Bank of Ireland

company

We found 5 decisions about Bank of Ireland from Central Bank and DPC, the latest dated 27 February 2023.

Fine, Reprimand, Order to comply — 27 February 2023
Data Protection Commission

Resources Guidance Decisions Law Blogs Podcasts Publications Case Studies Inquiry into Bank of Ireland 365 Area: Bank/Credit/Insurance Topic: Data security Articles: 5 , 32 DPC Reference: IN-20-7-2 Decision Date: 27 February 2023 The inquiry was commenced after BOI notified the DPC of a series of 10 data breaches relating to the BOI365 banking app. The data breach notifications concerned individuals gaining unauthorised access to other people’s accounts via the BOI365 app. The decision considered whether BOI had complied with Articles 5(1)(f) and 32(1) GDPR and, in particular, whether BOI had implemented appropriate technical and organisational measures to ensure a level of risk appropriate to the risks associated with its processing of data via the BOI365 app. After investigation, the decision found that BOI had infringed its obligations under Articles 5(1) and 32(1) GDPR as the technical and organisation measures in place at the time were not sufficient to ensure the security of the personal data processed on the BOI365 app. Corrective Powers Exercised: The decision issued BOI with a reprimand in respect of the infringements Articles 5(1)(f) and 32(1) GDPR. The decision ordered BOI to bring its processing into compliance with Articles 5(1)(f) and 32(1) GDPR. The decision imposed an administrative fine on BOI in the amount of €750,000 in respect of the infringement of Article 5(1)(f) GDPR. For more information, you can download the full decision at this link: Inquiry into Bank of Ireland 365 - February 2023 (PDF, 1.8mb) .

Extract from the regulator's publication.
Read the decision on the DPC website
Fine, Reprimand, Order to comply — 29 September 2022
Central Bank of Ireland — €100.5 million

Background to the Investigation Bank of Ireland is a bank licensed pursuant to Section 9 of the Central Bank Act, 1971. It has over 169 branches and approximately 2.2 million customers. Its principal activities consist of retail and commercial banking. 4 Bank of Ireland introduced tracker mortgages into its suite of mortgage product offerings in 2001. In October 2008, Bank of Ireland withdrew tracker mortgages as a product offering for new customers because, in line with other industry participants, Bank of Ireland viewed tracker mortgages to be unprofitable. At the same time, Bank of Ireland carried out an assessment to determine the tracker entitlements of its existing customers. Although Bank of Ireland determined that many customers were entitled to tracker rates, Bank of Ireland concluded that certain groups of customers were not entitled to revert to a tracker rate after a fixed rate period ended, despite identifying ambiguities in their MLOs and MFAs relating to whether or not customers were entitled to revert to or be offered a tracker rate. Bank of Ireland’s actions in doing so were in breach of its regulatory obligations. Bank of Ireland maintained that position until 2017, despite the fact that it either knew or ought to have known that its MLOs and MFAs were unclear. Bank of Ireland’s Deficient Tracker Remediation Programmes In 2010, the Central Bank challenged Bank of Ireland regarding the lack of clarity of its MLO and MFA documentation.

Extract from the regulator's publication.
Read the decision on the Central Bank website
Fine, Reprimand — 2 December 2021
Central Bank of Ireland — €24.5 million

The Central Bank has determined the appropriate fine to be €35,000,000, which has been reduced by 30% to €24,500,000 in accordance with the settlement discount scheme provided for in the Central Bank’s ASP. The Firm has admitted five contraventions1 occurring between 2008 and 2019 including:  The failure to demonstrate an ability to ensure continuity of service in the event of significant IT disruption; 1 Breaches of the European Communities (Licensing & Supervision of Credit Institutions) Regulations 1992 (S.I. No. 395 of 1992) (as amended)) and the European Union (Capital Requirements) Regulations 2014 (S.I. No. 158 of 2014). 2  The failure to have effective internal controls to identify deficiencies in the IT service continuity framework and ensure they were escalated to the senior management committees and ultimately the Board; and  The failure to properly engage and oversee the management of third party IT service providers with respect to IT service continuity. Firms and their boards are responsible for having an effective IT service continuity framework and associated internal controls. These are core parts of a firm’s operational resilience and will continue to be an area of focus as part of the Central Bank’s and the European Central Bank’s supervisory strategy. It is vital that firms have a framework in place so that they can ensure continuity of critical IT services and minimise the impact of any significant disruption.

Extract from the regulator's publication.
Read the decision on the Central Bank website
Fine, Reprimand — 28 July 2020
Central Bank of Ireland — €1.7 million

the Central Bank has determined the appropriate fine to be €2,370,000, which has been reduced by 30% in accordance with the settlement discount scheme provided for in the Central Bank’s Administrative Sanctions Procedure. The Central Bank’s investigation arose from a cyber-fraud incident that occurred in September 2014 (the Incident). Acting on instructions from a fraudster impersonating a client, BOIPB made two payments to a third party account totalling €106,430: one from a client’s personal current account, the other from BOIPB’s own funds. BOIPB immediately reimbursed the client. During a Full Risk Assessment of BOIPB in 2015, the Central Bank discovered a reference to the Incident in an operational incident log. BOIPB had not reported the cyber-fraud to An Garda Síochána, and only did so at the request of the Central Bank over one year after the Incident. The Central Bank’s investigation found serious deficiencies in respect of third party payments, including:  Inadequate systems and controls to minimise the risk of loss from fraud  Inadequate governance, oversight and ongoing review of the systems and control environment  Lack of staff training and a culture in which fulfilling clients’ instructions was given primacy over security and regulatory requirements  Lack of compliance monitoring. BOIPB’s failure to be open and transparent had the effect of misleading the Central Bank in the course of the investigation. BOIPB failed for a period of 19 months to disclose to the Central Bank an internal report, commissioned following the Incident, which identified ongoing systemic control failings in the processing of third party payments.

Extract from the regulator's publication.
Read the decision on the Central Bank website
Settlement, Fine, Reprimand — 30 May 2017
Central Bank of Ireland — €3.1 million

BACKGROUND BOI is authorised to carry on banking business in Ireland as a credit institution under Section 9 of the Central Bank Act 1971. 3 BOI is one of the largest banks in Ireland with over 250 branches, over 1.7 million consumer banking customers and in excess of 200,000 business banking customers. Its principal activities consist of retail and commercial banking. The Central Bank has responsibility for monitoring and enforcing the compliance of credit and financial firms with the CJA 2010. During 2013, the Central Bank conducted a review of BOI’s compliance with the CJA 2010. This review identified a number of issues concerning suspected non-compliance with the CJA 2010. The Central Bank subsequently engaged with BOI on remediation of the issues identified and an investigation into suspected breaches of the CJA 2010 commenced. PRESCRIBED CONTRAVENTIONS The Central Bank’s investigation identified twelve breaches of the CJA 2010, namely: Risk Assessment A thorough assessment of ML/TF risk exposure is fundamental to a robust AML/CFT framework. It allows a firm to identify the particular ML/TF risks to which it is exposed due to its business model. It informs the development of appropriate AML/CFT policies and procedures and the design of proportionate systems. The risk assessment must be proportionate to the nature, scale and complexity of a firm’s activities. Insufficient or absent ML/TF risk management policies, procedures and processes exposes firms to significant risks, including not only financial, but also reputational, operational and compliance risks.

Extract from the regulator's publication.
Read the decision on the Central Bank website
Monitor Bank of Ireland (email on any new decision) or order a dated report (€19).

Nearby in the register

See also: Central Bank · DPC