company type for legal entities in Sweden. Privat AB companies cannot advertise their desire to sell shares to the public, and can’t take in over 200 new shareholders in one share issue. For potential investors to view financial information, business plans, or financial forecasts of a Privat AB during an equity-based crowdfunding campaign on a Swedish platform without a MiFID9 license, the platform requires the user to become an “exclusive member” while signing up, even going so far as to require social media accounts. After logging in as an “exclusive member,” the investor has access to full information provided by the company that is seeking funding. The platform advertises no offerings from Privat AB companies—it “informs” the project is seeking funds (being informed about a share issue process is not considered advertisement). One of the leading platforms blocks the share issue process once the 200-investor limit is reached. If the company would like to continue to raise funds, the Privat AB board must decide to issue shares for a second or third time. In this way, regulating an intake of 200 investors can be enforced (Crowdfunding Hub, 2016b). It is unclear where the number of “200 new shareholders” originated; the Swedish Financial Supervision has considered the offering of a presale share purchase possibility, while sign-up for an issuance by up to 200 investors is regarded as a potential violation of the prohibition (Crowdfunding Hub, 2016a). Until now, there has not been an extensive study on crowdfunding platform investors, backers, and lenders to review who is actually participating and financing companies and individuals on crowdfunding platforms. If the result of such a study concludes that professional investors10 participate mostly in equity-based crowdfunding and crowdlending, their level of investor protection must be significantly lower than with consumers’ investments. Potential future scenarios of the national crowdfunding landscape in Sweden Assuming the Swedish crowdfunding market will follow the European trend and double yearly, it might continue to offer numerous benefits to Swedish small or medium enterprises, helping to close the capital gap in their funding needs (Massolution, 2015). Swedish crowdfunding remains relatively decentralized, as many players offer services in their niches. We have seen a range of companies enter the crowdfunding market in both 2016 and 2017, for example Co-owning.
Digital meetings 233 com, Peppins.se, and Tessin.se. This development has increased the public awareness of crowdfunding, but additionally increased the competition within the market. The crowdfunding market benefits from accessibility, but relies on the quality of the Internet infrastructure, and the digitalization of trust: •Synergy: In this scenario, the Swedish crowdfunding platforms might form an organization that would facilitate self-regulation on the platforms. Such an organization could enforce “coercive isomorphic change”11 in the industry (DiMaggio and Powell, 1983). Platforms would agree on types of valuation methods used for equity-based crowdfunding, scoring, and risk analysis models used for crowdlending. Such a development would bring a stronger transparency into the market and allow investors to directly compare different campaigns offered on various platforms. •Winner-takes-all market: In this scenario, crowdfunding platforms, both national and foreign, that have undergone the complex regulatory process of receiving an MiFID license or a banking license might attract significant institutional capital. This increase of capital might result in a merge and acquisition of platforms with complementary assets. Such a strategic alliance would increase the rate of new features and product development, and crystallize recognizable market leaders in crowdfunding. The scenario would work by the theory of network effects,12 as those merged platforms would have a bigger user base, and these users would attract a more significant number of new users in a snowball effect. •Participation of public funding: In this scenario, public authorities in Sweden would allocate funding alongside crowdfunding. This process would recognize crowdfunding as a tool to diminish the so-called market failures13 resulting from funding gap for entrepreneurs. This model is being executed in the UK. At the beginning of January 2017, Funding Circle, a crowdlending platform that allows entrepreneurs to seek funding, received GBP 40 million. The UK government, in the form of the British Business Bank, previously injected GBP 60 million into the platform. This funding has been distributed to around 10,000 businesses in the UK and allowed the bank to earn GBP 5 million in net interests over the past four years. Such cooperation allows the government to use the peer-to-peer side as a channel through which small businesses might be supported (Dunkley, 2016). The participation of public funding might be available to small businesses via the platform. Such a development might benefit the platforms, entrepreneurs, and the governmental institutions. •Active Financial Supervision (FI) 2.0 as a catalyst for growth and facilitator: In this scenario, the Financial Supervision would increase its position from the regulator to a moderator and facilitator. There would be an increase of the budget and active incorporation of new employees with a FinTech background. The goal of the FI 2.0 would be not only to regulate, but to promote, alternative finance. Financial Supervision 2.0 would take a membership seat in the Swedish FinTech associations, and provide guidelines for high industry standards. The regulator as “moderator of the market model”
234 Michal Gromek and Alexandre Dubois is being executed by the Securities Commission Malaysia in Kuala Lumpur. The Malaysian regulator is not only responsible for regulating the equity- and lending-based platforms, but additionally ensures that any imposed regulation is developing the market. The Securities Commission is facilitating roundtables with all platforms two times a year, and it hosts and promotes alternative finance conferences. It issues best practice guides and meets with representatives of platforms regularly (Securities Commission Malaysia, 2015). •Partnerships with traditional financial providers: In this scenario, facilitated in the US and the UK, banks would partner with crowdfunding platforms (Dunkley, 2016). In such a partnership, banks could use the platforms as deal generators and co-finance loans of the entrepreneurs that would fulfill the scoring criteria from banks. The platforms and entrepreneurs would benefit, as their campaign needs would be reached quicker, which will increase the cash flow liquidity in the market. •Provide other funding options to declined loan applications: This process has been initiated in the UK after the government issued a law that forces banks to ask small business owners to pass on their details to alternative finance providers (HM Treasury, 2014). According to a survey, only 3 percent of entrepreneurs were seeking alternative funding sources after being declined by a bank (Bank Referral Scheme, Small Business, Enterprise and Employment Act 2015).14 This non-financial intervention aimed to reduce the funding gaps of entrepreneurs. Banks that inform entrepreneurs about alternative sources of funding might potentially receive a commission from alternative financial providers. Notes 1 Funding gap—defines the amount of funding needed to continue to finance ongoing operations, which are not provided by entrepreneurs’ own cash, equity, or debt sources. 2 This platform is still operational but has no active projects online. An interview request remains without a response (accessed, March 1, 2017). 3 Multisided platform—serves as an intermediary for two or more groups of customers who are linked to indirect network effects (Evans and Noel, 2008). 4 As capital seekers have to repay the loan, their “working capital,” or “free capacity.” 5 Lindahl.se—Swedish-based law firm that facilitated the bankruptcy of Trustbuddy.se. 6 Low amount of IPO might be connected with the novelty of the market as equity crowdfunding investments have been possible in Sweden since 2013. 7 Tessin.se is a Swedish real estate crowdfunding platform. 8 According to the Securities Market Act (2007:528). 9 MiFID—the Markets in Financial Instruments Directive 2004/39/EC. 10 Professional investors are being defined as individuals who earn a significant amount of their income with earnings from their investments. 11 Coercive isomorphic change—involves the pressure that is being executed by the society on particular organizations, groups, or companies (DiMaggio and Powell, 1983). Such a development can lead to coercive isomorphism, where organizations might like to copy behavior. A crowdfunding industry organization in Sweden
Digital meetings 235 could agree on professional standards that would be imitated by players in the market without government intervention. 12 Network effect—a phenomenon in which a good service or a product increases its value with an increasing number of users. Airbnb or Uber might be a good example of the network effect. Platform services became more attractive while adding new hosts and travelers for Airbnb or drivers to the Uber network. As new users join the platforms, the services become more and more appealing, and still generate more new users, comparable to a snowball effect. 13 Market failures occur in the free market, when an allocation of resources shows signs of inefficient distribution in a particular market. 14 Bank Referral Scheme, Small Business, Enterprise and Employment Act 2015 available here: www.legislation.gov.uk/ukpga/2015/26/section/5/enacted [Accessed March 15, 2017]. Bibliography Agrawal, A., Catalini, C., and Goldfarb, A., 2011. The geography of crowdfunding. Cambridge, MA: National Bureau of Economic Research. Agrawal, A., Catalini, C., and Goldfarb, A., 2015. Crowdfunding: Geography, social networks, and the timing of investment decisions. Journal of Economics & Management Strategy, 24(2), pp.253–274. Ahlers, G.K.C., Cumming, D., Günther, C., and Schweizer, D., 2015. Signaling in equity crowdfunding. Entrepreneurship Theory and Practice, 39(4), pp.955–980. Baeck, P., Collins, L., and Zhang, B., 2014. The UK alternative finance industry report 2014. [online] Available at: www.nesta.org.uk [Accessed August 25, 2017]. Busch, C. and Mak, V., 2016. Peer-to-peer lending in the European Union. Journal of European Consumer and Market, 5(4), pp.181–181. Buysere, D.K., Gajda, O., Kleverlaan, R., and Marom, D., 2012. A framework for european crowdfunding. [online] Available at: http://www.academia.edu/11377521/ FRAMEWORK_EU_CROWDFUNDING [Accessed January 6, 2018]. CIA, 2017a. World Factbook: Congo. [online] Available at: https://www.cia.gov/library/ publications/resources/the-world-factbook/geos/cf.html [Accessed January 6, 2018]. CIA, 2017b. World Factbook: Monaco. [online] Available at: https://www.cia. gov/library/publications/resources/the-world-factbook/geos/mn.html [Accessed January 6, 2018]. Crowdfunding Hub, 2016a. Crowdfunding crossing borders. [online] Available at: www. fglawyersamsterdam.com/wp-content/uploads/2016/03/20160331-Crowdfunding- Crossing-Borders-Report.pdf [Accessed August 25, 2017]. Crowdfunding Hub, 2016b. Current state of crowdfunding in Europe. [online] Available at: www.sbs.ox.ac.uk/sites/default/files/Entrepreneurship_Centre/Docs/OxEPR2/currentstate-crowdfunding-europe-2016.pdf [Accessed August 25, 2017]. Cumming, D., Leboeuf, G., and Schwienbacher, A., 2014. Crowdfunding models: Keep-it- all vs. all-or-nothing. EUROFIDAI-AFFI paper (Vol.10). [online] Available at: http:// leeds-faculty.colorado.edu/Bhagat/CrowdfundingModels-KeppItAll-AllorNothing.pdf [Accessed August 25, 2017]. Cumming, D., Hornuf, L., Karami, M., and Schweizer, D., 2016. Disentangling crowdfunding from fraudfunding. [online] Max Planck Institute for Innovation & Competition. Available at: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2828919 [Accessed August 25, 2017].
