Blockchain Framework and Guidance

The Information Systems Audit and Control Association (ISACA) just released the ‘Blockchain Framework and Guidance’ publication.

“Blockchain Framework and Guidance provides an overview of blockchain, including history, types, benefits, features, concepts and use cases, and offers a framework for the adoption of blockchain technology across enterprises. The ISACA blockchain framework provides foundational information, practical guidance and proposed tools for proper blockchain implementation, governance, security, audit and assurance. The unique aspects of blockchain technology and the blockchain touchpoints with existing technology ecosystems are explained in detail. In addition, Blockchain Framework and Guidance maps existing technology implementation disciplines into the process of blockchain adoption.”

As a member of ISACA’s Emerging Technology Advisory Group, I served as an Expert Reviewer of this document.

You can access this excellent resource through ISACA’s Bookstore.

What the Government of Barbados Needs to Do to Get Fintech Right

There’s a common misconception that IT governance, risk and control (GRC) professionals like myself impose unreasonable demands on those trying to innovate and deliver human, social and economic benefits to society. But this is the furthest thing from the truth – our role is to ensure that those who are delivering technological solutions understand the risks and impacts associated with their IT platforms, and mitigate them in an adequate, effective, and sustainable manner.

The aforementioned point is key as I will go on to explore the privacy, security, and socio-economic implications of two recent announcements by the Government of Barbados pertaining to the implementation of Blockchain-related technology in the country. In a September 19th article titled ‘E-currency pilot coming’, it was stated that Prime Minister Mia Mottley “did not give details of the planned mobile wallet pilot project or when it would begin but gave the assurance that it would not be done in a reckless manner.” Barbados Today published an article on September 25th which stated ‘BSE to begin crypto-trading’, essentially heralding the decision of the Barbados Stock Exchange to trade in security tokens or crypto assets.

Given my intimate knowledge of privacy and security weaknesses in both the public and private sectors, the PM’s words do not instill in me any great confidence around the robustness of the security controls that will accompany these projects. The implementation of e-currency is a complex undertaking, that if not done correctly, can have a material impact on the country’s already weakened economic position. Security tokens are an extremely nascent solution with a lot of potential, but that doesn’t exempt them from security and privacy deficiencies. As such, I want to delve into some of the key areas that must be addressed before these solutions are widely deployed across our beloved nation.

Contract management and due diligence

Before any contracts are signed to commence these projects, the government must understand where personal data of Barbadian citizens will be stored. To provision users onto these platforms, personal data will need to be collected for AML and KYC purposes such as name, address, phone number, driver’s license, passport details, etc.

If the data is stored outside of Barbados, the privacy of Bajans may not be safeguarded as it will be subject to the laws and regulations of the jurisdiction in which the data resides (meaning that the legislation of a foreign country could permit them access to any and all data kept on Barbadian citizens). This is particularly concerning given the absence of data protection legislation in Barbados that would force any fintech company to ensure that transnational data flows must only occur where the destination country has an adequate legal framework in place to protect the rights of data subjects.

The lack of data protection legislation presents another problem in terms of imposing strict obligations on fintech providers to uphold the rights of data subjects. This includes setting requirements and fines for both data controllers and data processors as it pertains to protecting personal and sensitive data, obtaining consent to share personal/sensitive data, reporting data breaches to government and data subjects, among other rules. Hence, it would be in the best interests of Barbados citizens and foreign nationals if the 2018 Data Protection Bill was enacted into law before the launch of the new platforms […]

To view the remaining guidance on Technical Architecture, Deployment & Support, and Monitoring & Evaluation, you can read the entire blog here.

Why Bitcoin Will Not Solve the Caribbean’s Financial Inclusion Woes

What is Bitcoin? Is it electronic money?

There’s a deluge of hype around Bitcoin and blockchain technologies right now, and policymakers and regulators in the Caribbean are doing their best to wrap their heads around the advantages and disadvantages of this virtual currency. Similar questions are being contemplated in the ICTs for development (ICT4D) community, taking into account that electronic money (e-money) platforms such as Safaricom’s M-PESA have essentially solved the financial inclusion quandary for millions of people in Kenya. The service has now even expanded to Eastern Europe, Afghanistan, and India.

Besides sharing the characteristic of being digital, how do Bitcoin and e-money compare, especially with regards to reaching individuals who have previously been unable to access traditional financial services? Presently, there appear to be more differences than similarities between the two, and it’s critical not to confuse virtual currency with e-money.

Blockchain, in brief, is a record of digital events, distributed across multiple participants. It can only be updated by consensus between participants in the system, and when new data is entered, it can never be erased. The blockchain contains a true and verifiable record of each and every transaction ever made in the system. Launched in 2009, Bitcoin is a virtual, private currency that uses blockchain as an underlying, immutable public ledger. Bitcoins are ‘mined’ using distributed processing power across a global network of volunteer software enthusiasts. The supply mechanism is designed to grow slowly and has an upper limit of 21 million units as determined by a built-in algorithm. There is no central authority that controls blockchain or Bitcoin. There are no central banks that can be politically manipulated; and no way to inflate the value of a national currency by simply printing more money. Economic libertarians are ecstatic at the very thought of this. However, competing virtual currencies can be created that could have the net effect of devaluing the original.

Contrastingly, e-money is not a separate currency and is overseen by the same national regulatory authority that governs the printing of fiat money – as is the case with M-PESA and the Central Bank of Kenya. It’s an extension of a national currency like Jamaican dollars or Netherland Antilles guilders for use over digital networks to reduce the costs associated with handling physical cash. More specifically, it’s a one-to-one electronic store of value pegged to the cash receipt of the equivalent amount. To mitigate against risks like money laundering, terrorist financing, consumer protection, etc., the cash against which e-money is issued most often has to be deposited with fully regulated financial institutions.

The issue of financial exclusion

The issue of financial exclusion can be summarized into 2 categories: unbanked and underbanked. Unbanked individuals do not have an account at a regulated financial institution, while underbanked individuals have accounts, but frequently use alternative or unregulated financial services.

Before elaborating on the key factors behind financial exclusion, it is important to detail the effects of being unbanked to illustrate the severity of the problem. Unbanked individuals are faced with a heavy economic burden […]

The full article can be found on the CircleID website at: https://goo.gl/zn7Yg9