Showing posts with label social media. Show all posts
Showing posts with label social media. Show all posts

Saturday, March 9, 2013

Quick and Dirty (and Effective) Social Media Training Tool

ATTENTION BANKS USING SOCIAL MEDIA!  The day you have been fearing is here!

With the recent release of draft guidance by the FFIEC regarding social media use, social media is now front and center.

Conversations with auditors and examiners is revealing an interesting audit and regulatory expectation - mandatory social media training for all employees and directors.

As social media matures and more and more senior managers and directors feel comfortable with the use of social media, auditors and regulators have begun to look more closely at social media use by organizations.  Unfortunately, there still exists in many cases a lack of understanding on the part of internal auditors and examiners in terms of what exactly what and how social media works.  This ALWAYS spells trouble for bankers.

As we move forward as an industry in terms of social media adoption financial institutions must focus on three primary areas:

  1. Social Media Risk Assessment
  2. Social Media Policy
  3. Social Media Training
Social Media Risk Assessment

I have previously covered and provided social media risk assessment tools.  See my post "Social Media Risk Assessment Process - Part 5."  This is one of the most visited posts - with good reason, auditors and regulators expect institutions to conduct a risk assessment before deploying social media.

Social Media Policy

I have also previously covered and provided a sample social media policy.  See my post "Sample Social Media Policy for Banks."  This is another one of my most visited posts.  Even institutions that do not use social media are being required in some cases to have a policy confirming that fact!

Social Media Training

The final piece of the trifecta is Social Media Training.  Due to the widespread use of social media within society, auditors and regulators are now treating social media like they do areas such as information security and the Bank Secrecy Act.  Increasingly auditors and regulators want to see social media training for all new employees.  The thinking is that social media can do some real damage if employees are not aware of the risks.  As such, just like information security and money laundering, social media is equally risky.  In addition to new employee training, there is an increasing expectation of annual training and director training.  All this is new and sudden and many organizations have not been prepared.

In an effort to assist the banking industry, Pan American Bank made available on its YouTube channel a 30 minute social media training video.  Pan American Bank does not guarantee that the video will meet auditor or regulator requirements but it is a good starting point for those that need to quickly ramp up their employee and director training relative to social media use.

Check out the video and make use of it for training if it meets your needs.  And good luck with your upcoming audits and examinations!

Tuesday, August 14, 2012

Community Outreach and Retail Banking


According to a recent article written by Alan Mattei of consultancy Novantas LLC, community outreach is fundamental to retail banking.  The problem banks face is determining how to best respond to the plethora of social platforms that include blogs, Facebook, Twitter, Pinterest, etc.


Mr. Mattei argues that social networking is forcing banks to think twice about the singular importance of branch banking.  As more time is spent online, shopping habits, including those related to bank products and services, have morphed and as such, banks must find ways to meet with customers at their new destinations – social media platforms.

As evidence of this transition, Mattei provides examples of two branchless financial services players that have begun to market products and services through social platforms: Ally Bank and American Express.

Ally’s online outreach includes a blog with self-help tips and expert advice; a continuing heavy stream of articles that are broadcast and posted on its Website; posts on Facebook; tweets; and infographics. Such activities have generated millions of Website visits and have become a driver in deposit account origination, according to Forresteor Research.


American Express launched its “Sync, Tweet, Save” program, which entices customers to sync their cards with their Twitter accounts. Under this arrangement, promotions from merchants and American Express are pushed to the customer via Twitter, with discount offers concurrently activated at the merchant point of sale.

Mattei states that today’s innovators in the use of social media are going beyond traditional banking’s defensive measures (e.g., reputation management).  Regardless, Mattei makes a point for walking before running by stating that “as a reasonable first step, institutions within the top 100 should establish an individual set of surveillance routines and contingency response plans for social media. This includes participating in conversational threads as appropriate; responding to customer service requests; diffusing negative events; and generally monitoring “the voice of the customer.” Much of this preparation remains to be done, although there are a few standout examples of banks with strong antennas in the virtual space.”  Here Mr. Mattei is spot on.  Mr. Mattei’s only error is that he has limited his advice to the top 100 when in fact every institution should follow this advice.

Mr. Mattei argues that social media and banking is about proactive involvement.  He argues that banks must learn to “proactively participate in the online dialogue, not just react in trying circumstances.”  The ultimate goal accord to Mattei is strengthening brand presence and building product awareness through:
  • Community Building
  • Two-Way Conversations
  • Content Threads
Mattei states that banks must begin incorporating social media into the overall marketing plan – despite the lack of maturity in the market.  Just like the online marketing scene created chaos for bankers yet bankers adapted, so too must bankers adapt to social media despite the chaos.  Mattei states that “institutions will have to start somewhere, just as they did when the Internet took off ten to fifteen years ago.”


Mattei attacks the ROI question head on when he states that “it is a mistake to begin using strict return on investment (ROI) calculations to evaluate social media initiatives right now.”  He compares today’s social ROI debate to that of online billpay of yesterday.  He points out that what years ago was a horrible ROI example, today has been an incredibly profitable service that creates serious retention.

For a second time in the article Mattei makes reference to the “majors” by stating that “for major banks, real traction with social media will require a dedicated team.”  While the advice he gives is sound, it applies to all banks.  Regardless, depending on the success and the leverage of social media within an organization, even smaller shops may want to consider community managers to run the day-to-day social operation.  Should they be outsiders or bank employees?  That is a conversation (debate) for another day.