236 Michal Gromek and Alexandre Dubois Daboczy, D., 2016. Crowdfunding overview: FundedByMe doubles total money raised. [online] FundedByMe. Available at: http://blog.fundedbyme.com/ [Accessed August 25, 2017]. DiMaggio, P.J. and Powell, W.W., 1983. The iron cage revisited: Institutional isomorphism and collective rationality in organizational fields. American Sociological Review, 48(2), pp.147–160. Dunkley, E., 2016. Santander UK enters partnership with crowdfunder. Financial Times. [online] Available at: www.ft.com/content/5ee92158-8945-11e6-8cb7-e7ada1d123b1 [Accessed August 25, 2017]. European Commission, 2013. Crowdfunding in the EU: Exploring the added value of potential EU action. Consultation Document. [online] Available at: http://ec.europa. eu/finance/consultations/2013/Crowdfunding/docs/consultation-document_en.pdf [Accessed August 25, 2017]. European Commission, 2016a. SME performance review. [online] Available at: http:// ec.europa.eu/growth/smes/business-friendly-environment/performance-review-2016_ pl [Accessed August 25, 2017]. European Commission, 2016b. Commission staff working document: Report on crowdfunding in the EU capital markets union. [online] Available at: https://ec.europa.eu/info/ system/files/crowdfunding-report-03052016_en.pdf [Accessed September 13, 2017]. Evans, D.S. and Noel, M.D., 2008. The analysis of mergers that involve multisided platform businesses. Journal of Competition Law & Economics, 4(3), pp.663–695. Finansinspektionen, 2015. Crowdfunding in Sweden: An overview. [online] Available at: www.fi.se/en/published/reports/reports/2015/crowdfunding-in-sweden [Accessed December 6, 2017]. Gierczak, M., Bretschneider, U., and Leimeister, J., 2014. Is all that glitters gold? Exploring the effects of perceived risk on backing behavior in reward-based crowdfunding. [online] Available at: http://aisel.aisnet.org/icis2014/proceedings/EBusiness/43/ [Accessed August 25, 2017]. Gierczak, M., Bretschneider, U., Haas, P., Blohm, I., and Leimeister, J.M., 2016. Crowdfunding: Outlining the new era of fundraising. In: D. Brüntje and O. Gadja, eds. Crowdfunding in Europe: FGF studies in small business and entrepreneurship. Cham: Springer, pp.7–23. Hemer, J., Schneider, U., Dornbusch, F., and Frey, S., 2011. Crowdfunding und andere Formen informeller Mikrofinanzierung in der Projekt- und Innovationsfinanzierung [Crowdfunding and other types of informal Microfinance possibilities in project and innovation finance]. Stuttgart: Fraunhofer Verlag. HM Treasury, 2014. Consultation outcome, SME finance: Help to match SMEs rejected for finance with alternative lenders. [online] Available at: www.gov.uk/government/ consultations/sme-finance-help-to-match-smes-rejected-for-finance-with-alternative- lenders/sme-finance-help-to-match-smes-rejected-for-finance-with-alternative-lenders [Accessed September 13, 2017]. Kickstarter, 2017. Kickstarter stats. [online] Available at: www.kickstarter.com/help/stats [Accessed September 13, 2017]. Lindahl, 2017. Questions about TrustBuddy’s bankruptcy. [online] Available at: https:// www.lindahl.se/en/latest-news/cases-and-transactions/2015/lindahl-manages-the- bankruptcy-in-trustbuddy [Accessed January 6, 2018]. Massolution, 2015. The Crowdfunding Industry Report 2015. [online] Available at: http://reports.crowdsourcing.org/index.php?route=product/product&product_id=54 [Accessed December 6, 2017].
Digital meetings 237 Mollick, E., 2014. The dynamics of crowdfunding: An exploratory study. Journal of Business Venturing, 29(1), pp.1–16. Mollick, E., 2016. Containing multitudes: The many impacts of Kickstarter funding. [online] Available at: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2808000 [Accessed August 25, 2017]. Rao, D., 2013. Why 99.95% of entrepreneurs should stop wasting time seeking venture capital. Forbes. [online] Available at: www.forbes.com/sites/dileeprao/2013/07/22/ why-99-95-of-entrepreneurs-should-stop-wasting-time-seeking-venture-capital/ #647f840b46eb [Accessed August 25, 2017]. Riedl, C., Blohm, I., Leimeister, J.M., and Krcmar, H., 2013. The effect of rating scales on decision quality and user attitudes in online innovation communities. International Journal of Electronic Commerce, 17(3), pp.7–36. Salomon, V., 2016. Emergent models of financial intermediation for innovative companies: from venture capital to crowdinvesting platforms in Switzerland. Venture Capital, 18(1), pp.21–41. Securities Commission Malaysia, 2015. Guidelines on recognized markets. [online] Available at: www.sc.com.my/wp-content/uploads/eng/html/resources/guidelines/recognizedmkt/ guidelines_recognizedMarket_160413.pdf [Accessed August 25, 2017]. Tessin, 2017. Building the leading platform for digital real estate financing: Q1 2017. [Unpublished Electronic Presentation]. Stockholm: Tessin. World Bank, 2013. Crowdfunding’s potential for the developing world. [online] pp.1–104. Available at: www.infodev.org/infodev-files/wb_crowdfundingreport-v12.pdf [Accessed September 13, 2017].
