0% found this document useful (0 votes)
56 views119 pages

Understanding Enterprises and Business Processes

The document provides an overview of enterprises, information systems, and business processes, detailing their definitions, types, and functions. It emphasizes the importance of Enterprise Information Systems (EIS) in integrating processes across organizations to enhance efficiency, decision-making, and collaboration. Additionally, it discusses Business Process Automation (BPA), its goals, benefits, and implementation challenges, highlighting the transformative impact of EIS on business processes.

Uploaded by

i235509
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
56 views119 pages

Understanding Enterprises and Business Processes

The document provides an overview of enterprises, information systems, and business processes, detailing their definitions, types, and functions. It emphasizes the importance of Enterprise Information Systems (EIS) in integrating processes across organizations to enhance efficiency, decision-making, and collaboration. Additionally, it discusses Business Process Automation (BPA), its goals, benefits, and implementation challenges, highlighting the transformative impact of EIS on business processes.

Uploaded by

i235509
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Week – 1

1. What is an Enterprise?

• Definition: An enterprise is any organization or business entity working towards specific


goals within a framework of resources and strategies.
• Types of Enterprises:
o SME (Small and Medium Enterprises): Businesses with limited scale, fewer
employees, and lower revenue.
▪ Example: A local bakery, a boutique marketing agency, or a small law
firm.
o Large Enterprises: Organizations with massive operations, huge revenue, and
large workforces.
▪ Example: Multinational corporations like Coca-Cola, Toyota, or Google.
o Government Enterprises: Public sector organizations that provide essential
services.
▪ Example: Utilities (WAPDA), Transportation (Metro Bus), or Public
Health Services.
o Non-Profit Enterprises: Organizations focused on social or charitable goals, not
profit.
▪ Example: Edhi Foundation, Red Cross, or educational trusts.
o Startups: Newly established businesses focused on innovation and high growth.
▪ Example: A new AI software company or a FinTech app looking for
funding.

2. Information: The Core Asset

• Definition: Data that has been processed to be meaningful and useful for decision-
making.
• Types of Information:
o Operational Information: Data regarding day-to-day tasks.
▪ Example: Today's inventory levels, daily sales receipts, or specific
customer orders.
o Strategic Information: Data used for long-term planning and high-level
decisions.
▪ Example: 5-year financial forecasts, competitor analysis, or global market
trends.
o Tactical Information: Data for short-term planning and control.
▪ Example: Weekly staff schedules, monthly project budgets, or resource
allocation plans.
o Historical Information: Archived data from the past used for trend analysis.
▪ Example: Comparing 2023 sales vs. 2024 sales to see growth.
o Real-Time Information: Up-to-the-minute data for immediate action.
▪ Example: Live stock market feeds, Uber driver tracking, or real-time
supply chain logistics.

3. Systems Overview

• Definition: A set of components (technology, people, procedures) working together to


achieve a goal.
• Types of Systems:
o Information Systems (IS): Collects and processes info.
▪ Example: A student portal that stores grades and attendance.
o Business Systems: Manages specific functions.
▪ Example: A dedicated Accounting System like QuickBooks.
o Operational Systems: Handles core production/logistics.
▪ Example: An assembly line control system in a car factory.
o Decision Support Systems (DSS): Tools for complex decision-making.
▪ Example: A bank's loan approval system that analyzes credit risk.

4. Enterprise Information Systems (EIS)

• Definition: Large-scale systems that integrate processes and information across the entire
organization to facilitate coordination.
• Types of EIS:
o ERP (Enterprise Resource Planning): The "Backbone" integrating core
functions.
▪ Example: SAP or Oracle managing Finance, HR, and Procurement in one
place.
o CRM (Customer Relationship Management): Manages interactions with
clients.
▪ Example: Salesforce tracking sales leads and customer support tickets.
o SCM (Supply Chain Management): Manages the flow of goods.
▪ Example: A system tracking raw materials from a mine in Africa to a
factory in China.
o HRM (Human Resource Management): Manages employee lifecycle.
▪ Example: Workday handling payroll, recruitment, and performance
reviews.
o BI (Business Intelligence): Analyzes data for insights.
▪ Example: Tableau or PowerBI dashboards showing sales heatmaps.
o KMS (Knowledge Management Systems): Shares internal expertise.
▪ Example: An internal Wiki or Confluence page where employees
document how to solve common problems.

5. Key Functions of EIS

• A. Data Management (Single Source of Truth):


o Function: Centralizes data so everyone sees the same thing.
o Example: If Sales updates a customer's address, the Shipping department sees the
new address instantly. No "version conflicts".
• B. Transaction Processing:
o Function: Automates routine tasks.
o Example: Automatically generating invoices and emailing them to customers the
moment an order is shipped, instead of a human typing them out.
• C. Decision Support:
o Function: Turns "Big Data" into actionable insights.
o Example: Instead of just showing a list of sales, the system warns managers:
"Sales in the North Region are down 15% this month due to weather".
• D. Communication & Collaboration:
o Function: Connects departments.
o Example: A workflow tool where a "Leave Request" from an employee is
automatically routed to their manager's phone for approval.

6. Strategic Importance of EIS

• Alignment: Ensures IT supports business goals.


o Example: If the goal is "Global Expansion," the EIS supports multi-currency and
multi-language transactions.
• Operational Efficiency: Reduces costs by automating tasks.
o Example: Cutting admin costs by 30% by automating payroll calculations.
• Personalized Experience: Uses data to tailor services.
o Example: Netflix or Amazon recommending products based on what you bought
previously.
• Innovation Enablement: Provides a foundation for new ideas.
o Example: A bank using its robust EIS to launch a new "Digital Wallet" product
quickly.
Week – 2

1. What is a Business Process?

• Definition: A series of interconnected steps or activities performed by stakeholders


(people or systems) to achieve a specific, concrete goal.
• Key Characteristics:
o Input: The trigger (e.g., Customer places order).
o Value Creation: It must create value for a customer or the business.
o Repeatable: It happens the same way every time.
• Real-World Example: "Order Fulfillment"
o Input: Order received on website.
o Process: Check stock → Process payment → Pack item → Ship.
o Output: Customer receives package.

2. The Three Types of Business Processes

You must classify processes into these three categories.

A. Operational Processes (Core Processes)

• Definition: The primary processes that directly create value and generate revenue. The
"heart" of the business.
• Example:
o Manufacturing: Turning raw steel into a car.
o Sales: Taking an order and serving the food in a restaurant.

B. Supporting Processes

• Definition: Processes that do not generate revenue directly but are necessary to support
the core team.
• Example:
o HR: Hiring the factory workers (HR doesn't build the car, but they hire the people
who do).
o IT Support: Fixing the email server so Sales can work.

C. Management Processes

• Definition: Processes related to governing, planning, and overseeing the strategy.


• Example:
o Budgeting: Allocating funds for the next year.
o Compliance: Ensuring the factory meets safety laws.
3. The Business Process Lifecycle (7 Steps)

The standard cycle for creating and managing a process.

Step 1: Define Your Goals

• Concept: Clearly state what the process is supposed to achieve.


• Example: "The goal is to reduce the time it takes to onboard a new employee from 10
days to 3 days."

Step 2: Plan and Map the Process

• Concept: Create a roadmap or diagram showing every step. Identify the stakeholders.
• Example: Drawing a flowchart that shows: HR sends offer letter → Candidate signs →
IT creates email account → Facilities issues ID card.

Step 3: Set Actions and Assign Stakeholders

• Concept: Assign specific tasks to specific people or machines. Who does what?
• Example: The "IT Manager" is assigned the task of "Create Email," and the "Security
Officer" is assigned "Issue Keycard."

Step 4: Test the Process

• Concept: Run the process on a small scale to find bugs or gaps before going live.
• Example: Running a "Mock Onboarding" with a dummy candidate to see if the IT system
actually sends the welcome email correctly.

Step 5: Implement the Process

• Concept: Roll it out to the live environment.


• Example: Officially using the new digital onboarding system for all new hires starting
from Monday.

Step 6: Monitor Results

• Concept: Review the data. Is the process working as planned? Are there bottlenecks?
• Example: Checking the logs after one month and realizing that "Issuing ID Cards" is still
taking 5 days (a bottleneck) because the printer is broken.

Step 7: Repeat (Continuous Improvement)

• Concept: If it works, keep doing it. If it failed, go back to Step 1 and fix it.
• Example: Fixing the ID card printer and updating the process so the Security Officer gets
an alert 2 days earlier.

1. What is Business Process Automation (BPA)?

• Definition: BPA is the strategy of using technology to execute recurring tasks or


processes where manual effort can be replaced. It involves taking a manual, paper-based,
or email-based process and routing it through software that executes the steps
automatically.
• Core Concept: It shifts the responsibility of "moving the work" from humans to
machines.
• Example: Instead of an employee physically carrying a "Leave Request Form" to a
manager's desk for a signature, a BPA system automatically emails the manager a "Click
to Approve" button.

2. Goals of BPA

Why do companies do this?

1. Efficiency: To remove bottlenecks and speed up turnaround time.


2. Standardization: To ensure the process happens the exact same way every single time
(no skipping steps).
3. Transparency: To allow managers to see exactly where a task is stuck (e.g., "The
contract has been sitting with Legal for 4 days").
4. Compliance: To create an unchangeable digital audit trail (proving who approved what
and when).

3. Which Processes are Useful for Automation?

Not everything should be automated. You look for processes that meet these criteria:

• High Volume: Tasks that happen hundreds of times (e.g., Invoice Processing).
• Repetitive: The steps never change (e.g., Employee Onboarding).
• Rule-Based: Decisions can be made with simple logic (e.g., "If value < $50, approve
automatically. If > $50, send to Manager").
• Time-Sensitive: Processes that need to happen fast (e.g., Stock trading or Fraud alerts).

4. Technologies Used in BPA

• RPA (Robotic Process Automation): "Bots" that mimic human clicks. They can open
an email attachment, copy the data, and paste it into Excel.
• Workflow Engines: Software that routes tasks from Person A to Person B (e.g.,
SharePoint, ServiceNow).
• AI & OCR: Using AI to "read" documents (Optical Character Recognition) like
scanning a PDF invoice and extracting the tax amount automatically.
• Integration (APIs): Connecting different systems so they talk directly (e.g., The Website
automatically telling the Warehouse system to pack an order).

5. Benefits of BPA

• Cost Reduction: Robots are cheaper than humans for data entry.
• Error Reduction: Machines don't make typos or get tired.
• Employee Morale: Removes "boring" work so humans can focus on creative or strategic
tasks.
• Faster Service: Customers get answers instantly (e.g., auto-approval of refunds) rather
than waiting days.

6. Steps to Implement BPA (The Roadmap)

1. Identify the Process: Find the pain points. Look for processes where people complain
about delays or errors.
2. Analyze & Optimize (Crucial): Do not automate a bad process. Simplify the steps
first. If a form has 5 useless fields, delete them before building the bot.
3. Select the Tool: Choose the right software (RPA vs. Workflow tool).
4. Develop & Test: Build the automation and test it on a small scale to ensure it handles
"edge cases" (e.g., what happens if the data is missing?).
5. Change Management: Train the staff. Explain that the bot is here to help them, not fire
them, to reduce resistance.
6. Monitor & Scale: Track the results. If successful, apply the same logic to other
departments.

7. Challenges of BPA

• Resistance to Change: Employees often fear automation means layoffs. This culture
clash can kill a project.
• Complexity: Some human processes are too subtle for machines (e.g., "judging if a
candidate fits the company culture").
• Integration Issues: Connecting old "Legacy Systems" (that don't have APIs) to modern
automation tools is difficult.
• The "Automating Bad Processes" Trap: If you automate a messy process, you just
create a "fast mess." You must fix the process logic before applying technology.

Impact of EIS on Business Processes

This topic is often tested as a "Before vs. After" comparison.

1. The Core Shift: From Silos to Integration

• Before EIS (Siloed): Departments (Sales, Warehouse, Finance) worked in isolation.


They had their own separate databases and "handed off" paper or emails to the next team.
This caused delays and data errors.
• After EIS (Integrated): The process flows horizontally across the organization. All
departments share one central database.
• Impact: The "walls" between departments are removed.
2. Key Impacts on Business Processes
A. Data Integrity & "Single Source of Truth"

• The Change: Before EIS, Sales might say "We have 10 items" while the Warehouse says
"We have 8."
• The Impact: EIS forces everyone to look at the same number. If a salesperson sells an
item, the inventory count drops for everyone instantly.
• Example: A customer calls support to ask about their order status. In the old system,
support would have to call the warehouse. With EIS, support sees the tracking number
and location on their screen immediately.

B. Process Efficiency (Speed & Automation)

• The Change: Manual "hand-offs" are replaced by automated workflows.


• The Impact: Drastic reduction in "Cycle Time" (the time it takes to finish a process).
• Example: "Procure-to-Pay" Process.
o Old Way: Employee fills paper form -> Walks to manager for signature -> Faxes
to purchasing -> Purchasing types it into their system. (Time: 3 Days).
o New Way (EIS): Employee clicks "Buy" -> Manager gets phone alert -> Clicks
"Approve" -> PO is auto-generated and emailed to vendor. (Time: 5 Minutes).

C. Process Visibility & Monitoring

• The Change: Processes used to be "Black Boxes"—managers didn't know where things
were stuck until a deadline was missed.
• The Impact: Real-time transparency. Managers can look at dashboards to see exactly
where every transaction is sitting.
• Example: A Logistics Manager can see on a dashboard that "Truck #45 is delayed by 2
hours," allowing them to proactively call the customer before the customer complains.
Getty Images

D. Enforcement of Rules (Standardization)

• The Change: Employees often bypassed rules (e.g., giving a discount to a friend)
because manual systems were hard to police.
• The Impact: The system enforces the process. You physically cannot proceed to Step 2
until Step 1 is done correctly.
• Example: Credit Limit Checks. An EIS will simply block a salesperson from saving an
order if the customer’s debt is over $10,000. The salesperson cannot "override" it without
a manager's digital approval.

3. The "As-Is" vs. "To-Be" Transformation

Implementing an EIS forces a company to redesign how they work.


• As-Is Analysis (Current State): Mapping the current messy process to find the pain
points (bottlenecks, duplicate entry).
• To-Be Analysis (Future State): Designing the new, streamlined process that the EIS
will enable.
• The Impact: The software doesn't just "digitize" the old way; it re-engineers it.
• Example:
o As-Is: "We print invoices and mail them."
o To-Be: "The system auto-emails the invoice when the truck leaves the dock."

4. Summary: The "Order-to-Cash" Example

To summarize the impact, look at a single process like selling a product.

Step Without EIS (Manual) With EIS (Automated)

1. Order Sales rep writes order on paper, faxes to Customer enters order on portal. Data
Entry HQ. Risk: Typos, lost fax. flows directly to HQ. Risk: None.

Sales rep calls Finance to check if client


2. Credit System auto-checks credit limit in <1
can pay. Risk: Finance doesn't answer
Check second. Risk: None.
phone.

Warehouse checks shelf manually. Risk: System reserves stock instantly so no


3. Inventory
Item is missing (Ghost Inventory). one else can buy it. Risk: None.

Finance types invoice manually next week. System generates invoice instantly
4. Billing
Risk: Late billing = Late payment. upon shipment. Risk: None.
Week – 3

1. Fundamentals of Process Modelling


What is it?

• Definition: The activity of representing the processes of an enterprise significantly so


that the current ("As-Is") and future ("To-Be") processes may be analyzed and improved.
• The Goal: To translate a 100-page text manual into a visual diagram that explains Who
does What, When, and How.

Why Model? (The Benefits)

1. Transparency: It exposes "Black Boxes." You can see exactly where a document gets
stuck.
2. Standardization: Ensures every employee performs the "Customer Onboarding" task the
exact same way.
3. Compliance: Auditors need proof that your process includes safety checks (e.g., "Show
me where the Manager Approval happens").
4. Automation Readiness: You cannot automate a process (Week 2) until you have
modelled it (Week 3).

2. Levels of Detail (The Hierarchy)

Not all diagrams are the same. You must know the difference between a Map, a Model, and a
Diagram.

• Process Map: High-level view. Shows "Landscape."


o Example: A simple arrow showing Marketing -> Sales -> Support.
• Process Model: Detailed view. Shows logic, data flow, and exceptions.
o Example: "If credit score < 600, route to Manager; else, Auto-Approve."
• Process Instance: A single specific run of the process.
o Example: "Order #9921 placed by John Doe yesterday."
3. Standard Diagram Types
A. Process Flow Diagram (PFD)

• Focus: Sequence (Time).


• Components:
o Terminator (Oval): Start/Stop.
o Process (Rectangle): Action step (e.g., "Print Invoice").
o Decision (Diamond): Yes/No question (e.g., "Is Stock Available?").
o Flow Line (Arrow): Direction of sequence.

B. Cross-Functional Flowchart (Swimlane)

• Focus: Responsibility (Who).


• Structure: It adds "Lanes" to the PFD. Each lane represents a Department or Role.
• Critical Value: It highlights "Handoffs" (when the arrow crosses a line). Handoffs are
where 80% of errors happen (e.g., Sales sent the email, but Finance never opened it).

4. ArchiMate: The Enterprise Language

This is the core technical topic. ArchiMate is an open, independent modelling language for
Enterprise Architecture. It connects Business, IT, and Strategy.

