Banking Ethics: Changing Dynamics
Principles & Practices of Banking | Module D · Chapter 55
Covers the Role of IT in Banking (2 avenues: Communication & Connectivity + BPR), FinTech vs RegTech, RBI Regulatory Sandbox, Data Security (7 RBI guidelines), Data Privacy (Justice Srikrishna Committee 2018 — 7 principles), Intellectual Property Rights (Patents, Copyright; Patent = 20 years protection), and Ethics of Information Security (IT team as custodian).
📌 Why This Chapter Matters in JAIIB
Expect 4–6 questions from this chapter. All 4 MCQ answers are distinct: MCQ 1: Banking operations increasingly attuned to = (d) customers' preferences — NOT regulatory prescriptions, NOT IT challenges; MCQ 2: IT 2nd avenue in banking (other than communication & connectivity) = (b) Business Process Re-engineering (BPR) — NOT DRM, NOT IPR, NOT DLP; MCQ 3: RBI Committees on Mechanisation (1984) and Computerisation in Banks (1988) headed by = (b) Dr. C. Rangarajan; MCQ 4: IPR allows creator to use IP for own benefit and = (b) prohibits any third party use of such work. Other key exam points: FinTech = technology for delivery/facilitation of financial services; RegTech = technology facilitating regulatory compliance; RBI Regulatory Sandbox — based on Working Group on Fintech and Digital Banking; Patent protection period = generally 20 years; 2 categories of IP: (1) Patents — inventions, trademarks, industrial designs, geographical indications; (2) Copyright — artistic works, symbols; Justice B.N. Srikrishna Committee Report (2018) — 4 named principles of 7: Technology agnosticism, Data minimisation, Informed consent, Accountability of data controller; IT team = custodian of customer information — their ethical conduct is of paramount importance.
Key Facts & References — Chapter 55 at a Glance
Role of Information Technology in Banking
FreeRole of Information Technology in Banks
IT: No longer a choice — a compulsion
Banking and financial services have witnessed unprecedented changes with increasing IT use. IT is driving financial services business. It is now a matter of compulsion — not choice — for banks and financial institutions to use state-of-the-art technology for survival and growth.
2 Avenues of IT in Banking (MCQ 2 — answer (b))
Communication and Connectivity
Electronic channels, mobile banking, customer interaction — customers express satisfaction from their mobile screen instantly.
Business Process Re-engineering (BPR)
Redesigning internal banking processes using IT — sophisticated product development, better market infrastructure, reliable risk control techniques.
⚠️ MCQ 2 answer: (b) Business Process Re-engineering (BPR)
NOT (a) DRM, NOT (c) IPR, NOT (d) DLP. The two avenues are Communication & Connectivity + BPR.
3 Major Bank Functions Changed by IT
Also impacted by IT:
Efficiency of money markets, capital markets, and foreign exchange markets. IT also enables financial intermediaries to reach geographically distant and diversified markets.
⚠️ MCQ 1 — Banking operations attuned to ever-growing:
Answer: (d) customers' preferences. NOT (a) regulatory prescriptions, NOT (b) IT challenges, NOT (c) customers' incomes. Customer-focused banking now means serving customer preferences on digital channels.
Current IT Focus in Banking
Analytics and business intelligence to enhance CRM (Customer Relationship Management). Internally: MIS (Management Information Systems) and managing risks from IT implementation. Mergers: different technological frameworks create integration challenges.
⚠️ MCQ 3 — RBI Committees on Mechanisation (1984) and Computerisation (1988) headed by:
Answer: (b) Dr. C. Rangarajan
1984: Committee on Mechanisation in the Banking Industry
Headed by: Dr. C. Rangarajan
1988: Committee on Computerisation in Banks
Headed by: Dr. C. Rangarajan
(a) Shri YH Malegam — WRONG. (c) Shri WS Saraf — WRONG. (d) Shri M. Narasimham — WRONG (Narasimham headed the Banking Sector Reforms Committee).
Role of Ethics in Technology & FinTech / RegTech
FreeRole of Ethics in Technology
Each second, billions of data get captured and transmitted in public domains, while some data remain accessible to only a few authorised persons. Banks collect both banking-related data (deposits, loan interest, salary credits) and transaction/service data (air tickets, hotel payments, insurance premiums, mutual fund investments).
Primary Moral Obligation of Banks
As banks collect, store, and access customer data continuously, they have a primary moral obligation to prevent data leaks and data misuse. Customers must be assured that their data and information are handled in a secured and confidential manner.
IT Department Vigilance
Bank customers receive unsolicited marketing calls (resort operators, club houses, etc.) — IT department personnel must be monitored to ensure they do not leak customer data to outsiders, whether or not for a reward. Periodical training should be held to impress that data leakage is unethical, and guilty employees should be severely dealt with.
FinTech
Financial Technology — refers to technology for delivery / facilitation of financial services. Banks and financial institutions are realising the value in adopting/adapting FinTech innovations — increases revenues and brings innovation for customers.
RegTech
Regulatory Technology — refers to technology that facilitates regulatory compliance. Helps banks and financial institutions manage regulatory requirements efficiently using technology.
RBI Regulatory Sandbox
Based on recommendation of Working Group on Fintech and Digital Banking. Objective: foster responsible innovation, promote efficiency, benefit consumers. A formal regulatory programme for market participants to test new products/services/models with customers in a live environment, subject to certain safeguards and oversight.
