System and method for secure interface between financial institution and customer entities

The access control system addresses inefficiencies in financial institution onboarding by integrating registration, profiling, and access modules to provide secure, efficient, and accurate risk-based financial services access, reducing institutional overheads and enhancing security through a unified platform.

GB2638167APending Publication Date: 2025-08-20AGAM INT LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
GB2024001995
Authority / Receiving Office
GB · GB
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-13
Publication Date
2025-08-20

AI Technical Summary

Technical Problem

Existing financial institution customer onboarding processes are inefficient, time-consuming, and resource-intensive, often requiring repetitive customer profiling and interrogation, which can be biased and fail to accurately derive a true risk profile due to limited verification means.

Method used

An access control system that integrates a registration module, profiling module, and access module to manage customer registration, generate risk profiles using machine learning, and provide financial functions based on these profiles, allowing customers to access multiple institutions through a single platform with enhanced security and reduced processing overheads.

Benefits of technology

Facilitates rapid, secure, and efficient access to financial services by deriving real-time risk profiles, reducing institutional processing and communication overheads, and enhancing security by limiting access to pre-authorized entities, thus improving the speed and accuracy of financial product offerings.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

An access control system 20 for securely interfacing with a financial institution and customer entities includes a module for controlling registration of the customers and a module for generating risk profiles for the registered customers and providing S45 a risk profile for a requesting customer to a financial institution. An access module provides a financial function(s) S46 of the financial institution to the requesting customer, the financial functions being dependent on their risk profile, and the provision being dependent upon a set of access privileges. The risk profile may be derived using machine learning. A method of securing communication between a user terminal and a financial institution involves activating a link S42 received from a server, the link causing installation of a server interface application and a request for registration, including user information. Authorisation is received from the server to access functions of the financial institution, in accordance with a set of access privileges, when the user information is determined to match a user profile registered at the server.
Need to check novelty before this filing date? Find Prior Art

