CIBIL, the only operational Credit Bureau in India, has rolled out a mechanism wherein a borrower can request his/her credit report from CIBIL and dispute any incorrect entries made.
In this article on Apnapaisa.com, the author has detailed the procedure to be followed to obtain one's credit report. I will summarize it below for the benefit of the readers:
1. Fill out this form and send to CIBIL along with (self-attested) Id & address proof and a DD of Rs. 142/- as non-refundable charges. The address to send the forms is:
Credit Information Bureau (India) Limted
P.O. Box 17
Millennium Business Park
Navi Mumbai - 400 710
2. If you find any errors in the report, complaint to CIBIL. The CIBIL will inform the concerned bank and the bank will have to respond within 30 days, otherwise the disputed entry in the borrower's credit report will be deleted.
How the borrowers benefit from this:
1. You can monitor your credit report for any erroneous entries, which up till now wasn't an easy task. Now there is a mechanism also to address the borrowers' concerns regarding erroneous entries.
2. If you plan to apply for a loan and have a very good credit report/rating you can negotiate a lower interest rate.
Link via Apnapaisa.com
Form downloaded from here.
I had previously written about credit reports & CIBIL here.
Showing posts with label RBI. Show all posts
Showing posts with label RBI. Show all posts
Monday, August 31, 2009
Friday, August 21, 2009
How to keep your accounts operative?
Some of my friends have faced this problem and you might also have experienced it. When you are away from your home-town say been abroad for a long duration or due to work you shift to a different city but still want to keep your bank account at your home town, the banks may classify your account as inoperative or dormant if there have been no withdrawals/deposits into your account for a specified period.
Sunil has pointed out this RBI Notification which clearly specifies the criteria for classifying an account as inoperative or dormant. I am reproducing the list here for the reader's benefit:
Please visit Sunil's blog to read this complete blog post where he gives a little background and also suggests ways in which you can prevent your account from becoming dormant.
There is just one more point that I would like to add here in addition to debit to recurring deposits, SIP ( Systematic Investment Plan ) by ECS/Direct Debit in a mutual fund is also one of the ways in which you can keep your account active.
Sunil has pointed out this RBI Notification which clearly specifies the criteria for classifying an account as inoperative or dormant. I am reproducing the list here for the reader's benefit:
- Issue of cheque against available balance in the account.
- Deposit of cheques / demand drafts into the account for clearing.
- Deposit or withdrawal of cash from the account.
- Issue of demand drafts by debit to the account.
- Credits by ECS into the account. Account holder may receive credits from sources like dividend from shares, interest from bonds, deposits, debentures or other securities that may be credited directly to his account by the payer.
- Credit of interest from any other deposits in force with the same bank or branch.
- Debits against standing instructions.
Please visit Sunil's blog to read this complete blog post where he gives a little background and also suggests ways in which you can prevent your account from becoming dormant.
There is just one more point that I would like to add here in addition to debit to recurring deposits, SIP ( Systematic Investment Plan ) by ECS/Direct Debit in a mutual fund is also one of the ways in which you can keep your account active.
Monday, July 27, 2009
Are they really safe? - Verified by Visa and MasterCard Secure Code.
I have previously blogged about them.
An anonymous reader has commented and raised concerns about these added layer of security for online credit and debit card transactions (collectively known as 3-D secure protocol ).
As you can read on its Wikipedia page, 3-D secure has a long list of criticisms most of them related to its ability to secure online transactions.
I will try to address all of the reader's concern below:
- RBI never sponsored or stated specific systems such as Verified by Visa or Mastercard UCAF/SPA in its directive.
In my article also I did not say that RBI has specified VbyV or Secure Code must be used. RBI article only says that additional info ( apart from what is already present on the card ) is required for online transaction. Since most ( say 95 % ) of the card holders in India have either Visa or Master Card they will have to use either of these two services hence I explained their features from an end-user perspective. For American Express cards they ask for the billing address for verification.
- The anonymous reader has pointed out some security vulnerabilities in 3-D Secure giving some examples like inline frame and activation during shopping.