Data Security & Data Privacy
Data Security — 7 RBI Guidelines
RBI Guideline Reference
"Guidelines on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds" — issued to all commercial banks.
Data Integrity
Define and implement procedures to ensure integrity and consistency of all data in electronic form — databases, data warehouses, and data archives.
Secure Storage of Media
Physical and environmental controls (fire and flood protection), limiting access by physical locks/keypad/passwords/biometrics, labelling, and logged access.
Uniform Data Protection
Ensure uniform data protection within AND outside the institution. Consistent standards regardless of where data resides.
Appropriate Disposal
Banks need appropriate disposal procedures for both electronic AND paper-based media. Prevents recovery of sensitive disposed data.
Security in Transit
Banks should maintain security of media while in transit or when shared with third parties.
Encryption of Customer Data
Banks should encrypt customer account and transaction data which is transmitted, transported, delivered, or couriered to external parties or other locations.
Blocking/Filtering/Monitoring
Block, filter, and monitor electronic mechanisms (e-mail, printing). Monitor for unauthorised software/hardware: password cracking software, key loggers, wireless access points.
Data Privacy — Justice B.N. Srikrishna Committee 2018
Frauds through electronic means are easier to track than physical frauds. FinTech companies can use technology and analytics to prevent and predict frauds. The onus is on FinTech players to utilise their technological expertise and assist/engage with regulators to draft appropriate guidelines.
Data Privacy Bill
Measures were underway for approval of the Data Privacy Bill by Parliament during 2022–2023.
Justice B.N. Srikrishna Committee Report (2018) — 7 Principles for Data Protection Laws
Technology agnosticism
Data protection law must be flexible enough to include changing technologies
Data minimisation
Data sought and processed should be minimal and as necessary
Informed consent
Consent is an expression of human autonomy
Accountability of data controller
Data controller is accountable for data collected and processed
Additional principles
(Referred to in the full committee report — 7 principles total)
Intellectual Property Rights, Patents & Ethics of Information Security
Intellectual Property Rights (IPR) & Patents
Definition of Intellectual Property
Intellectual property refers to the creation of an asset by any individual using creativity and innovation. Such intellectual property (IP) belongs to that individual, and any unauthorised use of such IP is strictly prohibited under the applicable law of the land.
⚠️ MCQ 4 — IPR allows creator/innovator to use IP for own benefit and:
Answer: (b) prohibits any third party use of such work. NOT (a) allows government to use, NOT (c) non-prohibited use, NOT (d) dilutes credibility.
2 Categories of Intellectual Property
1. Patents
Examples: Inventions, trademarks, industrial designs, geographical indications
2. Copyright
Examples: Artistic works, symbols, innovative processes, methods
What is a Patent?
A patent is an exclusive right granted for an invention — a product or process that provides a new way of doing something OR a new technical solution to a problem.
Protection period
Generally 20 years
Protection for a limited period from the date of filing.
What IPR Provides
IPR allows its creator/innovator to use the IP for their own benefit. It prohibits any third party from using such work without authorisation. This provides incentive for creativity and innovation — creators can profit from their intellectual assets.
Ethics of Information Security
IT Team as Custodian
The IT team of the bank or financial institution is the custodian of the information of its customers, dealings, and activities. Their work conduct and ethical conduct is of paramount importance for the organisation.
Any failure of professionals handling the IT desk and data can result in:
Training Requirements
Awareness of ethical conduct has become very important with every technological advancement. Proper training — orientation and refresher courses — should be provided for ALL employees (not only IT department but also operations and support functions).
3 Key Focus Areas for Information Security Ethics
Chapter 55 — MCQ Quick Reference
All 4 Answers: 1.(d) 2.(b) 3.(b) 4.(b)
1. Banking operations in recent years are becoming increasingly customer-focused and, in a way, getting attuned to the ever-growing:
✓ (d) customers' preferences
NOT (a) regulatory prescriptions — that's compliance, not customer focus. NOT (b) IT challenges. NOT (c) customers' incomes.
2. IT has broadly been used under two avenues in banking. One is communication and connectivity, and the other is:
✓ (b) Business Process Re-engineering (BPR)
NOT (a) DRM (Digital Rights Management), NOT (c) IPR, NOT (d) DLP (Data Leak Prevention).
3. RBI's Committees on Mechanisation in the Banking Industry (1984) and on Computerisation in Banks (1988) were headed by:
✓ (b) Dr. C. Rangarajan
(a) Shri YH Malegam — WRONG. (c) Shri WS Saraf — WRONG. (d) Shri M. Narasimham — headed Banking Sector Reforms, not these committees.
4. Intellectual Property Right (IPR) allows its creator/innovator to use the IP for own benefit and:
✓ (b) prohibits any third party use of such work
NOT (a) allows government to use — WRONG. NOT (c) anyone for non-prohibited use — WRONG. NOT (d) dilutes credibility — WRONG.
Chapter 55 — Module D Complete: All answers at a glance
| Q | Topic | Answer |
|---|---|---|
| 1 | Banking operations attuned to ever-growing... | (d) customers' preferences |
| 2 | IT's 2nd avenue (other than communication & connectivity) | (b) Business Process Re-engineering (BPR) |
| 3 | RBI Committees on Mechanisation (1984) / Computerisation (1988) | (b) Dr. C. Rangarajan |
| 4 | IPR allows creator to use IP for own benefit and... | (b) prohibits any third party use of such work |
Discussion
No comments yet. Be the first to share your thoughts.