13 The payment landscape in Sweden Niklas Arvidsson Introduction Sweden was one of the first countries to launch government-supported cash, and may become one of the first to stop issuing government-supported cash. The development since 2012 has been very fast in terms of a reduction of the use of cash and an increased use of mobile payment services for peer-to-peer (P2P) payments, but there has also been an increase in the number of new firms in the payment sector and the number of alternative services that are on the market. A likely next step in this development is the introduction of contactless cards—which hitherto have been absent on the Swedish market—and other mobile payment services. This is a step in the progression toward more mobile payments, which also includes person-to-business (P2B) payments. We can also foresee a continued decrease in the use of cash, which is discussed in more detail in Chapter 4 in this volume. This chapter concludes by discussing critical factors that are the most likely to affect the development of retail payments in Sweden in the coming years. The recent history of payment services in Sweden The twentieth century use of payment services in Sweden was deeply influenced by the strong growth of the Swedish economy after World War II as industrialization was strengthened and international trade grew. Employment was high and real wages grew, which led to a demand for banking services. In the mid- 1900s, the use of cash was widespread, even though electronic payment services were established and gradually growing in popularity. In the 1960s, banks had made efforts to make transaction processing more efficient via digitalization, and influenced employers, unions, and workers to start accepting that salaries and wages were to be paid electronically directly to employees’ bank accounts instead of being paid in cash at the employers’ offices. It was an easy sell for the banks since employers saved costs, the banks got new customers, unions agreed as long as banks did not charge consumers for cash withdrawals, and employees liked it. This transformation laid the foundation for the electronic banking system for retail payments that we have to this day, where the bank account is the centerpiece for making and receiving payments. Another critical
The payment landscape in Sweden 239 transformation was made in the 1980s and 1990s when card payments started to become a reality for not only the wealthy, but made available to everyone. The use of cards was low in the early stages, but grew incrementally faster in the latter parts of the 1990s (Nyberg and Guibourg, 2003) and became a dominant part of retail payments. Checks were phased out in the 1990s as banks started to charge fees for check handling (Arvidsson, 2013). There was also an attempt by banks to launch prepaid cards, so-called “cash cards,” as a less costly alternative to debit and credit cards. However, these cash cards never gained popularity among merchants and consumers, and the project pulled to a halt. Although the early 2000s saw high expectations for the establishment of mobile payments, it would not be until 2014 for these services to become conventional in the market. The landscape for retail payments had become dominated by card payments (primarily debit cards), even if cash was still quite popular, as discussed by Arvidsson (2013). However, this was about to take a sharp turn. In the mid-2000s, there was an increase in cash-related robberies of banks, merchants, cash depots, and even of the public transportation system. Hence, efforts were made seeking to reduce the use of cash in Sweden. Lobbying campaigns against cash, such as “Kontantfritt.nu,” as well as action by banks and others, such as “Tryggare rörelsen,” started a movement toward reducing cash. Prominent actors in these movements were unions in public transportation, banks, and merchants. Unions and merchants acted primarily from a work environment perspective, and banks both saw the work environment issue but also had a genuine business interest in reducing the use of cash. Banks did not have revenues connected to cash, and would be happy if cash payments were replaced by card payments—an area where banks showed good profitability. The most spectacular robbery was the so-called “helicopter robbery” of a cash depot in Stockholm on September 23, 2009 (Bonnier, 2017). This was a rigorously planned and well-executed robbery of a cash depot where the robbers used a helicopter, explosives, machine guns, and other devices to steal SEK 39 million (approximately EUR 5 million at that time). The robbers used fake bombs to hinder police helicopters from taking off, various tools to stop police cars, and stolen getaway cars. The robbers then dumped the money and landed the helicopter in a remote area where they finally set it ablaze. All robbers, save one, would ultimately escape with the money. In retrospect, it is likely that the use of cash peaked in 2007 in Sweden, when the nominal value of cash in circulation was at its highest level of around SEK 110 billion (Arvidsson, 2013). This figure has decreased rapidly since then, and the nominal value of cash in circulation in Sweden is well below SEK 50 billion in November 2017. The number has decreased by 50 percent in 10 years! Paradoxically, it was at this peak that the Swedish Central Bank, the Riksbank, decided to launch new bills and coins in Sweden during the years 2015–2017. The decision was at the time well motivated by efforts to avoid counterfeit money and to make cash handling more efficient. To this end, the development during the last 10 years was not possible to predict.