ArchiMate is a modeling language developed by The Open Group that is used to describe,
analyze, and visualize the architecture within and across business domains. It provides a
standardized way to depict the relationships between different layers of an enterprise
architecture, such as business processes, applications, and technology

Key Features of ArchiMate

The Framework: 3 Layers & 3 Aspects

ArchiMate grid is defined by Layers (Vertical) and Aspects (Horizontal).

The 3 Layers (Color Coded)


1. Business Layer (Yellow): Defines products, services, and processes for the customer.
o Example: "Customer placing an order."
2. Application Layer (Blue): Defines the software applications that support the business.
o Example: "SAP ERP System calculating tax."
3. Technology Layer (Green): Defines the hardware and networks.
o Example: "Windows Server 2019 hosting the database."

5. Detailed ArchiMate Elements (Business Layer)

You must know the exact definitions and symbols for the Business Layer.

A. Active Structure Elements (The "Doers")

• Business Actor: An entity capable of performing behavior. It is a noun.


o Symbol: Stickman.
o Example: "Customer," "Supplier," "John (the person)."
• Business Role: A responsibility or specific behavior assigned to an actor. An actor can
play many roles.
o Symbol: Cylinder with a smaller cylinder inside.
o Example: "Account Manager" (John is the Actor; Account Manager is the Role).
• Business Collaboration: An aggregate of two or more roles that work together.
o Symbol: Two overlapping circles.
o Example: "Product Launch Team" (Marketing Mgr + Sales Mgr).
• Business Interface: A point of access where a service is made available to the outside.
o Symbol: A curve (like a parenthesis).
o Example: "Telephone Hotline," "Web Portal," "Front Desk."

B. Behavioral Elements (The "Actions")

• Business Process: A sequence of actions that creates a result. It is Time-Based.


o Symbol: Arrow inside a rounded rectangle.
o Example: "Claim Handling Process" (First receive, then verify, then pay).
• Business Function: A grouping of internal behavior/capabilities. It is Criteria-Based.
o Symbol: Chevron (up arrow) inside a rounded rectangle.
o Example: "Financial Management." (This function includes processes like Billing,
Auditing, and Payroll).
o Key Distinction: A Function is what a department can do (Capacity). A Process
is what it does in a specific sequence.
• Business Interaction: A behavior performed by a collaboration (requires 2+ roles).
o Example: "Contract Negotiation" (Requires Buyer + Seller).
• Business Event: Something that happens (instantaneous) and triggers a process.
o Symbol: Rounded rectangle with an arrow.
o Example: "Invoice Received," "Customer Complaint Filed."
• Business Service: A unit of functionality exposed to the environment. It hides internal
details.
o Symbol: Rounded rectangle with rounded ends.
o Example: "Payment Service." (The customer uses the service; they don't see the
internal "Verification Process").

C. Passive Structure Elements (The "Objects")

• Business Object: Data or physical items used in a process.


o Symbol: Rectangle.
o Example: "Invoice," "Customer File," "Product Package."

6. ArchiMate Relationships (The Lines)

Knowing the boxes is not enough; you must know how to connect them.

• Triggering (Solid Arrow): Temporal sequence. "A happens, then B happens."


o Use: Connecting steps in a process.
• Flow (Dashed Arrow): Transfer of data or goods.
o Use: "Step A sends Invoice Data to Step B."
• Access (Dotted Line with Arrow): Creation, reading, or writing of data.
o Use: "The 'Billing Process' reads the 'Customer Record'."
• Assignment (Line with circle at end): Links an Actor to a Role, or a Role to a Process.
o Use: "Mr. Smith is assigned to Sales Manager." / "Sales Manager is assigned to
Sell Product."
• Realization (Dashed Line with Triangle arrow): The "How." How a lower layer
creates a higher layer.
o Use: "The 'CRM Software' (App Layer) realizes the 'Customer Lookup Service'
(Business Layer)."

7. The "Service-Oriented" Concept

This is the philosophy behind ArchiMate.

• The Rule: Layers should be independent.


• The Bridge: Services connect the layers.
o The Technology Layer offers Infrastructure Services (e.g., Storage) to the
Application Layer.
o The Application Layer offers Application Services (e.g., Calculation) to the
Business Layer.
o The Business Layer offers Business Services (e.g., Loan Approval) to the
Customer.

8. Summary Example: A Restaurant

To ensure you understand everything, let's model a restaurant.

1. Actor: "Hungry Customer."


2. Interface: "Waiter" (This is how the customer talks to the business).
3. Event: "Order Placed."
4. Process: "Meal Preparation" (Triggered by the event).
o Step 1: Cook Food.
o Step 2: Serve Food.
5. Function: "Kitchen Kitchen Capability." (The Kitchen Function performs the Cooking
Process).
6. Object: "The Menu" (Read by Customer) and "The Food" (Flows to Customer).
Week – 4 Integration

Week 4: Enterprise Integration

1. Why Integration is Necessary

Before understanding "how," you must understand "why." The slides list specific drivers for
integration:

• Market Integration: Merging different markets and development sites.


• Vendor Complexity: Integrating hardware/software from different vendors (e.g., Dell
servers with Oracle software).
• Data Consolidation: Combining multiple systems for a single view of data (e.g., Order
Management).
• Speed: Integration increases "Time to Market" (getting products to customers faster).

The Basic Principles for Success:

• Vision: Provide the right information and resources.


• Empowerment: Empower people to share information freely.
• Communication: Build comprehensive networks to democratize information.

2. Major Issues & Challenges

Integration is difficult. The slides highlight these specific failure points:

1. Inadequate Support: Without senior management buy-in, you won't get resources.
2. Change Management: Employees resisting new workflows.
3. Rushing: Skipping "Business Process Reengineering" leads to automating bad processes.
4. Legacy Systems: Old, monolithic systems are technically hard to connect.
5. Data Quality: "Dirty Data" (incompatible formats) causes errors.
6. Automatic Synchronization: Manual transfers are error-prone; automatic syncing is
essential but hard to build.
7. Scalability and Security: Ensuring that the integrated system can scale and remain
secure is crucial
8. Lack of Expertise: Insufficient technical knowledge and experience can hinder the
integration process
9. Cost of integration and choosing the right architecture.
types of integrations, their specific benefits, challenges, and real-world examples.

1. Loose Integration vs. Full Integration

This classification is based on how tightly connected the systems are and how much they "know"
about each other.

A. Loose Integration

• Definition: Two systems exchange information, but there is no guarantee they interpret it
the same way. The specific internal details of one system are hidden from the other .
• Key Features:
o Independent operations of both systems.
o Integration happens through an API layer.
o Focuses on Request Initiation and Fulfillment rather than shared logic .
• Detailed Example: A Fintech Company offers a mobile banking app.
o The app provides checking and savings accounts (Internal).
o However, it partners with a Third-Party Payment Processor to handle bill
payments and transfers.
o Result: The Banking App and the Payment Processor operate independently. If
the Payment Processor updates its internal database software, the Banking App
doesn't care, as long as the API remains the same .
• Benefits :
o Flexibility: Easier to swap out components.
o Scalability: Systems can scale independently.
o Reduced Risks: If one system crashes, it is less likely to bring down the other.
o Ease of Implementation: Faster to set up.

B. Full Integration

• Definition: Two systems are fully integrated if they both contribute to a common task
and share the same definition of every concept they exchange .
• Key Features:
o Unified Database: All components look at the same data source.
o Tight Coupling: The systems are deeply interlinked.
• Detailed Example: An End-to-End Financial Platform.
o A company develops a single system that handles banking, investments, and
payment processing internally.
o Result: The Payment module and the Banking module share the exact same
"Customer ID" and database tables. They are effectively one giant brain .
• Benefits :
o Seamless User Experience: No friction or delay between modules (mostly for
internal users).
o Real-Time Data: Changes in one area (e.g., a withdrawal) update the other area
(e.g., investment balance) instantly.
o Enhanced Control: The company controls every aspect of the transaction flow.

2. Horizontal Integration vs. Vertical Integration

This classification is based on the direction of the integration within the organizational structure.

A. Horizontal Integration

• Definition: Integrating systems, processes, or functions that operate at the same level of
the hierarchy but across different departments or business units.
• Goal: To standardize, streamline, and optimize similar processes across the organization
to ensure consistency.
• Detailed Example: Regional Sales Offices.
o A multinational company has sales offices in New York, London, and Tokyo.
o They use Horizontal Integration to connect the sales systems of all these offices.
o Result: All offices use the same data formats and reporting tools, giving
headquarters a single, unified view of global sales .
• Benefits :
o Improved Efficiency: Reduces duplication of work across departments.
o Better Data Consistency: Everyone speaks the "same language."
o Enhanced Collaboration: Teams in different regions can work together easily.
• Challenges:
o Complexity of Integration: Hard to make different teams agree on one standard.
o Resistance to Change: Departments often fight against giving up their unique
local tools.

B. Vertical Integration

• Definition: Integrating systems that operate at different levels of the organization,


typically up and down the value chain (from the shop floor to the top floor).
• Goal: To create a seamless flow of information from the top of the hierarchy
(Management) to the bottom (Production).
• Detailed Example: Manufacturing Supply Chain.
o A factory connects its ERP (Enterprise Resource Planning - Top Level) with its
MES (Manufacturing Execution System - Factory Floor Level) and its SCM
(Supply Chain Management - Logistics Level).
o Result: When a customer places an order in the ERP, it automatically translates
into a production schedule in the MES and updates inventory levels in the SCM.
• Benefits:
o Improved Process Efficiency: Eliminates manual handoffs between management
and workers.
o Better Decision Making: Managers see real-time production data.
o Enhanced Customer Service: Faster response to orders.
• Challenges:
o High Implementation Cost: Linking complex machinery to software is
expensive.
o Complexity in Management: Managing the entire chain requires deep expertise.
o Risk of Overdependence: If the chain breaks, the whole business stops.

3. Intra-Enterprise vs. Inter-Enterprise Integration

This classification is based on the scope or boundary of the integration.

A. Intra-Enterprise Integration

• Definition: The integration of business processes internal to a single enterprise.


• Characteristics: This usually aligns with Full Integration because the company owns
all the systems and can enforce a unified database and tight coupling.

B. Inter-Enterprise Integration

• Definition: The integration of business processes between different enterprises (e.g.,


connecting your system with a supplier's system).
• Characteristics: This usually requires Loose Integration because you cannot control the
other company's database; you can only exchange information via APIs or standards.

Based on the Week 4 - EIS [Link] slides, here is the detailed explanation of the
Alignment Process and Integration Technologies.

1. The Alignment Process

Integration is not just about connecting wires; it is about connecting people and goals. The slides
define the Alignment Process as the crucial first step to ensure everyone is on the same page
before any coding begins.

A. Definition & Purpose

• Definition: The Alignment Process is the act of developing a common understanding


among key stakeholders regarding the project's purpose, goals, and the methods used to
achieve them .
• Goal: To establish trust, agree on participant roles, and decide how to track progress and
costs .
• Timing: This must happen during the Initiation Phase of the project.

B. How it is Conducted (The Kickoff)

Project managers conduct a "Start-up Meeting" (Kickoff). The duration depends on the project's
complexity:

• Low Complexity (Short Duration): Can be aligned in a simple lunch meeting.


• Medium Complexity: Requires a formal meeting lasting several hours.
• High Complexity: Cannot be done in one meeting. It requires several days of alignment
activities .

C. The 4-Step Alignment Flow

The slides outline a specific cycle for aligning processes between a Customer and a Supplier :

1. Internal Standard Development: First, define your own internal standards (know what
you want).
2. Understand Each Other's Processes: Learn how the partner operates. (e.g., The
Supplier learns the Customer's ordering workflow) .
3. Optimize & Agree: Create a joint "Co-development Process." Decide how to work
together efficiently.
4. Continuously Improve: Use a feedback loop to keep making the process better over
time.

D. The Importance of Trust

• The Risk: If alignment fails, trust breaks down.


• Consequence: A lack of trust causes delays because partners start "fact-checking"
everything instead of working, or they hide sensitive information because they don't trust
the other party to handle it safely.

2. Integration Technologies

The slides list four specific technologies used to technically connect Enterprise Systems.
A. ESB (Enterprise Service Bus)

• Concept: A centralized software architecture that acts as a communication highway (or


"Bus") between different applications.
• How it Works: Instead of System A talking directly to System B, System A sends a
message to the ESB. The ESB translates the message and delivers it to System B (and C,
and D).
• Example: A Bank has an old Mainframe (1980s) and a new Mobile App (2024). The
ESB sits in the middle, translating the Mobile App's modern JSON requests into the
Mainframe's old COBOL language.

B. APIs (Application Programming Interface)

• Concept: A set of defined rules that allow one application to talk to another. It acts as a
"Menu" of operations that a system exposes to the outside world.
• How it Works: App A asks App B for specific data using a standard request, and App B
responds.
• Example: When you use Uber, the app doesn't build its own maps. It uses the Google
Maps API to request map data and display it inside the Uber app.

C. SOAP / SOA (Service-Oriented Architecture)

• Concept: An older, highly structured standard for exchanging information, often used in
large enterprise environments requiring high security.
• Characteristics: It uses XML (Extensible Markup Language) to format messages. It is
very strict and rigid but very secure.
• Example: A Banking Wire Transfer System. Because money is involved, the bank
uses SOAP to ensure the message structure is rigid and validated before processing the
transaction.

D. Component-Wise Integration (Microservices)

• Concept: Breaking a massive application into tiny, independent "components" or


services that run on their own.
• How it Works: Instead of one giant "E-Commerce App," you build small separate apps:
a "Login Service," a "Cart Service," and a "Payment Service." They talk to each other to
form the full app.
• Example: Netflix. When you click "Play," one microservice checks your subscription,
another retrieves the video file, and a third updates your "Watch History." If the
"History" service breaks, the video still plays.

Implementation Strategies, the Buy Principles matrix, and Future Trends.


1. Implementation Strategy
This is the roadmap for introducing a new Enterprise System into an organization. It is
not just about installing software; it is about managing change.

The Roadmap 1

1. Planning and Requirement Analysis:


o Goal: Define exactly what the business needs before spending money.
o Example: A bank decides it needs a new "Mobile Wallet" system that
handles 1 million transactions per second.
2. System Selection and Vendor Evaluation:
o Goal: Comparing different software providers (e.g., Oracle vs. SAP vs.
Custom Build).
3. Customization vs. Configuration:
o Configuration: Changing settings without writing code (e.g., changing the
currency from USD to PKR). Preferred method.
o Customization: Rewriting the code to change how the software works.
Avoid if possible (makes upgrades hard).
4. Build vs. Buy:
o Buy (COTS - Commercial Off-The-Shelf): Buying pre-made software
(e.g., Salesforce). Pros: Fast, tested. Cons: Not unique.
o Build: Hiring developers to write code from scratch. Pros: Exact fit. Cons:
Expensive, slow, high maintenance.
5. Implementation Phases:
o Rolling out the system in stages (e.g., "Finance Module first, HR Module
second") rather than a "Big Bang" where everything changes at once.
6. Change Management and User Training:
o Training employees so they don't reject the new system.

2. Buy Principles (The Selection Matrix)


When you decide to Buy a system (instead of building it), you must evaluate it against
these strict criteria to ensure it fits the enterprise ecosystem2.

Capability Description & Requirement Real-World Example

Bank Teller System: The software


Identity & Access Management:
must allow a "Manager" to approve
1. Security The system must support roles
and strong controls so operational loans but restrict a "Teller" to only
risk is minimized 3.
cash deposits. It must integrate with
Capability Description & Requirement Real-World Example

Active Directory.

Single Sign-On (SSO): An

Seamless & Omnichannel: employee logs in once with their ID


2. User Security controls (like passwords) card, and the system automatically
should not annoy the user. Staff
Experience and customers shouldn't need 5 logs them into Email, CRM, and HR
different passwords for 5 different systems without asking for a
screens 4.
password again.

Telecom App: When you call the


helpline, the agent sees your Mobile
One Identity: Each user must
3. Customer have their information stored in Plan, Internet Plan, and Complaints
Single Vision one place (a single digital all under one "Customer ID," rather
identity), not scattered across
databases 5. than searching three different
systems.

Netflix Updates: Netflix can update

Cloud Ready & Micro-services: its "Recommendation Engine"


The solution should be "Cloud without stopping the "Video Player"
4. Agility Native" (ready for AWS/Azure)
and support APIs/Micro-services because they are agile micro-
for easy updates without breaking services. The software you buy must
other systems 6666.
allow this.

Fraud Investigation: If a transaction


is deleted, the system keeps a
Tracking: The solution must
5. Auditability provide full audit tracking permanent "Audit Log" showing who
independent of the user's access
deleted it and when, even if the user
capability7777.
tried to hide it.

6. TCO (Total Full Cost View: Before buying, Hidden Costs: A software might
calculate Development + Running
Cost of cost $10,000 to buy, but $50,000 a
Costs + People + Support8888.
Capability Description & Requirement Real-World Example

Ownership) year to maintain. You must look at


the total $60,000 cost before buying.

3. What Does the Future Hold?


The slides predict five major trends that are shaping the future of Enterprise
Integration9.

1. Cloud-Based EIS
• Trend: Moving from "On-Premise" (servers in the basement) to the Cloud (AWS,
Azure, Google Cloud)10.
• Impact: Companies stop maintaining hardware. They rent computing power.
• Example: Instead of buying 50 servers for a Black Friday sale, an e-commerce
store "rents" capacity from Amazon AWS for 3 days and then turns it off.

