BankopediaBankopedia
PPB Module DChapter Notes4–6 Marks Expected

Banking Ethics: Changing Dynamics

Principles & Practices of Banking | Module D · Chapter 55

Covers the Role of IT in Banking (2 avenues: Communication & Connectivity + BPR), FinTech vs RegTech, RBI Regulatory Sandbox, Data Security (7 RBI guidelines), Data Privacy (Justice Srikrishna Committee 2018 — 7 principles), Intellectual Property Rights (Patents, Copyright; Patent = 20 years protection), and Ethics of Information Security (IT team as custodian).

By Bankopedia.co.inUpdated 2026JAIIB PPB · Module D

📌 Why This Chapter Matters in JAIIB

Expect 4–6 questions from this chapter. All 4 MCQ answers are distinct: MCQ 1: Banking operations increasingly attuned to = (d) customers' preferences — NOT regulatory prescriptions, NOT IT challenges; MCQ 2: IT 2nd avenue in banking (other than communication & connectivity) = (b) Business Process Re-engineering (BPR) — NOT DRM, NOT IPR, NOT DLP; MCQ 3: RBI Committees on Mechanisation (1984) and Computerisation in Banks (1988) headed by = (b) Dr. C. Rangarajan; MCQ 4: IPR allows creator to use IP for own benefit and = (b) prohibits any third party use of such work. Other key exam points: FinTech = technology for delivery/facilitation of financial services; RegTech = technology facilitating regulatory compliance; RBI Regulatory Sandbox — based on Working Group on Fintech and Digital Banking; Patent protection period = generally 20 years; 2 categories of IP: (1) Patents — inventions, trademarks, industrial designs, geographical indications; (2) Copyright — artistic works, symbols; Justice B.N. Srikrishna Committee Report (2018) — 4 named principles of 7: Technology agnosticism, Data minimisation, Informed consent, Accountability of data controller; IT team = custodian of customer information — their ethical conduct is of paramount importance.

Key Facts & References — Chapter 55 at a Glance

IT 2 Avenues in Banking:1. Communication and Connectivity 2. Business Process Re-engineering (BPR). MCQ 2 answer: (b) BPR.
3 Bank Functions Changed by IT:Access to liquidity; Transformation of assets; Monitoring of risks. Also impacted: efficiency of money, capital and foreign exchange markets.
FinTech vs RegTech:FinTech = technology for delivery/facilitation of financial services. RegTech = technology facilitating regulatory compliance.
RBI Regulatory Sandbox:Based on Working Group on Fintech and Digital Banking. Objective: foster responsible innovation, promote efficiency, benefit consumers. Formal regulatory programme for live testing.
RBI Data Security Guidelines:7 guidelines — integrity of data / secure storage of media / uniform protection / disposal procedures / security in transit / encrypt customer data / block+filter+monitor electronic mechanisms.
Justice B.N. Srikrishna 2018:Committee report on data protection laws — 4 named principles: Technology agnosticism, Data minimisation, Informed consent, Accountability of data controller. Data Privacy Bill Parliament 2022-23.
IP 2 Categories:1. Patents: inventions, trademarks, industrial designs, geographical indications. 2. Copyright: artistic works, symbols.
Patent definition:Exclusive right for an invention (product or process) providing new way of doing something OR new technical solution. Protection: GENERALLY 20 YEARS.
IPR:Allows creator/innovator to use IP for own benefit and PROHIBITS any third party from using such work. MCQ 4 answer: (b).
IT Team as Custodian:IT team is CUSTODIAN of customer information. Ethical conduct of paramount importance. Failure = sensitive leakage, huge losses, reputation risk, expensive legal battles.
Dr. C. Rangarajan:Headed both: RBI Committee on Mechanisation in Banking Industry (1984) AND RBI Committee on Computerisation in Banks (1988). MCQ 3 answer: (b).
Banking now attuned to:Customers' preferences (MCQ 1 answer: d). Customer satisfaction expressed from mobile screen — shift from branch-based to digital.
1

Role of Information Technology in Banking

Free
55.2.1

Role of Information Technology in Banks

IT: No longer a choice — a compulsion

Banking and financial services have witnessed unprecedented changes with increasing IT use. IT is driving financial services business. It is now a matter of compulsion — not choice — for banks and financial institutions to use state-of-the-art technology for survival and growth.

2 Avenues of IT in Banking (MCQ 2 — answer (b))

1

Communication and Connectivity

Electronic channels, mobile banking, customer interaction — customers express satisfaction from their mobile screen instantly.

2

Business Process Re-engineering (BPR)

Redesigning internal banking processes using IT — sophisticated product development, better market infrastructure, reliable risk control techniques.

⚠️ MCQ 2 answer: (b) Business Process Re-engineering (BPR)

NOT (a) DRM, NOT (c) IPR, NOT (d) DLP. The two avenues are Communication & Connectivity + BPR.

3 Major Bank Functions Changed by IT

1Access to liquidity
2Transformation of assets
3Monitoring of risks

Also impacted by IT:

Efficiency of money markets, capital markets, and foreign exchange markets. IT also enables financial intermediaries to reach geographically distant and diversified markets.

⚠️ MCQ 1 — Banking operations attuned to ever-growing:

Answer: (d) customers' preferences. NOT (a) regulatory prescriptions, NOT (b) IT challenges, NOT (c) customers' incomes. Customer-focused banking now means serving customer preferences on digital channels.

Current IT Focus in Banking

Analytics and business intelligence to enhance CRM (Customer Relationship Management). Internally: MIS (Management Information Systems) and managing risks from IT implementation. Mergers: different technological frameworks create integration challenges.

⚠️ MCQ 3 — RBI Committees on Mechanisation (1984) and Computerisation (1988) headed by:

Answer: (b) Dr. C. Rangarajan

1984: Committee on Mechanisation in the Banking Industry

Headed by: Dr. C. Rangarajan

1988: Committee on Computerisation in Banks

Headed by: Dr. C. Rangarajan

(a) Shri YH Malegam — WRONG. (c) Shri WS Saraf — WRONG. (d) Shri M. Narasimham — WRONG (Narasimham headed the Banking Sector Reforms Committee).

2

Role of Ethics in Technology & FinTech / RegTech

Free
55.2.2

Role of Ethics in Technology

Each second, billions of data get captured and transmitted in public domains, while some data remain accessible to only a few authorised persons. Banks collect both banking-related data (deposits, loan interest, salary credits) and transaction/service data (air tickets, hotel payments, insurance premiums, mutual fund investments).

Primary Moral Obligation of Banks

As banks collect, store, and access customer data continuously, they have a primary moral obligation to prevent data leaks and data misuse. Customers must be assured that their data and information are handled in a secured and confidential manner.

IT Department Vigilance

Bank customers receive unsolicited marketing calls (resort operators, club houses, etc.) — IT department personnel must be monitored to ensure they do not leak customer data to outsiders, whether or not for a reward. Periodical training should be held to impress that data leakage is unethical, and guilty employees should be severely dealt with.

FinTech

Financial Technology — refers to technology for delivery / facilitation of financial services. Banks and financial institutions are realising the value in adopting/adapting FinTech innovations — increases revenues and brings innovation for customers.

RegTech

Regulatory Technology — refers to technology that facilitates regulatory compliance. Helps banks and financial institutions manage regulatory requirements efficiently using technology.

RBI Regulatory Sandbox

Based on recommendation of Working Group on Fintech and Digital Banking. Objective: foster responsible innovation, promote efficiency, benefit consumers. A formal regulatory programme for market participants to test new products/services/models with customers in a live environment, subject to certain safeguards and oversight.

3

Data Security & Data Privacy

55.3.1

Data Security — 7 RBI Guidelines

RBI Guideline Reference

"Guidelines on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds" — issued to all commercial banks.

i

Data Integrity

Define and implement procedures to ensure integrity and consistency of all data in electronic form — databases, data warehouses, and data archives.

ii

Secure Storage of Media

Physical and environmental controls (fire and flood protection), limiting access by physical locks/keypad/passwords/biometrics, labelling, and logged access.

iii

Uniform Data Protection

Ensure uniform data protection within AND outside the institution. Consistent standards regardless of where data resides.

iv

Appropriate Disposal

Banks need appropriate disposal procedures for both electronic AND paper-based media. Prevents recovery of sensitive disposed data.

v

Security in Transit

Banks should maintain security of media while in transit or when shared with third parties.

vi

Encryption of Customer Data

Banks should encrypt customer account and transaction data which is transmitted, transported, delivered, or couriered to external parties or other locations.

vii

Blocking/Filtering/Monitoring

Block, filter, and monitor electronic mechanisms (e-mail, printing). Monitor for unauthorised software/hardware: password cracking software, key loggers, wireless access points.

55.3.2

Data Privacy — Justice B.N. Srikrishna Committee 2018

Frauds through electronic means are easier to track than physical frauds. FinTech companies can use technology and analytics to prevent and predict frauds. The onus is on FinTech players to utilise their technological expertise and assist/engage with regulators to draft appropriate guidelines.

Data Privacy Bill

Measures were underway for approval of the Data Privacy Bill by Parliament during 2022–2023.

Justice B.N. Srikrishna Committee Report (2018) — 7 Principles for Data Protection Laws

1

Technology agnosticism

Data protection law must be flexible enough to include changing technologies

2

Data minimisation

Data sought and processed should be minimal and as necessary

3

Informed consent

Consent is an expression of human autonomy

4

Accountability of data controller

Data controller is accountable for data collected and processed

5–7

Additional principles

(Referred to in the full committee report — 7 principles total)

4

Intellectual Property Rights, Patents & Ethics of Information Security

55.4

Intellectual Property Rights (IPR) & Patents

Definition of Intellectual Property

Intellectual property refers to the creation of an asset by any individual using creativity and innovation. Such intellectual property (IP) belongs to that individual, and any unauthorised use of such IP is strictly prohibited under the applicable law of the land.

⚠️ MCQ 4 — IPR allows creator/innovator to use IP for own benefit and:

Answer: (b) prohibits any third party use of such work. NOT (a) allows government to use, NOT (c) non-prohibited use, NOT (d) dilutes credibility.

2 Categories of Intellectual Property

1. Patents

Examples: Inventions, trademarks, industrial designs, geographical indications

2. Copyright

Examples: Artistic works, symbols, innovative processes, methods

What is a Patent?

A patent is an exclusive right granted for an invention — a product or process that provides a new way of doing something OR a new technical solution to a problem.

Protection period

Generally 20 years

Protection for a limited period from the date of filing.

What IPR Provides

IPR allows its creator/innovator to use the IP for their own benefit. It prohibits any third party from using such work without authorisation. This provides incentive for creativity and innovation — creators can profit from their intellectual assets.

55.5

Ethics of Information Security

IT Team as Custodian

The IT team of the bank or financial institution is the custodian of the information of its customers, dealings, and activities. Their work conduct and ethical conduct is of paramount importance for the organisation.

Any failure of professionals handling the IT desk and data can result in:

Major leakages of sensitive information
Huge financial losses to the bank
Reputation risk
Expensive legal battles

Training Requirements

Awareness of ethical conduct has become very important with every technological advancement. Proper training — orientation and refresher courses — should be provided for ALL employees (not only IT department but also operations and support functions).

3 Key Focus Areas for Information Security Ethics

1Employees made aware of professional obligations relating to information security
2Employees (especially IT) aware of patterns of IT attacks on bank customers/servers/ATMs — familiar with profiles of attackers, patterns of thefts, and modus operandi
3Advised about various types of prevalent cybercrimes
5

Chapter 55 — MCQ Quick Reference

All 4 Answers: 1.(d) 2.(b) 3.(b) 4.(b)

1. Banking operations in recent years are becoming increasingly customer-focused and, in a way, getting attuned to the ever-growing:

(d) customers' preferences

NOT (a) regulatory prescriptions — that's compliance, not customer focus. NOT (b) IT challenges. NOT (c) customers' incomes.

2. IT has broadly been used under two avenues in banking. One is communication and connectivity, and the other is:

(b) Business Process Re-engineering (BPR)

NOT (a) DRM (Digital Rights Management), NOT (c) IPR, NOT (d) DLP (Data Leak Prevention).

3. RBI's Committees on Mechanisation in the Banking Industry (1984) and on Computerisation in Banks (1988) were headed by:

(b) Dr. C. Rangarajan

(a) Shri YH Malegam — WRONG. (c) Shri WS Saraf — WRONG. (d) Shri M. Narasimham — headed Banking Sector Reforms, not these committees.

4. Intellectual Property Right (IPR) allows its creator/innovator to use the IP for own benefit and:

(b) prohibits any third party use of such work

NOT (a) allows government to use — WRONG. NOT (c) anyone for non-prohibited use — WRONG. NOT (d) dilutes credibility — WRONG.

Chapter 55 — Module D Complete: All answers at a glance

QTopicAnswer
1Banking operations attuned to ever-growing...(d) customers' preferences
2IT's 2nd avenue (other than communication & connectivity)(b) Business Process Re-engineering (BPR)
3RBI Committees on Mechanisation (1984) / Computerisation (1988)(b) Dr. C. Rangarajan
4IPR allows creator to use IP for own benefit and...(b) prohibits any third party use of such work

Discussion

Sign in to join the discussion.

No comments yet. Be the first to share your thoughts.