Unit 4: Electronic banking and technology
Principles and Practices of Banking notes · PTU syllabus (MCOPBI321-18)
On this page
Unit summary
Technology has made banking instant, cashless and global — and created new risks. This unit covers electronic banking and payment systems, EFT systems and SWIFT, technology upgradation trends and their impact on banks, types of security risks and control mechanisms, IS audit, the Gopalakrishna Committee recommendations, and preventive vigilance against phishing.
After this unit you can
- Explain electronic banking and payment systems including EFT and SWIFT
- Explain technology upgradation trends and their impact on banks
- Explain security risks, control mechanisms and IS audit
- Explain the Gopalakrishna Committee recommendations and preventive vigilance against phishing
PTU syllabus topics
- Electronic banking and payment systems
- EFT systems and SWIFT
- technology upgradation trends and impact on banks
- security risk types and control mechanisms
- IS audit
- Gopalakrishna Committee recommendations
- preventive vigilance against phishing
NEFT
Half-hourly batches, 24x7
Any amount, non-urgent
RTGS
Real-time
₹2 lakh and above
IMPS
Instant, 24x7
Up to ₹5 lakh
UPI
Instant, 24x7
Everyday mobile payments
Topic 1
Electronic banking
E-banking is the delivery of banking services through electronic channels — internet, mobile, ATMs, POS, phone banking.
Internet banking
Account access, transfers, bill payments, FD opening
Mobile banking
Bank apps, USSD (*99#)
ATMs and cash recyclers
Cash withdrawal and deposit
Point of sale (POS)
Card payments at merchants
Phone banking
IVR and call centres
UPI and wallets
Instant mobile payments
| Advantages | Challenges |
|---|---|
| 24 × 7 convenience | Cyber fraud, phishing |
| Lower transaction costs | Digital literacy gaps |
| Faster transactions | Network and system downtime |
| Wider reach and inclusion | Data privacy |
- Core Banking Solution (CBS): centralised database where all branches are connected — "anywhere, anytime banking"; a customer of one branch can transact at any branch (CBS = Centralised Online Real-time Exchange).
Topic 2
EFT and payment systems
| System | Settlement | Limit | Availability |
|---|---|---|---|
| NEFT | Half-hourly batches | No minimum or maximum | 24 × 7 × 365 (since Dec 2019) |
| RTGS | Real-time, gross (one by one) | Minimum ₹2 lakh | 24 × 7 × 365 (since Dec 2020) |
| IMPS | Instant | Up to ₹5 lakh | 24 × 7 (NPCI) |
| UPI | Instant, via VPA/QR | Generally ₹1 lakh (higher for specified categories) | 24 × 7 (NPCI) |
- RTGS and NEFT are owned and operated by RBI; IMPS and UPI by NPCI.
- No charges on NEFT/RTGS for savings account customers through online channels (RBI, 2019).
Exam tip
UPI processes well over 15 billion transactions a month — a world-leading real-time payments system; a good example for "emerging trends".
SWIFT
- Society for Worldwide Interbank Financial Telecommunication (Belgium, 1973) — a secure messaging network used by over 11,000 institutions for cross-border payment instructions, LCs and securities messages; standardised message formats (MT and ISO 20022 MX); SWIFT gpi for faster tracking; India's alternatives — SFMS for domestic messaging, rupee trade settlement.
Topic 3
Technology upgradation trends and impact
Core banking and cloud
Centralised and scalable systems
Digital channels
Mobile apps, UPI, account aggregators, video KYC
AI and analytics
Credit scoring, fraud detection, chatbots
Open banking and APIs
Fintech partnerships, embedded finance
Blockchain
Trade finance, cross-border payments pilots
CBDC
Digital rupee (e₹) pilots since 2022
RegTech
Automated compliance and reporting
- Impact: lower costs, 24×7 service, financial inclusion, new competitors (fintechs, big tech), branch rationalisation, reskilling of staff, higher cyber risk and dependence on IT vendors.
Topic 4
Security risks, control mechanisms and IS audit
Cyber attacks
Malware, ransomware, DDoS
Phishing and social engineering
Fake emails, SMS, calls
Insider threats
Employee fraud, misuse of access
Data breaches
Theft of customer data
System failures
Outages, poor change management
Third-party risks
Vendor and cloud dependencies
- Controls: information security policy, access controls and multi-factor authentication, encryption, firewalls and intrusion detection, security operations centre (SOC), patch management, business continuity and disaster recovery, Cyber Crisis Management Plan, vendor risk management; RBI Cyber Security Framework (2016) and IT Governance Master Direction (2023).
- IS audit: independent review of IT systems, controls, security, data integrity and compliance — risk-based, by certified auditors (CISA); covers general controls (access, change management, operations) and application controls (input, processing, output).
Topic 5
Gopalakrishna Committee and preventive vigilance
- G. Gopalakrishna Working Group (RBI, 2011) on information security, electronic banking, technology risk management and cyber frauds — recommendations:
- IT governance: board-level IT strategy committee, CIO and CISO roles.
- Information security: risk assessment, ISO 27001-based controls, security operations.
- IT operations and service outsourcing: vendor risk management.
- IS audit: independent IS audit function and periodic audits.
- Cyber fraud: fraud risk management, monitoring and reporting.
- Business continuity planning and customer education; legal issues under the IT Act.
Preventive vigilance against phishing
- Phishing: fraudulent messages impersonating banks to steal credentials (vishing — calls; smishing — SMS).
- Bank measures: customer awareness campaigns ("RBI Kehta Hai"), never asking for PIN/OTP, transaction alerts, device binding, anomaly detection, cooling periods, takedown of fake sites, zero liability if fraud reported within 3 days.
- Customer measures: never share OTP/PIN, check URLs, use official apps, enable alerts, report to the bank and cybercrime.gov.in / 1930 helpline immediately.
Key terms
- SWIFT
- Global secure messaging network for financial institutions
- Core banking
- Centralised banking system across branches
- IS audit
- Independent review of information systems and controls
- Phishing
- Fraudulent attempt to obtain sensitive information by impersonation
- CISO
- Chief Information Security Officer
Quick revision
- E-banking channels; NEFT, RTGS, IMPS, UPI; SWIFT for cross-border messages.
- Trends: cloud, AI, APIs, blockchain, CBDC; impact on banks.
- Security risks and controls; RBI cyber security framework; IS audit.
- Gopalakrishna (2011): IT governance, security, IS audit, fraud, BCP, customer education.
- Phishing prevention; 1930 helpline; zero liability.
Important exam questions
Practice questions written to the PTU exam pattern for this unit's syllabus: short answers (Section A style) and long answers (Sections B and C style).
Short-answer questions
- Q1.What is SWIFT?
- Q2.State two technology trends in banking.
- Q3.What is IS audit?
- Q4.Who headed the RBI working group on information security (2011)?
- Q5.What is phishing?
- Q6.State three precautions against phishing.
Long-answer questions
- Q1.Explain electronic banking and electronic funds transfer systems.
- Q2.Discuss technology upgradation trends and their impact on banks.
- Q3.Explain security risks in banking and control mechanisms including IS audit.
- Q4.Explain the recommendations of the Gopalakrishna Committee and preventive vigilance against phishing.
Stuck on this unit?
Message SBS on WhatsApp for help with Principles and Practices of Banking, or to ask about studying M.Com at Synetic.
