26. UPI Architecture
Learn UPI Architecture as part of the Domain Knowledge learning path for software engineers and architects.
India has transformed digital payments through one of the world's most successful real-time payment systems—Unified Payments Interface (UPI).
Today, millions of individuals and businesses use UPI every day to transfer money instantly using mobile applications without remembering lengthy bank account numbers or IFSC codes.
Whether you're paying a friend, purchasing groceries, booking movie tickets, or paying utility bills, UPI enables secure, real-time bank-to-bank transfers in just a few seconds.
This chapter introduces the fundamentals of UPI, its architecture, ecosystem, participants, and how different organizations work together to provide a seamless payment experience.
Learning Objectives
By the end of this chapter, you'll understand:
- What UPI is
- History of UPI
- Why UPI was introduced
- Evolution from IMPS
- UPI ecosystem
- Key participants
- Virtual Payment Address (VPA)
- UPI ID
- Linked bank accounts
- High-level UPI architecture
- Real-world payment flow
- Advantages
- Limitations
- Business interview questions
What is UPI?
Unified Payments Interface (UPI) is a real-time payment system that enables instant bank-to-bank money transfers using a mobile device.
UPI allows users to:
- Send money
- Receive money
- Pay merchants
- Request money
- Pay bills
- Link multiple bank accounts
- Make payments 24×7
Unlike traditional banking methods, users typically do not need to enter bank account numbers for every transaction.
Instead, they use a Virtual Payment Address (VPA) such as:
venu@okbank
Who Developed UPI?
UPI was developed by the National Payments Corporation of India (NPCI).
NPCI is responsible for:
- Defining UPI standards
- Operating the UPI switching infrastructure
- Connecting participating banks
- Ensuring interoperability
- Managing transaction routing
NPCI enables banks and payment applications to work together through a common payment platform.
Why Was UPI Introduced?
Before UPI, digital payments often required:
- Bank account numbers
- IFSC codes
- Multiple banking applications
- Separate payment systems
- Complex transfer processes
Customers wanted:
- Faster payments
- Simpler user experience
- Mobile-first banking
- Instant fund transfers
- Secure authentication
UPI was introduced to address these challenges through a standardized, interoperable payment platform.
Evolution of Digital Payments
flowchart LR
Cash
Cash --> Cards
Cards --> NEFT
NEFT --> IMPS
IMPS --> UPI
UPI builds on earlier electronic payment systems while providing a simpler and more unified experience.
IMPS vs UPI
UPI was built on top of the Immediate Payment Service (IMPS) infrastructure while introducing new capabilities.
| IMPS | UPI |
|---|---|
| Account Number + IFSC | Virtual Payment Address (VPA) |
| Primarily bank channels | Banks and approved third-party apps |
| Immediate transfers | Immediate transfers |
| Basic user experience | Mobile-first experience |
| Limited interoperability features | Unified interoperable ecosystem |
Key Features of UPI
UPI offers several capabilities that distinguish it from traditional payment systems.
- Real-time payments
- 24×7 availability
- Bank-to-bank transfers
- Mobile-first experience
- Multiple linked bank accounts
- QR code payments
- Merchant payments
- Person-to-person transfers
- Request money functionality
- Interoperability across participating banks
UPI Ecosystem
UPI is not operated by a single bank.
Instead, it connects multiple organizations that work together to complete each payment.
flowchart LR
Customer
Customer --> UPIApp
UPIApp --> NPCI
NPCI --> Bank
Bank --> Merchant
Each participant performs a specific role during a transaction.
UPI Participants
The major participants include:
- Customer (Payer)
- Merchant (Payee)
- UPI Application
- PSP Bank
- Issuer Bank
- Beneficiary Bank
- NPCI
Customer (Payer)
The payer initiates the payment.
Responsibilities:
- Select recipient
- Enter payment amount
- Authenticate using UPI PIN
- Approve the transaction
Merchant (Payee)
The merchant receives payment.
Examples include:
- Grocery stores
- Restaurants
- E-commerce websites
- Utility providers
- Online service platforms
Merchants can accept payments using:
- QR codes
- UPI ID
- Payment links
- Collect requests
UPI Application
Customers interact with UPI through mobile applications.
Examples include:
- BHIM
- Google Pay
- PhonePe
- Paytm
- Bank mobile applications
These applications provide the user interface but do not hold customer funds.
PSP Bank
A Payment Service Provider (PSP) Bank enables UPI services for customers through UPI applications.
Responsibilities include:
- Register customers
- Link bank accounts
- Authenticate users
- Forward payment requests
- Receive transaction responses
Issuer Bank
The issuer bank is the bank where the payer maintains an account.
Responsibilities:
- Verify account status
- Authenticate UPI PIN
- Check available balance
- Authorize debit
- Send authorization response
Beneficiary Bank
The beneficiary bank maintains the merchant's or recipient's account.
Responsibilities:
- Validate destination account
- Accept incoming credit
- Credit beneficiary account
- Confirm successful transaction
NPCI
NPCI acts as the central switching platform.
Responsibilities include:
- Route payment requests
- Connect participating banks
- Validate routing information
- Exchange payment messages
- Coordinate transaction processing
NPCI does not hold customer money during normal UPI transactions; it facilitates communication between participating institutions.
Participant Interaction
flowchart LR
Customer
Customer --> PSPBank
PSPBank --> NPCI
NPCI --> IssuerBank
NPCI --> BeneficiaryBank
BeneficiaryBank --> Merchant
What is a Virtual Payment Address (VPA)?
A Virtual Payment Address (VPA) is a unique identifier used to send and receive money.
Example:
venu@okaxis
or
alex@oksbi
A VPA eliminates the need to repeatedly share:
- Bank account number
- IFSC code
- Branch details
Benefits of VPA
Advantages include:
- Easy to remember
- Improved privacy
- Faster payments
- Reduced typing errors
- Simplified payment experience
What is a UPI ID?
A UPI ID is the customer's payment identity within the UPI ecosystem.
Examples:
rahul@oksbi
john@ybl
anita@okicici
Every UPI transaction is routed using the registered UPI ID or another supported payment identifier.