Description

Field of invention The present invention relates to secure communication with a financial institution, and particularly to regulating an entity's access to functions of a financial institution in accordance with security credentials. Embodiments of the present invention provide a secure interface between a financial institution and its customers. Further embodiments of the present invention provide a software application enabling secure interaction between customers and a financial institution. Further embodiments make use of artificial intelligence to provide significant improvements to the speed and scale of provision of financial functions, responding in real-time to changes in circumstances. Technical background Financial institutions, such as banks and building societies, typically offer financial services and products whose nature is dependent upon a customer's financial circumstances. For example, customers with greater financial means, or a stronger credit history, may be offered products such as a loan or mortgage which have more favourable repayment terms than products offered to customers in a weaker financial position. This protects the financial institution from risks associated with the customer re-paying a loan or mortgage in the future. When a new customer approaches a financial institution to request access to a particular financial service or product, it is typically necessary for a registration process to be completed in order for the customer to be onboarded and given appropriate clearance by the financial institution. This involves the customer providing details of their financial circumstances and security information, so that a customer profile can be established and financial products can be offered which are appropriate for that customer profile. This can be a time-consuming process for both the customer and the financial institution. For example, the same customer may approach a number of different financial institutions requesting a similar product, in order to be able to make a comparison between the specific variants of the product which are offered by each institution, and is required to repeat a similar registration process for each new institution. Financial institutions also require evaluation of each potential new customer before they can be enrolled, which involves significant repetition of the same interrogation process in order to establish each customer profile. If the financial institution is accessed electronically, via a website or an application on a terminal such as a mobile phone, the interrogation process consumes data communication and processing resources, and in many cases, such resources are wasted if the available financial products are not deemed to be suitable for the customer in view of their financial circumstances. Further, the interrogation process is often biased by the nature of a user's responses and the way in which they explain their particular financial circumstances and behaviour. A true risk profile may be difficult to derive, as there is a limited means of verifying all of the information that a user might provide. Further, the user may present information representing a snapshot of their circumstances at a particular point in time, from which longer-term behavioural trends, and their associated impact on a risk profile, may be difficult to identify. There are consequently a number of inefficiencies and limitations associated with the process of making appropriate financial products or services, generalised herein as 'financial functions' available to a customer. Embodiments of the present invention seek to address such difficulties by the construction of a platform connecting customers to financial institutions, where the ability of a customer to access a function of the financial institution is controlled by the platform, rather than by the financial institution. In doing so, processing and communication overheads of the financial institution are reduced. For example, a particular financial product may be offered to an entity only if the entity has been preauthorised for such a financial product by the platform. The platform may simultaneously interface with a plurality of different financial institutions so that a potential new customer is required to enrol only once with the platform in order to be able to access functions of multiple financial institutions. Further, the processing and communication overheads of the platform itself are reduced, and security is enhanced, by the platform being accessible only to entities who have an endorsement from an entity that is already registered with the platform. Users whose financial circumstances are entirely unknown are therefore not able to access the platform, and particular security credentials are thus required in order for the user to derive the platform's benefits. Once access is provided, embodiments of the present invention use artificial intelligence to derive a risk profile for the user which is based on real-time modelling of several parameters, in order to enable appropriate financial functions to be delivered rapidly. As such, embodiments of the present invention provide an access control system for securely interfacing with a financial institution. Further embodiments of the present invention provide a method of securing communication between a user terminal and a financial institution. Further embodiments of the present invention provide a computer program which, when executed by one or more processors, is configured to cause the above method to be performed. Summary of Invention According to an aspect of the present invention, there is provided an access control system for securely interfacing with a financial institution and a plurality of customer entities, comprising: a registration module for controlling registration of customer entities; a profiling module for generating risk profiles of the registered customer entities based on a plurality of parameters, and for providing a generated risk profile of a requesting customer entity to the financial institution; and an access module for providing one or more financial functions of the financial institution to the requesting customer entity, wherein the financial functions are dependent on the generated risk profile of the requesting entity, and are provided in dependence upon a set of access privileges. In embodiments, the profiling module is arranged to aggregate entity information from a plurality of data sources in real time. In embodiments, the profiling module uses a machine-learning algorithm to derive a risk profile for an entity based on information from the plurality of data sources indicative of behavioural characteristics of the entity. In embodiments, the registration module is arranged to receive, from a registered entity, user profile information for each of a plurality of users associated with the registered entity, and store the user profile information in a registration database; the access module is arranged to authorise the requesting entity to access functions of the financial institution in accordance with a first set of access privileges; and the registration module is arranged to: provide the plurality of users with access to a communication channel through which to request user registration; receive a request for registration, through the communication channel, from a user of the plurality of users, the request comprising user information; compare the received user information with the stored user profile information; and register the user in the registration database when the received user information matches stored user profile information; wherein the access module is arranged to confirm to the financial institution that the registered user is authorised to access functions of the financial institution in accordance with the first set of access privileges. In embodiments, the user profile information includes contact information. In embodiments, access to the communication channel is provided via an executable link in an electronic message provided to the plurality of users. In embodiments, the registered user is a first registered user, wherein the registration module is arranged to receive a request for registration from a second user, and register the second user in the registration database when the request comprises information identifying the first registered user. In embodiments, the access module is arranged to receive, from the financial institution, confirmation of completion of a financial transaction by the registered user; wherein the registration module is arranged to verify the registered user in the registration database in response to receiving the confirmation; and wherein the access module is arranged to confirm to the financial institution that the verified user is authorised to access functions of the financial institution in accordance with a second set of access privileges permitting greater access than the first set of access privileges. In embodiments, the entity is a first entity, wherein the registration module is arranged to: receive a request from a second entity for registration, wherein the request comprises information identifying a referring user for the second entity and a geolocation of the second entity; identify an entity associated with the referring user, and if the identified entity is the first entity, and if the referring user is a verified user, determine a geolocation of the first entity and compare the geolocation of the first entity with the geolocation of the second entity; register the second entity in the registration database when the determined geolocation of the second entity is within a predetermined proximity of the geolocation of the first entity by receiving user profile information for each of a plurality of users associated with the second entity and storing the user profile information