Although I can't vouch for all banks in India, but I deal with HDFC Bank which does not use inline frame during 3-D secure authorization and it also has PAM ( Personal Assurance Message ).
It does have Activation during shopping but that too:
- is on hdfcbank.com domain with a proper SSL certificate ( no inline frame )
- requires your ATM password for authentication ( I don't know if the number of attempts is unlimited ). This I feel is secure enough.
But, I also know of cases where card issuing companies don't use their own domain during 3-D secure authorization like:
- SBI Card ( uses arcot.com )
- ICICI Bank ( uses payseal.com )
So our anon reader does have a valid point here. These systems are not 100% safe because of some inherent weakness in the Internet protocols.
- Then he raises a concern that the password can be easily phished and used by fraudsters. The transactions can never be disputed by the cardholder.
On this I don't agree with him. If there was no 3-D secure anyone who had physical access to the card even for a minute ( think of the last time you gave it for payment in the restaurant ) could have misused it ( by noting down the card details ). But introduction of 3-D secure had made life more difficult for fraudsters.
If transactions could be disputed without 3-D secure, they can still be disputed with 3-D secure activated as well. 3-D secure is not going to change that.
- A concern about fraudsters misusing this feature to cheat banks
This is a matter between the fraudsters between the banks and the fraudsters and I'm really not too much concerned about it. One thing I would like to point out here is that the act of issuing a card is not a completely online thing ( atleast in India ). There are id and address checks. Credit report is also verified. So if the bank has a diligent process in place before it issues a card, the chances of such cheating are lessened. However if the bank has lax procedures it obviously has to suffer ( that's in its Karma! )
- Be wary of mandated systems. A good security system never needs to be mandated.
If it is not mandated, the banks won't implement any safety feature. Only very few who actually care about customer concerns would be willing to do it on their own, since setting up an IT infrastructure for such a feature costs money and the management of banks is busy improving their profit margins cutting costs wherever they can.
An anonymous reader has commented and raised concerns about these added layer of security for online credit and debit card transactions (collectively known as 3-D secure protocol ).
As you can read on its Wikipedia page, 3-D secure has a long list of criticisms most of them related to its ability to secure online transactions.
I will try to address all of the reader's concern below:
- RBI never sponsored or stated specific systems such as Verified by Visa or Mastercard UCAF/SPA in its directive.
In my article also I did not say that RBI has specified VbyV or Secure Code must be used. RBI article only says that additional info ( apart from what is already present on the card ) is required for online transaction. Since most ( say 95 % ) of the card holders in India have either Visa or Master Card they will have to use either of these two services hence I explained their features from an end-user perspective. For American Express cards they ask for the billing address for verification.
- The anonymous reader has pointed out some security vulnerabilities in 3-D Secure giving some examples like inline frame and activation during shopping.
Although I can't vouch for all banks in India, but I deal with HDFC Bank which does not use inline frame during 3-D secure authorization and it also has PAM ( Personal Assurance Message ).
It does have Activation during shopping but that too:
- is on hdfcbank.com domain with a proper SSL certificate ( no inline frame )
- requires your ATM password for authentication ( I don't know if the number of attempts is unlimited ). This I feel is secure enough.
But, I also know of cases where card issuing companies don't use their own domain during 3-D secure authorization like:
- SBI Card ( uses arcot.com )
- ICICI Bank ( uses payseal.com )
So our anon reader does have a valid point here. These systems are not 100% safe because of some inherent weakness in the Internet protocols.
- Then he raises a concern that the password can be easily phished and used by fraudsters. The transactions can never be disputed by the cardholder.
On this I don't agree with him. If there was no 3-D secure anyone who had physical access to the card even for a minute ( think of the last time you gave it for payment in the restaurant ) could have misused it ( by noting down the card details ). But introduction of 3-D secure had made life more difficult for fraudsters.
If transactions could be disputed without 3-D secure, they can still be disputed with 3-D secure activated as well. 3-D secure is not going to change that.