Linked Bank Accounts
Users can link multiple bank accounts to one UPI application.
Example
Google Pay
↓
Savings Account
↓
Salary Account
↓
Joint Account
Users can choose which linked account should be used as the default payment account.
High-Level UPI Architecture
flowchart LR
Customer
Customer --> UPIApp
UPIApp --> PSPBank
PSPBank --> NPCI
NPCI --> IssuerBank
NPCI --> BeneficiaryBank
BeneficiaryBank --> Merchant
High-Level Payment Flow
A simplified UPI payment follows these steps:
- Customer opens a UPI application.
- Customer selects the recipient.
- Customer enters the amount.
- Customer authenticates using the UPI PIN.
- The PSP Bank forwards the request to NPCI.
- NPCI routes the request to the appropriate banks.
- The issuer bank verifies the transaction.
- The beneficiary bank credits the recipient.
- Both parties receive confirmation.
UPI Use Cases
UPI supports many everyday payment scenarios.
Examples include:
- Person-to-person transfers
- Merchant payments
- Utility bill payments
- Mobile recharge
- Subscription payments
- Educational fee payments
- Government service payments
- E-commerce purchases
Advantages of UPI
UPI provides several benefits.
For customers:
- Instant payments
- 24×7 availability
- Easy-to-use interface
- Multiple linked bank accounts
- Secure authentication
For merchants:
- Faster payment confirmation
- Lower cash handling
- Digital transaction records
- Broad customer adoption
For banks:
- Standardized payment infrastructure
- Interoperable ecosystem
- Efficient digital payment processing
Limitations
Although UPI is highly successful, it has operational considerations.
Examples include:
- Internet connectivity required
- Transaction limits
- Temporary bank downtime
- Mobile device dependency
- UPI service outages during maintenance
Payment success depends on all participating systems being available.
UPI Transaction Flow
A UPI payment usually completes within a few seconds, but behind every successful transaction is a coordinated workflow involving the customer, UPI application, PSP Bank, NPCI, issuing bank, and beneficiary bank.
Unlike traditional bank transfers that often require account numbers and IFSC codes, UPI uses a Virtual Payment Address (VPA) and real-time message exchange to provide a simple and seamless payment experience.
This chapter explains how a UPI transaction flows from initiation to completion.
Learning Objectives
By the end of this chapter, you'll understand:
- End-to-end UPI transaction flow
- Payment initiation
- Customer authentication
- UPI PIN validation
- NPCI switching
- Issuer bank authorization
- Beneficiary bank validation
- Success and failure responses
- Transaction states
- Push and Pull payments
- QR Code payments
- Dynamic QR
- Person-to-Person (P2P)
- Person-to-Merchant (P2M)
- Business scenarios
- Interview questions
End-to-End UPI Transaction Flow
flowchart LR
Customer
Customer --> UPIApp
UPIApp --> PSPBank
PSPBank --> NPCI
NPCI --> IssuerBank
NPCI --> BeneficiaryBank
BeneficiaryBank --> Merchant
Transaction Lifecycle
flowchart LR
Initiation
Initiation --> Authentication
Authentication --> Authorization
Authorization --> Debit
Debit --> Credit
Credit --> Confirmation
Every successful UPI payment follows these major stages.
Step 1 – Payment Initiation
The transaction begins when the customer decides to make a payment.
The customer may:
- Enter a UPI ID
- Scan a QR Code
- Select a saved contact
- Use a mobile number (if supported by the application)
- Accept a collect request
Example
Coffee Purchase
₹250
Merchant
Coffee Shop
Payment Initiation Flow
flowchart LR
Customer
Customer --> UPIApp
UPIApp --> PaymentRequest
Step 2 – Customer Authentication
Before money can move, the customer must authenticate.
Authentication ensures the transaction is being initiated by the legitimate account holder.
Common authentication methods include:
- Device verification
- Mobile number verification
- UPI PIN
Authentication protects against unauthorized payments.
Step 3 – UPI PIN Validation
The customer enters the UPI PIN.
The PIN is securely verified by the issuing bank.
flowchart LR
Customer
Customer --> UPIPIN
UPIPIN --> IssuerBank
If the PIN is incorrect:
- Transaction fails
- No money is debited
- Customer receives an error message
Step 4 – PSP Bank Receives Request
The Payment Service Provider (PSP) Bank receives the payment request.
Responsibilities include:
- Validate request format
- Verify customer registration
- Forward request
- Receive response
- Notify customer
The PSP Bank acts as the communication layer between the application and NPCI.
Step 5 – NPCI Switching
NPCI acts as the central switching platform.
Responsibilities:
- Identify participating banks
- Route requests
- Exchange payment messages
- Coordinate transaction processing
flowchart LR
PSPBank
PSPBank --> NPCI
NPCI --> IssuerBank
NPCI --> BeneficiaryBank
NPCI does not authorize the transaction itself; it routes messages between participating banks.
Step 6 – Issuer Bank Authorization
The issuer bank performs several checks before approving the payment.
Typical validations include:
- Account status
- Available balance
- UPI PIN validation
- Transaction limits
- Risk controls
- Fraud checks
Possible outcomes:
- Approved
- Declined
Authorization Decision
flowchart TD
Request
Request --> BalanceCheck
BalanceCheck --> RiskCheck
RiskCheck --> Decision
Decision --> Approved
Decision --> Declined
Step 7 – Debit Customer Account
If approved:
- Customer account is debited.
- Transaction reference is generated.
- Authorization response is created.
Example
Account Balance Before
₹12,000
Payment
₹250
Remaining Balance
₹11,750
Step 8 – Beneficiary Bank Validation
NPCI forwards the approved payment message to the beneficiary bank.
The beneficiary bank verifies:
- Beneficiary account
- Merchant status
- Account availability
If validation succeeds:
- Account is credited.
- Success response is generated.
Credit Flow
flowchart LR
NPCI
NPCI --> BeneficiaryBank
BeneficiaryBank --> Merchant
Step 9 – Confirmation
After the beneficiary bank confirms the credit:
- Merchant receives payment confirmation.
