Regulator cites gaps in IT internal controls, including lack of pre-deployment performance reviews
The Financial Supervisory Service on Wednesday convened a meeting with the chief information officers of six big tech-affiliated electronic financial service providers, urging them to prevent IT system failures and strengthen consumer protection.
The meeting, held at 10 a.m. at the FSS headquarters in Yeouido, Seoul, was attended by Lee Jong-o, the FSS deputy governor for digital and IT affairs, along with officials from the electronic finance supervision and inspection bureaus. Representing the industry were the CIOs and audit officers of six companies: Naver Financial, Kakao, Kakao Pay, Kakao Mobility, Viva Republica — the operator of Toss — and Toss Payments.
The gathering came in response to growing market concerns over the stability of electronic financial transactions, following a string of IT outages at big tech-affiliated companies.
The FSS had earlier imposed heavy sanctions — including fines and institutional warnings — on big tech affiliates in January over the unauthorized sharing of personal credit information with third parties, signaling that the regulator is intensifying its scrutiny of the broader information management practices of such firms.
Several incidents have hit big tech affiliates this year. In January, an update error in an authentication service relay server halted all payment, top-up and remittance services for about 30 minutes. In February, a database server overload caused by a points-accumulation event brought down order and payment services for roughly four hours. In June, a misconfigured block-time setting for simultaneous batch job execution caused duplicate automatic transfer withdrawals. The FSS said most of these incidents stemmed from basic failures in IT internal controls — including the omission of pre-deployment performance reviews, load testing and third-party verification when making program changes.
Deputy Governor Lee said the companies must secure IT stability at a level that meets or exceeds that of traditional financial institutions. He also noted that incidents could spread and escalate externally through single-app service environments and cloud-based external linkages.
Lee further called on the firms to conduct a comprehensive review of their internal controls for data protection and personal information management — given the vast amounts of personal data they hold — and to immediately address any shortcomings. He also requested that they establish fair compensation frameworks for affected users, strengthen complaint handling, and set clear compensation standards for merchants and other sellers.
The industry representatives said they would pursue pre-impact analysis and enhanced third-party verification before program changes, early detection of anomalies through real-time monitoring, and a review of business continuity measures to keep core services running even during outages. They also said they would put isolation systems in place to prevent a failure on one platform from spreading to the broader service or affiliated companies.
"For electronic financial service providers with frequent system failures, we will conduct on-site inspections to ensure fundamental improvements and corrections," an FSS official said. "We intend to respond strictly to major IT incidents caused by inadequate internal controls."
psj@heraldcorp.com
