🏹 Happy Dussehra — victory of good over evil!

SWIFT Payment Fraud Controls: RBI Rules Every Banker Must Know

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 15 August 2026 · Updated 28 Sep 2026 · 9 min read · 48 views
SWIFT Payment Fraud Controls: RBI Rules Every Banker Must Know

Cross-border money leaves an Indian bank through one narrow messaging rail, and that is exactly why SWIFT payment fraud controls now sit near the top of every cyber crime syllabus. A handful of forged messages at a single Mumbai branch cost one public sector bank roughly ₹14,000 crore, and the regulatory response rewrote how every authorised dealer branch runs its terminal. This guide covers how the fraud works, what the RBI mandates, and how examiners frame the questions.

🌐 What SWIFT Really Is — and Why It Is Targeted

SWIFT — the Society for Worldwide Interbank Financial Telecommunication — is a member-owned cooperative headquartered in Belgium that carries standardised financial messages between more than 11,000 institutions worldwide. The most examinable point is this: SWIFT is a messaging network, not a settlement system. It moves instructions; the money moves through correspondent NOSTRO and VOSTRO accounts.

Each member is identified by a Bank Identifier Code (BIC) of 8 or 11 characters. Messages fall into categories — MT 103 for a single customer credit transfer, MT 202 for a bank-to-bank transfer, MT 700 for a documentary credit, MT 760 for a guarantee or standby letter of credit, and MT 799 as a free-format message. Cross-border traffic is migrating from these legacy MT formats to richer ISO 20022 MX messages, so recognise both conventions.

That design creates the vulnerability. A correspondent abroad treats an authenticated message as an irrevocable commitment of the sending bank, so anyone who can produce one can commit the bank — no hacking of the core system required. The chapter on Global Payment Processing therefore treats correspondent banking as a risk domain of its own.

📌 Remember: SWIFT authenticates the message, not the transaction. Checking that the underlying trade, limit and margin exist is entirely the sending bank's job.

🕵️ Anatomy of the LoU Fraud: A Standalone Terminal

A Letter of Undertaking (LoU) was a form of bank guarantee used to raise buyer's credit abroad. The importer's Indian bank undertook to repay an overseas lender — usually the foreign branch of another Indian bank — which then funded the importer directly. The undertaking travelled over SWIFT, typically as an MT 760 or a free-format MT 799.

In the case that changed Indian banking, officials at one branch issued such undertakings year after year without ever passing a matching entry in the core banking system. Because the SWIFT terminal ran standalone, the books showed nothing: no limit consumed, no margin collected, no off-balance-sheet liability recorded, no NOSTRO reconciliation triggered. Each maturing undertaking was rolled over with a fresh one, so the scheme funded its own repayments until the officials retired and their successors asked for margin.

Three failures compound here, and examiners love the combination: no straight-through processing between SWIFT and the core system, no genuine maker-checker segregation because one small group held every role, and no independent log review. The behavioural side is covered in the notes on Online Transactions, and the same trusted-channel abuse drives preventing business email compromise fraud.

Following the episode, the RBI discontinued LoUs and Letters of Comfort for trade credit for imports into India in March 2018. Letters of credit and bank guarantees continue under the normal trade-credit framework.

Key Concepts — Prevention of Cyber Crime
Key Concepts — Prevention of Cyber Crime

🛡️ RBI's Mandated SWIFT–CBS Integration Controls

The RBI had circulated cautionary advisories on SWIFT operational controls before the fraud surfaced, and in February 2018 it issued a firm direction: banks were to complete straight-through integration of the SWIFT interface with the core banking system by 30 April 2018. In 2019 the regulator imposed monetary penalties on a long list of banks that missed the mark — a control deadline enforced with fines, and therefore a favourite examination fact. The circulars and press releases sit on the RBI's official website.

The control set supervisors now expect covers the whole message lifecycle:

  • Straight-through processing: every outward message must post to the core system, so exposure is recorded the moment it leaves.
  • Maker–checker–verifier: three distinct users for high-value and guarantee-type messages, with role-based access reviewed periodically.
  • Time and place restriction: an access-controlled room, defined operating hours, and escalation of any out-of-hours use.
  • Strong authentication: two-factor login, no shared credentials, hardware-token or HSM-based signing, and disabled removable media.
  • Independent log review: a daily message report checked outside the trade finance chain, plus periodic NOSTRO reconciliation.

The same supervisory expectations drive ransomware attacks on banks preparedness, and this segregation logic recurs throughout the CAIIB syllabus.

💡 Exam Tip: When a question gives you a date, it is almost certainly 30 April 2018 for SWIFT–CBS integration and March 2018 for the withdrawal of LoUs and LoCs. Keep the two apart.

🔐 SWIFT's Customer Security Programme and the CSCF

SWIFT launched its Customer Security Programme (CSP) after an earlier heist in which attackers used malware and stolen operator credentials at a central bank to push out fraudulent payment instructions worth tens of millions of dollars. The programme's core deliverable is the Customer Security Controls Framework (CSCF), a published set of mandatory and advisory controls grouped under three objectives: secure your environment, know and limit access, and detect and respond.