- Customer receives payment confirmation.
- Transaction is marked successful.
flowchart LR
Bank
Bank --> Merchant
Bank --> Customer
Transaction States
Every UPI transaction passes through one or more states.
| State | Description |
|---|---|
| Initiated | Customer started payment |
| Processing | Banks are validating transaction |
| Authorized | Issuer approved debit |
| Debited | Customer account debited |
| Credited | Beneficiary account credited |
| Successful | Transaction completed |
| Failed | Transaction not completed |
| Reversed | Debit returned to customer |
Common Failure Reasons
Transactions may fail because of:
- Incorrect UPI PIN
- Insufficient balance
- Bank server unavailable
- NPCI timeout
- Transaction limit exceeded
- Invalid UPI ID
- Beneficiary bank unavailable
- Network connectivity issue
Failure Handling
flowchart LR
Request
Request --> Validation
Validation --> Success
Validation --> Failure
Failure --> CustomerNotification
Request and Response Messages
UPI transactions involve multiple message exchanges.
Typical request information:
- Transaction ID
- UPI ID
- Amount
- PSP Identifier
- Bank Identifier
- Timestamp
Typical response information:
- Transaction Status
- Reference Number
- Approval Result
- Error Code (if applicable)
Push Payments
A Push Payment is initiated by the payer.
Example:
Customer
↓
Send Money
↓
Merchant
Examples:
- Paying a restaurant bill
- Sending money to a friend
- Paying rent
The customer actively pushes money to another account.
Pull Payments (Collect Request)
A Pull Payment begins when the payee requests money.
Example
Merchant
↓
Collect Request
↓
Customer
↓
Approve
↓
Payment
Common use cases:
- Utility bills
- Subscription payments
- Invoice collection
- Business payments
---
## Push vs Pull Payments
| Push Payment | Pull Payment |
|---------------|--------------|
| Initiated by payer | Initiated by payee |
| Customer sends money | Customer approves request |
| Immediate transfer | Requires customer approval |
| Common for retail payments | Common for bill collection |
---
## Person-to-Person (P2P)
P2P transactions occur between two individuals.
Examples:
- Friends
- Family
- Shared expenses
- Personal transfers
Flow
```mermaid
flowchart LR
PersonA
PersonA --> NPCI
NPCI --> PersonB
Person-to-Merchant (P2M)
P2M transactions occur when customers pay merchants.
Examples:
- Grocery stores
- Restaurants
- Fuel stations
- Online shopping
- Utility payments
Flow
flowchart LR
Customer
Customer --> Merchant
Merchant --> Bank
QR Code Payments
UPI supports QR Code payments.
The customer:
- Opens a UPI application.
- Scans the QR Code.
- Confirms the merchant.
- Enters the amount (for static QR).
- Enters the UPI PIN.
- Completes payment.
Benefits:
- Faster checkout
- Reduced typing errors
- Contactless payments
- Easy merchant onboarding
Static QR vs Dynamic QR
| Static QR | Dynamic QR |
|---|---|
| Merchant information only | Merchant information plus transaction details |
| Customer enters amount | Amount is pre-filled |
| Simple to deploy | Better for invoiced payments |
| Common in small businesses | Common in organized retail and e-commerce |
Merchant Payment Flow
flowchart LR
Customer
Customer --> QRCode
QRCode --> PSPBank
PSPBank --> NPCI
NPCI --> MerchantBank
MerchantBank --> Merchant
Transaction Reference Number
Every successful UPI transaction receives a unique reference number.
It helps:
- Track payments
- Investigate issues
- Resolve disputes
- Perform reconciliation
- Support customer service
Real-World Business Scenario
A customer purchases groceries worth ₹1,850 using a UPI application.
- The customer scans the merchant's dynamic QR code.
- The amount is automatically displayed.
- The customer verifies the merchant name.
- The customer enters the UPI PIN.
- The PSP Bank forwards the request to NPCI.
- NPCI routes the request to the issuing bank.
- The issuing bank verifies the account balance and authenticates the UPI PIN.
- The customer's account is debited.
- NPCI forwards the transaction to the beneficiary bank.
- The beneficiary bank credits the merchant's account.
- Both the customer and merchant receive instant confirmation.
The complete process is typically completed within a few seconds.
Key Takeaways
- UPI enables real-time bank-to-bank payments.
- Every transaction begins with payment initiation and customer authentication.
- The UPI PIN is validated by the issuing bank.
- NPCI serves as the central transaction switch connecting participating banks.
- The issuer bank authorizes the debit, while the beneficiary bank credits the recipient.
- UPI supports Push Payments, Pull Payments, P2P, P2M, and QR Code payments.
- Every successful transaction receives a unique reference number for tracking and reconciliation.
Business Interview Questions
- What are the major steps in a UPI transaction?
- What is the role of NPCI during transaction processing?
- How is the UPI PIN validated?
- What responsibilities does a PSP Bank perform?
- What checks are performed by the issuer bank?
- What is the difference between Push and Pull payments?
- What is the difference between P2P and P2M transactions?
- How do static and dynamic QR codes differ?
- What are the common reasons for UPI transaction failures?
- Why is the transaction reference number important?
Settlement & Reconciliation
A UPI payment appears to complete instantly from the customer's perspective, but the financial processing continues after the transaction is successful.
Behind every successful payment, banks, NPCI, and the Reserve Bank of India (RBI) work together to settle funds between participating banks and ensure that every transaction is accurately reconciled.
Settlement guarantees that money moves between banks, while reconciliation verifies that every financial record matches across all systems.
This chapter explains how settlement and reconciliation work in the UPI ecosystem.
Learning Objectives
By the end of this chapter, you'll understand:
- UPI settlement overview
- Role of NPCI
- Role of RBI
- Interbank settlement
- Merchant settlement
- Net settlement
- Settlement cycles
- Transaction reconciliation
- Failed transaction handling
- Reversals
- Refunds
- Daily reconciliation
- Settlement reports
- Operational KPIs
- Real-world business scenarios
- Interview questions
What is Settlement?
Settlement is the process of transferring money between participating banks after a payment has been successfully authorized.
