26. UPI Architecture

Learn UPI Architecture as part of the Domain Knowledge learning path for software engineers and architects.

India has transformed digital payments through one of the world's most successful real-time payment systems—Unified Payments Interface (UPI).

Today, millions of individuals and businesses use UPI every day to transfer money instantly using mobile applications without remembering lengthy bank account numbers or IFSC codes.

Whether you're paying a friend, purchasing groceries, booking movie tickets, or paying utility bills, UPI enables secure, real-time bank-to-bank transfers in just a few seconds.

This chapter introduces the fundamentals of UPI, its architecture, ecosystem, participants, and how different organizations work together to provide a seamless payment experience.


Learning Objectives

By the end of this chapter, you'll understand:

  • What UPI is
  • History of UPI
  • Why UPI was introduced
  • Evolution from IMPS
  • UPI ecosystem
  • Key participants
  • Virtual Payment Address (VPA)
  • UPI ID
  • Linked bank accounts
  • High-level UPI architecture
  • Real-world payment flow
  • Advantages
  • Limitations
  • Business interview questions

What is UPI?

Unified Payments Interface (UPI) is a real-time payment system that enables instant bank-to-bank money transfers using a mobile device.

UPI allows users to:

  • Send money
  • Receive money
  • Pay merchants
  • Request money
  • Pay bills
  • Link multiple bank accounts
  • Make payments 24×7

Unlike traditional banking methods, users typically do not need to enter bank account numbers for every transaction.

Instead, they use a Virtual Payment Address (VPA) such as:

venu@okbank

Who Developed UPI?

UPI was developed by the National Payments Corporation of India (NPCI).

NPCI is responsible for:

  • Defining UPI standards
  • Operating the UPI switching infrastructure
  • Connecting participating banks
  • Ensuring interoperability
  • Managing transaction routing

NPCI enables banks and payment applications to work together through a common payment platform.


Why Was UPI Introduced?

Before UPI, digital payments often required:

  • Bank account numbers
  • IFSC codes
  • Multiple banking applications
  • Separate payment systems
  • Complex transfer processes

Customers wanted:

  • Faster payments
  • Simpler user experience
  • Mobile-first banking
  • Instant fund transfers
  • Secure authentication

UPI was introduced to address these challenges through a standardized, interoperable payment platform.


Evolution of Digital Payments

flowchart LR

Cash

Cash --> Cards

Cards --> NEFT

NEFT --> IMPS

IMPS --> UPI

UPI builds on earlier electronic payment systems while providing a simpler and more unified experience.


IMPS vs UPI

UPI was built on top of the Immediate Payment Service (IMPS) infrastructure while introducing new capabilities.

IMPS UPI
Account Number + IFSC Virtual Payment Address (VPA)
Primarily bank channels Banks and approved third-party apps
Immediate transfers Immediate transfers
Basic user experience Mobile-first experience
Limited interoperability features Unified interoperable ecosystem

Key Features of UPI

UPI offers several capabilities that distinguish it from traditional payment systems.

  • Real-time payments
  • 24×7 availability
  • Bank-to-bank transfers
  • Mobile-first experience
  • Multiple linked bank accounts
  • QR code payments
  • Merchant payments
  • Person-to-person transfers
  • Request money functionality
  • Interoperability across participating banks

UPI Ecosystem

UPI is not operated by a single bank.

Instead, it connects multiple organizations that work together to complete each payment.

flowchart LR

Customer

Customer --> UPIApp

UPIApp --> NPCI

NPCI --> Bank

Bank --> Merchant

Each participant performs a specific role during a transaction.


UPI Participants

The major participants include:

  • Customer (Payer)
  • Merchant (Payee)
  • UPI Application
  • PSP Bank
  • Issuer Bank
  • Beneficiary Bank
  • NPCI

Customer (Payer)

The payer initiates the payment.

Responsibilities:

  • Select recipient
  • Enter payment amount
  • Authenticate using UPI PIN
  • Approve the transaction

Merchant (Payee)

The merchant receives payment.

Examples include:

  • Grocery stores
  • Restaurants
  • E-commerce websites
  • Utility providers
  • Online service platforms

Merchants can accept payments using:

  • QR codes
  • UPI ID
  • Payment links
  • Collect requests

UPI Application

Customers interact with UPI through mobile applications.

Examples include:

  • BHIM
  • Google Pay
  • PhonePe
  • Paytm
  • Bank mobile applications

These applications provide the user interface but do not hold customer funds.


PSP Bank

A Payment Service Provider (PSP) Bank enables UPI services for customers through UPI applications.

Responsibilities include:

  • Register customers
  • Link bank accounts
  • Authenticate users
  • Forward payment requests
  • Receive transaction responses

Issuer Bank

The issuer bank is the bank where the payer maintains an account.

Responsibilities:

  • Verify account status
  • Authenticate UPI PIN
  • Check available balance
  • Authorize debit
  • Send authorization response

Beneficiary Bank

The beneficiary bank maintains the merchant's or recipient's account.

Responsibilities:

  • Validate destination account
  • Accept incoming credit
  • Credit beneficiary account
  • Confirm successful transaction

NPCI

NPCI acts as the central switching platform.

Responsibilities include:

  • Route payment requests
  • Connect participating banks
  • Validate routing information
  • Exchange payment messages
  • Coordinate transaction processing

NPCI does not hold customer money during normal UPI transactions; it facilitates communication between participating institutions.


Participant Interaction

flowchart LR

Customer

Customer --> PSPBank

PSPBank --> NPCI

NPCI --> IssuerBank

NPCI --> BeneficiaryBank

BeneficiaryBank --> Merchant

What is a Virtual Payment Address (VPA)?

A Virtual Payment Address (VPA) is a unique identifier used to send and receive money.

Example:

venu@okaxis

or

alex@oksbi

A VPA eliminates the need to repeatedly share:

  • Bank account number
  • IFSC code
  • Branch details

Benefits of VPA

Advantages include:

  • Easy to remember
  • Improved privacy
  • Faster payments
  • Reduced typing errors
  • Simplified payment experience

What is a UPI ID?

A UPI ID is the customer's payment identity within the UPI ecosystem.

