Chapter 020: Deposit Lifecycle Case Study
Section 4: Deposit and Funding Accounting · Chapter 020 of 100
A corporate salary file (20,000 payments, 45m) meets a system migration, a rate change and a fraud freeze — in one week. This capstone case runs deposits and payments through exception storms with GL proof intact: lifecycle journals, suspense storms, three-way reconciliation and substantiated close. Blocks 3, 4 and 11 fire together.
1. Chapter opening
Case week (fictional): Monday — salary file with 300 bad account numbers; Tuesday — savings-rate rise misapplied to 40,000 accounts; Wednesday — fraud freeze on 2m of inflows; Thursday — migration dress-rehearsal breaks subledger-GL tie-out; Friday — close with everything proven. Each day: journals, breaks, owners, resolutions. Friday pack: zero unexplained breaks, attested balances, filed returns unaffected. The opening establishes the case-week structure: five days, five incidents, each requiring different controls, different skills, and different resolution paths. The case is capstone because it integrates deposit-lifecycle accounting (Section 4), payments (Section 6) and balance-sheet substantiation (Section 11) in a single scenario. The objective is not just to survive the week but to prove the system works under fire — to demonstrate that the controls, processes, and people can handle simultaneous exceptions without compromising the close. This is the real test of a finance operation: not whether it works on a normal day, but whether it works when everything goes wrong at once.
2. Learning objectives
- Post high-volume payment/deposit events with idempotency and batch controls.
- Manage simultaneous exceptions (returns, mis-accruals, freezes, feed breaks).
- Run three-way reconciliation (systems↔GL↔statements) under volume.
- Prove suspense clearing with item-level tie-outs.
- Close the week with substantiated balances and lessons logged.
3. Business context
Peak-week resilience is franchise infrastructure (salary failures trend publicly within hours); migration windows concentrate risk (dress rehearsals must use production volumes); concurrent incidents need incident-command discipline (severity tiers, war rooms, customer communications). Post-week review converts pain into prevention budgets — quantified by incident cost.
The salary week is the bank's most visible operational event: 20,000 payments flowing through the system in a single batch, each one expected to arrive on time and in the correct amount. Failure is public: employees who do not receive their salaries complain on social media, contact employers, and generate press coverage within hours. The bank's operational resilience is tested most intensely during this window, and the finance operation's quality is proven or disproven by how it handles the inevitable exceptions. Migration windows — periods when systems are being upgraded or replaced — concentrate risk because they introduce new failure modes into an already-stressed environment. The dress-rehearsal on Thursday is not optional: it proves that the migration can proceed without disrupting the close, even when production is under peak load. Concurrent incidents — multiple failures occurring simultaneously — require incident-command discipline: severity tiers, war rooms, customer communications. The post-week review converts the pain of the week into prevention budgets: each incident is costed, and the cost is compared to the investment required to prevent recurrence. This quantification — incident cost vs prevention cost — drives the business case for operational improvements.
| Day | Incident | Control fired |
|---|---|---|
| Mon | 300 bad accounts | Pre-settlement reject or post-settlement return as applicable |
| Tue | Rate misapplied | Accrual re-performance + reversal |
| Wed | 2m under investigation | Lawful hold authority and separate SAR/STR assessment |
| Thu | Tie-out break | Feed rollback + re-run |
| Fri | Close | Substantiation packs |
4. Finance and accounting view
4.1 Day-by-day journals (fictional, millions)
Monday: assume the employer holds its account at this bank and all salary beneficiaries are external. Debit 45.0 from the employer only when the approved processing rule recognises it: Dr Employer deposit 45.0 / Cr Settlement payable 45.0. Before external settlement, 300 items totalling 0.7 fail beneficiary validation: Dr Settlement payable 0.7 / Cr Employer deposit 0.7. Settle the valid 44.3: Dr Settlement payable 44.3 / Cr Settlement cash 44.3. The payable clears to zero and employer debit nets to 44.3. If invalid items were never debited, reject them without a refund journal. If a settled item returns later, book the actual returned cash and customer refund separately; do not call every pre-settlement reject a return.
Tuesday: duplicate accrued savings interest of 0.8 is reversed Dr Accrued interest payable 0.8 / Cr Interest expense 0.8. If already capitalised, reverse the appropriate customer deposit liability, subject to lawful recovery and remediation. Use journal linkage and a replay-safe correction.