in the registration database; wherein the access module is arranged to provide the plurality of users associated with the second entity with access to a communication channel through which to request user registration; and wherein the registration module is arranged to authorise the second entity to access functions of the financial institution in accordance with the first set of access privileges. In embodiments, the predetermined proximity is obtained by the registration module performing the steps of: determining a proximity score based on which of a plurality of predefined distance ranges represents the distance between the geolocation of the first entity and the geolocation of the second entity; and determining an entity categorisation for the second entity, defining the threshold to be applied to the predetermined proximity score to determine whether the geolocation of the second entity is within a predetermined proximity of the geolocation of the first entity. In embodiments, the referring user is a first referring user, and the registration module is further arranged to: receive a request for verification of the second entity, wherein the request for verification comprises information identifying a second referring user for the second entity; if the request for verification of the second entity is received within a predetermined time of the request for registration of the second entity, the registration module identifies an entity associated with the second referring user, and if the identified entity is the first entity, verifies the second entity in the registration database, and confirms to the financial institution that the verified second entity is authorised to access functions of the financial institution in accordance with the second set of access privileges. In embodiments, the first set of access privileges permits access to a first set of functions of the financial institution, and the second set of access privileges permits access to a second set of functions of the financial institution, wherein the second set of functions includes the first set of functions and first additional functions, and wherein the first set of functions is associated with financial information of the stored user profile information. In embodiments, the profiling module is arranged to obtaining data from a registered user representing a user's interaction with a user device through which the first set of functions is accessed, and the access module is arranged to provide access to a third set of functions of the financial institution including the first set of functions and second additional functions if the level of user interaction with the user device exceeds a predetermined threshold. According to another aspect of the present invention, there is provided a method of securing communication between a user terminal and a financial institution, the method comprising: receiving an electronic message from a server, the electronic message including an executable link; and receiving an activation command, from a user, to activate the link and executing the link in response to receiving the activation command; wherein executing the link causes: download and installation of an application providing an interface to the server; and transmission, from the user device, of a request for registration, to the server, the request including user information for the user of the user device; receiving authorisation, from the server, of the user to access functions of the financial institution, via the interface, in accordance with the first set of access privileges, when the user information is determined to match a user profile registered at the server. In embodiments, the application provides a selectable command which, when selected through a user interface by the user, sends an electronic message to a further user to invite the first user to request registration with the server, and wherein the user receives credit to a registration score associated with a user account for the application, when the application receives confirmation that the further user is registered. In embodiments, the application is configured to track a level of interaction between the user and an interface to the financial institution by measuring the time for which the interface is displayed on a screen of the user device, and / or by measuring user inputs to the interface, and the application is configured to request that the server authorises access to financial services which are additional to financial services associated with the first set of access privileges, when the level of interaction between the user and the interface exceeds a predetermined threshold. In embodiments, tracking a level of interaction between the user and an interface to the financial institution includes tracking the level of interaction between the user and a financial education function provided via the interface. According to another aspect of the present invention, there is provided a computer program which, when executed by one or more processors, is configured to cause the above method to be performed. The access control technique which is described herein, and which represents the platform described above, enables the establishment of an interconnected ecosystem, within which particular financial functions are accessed by customers and used. Embodiments of the present invention enable banks and other financial institutions to connect to a new, digitally onboarded customer base of trusted individuals and businesses. Brief description of drawings Embodiments of the present invention will be described by way of example, with reference to the accompanying figures, of which: Figure 1 illustrates a network containing an access control system, according to embodiments of the present invention; Figure 2 illustrates an access control system according to embodiments of the present invention; Figure 3 illustrates a functional representation of the access control system of Figure 2, according to embodiments of the present invention; and Figure 4 illustrates the data flows associated with the verification of a new customer by the access control system. Detailed description Network Overview Figure 1 illustrates an example of a system within which an access control system 10, according to embodiments of the present invention, is positioned. The illustrated system shows the relationship between entities, financial institutions, and the access control system, as a network showing the available data communication paths and associations between the different network components. The access control system 10 is positioned as an interface between the customer entities and the financial institutions. In the network illustrated in Figure 1, the financial institutions comprise three banks 11, 12, 13, and the customer entities include a small business 14, a large company 15, an employee 16 of the small business 14, employees 17,18 of the larger company 15, and an individual 19 not employed by a company associated with the access control system 10. It will of course be appreciated that the network illustrated in Figure 1 is a simplification of the network within which the access control system 10 is to be installed, in which there are far larger numbers of financial institutions and customer entities. Access Control System The access control system 10 regulates access to particular financial functions offered by any of the banks 11, 12,13. The regulation is described in conjunction with Figure 2, which illustrates an access control system 20 or platform according to embodiments of the present invention. The access control system 20 shown in Figure 2, which corresponds to a detailed illustration of access control system 10 shown in Figure 1, comprises a bank interface 21, an individual customer interface 22, and a company interface 23 for providing a data communications interface with employers 14,15 of individuals 16,17,18. The interfaces 21, 22, 23 include electronic communication means such as telecommunication links or links to one or more external computer servers (not shown). The access control system 20 further comprises at least two databases 24, 25 for storing employer and employee information. The operation of the access control system 20 is illustrated as being controlled by a central processing unit (CPU) 26. The CPU 26 may be implemented as a plurality of distributed processing units, and each of the banking, customer and company interfaces 21, 22, 23 may contain a local processing unit for performing processing functions to be described below. References to operations of each of the banking, customer and company interfaces 21, 22, 23 are to be understood as references to operations of functional modules of the access control system, 20 implemented either by sections of computer code executed by the CPU 26, or executed by dedicated processors within the respective interfaces, or a combination of the CPU and the dedicated processors. In particular, the banking interface 21 comprises what is referred to herein as a profiling module. The profiling module is configured for generating risk profiles of the registered customer entities based on a plurality of parameters, and for providing a generated risk profile of a requesting customer entity to the financial institution. The customer and company interfaces 22, 23 are also referred to herein as a registration module of the access control system 20. The registration module is configured for controlling registration of customer entities. An access module, as referred to herein, is a functional module which is distributed across the banking interface 21 and the customer and company interfaces 22, 23. The access module is configured for providing one or more financial functions of the financial institution to the requesting customer entity, wherein the financial functions are dependent on