Skip to main content

Posts

Showing posts from June, 2022

Systems are very bad people

In April this year, ASIC commenced action against Macquarie Bank for failing to “monitor, detect and prevent unauthorised transactions”.  These charges relate to actions of convicted fraudster Ross Hopkins, but crucially, ASIC specified their action was “not focused on Mr Hopkins’ conduct”. Where compliance is achieved through a combination of system functionality and user action - and the focus is not the conduct of the user - where does the moral accountability lie for financial fraud? * The practical reality is that users often rely on system functionality to "monitor, detect and prevent" actions which are “not permitted”.   Greyed-out menu items or modal warnings indicate, by convention, which operations are "permitted". But there are two types of authority at play here - one of the system, the other of the user. The first is an authority as in "your access level in the system means you could click this button" and the second is an authority as in &qu