240 Niklas Arvidsson Another factor reducing the interest in cash payments from the merchant perspective was the bankruptcy and illegal activities by the cash-in-transit service company Panaxia. The company filed for bankruptcy in September 2012 due to liquidity problems, as well as the subsequent illegal use of their clients’ money in order to cover their own expenses. Some merchants, such as grocery stores, petrol stations, etc., lost significant amounts of money (with some actors losing more than SEK 100 million, or around EUR 11 million at that time). The top managers of the company were later convicted to prison for fraud by a court of law (Svea Hovrätt, 2015). These events made merchants start considering stopping accepting cash payments, an act that is not illegal according to Swedish law. This, in turn, was accentuated by the increase in fees for cash-handling services as competition decreased and the market became dominated by two players. Mobile payment services were anticipated to start growing already in the early 2000s, but given problems related to learning processes (Arvidsson, 2014b) and a lack of interoperable service platforms (Apanasevic, Markendahl and Arvidsson, 2016), they did not start to make a strong appearance until 2012. The growth of new payment services after 2012 has been remarkable. This is attributed to several factors, such as the advancement of new technologies and new competition, along with the growth of an e-commerce industry. Furthermore, there has been a need for new payment services while interest by consumers has increased (especially so among younger consumers), aided by the strong use of apps and smartphones, as well as a general trend toward digitalization in Sweden. One essential new mobile payment service, Swish, was launched by banks on December 12 at 00:12 in 2012 (Arvidsson, 2015). Swish enabled realtime transactions between consumers (person-to-person payments) without fees and became a natural and efficient substitute to cash for payments between consumers. Another important service that has led to a reduction of cash payments in Sweden is that of iZettle, which is a card payment service based on mobile point-of-sale terminals that are connected to smartphones or tablets. It made it possible to relatively easily start accepting card payments in situations where cash payments had been dominating previously, such as in sports arenas, flea markets, temporary stands, and smaller merchants. Another factor that influenced Swedish society to start moving toward the reduction of cash usage was identified in macroeconomic studies showing that the social costs of cash are higher than the social costs of card payments. In a study by the Riksbank (Segendorf and Jansson, 2012), it was shown that the social costs of a card payment were estimated to be SEK 5.55, while the social costs of a cash payment in 2013 were estimated to be SEK 8.32. The study concluded that it would be good for the society as a whole if Sweden reduced its use of cash payments and replaced them by primarily debit card payments. Even if politicians in Sweden were not actively engaged in this issue, these studies are likely to have strengthened the idea that reduction of cash usage is advantageous from a macroeconomic perspective. It should be noted, however, that Swedish politicians have emphasized that the actual use of cash is to be decided by the demand for cash from banks, merchants, and ultimately consumers. The responsibility
The payment landscape in Sweden 241 for the Riksbank to make sure cash services are provided is limited to cases and situations where the market does not provide such services. It is consequently primarily a reduction of demand for cash by consumers, merchants, and banks that explains the decreased use of cash. In recent years, we have seen an intensified debate about the need to ensure cash does not disappear. In 2014, there was an attempt to promote an entirely cash-free music festival (the Bråvalla festival), which failed and led many to doubt the benefits of an entirely cash-free society. The festival later succeeded in becoming cash-free but was cancelled for other reasons. A strong move toward keeping cash in Sweden has instead been made by the so-called “cash uprising” led by the former chief of police Björn Eriksson, who argues that cash payments must be protected and kept as a well-functioning payment service in Sweden (Kontantupproret, 2015). The national organizations for senior citizens, PRO1 and SPF,2 also support this initiative. In 2016, the initiative led to a hearing on cash in the Swedish parliament, and one of the political opposition parties, the Center Party, made a statement saying they should act in the political arena to make sure cash services will be provided in Sweden in the future. The actual introduction of new bills and coins in Sweden in 2015–2017, which was decided in 2008, has led to a paradoxical development. Instead of these new bills and coins being welcomed by consumers, merchants, and banks, it has led to a situation where many have stopped using cash. Banks have reduced their number of retail offices that offer cash-handling services, and less than 50 percent of bank offices provide cash handling today (Ehrenberg and Jansson, 2016). More and more merchants have stopped accepting cash payments since the new bills and coins necessitate investments in new cash registers and other equipment, which, together with other factors such as fees for cash handling and risk of robberies, has led many merchants to say no to cash. This is also facilitated by new, alternative services. Consumers have continued to reduce their use of cash during recent years, and the launch of new cash in Sweden did not change this downward trend. The Swedish payment system today There is a long tradition of increasing digitalization of payments in Sweden that started as early as the middle of the twentieth century but has been increasing significantly in speed and coverage in the last decade. The success of substitutes to cash, such as Swish and iZettle, combined with other drivers of change, such as smartphones, bank strategies, the rise of FinTech, new regulations, and other factors, has meant that the last non-digital part of the system, cash, is facing a rapid decline and is potentially becoming marginalized. The introduction of Swedish cash supported by the state in 1668 (see Chapter 4 in this volume) was a successful initiative that is likely to have reached its peak at the end of 2007, when the value of cash in circulation reached its highest level. The decrease in the use of cash has been substantial throughout the past 10 years, and appears to be steadily decreasing in a consistent pattern.
