About Approach Capabilities Case Studies
Financial Services Government Healthcare Transport Energy & Utilities Telecommunication
Contact Book a Consultation
Case Studies Financial Services

Architecting Zero-Trust Core Ecosystems for
Regulated Banking Infrastructures

Client Regulated Banking Institution
Asia-Pacific Region
Industry Financial Services
Core Banking Infrastructure
Timeline 18 Months
Phased Delivery Model
Deployment Vector Singapore Strategic Hub
→ Nepal Engineering Node
Regulated banking financial district infrastructure
Critical Point of System Failure

A $2.4B regulatory exposure window. Zero architectural traceability. 14 competing delivery squads with no unified ownership model.

Regulatory Compliance Matrix

The institution operated under simultaneous audit obligations from MAS Technology Risk Management Guidelines, Basel III operational risk frameworks, and a SWIFT CSP attestation cycle. Each required distinct data lineage controls the existing architecture could not satisfy — creating compounding liability across every delivery workstream.

Legacy Architectural Technical Debt

Core banking systems spanning three vendor platforms — two on legacy COBOL stacks — were interconnected via point-to-point integrations with no API governance. Over 6,200 undocumented integration touchpoints prevented any systematic modernisation without catastrophic service disruption risk.

Scalability Boundaries

Peak transaction throughput was capped at 48,000 TPS — insufficient for the institution's 2027 volume targets of 190,000 TPS. Horizontal scaling was architecturally blocked by stateful session dependencies hardwired into the core settlement engine.

Engineering Implementation Matrix

Multi-Stack Solution Architecture Executed Across Dual-Hub Squads

01

Zero-Trust Network Segmentation & Identity Fabric

Deployed a service mesh across 14 microservice domains using Istio with mTLS enforcement at every east-west traffic boundary. Identity federation via SPIFFE/SPIRE replaced legacy IP-based trust zones. The Singapore hub owned architecture design authority; the Nepal engineering node executed full infrastructure provisioning and automated policy validation pipelines.

Istio SPIFFE / SPIRE mTLS Zero-Trust
02

Sovereign Data Pipeline Configuration

Engineered a custom data sovereignty layer routing classified financial telemetry exclusively through MAS-compliant Singapore data centres, with a separate high-throughput pipeline for non-classified operational data processed by the Nepal engineering node. Apache Kafka clusters with field-level encryption ensured zero cross-contamination between data classifications at 190,000 TPS design load.

Apache Kafka Field-Level Encryption Data Sovereignty Schema Registry
03

API Governance Layer & Integration Rationalisation

Systematically catalogued and rationalised 6,200+ legacy integration touchpoints, collapsing them into 218 governed API endpoints documented to OpenAPI 3.1 specification. Kong Gateway was deployed as the enterprise API management layer with rate limiting, circuit breakers, and automated compliance tagging aligned to MAS TRM control IDs — enabling full audit traceability for every API call crossing a compliance boundary.

Kong Gateway OpenAPI 3.1 MAS TRM Circuit Breaker
04

Architecture-Led Programme Governance Model

Established a Crestha Architecture Decision Record framework embedded directly into the delivery CI/CD pipeline — every infrastructure change required an ADR approval gate before merge. The Nepal engineering node operated autonomous sprint delivery within Crestha's governance model, with architecture authority enforced by the Singapore hub through automated compliance policy-as-code checks running on every pull request.

ADR Framework Policy-as-Code ArgoCD CI / CD
Verified Delivery Outcomes
99.997%

Core Banking Uptime sustained across the full 18-month programme delivery, including two major platform cutovers

−42%

Transaction Latency Reduction — P99 settlement time dropped from 340ms to 197ms at full 190,000 TPS load

Zero

Compliance Deviations — first institution to achieve MAS TRM + Basel III + SWIFT CSP attestation in a single audit cycle

6,218→218

Integration Rationalisation — legacy touchpoints collapsed to governed API endpoints, reducing risk surface by 96.5%

Programme Details

Dual-Hub Architecture Across Singapore & Nepal

Dual-Hub Delivery Model

Singapore strategic hub held architecture authority and client governance. Nepal engineering node executed 68% of total build throughput across 9 concurrent squads on a 24-hour asynchronous delivery cycle.

Regulatory Coverage

MAS TRM Guidelines · Basel III Operational Risk · SWIFT CSP Attestation · PDPA Data Residency · PCI-DSS Level 1

Technology Stack

Istio · Apache Kafka · Kong Enterprise · HashiCorp Vault · Terraform · ArgoCD · SPIFFE/SPIRE · PostgreSQL HA · AWS GovCloud SG · Kubernetes 1.28