2. Hyper Automation
• Trend: Automating everything that can be automated, using a mix of AI, RPA
(Robots), and Machine Learning11.
• Impact: Removing humans from complex decision loops, not just data entry.
• Example: An insurance claim is submitted -> AI analyzes the photo of the car
crash -> AI estimates damage -> Bot approves payment. Zero human
involvement.

3. Integration with AI
• Trend: EIS will not just store data; it will think12.
• Impact: Systems become predictive rather than reactive.
• Example: An Inventory System (SCM) uses AI to predict a heatwave next week
and automatically orders more Air Conditioners before customers even start
buying them.

4. Integration with Blockchain


• Trend: Using distributed ledgers for security and transparency13.
• Impact: Unhackable, transparent records shared between companies.
• Example: Supply Chain Tracking. A diamond mine, a cutter, and a jewelry store
all share a Blockchain ledger. The customer can scan a QR code to prove the
diamond is ethical and not a fake.
5. IoT (Internet of Things)
• Trend: Connecting physical devices (sensors, machines) directly to the EIS14.
• Impact: Real-time physical data flowing into digital systems.
• Example: Smart Manufacturing. A machine in a factory feels "hot" (vibration
sensor). It sends an alert to the ERP system, which automatically schedules a
maintenance technician to fix it before it breaks.

1. The 4 Key Elements of Loose Integration


A. Request Initiation

• Definition: This is the trigger. It is the moment one system (the Consumer) decides it
needs something from the other system (the Provider) and sends a message to start the
process. In loose integration, the consumer does not know how the provider will do the
job; it just asks for it.
• Key Detail: It involves authentication (Who are you?) and the payload (What do you
want?).
• Example: A Mobile Banking App (System A) sends a signal to a Utility Company
(System B) saying, "I want to pay Bill #123 with $50."

B. State Management

• Definition: Since the systems are disconnected (loose), they need a way to track the
conversation. State management ensures that both sides know exactly where they are in
the process, especially if there is a delay or network failure.
• Key Detail: Usually handled via a Correlation ID or Transaction ID. If the app crashes
and restarts, it can check this ID to see if the payment already happened.
• Example: The Banking App generates a unique ID Trans_999. It stores the state as
"Pending" in its local database. If the internet cuts out, it knows Trans_999 is still
pending and not yet "Success."

C. Request Provisioning

• Definition: This is the "preparation" phase on the receiver's side. Before doing the actual
work, the receiving system must validate the request, check if it has the resources to
fulfill it, and route it to the right internal module.
• Key Detail: It acts like a receptionist or a security guard. It checks logic: "Is the API key
valid? Is the user's balance sufficient? Is the database online?"
• Example: The Utility Company's server receives the request. It checks:
1. Does Bill #123 exist? (Yes).
2. Is the amount correct? (Yes).
3. Is the Banking App authorized to pay this? (Yes).
o Provisioning Complete: The request is valid and queued for processing.

D. Request Fulfillment

• Definition: This is the execution. The provider actually performs the business logic,
updates its database, and sends a final response back to the initiator.
• Key Detail: The transaction is committed permanently.
• Example: The Utility Company deducts $50 from the bill balance, marks Bill #123 as
"Paid," and sends a "200 OK - Success" message back to the Banking App.

Unified Scenario: The "Uber Ride" Example

To see how these work together, imagine you are using a Ride-Sharing App (System A) that
integrates loosely with a Google Maps Service (System B).

The Scenario: You open the app and request a ride.

1. Request Initiation (The Trigger):


o Action: You type in "Airport" and click "Find Driver."
o System A: Sends a message to System B: "Calculate route from Current
Location to Airport."
2. State Management (The Tracker):
o Action: The app shows a spinning wheel (Loading).
o System A: Creates a Session ID #Ride_55. It knows that for this specific screen,
it is waiting for an answer. It doesn't allow you to request a second ride while this
one is processing (State = "Requesting").
3. Request Provisioning (The Check):
o Action: Google Maps (System B) receives the message.
o System B: Checks: "Is the GPS coordinate valid? Do we have traffic data for this
area? Is the API Quota for this app exceeded?"
o Result: All checks pass. The server allocates memory to calculate the route.
4. Request Fulfillment (The Execution):
o Action: Google Maps calculates the traffic, finds the fastest path, and estimates
the time is 25 minutes.
o System B: Sends the data package {Time: 25 mins, Distance: 15km} back to
the App.
o System A: Updates the State to "Success" and displays the route on your screen.
Week – 5 ERP

1. What is ERP (Enterprise Resource Planning)?

• Definition: ERP systems are integrated software suites that manage and coordinate core
business processes across an entire organization.
• Core Concept: Instead of having five different software programs (one for accounting,
one for shipping, one for HR), ERP combines them all into one single system with a
shared database.
• Real-World Example: SAP ERP.
o Scenario: A car manufacturer uses SAP. When a car is sold (Sales Module), the
system automatically updates the revenue (Finance Module), deducts the parts
from stock (Inventory Module), and triggers a restock order (Procurement
Module). All instantly.

2. Key Features of ERP

• Centralized Database: All modules (Finance, HR, Sales) save data to the same place.
This eliminates "Data Silos" (where Sales thinks revenue is $1M but Finance thinks it's
$900k).
• Real-Time Access: Managers can see live data. You don't have to wait for the "End of
Month Report" to know how much money you made today.
• Integration: Seamless connection between departments. If HR hires a person, Payroll
automatically knows about it.
• Scalability: The system grows with you. You can start with 10 users and scale to 10,000.

3. Detailed ERP Modules

You must know the specific functions of each module for the exam.

A. Finance and Accounting Module

• Goal: Manage the money flow and ensure compliance.


• Key Features:
o General Ledger (GL): The master record of all financial transactions.
o Accounts Payable (AP): Money you owe to vendors (Bills).
o Accounts Receivable (AR): Money customers owe you (Invoices).
o Fixed Assets: Tracking long-term assets like buildings and machinery.
• Example: When the Procurement Team buys a new laptop, the Finance module
automatically records an expense of $1,000 in the General Ledger and creates a liability
in Accounts Payable to pay the vendor in 30 days.

B. Human Resources (HR) Module

• Goal: Align workforce management with company goals.


• Key Features:
o Employee Records: Storing address, emergency contacts, tax info.
o Payroll: Calculating salaries, taxes, and bonuses automatically.
o Recruitment: Tracking job applicants.
o Performance Management: Storing yearly reviews and KPIs.
• Example: An employee gets a promotion. The HR Manager updates the "Job Title" in
the system. The Payroll feature automatically increases their salary next month, and the
Security feature automatically gives them access to the Manager's parking gate.

C. Supply Chain Management (SCM) Module

• Goal: Manage the flow of goods from supplier to customer.


• Key Features:
o Procurement: Buying raw materials.
o Inventory Management: Tracking how many items are on the shelf.
o Logistics: Managing trucks and shipping.
• Example: A detailed flow from the slides :

1. Order Placement: Customer buys 10 chairs.


2. Inventory Check: System checks if stock is available.
3. Decision: If No Trigger Vendor Order. If Yes Arrange Shipment.
4. Invoicing: Send bill to customer.
5. Payment Processed: Money received.

D. Manufacturing and Production Module

• Goal: Optimizing the factory floor.


• Key Features :
o Bill of Materials (BOM): The "Recipe" for a product (e.g., A Bike = 2 wheels +
1 frame + 1 seat).
o Production Planning: Scheduling when to run the machines.
o Quality Management: Tracking defects.
• Example: The system calculates that to build 500 cars next week, you need exactly 2,000
tires delivered by Tuesday. It schedules the workers and machines accordingly to reduce
idle time.
E. Sales and Distribution (SD) Module

• Goal: Selling the product and getting it to the customer.


• Key Features:
o Order Management: Processing customer orders.
o Pricing: Managing discounts and price lists.
o Billing: Issuing invoices.
• Integration: It connects with CRM to see customer history and Marketing to run
promotions.

4. ERP Implementation Strategies

Implementing ERP is risky and expensive.

A.
The Implementation Life Cycle

1. Planning: Define goals (e.g., "We need to cut inventory costs by 10%").
2. Design: Blueprint the system.
3. Development/Configuration: Set up the software.
4. Testing: Make sure it doesn't crash.
5. Deployment: Go live.
6. Support: Fix bugs after launch.

B.
Major Challenges

• High Costs: ERP licenses cost millions.


• Resistance: Employees hate changing how they work (Change Management).
• Data Migration: Moving 20 years of data from old systems to the new one is messy.
• Customization Trap: Heavily customizing the core code makes future updates
impossible.

C.
Best Practices

• Top Management Support: The CEO must back the project, or it will fail.
• Phased Approach: Don't do everything at once. Launch Finance first, then HR.
• Training: Train users before the system goes live, not after.
5. Customization vs. Integration

1. Types of Customization
Not all changes are equal. You must distinguish between these three levels of change1:

• A. Configurations (Low Risk):


o Definition: Changing settings or parameters within the software without
writing any new code. This is how you set up the system to work for your
specific country or industry using the vendor's built-in switches.
o Example: Setting the default currency to PKR, defining the Fiscal Year as
July-June, or setting the default language to English.
• B. Extensions (Medium Risk):
o Definition: Creating new code or modules that sit on top of the core ERP
system. You are adding features, but you are not touching the engine.
o Example: Building a custom Reporting Dashboard that pulls data from
the ERP to show specific KPIs for your manager, or adding a new field
called "Customer Loyalty Score" to the Customer Master record.
• C. Modifications (High Risk):
o Definition: Changing the core source code of the ERP software itself.
This alters how the system behaves at a fundamental level.
o Example: Rewriting the standard Tax Calculation Logic in SAP because
your specific industry has a unique tax exemption rule that the standard
software doesn't support.

2. Pros and Cons of Customizing


Why do companies do it, and why is it dangerous? 2

Feature Pros (Why do it?) Cons (The Risk)

"Upgrade Nightmare": When the vendor


Tailors the software to fit your
releases a new version (e.g., Security
Fit unique business processes
Patch), it might overwrite your custom
perfectly.
code, breaking your system.

User Can simplify screens to make Cost: Custom developers are expensive
Experience them easier for employees to ($200+/hour), and maintaining that code
Feature Pros (Why do it?) Cons (The Risk)

use. forever costs even more.

Provides a competitive
Bugs: Custom code is rarely as
advantage (doing things
Strategy rigorously tested as the vendor's core
differently than competitors
code, leading to stability issues.
who use standard software).

3. Balancing Customization with Maintainability


This is the strategic challenge for IT Managers3.

• The Golden Rule: "Configure before you Customize."


o Always try to use the standard software (Vanilla ERP) first. Only
customize if it is critical for business survival.
• Ease of Upgrades: The more you modify the core code, the harder it is to apply
updates. A highly modified system can become "frozen in time" because
upgrading is too expensive.
• Best Practice: If you must customize, use Extensions (side-cars) rather than
Modifications (changing the engine) so that future updates don't break your
work.

1. Importance of Integration

An ERP system cannot live in isolation. To get a "360-degree view" of the business, it must talk
to specialized systems :

• ERP + CRM (Customer Relationship Management):


o Why: Sales people work in CRM, but Finance people work in ERP.
o Benefit: When a salesperson closes a deal in CRM, the ERP automatically knows
to send an invoice and deduct inventory.
• ERP + SCM (Supply Chain Management):
o Why: ERP handles the money/accounting, but specialized SCM tools optimize
complex logistics.
o Benefit: Ensures that financial forecasts match physical inventory levels.
• ERP + BI (Business Intelligence):
o Why: ERP is good for entering data, but BI is good for analyzing it.
o Benefit: Feeding ERP data into a BI tool (like Tableau) allows executives to
visualize trends and make strategic decisions.
2. How to Integrate (The Technology)

The slides highlight two main methods for connecting these systems:

• APIs (Application Programming Interfaces): The modern "plug-and-play" method. It


allows the ERP to send and receive real-time data requests (e.g., checking stock levels
instantly).
• Middleware: Software that acts as a "Translator" or "Hub" in the middle. It takes data
from an old system, reformats it, and pushes it into the new ERP. This is crucial for
connecting to Legacy Systems.

3. Real-World Integration Example

• Scenario: A large e-commerce company integrates Shopify (Web Store) with NetSuite
(ERP).
• The Flow:
1. Customer buys a shirt: Transaction happens on Shopify.
2. Integration (API): Shopify sends the order data to NetSuite instantly.
3. ERP Action: NetSuite records the revenue (Finance), reserves the item
(Inventory), and prints the shipping label (Logistics).
4. Result: Zero manual data entry, no errors, and the Finance team sees the money
immediately.

6. Cloud-Based ERP (The Future)

• Trend: Moving from On-Premise (servers in the basement) to SaaS (Software as a


Service).
• Benefits:
o Lower Upfront Cost: You pay a monthly subscription instead of buying
expensive servers.
o Mobile Access: Access ERP from your phone anywhere.
o Automatic Updates: The vendor updates the software for you.
• Example: Oracle NetSuite is a fully cloud-based ERP. A startup can use it without
hiring an IT team to manage servers.

7. Summary of Benefits (Why do companies do it?)

1. Integration: One version of the truth across all departments.


2. Efficiency: Automating boring tasks (like data entry) saves time.
3. Scalability: It supports business growth into new countries or product lines.

Yes, that is a very accurate way to describe it, though in technical terms, we would say
"Horizontal and Fully Integrated (Tightly Coupled)."

Here is the breakdown of why your assessment is correct based on the slides:

1. Why is it Horizontal?

• Definition: Horizontal Integration connects systems or functions that operate at the same
level of the organization but across different departments.
• ERP Context: An ERP connects Finance, HR, Sales, and Supply Chain. These are all
different departments sitting at the same operational level of the business.
o Example: The ERP allows the "Sales Department" to talk to the "Warehouse
Department" instantly.

2. Why is it "Fixed" (Full Integration)?

• Definition: Full Integration means the systems share the same definition of concepts and
usually a Unified Database.
• ERP Context: The defining feature of an ERP is its Centralized Database.
o Why it's "Fixed": You cannot just unplug the "Finance Module" and easily swap it
for a different brand because it is deeply wired (tightly coupled) into the same
database as the "HR Module." They are physically part of the same software
body.
Week – 6 CRM

Based on the Week 6 - Deep Dive into EIS - CRM slides, here are your comprehensive and
detailed notes. Since the slides are concise, I have expanded on every keyword to ensure no
concept is missed.

1. What is CRM (Customer Relationship Management)?

• Definition: CRM is a system or strategy designed to manage a company's interactions


with current and potential customers. It is not just software; it is a philosophy of putting
the customer at the center of the business.
• Core Objectives:
o Lifecycle Management: It tracks the customer from the moment they are a
"stranger" to when they become a "loyal advocate".
o Strategic Goal: To enhance customer satisfaction, increase retention (keeping
customers), and build loyalty.
• Real-World Example: Salesforce.
o Scenario: A retail company uses Salesforce. When you walk into the store, the
clerk sees on their iPad that you bought a blue shirt last month. They suggest a
matching tie. This is CRM in action—using data to personalize the experience.

2. The Three Types of CRM Systems

You must be able to distinguish between these three, as they serve different purposes.

A. Operational CRM (The "Front Office")

• Focus: Automating customer-facing processes. It helps employees do their daily jobs


faster.
• Key Functions: Sales, Marketing, and Customer Service.
• Example: A Call Center agent uses Operational CRM to see your "Recent Orders" so
they don't have to ask you for your order number 5 times.

B. Analytical CRM (The "Back Office")

• Focus: Analyzing customer data to gain insights and find patterns. It doesn't talk to the
customer; it talks to the data about the customer.
• Key Functions: Data Mining, Customer Segmentation, Predictive Modeling.
• Example: Analyzing 10,000 transactions to discover that "Customers who buy diapers
also buy beer on Fridays."
C. Collaborative CRM (The "Connector")

• Focus: Enabling different departments (and even external partners) to share customer
information.
• Key Goal: Breaking down silos.
• Example: You complain to Support about a broken product. Collaborative CRM alerts
the Sales Team not to call you for an upgrade today because you are angry.

3. Key Features and Functionalities

The slides list four major pillars of CRM functionality.

A. Sales Force Automation (SFA)

This is the heart of CRM for the Sales team.

• Lead Management: Tracking potential customers (Leads) from the first contact (e.g., a
website form fill) until they are qualified.
• Opportunity Management: Managing the "Deal." Tracking the probability of closing
the sale (e.g., "60% chance to close by Friday").
• Sales Forecasting: Using past data to predict how much revenue the team will generate
next month.
• Benefit: Streamlines the sales process so salespeople spend less time on admin and more
time selling.

B. Marketing Automation

This replaces manual marketing tasks.

• Campaign Management: Planning and tracking specific marketing pushes (e.g., "Black
Friday Sale").
• Lead Nurturing: Automatically sending emails to leads who aren't ready to buy yet
(e.g., sending a "How-To Guide" one week, then a "Discount Code" the next).
• Segmentation: Grouping customers based on behavior (e.g., "Females under 30 who live
in New York") to send personalized messages.

C. Customer Service and Support

• Case Management: Creating a "Ticket" for every problem. The system tracks the ticket
until it is resolved.
• Knowledge Base: A library of "How-To" articles. Agents use it to answer questions fast;
customers use it for self-service.
• 360-Degree View: Support agents can see the customer's sales history and marketing
emails, allowing them to solve issues efficiently.

D. Analytics and Reporting

• Sales Pipeline Analysis: visualizing where all the deals are stuck (e.g., "We have $1M in
proposals, but only $100k in closed deals").
• CLTV (Customer Lifetime Value): Calculating how much profit a single customer will
bring over their entire life.
• Predictive Analytics: Using AI to guess what a customer will do next (e.g., "Customer X
is 80% likely to cancel their subscription").

CRM – MEASURING SUCCESS AND ROI

1. Key Metrics for CRM Success

To ensure the CRM system is actually benefiting the company, you must track specific Key
Performance Indicators (KPIs).

A.
Key Performance Indicators (KPIs)

• Customer Satisfaction (CSAT):


o Concept: Measuring how happy customers are with your service or product. High
satisfaction usually leads to loyalty.
o Example: After a support call, the CRM automatically sends a one-question
survey: "How would you rate your experience from 1-5?" A score of 4.8/5
indicates high success.
• Customer Retention Rate:
o Concept: The percentage of customers who stay with the company over a specific
period (vs. those who leave/churn).
o Example: If you start the year with 100 subscribers and 95 renew their contracts,
your retention rate is 95%. The CRM tracks contract end dates to alert sales teams
to secure renewals.
• Sales Growth:
o Concept: Measuring the direct increase in revenue attributed to better CRM
management (e.g., upselling or closing deals faster).
o Example: Before CRM, the sales team closed $50,000/month. After implementing
CRM (which reminds them to follow up), sales jump to $65,000/month.
B.
Tracking Engagement and Response Rates

• Concept: Monitoring how customers interact with your marketing efforts. This tells you
if your message is interesting to them.
• Metrics:
o Open Rate: Did they open the email?
o Click-Through Rate (CTR): Did they click the link?
o Conversion Rate: Did they buy the product after clicking?
• Example: You send a "Summer Discount" email to 1,000 people via the CRM. The
system reports that 300 people opened it (Engagement), but only 5 people bought
something (Low Response). This tells you the subject line was good, but the offer was
weak.

C.
Role of Customer Feedback and Surveys

• Concept: Using the CRM to automate the collection of qualitative feedback.


• Application:
o NPS (Net Promoter Score): "How likely are you to recommend us to a friend?"
o Feedback Loops: If a customer leaves a low score, the CRM instantly creates a
"High Priority" ticket for a manager to call them back.
• Example: A restaurant chain uses CRM to send a survey after every online order. If a
customer complains about cold food, the system flags the branch manager immediately.

2. Calculating CRM ROI (Return on Investment)

Implementing a CRM is expensive (licenses, training, setup). Companies must prove that the
system generates more money than it costs.

A.
Overview of Calculation Methods

The basic formula for ROI is:

• Goal: To determine the financial efficiency of the system.

B.
Factors to Consider
You must look at three "buckets" of money to find the Net Gain:

1. Cost Savings (Efficiency): Money saved by automating tasks.


o Example: By automating data entry, 10 salespeople save 5 hours a week each.
That is 50 hours of salary saved (or repurposed for selling) per week.
2. Revenue Growth (New Money): Money gained from better sales performance.
o Example: The CRM's "Cross-Sell" suggestions prompt salespeople to sell
warranty packages they used to forget, adding $100k in new revenue.
3. Customer Acquisition & Retention:
o Acquisition: Lowering the cost to find a new customer (e.g., better targeting).
o Retention: Saving a customer who was about to leave. Keeping an existing
customer is 5x cheaper than finding a new one.

C.
Alignment with Business Goals

• Concept: Your ROI metrics must match what the CEO cares about right now.
• Example:
o If the company goal is "Market Share," focus your ROI calculation on New
Customer Acquisition numbers.
o If the company goal is "Profitability," focus your ROI calculation on Cost
Savings and Retention.

3. Continuous Improvement in CRM


A.
Regularly Reviewing Performance

• Concept: A CRM system degrades over time if not maintained. Processes become
outdated, and data becomes dirty.
• Action: Quarterly reviews to clean data and update workflows.
• Example: A company reviews its "Lead Scoring" rules every 6 months. They realize the
old rule ("Give 10 points for visiting the website") is no longer accurate, so they adjust it
to ("Give 20 points for visiting the Pricing Page").

B.
Supporting Organizational Improvement

• Concept: The CRM highlights operational weaknesses outside of the sales team.
• Example: The CRM shows that 40% of sales are lost at the "Contract Signing" stage. The
company realizes their Legal Department is too slow, so they hire more lawyers or switch
to digital signatures (DocuSign) to fix the bottleneck.

C.
The Future of CRM

The slides identify three driving forces for the future:

1. AI (Artificial Intelligence): Automating complex decisions.


o Example: AI chatbots handling 80% of routine support queries instantly.
2. Machine Learning (ML): The system learns from history.
o Example: The CRM "learns" that customers who buy in December rarely buy in
January, so it stops sending marketing emails in January to save money.
3. Customer Experience (CX): Moving beyond "Sales" to "Experience."
o Example: Using CRM to ensure a seamless transition between online chat and
phone support, so the customer feels "known" and valued at every touchpoint.

5. Implementation and Integration

1. Importance of Integrating CRM

A standalone CRM is useful, but an integrated CRM is powerful. Connecting it to other major
enterprise systems creates a seamless flow of data across the business.

• CRM + ERP (Enterprise Resource Planning):


o The "Why": Sales teams live in the CRM, while Finance/Operations teams live
in the ERP. Without integration, a salesperson might close a deal for an item that
is out of stock or sold at the wrong price.
o The Benefit: Connects the "Front Office" (Sales) to the "Back Office" (Finance).
When a deal is marked "Closed-Won" in CRM, the ERP automatically generates
the invoice and sets up the subscription billing.
• CRM + SCM (Supply Chain Management):
o The "Why": Customers often ask, "If I order today, when will it arrive?" A
standalone CRM doesn't know the answer.
o The Benefit: Gives salespeople real-time visibility into inventory levels and
shipping estimates. They can promise accurate delivery dates to customers
without calling the warehouse.
• CRM + BI (Business Intelligence):
o The "Why": CRM stores data, but BI analyzes it to find deep patterns.
o The Benefit: By feeding CRM data into a BI tool (like Tableau or PowerBI),
executives can visualize complex trends, such as "Customer Churn Rate by
Region vs. Marketing Spend," which is hard to see in standard CRM reports.

2. Technology Used for Integration

How do these systems talk to each other?

• APIs (Application Programming Interfaces):


o The standard modern method. The CRM (e.g., Salesforce) exposes an endpoint
that allows the ERP (e.g., SAP) to "push" or "pull" data instantly.
o Example: When a user updates their address on the website, the API instantly
updates the address in the CRM.
• Middleware:
o Software that acts as a "bridge" or "translator" in the middle. It is often used when
connecting a modern CRM to an older, legacy ERP system that doesn't have
modern APIs.

3. Real-World Example

• Scenario: A high-end furniture retailer integrates Salesforce (CRM) with Oracle


(ERP).
• The Workflow:
1. Sales: A salesperson enters a custom sofa order in Salesforce.
2. Integration: The system automatically checks Oracle to see if the fabric is in
stock.
3. Result:
▪ If Yes, the order is confirmed, and Oracle instantly schedules the
manufacturing job.
▪ If No, Salesforce alerts the salesperson immediately so they can manage
the customer's expectations regarding the delay.
• Benefit: Reduces human error (no re-typing orders), speeds up delivery, and improves
customer trust.

Challenges

• User Adoption: Salespeople often hate CRM because they feel it is "Big Brother"
watching them. If they don't enter data, the system is useless.
• Data Migration: Moving messy contact lists from Excel to CRM is difficult.
• Process Alignment: You must fix your sales process before buying the software.

Best Practices
• Executive Sponsorship: The CEO must say, "If it's not in Salesforce, it didn't happen."
• Phased Rollout: Don't launch everything at once. Start with the Sales module, then add
Marketing later.

6. Future Trends

• Cloud-Based CRM: Accessing data from mobile phones anywhere (SaaS).


• AI-Driven Insights: The CRM telling you who to call today.
• CDP (Customer Data Platforms): A newer, more advanced version of CRM that pulls
data from social media, web, and ads into one "Golden Record."
Week – 8 SCM

1. What is Supply Chain Management (SCM)?

• Definition: SCM is the management of the flow of goods, information, and finances
related to a product or service, from the procurement of raw materials to the delivery of
the final product to the end consumer.
• The Three Key Flows:
o Flow of Goods: Physical movement of materials from suppliers manufacturers
distributors retailers customers.
o Flow of Information: The transmission of orders, delivery status, and inventory
updates. (e.g., A customer tracks their package online).
o Flow of Finances: Payment schedules, credit terms, and ownership transfer.
• Key Objectives:

1. Efficiency: Minimizing waste and time in the production cycle.


2. Cost Reduction: Lowering the costs of holding inventory and transportation.
3. Customer Satisfaction: Ensuring the right product arrives at the right time in
perfect condition.

2. Real-World Example: Oracle SCM

The slides provide Oracle SCM as a prime example of modern supply chain software.

• Key Features :
o Inventory Management: Real-time tracking of stock levels to prevent "Out of
Stock" scenarios.
o Order Processing: Automating the lifecycle of an order from "Click" to "Ship."
o Supplier Management: Rating and managing vendor performance.
o Logistics: Planning the most efficient delivery routes.
• Use Case Scenario:
o Context: A logistics company manages thousands of shipments daily.
o Action: They use Oracle SCM to optimize inventory levels (keeping just enough
stock) and manage supplier relationships (ensuring raw materials arrive on time).
o Result: They can track shipments in real-time, reducing delays and saving money
on fuel by optimizing routes.
3. Introduction to SCM Systems (Software Solutions)

Based on the image and slides, SCM software can be categorized into two main architectures:

A. ERP-Integrated SCM

• Concept: The SCM module is part of a larger Enterprise Resource Planning (ERP) suite
(like SAP ERP).
• Pros: Seamless data sharing. If Sales (ERP) sells a product, SCM (Inventory) knows
instantly.
• Cons: Might lack very specialized features compared to standalone tools.

B. Standalone SCM Systems

• Concept: Specialized software dedicated only to supply chain (e.g., JDA Software).
• Pros: Deep functionality for complex chains.
• Cons: Harder to integrate with Finance or HR systems.

Key Vendors:

• SAP SCM & Oracle SCM: Major ERP players.


• JDA & Infor: Specialized supply chain experts.

4. Components of a Supply Chain

A supply chain is a network of entities working together .

1. Suppliers: The starting point. They provide raw materials (e.g., a Lithium mine for
batteries).
2. Manufacturers: They turn raw materials into finished goods (e.g., a Factory assembling
the battery into a car).
3. Warehouses: Storage facilities where goods are held before distribution.
4. Distribution Centers (DC): Hubs that break down large bulk shipments into smaller
orders for retailers.
5. Retailers: The final point of sale where the customer buys the product (e.g., Walmart).

Importance of Coordination: Partners must collaborate. If the Supplier is late and doesn't tell
the Manufacturer, the factory stops, and the Retailer runs out of stock. SCM systems bridge
this communication gap.
5. Types of Supply Chains (Push vs. Pull)

This is a critical concept often tested in exams.

A. Push Supply Chain (Make-to-Stock)

• Concept: Production is driven by Forecasts (predictions). You "push" products onto the
shelf hoping people will buy them.
• Strategy: Make-to-Stock.
• Example: Coca-Cola. They don't wait for you to order a Coke before making it. They
manufacture millions of cans based on summer sales predictions and push them to stores.
• Risk: If the forecast is wrong, you have too much inventory (Waste).

B. Pull Supply Chain (Make-to-Order)

• Concept: Production is driven by Actual Demand. You only make the product after the
customer orders it.
• Strategy: Make-to-Order.
• Example: Dell Computers (historically) or Custom Suits. They don't build the
computer until you select your specs on the website.
• Risk: Customers have to wait longer for delivery.

Feature Push (Make-to-Stock) Pull (Make-to-Order)

Trigger Forecast / Prediction Customer Order

Inventory Level High (Stocked in advance) Low (Just raw materials)

Focus Mass Production Efficiency Customization & Responsiveness

Example Groceries, Clothing Basics Private Jets, Custom Furniture

SCM – KEY MODULES AND FUNCTIONALITIES

1. Procurement and Supplier Management

This module is the starting point of the supply chain, focusing on acquiring the raw materials
needed for production.
Shutterstock

• Overview of Procurement Modules :


o Supplier Selection: The process of evaluating and choosing vendors based on
price, quality, and reliability.
▪ Example: An iPhone manufacturer evaluating three different glass
suppliers to see which one offers the strongest glass at the best price.
o Purchase Order (PO) Management: The creation and tracking of official
contracts (POs) sent to suppliers to buy goods.
▪ Example: Sending a digital PO to a steel vendor for "50 Tons of Steel" to
be delivered by next Tuesday.
o Supplier Relationship Management (SRM): Software dedicated to managing
the long-term relationship with vendors, tracking their performance and history.
▪ Example: Using SRM software to rate a supplier 2/5 stars because they
were late three times this month, prompting a renegotiation.
• Importance of Supplier Management:
o Quality: Ensuring raw materials meet standards so the final product isn't
defective.
o Cost Efficiency: Negotiating better rates for bulk orders.
o Timely Delivery: Ensuring materials arrive on time to prevent factory stoppages.
• Role of E-Procurement and Supplier Portals:
o E-Procurement: Using the internet to purchase goods and services digitally
rather than via paper trails.
o Supplier Portals: A web portal where suppliers can log in to see what the
company needs, submit invoices, and update delivery times themselves.
▪ Example: A car parts supplier logs into Toyota's portal to see that the
factory needs 500 tires tomorrow and confirms the shipment instantly.

2. Inventory Management

This module balances the fine line between "too much stock" (expensive storage) and "too little
stock" (lost sales).

• Overview of Inventory Functionalities:


o Stock Levels: Real-time tracking of exactly how many items are on the shelf.
o Demand Forecasting: Using historical data to predict how much stock will be
needed in the future.
▪ Example: Predicting that umbrella sales will spike in April due to the rainy
season.
o Reorder Points: A pre-set level that triggers an automatic new order.
▪ Example: "When stock drops below 10 units, automatically order 50
more."
• Importance of Inventory Optimization:
o Reducing Carrying Costs: Storing inventory costs money (rent, electricity,
security). Optimization minimizes this.
o Avoiding Stockouts: Ensuring customers don't leave empty-handed because the
product was sold out.
• Role of Advanced Inventory Strategies:
o Just-in-Time (JIT): A strategy where materials arrive exactly when production
starts, so zero inventory is held in storage.
▪ Example: A car seat arrives at the factory 2 hours before it is bolted into
the car.
o Vendor-Managed Inventory (VMI): The supplier monitors the buyer's
inventory and refills it without being asked.
▪ Example: Coca-Cola's distributor checks a supermarket's shelf and
restocks it, rather than the supermarket manager placing an order.

3. Production Planning and Scheduling

This module manages the "Factory Floor," ensuring that production meets demand without
overloading machines or workers.
Shutterstock

• Overview of Planning Modules:


o Master Production Schedule (MPS): The high-level plan stating what to make
and when.
▪ Example: "We need to build 500 red sedans in Week 1 and 300 blue
trucks in Week 2."
o Materials Requirement Planning (MRP): Calculates the raw materials needed
to execute the MPS.
▪ Example: "To build those 500 red sedans, we need 2,000 tires and 500
steering wheels delivered by Monday."
o Capacity Planning: Checking if the factory actually has enough machines and
workers to meet the schedule.
▪ Example: Realizing we only have 10 robots, so we can't build 500 cars in
one day; we must spread it over three days.
• Importance of Alignment:
o Aligning Production with Demand Forecasts: Making sure you don't build
1,000 units when the forecast says you will only sell 100.
o Supply Chain Constraints: Planning around limitations (e.g., if a machine is
down for maintenance).
• Role of APS (Advanced Planning and Scheduling) Systems:
o Optimization: Using algorithms to find the absolute best way to schedule
production to minimize downtime and cost.
▪ Example: An APS system rearranges the schedule so that all "Red Paint"
cars are painted in a row, saving the time it takes to wash the paint nozzles
between colors.

4. Logistics and Transportation Management

This module moves the product from the factory to the customer.

• Overview of Logistics Modules:


o Transportation Management: Planning how goods move (Truck, Train, Ship,
Air).
o Route Optimization: Finding the fastest or cheapest path for a vehicle.
▪ Example: UPS software calculating a route that avoids all left turns to save
fuel and time.
o Freight Management: Handling the costs and contracts with shipping carriers
(e.g., DHL, Maersk).
• Importance of Efficient Logistics :
o Reducing Costs: Fuel and shipping are massive expenses; efficiency saves
millions.
o Timely Delivery: Ensuring the "Amazon Prime" promise of 2-day delivery is
met.
• Role of Specialized Systems:
o TMS (Transportation Management System): Software specifically for
managing fleets and carriers.
o WMS (Warehouse Management System): Software that controls operations
inside the warehouse (e.g., telling a forklift driver exactly which aisle to go to).

5. Order Fulfillment and Distribution

This module is the final step where the customer actually gets what they paid for.

• Overview of Fulfillment Modules:


o Order Processing: Receiving the digital order and validating it.
o Picking: Finding the item on the warehouse shelf.
o Packing: Putting it in a box with bubble wrap.
o Shipping: Handing it to the carrier.
• Importance of Accuracy and Efficiency:
o Customer Satisfaction: If you send the wrong item (picking error) or it arrives
broken (packing error), the customer is angry.
• Role of Distribution Strategies:
o Distribution Centers (DC): Large hubs used to store goods closer to customers
to speed up delivery.
o Cross-Docking: A strategy where goods are unloaded from an incoming truck
and immediately loaded onto an outgoing truck with no storage time in between.
▪ Example: A truck full of fresh milk arrives; the pallets are instantly moved
to 10 smaller delivery vans. The milk never sits on a shelf.

SCM – TECHNOLOGICAL IMPACT & INNOVATION

I have broken this down into the three specific areas covered in the slides: The Role of
Technology, Emerging Technologies, and Cloud-Based Solutions.

1. Role of Technology in SCM

Technology is no longer just a support function; it is the driver of modern supply chains.

• Overview of Transformation:
o Technology transforms SCM from a linear, manual process into a dynamic,
digital ecosystem. It replaces paper trails with digital footprints.
• Impact of Digitalization:
o Real-time Data: Instead of waiting for a "Daily Report," managers see data
instantly.
▪ Example: A dashboard showing exactly how many units of "Product X"
are being scanned at checkout counters globally right this second.
o Automation: Removing human intervention from repetitive tasks.
▪ Example: Automated ordering systems that instantly place a restock order
with a supplier when inventory drops below 10 units, without a human
manager approving it.
o Enhanced Visibility: Seeing the entire chain from end-to-end.
▪ Example: A manager in New York can see that a container in the middle
of the Pacific Ocean is delayed by 2 days due to a storm.
• Importance of Integration:
o SCM cannot work alone. It must integrate with:
▪ ERP: For financial data.
▪ CRM: For customer demand data.
▪ BI (Business Intelligence): For strategic analysis.
2. Emerging Technologies in SCM

The slides highlight four specific cutting-edge technologies that are revolutionizing the industry.

A.
Internet of Things (IoT)

• Function: Real-time tracking and monitoring of goods and assets across the supply
chain.
• How it works: Placing sensors on physical objects that send data back to the SCM
system.
• Detailed Example: Cold Chain Logistics.
o A pharmaceutical company ships vaccines that must stay below -20°C.
o IoT sensors inside the truck monitor the temperature every second.
o If the temperature rises to -19°C, the sensor instantly alerts the driver and the head
office before the vaccines are ruined.

B.
Blockchain

• Function: Enhancing transparency and traceability.


• How it works: Creating a shared, unchangeable digital ledger that records every time a
product changes hands.
• Detailed Example: Food Safety.
o A supermarket sells a bag of spinach.
o Using Blockchain, they can trace that exact bag back to the specific farm, the
specific field, and the specific date it was picked.
o If there is an E. coli outbreak, they can recall only the affected bags instead of
throwing away all spinach.

C.
AI and Machine Learning (AI/ML)

• Function: Using algorithms to make smart decisions and predictions.


• Key Applications:
o Demand Forecasting: Predicting what customers will buy before they buy it.
▪ Example: AI analyzes weather reports and predicts a heatwave,
automatically ordering 20% more ice cream for stores in the affected
region.
o Predictive Maintenance: Predicting when a machine will break.
▪ Example: ML analyzes the vibration of a conveyor belt and warns:
"Bearing #4 will fail in 48 hours." Technicians fix it before it breaks,
preventing a factory shutdown.
o Supply Chain Optimization: Finding the absolute best routes and schedules.

D.
Robotics

• Function: Automating physical tasks.


• Example: Amazon Kiva Robots. instead of humans walking miles inside a warehouse
to find a book, a small robot drives under the shelf, lifts it up, and brings the shelf to the
human packer.

3. Cloud-Based SCM Solutions

The industry is moving away from installing software on big servers in the basement (On-
Premise) to renting software over the internet (Cloud).

• Overview of Cloud-Based SCM:


o It offers flexibility and accessibility that old systems cannot match.
• Comparison: On-Premise vs. Cloud:
o On-Premise: High upfront cost (buying servers), hard to update, accessed only
from the office.
o Cloud: Low upfront cost (monthly subscription), automatic updates, accessed
from anywhere.
• Emerging Trends:
o SaaS (Software as a Service): Paying for SCM like a subscription (e.g., Netflix
model).
o Multi-tenant Architecture: Multiple companies sharing the same secure
infrastructure to lower costs.
o Mobile Access: Managing the supply chain from a smartphone.
▪ Example: A logistics manager is at home having dinner. They get an alert
on their phone that a truck broke down. They use the Mobile SCM App to
reroute a nearby truck to pick up the cargo, solving the problem in minutes
without going to the office.

SCM – BORDERLESS APPLICATION

1. Managing Global Supply Chains

Supply chains today are rarely confined to a single country; they are "borderless" networks.
Managing them requires navigating a web of international complexity.
• Overview of Complexities:
o Managing global supply chains involves handling operations across different time
zones, languages, and cultural practices.
o It requires dealing with longer lead times (shipping across oceans) and varying
infrastructure quality in different regions.
• Global Sourcing and Supplier Diversity:
o Global Sourcing: The practice of procuring materials from the best source
worldwide, not just the nearest one.
o Supplier Diversity: Reducing reliance on a single country or vendor.
o Example: Instead of buying 100% of microchips from a single factory in Taiwan,
a company sources 60% from Taiwan and 40% from Germany. This ensures that
if a local event (like a typhoon) hits one region, production continues elsewhere.
• Risk Management: Implementing strategies to handle the uncertainties of international
trade.
• Regulations, Tariffs, and Customs:
o Companies must navigate complex global trade regulations.
o Tariffs: Taxes on imports that impact the final cost of goods. SCM systems help
calculate the "Landed Cost" to determine if importing is profitable.
o Customs: The bureaucratic process of clearing borders. Delays here can stall an
entire production line.
o Example: An SCM system automatically generates the specific customs
documentation required for a shipment of cotton to enter the European Union,
preventing it from being held at the port.

2. Supply Chain Risk Management

Because global supply chains are extended and complex, they are vulnerable to many types of
disruption.

• Overview of Supply Chain Risks:


o Natural Disasters: Earthquakes, floods, or hurricanes that destroy factories or
disrupt shipping lanes.
o Geopolitical Risks: Wars, sanctions, or trade disputes that suddenly block access
to a market.
o Supplier Failures: A key vendor going bankrupt or failing to meet quality
standards.
o Demand Fluctuations: Sudden, unexpected spikes or drops in customer demand
(e.g., the sudden demand for masks during a pandemic).
• Mitigation Strategies:
o Risk Assessment: Proactively identifying which parts of the chain are weak.
o Contingency Planning: Developing "Plan B" scenarios.
o Example: "If the Suez Canal is blocked, we have a pre-approved contract with an
air freight carrier to fly essential parts immediately."
• Role of SCM Systems:
o Systems identify and manage risks by monitoring real-time data.
o Modern tools can alert managers to potential disruptions (like a port strike) days
before they impact operations.

3. Sustainability in SCM

Modern SCM is not just about speed and cost; it is about responsibility.

• The Three Aspects of Sustainability :


o Environmental: Reducing carbon emissions, waste, and water usage.
o Social: Ensuring fair labor practices and safe working conditions in supplier
factories.
o Economic: Ensuring the business model is profitable and viable long-term.
• Key Strategies:
o Sustainable Sourcing: Choosing raw materials that are renewable or ethically
harvested.
o Green Logistics: Optimizing transportation to burn less fuel (e.g., combining
shipments to reduce truck trips).
o Circular Supply Chains: Designing products where materials can be returned
and recycled at the end of their life, rather than thrown away.
• Role of SCM Systems in Reporting:
o SCM systems track and report sustainability metrics to meet legal requirements
and customer expectations.
o Example: A coffee company uses SCM to track beans from the farm to the cup,
proving to customers that the farmers were paid a fair wage (Fair Trade
certification).

4. Collaboration and Communication

A global supply chain fails without constant communication between all parties.

• Importance of Collaboration:
o Success requires teamwork among Suppliers, Manufacturers, and Customers.
o It moves relationships from being purely transactional (buying/selling) to strategic
partnerships.
• Information Sharing:
o Communication and information sharing improve supply chain visibility and
coordination.
o Example: If a manufacturer shares their production schedule with their supplier,
the supplier knows exactly when to deliver materials, eliminating the need for
expensive warehousing.
• Tools for Collaboration:
o Collaboration Platforms: Cloud-based tools where all partners log in to view
shared data.
o Supply Chain Visibility Tools: Dashboards that show the real-time status of
orders and shipments across the entire network.
Week – 9 & 10: Banking and digital wallets

1. Digital Wallet Systems


What is a Digital Wallet System?

• Definition: Also known as e-wallets, these are electronic platforms that allow users to
store payment information and make transactions digitally. They eliminate the need to
carry physical cash or plastic cards .
• Platform: These systems typically run on smartphones, tablets, or computers.
• Connectivity: They can be linked to a user's bank account, credit card, or other payment
methods to fund transactions.

Key Features

• Secure Storage: They safely store payment information (card numbers, bank details).
• Payments & Transfers: They facilitate making payments to merchants and transferring
money to other people.
• Contactless Transactions: They support technologies like NFC (Near Field
Communication) for "tap-to-pay" transactions.

Real-World Examples

• Oracle Wallet Platform


• Huawei Wallet Platform
• Ericsson Wallet Platform

Use Case: Apple Pay

• Integration: It is integrated directly into iPhones.


• Function: It allows users to store their credit/debit card information securely on the
device.
• Usage: Users can make purchases in physical stores (by tapping their phone) or online
without entering card details repeatedly.

2. Digital Wallet Platforms

While a "System" is what the user sees, the "Platform" is the infrastructure that powers it.
Introduction to Digital Wallet Platforms

• Role: These platforms are critical in the modern payments industry and for FinTech
companies.
• Scope: They provide the backend software solutions that enable digital payments to
function.

Components of a Digital Wallet Solution

To build a functioning digital wallet, several technical components must work together:

1. Payments: The core ability to move money.


2. Payment Gateways: The bridge that connects the wallet to the banking network.
3. Authentication and Authorization: Security layers that verify the user is who they say
they are (e.g., FaceID, PINs).
4. Payment Network Integration: Connecting to networks like Visa, Mastercard, or local
banking switches.
5. Account Linking: Connecting the wallet to a real bank account or credit card.
6. Transaction Management: Recording the history of every penny spent or received.
7. Fund Transfer: Moving money between users (P2P).
8. Rewards and Loyalty: Managing points or cashback offers to keep users engaged.

Types of Payment Solutions

Digital wallet platforms often support multiple types of financial interactions:

• Card Payments: Using stored credit/debit cards.


• Transactional Systems: Handling high volumes of daily transactions.
• Digital Wallets: The stored value accounts themselves.
• Fund Transfer Systems: Peer-to-peer (P2P) sending.
• Payment Gateways: Processing online payments.
• Point of Sale (POS): Integration with the physical registers in stores.

Payment systems – key modules and functionalities

Since the slides provide the list of these critical components, I have expanded on each one with
detailed industry-standard definitions and examples to ensure you have the full context for your
"Deep Dive" study.
1. Card Payments

• Definition: The module responsible for processing transactions made via credit, debit, or
prepaid cards. It handles the communication between the Merchant, the Acquirer
(Merchant's Bank), the Card Network (Visa/Mastercard), and the Issuer (Customer's
Bank).
• Key Functionality:
o Authorization: Verifying the user has enough funds.
o Clearing & Settlement: Moving the actual money between banks.
• Example: A customer swipes a Visa card at a grocery store. This module encrypts the
card data, sends it to Visa, checks the balance, and returns an "Approved" message in
seconds.

2. Digital Wallets

• Definition: Software-based systems that store payment credentials (cards) or hold a


stored value (money balance) to make transactions easier and more secure.
• Key Functionality:
o Tokenization: Replacing real card numbers with a unique digital token to prevent
theft.
o NFC Support: Enabling "Tap to Pay."
• Example: Apple Pay. Instead of pulling out a physical card, you tap your phone. The
system uses a secure token, so the merchant never sees your real credit card number.

3. Core Banking Solutions

• Definition: The back-end engine of a bank that processes daily banking transactions and
posts updates to accounts and other financial records. It is the "source of truth" for
account balances.
• Key Functionality:
o Ledger Management: Recording every debit and credit.
o Balance Calculation: Calculating interest and current funds.
• Example: Temenos or Oracle FLEXCUBE. When you deposit $100, the Core Banking
system updates your balance from $500 to $600 and records the timestamp and location
of the deposit.

4. Lending

• Definition: A module designed to manage the entire lifecycle of a loan, from application
to final repayment.
• Key Functionality:
o Origination: Processing the loan application and checking credit scores.
o Servicing: Calculating monthly interest and collecting payments.
• Example: A Personal Loan inside a banking app. The user applies for $5,000. The
Lending module checks their credit score, approves the loan, disburses the cash, and sets
up a monthly auto-debit of $200.

5. Bank Transfers

• Definition: Mechanisms for moving funds directly from one bank account to another,
often without using card networks.
• Key Functionality:
o Domestic Transfers: Moving money within the country (e.g., ACH, Wire).
o International Transfers: Moving money across borders (SWIFT).
• Example: Sending money to your landlord via Bank Wire. You enter their Account
Number and Routing Number, and the funds move directly from your bank to theirs.

6. Crypto Payments

• Definition: Modules that enable the processing of payments using cryptocurrencies


(digital assets) on a blockchain.
• Key Functionality:
o Wallet Integration: Connecting to a crypto wallet.
o Conversion: Converting Crypto to Fiat (e.g., Bitcoin to USD) for the merchant.
• Example: Paying for a Tesla using Bitcoin. The system verifies the transaction on the
Blockchain ledger rather than through a central bank.

7. Payment Gateways

• Definition: The technology used by merchants (especially online) to accept electronic


payments. It acts as the digital version of a "Card Reader" (POS terminal).
• Key Functionality:
o Encryption: Securing sensitive data before sending it to the processor.
o Integration: connecting a website's "Checkout" button to the banking network.
• Example: Stripe or PayPal on an e-commerce website. When you click "Buy Now," the
Payment Gateway pops up, takes your card info securely, and tells the website "Payment
Successful."

8. P2P Payments (Peer-to-Peer)

• Definition: Platforms that allow individuals to transfer funds instantly to other


individuals, usually via a mobile app, without needing the recipient's bank account
number (often using email or phone number).
• Key Functionality:
o Instant Transfer: Real-time movement of funds.
o Social Integration: Adding notes or emojis to payments.
• Example: Venmo or Zelle. You owe a friend $10 for pizza. You select their name in the
app, type "$10 for Pizza," and the money appears in their account instantly.

9. BNPL (Buy Now, Pay Later)

• Definition: A point-of-sale financing option that allows customers to purchase items


immediately but pay for them in installments over time.
• Key Functionality:
o Soft Credit Check: Instant approval without hurting credit score.
o Installment Management: Splitting a $100 purchase into four $25 payments.
• Example: Klarna or Afterpay. You buy a $200 jacket online but only pay $50 today.
The BNPL module automatically charges your card $50 every two weeks until it's paid
off.

10. ESCROW

• Definition: A contractual arrangement where a third party receives and disburses money
for the primary transacting parties. The money is held by the "Escrow" module until
agreed-upon conditions are met.
• Key Functionality:
o Risk Mitigation: Ensuring the buyer gets the product and the seller gets the
money.
• Example: Freelance Work (Upwork/Fiverr). The client deposits money into Escrow.
The freelancer does the work. Once the client confirms they are happy with the work, the
Escrow module releases the money to the freelancer.

11. ETC (Electronic Toll Collection / Others)

• Definition: "ETC" in payment contexts often refers to Electronic Toll Collection


(automated payments for driving on roads) or simply "Etcetera" covering other niche
payment types.
• Example (Toll): EZ-Pass. A tag on your car talks to a sensor on the highway, and the
ETC module deducts the toll from your prepaid wallet while you drive 60mph.

PAYMENT SOLUTIONS – TECHNOLOGICAL IMPACT & INNOVATION

1. The Role of Technology in Payment Solutions

Technology is the primary driver transforming traditional banking into the modern "FinTech"
ecosystem. It has moved payments from physical cash to invisible digital transactions.

• Transforming Payment Solutions:


o Technology has shifted the focus from "Transaction Processing" (just moving
money) to "Customer Experience" (making it fast, easy, and fun).
o Example: In the past, you had to visit a bank branch to wire money. Today, APIs
allow apps like Venmo or WhatsApp Pay to send money instantly while chatting
with a friend.
• Impact of Digitalization:
o Digitalization enables Real-Time Data and automation. It removes manual
reconciliation errors and speeds up settlement times from days to seconds.
o Example: Instant Settlements. Instead of a merchant waiting 3 days for credit
card funds to arrive in their bank account, digital solutions can settle the funds
immediately.
• Integration with Enterprise Systems:
o Payment solutions must not work in isolation. They need to integrate with ERP
(for accounting), CRM (for customer history), and BI (for analytics).
o Example: When a customer pays an invoice online, the Payment Gateway
(Technology) instantly tells the ERP system "Invoice Paid," updates the General
Ledger, and stops the CRM from sending "Payment Overdue" emails.

2. Emerging Technologies in Payment Systems

The slides highlight four specific technologies that are reshaping how we pay .

