Recent discussions around online banking scams have raised important questions about liability when customers approve transactions that turn out to be fraudulent. The debate often centers on whether the customer or the bank should bear the loss, or whether responsibility should be shared. However, some experts suggest the fundamental issue is understanding why individuals entrust their money to banks rather than keeping it themselves.
Traditionally, customers deposited money in banks because these institutions were perceived to offer a safer, more reliable method for storing and transferring funds. This trust has been built on the expectation that banks provide security that individuals cannot replicate by holding cash at home. Yet, the evolution of banking—from in-person branch visits and paper-based transactions to instantaneous digital transfers—has introduced new challenges, including phishing, malware, and social engineering attacks that compromise accounts.
A key point in this debate is the role of the customer’s authorisation. Typically, if a customer enters a password, provides a one-time password (OTP), or otherwise approves a transaction, banks often consider the transaction authorised and may hold the customer responsible for any resulting loss. However, critics argue this view oversimplifies the issue. While banks should not act on forged or unauthorised instructions, the process through which digital approvals are obtained and verified is itself part of the banking system and warrants scrutiny.
Experts highlight that, in the digital era, the customer’s mandate is given through the bank’s technological systems, which include authentication protocols, transaction limits, warning mechanisms, and fraud detection tools. This integrated system should be evaluated not only by whether the customer formally approved the transaction but also by how effectively the system detected and responded to unusual or risky behaviors at the time of the transaction.
Some have pointed to observations by figures such as Datuk Seri Azalina Othman Said, who questioned the adequacy of expecting customers to bear losses simply because transactions were authorised digitally. This perspective raises the broader issue of what customers are paying banks to do if not to provide protection and reliability beyond mere authorization checkmarks.
Acknowledging that no security system can entirely eliminate fraud, there remains an expectation that banks offer protections significantly superior to what an individual could achieve independently. Assessing liability should therefore consider both the customer’s actions and the bank system’s response, including whether known risks were identified and addressed effectively.
In summary, the discussion about banking fraud and responsibility calls for deeper examination of banking system reliability. Rather than focusing solely on transaction authorization, it is crucial to ask whether the digital banking platform functioned with sufficient safeguards to merit the customer’s trust and provide reasonable protection against fraud.
