BankopediaBankopedia
PPB Module CChapter Notes4–6 Marks Expected

Operational Aspects of CBS Environment

Principles & Practices of Banking | Module C · Chapter 43

This chapter dives into the day-to-day operational mechanics of Core Banking Solutions — how transactions flow through CBS, maker-checker controls, EOD/BOD batch processes, password security rules, parameter file management, logical access controls, and the overall role and responsibilities of banks under CBS as mandated by RBI.

By Bankopedia.co.inUpdated 2026JAIIB PPB · Module C

📌 Why This Chapter Matters in JAIIB

Expect 4–6 questions from this chapter. Key focus areas: 3 transaction types (Cash, Clearing, Transfer); Maker-Checker functionality; 4 Basic Operational Controls (Segregation of Duties, Four Eye Principle/Maker-Checker, Rotation of Duties, Ownership of systems); password requirements (min 8 characters, upper+lowercase, letters+numbers, 1 special character, no dictionary word, no reuse, disable during leave, periodic changes, multi-factor for critical modules, stored encrypted); Parameter/Master File (operators = read-only; print before and after changes); EOD/BOD operations and their critical nature; daily backup in 6 sets (one per weekday) + 12 monthly sets; System Audit by Chartered Accountants; 14 IT policy areas banks must maintain under CBS.

Key Facts & References — Chapter 43 at a Glance

CBS definition:Platform where Communication Technology and IT merge for core banking needs; client software at branches connects to central server
CBS software examples:Finacle (Infosys), BaNCS (TCS), Flexcube (Oracle)
Branch connectivity to CBS:Lease lines, MPLS, VSAT, RF, 3G/4G and other networking technologies
3 CBS transaction types:Cash · Clearing · Transfer
Maker-Checker (branch):Maker (teller) initiates transaction; Checker (officer) authorises it — dual control at branch level
CBS accounting system:OLTP on real-time basis; debits/credits in all sub-systems (customer ledgers, general ledger, books) simultaneously
4 Basic Operational Controls:(A) Segregation of Duties; (B) Four Eye Principle / Maker-Checker; (C) Rotation of Duties; (D) Ownership of systems for granting access rights
Password minimum length:8 characters — the more the better
Password composition:Both uppercase and lowercase letters; mixture of letters and numbers; at least one special character; no dictionary words
Password management:Prevent reuse of previous passwords; disable during leave; enforce periodic changes; multi-factor for critical modules; stored encrypted only
OS password dual control:Kept in sealed cover under Dual Control of Branch Manager and System Administrator; opened in presence of at least 2 persons; changed immediately on opening
Parameter/Master File access:Operators should have READ-ONLY access; printouts taken before and after any changes; kept in safe custody of Branch Manager
CISO responsibility:Chief Information Security Officer ensures all available security features are implemented
User access principle:Minimum access level needed to do the job; restricted to specific applications, menus, files, servers
Daily backup sets:6 sets (one for each weekday) + 12 sets (one for each month); backup media in fireproof cabinet; off-site backups for emergency
Anti-virus requirement:Latest version installed in servers/PCs; regularly updated for new viruses; security patches applied as released
System Audit:Conducted by a firm of Chartered Accountants; scope: hardware, OS, critical apps, security/access controls, DRS, training, documentation
RBI circular reference:No.1462/02.14.003/2012-13 dated February 28, 2013 — mandates IT Policy and system audit requirements for banks
EOD/BOD criticality:Critical operations that must be performed diligently on time; EOD must complete before BOD can run for that day
BOD key activities:New day start; time deposit interest/maturity processing; standing instructions; value date processing; salary processing; expiry of OD limits
1

Introduction to CBS & Functions Performed

Free

43.1 Introduction — What is CBS?

Based on the level of computerisation, banks may be categorised as non-computerised, partially computerised, or fully computerised. Core Banking Solutions (CBS) is a platform where Communication Technology and Information Technology merge to suit core banking needs. Under CBS, client software is installed at different branches to connect to the central server for accessing and updating customer information and transactions.

