Operational Aspects of CBS Environment
Principles & Practices of Banking | Module C · Chapter 43
This chapter dives into the day-to-day operational mechanics of Core Banking Solutions — how transactions flow through CBS, maker-checker controls, EOD/BOD batch processes, password security rules, parameter file management, logical access controls, and the overall role and responsibilities of banks under CBS as mandated by RBI.
📌 Why This Chapter Matters in JAIIB
Expect 4–6 questions from this chapter. Key focus areas: 3 transaction types (Cash, Clearing, Transfer); Maker-Checker functionality; 4 Basic Operational Controls (Segregation of Duties, Four Eye Principle/Maker-Checker, Rotation of Duties, Ownership of systems); password requirements (min 8 characters, upper+lowercase, letters+numbers, 1 special character, no dictionary word, no reuse, disable during leave, periodic changes, multi-factor for critical modules, stored encrypted); Parameter/Master File (operators = read-only; print before and after changes); EOD/BOD operations and their critical nature; daily backup in 6 sets (one per weekday) + 12 monthly sets; System Audit by Chartered Accountants; 14 IT policy areas banks must maintain under CBS.
Key Facts & References — Chapter 43 at a Glance
Introduction to CBS & Functions Performed
Free43.1 Introduction — What is CBS?
Based on the level of computerisation, banks may be categorised as non-computerised, partially computerised, or fully computerised. Core Banking Solutions (CBS) is a platform where Communication Technology and Information Technology merge to suit core banking needs. Under CBS, client software is installed at different branches to connect to the central server for accessing and updating customer information and transactions.
Primary WAN
Lease lines / MPLS
Backup links
VSAT · RF · 3G/4G
CBS Examples
Finacle · BaNCS · Flexcube
Finacle is by Infosys · BaNCS (Bank and Customer Services) is by TCS · Flexcube is by Oracle
43.2 Functions Performed by CBS
CBS has evolved to handle almost every banking transaction. Common features across popular CBS platforms:
CBS also helps in making cheque clearings faster, improved housekeeping, prevention of income leakages, and faster inter-branch reconciliations (more accurate and automated). It also integrates with ATMs, mobile/internet banking.
Flow of Transactions & Accounting in CBS
Free43.3 Three Types of CBS Transactions
Cash
Physical currency deposits and withdrawals at branches or ATMs.
Clearing
Cheque clearing — inward/outward — processed through clearing system.
Transfer
Fund transfers between accounts within the bank or to other banks.
Transaction Flow — Key Points
- ▸Transactions by branch users, customers through alternate delivery channels, or third-party trusted vendors are ultimately reflected in the Central Database.
- ▸Branch user logs in with User ID + Password + biometric authentication at the CBS terminal.
- ▸Branch transactions follow Maker-Checker functionality: Maker (teller) initiates; Checker (authorising officer) validates.
- ▸Transactions are committed at the Central Database only after ALL legs of the transaction are completed.
- ▸System validates: account number, balance, teller (Maker) authority, officer (Checker) authority, and product-level parameters.
- ▸Transactions also flow from alternate delivery channels, Treasury systems, etc., into the core banking system.
43.4 Accounting of Transactions in CBS
CBS is an Online Transaction Processing (OLTP) system operating on a real-time basis. Transactions are effected in all sub-systems simultaneously, including:
- ▸Customer accounts ledgers
- ▸General Ledger
- ▸Any other books of accounts
All necessary debits and credits are done simultaneously across all sub-systems — there is no time lag.
EOD & BOD Operations
Members OnlyEOD (End of Day) and BOD (Beginning of Day) operations are very critical in core banking. EOD must be completed before BOD can run for that day. Days are always business days as specified in Branch Calendars — even if only one branch functions on a day, BOD must be run for that day.
BOD — Beginning of Day Operations
BOD can only run after previous day's EOD is completed successfully.
- ▸(a) Starts a new business day
- ▸(b) Time deposit processing — interest and maturity
- ▸(c) Standing instructions execution
- ▸(d) Value date processing of cheques (based on set-up)
- ▸(e) Salary processing
- ▸(f) Expiry of Overdraft Limits
EOD — End of Day Operations (43.6)
Carried out at Data Centre or Branch depending on CBS architecture.
- ▸i. Day-end activities documented and monitored via checklist
- ▸ii. Minimum balances calculated
- ▸ii. Products calculated for Current Account (Debit balances)
- ▸iv. Mandatory reports generated
- ▸v. Fallback procedures activated
- ▸vi. Day-end backup taken
- ▸vii. Recording in Log Books
- ▸vii. Recording entries in Backup Register
- ▸ix. Filing of reports
- ▸x. Shutting down of complete computer system
- ▸xi. Server Room locked; keys with authorised person only
- ▸xi. Data backups documented and kept in safe custody
Documents Generated at EOD
- ▸Cash Denomination Report — printed and filed.
- ▸Vouchers tallied and signed by Branch Manager or System Administrator.
- ▸If no Branch Server: all server activities (fallback, Central EOD, backups, shutdown/restart, ATM transactions on hold) are carried out at the Central Data Centre.
Password Control & Parameter/Master Files
Members Only43.7 Password Control — Basic Operational Controls
Segregation of Duties
Four Eye Principle / Maker-Checker
Rotation of Duties
Ownership of Systems — granting access rights
CBS Password Requirements
Operational Password Practices
- ▸i. All employees and users must maintain password secrecy.