Mattei goes on to address the use of social media for customer service.  He advises to start small and simple and figure out what works and what doesn’t.  He suggests using analytics to find the nuggets of gold that may result in an effective social effort.

Ultimately, Mattei states that “to mobilize for this new channel, executives must embrace the notion that building ‘social equity’ has long-term value for the institution. They then need to allocate the required resources, build the right teams, and craft a long-term strategy for transformation.”


I generally agree with Mattei.  I wish his focus would not have been so heavily slanted towards larger shops.  It is, after all, community banks that are best positioned to take advantage of the social media revolution.  Understandably, community banks are not likely going to spend the bucks on social like the top 100.  Regardless, it does not help the industry when the smaller players are ignored or left out of the "conversation."

Some useful links:  Social Media Risk Assessment Template

Thursday, July 19, 2012

Harnessing the Power of Social Media

In his article, "How Banks Can Harness the Power of Social Media," Tom Bukacek, CEO of Black Box Social Media LLC summarizes nicely the best way community banks should use social media.

Social Media Marketing And SEO For Business

According to Bukacek, banks have been slow to adopt social media in recent years due to factors such as ROI, risks and understanding how to best use social networks.  But this is changing every day.

Bukacek makes a strong point:  "CONSUMER INTERACTION CAN  ONLY OCCUR AT THE SMALLER COMMUNITY LEVEL."  

BINGO!!!!!!

Bukacek goes on to explain that the "sharing of experiences and stories brings the banks closer to customers and also ends up becoming a valuable source of information about consumer preferences."  He also addresses the issue of "negative feedback" by stating that a well handled social media crisis can result in a very positive outcome.

These are all simple but important rules when using social media in a community bank setting.  Forget the big and expensive national campaigns of the multinational banks.  Instead focus on micro-marketing through social media.  Win over new customers and turn existing customers into brand ambassadors and evangelists for your brand.


Wednesday, July 18, 2012

Social Media Policies Everywhere in Among Investment Advisors

The Investment Adviser Association, ACA Compliance Group and Old Mutual Asset Management released the 2012 Investment Management Compliance Testing Survey Report.  The report found that among the investment advisers surveyed:


  • 80% maintained formal written social media policies in 2012
  • 64%  maintained formal written social media policies in 2011
  • 43%  maintained formal written social media policies in 2012
The survey also found that in 2012, 54% of investment advisers prohibit personal social media sites such as Facebook to be used for business purposes.  Further, in 2012, 54% of investment adviser firms audit for compliance with social media policies.


This data suggests that the regulated financial services industries have realized the ubiquity of social media - not only in the personal lives of employees and clients, but in the financial services industries.

With so few investment advisers maintaining formal written social media policies, the regulatory expectation, AKA Best Practice, will be for every regulated firm to not only maintain such policies but also test for compliance with the policies.

Thursday, March 1, 2012

Complying with the HR Component

At the risk of being called a shameless plugger, I am referring you to my recent book, "Human Resources Guide to Social Media Risks" as a tool for complying with the human resources related threats found on yesterday's Social Media Risk Assessment.


I think that the book is a necessary read for not only HR professionals, but any manager and employee in and around social media (e.g., everyone).  There are some very important lessons in the book that can really help organizations manage their social media risks from an HR perspective.  As I like to say, social media risks are human risks.  They are not technology risks.  A review of the risk assessment document in yesterday's post makes that very apparent.  As such, be sure to pick up a copy of the guide.  I think you'll be very happy you did and I really do believe that you will be doing your organization a great service.

Social Media Risk Assessment Process - Part 5

Ahhhh. The fifth and final part of this series on the Social Media Risk Assessment Process ("SMRAP").  I hope you've enjoyed the series up to this point.  I know I've enjoyed bringing it to you.

This last segment is all about completing the SMRAP.  I've created a fairly basic yet effective social media risk assessment model.  As you will note from the graphic below, my model uses the concept of "Threat/Vulnerability" pairs to isolate weaknesses that can result in disaster.  In a nutshell, here's the deal:  there are threats and there are vulnerabilities.


Threats are actions or events that can cause harm to the organization.  For example, when it comes to social media risks, an example of a threat is the disclosure of confidential customer information over social media.

Vulnerabilities are simply weaknesses in the system.  They are the chinks in the armor.  Vulnerabilities are what enable the threats to take form.  For example, a vulnerability related to the threat above could be a lack of understanding of social media-related information security risks by employees.

Therefore, using the same threat example above, a way for the threat to manifest or occur can be due to a lack of adequate employee training.  In other words, an employee does not know that it is a bad idea to post confidential employee information on social media sites and as such, the employee post information or takes part in conversations that reveal confidential customer information.

This is what I refer to as the Threat/Vulnerability pair.  A threat creates havoc and a vulnerability permits the threat to wreak havoc.  It must be noted that threats in of themselves are fairly harmless.  Without a vulnerability threats have no life.


STEP 1:  Determine the threats that apply to the organization's social media environment.  I have created a social media risk assessment template that contains the majority of "high level" organizational threats.  You can download the social media risk assessment document here.

STEP 2: Determine the vulnerabilities (weaknesses) that can create an environment in which the threats can manifest.  In some cases a threat will have only one vulnerability associated with it.  However, in the majority of cases there will be multiple vulnerabilities associated with each threat.  If you inspect the template social media risk assessment you will see multiple vulnerabilities per threat (see graphic above).