During settlement:
- Customer funds are finalized
- Banks exchange financial obligations
- Merchant banks receive settlement funds
- Financial records are updated
Settlement completes the financial movement of money.
Settlement in UPI
Unlike card payments that may settle on T+1 or T+2, UPI provides an instant payment experience while participating banks periodically settle their net obligations through NPCI and RBI.
Customers receive immediate confirmation, while the interbank settlement process occurs in the background according to settlement schedules.
Settlement Lifecycle
flowchart LR
Payment
Payment --> Authorization
Authorization --> Success
Success --> Settlement
Settlement --> Reconciliation
Reconciliation --> Reporting
UPI Settlement Participants
The settlement process involves several organizations.
- Customer Bank
- Beneficiary Bank
- PSP Bank
- NPCI
- RBI
Each participant has a specific financial responsibility.
Role of NPCI
NPCI acts as the central switching and settlement coordinator.
Responsibilities include:
- Collect transaction records
- Calculate net obligations
- Prepare settlement files
- Send settlement instructions
- Generate settlement reports
- Coordinate participating banks
NPCI facilitates settlement but does not permanently hold customer funds.
Role of RBI
The Reserve Bank of India (RBI) performs the final interbank settlement.
Responsibilities include:
- Maintain settlement accounts
- Transfer funds between participating banks
- Complete net settlement
- Ensure settlement finality
- Maintain payment system stability
RBI acts as the settlement authority for participating banks.
Settlement Participants
flowchart LR
IssuerBank
IssuerBank --> NPCI
NPCI --> RBI
RBI --> BeneficiaryBank
Interbank Settlement
During the day, thousands of transactions occur between different banks.
Example
| Customer Bank | Merchant Bank | Amount |
|---|---|---|
| Bank A | Bank B | $120 |
| Bank A | Bank C | $80 |
| Bank B | Bank A | $60 |
| Bank C | Bank A | $40 |
Instead of settling each payment individually, banks calculate their net obligations.
Net Settlement
Net settlement combines all incoming and outgoing obligations into a single settlement amount.
Example
Bank A
Outgoing
$200
Incoming
$100
Net Settlement
Pay $100
This significantly reduces the number of financial transfers between banks.
Net Settlement Flow
flowchart LR
Transactions
Transactions --> NetCalculation
NetCalculation --> RBI
RBI --> Banks
Merchant Settlement
Customers receive immediate confirmation, but merchants receive funds through their acquiring or beneficiary bank according to the agreed settlement process.
Merchant settlement involves:
- Successful payment
- Bank credit
- Settlement reporting
- Merchant account update
Merchant Settlement Flow
flowchart LR
Customer
Customer --> Merchant
Merchant --> BeneficiaryBank
BeneficiaryBank --> Settlement
Settlement Reports
NPCI and participating banks generate reports for operational and financial teams.
Common reports include:
- Settlement Report
- Net Position Report
- Bank Settlement Report
- Merchant Settlement Report
- Exception Report
- Reconciliation Report
These reports support finance, operations, and audit activities.
Transaction Reconciliation
Settlement alone is not sufficient.
Banks must verify that every transaction was processed correctly.
Reconciliation compares:
- Transaction records
- Settlement reports
- Bank ledgers
- Merchant records
The objective is to ensure financial accuracy.
Reconciliation Lifecycle
flowchart LR
Transactions
Transactions --> Matching
Matching --> Exceptions
Exceptions --> Resolution
Resolution --> Closure
Matching Process
A reconciliation system typically compares:
- Transaction ID
- UPI Reference Number
- Amount
- Bank
- Merchant
- Settlement Date
- Transaction Status
If all required values match, the transaction is considered reconciled.
Successful Reconciliation Example
| Transaction ID | Merchant | Amount | Status |
|---|---|---|---|
| UPI501 | Grocery Store | $18 | Matched |
| UPI502 | Fuel Station | $42 | Matched |
| UPI503 | Pharmacy | $25 | Matched |
All records are successfully matched across participating systems.
Settlement Exceptions
Sometimes settlement does not complete successfully.
Common reasons include:
- Bank downtime
- Invalid settlement file
- Processing delay
- Network issue
- System maintenance
- Settlement timeout
Operations teams investigate every exception.
Failed Transaction Handling
A UPI payment may fail at different stages.
Examples:
- Authentication failure
- Insufficient balance
- Bank unavailable
- Beneficiary unavailable
- NPCI timeout
- Network interruption
If the customer's account has not been debited, no further action is required.
If the account has already been debited, the transaction may require reversal.
Failed Transaction Flow
flowchart LR
Payment
Payment --> Failure
Failure --> Investigation
Investigation --> Reversal
Reversal --> Customer
Reversals
A reversal returns money to the customer's account when a completed debit cannot be finalized.
Common situations include:
- Merchant not credited
- Beneficiary bank unavailable
- Processing interruption
- Settlement failure
The objective is to restore the customer's balance accurately.
Reversal Example
Customer Account
Before Payment
$500
Payment
$75
Processing Failure
Reversal
$75
Final Balance
$500
Refunds
Refunds differ from reversals.
A reversal corrects a failed payment.
A refund returns money after a successful payment has already been completed.
Examples:
- Product return
- Order cancellation
- Duplicate purchase
- Merchant goodwill
Refund vs Reversal
| Refund | Reversal |
|---|---|
| After successful payment | During failed processing |
| Merchant initiates | System or bank initiates |
| Business decision | Operational correction |
| Customer receives money back | Original debit is canceled |
Daily Reconciliation
Banks perform reconciliation every business day.
Typical workflow:
- Download transaction reports.
- Compare settlement records.
- Compare bank ledgers.
- Identify mismatches.
- Investigate exceptions.
- Resolve differences.
- Generate reconciliation reports.
Daily reconciliation ensures financial accuracy.
Daily Reconciliation Flow
flowchart LR
Reports
Reports --> Matching
Matching --> Exceptions
Exceptions --> Investigation
Investigation --> Reporting
Operational Dashboards
Payment operations teams monitor dashboards throughout the day.