A. Internet of Things (IoT)

• Concept: Connecting physical devices to payment networks so they can pay for things
automatically on your behalf.
• Role: Enables "Invisible Payments" where the transaction happens in the background
without the user pulling out a card.
• Example: Smart Fridge. Your Samsung fridge detects you are out of milk. It orders a
new gallon from the grocery store and pays for it automatically using your stored digital
wallet credentials.
• Example: Connected Car. You drive through a toll booth or a drive-thru. The car itself
broadcasts a payment token to the merchant's sensor, and the payment is made without
you rolling down the window.

B. Blockchain

• Concept: A decentralized, distributed ledger that records transactions securely and


transparently without a central authority (like a bank).
• Role:
o Security: Once a transaction is recorded on the blockchain, it cannot be altered or
deleted.
o Cost Reduction: It removes intermediaries (middleman banks), lowering
transaction fees for cross-border payments.
• Example: Cross-Border Remittance. A worker in the UAE sends money to their family
in India using a blockchain-based service (like Ripple). The money arrives in seconds
rather than days, and the fees are a fraction of standard SWIFT wire transfers.

C. Artificial Intelligence & Machine Learning (AI/ML)

• Concept: Using algorithms to analyze transaction data in real-time to make smart


decisions.
• Role:
o Fraud Detection: AI analyzes spending patterns. If your card is used in London
and 5 minutes later in New York, the AI blocks the transaction instantly because
it knows that travel is physically impossible.
o Personalization: AI suggests payment methods or offers coupons based on your
buying history.
• Example: Chatbot Banking. A bank uses an AI chatbot to help users reset passwords,
check balances, or pay bills via text command, 24/7 without human agents.

D. Crypto (Cryptocurrency)

• Concept: Digital currencies (like Bitcoin, Ethereum, or Stablecoins) used as a medium of


exchange.
• Role: Provides an alternative to government-issued currency (Fiat), offering user
anonymity and global reach.
• Example: Stablecoin Payments. A freelancer in Argentina prefers to be paid in USDC
(a stable crypto pegged to the dollar) to avoid local currency inflation.

3. Cloud-Based Payment Solutions

The industry is moving infrastructure from on-premise servers to the Cloud.

• Overview:
o Cloud payment solutions are hosted by providers like AWS, Azure, or Google
Cloud, allowing banks and fintechs to rent computing power instead of building
data centers.
• Comparison: On-Premises vs. Cloud:
o On-Premises: High security control but expensive to maintain and hard to scale
(e.g., if traffic spikes on Black Friday, the servers might crash).
o Cloud-Based: Highly scalable (auto-scales during traffic spikes), lower upfront
cost, and faster to deploy new features.
• Emerging Trends:
o Payments-as-a-Service (PaaS): Banks renting a cloud-based payment engine to
launch a new digital wallet in weeks instead of years.
o Serverless Architecture: Paying only for the exact computing time used per
transaction, reducing costs significantly for startups.

PAYMENT SOLUTIONS – BORDERLESS APPLICATION

here are the detailed notes for Payment Solutions – Borderless Application.

This section focuses on how payment systems operate globally (borderless) and the critical risk
management strategies required to keep them safe.

1. Global Payment Systems (Borderless Applications)

A "Borderless" application is one that works seamlessly across different countries, currencies,
and banking regulations. It allows a user to travel anywhere in the world and pay using the same
device or account they use at home.

• Concept: These systems abstract the complexity of international banking (currency


conversion, different banking switches) away from the user.
• Key Examples mentioned in the slides:

A.

Apple Wallet

o What it is: A mobile wallet integrated into iOS devices that tokenizes credit and
debit cards.
o How it is Borderless:
▪ Apple Pay relies on NFC (Near Field Communication), which is a
global standard.
▪ Example: A traveler from the USA can walk into a coffee shop in London
or Tokyo. They tap their iPhone on the payment terminal. Apple Wallet
automatically communicates with the terminal, the network performs the
currency conversion (USD to GBP/JPY), and the transaction approves
instantly. The user does not need to buy local currency or get a local card.

B.

Google Wallet

o What it is: The Android equivalent of Apple Wallet, storing cards, boarding
passes, and loyalty programs.
o How it is Borderless:
▪ It integrates with millions of global merchants and supports multiple
payment rails (Visa, Mastercard, PayPal).
▪ Example: A freelancer in Germany can use Google Wallet to pay for a
software subscription hosted in the USA. Google Wallet handles the cross-
border transaction fees and security verification in the background.

C.

ETC (Etcetera / Other Global Players)

o This refers to other massive cross-border ecosystems like PayPal, Samsung Pay,
AliPay, or WeChat Pay.
o Example: AliPay allows Chinese tourists to pay for luxury goods in Paris using
their home currency (RMB) via a QR code, while the French merchant receives
Euros.

2. Payment Systems Risk Management

When payment systems go borderless, the risks multiply. You are no longer just fighting local
fraudsters; you are fighting global hacking syndicates and navigating international laws.

A.
Overview of Risks

Operating a global payment system exposes the enterprise to specific threats:

• Cross-Border Fraud: Hackers in one country stealing credentials from users in another.
• Regulatory Risk: Every country has different laws (e.g., GDPR in Europe vs. Federal
Reserve rules in the USA). Breaking these can result in massive fines.
• Currency Fluctuation: The risk that the exchange rate changes between the moment the
transaction is authorized and when it settles (FX Risk).
• Operational Risk: System outages in one region affecting global transactions.

B.
Importance of Risk Assessment and Mitigation

To survive, EIS Payment Solutions must implement three layers of defense:

1. Risk Assessment:
o Definition: Proactively identifying vulnerabilities before they are exploited.
o Example: Before launching Apple Pay in a new country, Apple assesses the local
banking infrastructure's security standards to ensure it isn't vulnerable to "Man-in-
the-Middle" attacks.
2. Mitigation Strategies:
o Definition: Technologies and rules implemented to reduce risk.
o Strategy 1: Tokenization: Replacing real card numbers with random digital
tokens. If a hacker intercepts the transaction in a foreign country, the token is
useless to them.
o Strategy 2: AI Fraud Detection: Using Machine Learning to spot anomalies.
▪ Example: If a US user's card is used physically in New York at 9:00 AM
and then physically in Hong Kong at 9:15 AM, the system instantly
blocks the second transaction because physical travel is impossible.
3. Contingency Planning:
o Definition: Having a "Plan B" for when things go wrong.
o Example: If the primary undersea internet cable connecting Europe and America
is cut, the payment system must automatically reroute transaction data through
satellite or alternative cables to prevent global payment failures.

DIGITAL WALLET SOLUTIONS - BENEFITS

Digital Wallet Solutions - Benefits

The shift from physical leather wallets to digital wallets is driven by ten specific advantages that
improve the experience for both the user and the merchant.

1. Convenience

• Definition: Allows for easy and fast payments directly via smartphones, eliminating the
need to carry a bulky physical wallet.
• Example: You go for a morning run and want to buy water. You don't have your cash or
cards, but you can simply double-click your Apple Watch to pay instantly.

2. Security

• Definition: Digital wallets use advanced Encryption and Tokenization technology. This
reduces the risk of fraud because the merchant never sees your actual card number.
• Example: When you pay at a gas station with a digital wallet, the system sends a random
"Token" (e.g., 1234-XYZ) instead of your real Visa number. If hackers steal the gas
station's data, they only get useless tokens, not your credit card info.

3. Contactless Payments

• Definition: Supports NFC (Near Field Communication) technology for touch-free


transactions. This is faster and more hygienic than handling cash or touching pin pads.
• Example: During a flu season or pandemic, you can pay for groceries by hovering your
phone over the terminal without touching any dirty buttons.

4. Integration

• Definition: Seamlessly integrates with E-commerce (online stores) and POS (Point of
Sale) systems (physical registers).
• Example: When shopping on a website like Shopify, you don't need to type your 16-digit
card number and address. You just click the "Buy with Google Pay" button, and the
wallet automatically fills in all the details.

5. Multi-functionality

• Definition: These wallets are not just for money; they can store multiple credit cards,
debit cards, discount coupons, loyalty cards, and even event tickets.
• Example: Your Google Wallet can hold your Visa card, your Starbucks Loyalty Card,
your United Airlines boarding pass, and a concert ticket all in one app.

6. Accessibility

• Definition: Users can access their funds and transaction history anytime, anywhere, 24/7.
• Example: You are on vacation in a different time zone and need to check if your salary
has been deposited. You can open the wallet app at 3:00 AM local time and see your
funds instantly.

7. Cost Efficiency

• Definition: Digital transactions often reduce transaction costs for businesses and
sometimes fees for users compared to traditional methods.
• Example: A small coffee shop might pay high fees to rent a physical credit card
machine, but accepting payments via a QR Code wallet (like Venmo or Alipay) often
incurs lower processing fees.

8. Speed

• Definition: Enables faster checkout lines and quicker money transfers compared to
counting cash or waiting for chip cards to process.
• Example: Paying at a subway turnstile. Inserting a credit card takes ~10 seconds.
Tapping a phone takes ~1 second, preventing long lines during rush hour.
9. Record Keeping

• Definition: The system automatically tracks every transaction for the user, creating an
organized digital history.
• Example: Instead of keeping paper receipts for tax season, a freelancer can export their
entire spending history from their digital wallet to Excel to categorize expenses instantly.

10. Rewards

• Definition: Often integrated with loyalty programs and cashback offers, applying them
automatically during payment.
• Example: When you pay with the "Target Circle" app, it pays for your groceries and
automatically scans your coupons and adds loyalty points in a single scan, so you never
miss out on rewards.
Week – 11: EIS - HRMS & Integration

1. HRMS - Human Resource Management System

This section defines what the system is and why it is critical for modern enterprises.

• Definition: HRMS is a comprehensive suite of software applications designed to manage


human resources and related business processes throughout the employee lifecycle.
• Purpose:
o Streamline Processes: Automating routine tasks (like attendance tracking) to
save time.
o Improve Data Management: Moving away from paper files to a secure, digital
database.
o Enhance Decision-Making: Providing managers with data (analytics) to make
better hiring and promotion decisions.
• Scope: It is not just about "paying people." The scope covers Recruitment (finding
talent), Payroll (paying them), Performance Management (evaluating them), and much
more.
• Relevance: It is considered essential for modern enterprises to manage a large workforce
efficiently. Without it, compliance and tracking become impossible at scale.

2. HRMS - Evolution

The history of HRMS shows a shift from simple record-keeping to intelligent, integrated
systems.

• Early Systems (Pre-1980s):


o Relied on Manual Processes (filing cabinets, paper forms).
o Used Basic Computer Applications (like simple spreadsheets) for tracking lists
of names.
• 1980s - 1990s (The Standalone Era):
o Introduction of Standalone HR Software.
o These systems were installed on specific computers and did not talk to other
systems. Payroll was often separate from Personnel records.
• 2000s (The Integration Era):
o Integration with ERP: HRMS became a "Module" within larger Enterprise
Resource Planning systems (like SAP or Oracle).
o This allowed HR data to flow into Finance and Operations automatically.
• Present (The Intelligent Era):
o Cloud-Based: Accessed via the internet (SaaS) rather than installed on office
servers.
o AI-Driven: Using Artificial Intelligence to predict turnover or scan resumes
automatically.

3. HRMS – Core Modules

The slides categorize the system into "Core Modules" (Foundational) and specific "Functional
Modules." Below is the detailed breakdown of both to ensure you have the full picture.

A. The Foundational Core (Slide 6)

These are the pillars that hold the system together :

1. Employee Records: A centralized database serving as the "Single Source of Truth" for
all employee info (Contact details, history, emergency contacts).
2. Organizational Structure: Digital mapping of the company hierarchy, departments, and
roles (Who reports to whom).
3. Compliance: Tools ensuring the company follows labor laws, tax regulations, and safety
standards to avoid fines.
4. Reporting: Generating standard HR reports (Headcount, Turnover rate) and analytics for
leadership.

B. Detailed Functional Modules (Slides 7–12)

These modules handle specific HR tasks on top of the core foundation.

• Payroll Module:
o Salary Calculations: Automating complex math for gross-to-net pay.
o Tax Deductions: Automatically withholding the correct tax based on government
tables.
o Direct Deposits: Sending money directly to employee bank accounts.
o Payroll Reports: Summaries for the Finance department .
• Time & Attendance Module:
o Time Tracking: Clock-in/Clock-out systems (Biometric or App-based).
o Leave Management: Handling vacation requests, sick leave, and approvals.
o Overtime Calculation: Automatically applying "1.5x pay" rules when hours
exceed the limit.
o Attendance Reports: Identifying patterns of absenteeism .
• Benefits Administration Module:
o Enrollment: A portal where employees select their insurance/benefits packages.
o Claims Processing: handling reimbursement requests.
o Compliance: Ensuring benefit packages meet legal standards.
o Communication: Explaining complex benefit details to employees .
• Recruitment Module (ATS - Applicant Tracking System):
o Job Postings: One-click publishing of jobs to LinkedIn, Indeed, etc.
o Applicant Tracking: Managing candidates through the funnel (Applied ->
Interview -> Offer).
o Onboarding: Automating the "New Hire" paperwork and training setup.
o Recruitment Analytics: Measuring "Time to Hire" and "Cost per Hire" .
• Performance Management Module:
o Goal Setting: Managers and employees agree on KPIs for the year.
o Performance Reviews: Conducting annual or quarterly appraisals digitally.
o Feedback: Continuous feedback loops rather than just once a year.
o Development Plans: Creating a roadmap for the employee's career growth .
• Learning & Development (L&D) Module:
o Training Programs: Assigning mandatory training (e.g., "Cybersecurity
Basics").
o Skill Development: Tracking which skills employees have vs. what they need
(Gap Analysis).
o E-Learning: Hosting online courses and videos.
o Training Analytics: Measuring if the training actually improved performance .

Modules

1. Core Modules (The Foundation)

These modules form the backbone of the HRMS, ensuring the basic data structure and legal
compliance are in place.

• Employee Records:
o Detail: Acts as a centralized database for all employee information.
o Example: Storing personal details (address, phone), emergency contacts, and
employment history in one secure digital location instead of paper files.
• Organizational Structure:
o Detail: Defines and manages hierarchies, departments, and roles within the
company.
o Example: The system visually maps that the "Junior Developer" reports to the
"Team Lead," who reports to the "CTO."
• Compliance:
o Detail: Ensures adherence to labor laws and government regulations.
o Example: The system automatically flags if an employee is working more
consecutive hours than the local labor law allows.
• Reporting:
o Detail: Generates essential HR reports and analytics.
o Example: Generating a monthly "Headcount Report" or "Turnover Rate Report"
for the CEO.
2. Functional Modules

These are specialized modules designed to handle specific HR operations.

A. Payroll Module

• Salary Calculations:
o Detail: Automated processing of payroll.
o Example: The system automatically calculates: (Hours Worked × Hourly Rate) +
Bonuses = Gross Pay.
• Tax Deductions:
o Detail: Accurate calculation of taxes and ensuring compliance.
o Example: Automatically deducting the correct % for Income Tax and Social
Security based on the employee's tax bracket.
• Direct Deposits:
o Detail: Efficient disbursement of salaries directly to bank accounts.
o Example: Instead of printing paper checks, the system sends a digital file to the
bank to transfer funds to 500 employees simultaneously on the 30th of the month.
• Payroll Reports:
o Detail: Generating detailed summaries of payroll expenses.
o Example: A report showing the Finance Department exactly how much cash is
needed for salaries this month vs. last month.

B. Time & Attendance Module

• Time Tracking:
o Detail: Monitoring employee work hours.
o Example: Employees clock in using a fingerprint scanner or a mobile app when
they start work.
• Leave Management:
o Detail: Managing vacation, sick leave, and other absences.
o Example: An employee applies for "Annual Leave" in the portal, and the system
automatically checks if they have enough balance before sending it to the
manager for approval.
• Overtime Calculation:
o Detail: Accurate tracking and payment of overtime hours.
o Example: If an employee works 45 hours (where 40 is standard), the system
automatically flags the extra 5 hours to be paid at 1.5x the normal rate.
• Attendance Reports:
o Detail: Detailed records and analytics regarding attendance.
o Example: A report highlighting employees who are chronically late or absent on
Mondays.
C. Benefits Administration Module

• Benefits Enrollment:
o Detail: Managing the selection of employee benefits.
o Example: A new hire logs in to choose between "Plan A" (High Deductible) or
"Plan B" (Premium) health insurance.
• Claims Processing:
o Detail: Handling benefit claims efficiently.
o Example: An employee uploads a receipt for a gym membership reimbursement,
and the system routes it for approval.
• Compliance:
o Detail: Ensuring benefits packages comply with regulations.
o Example: Ensuring the health plan meets the minimum coverage standards
required by national law.
• Employee Communication:
o Detail: Informing employees about their benefits.
o Example: Sending automated emails during "Open Enrollment Season" to remind
employees to update their insurance choices.

D. Recruitment Module (Applicant Tracking System)

• Job Postings:
o Detail: Creating and managing job advertisements.
o Example: HR creates a job description for "Sales Manager" once, and the module
pushes it to LinkedIn, Indeed, and the company website simultaneously.
• Applicant Tracking:
o Detail: Tracking candidates through the entire hiring process.
o Example: Seeing clearly that Candidate A is in the "Screening" phase, while
Candidate B is in the "Interview" phase.
• Onboarding:
o Detail: Streamlining the process for new hires.
o Example: Automatically sending a welcome email with digital contract signing
and IT setup forms before the employee's first day.
• Recruitment Analytics:
o Detail: Analyzing metrics and performance.
o Example: Calculating "Cost per Hire" or "Time to Fill" to see if the recruitment
team is efficient.