STEP 3:  Once the threats and vulnerabilities have been identified it is time to determine the internal controls that are in place.  Internal controls are the practices and processes that will keep the vulnerability from turning the threat into a reality.  The template provided contains common controls.  It is not likely that every organization will have every control listed.  The greater the number and breadth of controls in place, the less likely the threat will take place.  Each control should be listed on the risk assessment as shown in the template document.

STEP: 4:  Based upon the internal controls in place and the nature of the threat and vulnerability, the organization must determine the likelihood that the threat will take place.  A sample Likelihood Matrix is such as the one shown below is contained in the template.


STEP 5:  Next, the organization must determine the severity of the effect of the threat if it were to manifest based upon the existing controls.  Similar to the Likelihood Matrix, the template contains a Severity Matrix such as the one below.


STEP 6: Finally, the organization uses both the Likelihood of Occurrence and the Impact of Severity to determine the Risk Level.  The template also contains a matrix to assist in the determination of risk.


STEP 7:  After completing the social media risk assessment it should be reviewed.  Considerations in the review include a risk level that is too high relative to the organization's risk appetite.  For example, it may be the policy that all "moderate" and "high" risk areas be reviewed with senior management to discuss further internal controls that can be implemented to reduce the risks. It is generally a good idea to summarize the risk assessment process and deliver a report to the organization's Audit Committee and possibly the Board of Directors.  Along with the report may be recommendations or action items that will be taken to increase the number of internal controls to reduce the overall risk.  Once such action items are completed the organization can again perform the risk assessment to determine if the internal controls have been effective in reducing the risk level.

It must be noted that there are many ways to conduct a risk assessment.  This method is just one.  There is no right or wrong methodology as long as the end result provides an assessment of the residual risk and considers all of the practical threats.

I encourage you to take this template and turn it into your own.  I also ask that you return to this post with you recommended revisions/enhancements to the template so that others may also benefit.

Enjoy.

Wednesday, February 22, 2012

Social Media Risk Assessment Process - Part 4

The Social Media Risk Assessment Process ("SMRAP") should be incorporated as a component of the organization’s overall risk management strategy.  

Generally, a revised social media risk assessment should be conducted on an annual basis.  The fundamental basis of the SMRAP is to balance the Bank’s desire and need to utilize social media with other factors associated with doing business.  The organization must recognize that some risk must be accepted to make use of social media business.  The organization must also recognize that some social media risks exist regardless of the organization's social media strategy.  As such, the risk assessment program provides a practical approach to efficiently and cost-effectively identifying risks associated with social media use - regardless of the look and feel of the organization's social media strategy.



Risk assessments help ensure that employees comply with the organization's requirements as outlined in its  social media policy, code of conduct and other related policies.  The SMRAP also raises employee awareness regarding social media risks associated with their business unit’s use of social media.  Additionally, the SMRAP assists the organization in making informed decisions about the need for additional risk mitigation controls. 

The SMRAP can be conducted by a centralized department or rolled out to departments and sites on a decentralized basis.  Each organization must determine how to best disseminate the SMRAP.  The goal of the SMRAP is to identify threats and vulnerabilities posed by social media.  This may be difficult to do through a centralized approach if the organization is large and/or spread out geographically.


Those responsible for performing the SMRAP must determine each threat and associated vulnerabilities.  For each vulnerability the manager must determine the controls in place to prevent the vulnerability from exploiting severity of impact upon the organization and determine the likelihood of the vulnerability exploit occurring given existing internal controls.  It is important to note that this process requires a certain level of subjectivity.  As such, the success or failure of the SMRAP hinges upon the knowledge and understanding of the individual(s) performing the SMRAP.  As such, the organization should select individuals with experience in assessing risks and business impact.  The use of junior staff to conduct the SMRAP may under- or overestimate the conclusions - unless the staff are well supervised.  Part 5 of this series will describe an easy manner to document the SMRAP.



Once the risk level is determined for each threat/vulnerability pair, organizations may consider additional controls for moderate- and high-risk levels.  After the control enhancements have been incorporated, the risk threat/vulnerability pair is re-evaluated to determine the residual risk after the  control is implemented. 

The outcome of the SMRAP process is the mitigation of risk to acceptable levels, thereby providing adequate protection to the organization.  As such, to the extent that moderate- and high-risk levels exist after the implementation of mitigating controls, a discussion of the threat should be elevated to senior management for further discussion.  It is important to note that operating under moderate- or high-risk levels is not uncommon.  However, under such circumstances it is important to ensure that the appropriate parties are aware of the risks in order to ensure that all options have been considered as well as to ensure that all parties are aware of the risks.  This awareness is crucial for line units - particularly during periods of duress.  Consider it a form of CYA!

In cases in which additional controls must be implemented to mitigate moderate and high risks, the organization should consider the development of a formal written action plan that documents the controls.  The action plan should include the steps to be taken, the time frame for completion and the individuals responsible for implementation of the controls.

It is highly recommended that the SMRAP be evaluated by the appropriate parties within the organization.  This may include the CEO, CIO, IT Steering Committee, Compliance Committee, Audit Committee and the Board of Directors.  The purpose of the review should be to share the strengths and weaknesses of the organization’s social media strategy from a risk perspective.  Identified organizational vulnerabilities should be addressed with the appropriate personnel for the purpose of implementing corrective actions.


The SMRAP focuses on strategic and operational issues.  Organizational vulnerabilities are weaknesses related to the organization’s policies or practices that can result in the manifestation of a threat.  Part 5 of this series will drill down into specific threats and vulnerabilities.  Part 5 of this series will provide as a template  the most common threats and vulnerabilities.  However, the framework that will be introduced in Part 5 provides sufficient flexibility to allow the user of the SMRAP to customize the  process with organization-specific threats and vulnerabilities.

Tuesday, February 21, 2012

Social Media Risk Assessment Process - Part 3

Risk is the possibility of an act or event occurring that would have an adverse effect on the organization.  Risk can also be the potential that a given threat will exploit vulnerabilities to cause loss of, or damage to, the organization.  Risk is generally measured by a combination of severity and likelihood of occurrence.

A threat is an action or event that might jeopardize the organization.  It is a sequence of circumstances and events that allow a human (disgruntled employee, etc.) or other agent (virus, Trojan horse, etc.) to cause a misfortune by exploiting vulnerabilities.  A vulnerability is a weakness that allows a threat to manifest itself. 



Considerations to keep in mind when determining threats:

  • Determining the legal implications and contingent liability associated with any identified risks.  For example, if hackers successfully access the organization’s Facebook account and use it to subsequently attack followers/friends, the organization may be liable for damages incurred by the party that is attacked.
  • Capability and motivation are important attributes of threats.  Threats need both attributes (capability and motivation) to be credible.  For example, a skilled hacker seeking access to a Facebook account is considered a credible threat because the hacker has the capability (skills) and motivation (financial/ideological gain from the use of the organization's Facebook account).
  • Interested parties.  Serious hackers, interested computer novices, dishonest vendors or competitors, disgruntled current or former employees, organized crime rings or even agents of espionage pose a potential threat.
  • Poor security program/poor employee security awareness.  Hackers often exploit well-known weaknesses in creating secure passwords.

Internal controls are mechanisms that enable the organization to achieve its business objectives.  With appropriate controls in place the organization is able to effectively mitigate the risk posed by a threat.  With respect to social media, internal controls are designed to meet three main objectives:

  • Confidentiality:  Preventing the disclosure of sensitive information;
  • Integrity:  Preventing unauthorized modifications to information and maintaining internal and external consistency; and,
  • Availability:  Ensuring that the systems are working and that the data is accessible to users as required.

In addition to requiring the documentation of threats and vulnerabilities, the SMRAP also requires the documentation of associated controls.  To maintain an effective social media risk assessment process the organization must ensure that the organization has adequately considered the implementation of the following types of controls:

  • Preventative Controls:  These controls are established to avoid occurrences of unwanted events.  This type of control may include passwords, policies, procedures, security awareness program, etc.  These controls are considered “proactive.”
  • Detective Controls:  These controls alert and identify violations after the fact.  These controls can include social media monitoring and other information that provides notification after the event has occurred.  These controls are considered “reactive.”
  • Corrective Controls:  These controls are intended to remedy unauthorized events and to restore the original controls.  For example, the ability to reset the custodian of a social media account that has been locked-out due to some adverse event is considered a corrective control.
  • Deterrent Controls:  These controls discourage violations. For example, a policy statement that states that violators may be terminated for non-compliance with the social media policy is considered a deterrent control.

Part 4 of this series will begin discussion on the risk assessment process.

Monday, February 20, 2012

Social Media Risk Assessment Process - Part 2

The first step in the Social Media Risk Assessment Process ("SMRAP") is to identify the social media-related threats that can adversely affect the organization.  While these threats can be technology-based, they are most dangerous when they originate from human acts.


The ubiquitous use of social media has brought social media-related threats to the forefront.  Among the threats associated with social media are:

  • Disclosure of Confidential Customer Information by Employees;
  • Disclosure of Confidential Company Information by Employees;
  • Systems Outages Due to Social Media-Based Virus/Malware Infections;
  • Remediation Expenses Related to  Social Media-Based Virus/Malware Infections;
  • Loss of Branding Content Contained on Social Media Platforms;
  • Lawsuits Related to Alleged Improper Use of Social Media in the Hiring Process;
  • Lawsuits Related to Alleged Improper Use of Social Media in the Termination Process;
  • Loss of Opportunity to Hire Star Employees Due to Information Contained on Social Media Platforms;
  • Spam/Malware/Virus Attacks Against Social Media Platform Friends/Followers; and, 
  • Excessive/Inappropriate Use of Social Media by Employees.

The SMRAP in and of itself does not assure adequate protection against social media-related risks.  Rather, the SMRAP is part of the organization’s overall Risk Management Program that includes the written policies, guidelines, employee awareness/training and an independent review of the organization’s social media practices.


The SMRAP concludes with a determination of the adequacy of existing controls relative to the identified threats and vulnerabilities.  The SMRAP allows management to determine the need for additional controls to reduce the Bank’s risk exposure. 



Since threats and vulnerabilities change over time, the SMRAP must be updated and reviewed on a regular basis to ensure the appropriateness and effectiveness of the controls in place.  Updates are minor changes to the existing risk profile.  These include changes resulting from the implementation and/or removal of a control, or when the effectiveness of a control changes.  Updates occur when the following events take place:

  • New control is implemented;
  • An incident highlights a minor discrepancy in the current risk profile (i.e., the likelihood or severity of a threat requires minor adjusting or the effectiveness of a control requires adjustment);
  • A risk is no longer applicable; and,
  • A new risk emerges.

The SMRAP should generally occur on an annual basis.  The SMRAP should also take place when the following occurs:

  • Increase in security risks/exposures due to an event or series of events (i.e., significant change in organization's social media strategy, development/implementation of in-house social network, etc.);
  • Cumulative updates indicate the need for a review;
  • Changes in regulatory requirements; and,
  • Serious social media-related incident.