Common metrics include:
- Total UPI transactions
- Successful payments
- Failed payments
- Settlement status
- Open exceptions
- Reversals
- Refunds
- Processing delays
Dashboards help operations teams respond quickly to issues.
Operational KPIs
| KPI | Description |
|---|---|
| Settlement Success Rate | Percentage of successfully settled transactions |
| Reconciliation Match Rate | Percentage of matched records |
| Failed Transaction Rate | Percentage of failed transactions |
| Average Settlement Time | Time required for settlement processing |
| Average Resolution Time | Time to resolve exceptions |
| Reversal Rate | Percentage of reversed transactions |
| Refund Processing Time | Average refund completion time |
| Exception Rate | Transactions requiring investigation |
Best Practices
Successful UPI operations should:
- Perform reconciliation daily
- Monitor settlement continuously
- Automate exception detection
- Maintain audit logs
- Resolve failures quickly
- Monitor settlement KPIs
- Validate settlement reports
- Investigate unmatched transactions promptly
Real-World Business Scenario
An online grocery platform processes 350,000 UPI payments during a weekend sale.
At the end of the settlement cycle:
- NPCI collects transaction records from participating banks.
- Net obligations for each bank are calculated.
- RBI completes the interbank settlement.
- Beneficiary banks update merchant accounts.
- Finance teams receive settlement and reconciliation reports.
- Automated systems match all transaction records.
- 349,920 transactions reconcile successfully.
- 80 transactions are flagged because of temporary bank downtime and delayed settlement confirmations.
- Operations teams investigate the exceptions, process necessary reversals where appropriate, and complete the final reconciliation.
This process ensures that banks, merchants, and customers maintain accurate financial records.
Key Takeaways
- Settlement transfers funds between participating banks after successful UPI payments.
- NPCI coordinates settlement by calculating net obligations and preparing settlement instructions.
- RBI performs the final interbank settlement between banks.
- Net settlement reduces the number of financial transfers required.
- Reconciliation verifies that transaction, settlement, and bank records match.
- Failed transactions may require reversals, while completed payments may later require refunds.
- Daily reconciliation and operational monitoring are essential for maintaining financial accuracy.
Business Interview Questions
- What is settlement in UPI?
- What is the role of NPCI during settlement?
- Why is RBI involved in UPI settlement?
- What is net settlement?
- How does merchant settlement work?
- What is reconciliation in UPI?
- What information is compared during reconciliation?
- What is the difference between a refund and a reversal?
- What are common settlement exceptions?
- Which KPIs are commonly monitored in UPI operations?
Security, Scalability & Operations
UPI has become one of the world's largest real-time payment systems, processing billions of transactions every month.
Supporting this scale requires much more than fast payment processing. The platform must protect customer data, prevent fraud, ensure high availability, recover quickly from failures, and continuously monitor system health.
This chapter explores the security mechanisms, operational practices, and scalability techniques that keep the UPI ecosystem reliable and secure.
Learning Objectives
By the end of this chapter, you'll understand:
- UPI security architecture
- Multi-factor authentication
- Device binding
- UPI PIN security
- Encryption
- Tokenization concepts
- Fraud detection
- Risk management
- Transaction limits
- Rate limiting
- High availability
- Disaster recovery
- Monitoring
- Operational dashboards
- Performance KPIs
- Common failures
- Best practices
- Real-world business scenarios
- Interview questions
Why Security Matters
Every UPI transaction involves:
- Customer identity
- Bank accounts
- Financial data
- Payment authorization
- Real-time money movement
A security weakness could result in:
- Financial loss
- Identity theft
- Fraud
- Customer distrust
- Regulatory penalties
Security is therefore a foundational requirement rather than an optional feature.
UPI Security Architecture
flowchart LR
Customer
Customer --> MobileDevice
MobileDevice --> UPIApp
UPIApp --> PSPBank
PSPBank --> NPCI
NPCI --> Bank
Each participant applies multiple security controls before allowing a transaction to proceed.
Multi-Factor Authentication
UPI uses multiple layers of authentication.
Common factors include:
- Registered mobile number
- Registered mobile device
- UPI PIN
Some banks may introduce additional risk-based verification for specific scenarios.
The objective is to verify both:
- Who is making the payment
- Which trusted device is being used
Authentication Flow
flowchart LR
Customer
Customer --> DeviceCheck
DeviceCheck --> UPIPIN
UPIPIN --> BankApproval
Device Binding
A customer's UPI profile is associated with a registered mobile device.
During registration, the application validates:
- Mobile number
- SIM information
- Device identity
- Bank registration
Benefits include:
- Prevents unauthorized device usage
- Reduces account takeover risk
- Improves transaction security
UPI PIN
The UPI PIN authorizes financial transactions.
Characteristics:
- Created by the customer
- Verified by the issuing bank
- Required for payment approval
- Never shared with merchants
Customers should never disclose their UPI PIN to anyone.
UPI PIN Best Practices
Users should:
- Create a strong PIN
- Change the PIN periodically
- Never share it
- Never write it down publicly
- Avoid predictable combinations
Banks educate customers about safe PIN practices to reduce fraud.
Encryption
Sensitive payment information is encrypted while moving between participating systems.
Encryption protects:
- Customer information
- Transaction details
- Authentication data
- Payment messages
Benefits:
- Confidentiality
- Integrity
- Secure communication
Secure Communication
flowchart LR
UPIApp
UPIApp --> PSPBank
PSPBank --> NPCI
NPCI --> Bank
All participating systems exchange payment information using secure communication channels.
Tokenization Concepts
Tokenization replaces sensitive information with a non-sensitive substitute called a token.
Benefits include:
- Reduced exposure of sensitive information
- Lower fraud risk
- Improved data protection
Although UPI primarily uses bank account-based payment routing, tokenization concepts are increasingly used in broader digital payment ecosystems to improve security.
Fraud Detection
Banks and payment providers continuously monitor transactions for suspicious activity.
Examples include:
- Unusual payment amount
- Unusual location
- Rapid repeated payments
- Multiple failed authentication attempts
- High-risk merchants
- Suspicious device activity
Potentially risky transactions may be declined or subjected to additional verification.