- A concern about fraudsters misusing this feature to cheat banks
This is a matter between the fraudsters between the banks and the fraudsters and I'm really not too much concerned about it. One thing I would like to point out here is that the act of issuing a card is not a completely online thing ( atleast in India ). There are id and address checks. Credit report is also verified. So if the bank has a diligent process in place before it issues a card, the chances of such cheating are lessened. However if the bank has lax procedures it obviously has to suffer ( that's in its Karma! )
- Be wary of mandated systems. A good security system never needs to be mandated.
If it is not mandated, the banks won't implement any safety feature. Only very few who actually care about customer concerns would be willing to do it on their own, since setting up an IT infrastructure for such a feature costs money and the management of banks is busy improving their profit margins cutting costs wherever they can.
Labels:
Credit Cards,
HDFC,
ICICI,
RBI,
SBI
ICICI can deduct money from your salary - WITHOUT your consent
ICICI Bank has modified the credit card agreement wherein they can deduct credit card dues from your salary directly ( by asking your employer to do so ). Any sort of agreement between your employer and you cannot prevent this deduction from your salary.
Although I don't hold any ICICI credit card, this may start a dangerous trend in the Indian credit card industry which will soon be followed by others also.
Just imagine the following scenario:
- You notice a fraudulent transaction on your card. You dispute it with the Credit card company.
- The Credit card company ( i.e. ICICI Bank ) does not agree with you and decides to charge you.
- They instruct your employer to deduct the money from your salary. You CAN'T stop it.
Or a second scenario:
- Usually private credit card companies delay cheque payments by 4-5 days so that they can charge you for late payments.
- Nowadays you can get these charges reversed after some negotiation with the customer care.
- But after this rule is implemented, the bank can directly deduct such fees ( like late fees ) from your salary. The Bank does not have to negotiate with you.
Remember this clause in the card member agreement has been inserted by a Bank which had introduced a rule in the year 2003 stating that more than 3 cash transactions at the home-branch will be charged. They of course had to take back such restrictions on RBI directions.
If I held an ICICI card, I would have immediately cancelled it citing this change in agreement as the reason. If ICICI card holders cancel their cards in sufficient numbers, other credit card companies won't dare to make such changes to the card agreement. Also, if money is deducted from your salary for wrong reasons by the credit card company, I will suggest you first approach the RBI Ombudsman and then Consumer Courts. Lets see if this rule can stand in a court of law.
Although I don't hold any ICICI credit card, this may start a dangerous trend in the Indian credit card industry which will soon be followed by others also.
Just imagine the following scenario:
- You notice a fraudulent transaction on your card. You dispute it with the Credit card company.
- The Credit card company ( i.e. ICICI Bank ) does not agree with you and decides to charge you.
- They instruct your employer to deduct the money from your salary. You CAN'T stop it.
Or a second scenario:
- Usually private credit card companies delay cheque payments by 4-5 days so that they can charge you for late payments.
- Nowadays you can get these charges reversed after some negotiation with the customer care.
- But after this rule is implemented, the bank can directly deduct such fees ( like late fees ) from your salary. The Bank does not have to negotiate with you.
Remember this clause in the card member agreement has been inserted by a Bank which had introduced a rule in the year 2003 stating that more than 3 cash transactions at the home-branch will be charged. They of course had to take back such restrictions on RBI directions.
If I held an ICICI card, I would have immediately cancelled it citing this change in agreement as the reason. If ICICI card holders cancel their cards in sufficient numbers, other credit card companies won't dare to make such changes to the card agreement. Also, if money is deducted from your salary for wrong reasons by the credit card company, I will suggest you first approach the RBI Ombudsman and then Consumer Courts. Lets see if this rule can stand in a court of law.
Labels:
Banks,
Credit Cards,
ICICI,
RBI
Thursday, April 30, 2009
ATM usage is free, so now we charge you for Fund transfer
As I had blogged earlier, thanks to a RBI notification transactions done at all ATMs across India are free of charges ( i.e. no charges for using other bank ATMs within India )
But now HDFC Bank has decided to charge for NEFT ( National Electronic Fund Transfer ) henceforth at the rate of Rs. 5 plus taxes for every transaction. This may have something to do with RBI's decision not to waive off charges after March 31,2009. Also Rs. 5 was the upper limit for charges specified by the RBI for transactions not exceeding Rs. 1 Lakh.