E. Performance Management Module

• Goal Setting:
o Detail: Defining and tracking employee goals.
o Example: A manager sets a KPI for a salesperson to "Close $100k in deals in Q4."
• Performance Reviews:
o Detail: Conducting regular evaluations.
o Example: The system triggers a 360-degree review where peers, managers, and
subordinates rate an employee's performance.
• Feedback:
o Detail: Providing continuous feedback.
o Example: A "Kudos" button allowing a manager to give instant positive feedback
after a successful project, stored for the year-end review.
• Development Plans:
o Detail: Creating plans for employee growth.
o Example: Identifying that an employee wants to become a manager and assigning
them a mentorship path.

F. Learning & Development (L&D) Module

• Training Programs:
o Detail: Managing training initiatives.
o Example: Scheduling a mandatory "Safety Workshop" for all factory workers.
• Skill Development:
o Detail: Identifying and developing key skills.
o Example: Tracking that 50% of the IT team knows Python, but the company
needs 80%, so training is assigned.
• E-Learning:
o Detail: Providing online learning resources.
o Example: Accessing a library of video courses (like LinkedIn Learning
integration) directly within the HR portal.
• Training Analytics:
o Detail: Measuring effectiveness of programs.
o Example: Using post-training quizzes to see if employees actually retained the
knowledge.

3. Self-Service Components

These are critical interfaces that allow users to interact with the modules above without calling
HR.

A. Employee Self Service (ESS)

• Personal Information: Employees update their own address/phone number.


• Leave Requests: Submitting and tracking vacation requests.
• Benefits Enrollment: Selecting insurance and benefits independently.
• Payslips: Downloading monthly salary slips.
B. Manager Self Service (MSS)

• Approvals: One-click approval for leave requests or expenses.


• Team Management: Viewing team hierarchy and contact info.
• Performance Tracking: Monitoring the goals/stats of their direct reports.
• Reports: Accessing specific HR analytics relevant to their team.

4. HR Analytics

• Data Collection: Gathering data from all the modules above.


• Reporting: Generating detailed static reports.
• Dashboards: Visualizing metrics (e.g., graphs of gender diversity or retention rates).
• Decision Making: Using this data to inform strategic choices.

Integration with other EIS

An HRMS does not operate in a vacuum. To be truly effective, it must exchange data with other
core business systems to ensure that "People Data" drives business decisions across the
company.

1. Integration with ERP (Enterprise Resource Planning)

• The Connection: This is the most critical integration. While HRMS manages the people,
ERP manages the money and resources associated with those people.
• Key Function: Automating the flow of financial data from HR to Finance.
• Detailed Example: Payroll to General Ledger.
o Scenario: The HRMS runs the monthly payroll and calculates that $500,000 is
owed in salaries and $100,000 in taxes.
o Without Integration: An HR manager prints a report, and a Finance manager
manually types these numbers into the Accounting System (prone to error).
o With Integration: The HRMS instantly pushes a "Journal Entry" to the ERP's
General Ledger, automatically debiting the "Salary Expense" account and
crediting "Cash."

2. Integration with CRM (Customer Relationship Management)

• The Connection: Connecting "Sales Performance" with "Employee Compensation."


• Key Function: Aligning sales results with rewards.
• Detailed Example: Automated Commission Payouts.
o Scenario: A salesperson closes a $1 million deal, which is recorded in Salesforce
(CRM). They are owed a 2% commission.
o Integration: The CRM system detects the "Closed-Won" status and sends a data
packet to the HRMS Payroll Module stating: "Add $20,000 commission to
Employee #123's next paycheck."
o Result: The salesperson is paid accurately and on time without manual
calculations.

3. Integration with SCM (Supply Chain Management)

• The Connection: Aligning "Labor Supply" (HR) with "Production Demand" (SCM).
• Key Function: Optimizing workforce scheduling based on operational needs.
• Detailed Example: Shift Scheduling in Manufacturing.
o Scenario: The SCM system predicts a surge in orders for next week and
determines that the factory needs to run 24 hours a day.
o Integration: The SCM system sends a "Labor Requirement" request to the HRMS
Time & Attendance Module.
o Result: The HRMS automatically checks which employees are qualified and
available, then fills the extra shifts, ensuring the factory has enough workers to
meet the supply chain demand.

4. Data Flow (The Technical Backbone)

• Definition: Ensuring a seamless, two-way exchange of information between systems


without human intervention.
• Why it matters:
o Data Integrity: Eliminates "double entry" errors (e.g., spelling a name differently
in IT vs. HR).
o Security: Reduces the number of people handling sensitive data files.
• Real-World Mechanism:
o Single Sign-On (SSO): When an employee is terminated in the HRMS, the
integration automatically triggers the IT security system to block their access to
ERP, CRM, and Email instantly. This protects the company from data theft by ex-
employees.

1. Cloud-Based HRMS

The industry is aggressively moving away from "On-Premise" systems (software installed on
computers in the office basement) to "Cloud-Based" systems (SaaS - Software as a Service).

• Accessibility:
o Detail: The ability to access the HRMS from anywhere in the world, provided
there is an internet connection.
o Example: A manager on a business trip in London can approve a leave request for
an employee in New York instantly via their laptop or phone.
• Scalability:
o Detail: The system can easily grow (or shrink) as the organization changes. You
don't need to buy new physical servers to add more users.
o Example: A startup with 50 employees grows to 500 employees in one year. With
a cloud system, they just upgrade their subscription plan instantly. With an old
system, they would have had to buy expensive new hardware.
• Cost-Effectiveness:
o Detail: Reduces the massive upfront capital cost of buying servers and licenses.
Instead, companies pay a monthly subscription fee (OpEx).
o Example: Paying $5 per user/month instead of paying $100,000 upfront for a
server license.
• Data Security:
o Detail: While some fear the cloud, major providers (like AWS or Azure) often
have better security and compliance certifications than a small company’s internal
IT team.
o Example: Automatic backups and encryption ensure that if the office building
burns down, the employee data is safe in the cloud.

2. Future Trends in HRMS

The slides highlight four cutting-edge technologies that are reshaping HR.

• AI and Machine Learning:


o Detail: Automating complex decisions and enhancing processes.
o Example: Resume Parsing. Instead of a human reading 1,000 CVs, an AI scans
them, identifies the top 10 matches based on keywords, and ranks them for the
recruiter.
• Blockchain:
o Detail: Improving data security, transparency, and verification.
o Example: Verified Credentials. An employee's university degree is stored on a
blockchain. When they apply for a job, the new employer can instantly verify it is
real without calling the university.
• Mobile HRMS:
o Detail: The shift toward "Mobile-First" experiences.
o Example: Gig economy workers (like Uber drivers) don't have desks. They
manage their entire employment—pay, profile, tax documents—exclusively
through a mobile app.
• Predictive Analytics:
o Detail: Using historical data to predict future outcomes.
o Example: Flight Risk Analysis. The system analyzes data (e.g., an employee
hasn't had a raise in 2 years and lives far away) and warns the manager:
"Employee X is 80% likely to quit this month."
3. Challenges and Solutions

Implementing an HRMS is difficult. The slides outline the main hurdles and how to overcome
them.

• Data Privacy:
o Challenge: HR data is highly sensitive (Salary, SSN, Health info). Leaks are
catastrophic.
o Solution: Implementing Role-Based Access Control (RBAC) so a manager can
only see their own team's data, not the CEO's salary.
• System Integration:
o Challenge: Getting the HRMS to talk to the ERP (Finance) or legacy systems is
technically difficult.
o Solution: Using APIs and Middleware to create seamless, automated data
pipelines between systems.
• User Adoption:
o Challenge: Employees often resist using new tools, preferring to just "email HR"
instead of logging into the portal.
o Solution: Change Management. conducting training sessions and making the
interface (UI) as simple as Facebook so employees actually want to use it.
• Best Practices:
o Detail: Following proven methods for success.
o Key Strategy: Don't just automate the old, bad process. Optimize the process
first, then automate it. Also, involve "Power Users" early in the testing phase to
champion the system to their peers.
Week – 11 & 12

Phase 1: Strategic Foundation & Readiness

Goal: Before writing code or buying tools, an enterprise must understand WHAT AI is for them
and IF they are ready to handle it.

1. The Core Concept: From "Passive" to "Adaptive"

Most traditional Enterprise Information Systems (like an old ERP) are Passive. They wait for
you to type in data and then just store it.

• AI in EIS changes it to Adaptive. The system learns from the data to predict what will
happen next.

• Definition: Embedding intelligence into systems (ERP, CRM, SCM) to automate


workflows, improve decision-making, and personalize experiences.

Traditional EIS (Passive) AI-Enabled EIS (Adaptive)

Records that a machine broke down Predicts that a machine will break down tomorrow
yesterday. (Predictive Maintenance).

Tells you which customer is likely to leave (Churn


Shows a list of all customers.
Prediction).

2. The 4 Drivers: Why do we need this NOW?

Enterprises are not adopting AI just because it is cool; they are forced to by these four pressures:

1. Data Explosion: Companies generate terabytes of data daily. Humans cannot read it all,
but AI can.
2. Decision Complexity: Global supply chains move too fast for manual spreadsheets. You
need real-time decisions.

3. Customer Demands: Customers expect instant, personalized service (like Netflix


recommendations), not generic emails.

4. Cost Pressure: Automating repetitive tasks (like invoice entry) drastically reduces
operating expenses (OPEX).

3. The 5-Step Readiness Assessment

You cannot just "switch on" AI. You must pass these five checks first.

Step 1: Data Readiness

• The Question: Is your data clean, labeled, and accessible via APIs? Or is it messy and
stuck in spreadsheets?

• The Reality: Garbage In = Garbage Out. If your data is bad, your AI will be bad.

• Real-World Example: Easypaisa (Pakistan). Before they could build AI models to catch
fraud, they first had to build "transaction-level data pipelines" to collect and clean the
data. You cannot detect fraud if you don't have a clean history of transactions.

Step 2: Technology & Infrastructure

• The Question: Do you have the raw computing power (GPUs) and storage (Cloud)?

• The Reality: AI requires massive processing power that old on-premise servers cannot
handle.

• Real-World Example: Revolut (Global Fintech). They shifted to AWS (Amazon Web
Services) multi-region cloud. This gave them the scalable infrastructure needed to run
heavy AI workloads that a local data center couldn't support.

Step 3: Talent & Skills


• The Question: Do you have Data Scientists and ML Engineers? Do normal employees
understand basic AI?

• The Reality: You need experts to build it and staff who trust it enough to use it.

• Real-World Example: Nubank (Brazil). They didn't just buy software; they invested
heavily in hiring their own AI teams early on, giving them a massive advantage over
traditional banks.

Step 4: Governance & Compliance

• The Question: Do you have rules for AI ethics and bias? Can you comply with laws like
GDPR or SBP (State Bank of Pakistan) regulations?

• The Reality: If your AI breaks the law (e.g., discriminates in lending), you will be fined.

Step 5: Business Alignment

• The Question: Does this AI project actually make money or save money?

• The Risk: Avoiding "AI Theatre"—doing cool projects that look nice in a presentation
but add zero value to the business.

4. The Readiness Quadrant (Types of Organizations)

Organizations are classified based on two axes: Infrastructure (Tech) and Strategy/Culture.

• 1. The Leaders (High Infra + High Strategy)

o Status: "AI-Ready". They have the data pipelines and the strategic vision. AI is
tied to business goals.

o Examples: Amazon, Revolut. They use AI for everything from logistics to


customer support.

• 2. The Opportunists (High Infra + Low Strategy)

o Status: "Tech-First, No Direction". They have big servers and lots of data, but
no idea how to monetize it. They risk doing "AI for AI's sake."
o Examples: Some Telecom companies. They have massive amounts of user data
but fail to turn it into profitable products.

• 3. The Aspirers (Low Infra + High Strategy)

o Status: "Vision-Driven". The CEO has a clear vision ("We want AI credit
scoring!"), but their systems are too old (legacy) to support it. They need
investment.

o Examples: Mid-size banks. They want to do advanced lending but lack the APIs
and clean data.

• 4. The Laggards (Low Infra + Low Strategy)

o Status: "Not Ready". They have poor data quality, siloed systems, and no vision.

o Examples: Small traditional firms still running on manual paper/Excel


processes.
The Strategic Roadmap for AI Adoption
This roadmap describes the maturity levels of an organization. You cannot jump to
Stage 4 without fixing Stage 1.

Stage 1: Foundation (The "Cleanup" Phase)


• Goal: Building the infrastructure. You cannot do AI if your data is messy or
locked in old servers.
• Key Activities:
o Data Lakes: Moving data from scattered Excel sheets/silos into a central
repository (Data Lake) where AI can access it.
o Cloud Migration: Moving from on-premise servers (limited power) to the
Cloud (infinite scalable power for AI).
o API Integration: Ensuring different systems (Sales, HR, Finance) can
"talk" to each other via APIs.
• Example: An enterprise spending months cleaning terabytes of historical data
before buying any AI tools.

Stage 2: Augmentation (The "Assistant" Phase)


• Goal: AI helps humans do their job better/faster, but humans are still in charge.
• Key Activities:
o Reporting: Using AI to generate reports instantly instead of manually
compiling them.
o Chatbots: Handling basic queries so humans only deal with complex
ones.
o Anomaly Detection: AI flagging weird things (e.g., "This transaction looks
wrong"), but a human decides what to do.
• Example: A Customer Service Chatbot in a CRM that answers FAQs, letting
human agents focus on angry customers.

Stage 3: Automation (The "Robot" Phase)


• Goal: AI takes over repetitive tasks completely. Humans are removed from the
loop for these specific tasks.
• Key Activities:
o Intelligent Workflows: The system routes tasks automatically (e.g., "If
value < $50, approve automatically").
o RPA (Robotic Process Automation): Bots that mimic human clicks to
enter data across systems.
• Example: AI Invoice Reconciliation. The AI reads the invoice, matches it to the
purchase order, and approves payment without any human touching it.

Stage 4: Transformation (The "Autonomous" Phase)


• Goal: The entire business model changes. The enterprise becomes "Self-
Driving."
• Key Activities:
o Autonomous Enterprise: AI doesn't just execute tasks; it makes
decisions at scale.
o AI-Driven Decision Making: The system decides what to buy, when to
sell, and how to price items in real-time.
• Example: Predictive Supply Chain where the system predicts a hurricane in
Florida, automatically reroutes shipments, and reorders stock from a backup
supplier in Texas—all before a human manager even wakes up.

Summary Table for Exam

Stage Theme Role of AI Example

None yet (Building the Cleaning Data / Cloud


1. Foundation Prepare
house) Migration

2. Augmentation Assist Helper (Human + AI) Chatbots / Anomaly Alerts

Auto-Invoice Processing /
3. Automation Replace Doer (AI does the task)
RPA

4. Decider (AI runs the Autonomous Financial


Lead
Transformation strategy) Planning

Phase 2: Implementation & Applications

Focus: The practical execution—how to build AI into Enterprise Systems and where to apply it.

1. The Implementation Roadmap (How to Build)

This is the 5-step technical framework for deploying AI within an enterprise.

Step 1: Define the Business Problem


• The Rule: Do not start with technology; start with the specific problem you want to
solve.
• Categorization:
o Customer-Facing: Chatbots, personalization.
o Back-Office: Risk scoring, fraud detection.
• Slide Example: Easypaisa (Pakistan) didn't just ask for AI; they defined the problem as
needing "real-time fraud alerts" for transactions.

Step 2: Data Strategy

• Collection: Gather raw logs from transaction history, KYC data, and CRM interactions.
• Cleaning: You must remove duplicates, normalize formats, and label data (e.g., tagging
past transactions as "Fraud" vs. "Genuine").
• Storage: Use secure Data Lakes like Snowflake, BigQuery, or AWS S3 to hold the data.
• Compliance: Ensure the data handling meets GDPR and SBP (State Bank of Pakistan)
standards.

Step 3: Model Selection (Choosing the Engine)

• (a) LLMs (Large Language Models):


o Use for: Text-heavy tasks like customer chat, summarizing KYC documents, or
generating reports.
o Examples: GPT-4, Llama 3, Claude.
• (b) Predictive ML Models:
o Use for: Numerical tasks like credit scoring and risk forecasting.
o Examples: XGBoost, Random Forest, Neural Networks trained on transaction
history.
• (c) AI Agents:
o Use for: Multi-step actions. An agent has "tools" (APIs) and "memory."
o Workflow Example: Check customer balance → Validate KYC → Initiate
payment.
o Frameworks: LangChain, AutoGPT.

Step 4: Development Process

1. Prototype (POC): Use pre-trained APIs (like OpenAI) for a low-cost validation of the
idea.
2. Fine-Tuning: Train the model on your internal knowledge base (e.g., fine-tuning a
model on SBP compliance FAQs).
3. Integration: Connect the AI to core systems (ERP, CRM) via an API Gateway.
4. Deployment: Use cloud-native microservices and set up real-time monitoring to watch
for "hallucinations" or errors.