the generated risk profile of the requesting entity. The arrangement of the profiling module, the access module and the registration module as shown in Figure 3, which shows a functional representation of the access control system 20 of Figure 2, according to embodiments of the present invention. In particular, Figure 3 shows an access control system 30 according to embodiments of the present invention, comprising a registration module 31, a profiling module 32 and an access module 33. The registration module 31 receives requests for registration from users or entities via communication link 34, which is a generalisation of link 28 and link 29 shown in Figure 2. The registration module performs registration and verification operations as described above, and sends electronic messages to customers to invite them to individually register with the access control system 30. The profiling module 32 communicates, via communication link 35, with one or more external data sources for receiving data and parameters indicative of financial and / or behavioural characteristics of an entity, and also external variables. Specific examples of the data sources, and the information exchanged with the profiling module, are described below, and may make use of a machine-learning algorithm which obtains training data relating to historical interactions between a customer and a financial institution, from the access module 33. The profiling module 32 also interfaces with the registration module 31, using, for example, user profile information associated with a company's employees. The profiling module generates a risk profile which is provided to the access module 33. The access module 33 interfaces between customer entities, via communication link 36, and financial institutions, via communication link 37, to enable the provision of financial functions, and customer interaction. A risk profile generated by the profiling mode 32 is provided to financial institutions for selection of one or more financial funebons in dependence upon the risk profile. The particular financial functions which may be accessed are dependent upon one or more access privileges, in the manner described above, which are in turn dependent upon the progression of a registration process as performed by the registration module 31. Embodiments of the present invention are described below with specific reference to the access control system 20 of Figure 2, although it will be appreciated that the description applies equally to the access control system 30 illustrated in Figure 3, by virtue of the correspondence between the features of Figure 2 and 3 described above. The access control system 20 may be hosted by a computer system, having volatile and non-volatile memories, the central processing unit 26, and one or more user interfaces (not shown). The one or more user interfaces permit interaction with the access control system 20 by, for example, a system administrator, who may configure or update the operation of the access control system 20, and may monitor operations of the banking, customer and company interfaces 21, 22, 23. Each of the banking customer, and company interfaces 21, 22, 23 may be associated with user input means and displays, implemented in local hardware, either as dedicated components, or integrated as screens or windows within a single display, or may be accessed remotely as a dashboard to be displayed on a terminal of the system administrator. The profiling module 32 of the banking interface 21 is responsible for performing credit risk assessment of an entity. The credit risk is provided to the banks 11,12,13, which can offer particular financial products to an entity in accordance with the determined risk. The banking interface 21 is associated with the portion of the access module 33 associated with interaction with financial functions, represented by the arrow 27 extending out from the access control system 20 in Figure 2. In order to enable an entity to have the opportunity to enjoy such interaction, it is necessary to assess the entity's security credentials and access privileges, and this is achieved by the registration module 31, representing a combination of the customer and company interfaces 22, 23, in a manner described below. In order to initialise the operation of the access control system 20, one or more predetermined companies or businesses are registered or 'onboarded' with the access control system 20, as approved companies whose employees are permitted to request access to financial functions of the banks 11, 12, 13 via the access control system 20. The predetermined companies may have a particular commercial relationship or physical proximity with an entity which hosts the access control system 20. The hosting entity may, for example, comprise one or more servers in a particular location, and be owned by or contained within an establishment owned by a particular service provider. The predetermined companies can be considered as trusted clients of the service provider. Each onboarded company provides corporate data to the access control system 20, via the company interface 23, over a communication link 28. In embodiments, the company interface 23 operates as a portal to the access control system 20 having a user interface which is accessed by a representative or department of the company, such as a human resources function. The corporate data includes an address of the employer, the number of staff, the date on which staff are paid, an operating permit or licence, and so on. Such information ensures, for the benefit of the banks 11,12,13, that the access control system 20 complies with local legislation relating to knowledge of its clients. The onboarding of such predetermined companies comprises providing such companies with the access privileges required in order to be able to access a set of financial functions provided via the banking interface 21. A company wishing to access such functions provides credentials such as a company name or ID, which is compared with company information held in the employer database 24 hosted by the access control system 20, based on any appropriate authentication protocol. If the provided company name or ID is identified in the employer database 20, access to the set of financial functions is authorised for that company. An onboarded company is able to provide employee payroll information to the access control system 20 through the company interface 23, for storage in the employee database 25. An onboarded company, being a trusted client of the service provider, is thus a company which has agreed with its employees that such information can be shared with the access control system 20, in exchange for the provision of access to benefits provided to the employees by the access control system 20. The payroll data comprises employee names, salaries or salary bands, and may further comprise employee information such as contact details, a salary bank account number, and employment start date. From this data, user profile data is created and stored in the employee database 25. Customer onboarding Once the access control system 20 is provided with such employer and employee information, it is able to contact employees individually, via the customer interface 22, using communication link or links 29. In embodiments of the present invention, the access control system 20 sends an electronic communication, such as a text message, to the employees of the onboarded one or more companies, using the contact information stored in the user profiles in the employee database 25. The message contains a means for establishing a communication channel through which the employee can request personal registration with the access control system 20, via the customer interface 22. In embodiments, text message comprises a link or uniform resource locator (URL), to be executed using a browser application of a user's terminal, such as a mobile device or computer, to activate communication with the customer interface 22 and to enable a registration request to be provided to the access control system 20. In this way, the access control system 20 is able to receive individual user registration requests only if the user is an employee of an onboarded company. The access control system 20 is therefore able to regulate the pool of users which can access financial functions through the banking interface 21, based on the inference that if the user is an employee of a trusted company, the employee is, by extension, also a trusted entity, with a known salary, and thus has a known risk profile for a bank. In some embodiments, the activation of the link or URL causes download of a computer-executable access control application to the user's terminal, and communication with the customer interface 22 is performed over a secure channel via the downloaded access control application, rather than via a system browser on the user's terminal. This enhances the security of the communication, as well as simplifying the user's interaction with the access control system 20, integrating the onboarding process with subsequent access to financial functions which may also be achieved via the application. In the following disclosure, the access control application, whether operating on behalf of a personal user or a company or business, communicates with the customer interface 29, but in some embodiments, the access control application, when operating on behalf of a company or business, communicates with the company interface 23 instead. To further enhance security, the user inputs a bank account number associated with the payment of their salary, which is verified using user identification information provided during the installation of the application. Such information is provided to the customer interface 22 so that the access control system 20 can verify that the user is in fact an employee