Foundations of Modern Banking — Module 3
Course Code: COM1MN106 • Lecture Notes
- Banking: Ethics, KYC Architecture & Anti-Money Laundering (AML) In modern financial ecosystems, public confidence is the cornerstone of banking solvency. To safeguard the financial system against criminal exploitation, terror financing, and illicit capital flows, commercial banks enforce stringent ethical governance frameworks, Know Your Customer (KYC) mandates, and statutory AntiMoney Laundering (AML) protocols. 1.1 The Prevention of Money Laundering Act (PMLA, 2002) & The 3 Stages of Money Laundering Money laundering is the illicit process of disguising the origin of illegal funds (from drug trafficking, bribery, tax evasion) to make them appear legitimate. It operates across three distinct stages:
Laundering Stage Operational Mechanism Banking Counter-Measures & Detection
- Placement: Injecting physical illicit cash into the legitimate financial system (e.g., structuring large deposits into multiple micro-deposits below reporting thresholds / "Smurfing").
- Strict cash deposit thresholds.
- Mandatory reporting of Cash Transaction Reports (CTR) for transactions > ₹10 Lakhs.
- Layering: Creating complex layers of financial transactions (wire transfers, shell companies, offshore accounts, crypto conversions) to obscure the audit trail.
- Automated transaction monitoring software.
- Tracking rapid velocity of funds and sudden cross-border SWIFT transfers. 3.
Integration Re-entering the laundered funds into the formal economy under the guise of clean wealth (purchasing luxury real estate, commercial assets, stocks).
- Source of Wealth (SoW) declarations.
- Suspicious Transaction Reports (STR) filed with FIU-IND (Financial Intelligence Unit – India). 1.2 Customer Due Diligence (CDD) & Enhanced Due Diligence (EDD)
- Standard: Customer Due Diligence (CDD) Conducted on all low-to-medium risk customers:
Verification of customer identity using
- Officially Valid Documents (OVDs: Aadhaar, PAN, Passport).
Establishing the identity of the Beneficial Owner (BO) owning ≥ 10% equity in corporate accounts.
Periodic Re-KYC verification (every 10 years for low-risk, 8 years for medium-risk).
- Enhanced: Due Diligence (EDD) Mandatory for high-risk accounts and Politically Exposed Persons (PEPs):
Senior government officials, politicians, military generals, and their immediate families.
Requires senior management approval prior to account onboarding.
Mandatory verification of Source of Funds (SoF) and continuous transaction monitoring;
Re-KYC every 2 years. 1.3 Banking Ethics & The RBI Integrated Ombudsman Scheme, 2021 To ensure fair customer treatment and transparent dispute resolution, the RBI unified previous ombudsman systems into the Reserve Bank – Integrated Ombudsman Scheme (RB-IOS, 2021): "One Nation, One Ombudsman" Principle: Provides a single, free, centralized digital portal for lodging customer grievances across banks, NBFCs, and payment system participants.
- Compensation Powers: The Ombudsman can award compensation up to ₹20 Lakhs for financial loss and up to ₹1 Lakh for mental harassment and loss of time. 1.4 The Financial Action Task Force (FATF) & Global AML Standards
1. FATF 40 Recommendations The global standard established by the intergovernmental body FATF to prevent money laundering, terrorist financing, and proliferation financing. Mandates international cooperation, beneficial ownership transparency, and PEP monitoring.
- FATF: Jurisdictional Lists Grey List (Jurisdictions under Increased
- Monitoring): Countries with strategic AML deficiencies actively working with FATF to resolve them.
- Black List (High-Risk Jurisdictions): Noncooperative countries subjected to strict economic countermeasures and enhanced banking scrutiny. 1.5 Statutory Reporting Architecture to FIU-IND Statutory Report Type Reporting Threshold & Criteria Mandatory Submission Deadline to FIU-IND
- Cash: Transaction Report (CTR) All individual cash transactions exceeding ₹10 Lakhs (or equivalent in foreign currency) or integrally connected transactions in a month.
Submitted monthly by the 15th of the succeeding month.
- Suspicious: Transaction Report (STR) Transactions giving rise to reasonable suspicion of criminal proceeds, tax evasion, or terrorist financing, regardless of monetary value.
Submitted within 7 working days of arriving at a conclusion of suspicion.
- Cross-Border: Wire Transfer Report (CBWTR) All cross-border wire transfers exceeding ₹5 Lakhs (or foreign currency equivalent).
Submitted monthly by the 15th of the succeeding month.