Fraud Monitoring Flow
flowchart LR
Transaction
Transaction --> RiskEngine
RiskEngine --> Approved
RiskEngine --> Review
RiskEngine --> Declined
Risk Management
Financial institutions implement risk controls such as:
- Transaction monitoring
- Velocity checks
- Customer behavior analysis
- Device reputation
- Merchant monitoring
- Fraud investigations
Risk management helps reduce financial losses while maintaining a smooth customer experience.
Transaction Limits
UPI transactions are subject to operational limits established by participating institutions and applicable regulations.
Examples of limits include:
- Maximum transaction value
- Daily transaction count
- Daily transfer value
- Merchant-specific limits
These limits help reduce fraud and manage operational risk.
Rate Limiting
To prevent misuse, systems may limit the number of requests from a user or application within a defined period.
Benefits include:
- Protection against abuse
- Prevention of excessive requests
- Improved platform stability
- Reduced operational risk
Common Security Threats
Payment providers defend against threats such as:
- Phishing
- Social engineering
- Fake payment applications
- Account takeover
- SIM swap attacks
- Malware
- Credential theft
Customer awareness is an important part of fraud prevention.
High Availability
UPI is expected to operate continuously throughout the year.
To achieve this, banks deploy:
- Multiple servers
- Redundant infrastructure
- Backup communication paths
- Automatic failover
The objective is to minimize service interruptions.
High Availability Architecture
flowchart LR
Customer
Customer --> ServerA
Customer --> ServerB
ServerA --> Bank
ServerB --> Bank
If one server becomes unavailable, another server continues processing requests.
Disaster Recovery
Despite strong infrastructure, failures can still occur.
Examples include:
- Data center outage
- Hardware failure
- Network disruption
- Natural disaster
- Power interruption
Disaster recovery plans help restore payment services quickly.
Disaster Recovery Flow
flowchart LR
Primary
Primary --> Failure
Failure --> Backup
Backup --> Recovery
Scalability
UPI processes extremely high transaction volumes during:
- Festivals
- Shopping events
- Salary days
- Utility bill due dates
- Government payment programs
The platform must scale without affecting customer experience.
Scalability strategies include:
- Horizontal infrastructure expansion
- Distributed processing
- Efficient request routing
- Load balancing
- Continuous capacity planning
Load Distribution
flowchart LR
Customers
Customers --> LoadBalancer
LoadBalancer --> ServerA
LoadBalancer --> ServerB
LoadBalancer --> ServerC
Load balancing distributes traffic across multiple servers, preventing any single server from becoming overloaded.
Monitoring
Operations teams continuously monitor:
- Transaction success rate
- Processing latency
- System availability
- Error rates
- Network health
- Bank connectivity
- Settlement processing
Monitoring enables rapid detection of operational issues.
Operational Dashboard
Common dashboard metrics include:
- Total transactions
- Successful transactions
- Failed transactions
- Transactions per minute
- Average response time
- Active participating banks
- Fraud alerts
- Open incidents
- System availability
Performance KPIs
| KPI | Description |
|---|---|
| Transaction Success Rate | Percentage of successful transactions |
| Average Response Time | Average payment processing time |
| System Availability | Platform uptime |
| Fraud Detection Rate | Fraud identified before financial loss |
| Failed Transaction Rate | Percentage of unsuccessful transactions |
| Incident Resolution Time | Average time to resolve operational issues |
| Average Recovery Time | Time to restore service after failure |
| Customer Complaint Rate | Operational quality indicator |
Common Operational Failures
Operations teams commonly investigate:
- Bank server downtime
- Network failures
- NPCI connectivity issues
- Delayed responses
- High transaction volume
- Merchant connectivity issues
- Incorrect customer authentication
- System maintenance windows
Incident Management Lifecycle
flowchart LR
Alert
Alert --> Investigation
Investigation --> Resolution
Resolution --> Verification
Verification --> Closure
Operational Best Practices
Organizations should:
- Monitor systems continuously
- Encrypt sensitive information
- Perform regular security reviews
- Maintain disaster recovery plans
- Monitor fraud trends
- Review operational dashboards
- Test backup systems regularly
- Educate customers about payment safety
- Perform capacity planning
- Continuously improve security controls
Customer Safety Tips
Customers should:
- Verify merchant names before paying
- Never share the UPI PIN
- Avoid unknown payment links
- Download only official banking applications
- Report suspicious transactions immediately
- Keep mobile applications updated
These simple practices significantly reduce fraud risk.
Real-World Business Scenario
A major online retailer experiences a surge in UPI payments during a national festival sale.
During peak hours:
- Millions of customers initiate payments simultaneously.
- Load balancers distribute incoming requests across multiple application servers.
- PSP Banks validate customer requests and forward them to NPCI.
- Fraud monitoring systems identify unusual transaction patterns and block suspicious requests.
- Issuing banks authenticate customers using device verification and UPI PIN validation.
- One application server experiences an unexpected hardware failure.
- Automatic failover redirects traffic to healthy servers without interrupting ongoing transactions.
- Monitoring dashboards detect the incident, and operations teams begin investigation immediately.
- The failed server is restored while payment processing continues uninterrupted.
- Customers continue completing transactions without noticing the infrastructure issue.
This demonstrates how security, monitoring, scalability, and high availability work together to provide a reliable payment experience.
Key Takeaways
- Security is fundamental to every UPI transaction.
- Multi-factor authentication combines trusted devices and UPI PIN verification.
- Device binding helps prevent unauthorized access.
- Encryption protects payment information during transmission.
- Fraud detection systems continuously monitor transaction behavior.
- High availability and disaster recovery help maintain uninterrupted payment services.
- Monitoring, scalability, and operational best practices enable UPI to support very high transaction volumes.
Business Interview Questions
- Why is security critical in UPI?
- What is multi-factor authentication in UPI?
- What is device binding?
- How is the UPI PIN protected?
- What role does encryption play in UPI?
- How do banks detect fraudulent UPI transactions?
- Why are transaction limits important?
- How does high availability improve payment reliability?