of the onboarded company. The user is therefore authorised both at an individual level and at an employer level, in order for personal registration to be achieved. Customer to Customer referral Once a user is registered, the registered user is able to refer another user for registration. In this manner, the referred user is deemed to be a trusted user by extension of the trust in the referring user and in the referring user's employer. The referral may be performed via provision of a referral code in an electronic message to the referred user, to a destination derived from contact information in the referring user's address book, such as a phone number. The provision of the referral message may be initiated via the access control application on the user's terminal, making use of the communication functionality of the user's terminal. In some embodiments, the referral message is generated by the access control system 20, rather than the access control application, and a request for such generation is provided to the customer interface 22, with the referral code being output from the customer interface 22 to the referred user. The referred user may be a co-worker at the referring user's company, and thus share the same employer relationship, but this is not essential. The referred user may be a friend or family member having no relationship with the referring user's employer. In such cases, it is not possible for the referred user to provide a salary bank account which will match information held by the employee database 25, since the referred user may be employed by a company which is not onboarded, or may not be employed at all. Instead, the referred user may provide identification information of the referring user. Such identification information may be embedded within the referring code, as a text string or identification number which directly or indirectly defines the referring user. In exchange for referring another user to register with the access control system 20, the referring user may be given incentives such as credits or points which are added to a loyalty account accessed via the access control application, and which may be exchanged for particular goods or services. As such, it is in a user's personal interest to refer other users and to develop the network of trusted entities who may become customers of the one or banks. Customer verification A registered user is able to access a first set of financial functions from a bank. For example, based on registered user's salary, the banking interface 21 of the access control system determines that the user is able eligible to apply for a particular loan or fund amount, with a prescribed repayment period, from one or more banks. If such a product is taken by the user, and loan or fund is repaid within the prescribed period, the user is considered to have engaged successfully with that financial product, and the user is promoted from being a registered user to a verified user. In some embodiments, the verified user is also rewarded with credits or points to their loyalty account. Being a verified user provides the access privileges which are necessary to enable the customer to access an enhanced second set of financial functions, such as higher loans or funds, or longer repayment periods than those of the first set of financial functions. In addition to being able to access enhanced financial functions, verified users are also permitted to refer and onboard other businesses, as described below. Figure 4 illustrates the data flows associated with the verification of a new customer by the access control system, according to embodiments of the present invention. In step S40, company and employee data are provided to the access control system 20 by an employer, as part of a process of initialising the access control system 20 so that it is able to accept subsequent referrals. The company data is stored in the employer database 24 and employee data is stored in employee database 25. In step S41, electronic messages inviting employees of the registered company to register themselves with the access control system as individual customers. The electronic messages contain links which, when executed by the employees, establish a communication link with the customer interface 22 over which such registration requests as provided in step S42. In step S43, the access control system 20 verifies information provided with the registration request to determine whether the requesting employer is in fact associated with the registered company and is eligible to request registration. If registration is successful, this is stored in the employee database 25, or in any registration database available to the access control system 20, and completion of registration is communicated to the employee. Once registered, the employee is permitted to access one or more financial functions of a financial institution, and this is done in step S44. The request is provided to the customer interface 22. The banking interface 21 derives a risk profile for the employee in step S45, which is based on employee information contained in the employee's user profile, and which may also take into account employer information from the employer database 24. The risk profile is provided to a financial institution so that the financial institution may identify one or more financial products or services to be provided to the employee. The one or more financial products or services are provided to the employee via the banking interface 21 and the customer interface 22 in step S46. The financial product or service is associated with repayment terms, and the employee complies with these repayment terms over a period of time in step S47 by submitting payments through the customer interface 22 and the banking interface 21. To this effect, the communication links 29, 27 of the customer interface 22 and the banking interface user communication protocols having security and encryption levels which are appropriate for execution of financial transactions. In step S48, the financial institution determines that the repayment conditions of the financial product or service are complete, and informs the access control system 20 accordingly via the banking interface 21. In turn, the customer interface 22 informs the employee that the employee is now a verified customer, with enhanced access privileges. The verified status of the employee is stored in either the employee database 25 or another registration database accessible to the access control system 20. Business onboarding Upon successful verification, access to enhanced functionality of the access control application installed on the user's terminal is opened. Visually, this may be achieved by adding selectable options to a user interface, promoting previously greyed-out options to selectable options, but any other appropriate interface control technique may be adopted instead. The enhanced functionality includes, in embodiments of the present invention, the ability of a verified user to onboard a new company or business. A verified user is able to refer a business to the access control system by sending a referral code to the business. In this manner, the referral code operates on a similar principle as described above in relation to customer-to-customer referral, where information identifying the referring user is embedded within the referral code, and where transmission of the referral code is initiated through the access control application. The contact information to which the referral code is provided may be any suitable means of contacting the business privately, such as a mobile number or email account, but not a publicly available social media account, since the referral code should be kept private between the referring user and the business to avoid interception by third parties. On receipt of the referral code, the access control application is downloaded to an account associated with the business, and the business requests registration via a communication channel which is established with the customer interface 22 of the access control system. The registration request includes the identity of the referring user. The access control application requests the business to enable geolocation services, and the registration request provided to the access control system includes the geolocation associated with the business. The customer interface 22 identifies the referring user from the registration request, as identified from information contained within the referral code, and identifies the referring user's employer from the user profile that is established in the employee database 25 from the original registration of the referring user. The address of the referring user's employer is identified from the employer database 24, and the distance between the referring user's employer and the geolocation of the requesting business is calculated. The distance may be calculated by providing the geolocation of the requesting business and the user's employer address to a mapping application or external webserver which hosts a map application from which a physical distance can be identified. In embodiments, the new business is onboarded only if the referring user is confirmed as having been verified, and if the business is within a predetermined distance of the referring user. In some embodiments, the predetermined distance may be a 2km radius, such that the business can be considered as local, with respect to the employer of the referring user. The likelihood that the business is known to the referring user, and is therefore trusted, is increased if the referred business is local to the referring user. Having been registered, the business is able to provide payroll information for its employees in a manner analogous to what is described above in relation to the onboarding of the initial group of predetermined