PYX Resources: Achieving volume and diversification milestones. Watch the video here.

Less Ads, More Data, More Tools Register for FREE

Pin to quick picksRBS.L Regulatory News (RBS)

  • There is currently no data for RBS

Watchlists are a member only feature

Login to your account

Alerts are a premium feature

Login to your account

FCA fines RBS, NatWest and Ulster Bank Ltd

20 Nov 2014 07:02

RNS Number : 5372X
Financial Conduct Authority
20 November 2014
 



FCA fines RBS, NatWest and Ulster Bank Ltd £42 million for IT failures

The Financial Conduct Authority (FCA) has today fined the Royal Bank of Scotland Plc, ("RBS") National Westminster Bank Plc ("NatWest") and Ulster Bank Ltd ("Ulster Bank") (the "Banks") £42 million for IT failures which occurred in June 2012 and meant that the Banks' customers could not access banking services.

The FCA has taken this action against the Banks for failing to put in place resilient IT systems which could withstand, or minimise the risk of, IT failures.

The actual cause of the IT incident was a software compatibility problem with the underlying cause being the Banks' failure to put in place adequate systems and controls to identify and manage their exposure to IT risks.

The IT failure affected over 6.5 million customers in the United Kingdom for several weeks. Over the course of that period customers could not use online banking facilities to access their accounts or obtain accurate account balances from ATMs; customers were unable to make timely mortgage payments; customers were left without cash in foreign countries; the Banks applied incorrect credit and debit interest to customers' accounts and produced inaccurate bank statements; and some organisations were unable to meet their payroll commitments or finalise their audited accounts.

Tracey McDermott, director of enforcement and financial crime at the FCA said:

"Modern banking depends on effective, reliable and resilient IT systems. The Banks' failures meant millions of customers were unable to carry out the banking transactions which keep businesses and people's everyday lives moving.

 

"The problems arose due to failures at many levels within the RBS Group to identify and manage the risks which can flow from disruptive IT incidents and the result was that RBS customers were left exposed to these risks. We expect all firms to focus on how they ensure that they can meet the requirements of their customers when looking at their IT strategies and policies."

 

On 17 June 2012 Technology Services (the Banks' group centralised IT function) upgraded the software that processed updates to customers' accounts overnight. When it noticed problems with the upgrade it decided to uninstall it without first testing the consequences of that action. Technology Services did not realise, however, that the upgraded software was not compatible with the previous version. This caused the IT incident that disrupted customers' ability to use banking facilities on 20 June 2012.

The FCA found that Banks' did not have adequate systems and controls to identify and manage their exposure to IT risks. In particular:

- there were inadequate testing procedures for managing changes to software;

- the risks related to the design of the software system that ran the updates to customers' accounts were not identified;

- the IT risk appetite and policy was too limited because it should have had a much greater focus on designing systems to withstand or minimise the effect of a disruptive incident.

The incident was not the result of the Banks' failure to make a sufficient investment in its IT infrastructure. The RBS Group spends over £1 billion annually to maintain IT infrastructure. The FCA acknowledges that since the IT Incident the Banks have taken significant steps to address the failings in their IT systems and controls.

Today's fine is the first time the FCA and the Prudential Regulation Authority (PRA) have taken joint enforcement action. The PRA has fined the Banks £14 million.

The Banks agreed to settle at an early stage of the investigation and therefore qualified for a 30% Stage 1 discount.

Shortly after the IT incident, the FCA wrote to the chairmen of major retail banks in 2012 to ask them to identify the steps they had considered at board level to assess and mitigate their exposure to IT risks. The FCA and PRA recently initiated a second "Dear Chairman" exercise and, once again, it is seeking to assess how well banks are managing their exposure to IT risk and to what extent banks' governing bodies have formally assessed the extent to which a bank is vulnerable to technology failure affecting services supporting retail economic functions.

Today's decision reflects the FCA's commitment to ensuring that banks make the cultural shift away from "business continuity" (recovering from disruptive events) to "resilience" (ensuring that the banking activities most critical to customers can withstand the effect of disruptive events like software and other IT failures).

The FCA would like to acknowledge the cross-jurisdictional co-operation it received from the Central Bank of Ireland in the Republic of Ireland, who have taken their own enforcement action in respect of the IT failure against Ulster Bank (ROI) a subsidiary of the RBS Group.

Notes to editors

1. The final notice for the Banks can be viewed on the FCA website.

2. On 1 April 2013, the FCA became responsible for the conduct supervision of all regulated financial firms and the prudential supervision of those not supervised by the PRA.