Examples:

rahul@oksbi

john@ybl

anita@okicici

Every UPI transaction is routed using the registered UPI ID or another supported payment identifier.


Linked Bank Accounts

Users can link multiple bank accounts to one UPI application.

Example

Google Pay

↓

Savings Account

↓

Salary Account

↓

Joint Account

Users can choose which linked account should be used as the default payment account.


High-Level UPI Architecture

flowchart LR

Customer

Customer --> UPIApp

UPIApp --> PSPBank

PSPBank --> NPCI

NPCI --> IssuerBank

NPCI --> BeneficiaryBank

BeneficiaryBank --> Merchant

High-Level Payment Flow

A simplified UPI payment follows these steps:

  1. Customer opens a UPI application.
  2. Customer selects the recipient.
  3. Customer enters the amount.
  4. Customer authenticates using the UPI PIN.
  5. The PSP Bank forwards the request to NPCI.
  6. NPCI routes the request to the appropriate banks.
  7. The issuer bank verifies the transaction.
  8. The beneficiary bank credits the recipient.
  9. Both parties receive confirmation.

UPI Use Cases

UPI supports many everyday payment scenarios.

Examples include:

  • Person-to-person transfers
  • Merchant payments
  • Utility bill payments
  • Mobile recharge
  • Subscription payments
  • Educational fee payments
  • Government service payments
  • E-commerce purchases

Advantages of UPI

UPI provides several benefits.

For customers:

  • Instant payments
  • 24×7 availability
  • Easy-to-use interface
  • Multiple linked bank accounts
  • Secure authentication

For merchants:

  • Faster payment confirmation
  • Lower cash handling
  • Digital transaction records
  • Broad customer adoption

For banks:

  • Standardized payment infrastructure
  • Interoperable ecosystem
  • Efficient digital payment processing

Limitations

Although UPI is highly successful, it has operational considerations.

Examples include:

  • Internet connectivity required
  • Transaction limits
  • Temporary bank downtime
  • Mobile device dependency
  • UPI service outages during maintenance

Payment success depends on all participating systems being available.


UPI Transaction Flow

A UPI payment usually completes within a few seconds, but behind every successful transaction is a coordinated workflow involving the customer, UPI application, PSP Bank, NPCI, issuing bank, and beneficiary bank.

Unlike traditional bank transfers that often require account numbers and IFSC codes, UPI uses a Virtual Payment Address (VPA) and real-time message exchange to provide a simple and seamless payment experience.

This chapter explains how a UPI transaction flows from initiation to completion.


Learning Objectives

By the end of this chapter, you'll understand:

  • End-to-end UPI transaction flow
  • Payment initiation
  • Customer authentication
  • UPI PIN validation
  • NPCI switching
  • Issuer bank authorization
  • Beneficiary bank validation
  • Success and failure responses
  • Transaction states
  • Push and Pull payments
  • QR Code payments
  • Dynamic QR
  • Person-to-Person (P2P)
  • Person-to-Merchant (P2M)
  • Business scenarios
  • Interview questions

End-to-End UPI Transaction Flow

flowchart LR

Customer

Customer --> UPIApp

UPIApp --> PSPBank

PSPBank --> NPCI

NPCI --> IssuerBank

NPCI --> BeneficiaryBank

BeneficiaryBank --> Merchant

Transaction Lifecycle

flowchart LR

Initiation

Initiation --> Authentication

Authentication --> Authorization

Authorization --> Debit

Debit --> Credit

Credit --> Confirmation

Every successful UPI payment follows these major stages.


Step 1 – Payment Initiation

The transaction begins when the customer decides to make a payment.

The customer may:

  • Enter a UPI ID
  • Scan a QR Code
  • Select a saved contact
  • Use a mobile number (if supported by the application)
  • Accept a collect request

Example

Coffee Purchase

₹250

Merchant

Coffee Shop


Payment Initiation Flow

flowchart LR

Customer

Customer --> UPIApp

UPIApp --> PaymentRequest

Step 2 – Customer Authentication

Before money can move, the customer must authenticate.

Authentication ensures the transaction is being initiated by the legitimate account holder.

Common authentication methods include:

  • Device verification
  • Mobile number verification
  • UPI PIN

Authentication protects against unauthorized payments.


Step 3 – UPI PIN Validation

The customer enters the UPI PIN.

The PIN is securely verified by the issuing bank.

flowchart LR

Customer

Customer --> UPIPIN

UPIPIN --> IssuerBank

If the PIN is incorrect:

  • Transaction fails
  • No money is debited
  • Customer receives an error message

Step 4 – PSP Bank Receives Request

The Payment Service Provider (PSP) Bank receives the payment request.

Responsibilities include:

  • Validate request format
  • Verify customer registration
  • Forward request
  • Receive response
  • Notify customer

The PSP Bank acts as the communication layer between the application and NPCI.


Step 5 – NPCI Switching

NPCI acts as the central switching platform.

Responsibilities:

  • Identify participating banks
  • Route requests
  • Exchange payment messages
  • Coordinate transaction processing
flowchart LR

PSPBank

PSPBank --> NPCI

NPCI --> IssuerBank

NPCI --> BeneficiaryBank

NPCI does not authorize the transaction itself; it routes messages between participating banks.


Step 6 – Issuer Bank Authorization

The issuer bank performs several checks before approving the payment.

Typical validations include:

  • Account status
  • Available balance
  • UPI PIN validation
  • Transaction limits
  • Risk controls
  • Fraud checks

Possible outcomes:

  • Approved
  • Declined

Authorization Decision

flowchart TD

Request

Request --> BalanceCheck

BalanceCheck --> RiskCheck

RiskCheck --> Decision

Decision --> Approved

Decision --> Declined

Step 7 – Debit Customer Account

If approved:

  • Customer account is debited.
  • Transaction reference is generated.
  • Authorization response is created.

Example

Account Balance Before

₹12,000

Payment

₹250

Remaining Balance

₹11,750


Step 8 – Beneficiary Bank Validation

NPCI forwards the approved payment message to the beneficiary bank.

The beneficiary bank verifies:

  • Beneficiary account
  • Merchant status
  • Account availability

If validation succeeds:

  • Account is credited.
  • Success response is generated.