Similarly Axis Bank has introduced some security features to use NEFT facility online for which they will charge an annual fees. But most of these security features like code on SMS are offered free of cost by other banks like ICICI & Citibank. Then why does Axis Bank has to charge for a security feature which is provided free of cost by other private banks which have similar AQB requirements? And you can't use NEFT online with Axis Bank without having these security features so there is no other option to the customer than to pay.
Also HDFC Bank by levying charges for NEFT fails to understand that Indian customers are very price sensitive and even if 25% of the transactions which happen on NEFT presently shift to cheques then their work will increase manifold. Since processing of cheques requires human intervention & lot of paper work but NEFT processing is almost completely done by computers.
I believe HDFC Bank is taking a chance here, they are waiting to see the response of their competitors and customers.If their competitor ( read ICICI Bank ) also decides to levy charges for NEFT then all other banks will also follow suite. ICICI Bank also charges for NEFT now i.e. Rs. 5+ tax for less than Rs. 1 lac and Rs. 25 + tax for more than Rs. 1 Lac.The days of no-charges NEFT for bank customers are over :(
But now HDFC Bank has decided to charge for NEFT ( National Electronic Fund Transfer ) henceforth at the rate of Rs. 5 plus taxes for every transaction. This may have something to do with RBI's decision not to waive off charges after March 31,2009. Also Rs. 5 was the upper limit for charges specified by the RBI for transactions not exceeding Rs. 1 Lakh.
Similarly Axis Bank has introduced some security features to use NEFT facility online for which they will charge an annual fees. But most of these security features like code on SMS are offered free of cost by other banks like ICICI & Citibank. Then why does Axis Bank has to charge for a security feature which is provided free of cost by other private banks which have similar AQB requirements? And you can't use NEFT online with Axis Bank without having these security features so there is no other option to the customer than to pay.
Also HDFC Bank by levying charges for NEFT fails to understand that Indian customers are very price sensitive and even if 25% of the transactions which happen on NEFT presently shift to cheques then their work will increase manifold. Since processing of cheques requires human intervention & lot of paper work but NEFT processing is almost completely done by computers.
I believe HDFC Bank is taking a chance here, they are waiting to see the response of their competitors and customers.
Thursday, February 26, 2009
Online transactions now even safer
Traditionally, to transact with a credit card ( either online or over the phone ) all the info required for processing the payment is present on the card.
The info that is usually needed for transacting is:
1. The 16-digit card number
2. Expiry date of the card
3. The CVV ( Credit Verfification Value ) found on the back of the card
4. The card holder's name
Since, all this info is present on the card, the customers always had security concerns related to credit card usage online. To address customers' security concerns Visa and MasterCard came up with initiatives like Verified by Visa and MasterCard SecureCode. Basically both of them worked on the same principle.A separate password, apart from the info already found on the card is required to complete a credit card transaction.
The diagram below will help you understand the "Verified by Visa" or "MasterCard SecureCode" better.

But there are 2 limitations to "Verified by Visa" or "MasterCard SecureCode" which might have hampered its popularity in India.
1. The merchant ( i.e. merchant's payment gateway ) must support these features.
2. Also, the credit card issuing bank must support these security features. Although most large private banks ( like ICICI, HDFC ) support these security features, most of the PSU Banks still do not support "Verified by Visa" or "MasterCard SecureCode" for online transactions.
If either the payment gateway or the bank does not support them, the customer cannot use "Verified by Visa" or "MasterCard SecureCode" for online transactions.
Now RBI has made such authentication, based on info not found on the card( i.e. with a separate password ), mandatory for all online transactions. Also it is mandatory to send SMS and online alerts for online transactions exceeding Rs. 5000. What this means is that all payment gateways and card-issuing banks will have to support authentication by a separate password. Please note that these regulations are applicable only from August 2009.
As per this report, RBI is also working on security features to be employed for credit card transactions over the telephone. These regulations will go a long way in ensuring the safety of your online & IVR transactions. Thanks, RBI.