The results of the initial SMRAP and periodic SMRAP updates should be provided to the appropriate party within the organization such as the organization's Audit Committee and Board of Directors. 


Part 3 of this series will discuss risks, threats and vulnerabilities.


Series:
Social Media Risk Assessment Process - Part 1

Sunday, February 19, 2012

Social Media Risk Assessment Process - Part 1

Do you hear that?  There it is again.  Did you hear it that time?!  Oh man, it's worse than I thought.  The bank examiners are updating their examination procedures to include "social media" and the industry is not ready for it.  What does that mean?  Low Hanging Fruit Time.  Noooooooooo....   


This post is about the development of a Social Media Risk Assessment Process (“SMRAP”).  The SMRAP provides organizations with a systematic approach to evaluating exposure to social media-related risks.  The SMRAP focuses on five components: Threats, Vulnerabilities, Controls, Likelihood of Occurrence and Impact.

Social Media Risk Assessment Matrix

The SMRAP is intended to achieve one basic goal: the protection of the organization's reputation.

Management is responsible for ensuring that systems and data are adequately protected.  Historically this has related to the systems and data maintained within the organization's walls.  Unfortunately, as an organizations are increasingly moving to third-party social media platforms such as Facebook, Twitter and LinkedIn (and for good reasons), management must now take measures to adequately controls risks related to external systems.



Management is also responsible for protecting the organization's reputation from intentional and unintentional acts that may cause harm to the organization.  Unfortunately, reputational harm can come from many directions, including public outcry (think Bank of America's debit card debacle or Occupy Wall Street).

An organizational key business objective is to maintain a set of policies and procedures that protect and mitigate against risks related to day-to-day operations.  Social media risks have become part of the day-to-day risks of any organization.  As has been previously stated, organizations cannot determine whether or not to participate in social media.  Social media happens.  And it has been happening for some time.  The question is whether or not management has realized this fact and has moved to mitigate the risks before the risks mitigate the organization.

The SMRAP is used to identify, evaluate, document, monitor and manage social media risks.  Through the SMRAP the organization is able to identify and prioritize social media-related risks and develop appropriate risk management strategies.  Such strategies include the establishment of appropriate policies and the selection of cost-effective controls that implement the policies.

Part 2 of this series will begin the process of identifying the social media threats that must be evaluated as part of a risk assessment process.

Friday, October 7, 2011

Social Media Password Policies - More Than An Ounce Of Prevention

In early September, the Bank of Melbourne had its Twitter account hijacked by someone that used it to send phishing messages to its followers, many of whom were customers. The tweets sent from the Bank of Melbourne Twitter account contained malicious links.


The likely cause for the account compromise was a weak password used by a staffer with access to Twitter.


This event should serve as a lesson to banks with a social media presence. Just as banks maintain effective password policies to access internal systems, similar policies should be required for external systems.  Employees should be made aware of the damage that can result from lax/poor controls over passwords.  The lack of effective controls can result in reputational harm, regulatory criticism and legal action.

Thursday, October 6, 2011

Social Media is Social Business

Boxley Llewellyn and Chitra Dorai from IBM came up with these four ways that social media is transforming the banking industry.  They provided their analysis in a

1) Social business is critical for forging new connections, as well as elevating the brand.
Banks that can use it wisely can generate immediate, impactful results on increasingly social customers, many of whom use social media as an underlying "operating system" for their work and social lives.

2) Social business is a pivotal outlet for building communities.
Selling banking products and services can be understandably complex. However, building communities around products and services opens up a new way for consumers to inquire, engage and share material. Focusing on customer service and adopting the personalities of the people they serve, banks can bring new meaning to customer centricity.

3) Social business can be an invaluable tool for product research and education.
Whether you're crowd-sourcing to find out what customers think of your services, or using social media to encourage customers to develop new products, the social network provides a channel to solicit ideas and input. In fact, social customers expect to be able to input ideas, rate experiences and debate ideas. Banks are redesigning their websites to include new features to gather ideas and feedback. They deliver videos on product information via YouTube and ask customers to rate the site and suggest new products.

4) Social business can provide deeper insights into bank customers.
All of the information that is generated on social media sites is valuable data that can be analyzed and mined. New patterns can be uncovered and valuable insight gleaned -- from gauging what customers like and dislike, to understanding what products they respond to and assessing areas of improvement for customer service. Banks are just starting to use more advanced analytics to tap into this data and develop more customized services and offerings for customers to ultimately drive more business. They can deliver more tailored marketing and sales campaigns to generate more targeted results.

Wednesday, October 5, 2011

Rodney Dangerfield - The Father of Social Media Sentiment Analysis

When I was an undergrad at UCLA I had a horrible habit of staying up all night with friends, drinking Schaefer beer and eating Domino's while watching movies such as Caddyshack.  I gotta admit those were some of the best times. Cheap beer, good food and great friends. Of course, never did I think that anything other than bad hangovers would result from the experience.


I guess that's why I'm just a blogger and not a multi-gazillionaire.  You see, if I were paying better attention I would have noticed the wisdom in the words of the late Rodney Dangerfield.



That clip above wasn't the wisdom I was talking about. That was just funny.

Somewhere in the movie Rodney says "they're all buying, then sell, sell, sell!" It seems that the folks at Barchart.com, Inc. were also avid fans of Caddyshack. How else would they have come up with the idea of tracking company sentiment on social media as a means of determining which stock to buy and which to sell.

