The Deposits Nobody Reported — Python Bug Hunt

Modelled on the Commonwealth Bank of Australia AUSTRAC case (filed August 2017): AUSTRAC alleged that CBA's Intelligent Deposit Machines failed to send…

  • Language: Python
  • Layer: Backend
  • Difficulty: Easy
  • Concepts: Validation, Money, Config
  • Modelled on: Commonwealth Bank · 2017
  • Visible tests: a teller cash deposit of $10,000 is reported; a deposit-machine cash deposit over the threshold is reported
  • Reward: 50 XP for a complete fix

Briefing

Modelled on the Commonwealth Bank of Australia AUSTRAC case (filed August 2017): AUSTRAC alleged that CBA's Intelligent Deposit Machines failed to send 53,506 threshold transaction reports for cash deposits of $10,000 or more between 2012 and 2015. CBA attributed the failure to a coding error introduced by a 2012 software update to the machines. The bank later agreed to a A$700 million penalty. This project reconstructs that kind of error: the update gave machine deposits their own transaction code, and the reporting rule still keys on the old one.

ttr.py decides which transactions need a threshold transaction report (TTR). Deposit-machine cash deposits carry their own code in codes.py.

Fix needs_ttr so every cash deposit at or above the threshold is reported, whichever channel it came through.

Bug report

BUG-TTR · Priority: Critical (regulatory) · Reported by: financial crime compliance

needs_ttr(txn) is True exactly when:

  • txn["type"] is a cash-deposit code — any code in codes.CASH_DEPOSIT_CODES (teller AND deposit-machine), and
  • txn["amount_cents"] >= codes.THRESHOLD_CENTS (AUD 10,000.00 exactly counts)

Card payments, transfers and anything else never need a TTR. reports_due(txns) returns the ids of the transactions needing one, in input order.

Observed: cash deposits made at deposit machines are never reported.

Logs

[aml] batch 2015-09-01 txns=48211 ttr_due=3
[aml] idm=IDM-0412 type=CD07 amount=2000000 ttr=false

The code as shipped

src/aml/ttr.py (editable)

codes = bug_require("src/aml/codes.py")


def needs_ttr(txn):
    return (
        txn["type"] == codes.TELLER_CASH_DEPOSIT
        and txn["amount_cents"] >= codes.THRESHOLD_CENTS
    )


def reports_due(txns):
    return [t["id"] for t in txns if needs_ttr(t)]

Read-only context: src/aml/codes.py.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.