This mapping enables the Bank to identify concentration risk, single points of failure, and systemic dependencies across payment channels such as IBFT, RENTAS, DuitNow, cross-border transfers, and corporate bulk payments. It also provides a foundational dataset for scenario testing, disruption analysis, recovery prioritisation, and board reporting, ensuring that payment services remain within defined impact tolerances during severe but plausible disruptions.
|
Sub-CBS Code |
Sub-CBS |
Processes |
People |
Technology (Applications & Infrastructure) |
Third-Party Vendors |
Upstream / Downstream Dependencies |
|
2-01 |
Customer Payment Initiation |
Payment instruction capture via branch, internet banking, mobile banking, ATM, API; input validation; beneficiary validation |
Branch staff, Contact centre, Digital banking team, Product owners |
Internet banking platform, Mobile banking app, ATM switch, API gateway, Core Banking System (CBS), Customer Information File (CIF), Channel servers |
Channel platform vendors, ATM network providers |
Upstream: Customer authentication, account status. Downstream: Authorization engine, Funds processing |
|
2-02 |
Funds Transfer Processing (Intra-bank) |
Account balance verification, debit/credit posting, transaction queuing |
Operations team, Core banking support |
Core Banking System, Transaction processing engine, Middleware, Database cluster |
Core banking vendor |
Upstream: Payment initiation. Downstream: Posting, Notification |
|
2-03 |
Interbank Transfer Processing (IBFT & RENTAS) |
Payment routing, clearing file generation, and settlement instruction submission |
Payment operations, Treasury operations |
Payment hub, IBFT interface, RENTAS gateway, SWIFT interface, Network infrastructure |
Payments Network Malaysia (PayNet), Bank Negara Malaysia (RENTAS operator), SWIFT |
Upstream: Authorization, AML screening. Downstream: Clearing & settlement |
|
2-04 |
DuitNow & Instant Payment Services |
Real-time validation, proxy resolution, instant fund transfer |
Digital payments team, IT support |
DuitNow switch connectivity, Real-time payment engine, API services, Fraud monitoring tools |
Payments Network Malaysia |
Upstream: Customer authentication. Downstream: Core banking update, Notification |
|
2-05 |
Payment Clearing & Settlement |
Clearing file exchange, net settlement calculation, liquidity verification |
Treasury, Settlement team |
Clearing module, RENTAS interface, Liquidity management system |
Bank Negara Malaysia, Payments Network Malaysia |
Upstream: Interbank processing. Downstream: Nostro reconciliation |
|
2-06 |
Corporate & Bulk Payment Processing |
File upload validation, batch processing, payroll/vendor payment execution |
Corporate banking ops, Relationship managers |
Corporate online banking portal, Host-to-host gateway, Batch processing engine |
Corporate channel vendor |
Upstream: Customer file submission. Downstream: Clearing & posting |
|
2-07 |
Cross-Border Payment Processing |
FX validation, SWIFT MT/MX generation, correspondent routing |
Trade finance ops, Treasury, Compliance |
SWIFT gateway, FX system, Core banking, Payment hub |
SWIFT, Correspondent banks |
Upstream: AML screening, FX rates. Downstream: Nostro management |
|
2-08 |
Payment Authorization & Authentication |
2FA validation, OTP generation, transaction signing, limit checks |
Fraud risk team, IT security |
Authentication server, Token management system, Fraud detection engine, IAM platform |
Authentication solution vendor, SMS gateway provider |
Upstream: Payment initiation. Downstream: Processing engines |
|
2-09 |
Sanctions Screening & AML Monitoring |
Name screening, transaction monitoring, alert generation, and case management |
Compliance officers, AML analysts |
Sanctions screening engine, AML monitoring system, Case management tool |
AML software vendor, Sanctions list data providers |
Upstream: Transaction details. Downstream: Authorization decision |
|
2-10 |
Transaction Posting & Core Banking Update |
Ledger update, GL posting, audit trail logging |
Core banking operations |
Core Banking System, GL system, Database servers, Backup systems |
Core banking vendor |
Upstream: Funds transfer processing. Downstream: Reconciliation, Reporting |
|
2-11 |
Exception Handling & Reversal Management |
Failed transaction review, reversal approval, dispute management |
Payment ops, Customer service, Risk team |
Case management system, Core banking, Workflow engine |
CRM vendor |
Upstream: Transaction failure alerts. Downstream: Customer notification |
|
2-12 |
Reconciliation & Nostro/Vostro Management |
Daily reconciliation, suspense account review, nostro balancing |
Finance ops, Treasury back office |
Reconciliation system, Nostro management module, Reporting system |
Correspondent banks |
Upstream: Settlement files. Downstream: Regulatory reporting |
|
2-13 |
Customer Notification & Confirmation |
SMS/email push notification, e-receipt generation |
Digital banking ops, IT support |
Notification engine, SMS gateway, Email server, Mobile push service |
Telco/SMS provider, Email service provider |
Upstream: Successful posting. Downstream: Customer assurance |
|
2-14 |
Payment Reporting & Regulatory Submission |
Regulatory data aggregation, BNM reporting, and audit report generation |
Regulatory reporting team, Compliance |
Regulatory reporting system, Data warehouse, BI tools |
Regulatory reporting solution vendor |
Upstream: Transaction database. Downstream: Submission to Bank Negara Malaysia |
|
2-15 |
Payment Channel Availability & Infrastructure Support |
System monitoring, incident management, DR activation, capacity management |
IT infrastructure, Cybersecurity team, BCM team |
Data centres (primary/DR), Cloud infrastructure, Network devices, SIEM, Backup systems |
Data centre providers, Cloud providers, Network service providers |
Upstream: Power, network connectivity. Downstream: All payment sub-CBS |
The mapping of CBS-2 Payments and Funds Transfer Services provides a transparent, end-to-end view of how critical payment capabilities are delivered, supported, and governed across the Bank. By identifying process flows, key personnel, enabling technologies, third-party dependencies, and upstream/downstream linkages, the Bank can clearly determine concentration risks, systemic exposure to shared infrastructure, and areas requiring strengthened redundancy or diversification.
More importantly, this structured mapping enables effective scenario testing. Disruptions such as payment switch outages, cyber incidents, correspondent bank failure, liquidity stress, or data centre downtime can now be tested against clearly defined dependencies and recovery pathways. Through continuous refinement of this mapping, the Bank strengthens its ability to remain within impact tolerance levels, safeguard customer trust, and sustain payment stability even during severe but plausible disruptions.
|
Implementing Operational Resilience for Bank Islam: Aligning with BNM and Global Best Practices |
|||||
| eBook 3: Starting Your OR Implementation |
|||||
| CBS-2 Payments and Funds Transfer Services | |||||
| CBS-2 DP | CBS-2 MD | CBS-2 MPR | CBS-2 ITo | CBS-2 SuPS | CBS-2 ST |
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|