248 Niklas Arvidsson payments” (Andersen and Gladov, 2015; ECB, 2015; Bank of England, 2017). There have also been a number of seminars on these issues, for instance related to work by SEPA on instant payments (EPC, 2017). Another critical factor for changes in the near future is the combined effect of national and international regulatory changes related to payment services. There are several regulatory changes that are likely to change the payment system in the coming years. Much of this comes from the European Union, where the Commission (European Commission, 2003) already in 2003 articulated their ambition to create an inner market for payment services in the EU. They had concluded that there were too many obstacles for a common market, and thus aimed to reduce these obstacles through regulation. It should at the same time be noted that the Swedish market was at the forefront of many of these areas of concern. One important first action was the Payment Services Directive that was implemented in Sweden in 2010 (Finansdepartementet, 2010), which aimed to stimulate competition by introducing new legal entities for payment service provisions that would make it easier to start competing with the traditional providers. This is also what we have seen happen in Sweden. The Second Payment Services Directive and its complementary parts, which is yet to be fully implemented in Sweden, continues the efforts to create a common market characterized by more intense competition and lower fees for payment services. The second directive intends to cover aspects that the first did not, as well as cover new aspects that has risen due to technological developments and other changes in the business system around payment services. The overall regulatory work where the second PSD is one part focuses on issues such as interchange fee regulation (i.e., caps on multilateral interchange fees for card transactions), payment accounts directive (i.e., the rights to accounts as well as responsibilities and protection when using payment accounts), and surcharging (i.e., the possibility for merchants to add payments fees to consumers when they use certain types of cards when making a payment) (Arvidsson, 2016). The new regulation also involves a stronger consumer protection provision than before. One additional and integral part in the new payment regulations focuses on new actors and legal entities in the area of payments. The directive makes it easier for companies to start new legal entities and services such as payment initiation service providers (PISPs) and account information services providers (AISPs) with the aim that these will lead to increased competition and better value for customers. A PISP could be a service where the provider has an agreement with a consumer that the provider can withdraw money from the consumer’s bank account for certain types of payments, and where the bank must allow this to happen. As discussed above, the bank account is the backbone of the payment system, and banks therefore have a unique access to consumers that other payment service providers do not. Through PISP services, the benefit and uncompetitive aspects of this unique access by banks will be reduced. One example in Sweden of such a provider is Trustly, which offers a service where a consumer may allow Trustly to access their bank account for payments related to e-commerce. The other service—AISP—builds on a similar setup, but is focused on access to information
The payment landscape in Sweden 249 about the consumer’s bank account. The overall aim is to reduce the banks’ unique position in the payment system related to the fact that they manage the backbone of the system—the bank accounts. It should be noted that there are challenges arising from implementing these changes, since it must be made clear who takes the risks and responsibilities if the system and its services are misused or even abused. Is the risk then to be taken by banks, service providers, or consumers? The ambition builds on prerequisites that the overall system as such has clear specifications of risk and responsibilities; that all providers have the needed licenses, as well as the needed capabilities, intentions, and systems to provide services; and that all users are knowledgeable and in demand of these services. It should also be noted that there will be additional regulatory changes related to cash handling as well as a likely revision of the Central Bank Law in the near future. Implications from these changes are most likely a stronger and clearer definition of responsibilities around cash-in-transit services, but also an intensified debate on the role of cash in Sweden. Even if the focus in the study of the Central Bank Law (Finansdepartementet, 2016) concerns financial and monetary policies, there will also be a discussion of the role of cash as legal tender in Sweden due to increasing social problems related to the decline in cash-handling services in Sweden (Ehrenberg and Jansson, 2016). Concluding remarks and summary To sum up this chapter becomes a task that is simple in one way, but difficult in another. One conclusion is that the payment system in Sweden is characterized by high degrees of change, where a combination of simultaneous change in a number of factors—social, economic, technological, political, and legal—makes it difficult to foresee what may happen in the future. The main challenge is to make sure this situation does not end up in inertia (Arvidsson, 2014a), but instead becomes a process characterized by energetic startups, new competition, and demanding users. In the near future, we will likely witness contactless cards becoming more prevalent, even if their main role is to primarily transform the system into using mobile payments to a larger extent. The contactless card may become the factor that pushes merchants to invest in point-of-sale terminals, as well as educating their employees to use these technologies, while at the same time educating consumers to start paying without inserting their cards, and using chip and PIN7 identification and verification. Contactless cards are likely to become important transitional objects on the road to contactless payments based on phone apps (even if still based on the technological systems for card payments). This will of course also be a way for card operators (e.g., Visa and Mastercard), as well as large retail banks, to continue being dominating players in the payment industry. Another and more drastic—as well as unpredictable—pattern of change relates to the new payment regulations in combination with new technologies. The relative reduction of legal difficulties to start selling payment services8 will most likely mean that new actors from the FinTech industry will launch their services and subsequently start competing with banks. It is not unlikely, of course, that we will