Wednesday: 2.0 of already received funds remains a customer liability while lawful access restrictions are investigated. A fraud hold, sanctions freeze and AML SAR/STR are distinct decisions; suspicion reporting is not an automatic instruction to freeze. Determine legal authority, confidentiality and permitted customer messaging.
Thursday: a migration extract omits 5,000 records. Count/control-total checks detect the omission; a trusted payload hash checks transfer integrity. Quarantine or contain under the interface design, obtain a corrected extract and prove no duplicate effects.
Friday: reconcile deposits, payable, actual cash settlements, accrued interest and every open suspense item. A clearing account may retain legitimate unsettled items at cut-off; prove those items and age them rather than forcing zero through a plug.
4.2 Proof pack (Friday)
The pack ties customer subledgers to GL control accounts with defined measurement/date bridges, GL cash to external statements, and payment processing to settled/rejected/returned/pending populations. Explain each residual by item, owner, status and expected resolution. A zero net clearing balance can hide unmatched debit and credit items, so inspect item-level movements.
Outstanding reconciling items do not become cleared merely because they have owners. Assess materiality, customer impact and permitted sign-off under policy; retain the limitation in attestation and assess any affected report. Regulatory data requires current reconciled balances plus relevant risk/attribute inputs, not the GL alone.
4.3 Deep dive: incident-command architecture and customer-communication playbooks
Assign incident commander, technical/accounting leads, Operations, Compliance and communications owners. Use institution-specific severity, decision rights and escalation timeframes; legal reporting clocks require their own jurisdiction assessment. Protect evidence and avoid improvised recovery debits.
Issue accurate customer updates through approved channels and review restrictions with Compliance. Do not promise a fraud/AML hold is temporary or funds are safe when the outcome is unknown. Prioritise vulnerable customers and document compensation/redress authority. Close an incident on tested recovery, reconciled accounting and an owned follow-up plan, not an arbitrary five-day universal rule.
5. Product and customer impact
Salary-week failures need minute-level customer communication (employer hotline, beneficiary updates, compensation for charges caused); rate-error reversals need explanatory statements (not silent corrections); fraud holds need careful messaging (tipping-off constraints). Post-incident goodwill (fee waivers, interest compensation) costs less than attrition.
The product and customer impact of the case week is immediate and measurable. Salary failures — employees not receiving their salaries — generate employer hotline calls, beneficiary complaints, and social media posts within hours. The bank's response determines whether the incident becomes a retention event or an attrition event. Rate-error reversals — silently correcting a misapplied rate — are worse than the error itself: customers who see an unexpected interest charge and then see it reversed without explanation lose trust in the bank's accuracy and transparency. Fraud holds — freezing funds pending investigation — require careful messaging: applicable confidentiality and tipping-off rules constrain some disclosures, while a fraud hold is not automatically an AML restriction. Compliance must approve accurate wording; do not promise a temporary hold, safe funds or a guaranteed release when the outcome is unknown. Post-incident goodwill — fee waivers, interest compensation, goodwill gestures — costs less than attrition: the cost of retaining a customer through a goodwill gesture is a fraction of the cost of acquiring a replacement.
6. Regulatory and supervisory view
Payment, operational-resilience and fraud incident reporting have different thresholds and clocks by jurisdiction, scheme and incident. There is no global 2-4 hour S1 reporting rule. SAR/STR duties and confidentiality are separately assessed; filing one does not replace a fraud crime report. Record actual financial losses for operational-risk and accounting assessment, but do not claim every incident automatically increases regulatory capital in the same way.
7. Systems and data view
Use separate payment, deposit-accrual, fraud-case, migration, reconciliation and incident-management records. A salary batch can contain accepted, rejected and pending individual items; the entire batch need not be one atomic external settlement. Enforce idempotency at the designed payment/action unit and prove the sum of all dispositions.
Sender/receiver counts and amount totals establish population completeness; trusted hashes establish integrity of the compared payload. Fraud holds need lawful authority and audit history, while SAR/STR decisions have separate legal criteria and confidentiality requirements. Reconcile source/subledger, GL and external bank/scheme evidence at a risk-appropriate cadence, preserving unresolved items with owners.
8. End to end process
- Absorb volume with batch controls. 2. Triage exceptions by taxonomy. 3. Apply the designed rejection or partial-acceptance boundary and retain every item’s disposition. 4. Reverse errors with narratives. 5. Reconcile three-way continuously. 6. Prove Friday with packs. 7. Log lessons with prevention budgets.