- ▸ii. OS Password kept under Dual Control of Branch Manager and System Administrator — in a sealed cover; opened in presence of at least 2 persons; changed immediately on opening.
- ▸iii. Critical passwords for sensitive jobs (entering OS, local backups, monitoring disk space, creating/editing Master Records) known only to Branch Manager or System Administrator.
43.8 Parameter/Master Files
Parameter/Master Files are set up at the first stage of implementation. Thereafter, the system operates according to the enforced parameters. Operators should have READ-ONLY access — modifiable access invites undesirable alterations leading to revenue leakage and fund misuse.
Bank Responsibilities for Parameter Files
- ▸(a) Authorised personnel mark all Bank Holidays in the software before the beginning of the Financial Year.
- ▸(b) Operation limits and authorisation levels defined clearly for operators and supervisors.
- ▸(c) Parameter files printed BEFORE and AFTER changes are given effect; documented and filed.
- ▸(d) Parameters for Interest and Bank Charges defined per applicable rates/guidelines; updated when changes are announced.
- ▸(e) Safe custody of printouts ensured; alterations captured in the 'Parameter Register'.
Important Master Files in CBS
Logical Access Control & Security Controls
Members Only43.9 Logical Access Control
To safeguard assets, computer systems, and data integrity, the following must be ensured:
- ▸(a) Security policy addresses specific OS capabilities; available security features must be implemented.
- ▸(b) Chief Information Security Officer (CISO) ensures all available features are implemented.
- ▸(c) Process for granting access levels must be clearly defined.
- ▸(d) Users must have the MINIMUM access level needed to do their job.
- ▸(e) Users' access restricted to specific applications, menus within applications, files, and servers.
- ▸(f) File maintenance should be a separate access privilege.
- ▸(g) Maintenance restricted to minimum number of persons; properly approved and reviewed.
- ▸(h) Modem access should be restricted; modem passwords changed periodically.
- ▸(i) After-hours access must be controlled and monitored.
43.10 Operational Aspects of Security Control in CBS
Key security control aspects in a computerised bank:
Bank Roles & Responsibilities, Summary & Flashcards
Members Only43.11 Role and Responsibilities of the Bank under CBS
As per RBI Circular No.1462/02.14.003/2012-13 dated February 28, 2013, banks must have documented policies and procedures covering the following IT areas:
System Audit Requirement
- ▸Banks must get a System Audit done by a firm of Chartered Accountants.
- ▸Scope: hardware structure, operating systems, critical applications, security controls, access controls on key applications, DRS, personnel training, documentation.
- ▸System auditor must comment on deviations from the process flow submitted to RBI while seeking authorisation.
Chapter 43 in 5 Lines
- CBS merges Communication Technology + IT; client software at branches connects to central server via MPLS/VSAT/RF/3G/4G. Examples: Finacle (Infosys), BaNCS (TCS), Flexcube (Oracle). 12 functions from account management to CRM. Three transaction types: Cash, Clearing, Transfer.
- Branch transactions follow Maker-Checker: teller (Maker) initiates, officer (Checker) authorises. System validates account number, balance, authority, and product-level parameters before committing. CBS is an OLTP system — simultaneous real-time debits/credits across customer ledgers, GL, and all sub-systems.
- EOD must complete before BOD can run. BOD: new day start, time deposit processing, standing instructions, value date processing, salary, OD limit expiry. EOD: minimum balance calculation, mandatory reports, fallback procedures, day-end backup, log book and backup register entries, system shutdown, server room locked.
- 4 Basic Operational Controls: Segregation of Duties, Four Eye Principle/Maker-Checker, Rotation of Duties, Ownership of systems. CBS enforces 10 password controls including min 8 chars, upper+lowercase, letters+numbers, 1 special character, no dictionary word, no reuse, disabled during leave, periodic change, multi-factor for critical modules, encrypted storage. OS password under dual control in sealed cover.
- Operators have READ-ONLY access to Parameter/Master Files; printouts taken before and after any changes. CISO ensures security features are implemented; users get minimum access level. Daily backup: 6 sets per week + 12 monthly; fireproof cabinet storage + off-site. Banks must have 14 IT policy areas per RBI circular No.1462 (Feb 28, 2013); System Audit by Chartered Accountants is mandatory.
Flashcards — Chapter 43
1. What is CBS and what does it merge?▼
2. Name three CBS software examples and their vendors.▼
3. What connectivity does CBS use to connect branches to the central server?▼
4. What are the three types of transactions in CBS?▼
5. Explain the Maker-Checker concept in CBS.▼
6. What does the system validate before committing a CBS transaction?▼
7. What type of system is CBS for accounting purposes?▼
8. What is the relationship between EOD and BOD? Why are they critical?▼
9. What are the key BOD (Beginning of Day) operations in CBS?▼
10. What are the key EOD (End of Day) operations in CBS?▼
11. What are the four Basic Operational Controls in CBS?▼
12. List the CBS password requirements.▼
13. How should the OS password be controlled at a branch?▼
14. What is the access level for operators on Parameter/Master Files?▼
15. What is the procedure for making changes to Parameter/Master Files?▼
16. What is the access principle for CBS users (Logical Access Control)?▼
17. What is the backup frequency requirement for CBS?▼
18. What is the anti-virus and patch management requirement in CBS?▼
19. What RBI circular governs bank IT responsibilities under CBS, and what does it mandate?▼
20. What is System Audit in the CBS context and who conducts it?▼
Discussion
No comments yet. Be the first to share your thoughts.