The info that is usually needed for transacting is:
1. The 16-digit card number
2. Expiry date of the card
3. The CVV ( Credit Verfification Value ) found on the back of the card
4. The card holder's name
Since, all this info is present on the card, the customers always had security concerns related to credit card usage online. To address customers' security concerns Visa and MasterCard came up with initiatives like Verified by Visa and MasterCard SecureCode. Basically both of them worked on the same principle.A separate password, apart from the info already found on the card is required to complete a credit card transaction.
The diagram below will help you understand the "Verified by Visa" or "MasterCard SecureCode" better.
But there are 2 limitations to "Verified by Visa" or "MasterCard SecureCode" which might have hampered its popularity in India.
1. The merchant ( i.e. merchant's payment gateway ) must support these features.
2. Also, the credit card issuing bank must support these security features. Although most large private banks ( like ICICI, HDFC ) support these security features, most of the PSU Banks still do not support "Verified by Visa" or "MasterCard SecureCode" for online transactions.
If either the payment gateway or the bank does not support them, the customer cannot use "Verified by Visa" or "MasterCard SecureCode" for online transactions.
Now RBI has made such authentication, based on info not found on the card( i.e. with a separate password ), mandatory for all online transactions. Also it is mandatory to send SMS and online alerts for online transactions exceeding Rs. 5000. What this means is that all payment gateways and card-issuing banks will have to support authentication by a separate password. Please note that these regulations are applicable only from August 2009.
As per this report, RBI is also working on security features to be employed for credit card transactions over the telephone. These regulations will go a long way in ensuring the safety of your online & IVR transactions. Thanks, RBI.
Labels:
Credit Cards,
HDFC,
ICICI,
RBI
Monday, December 15, 2008
Tax free bonds are back!
Remember 6.5% tax free bonds issued by RBI, which were dis-continued in July, 2004. Now RBI only issues 8% taxable bonds.
Govt of India has decided to re-introduce tax-free bonds, as part of the stimulus package for the economy. But this time they are being floated by IIFCL and not by RBI.
Its features:
- Comes with sovereign guarantee ( it means that the returns are guaranteed by Govt. of India )
- Coupon rate is 7.5 % ( much better than the older RBI 6.5% tax-free bonds )
- Will have a lock-in period of atleast 10 years
- The first issue will be through private placement, but the subsequently there will be a public issue as well.
- I speculate that they will be listed on atleast on one of the stock exchanges ( probably, BSE ) in order to provide early exit option to investors.
The article in link, also describes how this scheme is going to work:
- IIFCL raises money through these bonds at 7.5%
- IIFCL pays 0.25% annually to the Central Govt. for the sovereign guarantee it offers
- IIFCL lends this money to banks at 8.5%
- Banks can then use this to re-finance infrastructure projects at any rate between 8.5% - 11%
Tax-free bonds are a very good option for HNIs ( High-net worth individuals ) and those in the higher tax slab ( i.e. 30% ). Individuals in the lower tax slab may stick with Bank FDs, since they are offering higher yields presently.
Govt of India has decided to re-introduce tax-free bonds, as part of the stimulus package for the economy. But this time they are being floated by IIFCL and not by RBI.
Its features:
- Comes with sovereign guarantee ( it means that the returns are guaranteed by Govt. of India )
- Coupon rate is 7.5 % ( much better than the older RBI 6.5% tax-free bonds )
- Will have a lock-in period of atleast 10 years
- The first issue will be through private placement, but the subsequently there will be a public issue as well.
- I speculate that they will be listed on atleast on one of the stock exchanges ( probably, BSE ) in order to provide early exit option to investors.
The article in link, also describes how this scheme is going to work:
- IIFCL raises money through these bonds at 7.5%
- IIFCL pays 0.25% annually to the Central Govt. for the sovereign guarantee it offers
- IIFCL lends this money to banks at 8.5%
- Banks can then use this to re-finance infrastructure projects at any rate between 8.5% - 11%
Tax-free bonds are a very good option for HNIs ( High-net worth individuals ) and those in the higher tax slab ( i.e. 30% ). Individuals in the lower tax slab may stick with Bank FDs, since they are offering higher yields presently.
Subscribe to:
Posts (Atom)