Credit Flow

flowchart LR

NPCI

NPCI --> BeneficiaryBank

BeneficiaryBank --> Merchant

Step 9 – Confirmation

After the beneficiary bank confirms the credit:

  • Merchant receives payment confirmation.
  • Customer receives payment confirmation.
  • Transaction is marked successful.
flowchart LR

Bank

Bank --> Merchant

Bank --> Customer

Transaction States

Every UPI transaction passes through one or more states.

State Description
Initiated Customer started payment
Processing Banks are validating transaction
Authorized Issuer approved debit
Debited Customer account debited
Credited Beneficiary account credited
Successful Transaction completed
Failed Transaction not completed
Reversed Debit returned to customer

Common Failure Reasons

Transactions may fail because of:

  • Incorrect UPI PIN
  • Insufficient balance
  • Bank server unavailable
  • NPCI timeout
  • Transaction limit exceeded
  • Invalid UPI ID
  • Beneficiary bank unavailable
  • Network connectivity issue

Failure Handling

flowchart LR

Request

Request --> Validation

Validation --> Success

Validation --> Failure

Failure --> CustomerNotification

Request and Response Messages

UPI transactions involve multiple message exchanges.

Typical request information:

  • Transaction ID
  • UPI ID
  • Amount
  • PSP Identifier
  • Bank Identifier
  • Timestamp

Typical response information:

  • Transaction Status
  • Reference Number
  • Approval Result
  • Error Code (if applicable)

Push Payments

A Push Payment is initiated by the payer.

Example:

Customer

↓

Send Money

↓

Merchant

Examples:

  • Paying a restaurant bill
  • Sending money to a friend
  • Paying rent

The customer actively pushes money to another account.


Pull Payments (Collect Request)

A Pull Payment begins when the payee requests money.

Example

Merchant

Collect Request

Customer

Approve

Payment


Common use cases:

- Utility bills
- Subscription payments
- Invoice collection
- Business payments

---

##  Push vs Pull Payments

| Push Payment | Pull Payment |
|---------------|--------------|
| Initiated by payer | Initiated by payee |
| Customer sends money | Customer approves request |
| Immediate transfer | Requires customer approval |
| Common for retail payments | Common for bill collection |

---

##  Person-to-Person (P2P)

P2P transactions occur between two individuals.

Examples:

- Friends
- Family
- Shared expenses
- Personal transfers

Flow

```mermaid
flowchart LR

PersonA

PersonA --> NPCI

NPCI --> PersonB

Person-to-Merchant (P2M)

P2M transactions occur when customers pay merchants.

Examples:

  • Grocery stores
  • Restaurants
  • Fuel stations
  • Online shopping
  • Utility payments

Flow

flowchart LR

Customer

Customer --> Merchant

Merchant --> Bank

QR Code Payments

UPI supports QR Code payments.

The customer:

  1. Opens a UPI application.
  2. Scans the QR Code.
  3. Confirms the merchant.
  4. Enters the amount (for static QR).
  5. Enters the UPI PIN.
  6. Completes payment.

Benefits:

  • Faster checkout
  • Reduced typing errors
  • Contactless payments
  • Easy merchant onboarding

Static QR vs Dynamic QR

Static QR Dynamic QR
Merchant information only Merchant information plus transaction details
Customer enters amount Amount is pre-filled
Simple to deploy Better for invoiced payments
Common in small businesses Common in organized retail and e-commerce

Merchant Payment Flow

flowchart LR

Customer

Customer --> QRCode

QRCode --> PSPBank

PSPBank --> NPCI

NPCI --> MerchantBank

MerchantBank --> Merchant

Transaction Reference Number

Every successful UPI transaction receives a unique reference number.

It helps:

  • Track payments
  • Investigate issues
  • Resolve disputes
  • Perform reconciliation
  • Support customer service

Real-World Business Scenario

A customer purchases groceries worth ₹1,850 using a UPI application.

  1. The customer scans the merchant's dynamic QR code.
  2. The amount is automatically displayed.
  3. The customer verifies the merchant name.
  4. The customer enters the UPI PIN.
  5. The PSP Bank forwards the request to NPCI.
  6. NPCI routes the request to the issuing bank.
  7. The issuing bank verifies the account balance and authenticates the UPI PIN.
  8. The customer's account is debited.
  9. NPCI forwards the transaction to the beneficiary bank.
  10. The beneficiary bank credits the merchant's account.
  11. Both the customer and merchant receive instant confirmation.

The complete process is typically completed within a few seconds.


Key Takeaways

  • UPI enables real-time bank-to-bank payments.
  • Every transaction begins with payment initiation and customer authentication.
  • The UPI PIN is validated by the issuing bank.
  • NPCI serves as the central transaction switch connecting participating banks.
  • The issuer bank authorizes the debit, while the beneficiary bank credits the recipient.
  • UPI supports Push Payments, Pull Payments, P2P, P2M, and QR Code payments.
  • Every successful transaction receives a unique reference number for tracking and reconciliation.

Business Interview Questions

  1. What are the major steps in a UPI transaction?
  2. What is the role of NPCI during transaction processing?
  3. How is the UPI PIN validated?
  4. What responsibilities does a PSP Bank perform?
  5. What checks are performed by the issuer bank?
  6. What is the difference between Push and Pull payments?
  7. What is the difference between P2P and P2M transactions?
  8. How do static and dynamic QR codes differ?
  9. What are the common reasons for UPI transaction failures?
  10. Why is the transaction reference number important?

Settlement & Reconciliation

A UPI payment appears to complete instantly from the customer's perspective, but the financial processing continues after the transaction is successful.

Behind every successful payment, banks, NPCI, and the Reserve Bank of India (RBI) work together to settle funds between participating banks and ensure that every transaction is accurately reconciled.

Settlement guarantees that money moves between banks, while reconciliation verifies that every financial record matches across all systems.

This chapter explains how settlement and reconciliation work in the UPI ecosystem.


Learning Objectives

By the end of this chapter, you'll understand:

  • UPI settlement overview
  • Role of NPCI
  • Role of RBI
  • Interbank settlement
  • Merchant settlement
  • Net settlement
  • Settlement cycles
  • Transaction reconciliation
  • Failed transaction handling
  • Reversals
  • Refunds
  • Daily reconciliation
  • Settlement reports
  • Operational KPIs
  • Real-world business scenarios
  • Interview questions

What is Settlement?

Settlement is the process of transferring money between participating banks after a payment has been successfully authorized.

During settlement:

  • Customer funds are finalized
  • Banks exchange financial obligations
  • Merchant banks receive settlement funds
  • Financial records are updated

Settlement completes the financial movement of money.


Settlement in UPI

Unlike card payments that may settle on T+1 or T+2, UPI provides an instant payment experience while participating banks periodically settle their net obligations through NPCI and RBI.

Customers receive immediate confirmation, while the interbank settlement process occurs in the background according to settlement schedules.


Settlement Lifecycle

flowchart LR

Payment

Payment --> Authorization

Authorization --> Success

Success --> Settlement

Settlement --> Reconciliation

Reconciliation --> Reporting

UPI Settlement Participants

The settlement process involves several organizations.

  • Customer Bank
  • Beneficiary Bank
  • PSP Bank
  • NPCI
  • RBI

Each participant has a specific financial responsibility.


Role of NPCI

NPCI acts as the central switching and settlement coordinator.

Responsibilities include:

  • Collect transaction records
  • Calculate net obligations
  • Prepare settlement files
  • Send settlement instructions
  • Generate settlement reports
  • Coordinate participating banks

NPCI facilitates settlement but does not permanently hold customer funds.


Role of RBI

The Reserve Bank of India (RBI) performs the final interbank settlement.

Responsibilities include:

  • Maintain settlement accounts
  • Transfer funds between participating banks
  • Complete net settlement
  • Ensure settlement finality
  • Maintain payment system stability

RBI acts as the settlement authority for participating banks.


Settlement Participants

flowchart LR

IssuerBank

IssuerBank --> NPCI

NPCI --> RBI

RBI --> BeneficiaryBank

Interbank Settlement

During the day, thousands of transactions occur between different banks.

Example

Customer Bank Merchant Bank Amount
Bank A Bank B $120
Bank A Bank C $80
Bank B Bank A $60
Bank C Bank A $40

Instead of settling each payment individually, banks calculate their net obligations.


Net Settlement

Net settlement combines all incoming and outgoing obligations into a single settlement amount.

Example

Bank A

Outgoing

$200

Incoming

$100

Net Settlement

Pay $100

This significantly reduces the number of financial transfers between banks.


Net Settlement Flow

flowchart LR

Transactions

Transactions --> NetCalculation

NetCalculation --> RBI

RBI --> Banks

Merchant Settlement

Customers receive immediate confirmation, but merchants receive funds through their acquiring or beneficiary bank according to the agreed settlement process.

Merchant settlement involves:

  • Successful payment
  • Bank credit
  • Settlement reporting
  • Merchant account update

Merchant Settlement Flow

flowchart LR

Customer

Customer --> Merchant

Merchant --> BeneficiaryBank

BeneficiaryBank --> Settlement

Settlement Reports

NPCI and participating banks generate reports for operational and financial teams.

Common reports include:

  • Settlement Report