- What is the purpose of disaster recovery in payment systems?
- Which operational KPIs are commonly monitored in UPI platforms?
Reference Guide & Interview Preparation
Congratulations! You have completed the UPI Architecture series.
You now understand how one of the world's largest real-time payment systems enables secure, instant bank-to-bank payments while handling billions of transactions every month.
UPI has transformed digital payments by providing:
- Real-time fund transfers
- Interoperability between banks
- Mobile-first payments
- QR code payments
- Merchant payments
- Secure authentication
- Scalable infrastructure
This chapter summarizes the entire UPI ecosystem and serves as a quick reference guide for Banking and FinTech professionals preparing for interviews.
Learning Objectives
By the end of this chapter, you'll be able to:
- Explain the complete UPI lifecycle
- Compare UPI with other payment systems
- Understand important UPI terminology
- Identify operational best practices
- Understand future trends
- Review business KPIs
- Prepare for Banking and FinTech interviews
Complete UPI Lifecycle
flowchart LR
Customer
Customer --> UPIApp
UPIApp --> PSPBank
PSPBank --> NPCI
NPCI --> IssuerBank
IssuerBank --> BeneficiaryBank
BeneficiaryBank --> Merchant
Merchant --> Settlement
Settlement --> Reconciliation
End-to-End UPI Transaction Lifecycle
flowchart LR
Initiation
Initiation --> Authentication
Authentication --> Authorization
Authorization --> Debit
Debit --> Credit
Credit --> Settlement
Settlement --> Reconciliation
Reconciliation --> Reporting
UPI Ecosystem
flowchart LR
Customer
Customer --> UPIApp
UPIApp --> PSPBank
PSPBank --> NPCI
NPCI --> IssuerBank
NPCI --> BeneficiaryBank
BeneficiaryBank --> Merchant
Complete Payment Journey
| Step | Activity |
|---|---|
| 1 | Customer initiates payment |
| 2 | UPI App creates payment request |
| 3 | PSP Bank validates request |
| 4 | NPCI routes payment |
| 5 | Issuer Bank authenticates customer |
| 6 | Customer account is debited |
| 7 | Beneficiary Bank receives request |
| 8 | Merchant account is credited |
| 9 | Settlement between participating banks |
| 10 | Reconciliation and reporting |
UPI vs IMPS
| UPI | IMPS |
|---|---|
| Uses Virtual Payment Address | Uses Account Number and IFSC |
| Mobile-first platform | Traditional banking channels |
| Supports QR payments | No native QR support |
| Supports Collect Requests | Primarily push transfers |
| Better customer experience | More banking-oriented |
UPI vs NEFT
| UPI | NEFT |
|---|---|
| Real-time payments | Batch-based settlement |
| Mobile-first | Traditional banking transfers |
| Ideal for daily payments | Suitable for bank transfers |
| Uses UPI ID | Uses Account Number and IFSC |
| Simple user experience | More banking details required |
UPI vs RTGS
| UPI | RTGS |
|---|---|
| Everyday retail payments | High-value transfers |
| Instant user experience | Real-time gross settlement |
| Mobile applications | Banking channels |
| Consumer-focused | Enterprise and large-value transactions |
| Supports QR payments | No QR payments |
UPI vs Credit Cards
| UPI | Credit Card |
|---|---|
| Direct bank account payment | Credit-based payment |
| Immediate account debit | Bill paid later |
| UPI PIN authentication | Card PIN or OTP authentication |
| No physical card required | Physical or virtual card |
| Bank-to-bank transfer | Card network transaction |
UPI vs Digital Wallets
| UPI | Wallet |
|---|---|
| Linked directly to bank account | Requires wallet balance or funding |
| No need to preload money | Often requires loading funds |
| Bank interoperability | Wallet ecosystem dependent |
| Real-time account transfer | Wallet-to-wallet transfers common |
| Wide bank participation | Depends on wallet provider |
Push vs Pull Payments
| Push Payment | Pull Payment |
|---|---|
| Initiated by payer | Initiated by payee |
| Customer sends money | Merchant requests payment |
| Common for retail purchases | Common for bill collection |
| Immediate authorization | Customer approval required |
Person-to-Person vs Person-to-Merchant
| P2P | P2M |
|---|---|
| Individual to individual | Customer to merchant |
| Personal transfers | Business payments |
| Family and friends | Retail purchases |
| Expense sharing | Commercial transactions |
Static QR vs Dynamic QR
| Static QR | Dynamic QR |
|---|---|
| Merchant details only | Merchant and transaction details |
| Customer enters amount | Amount is pre-filled |
| Simple implementation | Better for invoicing |
| Small merchants | Organized retail and e-commerce |
UPI Services
UPI supports many financial services.
Examples include:
- Person-to-Person transfers
- Merchant payments
- QR payments
- Bill payments
- Mobile recharge
- Subscription payments
- Government payments
- Educational fee payments
- E-commerce payments
- Collect Requests
UPI Participants
| Participant | Responsibility |
|---|---|
| Customer | Initiates payment |
| Merchant | Receives payment |
| UPI App | Customer interface |
| PSP Bank | Payment processing |
| NPCI | Transaction switching |
| Issuer Bank | Debits customer account |
| Beneficiary Bank | Credits recipient account |
| RBI | Final interbank settlement |
Important UPI Terminology
| Term | Meaning |
|---|---|
| UPI | Unified Payments Interface |
| NPCI | National Payments Corporation of India |
| RBI | Reserve Bank of India |
| PSP Bank | Payment Service Provider Bank |
| VPA | Virtual Payment Address |
| UPI ID | Customer payment identity |
| QR Code | Machine-readable payment code |
| Collect Request | Payment request initiated by payee |
| Push Payment | Payment initiated by payer |
| Reversal | Return of funds after processing failure |
| Refund | Return of funds after successful payment |
| Settlement | Transfer of funds between banks |
| Reconciliation | Matching financial records |
Common Transaction Status
| Status | Meaning |
|---|---|
| Initiated | Payment started |
| Processing | Validation in progress |
| Authorized | Approved by issuing bank |
| Debited | Customer account debited |
| Credited | Beneficiary account credited |
| Successful | Payment completed |
| Failed | Payment unsuccessful |
| Reversed | Amount returned |
Common Failure Reasons
Payment failures may occur because of:
- Incorrect UPI PIN
- Insufficient balance
- Bank server unavailable
- Network interruption
- Invalid UPI ID
- Transaction limit exceeded
- Beneficiary bank unavailable
- Scheduled maintenance
Operations teams investigate failures and process reversals when necessary.
