Tribhuvan University
Faculty of Management
Office of the Dean
Official Model Question Paper / Dean's Office Blueprint
Candidates are required to give their answers in their own words as far as practicable. Figures in the margin indicate full marks.
Group A
Brief Answer Questions. Attempt ALL questions. (5 × 2 = 10)
[5*2=10]- [2]
What is Customer Due Diligence (CDD) and when is Enhanced Due Diligence (EDD) required?
View model solution
CDD and EDD in Bank Operations
- Customer Due Diligence (CDD): The standard process of identifying and verifying the identity of a client, beneficial owner, and source of funds prior to onboarding.
- Enhanced Due Diligence (EDD): A rigorous verification protocol required for high-risk customers, such as Politically Exposed Persons (PEPs), high-net-worth individuals, non-resident clients, or complex corporate trusts.
- [2]
Define the role of the Financial Information Unit (FIU-Nepal) under Nepal Rastra Bank.
View model solution
Financial Information Unit (FIU-Nepal)
FIU-Nepal is the national central agency housed within Nepal Rastra Bank responsible for receiving, analyzing, and disseminating financial intelligence related to Suspicious Transactions (STR) and Currency Transactions (CTR) to combat money laundering and terrorist financing.
- [2]
Distinguish between Electronic Cheque Clearing (ECC) and connectIPS in Nepal.
View model solution
ECC vs. connectIPS
- ECC (NCHL): An automated image-based electronic clearing system that clears paper physical cheques between banks in scheduled daily settlement batches.
- connectIPS: A real-time, 24/7 retail payment switch enabling instant account-to-account electronic fund transfers via web and mobile apps without cheque issuance.
- [2]
What is a Pari-Passu charge in consortium lending operations?
View model solution
Pari-Passu Charge
A Pari-Passu charge is a legal mortgage arrangement where multiple lending banks in a loan consortium hold equal, proportional rights over the borrower’s mortgaged collateral, with no single bank having prior or superior claim over others during asset liquidation.
- [2]
Define operational risk in banking according to the Basel framework.
View model solution
Operational Risk (Basel)
Operational risk is the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events (including internal fraud, cyberattacks, software crashes, and natural disasters).
Group B
Short Answer Questions. Attempt any THREE questions. (3 × 10 = 30)
[3*10=30]- [10]
Detail the Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT) operational framework in Nepalese banks, focusing on goAML reporting, Suspicious Transaction Reporting (STR), and Currency Transaction Reporting (CTR).
View model solution
AML/CFT Operational Framework in Nepalese Banking
Under the Assets (Money) Laundering Prevention Act (2064 BS) and NRB directives, commercial banks must maintain an automated compliance framework:
Customer Onboarding (KYC/CDD) -> Transaction Monitoring -> goAML System -> FIU-Nepal Reporting1. Core Operational Components
- Know Your Customer (KYC) & Biometric Verification: Verifying client identity, permanent address, tax identification (PAN), and identifying the ultimate Beneficial Owner (UBO) behind corporate accounts.
- Screening against Sanctions Lists: Real-time screening of all customer names and wire transfers against United Nations Security Council (UNSC) sanction lists and national terrorist watchlists.
2. Regulatory Reporting via goAML
Nepalese commercial banks must submit standardized electronic reports to FIU-Nepal through the goAML web portal:
- Currency Transaction Reporting (CTR):
- Mandatory reporting of any single cash deposit, withdrawal, or exchange transaction equal to or exceeding Rs. 1,000,000 (Rs. 10 Lakhs) (or equivalent foreign currency) within 7 days of occurrence.
- Suspicious Transaction Reporting (STR):
- Mandatory submission within 3 days whenever a transaction appears inconsistent with the customer’s known business profile, lacks commercial rationale, or involves suspected proceeds of crime, regardless of monetary amount.
- Tipping-Off Prohibition: Bank staff are legally prohibited from disclosing to the customer or any third party that an STR has been reported.
- [10]
Explain the operational workflow of commercial loan administration: loan origination, credit appraisal, legal title search, mortgage deed registration (Drishtibandhak), disbursement, and post-disbursement monitoring.
View model solution
Commercial Loan Administration Workflow
Credit operations require sequential risk-control stages to guarantee legal enforceability and prevent loan diversion:
1. Origination -> 2. Appraisal -> 3. Legal / Val. -> 4. Mortgage Reg. -> 5. Disbursement -> 6. Monitoring1. Loan Origination & Application Intake
- Receiving formal loan application, business proposal, past 3 years’ audited financial statements, tax clearance certificates, company registration, and board resolution.
- CIB check: Mandatory inquiry with Credit Information Bureau Nepal to verify absence of blacklisting or cross-defaults.
2. Credit Appraisal & Financial Analysis
- Credit officers evaluate the 5 Cs of Credit (Character, Capacity, Capital, Collateral, Conditions).
- Assessing Debt Service Coverage Ratio (DSCR > 1.5x), Current Ratio (> 1.2x), and debt-to-equity leverage.