3. The FCA has an overarching strategic objective of ensuring the relevant markets function well. To support this it has three operational objectives: to secure an appropriate degree of protection for consumers; to protect and enhance the integrity of the UK financial system; and to promote effective competition in the interests of consumers.

4. Find out more information about the FCA.

 

 

This information is provided by RNS
The company news service from the London Stock Exchange
 
END
 
 
MSCEAXFEAEFLFEF
Date   Source Headline
17th Mar 20205:24 pmRNSDirectorate Change
17th Mar 20204:42 pmRNSSecond Price Monitoring Extn
17th Mar 20204:38 pmRNSPrice Monitoring Extension
17th Mar 20208:30 amRNSMorgan Stanley European Financials Conference
16th Mar 20205:14 pmRNSNatWest Markets N.V. 2019 ARA
10th Mar 20204:51 pmRNSDirector/PDMR Shareholding
2nd Mar 20202:34 pmRNSDirector/PDMR Shareholding
28th Feb 20204:29 pmRNSCorrection of Dividend Declaration
28th Feb 20201:58 pmRNSTotal Voting Rights and Capital
28th Feb 20207:00 amRNSFiling of Annual Report on Form 20-F with US SEC
27th Feb 20209:55 amRNSBlock Listing Cancellation
24th Feb 202012:40 pmRNSDividend Declaration
20th Feb 20204:10 pmRNSHolding(s) in Company
14th Feb 20203:58 pmRNSRBSG ENTM Publication of Suppl.Prospcts
14th Feb 20207:01 amRNSAnnual Financial Report
14th Feb 20207:00 amRNSFinal Results
31st Jan 20202:12 pmRNSTotal Voting Rights and Capital
30th Jan 20203:57 pmRNSDirector/PDMR Shareholding
16th Jan 20202:08 pmRNSForm 8.3 - Accesso Technology Group plc
2nd Jan 20201:58 pmRNSForm 8.3 - Accesso Technology Group plc
31st Dec 20191:10 pmRNSDirector/PDMR Shareholding
31st Dec 201911:20 amRNSTotal Voting Rights and Capital
30th Dec 20193:02 pmRNSForm 8.3 - Accesso Technology Group plc
20th Dec 20197:00 amRNSPublication of Suppl.Prospcts replacement
19th Dec 20195:40 pmRNSPublication of Suppl.Prospcts
19th Dec 20197:00 amRNSNatWest Markets Change in Executive Directors
16th Dec 20195:47 pmRNS2019 Bank of England stress test results
4th Dec 201912:34 pmRNSForm 8.3 - Accesso Technology Group plc
2nd Dec 20195:34 pmRNSPublication of Suppl.Prospcts
29th Nov 20192:20 pmRNSDirector/PDMR Shareholding
29th Nov 20191:28 pmRNSAnnouncement of NatWest Markets N.V. Transfer
29th Nov 201912:01 pmRNSTotal Voting Rights and Capital
27th Nov 201911:56 amRNSDividend Declaration
21st Nov 20196:26 pmRNSPublication of a Prospectus
21st Nov 201910:45 amRNSReduction in Pillar 2A capital requirements
14th Nov 201911:23 amRNSPublication of Final Terms
13th Nov 20193:00 pmRNSForm 8.3 - Accesso Technology Group plc
8th Nov 20193:00 pmRNSDirector/PDMR Shareholding
1st Nov 20194:12 pmRNSDirector/PDMR Shareholding
31st Oct 20193:30 pmRNSDirector/PDMR Shareholding
31st Oct 20192:08 pmRNSTotal Voting Rights and Capital
30th Oct 20199:38 amRNSRBSG pricing of US$750mn of Subordinated Notes
25th Oct 20195:22 pmRNSPublication of Suppl.Prospcts
24th Oct 20197:00 amRNSQ3 Interim Management Statement
16th Oct 20192:54 pmRNSForm 8.3 - Accesso Technology Group plc
8th Oct 201911:35 amRNSBlock Listing Six Monthly Return
3rd Oct 20191:08 pmRNSPublication of Final Terms
1st Oct 20195:29 pmRNSDirector/PDMR Shareholding
30th Sep 20193:28 pmRNSTotal Voting Rights
24th Sep 20198:30 amRNSBank of America Merrill Lynch Annual Conference

Due to London Stock Exchange licensing terms, we stipulate that you must be a private investor. We apologise for the inconvenience.

To access our Live RNS you must confirm you are a private investor by using the button below.

Login to your account

Don't have an account? Click here to register.

Quickpicks are a member only feature

Login to your account

Don't have an account? Click here to register.