  • Net Position Report
  • Bank Settlement Report
  • Merchant Settlement Report
  • Exception Report
  • Reconciliation Report

These reports support finance, operations, and audit activities.


Transaction Reconciliation

Settlement alone is not sufficient.

Banks must verify that every transaction was processed correctly.

Reconciliation compares:

  • Transaction records
  • Settlement reports
  • Bank ledgers
  • Merchant records

The objective is to ensure financial accuracy.


Reconciliation Lifecycle

flowchart LR

Transactions

Transactions --> Matching

Matching --> Exceptions

Exceptions --> Resolution

Resolution --> Closure

Matching Process

A reconciliation system typically compares:

  • Transaction ID
  • UPI Reference Number
  • Amount
  • Bank
  • Merchant
  • Settlement Date
  • Transaction Status

If all required values match, the transaction is considered reconciled.


Successful Reconciliation Example

Transaction ID Merchant Amount Status
UPI501 Grocery Store $18 Matched
UPI502 Fuel Station $42 Matched
UPI503 Pharmacy $25 Matched

All records are successfully matched across participating systems.


Settlement Exceptions

Sometimes settlement does not complete successfully.

Common reasons include:

  • Bank downtime
  • Invalid settlement file
  • Processing delay
  • Network issue
  • System maintenance
  • Settlement timeout

Operations teams investigate every exception.


Failed Transaction Handling

A UPI payment may fail at different stages.

Examples:

  • Authentication failure
  • Insufficient balance
  • Bank unavailable
  • Beneficiary unavailable
  • NPCI timeout
  • Network interruption

If the customer's account has not been debited, no further action is required.

If the account has already been debited, the transaction may require reversal.


Failed Transaction Flow

flowchart LR

Payment

Payment --> Failure

Failure --> Investigation

Investigation --> Reversal

Reversal --> Customer

Reversals

A reversal returns money to the customer's account when a completed debit cannot be finalized.

Common situations include:

  • Merchant not credited
  • Beneficiary bank unavailable
  • Processing interruption
  • Settlement failure

The objective is to restore the customer's balance accurately.


Reversal Example

Customer Account

Before Payment

$500

Payment

$75

Processing Failure

Reversal

$75

Final Balance

$500


Refunds

Refunds differ from reversals.

A reversal corrects a failed payment.

A refund returns money after a successful payment has already been completed.

Examples:

  • Product return
  • Order cancellation
  • Duplicate purchase
  • Merchant goodwill

Refund vs Reversal

Refund Reversal
After successful payment During failed processing
Merchant initiates System or bank initiates
Business decision Operational correction
Customer receives money back Original debit is canceled

Daily Reconciliation

Banks perform reconciliation every business day.

Typical workflow:

  1. Download transaction reports.
  2. Compare settlement records.
  3. Compare bank ledgers.
  4. Identify mismatches.
  5. Investigate exceptions.
  6. Resolve differences.
  7. Generate reconciliation reports.

Daily reconciliation ensures financial accuracy.


Daily Reconciliation Flow

flowchart LR

Reports

Reports --> Matching

Matching --> Exceptions

Exceptions --> Investigation

Investigation --> Reporting

Operational Dashboards

Payment operations teams monitor dashboards throughout the day.

Common metrics include:

  • Total UPI transactions
  • Successful payments
  • Failed payments
  • Settlement status
  • Open exceptions
  • Reversals
  • Refunds
  • Processing delays

Dashboards help operations teams respond quickly to issues.


Operational KPIs

KPI Description
Settlement Success Rate Percentage of successfully settled transactions
Reconciliation Match Rate Percentage of matched records
Failed Transaction Rate Percentage of failed transactions
Average Settlement Time Time required for settlement processing
Average Resolution Time Time to resolve exceptions
Reversal Rate Percentage of reversed transactions
Refund Processing Time Average refund completion time
Exception Rate Transactions requiring investigation

Best Practices

Successful UPI operations should:

  • Perform reconciliation daily
  • Monitor settlement continuously
  • Automate exception detection
  • Maintain audit logs
  • Resolve failures quickly
  • Monitor settlement KPIs
  • Validate settlement reports
  • Investigate unmatched transactions promptly

Real-World Business Scenario

An online grocery platform processes 350,000 UPI payments during a weekend sale.

At the end of the settlement cycle:

  1. NPCI collects transaction records from participating banks.
  2. Net obligations for each bank are calculated.
  3. RBI completes the interbank settlement.
  4. Beneficiary banks update merchant accounts.
  5. Finance teams receive settlement and reconciliation reports.
  6. Automated systems match all transaction records.
  7. 349,920 transactions reconcile successfully.
  8. 80 transactions are flagged because of temporary bank downtime and delayed settlement confirmations.
  9. Operations teams investigate the exceptions, process necessary reversals where appropriate, and complete the final reconciliation.

This process ensures that banks, merchants, and customers maintain accurate financial records.


Key Takeaways

  • Settlement transfers funds between participating banks after successful UPI payments.
  • NPCI coordinates settlement by calculating net obligations and preparing settlement instructions.
  • RBI performs the final interbank settlement between banks.
  • Net settlement reduces the number of financial transfers required.
  • Reconciliation verifies that transaction, settlement, and bank records match.
  • Failed transactions may require reversals, while completed payments may later require refunds.
  • Daily reconciliation and operational monitoring are essential for maintaining financial accuracy.

Business Interview Questions

  1. What is settlement in UPI?
  2. What is the role of NPCI during settlement?
  3. Why is RBI involved in UPI settlement?
  4. What is net settlement?
  5. How does merchant settlement work?
  6. What is reconciliation in UPI?
  7. What information is compared during reconciliation?
  8. What is the difference between a refund and a reversal?
  9. What are common settlement exceptions?
  10. Which KPIs are commonly monitored in UPI operations?

Security, Scalability & Operations

UPI has become one of the world's largest real-time payment systems, processing billions of transactions every month.

Supporting this scale requires much more than fast payment processing. The platform must protect customer data, prevent fraud, ensure high availability, recover quickly from failures, and continuously monitor system health.

This chapter explores the security mechanisms, operational practices, and scalability techniques that keep the UPI ecosystem reliable and secure.


Learning Objectives

By the end of this chapter, you'll understand:

  • UPI security architecture
  • Multi-factor authentication
  • Device binding
  • UPI PIN security
  • Encryption
  • Tokenization concepts
  • Fraud detection
  • Risk management
  • Transaction limits
  • Rate limiting
  • High availability
  • Disaster recovery
  • Monitoring
  • Operational dashboards
  • Performance KPIs
  • Common failures
  • Best practices
  • Real-world business scenarios
  • Interview questions

Why Security Matters

Every UPI transaction involves:

  • Customer identity
  • Bank accounts
  • Financial data
  • Payment authorization
  • Real-time money movement

A security weakness could result in:

  • Financial loss
  • Identity theft
  • Fraud
  • Customer distrust
  • Regulatory penalties

Security is therefore a foundational requirement rather than an optional feature.


UPI Security Architecture

flowchart LR

Customer

Customer --> MobileDevice

MobileDevice --> UPIApp

UPIApp --> PSPBank

PSPBank --> NPCI

NPCI --> Bank

Each participant applies multiple security controls before allowing a transaction to proceed.


Multi-Factor Authentication

UPI uses multiple layers of authentication.

Common factors include:

  • Registered mobile number
  • Registered mobile device
  • UPI PIN

Some banks may introduce additional risk-based verification for specific scenarios.

The objective is to verify both:

  • Who is making the payment
  • Which trusted device is being used

Authentication Flow

flowchart LR

Customer

Customer --> DeviceCheck

DeviceCheck --> UPIPIN

UPIPIN --> BankApproval

Device Binding

A customer's UPI profile is associated with a registered mobile device.

During registration, the application validates:

  • Mobile number
  • SIM information
  • Device identity
  • Bank registration

Benefits include:

  • Prevents unauthorized device usage
  • Reduces account takeover risk
  • Improves transaction security

UPI PIN

The UPI PIN authorizes financial transactions.

Characteristics:

  • Created by the customer
  • Verified by the issuing bank
  • Required for payment approval
  • Never shared with merchants

Customers should never disclose their UPI PIN to anyone.


UPI PIN Best Practices

Users should:

  • Create a strong PIN
  • Change the PIN periodically
  • Never share it
  • Never write it down publicly
  • Avoid predictable combinations

Banks educate customers about safe PIN practices to reduce fraud.


Encryption

Sensitive payment information is encrypted while moving between participating systems.

Encryption protects:

  • Customer information
  • Transaction details
  • Authentication data
  • Payment messages

Benefits:

  • Confidentiality
  • Integrity
  • Secure communication

Secure Communication

flowchart LR

UPIApp

UPIApp --> PSPBank

PSPBank --> NPCI

NPCI --> Bank

All participating systems exchange payment information using secure communication channels.


Tokenization Concepts

Tokenization replaces sensitive information with a non-sensitive substitute called a token.

Benefits include:

  • Reduced exposure of sensitive information
  • Lower fraud risk
  • Improved data protection

Although UPI primarily uses bank account-based payment routing, tokenization concepts are increasingly used in broader digital payment ecosystems to improve security.


Fraud Detection

Banks and payment providers continuously monitor transactions for suspicious activity.

Examples include:

  • Unusual payment amount
  • Unusual location
  • Rapid repeated payments
  • Multiple failed authentication attempts
  • High-risk merchants
  • Suspicious device activity

Potentially risky transactions may be declined or subjected to additional verification.


Fraud Monitoring Flow

flowchart LR

Transaction

Transaction --> RiskEngine

RiskEngine --> Approved

RiskEngine --> Review

RiskEngine --> Declined

Risk Management

Financial institutions implement risk controls such as:

  • Transaction monitoring
  • Velocity checks
  • Customer behavior analysis
  • Device reputation
  • Merchant monitoring
  • Fraud investigations

Risk management helps reduce financial losses while maintaining a smooth customer experience.


Transaction Limits

UPI transactions are subject to operational limits established by participating institutions and applicable regulations.

Examples of limits include:

  • Maximum transaction value
  • Daily transaction count
  • Daily transfer value
  • Merchant-specific limits

These limits help reduce fraud and manage operational risk.


Rate Limiting

To prevent misuse, systems may limit the number of requests from a user or application within a defined period.

Benefits include:

  • Protection against abuse
  • Prevention of excessive requests
  • Improved platform stability
  • Reduced operational risk

Common Security Threats

Payment providers defend against threats such as:

  • Phishing
  • Social engineering
  • Fake payment applications
  • Account takeover
  • SIM swap attacks
  • Malware
  • Credential theft

Customer awareness is an important part of fraud prevention.


High Availability

UPI is expected to operate continuously throughout the year.

To achieve this, banks deploy:

  • Multiple servers
  • Redundant infrastructure
  • Backup communication paths
  • Automatic failover

The objective is to minimize service interruptions.


High Availability Architecture

flowchart LR

Customer

Customer --> ServerA

Customer --> ServerB

ServerA --> Bank

ServerB --> Bank

If one server becomes unavailable, another server continues processing requests.


Disaster Recovery

Despite strong infrastructure, failures can still occur.

Examples include:

  • Data center outage
  • Hardware failure
  • Network disruption
  • Natural disaster
  • Power interruption

Disaster recovery plans help restore payment services quickly.


Disaster Recovery Flow

flowchart LR

Primary

Primary --> Failure

Failure --> Backup

Backup --> Recovery

Scalability

UPI processes extremely high transaction volumes during:

  • Festivals
  • Shopping events
  • Salary days
  • Utility bill due dates
  • Government payment programs

The platform must scale without affecting customer experience.

Scalability strategies include:

  • Horizontal infrastructure expansion
  • Distributed processing
  • Efficient request routing
  • Load balancing
  • Continuous capacity planning

Load Distribution

flowchart LR

Customers

Customers --> LoadBalancer

LoadBalancer --> ServerA

LoadBalancer --> ServerB

LoadBalancer --> ServerC

Load balancing distributes traffic across multiple servers, preventing any single server from becoming overloaded.


Monitoring

Operations teams continuously monitor:

  • Transaction success rate
  • Processing latency
  • System availability
  • Error rates
  • Network health
  • Bank connectivity
  • Settlement processing

Monitoring enables rapid detection of operational issues.


Operational Dashboard

Common dashboard metrics include:

  • Total transactions
  • Successful transactions
  • Failed transactions
  • Transactions per minute
  • Average response time
  • Active participating banks
  • Fraud alerts
  • Open incidents
  • System availability

Performance KPIs

KPI Description
Transaction Success Rate Percentage of successful transactions
Average Response Time Average payment processing time
System Availability Platform uptime
Fraud Detection Rate Fraud identified before financial loss
Failed Transaction Rate Percentage of unsuccessful transactions
Incident Resolution Time Average time to resolve operational issues
Average Recovery Time Time to restore service after failure
Customer Complaint Rate Operational quality indicator

Common Operational Failures

Operations teams commonly investigate:

  • Bank server downtime
  • Network failures
  • NPCI connectivity issues
  • Delayed responses
  • High transaction volume
  • Merchant connectivity issues
  • Incorrect customer authentication
  • System maintenance windows

Incident Management Lifecycle

flowchart LR

Alert

Alert --> Investigation

