1.9 Customer Access Group

This topic describes the information about the Customer Access Group configurations.

Customer access group functionality is part of privacy by design requirements. The customer access group will restrict unauthorized access by the users to details of customers within specific customer access groups such as High Net Worth, Sensitive etc.

Customer Access Group Configuration:

Step 1 – Create Customer Access Group (Core Maintenance)

Step 2 – Map Customer Access Group/s to User/s (SMS User Maintenance)

During Party Onboarding and Amendment process, based on the configuration, customer access group can be assigned updated by users.

Customer Access Group is applicable for all customer types – Retail, Small and Medium Business (SMB), Small and Medium Enterprise (SME), Corporate, Financial Institutions (FI).

Example of Customer Access Group:

  • Access Groups: AccessGroup_1, AccessGroup_2,
  • User: USER1, USER2
  • Customers: CUST11, CUST12, CUST13, CUST21, CUST22, CUST23, CUST31, CUST32 & CUST33
Mapping of User and Access Group Restriction and Customer belongs to Access Group as follows:

Table 1-10 Access Group Mapping

USER1 USER2 USER3 & USER4
AccessGroup_1 AccessGroup_2

AccessGroup_3

AccessGroup_3
AccessGroup_1 AccessGroup_2 AccessGroup_3
CUST11

CUST12

CUST13

CUST21

CUST22

CUST23

CUST31

CUST32

CUST33

  • USER1 will be able to access customer belonging to AccessGroup_1 only. User will not be able to query CUST21, since CUST21 belongs to AccessGroup_2 which is not allowed for user USER1.
  • USER2 will be able to access customer belonging to AccessGroup_2 and AccessGroup_3. User will not be able to access CUST12 belongs to AccessGroup_1 which is not allowed for this user.
  • USER3 & USER4 both will be able to access customer belonging to AccessGroup_3 only. User will not be able to access Cust11 or Cust21, belongs to AccessGroup_1 & AccessGroup_2 which is not allowed for this user.

Note:

The customer access group is applicable for stakeholders also. A user will not be able to access details of a stakeholder linked to a party, if user does not have access to customer access group of the linked stakeholder.

For more details, refer to Oracle Banking Common Core User Guide and Oracle Banking Security Management System User Guide.