250 Niklas Arvidsson see more cooperation between banks and FinTech firms, as well as FinTech firms becoming/transforming into banks, one example being Klarna (TT News Agency, 2017). We will see more services—some that compete directly with banks’ payment services and some that complement them—and ultimately more actors. Merchants and consumers are then likely to meet lower fees, while at the same time facing the challenge of knowing which service and which service provider to select and use. In the end, it will be these choices by merchants and consumers that determine the effects of the new regulations. The challenges are many, but the opportunities are likely to outweigh them. Many attempts to revolutionize the payment industry will presumably be made where, as always, some will fail and be forgotten, while others may become front-running firms in an era of a fully digitalized payment system. On a final note, it is likely that some of the winners will come from Sweden! Notes 1 www.pro.se. 2 www.spfseniorerna.se. 3 Based on data from the company register of Finansinspektionen. It should be noted that there were, in addition, 20 companies licensed as payment service providers that operated as cooperative real estate providers, and therefore not active on the payment service markets. The number also excludes Bankgirocentralen, which is licensed as a clearing organization. 4 This is a term used in psychological studies to explain the role an object may have for changed behaviors by humans. 5 This is a digital platform enabling real-time clearing and settlement of peer-to-peer payments done via the service Swish provided by the banks. 6 PMB—payment message broker service. 7 Chip and PIN is an abbreviation for cards where a computer chip stores all information around the transaction, the payer, and the payee, and where verification of the transaction is done by a PIN code known by the payer. 8 Both PSD1 and PSD2, with the launch of payment institutions, payment initiation service providers, and account information service providers, will make it easier to start competing with the traditional banks. It can also be mentioned that other directives such as the e-money directive and work aiming to make it easier to switch banks, lead in this direction. Bibliography Andersen, A.T. and Gladov, T.M., 2015. Initial experience with instant payments. [online] Available at: www.nationalbanken.dk/en/publications/Documents/2015/03/Initial%20 Experience%20with%20Instant%20Payments_Mon1-15_UK.pdf#search=Initial%20 experience%20with%20instant%20payments [Accessed January 9, 2018]. Apanasevic, T., Markendahl, J., and Arvidsson, N., 2016. Stakeholders’ expectations of mobile payment in retail: Lessons from Sweden. International Journal of Bank Marketing, 34(1), pp.37–61. Arvidsson, N., 2013. Det kontantlösa samhället: rapport från ett forskningsprojekt [The cashless society: Report from a research project]. [online] Available at: www. worldcat.org/title/det-kontantlosa-samhallet-rapport-fran-ett-forskningsprojekt/ oclc/834900208&referer=brief_results [Accessed August 26, 2017].
The payment landscape in Sweden 251 Arvidsson, N., 2014a. A study of turbulence in the Swedish payment system: Is there a way forward? Foresight, 16(5), pp.462–482. Arvidsson, N., 2014b. Consumer attitudes on mobile payment services: Results from a proof of concept test. International Journal of Bank Marketing, 32(2), pp.150–170. Arvidsson, N., 2015. Emergence of an ICT-based disruptive mobile payment service. In: E. Giertz, A. Rickne, and P. Rouvinen, eds. Small and beautiful: The ICT success of Finland & Sweden. [online] VINNOVA, pp.200–208. Available at: https://www. vinnova.se/publikationer/small-and-beautiful [Accessed January 9, 2018]. Arvidsson, N., 2016. Framväxten av mobila, elektroniska betalningstjänster i Sverige. [online] Available at: www.konkurrensverket.se/globalassets/publikationer/uppdrags forskning/forsk-rapport_2016-4.pdf [Accessed August 27, 2017]. Bank of England, 2017. Bank of England. [online] Available at: https://www.bankofengland. co.uk/research [Accessed January 9, 2018]. Bankgirot, 2017. Bankgirot’s two payment systems. [online] Available at: www. bankgirot.se/en/about-bankgirot/our-offer/payment-systems/ [Accessed August 27, 2017]. Bonnier, J., 2017. Helikopterrånet [The helicopter robbery]. Stockholm, Sweden: Albert Bonniers Förlag. European Commission, 2003. Communication from the commission to the council and the European Parliament concerning a New Legal Framework for Payments in the Internal Market (Consultative Document). 2. Consultive Document. [online] Available at: http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52003DC0718& from=SV [Accessed January 9, 2018]. Contactless Forum, 2017. Antal kort och terminaler med kontaktlös funktion [Number of cards and terminals with contactless technology]. [online] Available at: http://contact less.se/bild-ett/ [Accessed August 27, 2017]. ECB, 2015. Instant payments. [online] Available at: www.ecb.europa.eu/paym/retpaym/ instant/html/index.en.html [Accessed August 27, 2017]. Ehrenberg, S. and Jansson, J., 2016. Bevakning av grundläggande betaltjänster 2016 [Monitoring the basic payment solutions 2016]. [online] Available at: www.lans styrelsen.se/Dalarna/SiteCollectionDocuments/Sv/Publikationer/Rapporter-2016/ Betaltjanster-2016.pdf [Accessed August 27, 2017]. EPC, 2017. SEPA instant payments. [online] Available at: https://www.europeanpayments council.eu [Accessed January 9, 2018]. Finansdepartementet [Swedish Ministry of Finance], 2010. Lag (2010:751) om betaltjänster [Legal act (2010:751) on payment services]. [online] Available at: www.riksdagen. se/sv/dokument-lagar/dokument/svensk-forfattningssamling/lag-2010751-om-betalt janster_sfs-2010-751 [Accessed August 27, 2017]. Finansdepartementet [Swedish Ministry of Finance], 2016. Översyn av det penningpolitiska ramverket och riksbankslagen Dir. 2016:114 [Review of the monetary framework and the Riksbank act Dir:114]. [online] Available at: www.regeringen.se/4b02ef/contentassets /0f4c260cae774a999ae0e5b280fd6926/oversyn-av-det-penningpolitiska-ramverket-och- riksbankslagen-dir.-2016114 [Accessed August 27, 2017]. Kontantupproret, 2015. Kontantupproret. [online] Available at: www.kontantupproret.se/ wp-content/uploads/2014/11/Skrivelse-till-Riksbanksfullmäktige-från-Kontantupproret- dec-2015.pdf [Accessed August 27, 2017].