- Major: Banking Regulations & Statutory Frameworks in India Indian banking operates under a robust statutory architecture designed to ensure institutional soundness, depositor protection, and effective resolution of stressed assets. 2.1 Master Statutory Pillars Governing Indian Banking Statutory Act Key Legislative Provisions Core Regulatory Mandate
- Banking: Regulation Act, 1949
- Section 5(b): Definitional scope.
- Section 21 & 35A: RBI powers to control advances and issue binding policy directives.
- Section 36/45: Compulsory amalgamation and moratorium powers.
Comprehensive supervision of banking operations, licensing, board appointments, and branch expansion.
- Reserve: Bank of India Act, 1934
- Section 22: Note issue monopoly.
- Section 42: Cash Reserve Ratio (CRR) enforcement.
- Second Schedule: Scheduled Bank criteria. Constitutes the RBI as the apex central bank, currency authority, and monetary controller.
- SARFAESI: Act, 2002
- Section 13(2): 60-day legal demand notice to NPA borrowers.
- Section 13(4): Direct enforcement and takeover of secured collateral without court intervention.
- Establishment of Asset Reconstruction Companies (ARCs).
Empowers secured creditors (banks) to recover NPAs rapidly by seizing, managing, or auctioning mortgaged assets without court intervention.
- Insolvency and: Bankruptcy Code (IBC, 2016)
- Corporate Insolvency Resolution Process (CIRP) conducted under the National Company Law Tribunal (NCLT).
- Strict 180+90 day resolution timeline; committee of creditors (CoC) voting.
Time-bound reorganization and insolvency resolution for corporate debtors to maximize asset value and protect creditor claims.
- DICGC: Act, 1961
- Deposit Insurance and Credit Guarantee Corporation provides statutory insurance coverage up to ₹5 Lakhs per depositor per bank (principal + interest) across all branches.
Protects small retail depositors in the rare event of commercial or cooperative bank liquidation. 2.2 Comparative Analysis: SARFAESI Act, 2002 vs. Insolvency and Bankruptcy Code (IBC, 2016) Analytical Dimension SARFAESI Act, 2002 Insolvency and Bankruptcy Code (IBC, 2016)
- Primary: Objective Individual debt recovery and collateral enforcement for secured creditors.
Corporate revival, collective resolution, and value maximization of the corporate debtor.
- Judicial: Forum Debt Recovery Tribunal (DRT) and DRAT (Debt Recovery Appellate Tribunal).
National Company Law Tribunal (NCLT) and NCLAT.
- Trigger &: Initiation Initiated solely by secured creditors holding ≥ 60% value of debt once account is classified NPA.
Initiated by Financial Creditors, Operational Creditors, or Corporate Debtor for defaults ≥ ₹1 Crore.
- Moratorium: Protection No automatic moratorium on other borrower assets.
Calm Period / Moratorium (Section 14): Prohibits all debt recovery actions during CIRP. 2.3 The RBI Prompt Corrective Action (PCA) Framework To preserve systemic solvency, the RBI places financially vulnerable banks under the Prompt Corrective Action (PCA) regime based on three tracked parameters: Capital (CRAR / CET-1), Asset Quality (Net NPA Ratio), and Leverage. ∑ Worked Illustration: RBI Prompt Corrective Action (PCA) Diagnostic Assessment
- Bank Solvency & Asset Quality Audit: Bank's Total Advances = ₹50,000 Cr | Gross NPAs = ₹4,000 Cr | Provisions Held = ₹1,000 Cr → Net NPAs = ₹3,000 Cr.
- Net NPA: Ratio = (₹3,000 Cr ÷ ₹50,000 Cr) × 100 = 6.0% (Breaches Risk Threshold 1 of 6.0%).
- Capital Position: Total Capital = ₹4,200 Cr | Risk-Weighted Assets = ₹50,000 Cr → CRAR = 8.4% (Below RBI minimum 9.0% benchmark).
- PCA MANDATORY SANCTIONS TRIGGERED: (1) Restriction on dividend distribution; (2) Restriction on opening new branch network; (3) Cap on high-risk commercial lending; (4) Mandatory capital infusion plan.
- Artificial: Intelligence (AI) in Banking Operations & Open Banking The global banking sector is undergoing a profound paradigm shift driven by Artificial Intelligence (AI),
Machine Learning (ML), Natural Language Processing (NLP), and Application Programming Interfaces (APIs). 3.1 Transformative AI Applications in Modern Banking
- AI in: Fraud Detection & Cybersecurity Machine learning models analyze millions of transaction parameters per second in real time:
- Behavioral Biometrics: Monitors typing speed, touchscreen swipe patterns, and device geolocation.
- Anomaly Scoring: Instantly flags out-ofcharacter international credit card swipes, triggering automated transaction freezing.
- AI-Driven: Credit Underwriting Transition from static CIBIL scores to dynamic multivariable credit assessment:
Analyzes alternative data (GST invoices, utility bills, digital cash flow velocity, ecommerce transactions).
Enables automated instant micro-lending for thin-file MSMEs and gig economy workers.
- Conversational AI &: Intelligent Chatbots 24/7 autonomous customer service:
NLP-powered virtual assistants (e.g., SBI SIA, HDFC EVA, ICICI iPal) resolving balance inquiries, card blocking, and fund transfers in regional languages.
- Robotic: Process Automation (RPA) Automating repetitive back-office operations:
Optical Character Recognition (OCR) for extracting data from scanned invoices and KYC forms.
Automated inter-bank reconciliations and loan sanction documentation. 3.2 Open Banking & The Account Aggregator (AA) Ecosystem Open Banking leverages secure, standardized APIs to allow third-party FinTech providers to access customer financial data with explicit consumer consent. In India, this is formalized through the RBI Account Aggregator (AA) Framework:
AA Ecosystem Entity Institutional Identity Operational Role
- Financial: Information Provider (FIP) Banks, Mutual Funds, Insurance Companies, Tax Portals.
Custodians of customer financial data; releases encrypted data upon validated consent.
- Account: Aggregator (AA) RBI-regulated NBFC-AA (e.g.,
Anumati, OneMoney, Finvu). Data-blind digital pipeline transferring encrypted data; cannot read or store customer data.
- Financial: Information User (FIU) Lending Banks, Wealth Managers, Personal Finance Apps.
Consumes aggregated data to offer instant loan underwriting, wealth planning, and advisory. 3.3 AI-Driven Credit Scoring: Machine Learning vs. Traditional Underwriting
- MATHEMATICAL FORMULA: LOGISTIC CREDIT DEFAULT PROBABILITY SCORE Predictive ML Underwriting P (D ef ault) = 1 ÷ [ 1 + e^−(β0 + β1 X 1 + β2 X 2 + ... + βn X n) ] Where: $X_1$ = Cash Flow Stability; $X_2$ = Utility Payment Regularity; $X_3$ = GST Return Inflows; $ eta$ = Feature Importance Weights. ∑ Worked Illustration: AI Multi-Variable MSME Loan Sanction Scoring MSME Applicant Financial Profile (Thin-File / No Prior CIBIL History):
- Monthly Average Bank Balance (MABB) = ₹85,000 (Weight 30% → Score 85/100).
- GST Filing Consistency (12 Months Clean) = 100% (Weight 30% → Score 95/100).
- Digital Merchant POS Inflows = ₹2,40,000/mo (Weight 25% → Score 90/100).
- Utility / Tax Payment Promptness = Clean (Weight 15% → Score 80/100).
Composite AI Credit Score = (85 × 0.30) + (95 × 0.30) + (90 × 0.25) + (80 × 0.15) = 25.5 + 28.5 + 22.5 + 12.0 = 88.5 / 100.
- DECISION ENGINE OUTPUT: Score 88.5 > Cut-off Threshold 75.0 → AUTOMATED INSTANT SANCTION: ₹5,00,000 Working Capital Overdraft at 10.5% p.a. (Zero Manual Human Intervention). 3.4 Banking-as-a-Service (BaaS) & Embedded Finance Architecture
- Banking-as-a-Service (BaaS): Licensed banks integrate their core banking services directly into non-bank FinTech platforms via APIs, allowing non-banks to offer co-branded accounts and cards.
- Embedded: Finance & BNPL Integrating credit, payments, or insurance seamlessly into non-financial apps (e.g., Buy Now Pay Later - BNPL at e-commerce checkout, ridehailing insurance).
- Financial: Inclusion Architecture: The India Stack & Digital Banking Modern banking technology has democratized financial access across rural and low-income demographics through a multi-layered digital public infrastructure known as the India Stack. 4.1 The India Stack & The JAM Trinity
- The JAM: Trinity
- Jan Dhan (PMJDY): Basic Savings Bank Deposit Accounts (BSBDAs) with zero minimum balance, RuPay debit cards, and ₹10,000 overdraft facility.
- Aadhaar: 12-digit biometric digital identity enabling instant e-KYC.
- Mobile: High-speed smartphone connectivity acting as a personal bank branch.
- Payment &: Data Layers
- Unified Payments Interface (UPI): Realtime mobile payment rails developed by NPCI.
- AePS (Aadhaar Enabled Payment System): Enables cash withdrawals and deposits at village micro-ATMs via biometric fingerprint authentication.
- DigiLocker: Cloud repository for verified electronic documents. 4.2 Direct Benefit Transfer (DBT) & The Business Correspondent (BC) Model By routing government welfare subsidies directly into beneficiary bank accounts via the Aadhaar Payment Bridge System (APBS), India eliminated middleman leakages and ghost beneficiaries. Village Business Correspondents (Bank Mitras) extend branchless banking to the deepest rural frontiers. 4.3 The National Payments Corporation of India (NPCI) Product Suite NPCI Payment Rail Technical Architecture Primary Economic Purpose
- UPI (Unified: Payments Interface) Virtual Payment Address (VPA / UPI ID) over IMPS switching architecture.
Peer-to-Peer (P2P) and Peer-to-Merchant (P2M) instant retail settlements.
- IMPS (Immediate: Payment Service) 24/7/365 instant inter-bank electronic fund transfer rail up to ₹5 Lakhs.
Foundation switching engine powering mobile and online fund transfers.
- NACH (National: Automated Clearing House) High-volume bulk transaction processing engine.
Bulk salary/dividend credits (NACH Credit) and recurring loan EMIs/SIPs (NACH Debit).
- Central: Bank Digital Currency (CBDC / eRupee) RBI-issued sovereign digital token recorded on distributed ledger technology.
Legal tender digital cash operating alongside physical banknotes (Wholesale & Retail e-₹).
- Ethical: Considerations, Algorithmic Bias & Data Protection (DPDP Act, 2023) While AI unlocks unparalleled operational efficiencies, it introduces profound ethical, legal, and operational risks that demand stringent algorithmic governance. 5.1 Key Ethical & Technological Challenges in AI Banking Ethical / Operational Risk Technical Mechanism Regulatory & Managerial Remedy
- Algorithmic: Bias & Discrimination AI models trained on biased historical loan data may unfairly reject loans to marginalized communities or specific geographic pincodes.
Mandatory algorithmic fairness audits; stripping protected demographic attributes from training datasets.
2. The "Black Box" Problem Deep neural networks make complex credit decisions without humaninterpretable reasoning (lack of explainability).
Deploying Explainable AI (XAI) frameworks enabling banks to provide rejected borrowers with precise legal reasons for adverse credit actions.
- Data: Privacy & Surveillance Unauthorized aggregation and commercial monetisation of private customer transaction histories.
Strict compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act):
Explicit consent, purpose limitation, and right to data erasure.
- Workforce: Deskilling & Displacement Automation of routine branch teller, customer support, and document processing roles.
Continuous reskilling and upskilling programs transitioning bank employees toward advisory and relationship management. 5.2 Core Principles of Responsible AI in Banking
- Fairness &: Transparency Algorithms must treat all applicants equitably without discriminatory bias, with clear disclosure of automated decision processes.
- Human-in-the-Loop (HITL): Oversight High-stakes decisions (large corporate loan sanctions, fraud investigations) must retain human executive validation to prevent catastrophic model drift. 5.3 The RBI Regulatory Sandbox Framework for FinTech Innovation
- Meaning &: Sandbox Architecture A controlled regulatory testing environment allowing FinTech startups and banks to live-test innovative products (e.g., cross-border retail payments, offline digital payments, MSME lending algorithms) on a limited cohort of real customers with relaxed regulatory requirements.
- Key: Sandbox Thematic Cohorts Cohort 1: Retail Payments (Soundbox, offline NFC).
Cohort 2: Cross-Border Remittances. Cohort 3: MSME Digital Lending.
Cohort 4: Prevention and Mitigation of Financial Frauds. 5.4 Banking Compliance Architecture under the DPDP Act, 2023 Statutory DPDP Requirement Legal Mandate on Banking Entities (Data Fiduciaries) Enforcement & Penal Liabilities
- Explicit &: Itemized Consent Notice must be clear, unambiguous, and available in all 22 Eighth Schedule Indian languages before collecting financial/KYC data.
Pre-ticked consent boxes strictly prohibited; consent can be withdrawn anytime.
- Purpose: Limitation & Data Erasure Financial data can only be used for the explicit purpose for which consent was obtained; data must be permanently erased once the account is closed.
Data breaches punishable with statutory fines up to ₹250 Crore imposed by the Data Protection Board of India (DPBI).
- Appointment of: Data Protection Officer (DPO) Banks designated as Significant Data Fiduciaries (SDFs) must appoint an Indiabased DPO and conduct periodic Data Protection Impact Assessments (DPIAs).
Mandatory internal audit reporting to RBI and Board of Directors.
Download Module 3 Notes (PDF)
Calicut University • FYUGP 2024 Syllabus
Finished this module?
Continue reading the next module or return to the subject overview.