businesses. Business verification In embodiments, if a further referring user, referred to herein as a second referring user, employed by the same employer as the referring user described above (referred to herein as a first referring user), refers the onboarded business within a predetermined time period of the first referral, it is possible for the onboarded business to be verified. In embodiments, the predetermined period is of the order of seven days and may be configured by a system administrator for the access control system. By requiring multiple referrals within such a limited time period, a referral rate can be ensured which is sufficient for the business to be trusted by the financial institutions. In contrast, if a business receives two local referrals, but separated by several months or years, the financial institutions are likely to have lower confidence in the business due to its lower referral rate. As with the referral by the first referring user, the customer interface 22 checks the proximity of the geolocation of the onboarded business to the employer address associated with the second referring user. The employer address in the employer database 24 should be the same as that associated with the first referring user. The company interface 22 determines whether the onboarded business is within the predetermined distance of the second referring user's employer, and if it is, the onboarded business is verified. As such, verification of the onboarded business is achieved by the referrals of two users who are both employees at the same company, and who refer the business within a limited time of each other. In some embodiments, verification of a business requires referral of three or more users who are each employees at the same, and who refer the business within a limited time of each other. A verified business is provided with the access privileges necessary to access an enhanced set of financial functions of the banks in comparison with the financial functions available to a registered business, which has a reduced set of access privileges. In embodiments, the distinction between the financial functions available to a registered business and those available to a verified business is analogous to the distinction between the first and second sets of financial functions respectively available to a registered user and those available to a verified user as described above. The specific nature of the enhanced set of financial functions may, however, be defined in accordance with the type of the verified business, and by a specific measure of the proximity of the registered business to the company associated with the referring users. In embodiments, a type score is assigned to a business based on industry and size categorisation. Larger businesses, such as a manufacturing industry, may be associated with a higher score than a local convenience store, for example. It is possible to define a plurality of business categories each associated with a sliding scale of type scores based on the size and nature of the business. Such type score categories are stored in a database accessible to the company interface 23 and in embodiments, such a database is part of the access control system 20 itself. In embodiments, proximity scores are assigned based on particular ranges of the distance between the verified business and the employer of the referring users. For example, in the case of a proximity of 2km, the business may be assigned the lowest proximity score, on the basis that 2km is defined above as an example of the maximum permitted distance within which the business may be verified at all. In this example, specific proximity ranges such as 200-500m, 500-750m, 750m - 1km, and so on, are allocated proximity scores which increase with proximity. The type score and proximity scores are added together to create a combined business score, and the financial functions which are accessible to the business are adjusted in dependence upon the combined business score. Businesses which have a high combined business score are permitted to access more favourable functions than businesses having a low combined business score. In this manner, the banks are able to service businesses based on both the perceived significance of the business and a level of trust that can be inferred from the proximity of the referring users to the business. For example, a local cafe, which is visited regularly by employees of an adjacent company, is likely to be a business which is trusted by the employees, and for whom a regular source of income is derived from such employees. A business which is further away from the employees may be perceived as being associated with a greater repayment risk by the banks, since its operations may not be as well-known to the referring users. Conversely, the relative financial stability of a larger business may be more attractive to a bank than volatility associated with a small business. In this manner, the operation of the company interface provides an effective client-management function which does not need to be performed by the banks themselves, which frees data processing and communication resources at the banks. In embodiments, the set of proximity scores is defined differently in dependence upon the business type. For example, a cafe or convenience store may have a high proximity score in the range of 200-500m, but the proximity score may reduce sharply as the proximity decreases, on the basis that there are likely to be a large number of different cafes or convenience stores in the vicinity of a referring user's employment, and such cafes or convenience stores are less likely to be visited by the referring user. In contrast, a business such as a factory is more likely to have significance to the referring user at a greater distance from the referring user's employment, and so may have a proximity score which reduces less sharply as distance increases. Provision of financial functions The financial functions provided by the one or more financial institutions are accessed and provided, via the access module 33, and are administered by an entity via the access control application. The access control application may be associated with a user interface to be displayed on a device or terminal, such as a dashboard, displaying payment history, scheduled payments, balance, interest rates, risk score, and may also present information about other registered customers, or contacts or business eligible to receive a referral. As described above, the one or more financial institutions which interface with the access control system 20 are able to provide financial products or services which are selected based on a risk profile for a particular customer or business. The risk profile is generated by the profiling module 32 of the banking interface 21 of the access control system 20, and the one or more financial institutions are able offer products and services without the need for detailed interrogation of the requesting entity. A financial institution trusts the analysis of the access control system 20 on the basis that the access control system 20 has already restricted the pool of available customers, by specifying that new customers are referred by already-registered customers, and that enhanced financial functions should be offered only if a customer has completed a verification process. Further, entities that may access financial services are restricted by referrals from two or more local individuals, provided in close temporal proximity. As such, the financial institution has a degree of confidence in the likely repayment of a loan or mortgage, for example. Further financial security can be provided to the financial institutions by enhancing the basis on which a risk profile is determined by the profiling module 32 of the banking interface 21. Such enhancement involves the provision of enriched profile information, via the customer interface 22 or company interface 23, or via connection between the access control system 20 and a plurality of data sources, depending on the entity requesting financial functions. Such information includes represents a plurality of variables derived from interrogation of an individual or company, performed via the access control application. The interrogation may extract information defining, for example, financial stress, physical stress, indication of an addictive personality, gambling tendencies, location history, education background, dependents, profit and loss accounts, tax payment history, company growth, debts and so on. In embodiments of the present invention, the profiling module 32 of the banking interface 21 comprises a computer system which hosts and executes a machine-learning (ML) algorithm. The ML algorithm operates to aggregate and process data from a large variety of sources representing variables or characteristics of an entity which are processed to develop the entity's risk profile. The ML algorithm operates in such a way that it can identify and respond to changes in an entity's behaviour or circumstances and changes in real-time, which significantly improves the speed at which a financial institution can provide appropriate financial functions, while minimizing the risk to the financial institution. In more detail, the ML algorithm is resolved, in embodiments of the present invention, into macrolearning and micro-learning portions, each of which monitors and processes particular groups of characteristics. The micro-learning portion is associated with responding to specific characteristics of an entity, including, but not limited to, financial and emotional stress, indications of gambling or addictive tendencies, indications of dishonesty or recklessness, and an entity's geolocation information. For example, the access control application may include functionality whereby interaction of a user or company with the