Primary WAN

Lease lines / MPLS

Backup links

VSAT · RF · 3G/4G

CBS Examples

Finacle · BaNCS · Flexcube

Finacle is by Infosys · BaNCS (Bank and Customer Services) is by TCS · Flexcube is by Oracle

43.2 Functions Performed by CBS

CBS has evolved to handle almost every banking transaction. Common features across popular CBS platforms:

(a) Customer accounts management
(b) Office account management
(c) Loans disbursal and management
(d) Cash deposits and withdrawals
(e) Transactions management (online and history)
(f) Inward/Outward clearing process
(g) Calculation of interest on advances and deposits
(h) Charges/Fees application
(i) Application of minimum balance charges, transaction charges, cheque book charges etc.
(j) Asset Classification and Income recognition
(k) Non-Performing Assets (NPA) Management
(l) Customer Relationship Management (CRM) activities

CBS also helps in making cheque clearings faster, improved housekeeping, prevention of income leakages, and faster inter-branch reconciliations (more accurate and automated). It also integrates with ATMs, mobile/internet banking.

2

Flow of Transactions & Accounting in CBS

Free

43.3 Three Types of CBS Transactions

💵

Cash

Physical currency deposits and withdrawals at branches or ATMs.

🏦

Clearing

Cheque clearing — inward/outward — processed through clearing system.

↔️

Transfer

Fund transfers between accounts within the bank or to other banks.

Transaction Flow — Key Points

  • Transactions by branch users, customers through alternate delivery channels, or third-party trusted vendors are ultimately reflected in the Central Database.
  • Branch user logs in with User ID + Password + biometric authentication at the CBS terminal.
  • Branch transactions follow Maker-Checker functionality: Maker (teller) initiates; Checker (authorising officer) validates.
  • Transactions are committed at the Central Database only after ALL legs of the transaction are completed.
  • System validates: account number, balance, teller (Maker) authority, officer (Checker) authority, and product-level parameters.
  • Transactions also flow from alternate delivery channels, Treasury systems, etc., into the core banking system.

43.4 Accounting of Transactions in CBS

CBS is an Online Transaction Processing (OLTP) system operating on a real-time basis. Transactions are effected in all sub-systems simultaneously, including:

  • Customer accounts ledgers
  • General Ledger
  • Any other books of accounts

All necessary debits and credits are done simultaneously across all sub-systems — there is no time lag.

3

EOD & BOD Operations

Members Only

EOD (End of Day) and BOD (Beginning of Day) operations are very critical in core banking. EOD must be completed before BOD can run for that day. Days are always business days as specified in Branch Calendars — even if only one branch functions on a day, BOD must be run for that day.

BOD — Beginning of Day Operations

BOD can only run after previous day's EOD is completed successfully.

  • (a) Starts a new business day
  • (b) Time deposit processing — interest and maturity
  • (c) Standing instructions execution
  • (d) Value date processing of cheques (based on set-up)
  • (e) Salary processing
  • (f) Expiry of Overdraft Limits

EOD — End of Day Operations (43.6)

Carried out at Data Centre or Branch depending on CBS architecture.

  • i. Day-end activities documented and monitored via checklist
  • ii. Minimum balances calculated
  • ii. Products calculated for Current Account (Debit balances)
  • iv. Mandatory reports generated
  • v. Fallback procedures activated
  • vi. Day-end backup taken
  • vii. Recording in Log Books
  • vii. Recording entries in Backup Register
  • ix. Filing of reports
  • x. Shutting down of complete computer system
  • xi. Server Room locked; keys with authorised person only
  • xi. Data backups documented and kept in safe custody

Documents Generated at EOD

  • Cash Denomination Report — printed and filed.
  • Vouchers tallied and signed by Branch Manager or System Administrator.
  • If no Branch Server: all server activities (fallback, Central EOD, backups, shutdown/restart, ATM transactions on hold) are carried out at the Central Data Centre.
4