Investigation --> Resolution

Resolution --> Verification

Verification --> Closure

Operational Best Practices

Organizations should:

  • Monitor systems continuously
  • Encrypt sensitive information
  • Perform regular security reviews
  • Maintain disaster recovery plans
  • Monitor fraud trends
  • Review operational dashboards
  • Test backup systems regularly
  • Educate customers about payment safety
  • Perform capacity planning
  • Continuously improve security controls

Customer Safety Tips

Customers should:

  • Verify merchant names before paying
  • Never share the UPI PIN
  • Avoid unknown payment links
  • Download only official banking applications
  • Report suspicious transactions immediately
  • Keep mobile applications updated

These simple practices significantly reduce fraud risk.


Real-World Business Scenario

A major online retailer experiences a surge in UPI payments during a national festival sale.

During peak hours:

  1. Millions of customers initiate payments simultaneously.
  2. Load balancers distribute incoming requests across multiple application servers.
  3. PSP Banks validate customer requests and forward them to NPCI.
  4. Fraud monitoring systems identify unusual transaction patterns and block suspicious requests.
  5. Issuing banks authenticate customers using device verification and UPI PIN validation.
  6. One application server experiences an unexpected hardware failure.
  7. Automatic failover redirects traffic to healthy servers without interrupting ongoing transactions.
  8. Monitoring dashboards detect the incident, and operations teams begin investigation immediately.
  9. The failed server is restored while payment processing continues uninterrupted.
  10. Customers continue completing transactions without noticing the infrastructure issue.

This demonstrates how security, monitoring, scalability, and high availability work together to provide a reliable payment experience.


Key Takeaways

  • Security is fundamental to every UPI transaction.
  • Multi-factor authentication combines trusted devices and UPI PIN verification.
  • Device binding helps prevent unauthorized access.
  • Encryption protects payment information during transmission.
  • Fraud detection systems continuously monitor transaction behavior.
  • High availability and disaster recovery help maintain uninterrupted payment services.
  • Monitoring, scalability, and operational best practices enable UPI to support very high transaction volumes.

Business Interview Questions

  1. Why is security critical in UPI?
  2. What is multi-factor authentication in UPI?
  3. What is device binding?
  4. How is the UPI PIN protected?
  5. What role does encryption play in UPI?
  6. How do banks detect fraudulent UPI transactions?
  7. Why are transaction limits important?
  8. How does high availability improve payment reliability?
  9. What is the purpose of disaster recovery in payment systems?
  10. Which operational KPIs are commonly monitored in UPI platforms?

Reference Guide & Interview Preparation

Congratulations! You have completed the UPI Architecture series.

You now understand how one of the world's largest real-time payment systems enables secure, instant bank-to-bank payments while handling billions of transactions every month.

UPI has transformed digital payments by providing:

  • Real-time fund transfers
  • Interoperability between banks
  • Mobile-first payments
  • QR code payments
  • Merchant payments
  • Secure authentication
  • Scalable infrastructure

This chapter summarizes the entire UPI ecosystem and serves as a quick reference guide for Banking and FinTech professionals preparing for interviews.


Learning Objectives

By the end of this chapter, you'll be able to:

  • Explain the complete UPI lifecycle
  • Compare UPI with other payment systems
  • Understand important UPI terminology
  • Identify operational best practices
  • Understand future trends
  • Review business KPIs
  • Prepare for Banking and FinTech interviews

Complete UPI Lifecycle

flowchart LR

Customer

Customer --> UPIApp

UPIApp --> PSPBank

PSPBank --> NPCI

NPCI --> IssuerBank

IssuerBank --> BeneficiaryBank

BeneficiaryBank --> Merchant

Merchant --> Settlement

Settlement --> Reconciliation

End-to-End UPI Transaction Lifecycle

flowchart LR

Initiation

Initiation --> Authentication

Authentication --> Authorization

Authorization --> Debit

Debit --> Credit

Credit --> Settlement

Settlement --> Reconciliation

Reconciliation --> Reporting

UPI Ecosystem

flowchart LR

Customer

Customer --> UPIApp

UPIApp --> PSPBank

PSPBank --> NPCI

NPCI --> IssuerBank

NPCI --> BeneficiaryBank

BeneficiaryBank --> Merchant

Complete Payment Journey

Step Activity
1 Customer initiates payment
2 UPI App creates payment request
3 PSP Bank validates request
4 NPCI routes payment
5 Issuer Bank authenticates customer
6 Customer account is debited
7 Beneficiary Bank receives request
8 Merchant account is credited
9 Settlement between participating banks
10 Reconciliation and reporting

UPI vs IMPS

UPI IMPS
Uses Virtual Payment Address Uses Account Number and IFSC
Mobile-first platform Traditional banking channels
Supports QR payments No native QR support
Supports Collect Requests Primarily push transfers
Better customer experience More banking-oriented

UPI vs NEFT

UPI NEFT
Real-time payments Batch-based settlement
Mobile-first Traditional banking transfers
Ideal for daily payments Suitable for bank transfers
Uses UPI ID Uses Account Number and IFSC
Simple user experience More banking details required

UPI vs RTGS

UPI RTGS
Everyday retail payments High-value transfers
Instant user experience Real-time gross settlement
Mobile applications Banking channels
Consumer-focused Enterprise and large-value transactions
Supports QR payments No QR payments

UPI vs Credit Cards

UPI Credit Card
Direct bank account payment Credit-based payment
Immediate account debit Bill paid later
UPI PIN authentication Card PIN or OTP authentication
No physical card required Physical or virtual card
Bank-to-bank transfer Card network transaction

UPI vs Digital Wallets

UPI Wallet
Linked directly to bank account Requires wallet balance or funding
No need to preload money Often requires loading funds
Bank interoperability Wallet ecosystem dependent
Real-time account transfer Wallet-to-wallet transfers common
Wide bank participation Depends on wallet provider

Push vs Pull Payments

Push Payment Pull Payment
Initiated by payer Initiated by payee
Customer sends money Merchant requests payment
Common for retail purchases Common for bill collection
Immediate authorization Customer approval required

Person-to-Person vs Person-to-Merchant

P2P P2M
Individual to individual Customer to merchant
Personal transfers Business payments
Family and friends Retail purchases
Expense sharing Commercial transactions

Static QR vs Dynamic QR

Static QR Dynamic QR
Merchant details only Merchant and transaction details
Customer enters amount Amount is pre-filled
Simple implementation Better for invoicing
Small merchants Organized retail and e-commerce

UPI Services

UPI supports many financial services.

Examples include:

  • Person-to-Person transfers
  • Merchant payments
  • QR payments
  • Bill payments
  • Mobile recharge
  • Subscription payments
  • Government payments
  • Educational fee payments
  • E-commerce payments
  • Collect Requests

UPI Participants

Participant Responsibility
Customer Initiates payment
Merchant Receives payment
UPI App Customer interface
PSP Bank Payment processing