application is monitored, in terms of cumulative screen time and the nature of the interactions. Increased interaction with the application may be indicative of a higher priority being assigned to an entity's financial affairs. The financial nature of the interactions is also indicative of financial behaviour, such as compliance with repayment terms, current account balance, size and frequency of incomings and outgoings, and so on. Such information is provided to the ML algorithm by the access control application. The ML algorithm responds by modelling a financial risk, in which the model is trained on training data including an entity's financial and behavioural characteristics before requesting access to prior particular financial functions, and the entity's financial and behavioural characteristics after being given access to one or more financial functions, whether the same or different from those financial functions originally requested. In this manner, the ML algorithm is able to assess the significance of particular characteristics in the overall risk profile. For example, an entity may be identified as having a gambling tendency, but the gambling tendency may be modelled by the ML algorithm as being restricted to a particular gambling limit which does not impact on other financial responsibilities. In contrast, observation of repeated internal balance transfers may indicate the absence of discrete ring-fenced areas of an entity's financial management, increasing the entity's repayment risk. In cases in which the financial institutions are able to offer financial education or training, for example by the provision of one or more presentations, audiovisual recordings, or educational material or interactive components delivered by an appropriate electronic learning format, the access control application has the capability to monitor specifically an entity's interactions with such educational tools. In doing so, an entity's financial skill level can be assessed based on the types of educational tool accessed, and the speed of response to educational questions. For example, in the event of a modular financial education programme, progress through the programme can be derived by identifying completion of each module. The access control application implements such screen monitoring by the automatic periodic capture of display information and / or user key inputs, either using a dedicated tool such as a screen-scraper or gesture tracker, or by harnessing on-board device functionality associated with the device's operating system, and performs an assessment of the content being accessed or consumed, and whether the content has been consumed at a cursory level, or in detail. Excessive or repetitive access to the same content, or slow responses to questions, may be indicative of a user having difficulty in understanding certain concepts. An educational assessment score is derived by the access control application, and provided to the access control system 20, for combination with one or more other scores derived from the in-depth interrogation described above, payroll information, company type or proximity, and so on. The educational assessment score may be calculated based on whether one or more interaction parameters exceeds one or more threshold levels associated with financial learning as described above. In alternative embodiments, the interaction data is provided to the access control system 20 where the ML algorithm of the banking interface 21 determines the educational assessment score. The combined score is used to derive a risk profile which is provided to the financial institutions to assess the financial functions which can be offered. In some embodiments, the successful completion of an educational module can be considered to constitute authorisation to request a more advanced financial training component from the financial institutions, and such a training component may be included with the term 'financial function' used in the present disclosure. Modelling of geolocation data by the ML algorithm may be used to derive behavioural characteristics such as hybrid working conditions in which an entity spends a portion of time at the location of their employer, and a portion of time working from their home or another location. If the user's geolocation data follows a regular pattern, for example, it may be inferred that the user has a particular regime to which they adhere closely, and that their overall behaviour and financial circumstances are likely of a similarly predictable nature. Behaviour which deviates from such regular patterns, suggesting, for example a prolonged absence from work, might be identified by the algorithm as concerning. A determination that a user's movements are generally irregular, might lead to a need to include information from additional sources in the modelling of the user, in order to fully derive the user's risk profile. The macro-learning portion of the ML algorithm is associated with the modelling of factors which are external, with respect to a particular entity, and which may also affect the entity's financial circumstances. Examples of such factors include, but are not limited to, seasonal demands, national holidays and festivals, seasonal illnesses, climactic events or natural disasters, and demographic or industry-specific workforce demands. Generally, such factors allow for the prediction of periods of particular behaviours, such as travel and increased financial expense, increased or decreased productivity in the workplace and their impact on sales, profits and remuneration. Such factors also allow for explanation or justification for otherwise unpredicted behaviours, such flooding events reducing productivity in a period when other factors might suggest high demand for products or services associated with a user's employment. Unexpected absence from the workplace, identified based on geolocation data, can be explained by, for example, extreme temperature events, and by linking the ML algorithm to sources of meteorological data, the predicted length and severity of particular climactic events, and their likely impact, can be modelled. As such, the access control system 20, in conjunction with the access control application installed by the customer or company, and one or more sources of data, uses a variety of techniques in order to regulate the provision of financial services to entities, in a manner which preserves the abilities of the financial institutions to customise the financial products and services which they offer, but which restricts the financial risk to be taken by the financial institutions as a result of the preliminary and ongoing profiling, endorsement and verification processes which are performed. In this manner,, it is possible for the financial institutions to be provided with information that would not otherwise be available to them, such that it is possible to make a rapid determination of the financial functions which should be made accessible at any particular time. As described above, the access control system 20 also optimises network resources and particularly data communication and processing overheads that might otherwise be consumed by the financial institutions in performing such processes manually on a per-entity basis, and in doing so, is able to significantly expand the number of customers to whom financial functions can offered. For example, by providing employee data to the access control system 20 for an entire company, as a single batch process, it is possible profile extremely significant numbers of users via a small number of data exchanges. As an example, the population of Bangladesh is estimated in 2023 to be 175 million, of which 79 million are estimated to be part of the country's workforce. In conjunction with the modelling process associated with the profiling module 32 of the banking interface 21, it is possible to ensure that high levels of customers are profiled on an ongoing basis, and in a way which takes into account a far more significant number of factors, at high speed than might be possible using any direct interaction between a customer and a banking institution. This enables financial functions to be offered both rapidly and confidently, on a scale which is not otherwise possible. For example, embodiments of the present invention might enable loans to be underwritten and finalized within as little as four minutes per person, with funds reaching a user's account within 0.3 seconds. In contrast, a manual process might take as much as 10-14 days, while failing to take into account real-time changes in a user's internal or external circumstances. Embodiments of the present invention enable real-time credit scoring and funding, with no human bias, at low cost and high efficiency. 5 Further, a network of customers is developed by embodiments of the present invention on the basis of the referral and verification techniques disclosed above, such that access to the financial institutions via the access control system is secure. For example, only employees of a predetermined company may be provided initially with a means of requesting personal registration. In this manner, a 10 controlled ecosystem of financial institutions, and their customers, is established. At the same time, in the case of Bangladesh, as many as 8 million people are estimated to be employed by small and micro businesses which are particularly suitable entities to form the trusted network of customers, in which referrals may be based on strong relationships and endorsements. 15 It will be appreciated that the embodiments described above are by way of example only, and modifications will be apparent which fall within the scope of the appended claims. Combinations of features of compatible embodiments may also be made to generate new embodiments falling with the scope of the appended claims.

Claims

1. An access control system for securely interfacing with a financial institution and a plurality of customer entities, comprising:a registration module for controlling registration of customer entities;a profiling module for generating risk profiles of the registered customer entities based on a plurality of parameters, and for providing a generated risk profile of a requesting customer entity to the financial institution; andan access module for providing one or more financial functions of the financial institution to the requesting customer entity, wherein the financial functions are dependent on the generated risk profile of the requesting entity, and are provided in dependence upon a set of access privileges.

2. An access control system according to claim 1, wherein the profiling module is arranged to aggregate entity information from a plurality of data sources in real time.

3. An access control system according to claim 2, wherein the profiling module uses a machinelearning algorithm to derive a risk profile for an entity based on information from the plurality of data sources indicative of behavioural characteristics of the entity.

4. An access control system according to any one of the preceding claims, wherein:the registration module is arranged to receive, from a registered entity, user profile information for each of a plurality of users associated with the registered entity, and store the user profile information in a registration database;the access module is arranged to authorise the requesting entity to access functions of the financial institution in accordance with a first set of access privileges; andthe registration module is arranged to:provide the plurality of users with access to a communication channel through which to request user registration;receive a request for registration, through the communication channel, from a user of the plurality of users, the request comprising user information;compare the received user information with the stored user profile information; and register the user in the registration database when the received user informationmatches stored user profile information;wherein the access module is arranged to confirm to the financial institution that the registered user is authorised to access functions of the financial institution in accordance with the first set of access privileges.

5. An access control system according to claim 4, wherein the user profile information includes contact information.

6. An access control system according to claim 5, wherein access to the communication channel is provided via an executable link in an electronic message provided to the plurality of users.

7. An access control system according to any one of claims 4 to 6, wherein the registered user is a first registered user, wherein the registration module is arranged to receive a request for registration from a second user, and register the second user in the registration database when the request comprises information identifying the first registered user.

8. An access control system according to any one of the preceding claims, wherein the access module is arranged to receive, from the financial institution, confirmation of completion of a financial transaction by the registered user;wherein the registration module is arranged to verify the registered user in the registration database in response to receiving the confirmation; andwherein the access module is arranged to confirm to the financial institution that the verified user is authorised to access functions of the financial institution in accordance with a second set of access privileges permitting greater access than the first set of access privileges.

9. An access control system according to claim 8, wherein the entity is a first entity, wherein the registration module is arranged to:receive a request from a second entity for registration, wherein the request comprises information identifying a referring user for the second entity and a geolocation of the second entity;identify an entity associated with the referring user, and if the identified entity is the first entity, and if the referring user is a verified user, determine a geolocation of the first entity and compare the geolocation of the first entity with the geolocation of the second entity;register the second entity in the registration database when the determined geolocation of the second entity is within a predetermined proximity of the geolocation of the first entity by receiving user profile information for each of a plurality of users associated with the second entity and storing the user profile information in the registration database; wherein the access module is arranged to provide the plurality of users associated with the second entity with access to a communication channel through which to request user registration; andwherein the registration module is arranged to authorise the second entity to access functions of the financial institution in accordance with the first set of access privileges.

10. An access control system according to claim 9, wherein the predetermined proximity is obtained by the registration module performing the steps of:determining a proximity score based on which of a plurality of predefined distance ranges represents the distance between the geolocation of the first entity and the geolocation of the second entity; anddetermining an entity categorisation for the second entity, defining the threshold to be applied to the predetermined proximity score to determine whether the geolocation of the second entity is within a predetermined proximity of the geolocation of the first entity.

11. An access control system according to claim 9 or claim 10, wherein the referring user is a first referring user, and the registration module is further arranged to:receive a request for verification of the second entity, wherein the request for verification comprises information identifying a second referring user for the second entity;if the request for verification of the second entity is received within a predetermined time of the request for registration of the second entity, the registration module identifies an entity associated with the second referring user, and if the identified entity is the first entity, verifies the second entity in the registration database, and confirms to the financial institution that the verified second entity is authorised to access functions of the financial institution in accordance with the second set of access privileges.

12. An access control system according to any one of claims 8 to 11, wherein the first set of access privileges permits access to a first set of functions of the financial institution, and the second set of access privileges permits access to a second set of functions of the financial institution, wherein the second set of functions includes the first set of functions and first additional functions,and wherein the first set of functions is associated with financial information of the stored user profile information.

13. An access control system according to claim 12, wherein the profiling module is arranged to obtaining data from a registered user representing a user's interaction with a user device through which the first set of functions is accessed, and the access module is arranged to provide access to a third set of functions of the financial institution including the first set of functions and second additional functions if the level of user interaction with the user device exceeds a predetermined threshold.

14. A method of securing communication between a user terminal and a financial institution, the method comprising:receiving an electronic message from a server, the electronic message including an executable link; andreceiving an activation command, from a user, to activate the link and executing the link in response to receiving the activation command;wherein executing the link causes:download and installation of an application providing an interface to the server; and transmission, from the user device, of a request for registration, to the server, the request including user information for the user of the user device;receiving authorisation, from the server, of the user to access functions of the financial institution, via the interface, in accordance with the first set of access privileges, when the user information is determined to match a user profile registered at the server.

15. A method according to claim 14, wherein the application provides a selectable command which, when selected through a user interface by the user, sends an electronic message to a further user to invite the first user to request registration with the server, and wherein the user receives credit to a registration score associated with a user account for the application, when the application receives confirmation that the further user is registered.

16. A method according to claim 14 or claim 15, wherein the application is configured to track a level of interaction between the user and an interface to the financial institution by measuring the time for which the interface is displayed on a screen of the user device, and / or by measuring user inputs to the interface, and the application is configured to request that the server authorises accessto financial services which are additional to financial services associated with the first set of access privileges, when the level of interaction between the user and the interface exceeds a predetermined threshold.5 17. A method according to claim 16, wherein tracking a level of interaction between the userand an interface to the financial institution includes tracking the level of interaction between the user and a financial education function provided via the interface.

18. A computer program which, when executed by one or more processors, is configured to10 cause the method of any one of claims 14 to 17 to be performed.