International comparison of bank fraud reimbursement: customer perceptions and contractual terms

The study presented in this article investigated to what extent bank customers understand the terms and conditions (T&Cs) they have signed up to. If many customers are not able to understand T&Cs and the behaviours they are expected to comply with, they risk not being compensated when their...

Full description

Saved in:  
Bibliographic Details
Main Author: Abu-Salma, Ruba (Author)
Contributors: Stringhini, Gianluca ; Sasse, M Angela ; Murdoch, Steven J ; Hutchings, Alice ; Bohm, Nicholas ; Becker, Ingolf ; Anderson, Ross
Format: Electronic Article
Language:English
Published: 2016
In: Journal of Cybersecurity
Year: 2016
Online Access: Volltext (kostenfrei)
Volltext (kostenfrei)
Journals Online & Print:
Drawer...
Check availability: HBZ Gateway
Description
Summary:The study presented in this article investigated to what extent bank customers understand the terms and conditions (T&Cs) they have signed up to. If many customers are not able to understand T&Cs and the behaviours they are expected to comply with, they risk not being compensated when their accounts are breached. An expert analysis of 30 bank contracts across 25 countries found that most contract terms were too vague for customers to infer required behaviour. In some cases the rules vary for different products, meaning the advice can be contradictory at worst. While many banks allow customers to write Personal identification numbers (PINs) down (as long as they are disguised and not kept with the card), 20% of banks categorically forbid writing PINs down, and a handful stipulate that the customer have a unique PIN for each account. We tested our findings in a survey with 151 participants in Germany, the USA and UK. They mostly agree: only 35% fully understand the T&Cs, and 28% find important sections are unclear. There are strong regional variations: Germans found their T&Cs particularly hard to understand, and USA bank customers assumed some of their behaviours contravened the T&Cs, but were reassured when they actually read them
ISSN:2057-2093
DOI:10.1093/cybsec/tyx011