3. Legal Title Search & Engineering Valuation
- Legal Due Diligence: Bank’s legal advocate verifies the 30-year ownership history (Tiro Tiro Parikshan) at the Land Revenue Office (Malpot Karyalaya) to ensure unencumbered freehold title.
- Technical Valuation: Independent certified engineer assesses Fair Market Value (FMV) and Distress Value (DV).
4. Collateral Mortgage Registration (Drishtibandhak / Rokha)
- Formal execution of mortgage deed (Drishtibandhak) at Malpot Karyalaya, legally freezing the land ownership certificate (Lalpurja Rokha) in the bank’s name.
5. Loan Disbursement
- Checking compliance with sanction terms. Funds are disbursed directly to suppliers or creditors (vendor payments) rather than credited as unrestricted cash to the borrower’s account.
6. Post-Disbursement End-Use Monitoring
- Quarterly physical stock verification (hypothecated inventory and receivables audits), tax returns review, and site inspection to verify funds were not diverted to speculative real estate or equities.
- [10]
Discuss bank clearing and payment settlement operations in Nepal: RTGS for high-value wholesale transactions, connectIPS for retail instant settlements, and National Payment Switch (NPS).
View model solution
Clearing and Payment Settlement Operations in Nepal
Nepal’s national payment architecture is managed jointly by Nepal Rastra Bank and Nepal Clearing House Limited (NCHL):
1. Payment Settlement Architecture
Settlement Channel Operating Entity Transaction Ticket Size Processing Speed Use Cases RTGS Nepal Rastra Bank High-value (Above Rs. 200,000; up to billions). Real-time, gross order-by-order settlement. Interbank call money, corporate supplier settlements, treasury bond auctions. connectIPS NCHL Retail / Mid-value (Up to Rs. 2,000,000 per transaction). Instant real-time account-to-account. Government tax payments, utility bills, capital market share application IPOs. NCHL-ECC NCHL Standard cheques (Paper image clearing). Scheduled batch clearing (Express & Regular). Traditional paper cheque clearance between commercial banks. National Payment Switch (NPS / NepalPay) NCHL / NRB Micro & retail payments via QR & cards. Instant clearing with central routing. Interoperable merchant QR codes (Fonepay, NepalPay) and domestic card switch. 2. Operational Risk Controls
- Liquidity Management: Banks maintain central bank settlement accounts with NRB to fund intraday settlement obligations, using the Standing Liquidity Facility (SLF) for overnight settlement shortfalls.
- Cybersecurity & Encryption: Secure financial messaging via dedicated private fiber networks using PKI encryption, digital certificates, and ISO 20022 messaging standards.
- [10]
Analyze internal control systems in branch operations: Dual Control, the Maker-Checker authorization principle, Segregation of Duties, and Surprise Vault Inspections.
View model solution
Internal Control Systems in Bank Branch Operations
Branch operations handle physical cash and transactional authorization, requiring strict preventative control systems:
+----------------------------------------------------------------------+ | BRANCH INTERNAL CONTROL MECHANISMS | +-------------------+--------------------------------------------------+ | 1. Dual Control | Two different keyholders required to access vault| | 2. Maker-Checker | One staff enters data, second officer verifies | | 3. Segregation | Accounting clerks cannot disburse cash | | 4. Surprise Audit | Unannounced vault cash counts and security audits| +-------------------+--------------------------------------------------+1. Dual Control
- Rule: High-security physical assets (vault doors, ATM combination dials, strongrooms, locker master keys) require two authorized officers holding distinct keys or combination codes to open.
- Purpose: Eliminates single-person access, preventing unilateral theft or coercion.
2. The Maker-Checker Principle
- Rule: In Core Banking Systems (CBS), every financial transaction above a nominal threshold (e.g., transactions > Rs. 50,000) must be initiated by a Maker (teller/assistant) and independently reviewed and authorized by a Checker (supervisor/manager).
- Purpose: Catches input errors, prevents unauthorized overdrafts, and stops rogue employees from crediting personal accounts.
3. Segregation of Duties (SoD)
- The employee responsible for custody of assets (cashier) cannot maintain accounting ledgers or reconcile bank Nostro accounts. Credit appraisal officers cannot disburse loan funds or release mortgaged collateral deeds.
4. Mandatory Surprise Vault Counts
- Branch managers and internal inspection teams conduct unannounced physical cash counts against CBS general ledger balances at least twice a month, recording physical counts in stamped vault register logs.
Group C
Comprehensive Answer / Case Analysis Question. Attempt ALL questions. (1 × 20 = 20)
[1*20=20]- [20]
Case Analysis: Lumbini Bank of Commerce
Lumbini Bank of Commerce is a mid-sized commercial bank in Nepal. An internal audit investigation at its Butwal regional branch revealed a major fraud: an Assistant Branch Manager, possessing elevated system supervisor credentials, colluded with an external building contractor to issue unauthorized Bank Guarantees (BGs) totaling Rs. 80 Million and execute unverified RTGS wire transfers worth Rs. 45 Million. The investigation disclosed:
- The manager bypassed the mandatory Maker-Checker authorization protocol by using the shared login credentials of a junior teller on leave.