According to a Barchart press release, "researchers from Indiana University and the University of Manchester recently published findings that social media can have up to an 86.7% accuracy rate at predicting the market."  The Barchart product analyzes thousands of social media messages every second, compiling data that can be used for research, system development and real-time stock, futures and forex signal creation. The software instantly evaluates and generates trading signals based on the sentiment of investors using social media tools.

This product and the research behind it may be useful to banks relative to decisions and transaction that involve stock price such as merger and acquisition transactions.

Another example of the usefulness of social media.  But does it look good on you?

California Bankers Association Goes Hands On

NOTICE:  This post is a little off-track as it does not relate entirely to social media but relates generally to technology.  The next post will return us to our regularly scheduled programming.

If you're a banker chances are you've attended a conference or seminar hosted by a state banking association. As a long-time banker I've been to so many of these events that they have all started to look and sound the same. So when I received an email for the California Bankers Association Technology and Community Banking Conference I was pleasantly surprised.


According to the marketing materials, "this session will be unlike our prior seminars, in that to help get you more comfortable with these new technologies you will have a chance to try all of them out! Our goal is to allow you at least as much 'hands on' time to use the products as to just hear about them."

What a great idea!

As new technologies evolve and as more and more options fill the technology landscape, having these types of hands-on opportunities provides real value to conference goers.  One job of staff attending conferences is to report back to executive management about trends in the industry and the tools that benefit the organization.  Too many times all we have are Powerpoint presentations containing screen shots.

As an experienced conference speaker I understand the risks of letting the technology loose on the conference room floor.  If there was ever a call for gremlins, this is it.  But that is exactly why I commend the California Bankers Association for taking a risk and requiring their presenters and vendors to let the attendees "test drive" their wares.  At the end of the day, the money and time will be much better spent if  bankers get a chance to play around with the technology and decide for themselves whether the product is the real deal or just good marketing.


Kudos to the California Bankers Association for taking the risk and providing a meaningful experience to the attendees.  This should go a long way in engaging attendees and should earn the California Bankers Association some positive buzz.

Sunday, September 18, 2011

Social Media Is Problem Solving - Not Rocket Science

According to Jeff Molander, Loyola University Business School, social media challenges marketers to design conversations in ways that solve customers’ problems.  According to Molander, the key to selling more with social media is based on organizations developing a way of creating conversations with consumers that provide value through problem solving.

Molander points to Anchor Bank as an example of an organization that follows customers, not trends. Their customers signal the “when, where, why and how” that powers technology decision making. Anchor Bank translates customers’ needs and responds by scratching their itches—and in the process earning more transactions. They’re helping customers navigate themselves toward needed answers.



Molnader's key take-away: brainstorm gestures for your company that help solve your customers’ problems and make products more relevant. Start in areas of strength. For instance, AnchorBank focuses on helping customers get out of debt, learn about appropriate sources of financing, and prepare their “money lives” for divorces or marriages.

Friday, September 16, 2011

Bank Security Officer Wanted - Social Media Skills a Plus

The Security Officer for BBVA Compass Bank likely received a crash course in social media tonight after someone attempted to rob BBVA's Vestavia Liberty Parkway Branch.

Police in Vestavia Hills are looking for a man who they say tried to rob BBVA Compass Bank. Bank surveillance camera photos of the suspect from the attempted robbery have been posted to the Vestavia Hills Police Department Facebook page.


Increasingly police departments are turning to social media sites to share information and alert the public about wanted individuals. Facebook has increasingly become a valuable crime fighting tool for banks and police investigators.





If you're a Bank Security Officer you may want to do a few things to improve your chances of catching perps:

1) Implement procedures that allow immediate transfer of video and photos to Internet-friendly formats. The faster the images are available, the better the chances of catching criminals.

2) Determine immediately upon an incident whether the local police department has a Facebook or other social media site established for the purpose of distributing images and video to the public.

3) Do not post any photos or video of the crime on the bank's Facebook page without first consulting with the local police department. They may have a strategy that may conflict with your strategy. So if the bank wishes to post photos or video, first run it past the police department. In addition, posting such information may create reputational harm by giving the impression to customers that visit the bank's Facebook page that the bank's branches are not safe. So having the information posted on the police department site may be the best  bet.

Tuesday, September 13, 2011

Using Location-Based Social Media Without Driving Up Branch Costs

On August 30, 2011, The Financial Brand posted a great article on the use of location-based social media platforms such as Foursquare. According to the article, "most retail financial institutions have spent the better part of the last decade shooing people out of costly branch networks, choosing to push online, mobile and paperless solutions over one-to-one, personal interactions. Most banks and credit unions have done what they can to keep consumers out of branches and reduce transaction volumes."


It's true.  Since online banking and ATM availability have become ubiquitous banks have looked to leverage these lower cost options in lieu of the higher costs associated with branch operations.  So why are banks now trying to drive the traffic back into the branches through "check-in" campaigns associated with location-based social media platforms?  Confusion.


In an attempt to make use of these very fun and interesting tools, marketers are unintentionally undermining years of effort in moving customers to lower cost distribution channels.  While there is some advantage to drive traffic to branches - to open accounts.  In most cases the transactions can be managed through online banking or automated phone banking.

If bank marketers insist on using location-based social media tools - and I believe they should, they need to get just a bit more creative.  For example, banks can identify their best business customers and reward consumers for checking in at bank business customer locations.  Or even better, how about struggling bank borrowers.  Send business to them so they can make they loan payments this month!

Banks are extremely supportive of community-based events and sponsor many such events.  How about rewarding customers for checking in at the local YMCA fundraiser or farmers market or similar community event.

Location-based social media platforms are great.  But marketers need to think a little bit before unleashing their power.  With a little thought banks can make use of a great tool while creating significant benefit for the bank and the community - without having to hire more tellers.

Monday, September 12, 2011

Social Media + Mobile = Business Continuity/Disaster Recovery

An area of banking that is the equivalent of going to the dentist is the business continuity planning/disaster recovery ("BCP/DR") preparation and testing.  While there is nothing more true than the old saying regarding an ounce of prevention, there is nothing more frustrating and tedious than thinking and planning for the unthinkable.  Regardless, as bankers we must make sure we do not fail to plan so as to not plan to fail.  Lives may depend on it.



A recent American Banker article discussed how banks recently affected by hurricane Irene used social media and mobile to efficiently address BCP/DR challenges.  During the recent storm, banks such as Citibank and TD Bank used social media and mobile to inform customers of branch closures and ATM availability.  This enabled customers to limit their exposure to the hurricane and obtain the needed services to manage through the storm.

Whether the event is a storm, civil disobedience, earthquake or other natural or man-made disaster, the more information a consumer has the safer the consumer will be.  Social media and mobile can be used to provide customers with "hot spots" such as floods, riots, fires, etc, near branches and ATMs and suggest safer alternatives.  The same social media and mobile combination can be used to obtain information from customers regarding dangers.

While social media will not do much to prevent or resume banking operations, it is a nice option to have for customers during difficult times.  Every bank should consider using its social media accounts to keep customers informed throughout a disaster.

Wednesday, June 8, 2011

FAIR DEBT COLLECTION PRACTICES ACT AND SOCIAL NETWORKS

As social media use has become ubiquitous, industries have been hard at work determining how to best take advantage of the often-frequented social network communities. With Facebook at over 500 million active users, Twitter processing over 155 million tweets per day and LinkedIn with over 100 million registered professionals, it is no wonder organizations are looking for ways to leverage what social networks bring - people.

One industry that believes it has found a great use for social media is the debt collection industry. Many debt collectors find social networks extremely helpful for obtaining crucial information such as debtor’s home and work locations, lifestyle expenditures, lists of friends and family, determining whether a debtor has the financial wherewithal to make payments on a defaulted debt, and as a result, whether a debtor is worth the expense of suing in court. Debt collectors also find social networks useful in communicating with debtors in a manner that may be more effective than mail or telephone. Unfortunately for collectors, social networks have their drawbacks - drawbacks that can lead to legal action, regulatory criticism and reputational harm.

Nearly 35 years ago Congress passed the Fair Debt Collection Practices Act of 1977 (“FDCPA”) (15 U.S.C. §§ 1692-1692p). The FDCPA was passed by Congress in response to certain questionable and unethical tactics used by debt collectors. Prior to the passing of the FDCPA it was not uncommon to have debt collectors disclose to the friends and family of delinquent borrowers, the delinquent status of a loan. Other unethical tactics included making threatening, misleading and other statements to debtors with the intent of forcing repayment. The FDCPA was essentially enacted to protect consumers from the harassment, both verbal and psychological, that frequently accompanied collection efforts. While the FDCPA generally defines debt collectors as agents/contractors engaged to collect debts on behalf of others, this article assumes debt collectors to be agents/contractors as well as the owners of the debt such as banks, finance companies and investors because, while the federal FDCPA narrowly defines debt collectors, many state collection laws that mirror the federal FDCPA define debt collectors as anyone that collects a debt.

The FDCPA was passed by Congress seven years before Facebook founder Mark Zuckerberg was born. Twitter founder Jack Dorsey was one year old and MySpace co-founder Tom Anderson was seven years old when the FDCPA was put into place. As such, today’s social media explosion could not have been anticipated by the framers of the FDCPA. Many experts in the debt collection field believe that due to the FDCPA’s age the law requires a revision to specifically address social media. According to these experts, debt collectors are operating in a “no man’s land” - the equivalent of the Wild West. These experts believe that without social media-specific guidance, the debt collection industry is at risk of extensive litigation brought by private parties and class action plaintiffs’ attorneys.

The Federal Trade Commission (“FTC”), the federal agency with authority to enforce the FDCPA, has not indicated that it will revise the FDCPA any time soon. Instead, the FTC has stated that the consumer protections included in the FDCPA are sufficient to protect consumers and that the FDCPA addresses all forms of communications, including communications initiated through social networks and other social media. According the the FTC, the FDCPA includes sufficient guidance to prevent harassment of debtors and improper communication.


As such, the FTC disagrees with debt collection experts that are calling for an amendment to the FDCPA relative to social media. As demonstrated below, it appears that debt collector’s challenges relative to social media appear to be due to a lack of understanding of the FDCPA or blatant disregard for the Act.

In August 2010, Florida resident Melanie Beacham sued debt collection agency MarkOne Financial LLC after the debt collector used Facebook to allegedly harass the consumer who was delinquent on an auto loan. According to the lawsuit, in addition to aggressively using traditional collection methods, the debt collector also used Facebook’s messaging function to contact the delinquent borrower as well as to contact her relatives to ask that they have her contact the collection agency. According to the lawsuit, MarkOne Financial LLC used Facebook to intentionally harass the debtor in an “outrageous format.”