NPCI Transaction switching
Issuer Bank Debits customer account
Beneficiary Bank Credits recipient account
RBI Final interbank settlement

Important UPI Terminology

Term Meaning
UPI Unified Payments Interface
NPCI National Payments Corporation of India
RBI Reserve Bank of India
PSP Bank Payment Service Provider Bank
VPA Virtual Payment Address
UPI ID Customer payment identity
QR Code Machine-readable payment code
Collect Request Payment request initiated by payee
Push Payment Payment initiated by payer
Reversal Return of funds after processing failure
Refund Return of funds after successful payment
Settlement Transfer of funds between banks
Reconciliation Matching financial records

Common Transaction Status

Status Meaning
Initiated Payment started
Processing Validation in progress
Authorized Approved by issuing bank
Debited Customer account debited
Credited Beneficiary account credited
Successful Payment completed
Failed Payment unsuccessful
Reversed Amount returned

Common Failure Reasons

Payment failures may occur because of:

  • Incorrect UPI PIN
  • Insufficient balance
  • Bank server unavailable
  • Network interruption
  • Invalid UPI ID
  • Transaction limit exceeded
  • Beneficiary bank unavailable
  • Scheduled maintenance

Operations teams investigate failures and process reversals when necessary.


Operational Dashboards

Typical dashboard metrics include:

  • Total transactions
  • Successful payments
  • Failed payments
  • Average response time
  • Transactions per minute
  • Fraud alerts
  • Settlement status
  • Open incidents
  • System availability
  • Reconciliation status

Business KPIs

KPI Description
Transaction Success Rate Successful payment percentage
Average Response Time Payment processing speed
Settlement Success Rate Successfully settled transactions
Reconciliation Match Rate Correctly matched records
Fraud Detection Rate Fraud identified before financial loss
Failed Transaction Rate Unsuccessful payment percentage
Average Recovery Time Disaster recovery efficiency
Incident Resolution Time Operational issue resolution time
Customer Complaint Rate Customer service quality indicator

Best Practices

Organizations should:

  • Monitor systems continuously
  • Encrypt sensitive payment information
  • Perform reconciliation daily
  • Maintain complete audit trails
  • Detect fraud proactively
  • Monitor transaction performance
  • Test disaster recovery regularly
  • Educate customers about payment safety
  • Review operational dashboards
  • Continuously improve payment infrastructure

Business Challenges

Large-scale payment systems must manage:

  • Rapid transaction growth
  • High availability
  • Fraud prevention
  • Cross-bank interoperability
  • Peak traffic during festivals
  • Regulatory compliance
  • Customer expectations
  • Operational efficiency

Future Trends

AI-Powered Fraud Detection

Artificial Intelligence is increasingly used for:

  • Fraud prediction
  • Customer behavior analysis
  • Risk scoring
  • Transaction monitoring

Real-Time Risk Engines

Banks continue investing in:

  • Instant fraud detection
  • Dynamic transaction scoring
  • Intelligent authorization decisions

International Payment Integration

Future payment ecosystems may support:

  • Faster international payments
  • Better interoperability
  • Cross-border payment innovation

Digital Identity

Emerging technologies continue improving:

  • Customer verification
  • Identity management
  • Authentication methods

Cloud-Native Payment Platforms

Modern payment providers are adopting cloud technologies to improve:

  • Scalability
  • Reliability
  • Disaster recovery
  • Operational efficiency

Complete Business Scenario

A national retail chain processes 2 million UPI transactions during a festive shopping event.

  1. Customers make payments using QR codes through different UPI applications.
  2. PSP Banks receive payment requests and forward them to NPCI.
  3. NPCI routes transactions to the respective issuing and beneficiary banks.
  4. Issuing banks authenticate customers and authorize debits.
  5. Beneficiary banks credit merchant accounts and return successful responses.
  6. Throughout the day, fraud monitoring systems analyze transaction patterns and identify suspicious activity.
  7. NPCI calculates net obligations among participating banks.
  8. RBI performs interbank settlement.
  9. Finance teams reconcile settlement reports with bank records.
  10. Operations teams resolve exceptions and generate regulatory and business reports.

Despite processing millions of payments, customers experience near-instant confirmation because the ecosystem is designed for scalability, resilience, and continuous monitoring.


Learning Checklist

After completing this series, you should be able to explain:

  • ✅ UPI architecture
  • ✅ NPCI ecosystem
  • ✅ PSP Bank responsibilities
  • ✅ Issuer and Beneficiary Bank roles
  • ✅ Virtual Payment Address (VPA)
  • ✅ UPI ID
  • ✅ Payment initiation
  • ✅ Authentication
  • ✅ UPI PIN validation
  • ✅ NPCI switching
  • ✅ Push and Pull payments
  • ✅ QR Code payments
  • ✅ P2P and P2M transactions
  • ✅ Settlement lifecycle
  • ✅ Reconciliation process
  • ✅ Refunds and reversals
  • ✅ Fraud detection
  • ✅ High availability
  • ✅ Disaster recovery
  • ✅ Operational dashboards
  • ✅ Performance KPIs

Banking & FinTech Interview Questions

Fundamentals

  1. What is UPI?
  2. Why was UPI introduced?
  3. What is the role of NPCI?
  4. What is a PSP Bank?
  5. What is a Virtual Payment Address (VPA)?

Transaction Flow

  1. Explain the end-to-end UPI transaction flow.
  2. How is the UPI PIN validated?
  3. What is the role of the issuing bank?
  4. What is the role of the beneficiary bank?
  5. What happens after a successful authorization?

Settlement & Reconciliation

  1. How are UPI transactions settled?
  2. What is the role of RBI in settlement?
  3. What is net settlement?
  4. What is reconciliation?
  5. What is the difference between a refund and a reversal?

Security

  1. What security controls protect UPI transactions?
  2. What is device binding?
  3. How do banks detect fraudulent transactions?
  4. Why is encryption important?
  5. What are common payment risks?

Architecture

  1. What is the difference between UPI and IMPS?
  2. How does UPI differ from NEFT?
  3. How does UPI differ from RTGS?
  4. Why is UPI considered a real-time payment system?
  5. What are the responsibilities of NPCI?

Operations

  1. What operational KPIs are monitored?
  2. How does high availability improve payment reliability?
  3. What is disaster recovery?
  4. How do operations teams handle failed transactions?
  5. What best practices improve UPI operations?

Series Summary

Congratulations!

You have completed the UPI Architecture series and gained a comprehensive understanding of one of the world's most advanced real-time payment systems.

You now understand:

  • UPI ecosystem and architecture
  • Roles of NPCI, RBI, PSP Banks, Issuer Banks, and Beneficiary Banks
  • End-to-end transaction processing
  • Payment authorization and routing
  • Settlement and reconciliation
  • Security, fraud prevention, and risk management
  • Scalability and operational monitoring
  • Business KPIs and operational best practices

This knowledge provides a strong foundation for careers in:

  • Banking
  • FinTech
  • Digital Payments
  • Merchant Acquiring
  • Payment Gateways
  • Core Banking
  • Payment Operations
  • Financial Technology
  • Solution Architecture
  • Business Analysis