Every member institution must attest annually against the CSCF through SWIFT's KYC-SA application, and the attestation has to be backed by an independent assessment rather than a self-declaration alone. Counterparties can read each other's attestation status, so a weak posture is visible to the correspondents a bank depends on.

Two supporting services matter for the exam. The Relationship Management Application — and its enhanced form, RMA Plus — lets a bank decide precisely which counterparties may send it which message types, shrinking the attack surface to declared relationships. Daily Validation Reports, generated outside the bank's own infrastructure, give a second independent view of the day's traffic that an insider cannot quietly alter.

These are network-level defences layered above the bank's own perimeter. Compromise still usually begins on an ordinary endpoint, which is why the material on Channels Of Cyber Crimes starts with email, removable media and remote access rather than with the payment rail.

Process & Framework — Prevention of Cyber Crime
Process & Framework — Prevention of Cyber Crime

🚨 Detection, Reconciliation and Incident Reporting

Detection rests on reconciling three independent records: the SWIFT message log, the core banking entries, and the NOSTRO mirror statements from correspondents. Anything in one but missing from another is an incident until proved otherwise.

Red flags include messages generated outside declared business hours, a run of free-format MT 799 messages to one counterparty, repeated rollovers of the same undertaking, beneficiaries in jurisdictions unrelated to the underlying trade, and gaps or deletions in the local log. One alone may be innocent; the cluster rarely is.

Once a fraudulent message is confirmed, the clock starts. Cancellation requests such as MT 192 or MT 292 and SWIFT's stop-and-recall service must fire at once, because recovery odds collapse within hours. The RBI's cyber security framework requires unusual cyber security incidents to be reported within 2 to 6 hours; the national agency's timeline is covered in our note on CERT-In incident reporting directions. Fraud reporting follows the Master Directions on Fraud Risk Management.

Recovery after that is a legal grind where timelines decide outcomes, as in the pre-packaged insolvency resolution process on the credit side. Structured response steps are covered in Incident Management.

Message typeTypical useAuto-posted to CBS after STP?Risk if terminal is standalone
MT 103Single customer credit transfer✅Funds pushed to a mule beneficiary abroad
MT 202Bank-to-bank cover payment✅NOSTRO drained with no customer-level trail
MT 760Guarantee or standby letter of credit✅Off-balance-sheet exposure never recorded
MT 799Free-format message❌ needs a manual workflow controlUndertaking terms conveyed with no accounting trail
⚠️ Common Mistake: Writing that SWIFT "transfers funds". It does not. That single sentence costs more marks than any forgotten date.
In Practice — Prevention of Cyber Crime
In Practice — Prevention of Cyber Crime

🧠 Practice MCQs: SWIFT Payment Fraud Controls

Q1. The RBI directed banks to complete straight-through integration of SWIFT with the core banking system by which date? (a) 31 December 2017 (b) 28 February 2018 (c) 30 April 2018 (d) 30 June 2018

Answer: (c) — The February 2018 direction set 30 April 2018 as the integration deadline.

Q2. Which SWIFT message category is a free-format message that was misused to convey undertaking terms? (a) MT 103 (b) MT 202 (c) MT 700 (d) MT 799

Answer: (d) — MT 799 is free-format, so it needs a compensating manual workflow control.

Q3. In March 2018 the RBI discontinued which instruments for trade credit for imports into India? (a) Letters of credit (b) Bank guarantees (c) Letters of Undertaking and Letters of Comfort (d) Documentary collections

Answer: (c) — LoUs and LoCs were withdrawn; LCs and bank guarantees continue.

Q4. Under SWIFT's Customer Security Programme, member banks attest compliance with the CSCF through which application? (a) KYC-SA (b) RMA Plus (c) Alliance Lite2 (d) The gpi Tracker

Answer: (a) — KYC-SA is the attestation application; RMA Plus controls counterparty message permissions.

Q5. Under the RBI cyber security framework, unusual cyber security incidents must be reported to the RBI within: (a) 2 to 6 hours (b) 24 hours (c) 48 hours (d) 7 days

Answer: (a) — The framework prescribes reporting within 2 to 6 hours of detection.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Does SWIFT actually move money between banks?

No. SWIFT carries authenticated instructions between member institutions. Settlement happens separately through correspondent NOSTRO and VOSTRO accounts or a domestic clearing system.

Why did the RBI discontinue Letters of Undertaking?

LoUs created large off-balance-sheet exposures that were easy to issue over a messaging channel and hard to reconcile in the books. Withdrawing them removed the instrument that made the fraud possible.

Is SWIFT–CBS integration alone enough to stop this fraud?

No. Integration ensures every message creates a book entry, but role segregation, restricted terminal access, two-factor authentication and independent log review are still required. An insider holding all roles can defeat it.

Do Indian banks have to comply with the SWIFT CSCF?

Yes. Every SWIFT member attests annually against the Customer Security Controls Framework through the KYC-SA application, supported by an independent assessment that counterparties can view.

Take this into the exam room

Three anchors answer almost anything here: SWIFT moves messages, not money; 30 April 2018 for integration; and reconciliation across log, core system and NOSTRO as the detection engine. Browse more notes on the Prevention of Cyber Crime hub and track fresh directions through IIBF news and circular updates.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading