Annex I Scope of Work the Proposal Is for Purchase of an Electronic
Total Page:16
File Type:pdf, Size:1020Kb
Annex I Scope of Work The proposal is for purchase of an Electronic funds transfer switching services for enabling transactions such as ATM, RUPAY, UPI, IMPS, etc. through NPCI. The service of switch is proposed to be utilized in OPEX model. The 24 x 7 x 365 service is to be offered, ensuring seamless transactions for all the latest and innovative gadgets such as ATM, etc. The interface with CBS, establishing connectivity with DC, DR and NDR, testing and certification is included in the scope. The service of the switch shall be utilized for an initial period of 5 years which can be extended for further period on the basis of mutual agreement. The switch vendor should take the responsibility of providing switch updations from time to time as per the stipulations of NPCI, RBI and other related authorities/ agencies. The switch vendor shall allocate adequate manpower to ensure continuous, day to day and timely support 24 x 7 x 365. Technical Bid Form TECHNICAL REQUIREMENTS Bidders should offer the solution that is state of the art and which will be supported for a minimum period of 5 years from the date of migration. Deviations in technical specifications may be clearly indicated. Functional & Technical Specifications: 1. EFT Switch Solution 1. Solution should be compliant to all existing regulatory guidelines GOI/IBA/RBI/NPCI etc. 2. Solution should be compliant with standards and guidelines issue by major interchanges such as Rupay, VISA, Maestro Master Card etc. 3. Solution should adhere to requirements of IT Act 2000 and its amendments 4. Solution should adhere to requirements of Payment and Settlement Act 2007 and its amendments. 5. ATM Switch Solution should be EMV/PCI-DSS/PA-DSS Certified 6. Should support EMV (Chip & PIN) compliant with contact and contact-less, for acquiring ATM and POS Transactions 7. Should support Biometric Authentication as per Bank’s existing Biometric System and also Aadhaar Based Biometric authentication (when required) 8. Should be Triple DES compliant 9. Should support PKI based transactions 10. Should support message level encryption (software and hardware based) for entire or selected critical elements in the message such as PIN, Track Data etc. 11. Transaction Security - The system should support measures such as PIN Verification, 3DES Encryption, Key Management, MACing, Key encryption and Masking, Dual HSMs with automatic fallback 12. Solution should provide capabilities to enable biometric, Two Factor Authentication, Secure PIN Based and similar industry standard modes of authentication. 13. Switch must handle any Message Level Interface and should support all Industry standard message formats like ISO 8583, XML etc, for all major ATM machines and POS terminals, Core Banking Systems, Third Party Interface, etc. 14. Switch must handle any Message Level routing based on but not limited to Card Based, Account Based, Institution Code, BIN, Card Range, Message ID, Transaction Type and any other ISO/XML field value. 15. Solution should provide GUI to handle Message Level routing 16. Switch must provide connectivity to various Card & PIN as well as biometric based ATMs/POS/Kiosks with NDC/ DDC message formats as well as ISO 8583 V93 formats. 17. Solution should support Note Acceptance (Single and bunch) and Cash recycler for makes such as Diebold, NCR, Vortex, Wincor, LIPI and all major terminals available in the domestic/ global market 18. Solution should provide front end software for accessing the ATM Switch in a secure manner 19. The system should support ATM access fee based on Terminal ID, ATM Location, BIN, Country Code, etc 20. The proposed solution should have an open architecture and proven and mature platform, in production at least 21. Solution must support international networks/ interchanges including but not limited to Rupay, VISA, MASTERCARD, Maestro, Amex, Dinners, Cirrus, DISCOVER etc. 22. Solution must support national and International networks / interchanges including but not limited to NPN, SCT, NPCI, DFS etc. 23. Switch should have capability to drive all standard ATMs including DIEBOLD,NCR, Wincor, LIPI, Hitachi, Vortex, Hyusang, etc 24. Switch should be compatible with all standard Kiosks available in the market 25. Switch should have capability to drive all standard POS terminals along with Mobile POS terminals 26. Provide an integrated solution for both hardware and software including enterprise support from OEM 27. Should provide High Availability at component level at data centre and near DR site. 28. Should provide High Availability of DR. The bidder should explain its DC and DR and near DR site Architecture 29. Should ensure near zero data loss DR environment to support the Bank's existing DC-DR-Near DR Site network architecture 30. Should be up and running in DR environment in less than 30 minutes if the primary site fails in case of Active Passive. 31. Should maintain switch data for at least 10 years in an easily retrievable form 32. Should maintain online transaction data for minimum 180 days 33. Should support Domestic interchange 34. Should automatically update from external Interchange Routing tables list refresh sources (VISA, MasterCard, Rupay etc) 35. Should support instant Refresh of balances from the host to the Switch online 36. Should support any other mandatory requirements introduced by Govt. of India/regulatory authority/settlement agency such as Rupay/ Visa/ Master 2. Solution must provide interface to alternate channel applications and Payment Products like: 1. Rupay 2. ATM, BNA, Recycler, Kiosk 3. Online transactions like online shopping, bill payments 4. Mobile Banking 5. IMPS 6. Payment Gateway Interface 7. Telephone Banking and IVR Interface 8. Should support configuration of new Host parameters on the Switch without stopping services. 9. Online addition of New ATM/CR (Cash Recyclers) without bringing down the System/ Switch network 10. Solution should provide for dynamic generation of terminal session key. 11. Solution should offer remote key download functionality with requisite security features such as password/encryption etc. 12. System should automatically generate Daily transaction reports based on the scheduled time and should have the capability to export the same in different formats but not limited to CSV, xls,xlsx, xml, text, etc 3. Scalability: The system architecture should be modular, with load balancing and fault tolerance for data recovery, hardware failure and site failure with built in redundancy. The solution should also allow 100% scalability, by adding capacity to the current environment (vertical and horizontal) 4. Services through ATMs/Recyclers: 1. Cash Withdrawal 2. Cash Deposit (in case of Recycler) 3. Balance Enquiry 4. Fast Cash 5. Mini Statement 6. PIN Change 7. Fund transfer between accounts linked with the card 8. Utility Bill payment 9. Mobile Recharge 10. Linking Aadhaar Number with Bank Account 11. Cheque deposit, Cheque book request, Pin Generation, Utility bill payment etc 12. Cardless Cash Withdrawal 13. QR Code based Cash withdrawal 5. Fraud and Risk Monitoring Solution: 1. Should integrate with the NPCI FRM solution in Near Real time /Real time mode. In case of real time mode, the risk score provided by NPCI for every transaction should be validated by the switch and decision to be taken for authorization/ decline based on the parameters configured. 2. The solution should monitor all On-us transactions i.e. transaction happening in our Bank ATMs and all other terminals connected to the Switch. 3. The FRM Solution offered should be configurable, scalable and customizable and integrated with the ATM switch solution offered by the bidder, to support the Bank’s requirement on Fraud Risk Monitoring and take real time decision. 4. The solution should provide an option to configure rules based on various risk parameters, test the same in live database to analyze the impact of implementing the rule before enable the same in live. 5. The FRM solution offered by the bidder should have all the parameters available in the solutions shall be customizable to enable any new parameters as per the requirements given by the Bank in future. 6. The system should provide the risk score for each transaction based on the defined set of rules using which the switch can take a decision either to approve or decline the transaction. 7. Solution should generate real time alert (SMS & email) and should work intelligently based on the pre-set parameters and transaction patterns 6. Security control 1. Solution should support security controls over specific users or group of users 2. Data access should be controlled based on individual profiles/roles. 3. Solution should provide for configuring privileges at user level and be able to set preferences. 4. Solution should provide facility for recording centime, timeout of user from such device in Switch database. Audit logs should be maintained and made available for the bank in case of need 5. Solution should provide adequate reports for these controls and should provide report/alert on unauthorized access 7. Operational Security 1. Mode to access the system should be through passwords to ensure that only authorized users gain access 2. Solution should provide for configuration of complex passwords using algorithms and special characters. 3. Option to set life for the password in the system for forcing the user to change it once it expires 4. Password history is to be maintained and validated so that the same password is not continued by the user. 5. The user rights on the system should be definable so that a user can perform only those tasks, which are assigned to them. 6. System must provide levels of security, which will include Add, Modify, Delete, Query etc 7. It should be capable of maintaining audit logs of each activity on the system. Audit Trail of all changes made in the application, system Parameter, user role change etc. with details like user name, IP address, date and time, module name etc.