Password Control & Parameter/Master Files

Members Only

43.7 Password Control — Basic Operational Controls

A

Segregation of Duties

B

Four Eye Principle / Maker-Checker

C

Rotation of Duties

D

Ownership of Systems — granting access rights

CBS Password Requirements

(a)Minimum length 8 characters — the more, the better
(b)Both uppercase and lowercase letters
(c)Must be a mixture of letters and numbers
(d)Must include at least one special character
(e)Dictionary words must be avoided
(f)Prevent reusing of previous passwords
(g)Enforce periodical password changes
(h)Passwords disabled during employee's leave of absence
(i)Multi-user or multi-factor authentication for critical modules
(j)Passwords stored in the system in encrypted form only

Operational Password Practices

  • i. All employees and users must maintain password secrecy.
  • ii. OS Password kept under Dual Control of Branch Manager and System Administrator — in a sealed cover; opened in presence of at least 2 persons; changed immediately on opening.
  • iii. Critical passwords for sensitive jobs (entering OS, local backups, monitoring disk space, creating/editing Master Records) known only to Branch Manager or System Administrator.

43.8 Parameter/Master Files

Parameter/Master Files are set up at the first stage of implementation. Thereafter, the system operates according to the enforced parameters. Operators should have READ-ONLY access — modifiable access invites undesirable alterations leading to revenue leakage and fund misuse.

Bank Responsibilities for Parameter Files

  • (a) Authorised personnel mark all Bank Holidays in the software before the beginning of the Financial Year.
  • (b) Operation limits and authorisation levels defined clearly for operators and supervisors.
  • (c) Parameter files printed BEFORE and AFTER changes are given effect; documented and filed.
  • (d) Parameters for Interest and Bank Charges defined per applicable rates/guidelines; updated when changes are announced.
  • (e) Safe custody of printouts ensured; alterations captured in the 'Parameter Register'.

Important Master Files in CBS

(a) Master Data of Accounts
(b) General-purpose parameter files
(c) Account types and structure for the General Ledger
(d) Advances interest rates for various schemes
(e) Deposit interest rates for various tenors
(f) List of holidays
(g) Authorization rights for exceptional transactions
(h) Types of users and their work classes
5

Logical Access Control & Security Controls

Members Only

43.9 Logical Access Control

To safeguard assets, computer systems, and data integrity, the following must be ensured:

  • (a) Security policy addresses specific OS capabilities; available security features must be implemented.
  • (b) Chief Information Security Officer (CISO) ensures all available features are implemented.
  • (c) Process for granting access levels must be clearly defined.
  • (d) Users must have the MINIMUM access level needed to do their job.
  • (e) Users' access restricted to specific applications, menus within applications, files, and servers.
  • (f) File maintenance should be a separate access privilege.
  • (g) Maintenance restricted to minimum number of persons; properly approved and reviewed.
  • (h) Modem access should be restricted; modem passwords changed periodically.
  • (i) After-hours access must be controlled and monitored.

43.10 Operational Aspects of Security Control in CBS

Key security control aspects in a computerised bank:

(a)Authorised, accurate, and complete data are made available for processing.
(b)In case of interruption (power/mechanical/processing failure), system restarts without distorting the completion of records.
(c)System prevents unauthorised amendments to programmes.
(d)Access controls assigned to staff match their responsibilities as per manual.
(e)Segregation of duties maintained while granting system access; user activities monitored by reviewing Logs.
(f)Changes in parameters or user levels must be authenticated.
(g)Charges calculated manually (for functions not regulated through parameters) are properly accounted for and authorised.
(h)All modules in the software are implemented.
(i)Exceptional transaction reports authorised and verified regularly by concerned officials.
(j)Account master and balance cannot be modified/amended/altered except by authorised personnel.
(k)Balance in General Ledger tallies with balance in the subsidiary book.
(l)All GL account codes authorised by Head Office exist in the system.
(m)Important passwords (database administrator, branch manager) kept in sealed cover with branch manager for emergency use.
(n)Backup media stored in a FIREPROOF CABINET under lock and key; off-site backups preserved for emergency.
(o)Daily backup in 6 sets (one per weekday) + 12 sets (one per month); Backup Register maintained and updated.
(p)Anti-virus software of latest version installed in servers/PCs; regularly updated for new viruses.
(q)Security patches applied to systems as and when released by vendors/developers.
(r)Access to the computer room restricted to authorised persons only.
6

Bank Roles & Responsibilities, Summary & Flashcards

Members Only

43.11 Role and Responsibilities of the Bank under CBS

As per RBI Circular No.1462/02.14.003/2012-13 dated February 28, 2013, banks must have documented policies and procedures covering the following IT areas:

(1) IT Policy
(2) Data processing and data interface under various systems
(3) Data integrity and data security
(4) Business Continuity Plans and Disaster Recovery Plans
(5) Accounting manual and critical accounting entries (including month-end/year-end) — IT Controls over account codes, KYC/AML, ALM, etc.
(6) Documentation of Controls and various e-banking and internet banking products
(7) Manual processing of key transactions
(8) MIS reports generated and their periodicity
(9) Hard copies generated and their periodicity
(10) Process of generating information for disclosures in financial statements
(11) Generation of major exceptional reports and actionables
(12) Major IT-related issues (frauds/failures) faced and resolved/unresolved during the year
(13) Significant observations of internal/concurrent/system auditors and RBI inspection related to computerised accounting
(14) Customer complaints related to errors in transactions (interest application, balances, etc.)

System Audit Requirement

  • Banks must get a System Audit done by a firm of Chartered Accountants.
  • Scope: hardware structure, operating systems, critical applications, security controls, access controls on key applications, DRS, personnel training, documentation.
  • System auditor must comment on deviations from the process flow submitted to RBI while seeking authorisation.

Chapter 43 in 5 Lines

  1. CBS merges Communication Technology + IT; client software at branches connects to central server via MPLS/VSAT/RF/3G/4G. Examples: Finacle (Infosys), BaNCS (TCS), Flexcube (Oracle). 12 functions from account management to CRM. Three transaction types: Cash, Clearing, Transfer.
  2. Branch transactions follow Maker-Checker: teller (Maker) initiates, officer (Checker) authorises. System validates account number, balance, authority, and product-level parameters before committing. CBS is an OLTP system — simultaneous real-time debits/credits across customer ledgers, GL, and all sub-systems.
  3. EOD must complete before BOD can run. BOD: new day start, time deposit processing, standing instructions, value date processing, salary, OD limit expiry. EOD: minimum balance calculation, mandatory reports, fallback procedures, day-end backup, log book and backup register entries, system shutdown, server room locked.
  4. 4 Basic Operational Controls: Segregation of Duties, Four Eye Principle/Maker-Checker, Rotation of Duties, Ownership of systems. CBS enforces 10 password controls including min 8 chars, upper+lowercase, letters+numbers, 1 special character, no dictionary word, no reuse, disabled during leave, periodic change, multi-factor for critical modules, encrypted storage. OS password under dual control in sealed cover.
  5. Operators have READ-ONLY access to Parameter/Master Files; printouts taken before and after any changes. CISO ensures security features are implemented; users get minimum access level. Daily backup: 6 sets per week + 12 monthly; fireproof cabinet storage + off-site. Banks must have 14 IT policy areas per RBI circular No.1462 (Feb 28, 2013); System Audit by Chartered Accountants is mandatory.

Flashcards — Chapter 43

1. What is CBS and what does it merge?
CBS (Core Banking Solutions) is a platform where Communication Technology and Information Technology merge to suit core banking needs. Client software at branches connects to a central server.
2. Name three CBS software examples and their vendors.
Finacle (Infosys), BaNCS — Bank and Customer Services (TCS), Flexcube (Oracle).
3. What connectivity does CBS use to connect branches to the central server?
Lease lines, MPLS (Multi-Protocol Label Switching), VSAT, RF (Radio Frequency), 3G/4G, and other networking technologies.
4. What are the three types of transactions in CBS?
Cash, Clearing, and Transfer. All transactions made by branch users, customers through alternate delivery channels, or third-party trusted vendors are ultimately reflected in the Central Database.
5. Explain the Maker-Checker concept in CBS.
Branch transactions follow Maker-Checker functionality. The Maker (teller) initiates/does the transaction. The Checker (authorising officer) validates and authorises it. Transactions are committed to the Central Database only after ALL legs are completed.
6. What does the system validate before committing a CBS transaction?
Account number, balance in the account, authority of the Maker (teller), authority of the Checker (authorising officer), and other product-level parameterised validations.
7. What type of system is CBS for accounting purposes?
CBS is an OLTP (Online Transaction Processing) system operating on a real-time basis. Transactions are effected simultaneously in all sub-systems — customer accounts ledgers, General Ledger, and all other books of accounts — with necessary debits and credits.
8. What is the relationship between EOD and BOD? Why are they critical?
EOD (End of Day) must be completed before BOD (Beginning of Day) can run for the next day. Both are very critical operations that must be performed diligently on time. Days are always business days as specified in Branch Calendars.
9. What are the key BOD (Beginning of Day) operations in CBS?
(a) Starts a new business day; (b) Time deposit processing — interest and maturity; (c) Standing instructions execution; (d) Value date processing of cheques; (e) Salary processing; (f) Expiry of Overdraft Limits.
10. What are the key EOD (End of Day) operations in CBS?
Minimum balance calculation; products for Current Account (debit balances); mandatory reports generated; fallback procedures activated; day-end backup taken; recording in Log Books and Backup Register; filing of reports; shutting down computer system; server room locked with keys to authorised person only; data backups in safe custody.
11. What are the four Basic Operational Controls in CBS?
(A) Segregation of Duties; (B) Four Eye Principle / Maker-Checker; (C) Rotation of Duties; (D) Ownership of systems for granting access rights.
12. List the CBS password requirements.
(a) Min 8 characters; (b) Both uppercase and lowercase; (c) Letters + numbers; (d) At least one special character; (e) No dictionary words; (f) Prevent reuse of previous passwords; (g) Periodic changes enforced; (h) Disabled during leave of absence; (i) Multi-factor authentication for critical modules; (j) Stored in encrypted form only.
13. How should the OS password be controlled at a branch?
Under Dual Control of Branch Manager and System Administrator. Kept in a sealed cover; opened in the presence of at least two persons; changed immediately upon opening.
14. What is the access level for operators on Parameter/Master Files?
Operators should have READ-ONLY access to Parameter/Master Files. Modifiable access invites undesirable alterations leading to revenue leakage and fund misuse.
15. What is the procedure for making changes to Parameter/Master Files?
Printouts of the file must be taken BEFORE and AFTER changes are made; these printouts are documented in safe custody of the Branch Manager. Alterations are captured in the 'Parameter Register'.
16. What is the access principle for CBS users (Logical Access Control)?
Users should have the MINIMUM access level needed to do their job. Access is restricted to specific applications, menus within applications, files, and servers. File maintenance is a separate access privilege.
17. What is the backup frequency requirement for CBS?
Daily backup in 6 sets — one for each weekday — and 12 sets for each month. Backup media stored in a FIREPROOF cabinet under lock and key; off-site backups preserved for emergency. Backup Register maintained and updated.
18. What is the anti-virus and patch management requirement in CBS?
Anti-virus software of the latest version must be installed in all servers/PCs of branches; regularly updated for new viruses. Security patches applied to systems as and when released by vendors/developers.
19. What RBI circular governs bank IT responsibilities under CBS, and what does it mandate?
RBI Circular No.1462/02.14.003/2012-13 dated February 28, 2013. It mandates banks to have documented IT Policy, BCP/DRP, accounting manual, MIS reports, documentation of controls, and 14 specific IT policy areas covering data integrity, security, e-banking, audit observations, and customer complaints.
20. What is System Audit in the CBS context and who conducts it?
System Audit is conducted by a firm of Chartered Accountants. Scope: hardware structure, OS, critical applications, security and access controls, Disaster Recovery Plans, personnel training, and documentation. The auditor must also comment on deviations from the process flow submitted to RBI.

Discussion

Sign in to join the discussion.

No comments yet. Be the first to share your thoughts.