252 Niklas Arvidsson Litt, C.J., 1986. Theories of transitional object attachment: An overview. International Journal of Behavioral Development, 9(3), pp.383–399. Nyberg, L. and Guibourg, G., 2003. Card payments in Sweden. Sveriges Riksbank Economic Review, [online] (2), pp.29–40. Available at: www.riksbank.se/Upload/Dokument_riks bank/Kat_publicerat/Artiklar_PV/er03_2_artikel2.pdf [Accessed August 27, 2017]. Segendorf, B. and Jansson, T., 2012. The cost of consumer payments in Sweden. Sveriges Riksbank Working Paper Series, [online] 262, p.58. Available at: www. riksbank.se/documents/rapporter/working_papers/2012/rap_wp262_120619.pdf [Accessed August 27, 2017]. Svea Hovrätt [Svea Court of Appeal], 2015. Dom i det s.k. Panaxiamålet [Verdict in the so-called Panaxia case]. [online] Available at: www.svea.se/Om-Svea-hovratt/ Nyheter-fran-Svea-hovratt/Dom-i-det-sk-Panaxiamalet/ [Accessed August 27, 2017]. Sveriges Riksbank [The Riksbank], 2015. Den svenska finansmarknaden 2015 [The Swedish financial market 2015]. [online] Available at: www.riksbank.se/Documents/ Rapporter/Finansmarknaden/2015/rap_finansm_150813_sve.pdf [Accessed November 28, 2017]. Sveriges Riksbank [The Riksbank], 2016. Den svenska finansmarknaden 2016 [The Swedish financial market 2016]. [online] Available at: www.riksbank.se/ Documents/Rapporter/Finansmarknaden/2016/rap_finansm_160831_sve.pdf [Accessed November 28, 2017]. Swish, 2017. Swish. [online] Available at: www.getswish.se [Accessed August 27, 2017]. TT News Agency, 2017. Klarna – Europas största bolag inom fintech [Klarna—Europe’s largest FinTech company]. [online] SvD. Available at: www.svd.se/klarna--europas- storsta-bolag-inom-fintech [Accessed November 28, 2017].
14 Introduction to the robo-advisory industry in Sweden Agnė Mačijauskaitė Introduction to robo-advisory With the advent of the Internet and computers, organizations throughout the financial industry have been forced to partly adjust or even completely change their work practices to stay competitive. The new robo-advisory industry was born in the US in 2008 as a complement to the traditional global SEK 650 trillion wealth management industry, in what one today might consider an inflection point for “business as usual” (Kocianski, 2016). According to the Swedish Financial Supervisory Authority (FSA), robo-advisors are defined as companies that provide personal advice on financial instruments with limited human involvement (Olivendahl and Thorsbrink, 2016). As of 2017, the robo-advisory companies mainly provide automated and algorithm-based asset allocation and securities, rebalancing services in accordance with an investor’s risk profile and preferences (Sironi, 2016). In addition to algorithm-based platforms, robo-advisors are usually characterized by being low-cost, available to a large share of the population, and easy to use. In the global market, the robo-advisory industry is just starting to take off and, with further development of more powerful computers and artificial intelligence, it is expected to significantly impact the remaining areas of wealth management (Sironi, 2016). This chapter provides an overall assessment of the even younger robo-advisory industry in Sweden. In the first part, I will describe the general trends in the overall market that create the vacuum for robo-advisors to enter. I reflect on the key drivers of the industry, focusing on three main factors: investor behavior, technological development, and the current structure of the financial and regulatory environment. I then take a closer look at how robo-advisory companies work and describe the most common business models currently found in the market. I then discuss the already visible directions and implications of the automated advisory market in Sweden, which are supported by case examples of four selected companies. The chapter ends with an assessment of expected future developments in the industry and subsequent effects on traditional wealth management. Mixed environment surrounding robo-advisory In general, FinTech companies specialize in targeting one or a few traditional financial industry areas (Sironi, 2016). As mentioned before, robo-advisors
[Document text truncated for crawler view.]