Device bind, then a different limit
A newly bound phone can inherit a higher band, skip a cooling-off, or reuse an old session token. Transfer-path reconstructions start with the device event, not only the debit.
Transaction paths
A working reference we use to frame reconstructions and walkthroughs—not a generic controls catalogue.
Each point names the usual story, the evidence we look for, and the engagement that clarifies it.
A newly bound phone can inherit a higher band, skip a cooling-off, or reuse an old session token. Transfer-path reconstructions start with the device event, not only the debit.
Transfer approval judges the instruction. It rarely asks whether the account number changed last night. Payee-integrity reviews sit before the trail you are proud of.
The policy wall shows one daily cap. The application may apply another after a product flag or a scheduled transfer. Limit testing asks which stop is hard.
Initiate, amend, approve, and release can sit on a single staff or privileged-customer account even when the organisation chart looks clean. A maker-checker walkthrough names the accounts.
Limit screens print a message users can tap past. Exception testing asks whether over-limit and split instructions actually stop, including after-hours windows.
Reversal and unlock buttons are not the failure. Unreviewed logs are. Privileged-function examinations sample the exceptions and ask who last opened the report.
Pick the point closest to the debate in your next sitting, then request the matching engagement. The map frames the sample; it does not replace your application data.
Which mobile banking build your customers use, and which committee or Bank Negara paper you are preparing.
We confirm whether the usual story fits, or whether a different point better explains the instructions.
Reconstruction, walkthrough, payee review, limit testing, or privileged-function examination—scoped to the decision you need to table.