The debtor, who fell behind on her loan payment during a medical leave from her job, stated that she was shocked when she learned that the debt collectors used Facebook to track down her whereabouts and contact her family. The debtor claimed significant embarrassment related to the disclosure of her bad debt to her family.

In April 2011, while the lawsuit remained pending, W. Douglas Baird, the Judge hearing the complaint, ordered MarkOne Financial LLC to cease the use of social networks for the purpose of contacting the debtor and the debtor’s family and friends. The order, considered groundbreaking by many in the field of debt collection, shows how social media is increasingly becoming the basis for lawsuits. The challenge to debt collectors that use social networks is not so much federal and state collections laws do not address the use of social media. Instead, the challenge is one of compliance and training.

While social media is widely used, many users, including debt collectors, do not fully understand the functionality and impact of many social media features. As in the example above, debt collectors may locate a debtor on Facebook (or any other social network) and may make use of the “Send Message” function provided. This feature allows the sender to send a confidential message to the recipient similar to an email. As this feature requires little effort on the part of the debt collector, it is possible to abuse this feature by repeatedly sending messages to the debtor - an act that may violate § 1692d of the FDCPA, which defines harassment or abuse as “any conduct the natural consequence of which is to harass, oppress, or abuse any person in connection with the collection of a debt.” As such, in order to avoid a violation of § 1692d, debt collectors should observe their firm’s FDCPA policy relative to phone calls and treat social network messages as a similar communication when using the messaging feature on a social network.


In addition to sending messages to the debtor, it is possible for debt collectors to send messages to the friends and family members of the debtor that are part of the debtor’s social circle. This functionality allows debt collectors to contact third parties for assistance in obtaining information about the debtor, a permissible act according to § 1692b of the FDCPA. However, debt collectors using the messaging function to contact friends and family of the debtor must comply with the FDCPA. As such, any communication with friends and family through a social network requires the following of the debt collector:

(1) Identify himself, state that he is confirming or correcting location information concerning the consumer, and, only if expressly requested, identify his employer;

(2) Not state that such consumer owes any debt;

(3) Not communicate with any such person more than once unless requested to do so by such person or unless the debt collector reasonably believes that the earlier response of such person is erroneous or incomplete and that such person now has correct or complete location information;

(4) Not communicate by post card. In the case of social media, this should also include not posting any messages on the “Wall” of the debtor or the debtor’s friends and family. A postcard has the effect of openly disclosing a debt. A “Wall” posting is a digital equivalent;

(5) Not use any language or symbol on any envelope or in the contents of any communication effected by the mails or telegram that indicates that the debt collector is in the debt collection business or that the communication relates to the collection of a debt. While a social network message is not physical mail, it is the equivalent of electronic mail. As such, the debt collector should ensure that any message fully complies with this requirement; and,

(6) After the debt collector knows the consumer is represented by an attorney with regard to the subject debt and has knowledge of, or can readily ascertain, such attorney’s name and address, not communicate with any person other than that attorney, unless the attorney fails to respond within a reasonable period of time to the communication from the debt collector.

Debt collectors must ensure that their use of social media and social networks conforms to the spirit and intent of the FDCPA. Based upon the general language of the FDCPA, acts of noncompliance are generally the result of inadequate training or blatant disregard for the FDCPA - not shortcomings in the FDCPA language.

Sunday, February 6, 2011

Your Neighbor Hates the Bank....You're Fired!

About once per year there occurs a social media-related event that gets the social media talking heads (myself included), well, talking.

This year's first nominee for the 2011 Social Media "Oh No You Didn't" Award goes to Commonwealth Bank in Australia.

The Australian newspaper titled its coverage of the story, "Bank Threatens Staff with Sack Over Social Media Comments."  The gist of the story is this...Commonwealth Bank published a social media policy that essentially "deputized" employees with the mission of reporting and eliminating any adverse social media comments - or possibly face the executioner (Human Resources Manager).


According to the published story, "bank employees have been told they must immediately notify their manager if they become aware of 'inappropriate or disparaging content and information stored or posted by others', including non-employees, in the 'social media environment'."


The policy holds employees accountable for the actions of third parties.  According to The Australian report, the policy state:  "For example, your friend could post an inappropriate comment about the group on your Facebook page or create a blog about the group."


As if holding employees accountable for the acts of others isn't bad enough, the policy then goes on to state that "failure to comply with this policy is a serious disciplinary matter and may result in disciplinary action being taken against you, which may include the termination of your employment."


Sounds to me like whoever drafted this policy did not have a good understanding of how social media works.  But even worse, this person did not know the advantages that comes with openly addressing criticism.


Back on December 17th I posted "Firing An Employee Bad Mouthing the Company on Social Media?  Better Think Twice."  While the December 17th post relates primarily to U.S. incidents, there is much that applies to any locale.  As such, it was no surprise when the Australian Finance Sector Union demanded  suspension of the bank's new social media policy, accusing it of trying to restrict freedom of expression.


Quite honestly, I was shocked when I heard about this incident.  At this stage in the game most corporations should at least know the basics of social media and employee relations - or at least ask someone that does before putting out such a draconian policy.  On the other hand, I suppose this need for education bodes well for me as just last month I released a new book, "Human Resources Guide to Social Media Risks" (shameless plug!).


Human Resources Guide to Social Media Risks


I hate to break it to Commonwealth Bank but they just made it onto every social media consultant's  Powerpoint deck.  I'm sure the story does not end here.  Let me know what you think and hear.