- The Bank Guarantees were issued on authentic security paper stolen from the branch stationery vault, which had not been physically audited in over six months.
- The transactions were omitted from the branch daily end-of-day (EOD) batch balancing reports through unauthorized core banking ledger adjustments.
Questions: (a) Diagnose the systemic internal control failures, credential mismanagement, and branch authorization breakdowns that enabled this fraud. (7 marks) (b) Design an operational risk control matrix and secure custody protocol for high-security stationery (Bank Guarantees, Chequebooks, Letters of Credit) and Core Banking System (CBS) access hierarchy. (7 marks) (c) Detail the mandatory legal and regulatory reporting steps the bank must immediately execute under Nepal Rastra Bank Directives, FIU guidelines, and the Banking Offence and Punishment Act (2064 BS). (6 marks)
View model solution
Case Analysis: Lumbini Bank of Commerce
(a) Systemic Internal Control Failures & Authorization Breakdowns (7 Marks)
+------------------------------------------------------------------------------------------------+ | LUMBINI BANK OF COMMERCE: CONTROL FAILURE AUDIT | +-------------------+------------------------------------+---------------------------------------+ | Control Dimension | Failure Identified | Operational Breakdown Impact | +-------------------+------------------------------------+---------------------------------------+ | 1. Credential & | Shared password usage; using | Complete breakdown of Maker-Checker | | Access Control | credentials of staff on leave | principle; non-repudiation destroyed. | +-------------------+------------------------------------+---------------------------------------+ | 2. Stationery | Unaudited BG security paper stock | Fraudulent guarantees issued on | | Custody | for 6 months without Dual Control | genuine paper creating bank liability.| +-------------------+------------------------------------+---------------------------------------+ | 3. High-Value | Single-manager override of Rs. 45M | Bypassed regional/head-office limits | | Wire Transfers | RTGS wire transfers without HO sign| for high-value external transfers. | +-------------------+------------------------------------+---------------------------------------+ | 4. Reconcilement | Manipulation of End-of-Day (EOD) | Off-balance-sheet guarantees went | | & General Ldg. | batch balancing reports | unrecorded in CBS general ledger. | +-------------------+------------------------------------+---------------------------------------+- Root Cause: A toxic culture of informal password sharing paired with complete failure of branch dual custody controls over critical instruments.
(b) Operational Risk Control Matrix & Custody Protocol (7 Marks)
To prevent recurrence, the bank must institute an enterprise risk control matrix:
- Biometric Multi-Factor Authentication (MFA) in Core Banking:
- Eliminate alphanumeric password-only logins for supervisory approvals. Mandate biometric fingerprint or hardware FIDO security key authentication for all transactions exceeding Rs. 100,000.
- Automated System Lockout: System credentials of any employee on approved annual or sick leave must be automatically deactivated by HR software.
- High-Security Stationery Custody Protocol:
- Bank Guarantee and Letter of Credit paper sheets must be treated as physical cash—kept inside a dual-locked stationery safe requiring keys from both the Operations Manager and Branch Manager.
- Mandatory physical stock counts logged weekly in a numbered stationery register.
- Centralized Trade Finance Verification Desk (Head Office Authorization):
- Branches are stripped of autonomous authority to issue Bank Guarantees above Rs. 5 Million. All BG applications must be uploaded to Head Office Trade Operations, where an independent verification team verifies collateral before issuing digital signatures.
- Public Online BG Verification Portal:
- Implement QR-code verification on every issued Bank Guarantee linking to a public portal (
bank.com/verify-bg), enabling government procurement agencies to verify authenticity independently.
- Implement QR-code verification on every issued Bank Guarantee linking to a public portal (
(c) Legal, Statutory, and Regulatory Reporting Mandates (6 Marks)
Under Nepalese banking laws, Lumbini Bank of Commerce must execute immediate legal steps:
- Immediate Notification to Nepal Rastra Bank:
- Submit a formal Fraud Event Report to the Bank Supervision Department of NRB within 24 hours under Unified Directives, detailing the estimated loss, implicated staff, and remedial measures.
- Filing with the Financial Information Unit (FIU-Nepal):
- Submit an immediate Suspicious Transaction Report (STR) on goAML identifying the fraudulent beneficiary accounts and contractor entities.
- Filing First Information Report (FIR) with Nepal Police Central Investigation Bureau (CIB):
- Lodge a criminal complaint under the Banking Offence and Punishment Act (2064 BS).
- Request immediate freezing of all bank accounts, movable assets, and real estate owned by the colluding manager, contractor, and immediate family members.
- Public Legal Notice & Guarantees Disclaimer:
- Publish immediate national public legal notices declaring the specific stolen BG certificate numbers fraudulent, null, and void.
- Internal Disciplinary Action & Suspension:
- Immediately suspend the implicated manager and junior teller, initiate a forensic internal audit, and lodge insurance claims under the bank’s Bankers Blanket Bond (BBB) insurance policy.