9. Controls and risks
| Risk | Control | Evidence |
|---|---|---|
| Duplicate batch posting | Idempotency + rerun guards | Replay logs |
| Silent feed drops | Hash/count completeness | Proof packs |
| Tipping-off in comms | Compliance scripts | Script adherence |
| Unproven close | Pack gates (zero unexplained) | Attestation packs |
10. Practical examples
Salary proof: 20,000 instructions total45.0m. Assume300 items total0.7m reject before external settlement, leaving19,700 items total44.3m settled. The employer deposit is debited45.0m and recredited0.7m; settlement cash falls44.3m. A later return of a settled item is a distinct event and must not reuse the pre-settlement rejection journal.
Accrual proof: opening12.0 + engine2.1 − capitalised1.9 − error reversal0.8 = closing11.4. Any additional goodwill interest is a separately posted expense/liability and does not disappear from this roll-forward.
Open items: suspense1.4 equals42 evidenced items; three nostro differences remain owned and dated. An attestation can confirm their recorded dispositions, not claim that all breaks cleared. A zero clearing balance is only expected where the actual settlement cycle has completed.
Incident review: prevention budget0.3+0.1+0.2=0.6m is compared with expected future benefits, loss probabilities and actual incident cost; direct cost0.09m alone does not establish payback. A suspected-money-laundering assessment follows applicable law; no universal “SAR on day2” deadline or automatic fraud freeze is assumed.
11. Diagrams
Figure 1. Deposit case lifecycle.
Figure 2. Deposit reconciliation.
Figure 3. Deposit maturity outcomes.
12. Tables
Table 1 — Week journal summary (fictional m)
| Day | Postings | Breaks cleared |
|---|---|---|
| Mon | 44.3 externally settled, 0.7 pre-settlement rejection refunded | 300 rejected items evidenced; repair is a separate action |
| Tue | 0.8 double-accrual reversed | Rate engine fixed |
| Wed | 2.0 restricted if lawfully authorised | Separate documented SAR/STR assessment |
| Thu | Feed re-sent, deduped | Tie-out restored |
| Fri | Close proven | 42 suspense owned |
Table 2 — Incident costs (illustrative)
| Cost | Amount |
|---|---|
| Compensation/goodwill | 0.05m |
| Overtime/war room | 0.02m |
| Illustrative prevention budget approved | 0.6m |
13. Illustrative bank case study
A salary batch acknowledgement is lost. In this fictional case, the payment service commits a salary batch but the success acknowledgement does not reach the producer. A retry with the same stable action IDs returns the original outcomes. Without that control, recovery of duplicate customer payments would require legal entitlement, scheme procedures and customer communication; a recall request does not guarantee funds can be recovered.
14. BA, developer, tester and operations guidance
- BA: Specify batch controls, exception taxonomies, communication triggers per incident class.
- Developer: Idempotent batches; hash-complete feeds; narrative-rich reversals.
- Tester: Volume + incident combined scenarios (the conjunctions production runs).
- Operations: Command incidents by severity; communicate early; log lessons with budgets.
15. Common mistakes
- Uncontrolled partial acceptance without reconciliation of accepted, rejected and pending items.
- Silent reversals without customer explanation.
- Freezing funds without tipping-off review.
- Closing over unexplained breaks to "catch up."
- Lessons logged without prevention budgets.
- Treating incidents as heroics rather than repeatable processes.
- Post-incident reviews delayed beyond 2 weeks, losing detail and honesty.
16. Key takeaways
- Volume + incidents is the real test — design for conjunctions.
- Quarantine bad feeds; reverse errors narratively; freeze lawfully.
- Three-way reconciliation runs continuously, not after.
- Friday proven means zero unexplained with packs attested.
- Incident cost quantifies prevention budgets — log both.
17. References and verification notes
-
BCBS 239: risk data aggregation principles: governance, architecture, accuracy, completeness, timeliness and adaptability underpin risk-data aggregation; scope and supervisory application vary. It prescribes neither one warehouse architecture nor universal numeric reconciliation tolerances.
-
UK NCA: suspicious activity reporting: UK-specific SAR and tipping-off framework; fraud reporting, money-laundering reporting and legal restriction of funds are distinct decisions.
-
Incident-reporting, tipping-off, conduct/redress duties per applicable jurisdiction — verify locally; SAR/STR timelines confirm.
-
All volumes, amounts and timelines are fictional training designs.