Operational Dashboards
Typical dashboard metrics include:
- Total transactions
- Successful payments
- Failed payments
- Average response time
- Transactions per minute
- Fraud alerts
- Settlement status
- Open incidents
- System availability
- Reconciliation status
Business KPIs
| KPI | Description |
|---|---|
| Transaction Success Rate | Successful payment percentage |
| Average Response Time | Payment processing speed |
| Settlement Success Rate | Successfully settled transactions |
| Reconciliation Match Rate | Correctly matched records |
| Fraud Detection Rate | Fraud identified before financial loss |
| Failed Transaction Rate | Unsuccessful payment percentage |
| Average Recovery Time | Disaster recovery efficiency |
| Incident Resolution Time | Operational issue resolution time |
| Customer Complaint Rate | Customer service quality indicator |
Best Practices
Organizations should:
- Monitor systems continuously
- Encrypt sensitive payment information
- Perform reconciliation daily
- Maintain complete audit trails
- Detect fraud proactively
- Monitor transaction performance
- Test disaster recovery regularly
- Educate customers about payment safety
- Review operational dashboards
- Continuously improve payment infrastructure
Business Challenges
Large-scale payment systems must manage:
- Rapid transaction growth
- High availability
- Fraud prevention
- Cross-bank interoperability
- Peak traffic during festivals
- Regulatory compliance
- Customer expectations
- Operational efficiency
Future Trends
AI-Powered Fraud Detection
Artificial Intelligence is increasingly used for:
- Fraud prediction
- Customer behavior analysis
- Risk scoring
- Transaction monitoring
Real-Time Risk Engines
Banks continue investing in:
- Instant fraud detection
- Dynamic transaction scoring
- Intelligent authorization decisions
International Payment Integration
Future payment ecosystems may support:
- Faster international payments
- Better interoperability
- Cross-border payment innovation
Digital Identity
Emerging technologies continue improving:
- Customer verification
- Identity management
- Authentication methods
Cloud-Native Payment Platforms
Modern payment providers are adopting cloud technologies to improve:
- Scalability
- Reliability
- Disaster recovery
- Operational efficiency
Complete Business Scenario
A national retail chain processes 2 million UPI transactions during a festive shopping event.
- Customers make payments using QR codes through different UPI applications.
- PSP Banks receive payment requests and forward them to NPCI.
- NPCI routes transactions to the respective issuing and beneficiary banks.
- Issuing banks authenticate customers and authorize debits.
- Beneficiary banks credit merchant accounts and return successful responses.
- Throughout the day, fraud monitoring systems analyze transaction patterns and identify suspicious activity.
- NPCI calculates net obligations among participating banks.
- RBI performs interbank settlement.
- Finance teams reconcile settlement reports with bank records.
- Operations teams resolve exceptions and generate regulatory and business reports.
Despite processing millions of payments, customers experience near-instant confirmation because the ecosystem is designed for scalability, resilience, and continuous monitoring.
Learning Checklist
After completing this series, you should be able to explain:
- ✅ UPI architecture
- ✅ NPCI ecosystem
- ✅ PSP Bank responsibilities
- ✅ Issuer and Beneficiary Bank roles
- ✅ Virtual Payment Address (VPA)
- ✅ UPI ID
- ✅ Payment initiation
- ✅ Authentication
- ✅ UPI PIN validation
- ✅ NPCI switching
- ✅ Push and Pull payments
- ✅ QR Code payments
- ✅ P2P and P2M transactions
- ✅ Settlement lifecycle
- ✅ Reconciliation process
- ✅ Refunds and reversals
- ✅ Fraud detection
- ✅ High availability
- ✅ Disaster recovery
- ✅ Operational dashboards
- ✅ Performance KPIs
Banking & FinTech Interview Questions
Fundamentals
- What is UPI?
- Why was UPI introduced?
- What is the role of NPCI?
- What is a PSP Bank?
- What is a Virtual Payment Address (VPA)?
Transaction Flow
- Explain the end-to-end UPI transaction flow.
- How is the UPI PIN validated?
- What is the role of the issuing bank?
- What is the role of the beneficiary bank?
- What happens after a successful authorization?
Settlement & Reconciliation
- How are UPI transactions settled?
- What is the role of RBI in settlement?
- What is net settlement?
- What is reconciliation?
- What is the difference between a refund and a reversal?
Security
- What security controls protect UPI transactions?
- What is device binding?
- How do banks detect fraudulent transactions?
- Why is encryption important?
- What are common payment risks?
Architecture
- What is the difference between UPI and IMPS?
- How does UPI differ from NEFT?
- How does UPI differ from RTGS?
- Why is UPI considered a real-time payment system?
- What are the responsibilities of NPCI?
Operations
- What operational KPIs are monitored?
- How does high availability improve payment reliability?
- What is disaster recovery?
- How do operations teams handle failed transactions?
- What best practices improve UPI operations?
Series Summary
Congratulations!
You have completed the UPI Architecture series and gained a comprehensive understanding of one of the world's most advanced real-time payment systems.
You now understand:
- UPI ecosystem and architecture
- Roles of NPCI, RBI, PSP Banks, Issuer Banks, and Beneficiary Banks
- End-to-end transaction processing
- Payment authorization and routing
- Settlement and reconciliation
- Security, fraud prevention, and risk management
- Scalability and operational monitoring
- Business KPIs and operational best practices
This knowledge provides a strong foundation for careers in:
- Banking
- FinTech
- Digital Payments
- Merchant Acquiring
- Payment Gateways
- Core Banking
- Payment Operations
- Financial Technology
- Solution Architecture
- Business Analysis