Regulatory Compliance Matrix
The institution operated under simultaneous audit obligations from MAS Technology Risk Management Guidelines, Basel III operational risk frameworks, and a SWIFT CSP attestation cycle. Each required distinct data lineage controls the existing architecture could not satisfy — creating compounding liability across every delivery workstream.
Legacy Architectural Technical Debt
Core banking systems spanning three vendor platforms — two on legacy COBOL stacks — were interconnected via point-to-point integrations with no API governance. Over 6,200 undocumented integration touchpoints prevented any systematic modernisation without catastrophic service disruption risk.
Scalability Boundaries
Peak transaction throughput was capped at 48,000 TPS — insufficient for the institution's 2027 volume targets of 190,000 TPS. Horizontal scaling was architecturally blocked by stateful session dependencies hardwired into the core settlement engine.
Deployed a service mesh across 14 microservice domains using Istio with mTLS enforcement at every east-west traffic boundary. Identity federation via SPIFFE/SPIRE replaced legacy IP-based trust zones. The Singapore hub owned architecture design authority; the Nepal engineering node executed full infrastructure provisioning and automated policy validation pipelines.
Engineered a custom data sovereignty layer routing classified financial telemetry exclusively through MAS-compliant Singapore data centres, with a separate high-throughput pipeline for non-classified operational data processed by the Nepal engineering node. Apache Kafka clusters with field-level encryption ensured zero cross-contamination between data classifications at 190,000 TPS design load.
Systematically catalogued and rationalised 6,200+ legacy integration touchpoints, collapsing them into 218 governed API endpoints documented to OpenAPI 3.1 specification. Kong Gateway was deployed as the enterprise API management layer with rate limiting, circuit breakers, and automated compliance tagging aligned to MAS TRM control IDs — enabling full audit traceability for every API call crossing a compliance boundary.
Established a Crestha Architecture Decision Record framework embedded directly into the delivery CI/CD pipeline — every infrastructure change required an ADR approval gate before merge. The Nepal engineering node operated autonomous sprint delivery within Crestha's governance model, with architecture authority enforced by the Singapore hub through automated compliance policy-as-code checks running on every pull request.
Core Banking Uptime sustained across the full 18-month programme delivery, including two major platform cutovers
Transaction Latency Reduction — P99 settlement time dropped from 340ms to 197ms at full 190,000 TPS load
Compliance Deviations — first institution to achieve MAS TRM + Basel III + SWIFT CSP attestation in a single audit cycle
Integration Rationalisation — legacy touchpoints collapsed to governed API endpoints, reducing risk surface by 96.5%
Singapore strategic hub held architecture authority and client governance. Nepal engineering node executed 68% of total build throughput across 9 concurrent squads on a 24-hour asynchronous delivery cycle.
MAS TRM Guidelines · Basel III Operational Risk · SWIFT CSP Attestation · PDPA Data Residency · PCI-DSS Level 1
Istio · Apache Kafka · Kong Enterprise · HashiCorp Vault · Terraform · ArgoCD · SPIFFE/SPIRE · PostgreSQL HA · AWS GovCloud SG · Kubernetes 1.28