Step 5: Feedback Loop

• Action: Track metrics like NPS (Net Promoter Score) and accuracy.
• Maintenance: Continuously retrain the model with new data to prevent it from becoming
outdated.

2. Real-World Use Cases (The "Big Three")

You must know these specific examples provided in the lecture.

A. AI in ERP (Enterprise Resource Planning)

• Core Function: Integrating Finance, HR, and Supply Chain. AI makes it predictive.
• Use Case 1: Predictive Demand Forecasting
o What it does: AI models predict seasonal demand to reduce inventory costs.
o Example: SAP uses AI to help manufacturers predict exactly when demand will
spike.
• Use Case 2: Automated Invoice Processing
o What it does: Uses OCR (Optical Character Recognition) + NLP to read invoices,
extract data, and post entries automatically.
o Example: Oracle ERP Cloud uses this to cut manual work by 60%.
• Use Case 3: Fraud Detection: AI flags unusual vendor payments or duplicate invoices.

B. AI in CRM (Customer Relationship Management)

• Core Function: Managing sales and support. AI turns it into "Relationship Intelligence."
• Use Case 1: Next Best Action
o What it does: Suggests exactly which product to pitch to a specific client based on
their history.
o Example: Salesforce Einstein analyzes past behavior to suggest upsell
opportunities.
• Use Case 2: Chatbots & Virtual Assistants
o What it does: Handles routine queries (up to 80% of volume).
o Example: Easypaisa uses AI chatbots for customer service in Pakistan.
• Use Case 3: Sentiment Analysis
o What it does: Scans emails/calls to understand customer mood.
o Example: HubSpot uses sentiment scoring to prioritize complaints from angry
customers.

C. AI in HRMS (Human Resources)

• Core Function: Managing hiring and workforce.


• Use Case 1: Resume Screening
o What it does: Filters thousands of CVs in seconds.
o Example: Workday ranks candidates based on skills and experience.
• Use Case 2: Attrition Prediction
o What it does: Identifies employees who are likely to resign.
o Example: IBM Watson helps managers take pre-emptive action to retain top
talent.
• Use Case 3: AI Learning Paths: Personalized training recommendations for employees.

3. The Prioritization Matrix (What to Build First?)

Not all AI projects are worth the money. Use this matrix to decide.

Category Description Example Strategy

Easy + High AI Chatbots in CRM, Fraud


Quick Wins Do these first for fast ROI.
Value Alerts.

Strategic Hard + High Predictive Supply Chain, High impact, but requires heavy
Bets Value Autonomous ERP. infrastructure.

Easy + Low Sentiment Analysis


Fillers Useful, but limited impact.
Value Dashboards.

Hard + Low Experimental Blockchain + AI


Avoid Costly with low business payoff.
Value in ERP.

Phase 3: Risks, Governance & Data Privacy


Focus: The "Dark Side" of AI—understanding what can go wrong, why it gets
expensive, and how to strip sensitive data so you don't get sued.

1. The 6 Major Risks of AI in EIS


It is not just about "will it work?"; it is about "will it destroy our reputation?" The slides
highlight six specific risks.

• A. Hallucination & Reliability


o The Problem: LLMs can generate answers that sound fluent and
confident but are factually false.
o Real-World Example: A FinTech chatbot telling a customer the wrong
regulatory limits on international money transfers. This leads to regulatory
breaches and lawsuits.
• B. Data Privacy & Security
o The Problem: If you train an AI on confidential data, or send that data to a
public API (like ChatGPT), the AI might "leak" that secret to other users.
o Real-World Example: In 2023, Samsung engineers accidentally
exposed their proprietary source code by pasting it into ChatGPT to check
for bugs.
• C. Bias & Fairness
o The Problem: If historical data is biased (e.g., past loan officers rejected
women), the AI will learn that bias and automate discrimination.
o Regulatory Pressure: This violates laws like the EU AI Act and SBP
(State Bank of Pakistan) compliance rules regarding fair lending.
• D. Explainability & Trust (XAI)
o The Problem: "Black Box" decisions. In high-stakes finance (like AML -
Anti Money Laundering), you cannot just say "The AI rejected this
transaction." You must explain why.
o Requirement: Compliance teams need Explainable AI to prove to
regulators why a specific remittance was flagged as suspicious.
• E. Scalability & Cost
o The Problem: AI is not free. Training models requires expensive GPUs,
and running queries (inference) costs money per word (token).
o The Math: OpenAI's GPT-4 costs approx. $0.03–$0.06 per 1K tokens. For
a bank with millions of daily queries, this bill becomes massive.
• F. Adversarial Attacks
o The Problem: Hackers manipulating the AI to bypass security.
o Example: Prompt Injection, where a fraudster types a specific trick
phrase to convince a banking chatbot to bypass AML checks and approve
a transaction.

2. Data Anonymization: The Defense Layer


To safely use AI without leaking secrets, you must use Anonymization. This ensures
algorithms learn patterns without knowing identities.

Why is it required?

1. Trust: Banking is trust-based; one leak of credit card numbers destroys


reputation.
2. Compliance: Required by GDPR (Europe), PDPA (Singapore), and HIPAA
(Healthcare).
3. Sharing: Enables you to send data to 3rd party AI vendors or regulators without
exposing raw secrets.
The 4 Key Techniques:

Technique How it Works Technical Method Use Case

Uses Regex to find


Replaces sensitive
patterns (e.g., credit Hiding IDs in
values with fake but
1. Data Masking cards) and swaps customer support
valid-looking
them (e.g., XXXX- screens.
characters.
XXXX-1234).

Payments (PCI
Real Value → Hash +
Swaps real data for a DSS). The
Salt → Token. The
2. Tokenization random "Token" stored merchant never
app only sees the
in a secure vault. sees the card
token.
number.

Replaces names with Analytics. You can


unique IDs Create a lookup track U0001's
3.
(Pseudonyms) to keep table: UserID 123 → behavior over time
Pseudonymization
data relationships PseudoID U0001. without knowing it's
intact. "John".

Removing irrelevant
Completely removes or Replace field with sensitive info (e.g.,
4. Redaction
blanks out the data. NULL. Religion) to prevent
bias.

2. Data Anonymization: The Defense Layer


You cannot just feed all your company data into an AI model. Banking is a trust-based
business, and regulations like GDPR, HIPAA, and SBP (State Bank of Pakistan)
mandate the protection of PII (Personally Identifiable Information).

Why is it required?
• Trust: A single breach of credit card numbers or account balances destroys
years of customer trust.
• Collaboration: Anonymization allows you to share data with 3rd-party AI
vendors or regulators without exposing raw secrets.
• Safety: Prevents "Hallucinations" and bias from being amplified by identifiable
personal data.

The 4 Key Techniques


You must know the difference between these for the exam.

Technique How it Works Technical Method Use Case

Uses Regex to find


Customer Support
Replaces sensitive patterns (like
Screens: Agents see
values with fake but CNIC/Credit Cards)
1. Data Masking the last 4 digits to
structurally valid and swaps them
verify ID, but can't
characters. (e.g., XXXX-XXXX-
steal the full number.
1234).

Payments (PCI DSS):


Real Value → Token
Replaces data with a Storing credit cards as
Generator → Token.
random "Token" tokens so if the
2. Tokenization The app only sees
stored in a secure database is hacked,
the token; the Vault
vault. thieves get useless
holds the key.
strings.

Replaces names with Analytics: You can


unique IDs Create a lookup track U0001's spending
3.
(Pseudonyms) to table: UserID 123 → history over 10 years
Pseudonymization
keep data PseudoID U0001. without knowing who
relationships intact. they actually are.

Completely removes Replace the field Bias Prevention:


4. Redaction or blanks out the with NULL or delete Removing fields like
data field. the column. "Religion" or "Race" so
Technique How it Works Technical Method Use Case

the AI cannot learn to


discriminate.

4. Data Anonymization Priority Matrix

You cannot anonymize everything because it destroys the value of the data. You must
prioritize based on Risk vs. Business Value.

1. Must Have (High Risk / High Value)

• Data: PII (Personally Identifiable Information), Credit Card Numbers, CNICs.


• Action: Strict Anonymization. You cannot operate or use this data in AI without
full protection (Masking/Tokenization).
2. Competitive Edge (High Risk / Low Value)

• Data: Spending Clusters, Customer Segmentation patterns.


• Action: Strong Protection. While this isn't PII, it is your "Secret Sauce" (unique
insights). If leaked, competitors gain an advantage.

3. Optional but Useful (Low Risk / High Value)

• Data: Generic behavioral data, fraud signals, web traffic.


• Action: Anonymize if easy, but it's not a critical compliance emergency.

4. Avoid (Low Risk / Low Value)

• Data: Raw system logs, noisy location data.


• Action: Do Not Process. It costs too much to clean and offers little insight.
Ignore this data for AI projects.
Week – 13
1. Enterprise Information Systems (EIS) Project Management

• Definition: Managing projects specifically related to large-scale enterprise systems (like


ERP, CRM).
• Key Objectives:
o Efficiency: Doing more with less.
o Scalability: Ensuring the system can grow with the company.
o Security & Compliance: Protecting data and following laws.

2. The Procurement Process: RFI vs. RFP

This is the standard process for finding and hiring vendors to build your system.

A. RFI (Request for Information)

• Purpose: Used early in the lifecycle to gather general information from vendors about
what is possible. You don't know exactly what you want yet; you are just "shopping
around."
• Process Steps:
1. Requirement Gathering: Figure out roughly what you need.
2. Vendor Inquiry: Ask vendors for data.
3. Preliminary Evaluation: Filter out the bad options.
• Example: You want a new HR system but don't know if AI features exist yet. You send an
RFI to 10 vendors asking, "Do you have AI resume screening?"

B. RFP (Request for Proposal)

• Purpose: Used after the RFI to get specific, binding proposals. You know what you
want, and you are asking "How much will it cost and how will you build it?"
• Process Best Practices:
o Define exact requirements and evaluation criteria (e.g., "Must cost under $50k").
o Manage the timeline strictly so all vendors submit on time.
• Example: You narrowed it down to 3 vendors. You send an RFP saying, "We need an AI
HR system installed by Dec 1st. Submit your price and timeline."

C. Key Difference

• RFI is for Information (Exploration).


• RFP is for Proposals (Commitment/Bidding).
3. Project Management Office (PMO)

The PMO is the department that sets the rules for how projects are run.

• Functions:
o Strategic Alignment: Ensuring projects match business goals.
o Resource Allocation: Deciding who works on what.
o Governance: Enforcing rules.
• Types of PMO:
o Supportive: Provides templates and training (Low control).
o Controlling: Requires compliance with specific frameworks (Medium control).
o Directive: Directly manages the projects (High control).
• Common Frameworks:
o PRINCE2 (Projects IN Controlled Environments).
o PMBOK (Project Management Body of Knowledge).
o ITIL (IT Infrastructure Library).
• PMO & TOGAF Interaction:
o The PMO ensures that project phases align with TOGAF principles (The Open
Group Architecture Framework) to maintain strategic alignment and compliance.

4. SDLC Models (Software Development Life Cycle)

The "recipe" for building software.

Lifecycle Phases

Every project goes through these stages:

1. Requirement Analysis
2. Planning and Design
3. Implementation (Coding)
4. Testing
5. Release
6. Continuous Maintenance.

A. Waterfall Model

• Definition: A sequential approach. You must finish step 1 before starting step 2.
• Pros: Good for projects with clear, fixed requirements.

• Cons: Inflexible. If you realize you made a mistake in the design phase while you are
testing, it is very expensive to go back.
• Example: Building a bridge. You cannot change the blueprint after you have poured the
concrete.

B. Agile Model

• Definition: An iterative approach. You build small parts, get feedback, and improve.
• Pros: Supports customer feedback and changes mid-project.
• Cons: Risk of Scope Creep (the project keeps getting bigger) and requires more
resources/meeting time.
• Example: Developing a mobile app. You release a basic version, users ask for "Dark
Mode," and you add it in the next update.

How to Choose?

• Choose Waterfall if: Requirements are fixed and the project is simple.
• Choose Agile if: You need flexibility and expect changes.
• Hybrid Models: Often used to balance the benefits of both.

5. Communication Strategies

Communication is how you keep stakeholders (bosses, clients) happy.

• Channels: Use a mix of emails, meetings, dashboards, and reports.


• Governance Communication:
o Focus on Transparency and Accountability.
o Provide frequent updates so there are no surprises.
• Example: Instead of just emailing "We are late," a Project Manager uses a Dashboard
(Red/Amber/Green status) to show exactly which task is blocking progress.

Agile or waterfall??

Based on your slides (specifically Project Mgt in EIS and EIS Architectures), the "right"
approach is determined by the Requirements, Timeline, and Client Interaction.

Here is the perfect answer to give your "sir," structured so you can explain your reasoning:
The "It Depends" Framework (The Best Answer)

You should answer: "Sir, the choice depends on the nature of the client's requirements and the
project environment. There is no single 'best' method, but I would choose based on these
factors:"

1. Choose Waterfall IF:

Use this when the client knows exactly what they want and cannot change their mind later.

• Requirements: Are clear, fixed, and well-documented from the start.


• Timeline/Budget: Fixed and strict (e.g., a government contract).
• Client Involvement: The client wants to sign a contract and only see the final product at
the end (Low involvement).
• Example from Slides: A government project with strict timelines.

2. Choose Agile IF:

Use this when the client has a vague idea or wants to see progress constantly.

• Requirements: Are unclear, evolving, or likely to change (Dynamic).


• Timeline: Flexible; speed to market is more important than a perfect "Day 1" launch.
• Client Involvement: The client wants to give feedback every few weeks and change
features mid-development.
• Example from Slides: A bank releasing updates for a digital banking app.

Summary for the Oral/Written Answer

If he pushes you for a specific choice for a "general client software", the safest bet in modern
development is Agile.

Why Agile?

• Risk Management: You fail fast and fix fast. In Waterfall, you might build the wrong
thing for 6 months and only realize it at the end.
• Customer Satisfaction: The client gets to see "iterative development" and provide
feedback, ensuring the final product is actually what they need.

Exam Tip: If the question mentions "Innovation," "Startups," or "User Feedback," the
answer is Agile. If the question mentions "Compliance," "Safety Critical Systems," or
"Fixed Budget," the answer is Waterfall.
Week – 13
What is Enterprise Architecture?

The process of translating business vision and strategy into effective enterprise change by
creating, communicating, and improving the key principles and models that describe the
enterprise’s future state and enable its evolution. (Source: Gartner®)

A set of abstractions and models that simplify and communicate complex structures, processes,
rules, and constraints to improve understanding, implementation, forecasting, and resourcing.
(Source: DoDAF)

Purpose: It bridges the gap between Strategy (Business goals) and Execution (IT Systems)

1. What is Enterprise Architecture (EA)?

• Definition: The process of translating business vision into effective change by creating
models that describe the enterprise's future state.
• Purpose: It bridges the gap between Strategy (Business goals) and Execution (IT
Systems).
• Why is it Important?
o Aligns business and IT (stops IT from building useless tools).
o Reduces Complexity: Removes redundant systems (e.g., two departments buying
the same software).
o Supports Compliance: Ensures security standards are met.
o Enhances user experiences: since the complexity is removed, and only right
tools are made, this makes users experience better.

2. The Four Key Components of EA

You must know these four layers. They often appear in "Match the following" or definition
questions.

1. Business Architecture: Defines what the business does (Processes, Org Structure,
Mission).
2. Data Architecture: Defines how data is stored, governed, and integrated (Data Models,
Master Data Management).
3. Application Architecture: Defines the software used (Integrations, Custom Apps,
SaaS).
4. Technology Architecture: Defines the hardware/infra (Servers, Networks, Cloud, OS).
Common Frameworks: TOGAF (The Open Group Architecture Framework), Zachman, FEA
(Federal).

Overview of it architectures
1. Monolithic Architecture (The Traditional Model)

• Definition: The entire application is built as a single, unified unit. All functions (User
Interface, Business Logic, Database Access) are tightly woven together into one large
code base.
• How it works: If you want to change one small part (e.g., the "Login" button), you often
have to re-compile and re-deploy the whole application.
• Pros: Simple to develop and debug initially, easier to deploy
• Cons: If one part breaks, the whole system can crash (Single Point of Failure). It is also
very hard to scale just one part of it and it is very difficult to maintain.

2. Microservices Architecture (The Modern Standard)

• Definition: The application is broken down into small, independent services that run on
their own and talk to each other via APIs.
• How it works: You have a specific "Payment Service" and a separate "Inventory
Service." They can be written in different coding languages and managed by different
teams.
• Pros: Fault Isolation (if "Payments" fail, users can still browse "Inventory") and
Independent Scaling (you can add more power just to the busy service) and continuous
deployment.
• Cons: It is complex to manage because there are so many moving parts to coordinate.
API management is needed and difficult to communicate.

3. Layered (or N-Tier) Architecture

• Definition: The system is organized into horizontal layers, where each layer has a
specific responsibility and only talks to the layer directly above or below it.
• The Classic 3 Layers:
1. Presentation Layer: What the user sees (UI/Web Page).
2. Application (Logic) Layer: The code that processes data (e.g., calculating tax).
3. Data Layer: Where the information is stored (Database).
• Why use it? It keeps code organized. You can change the database (Data Layer) without
breaking the website design (Presentation Layer).

4. Service-Oriented Architecture (SOA)

• Definition: An older "big brother" to microservices. It focuses on exposing business


functions (like "Check Credit Score") as reusable services that can be used across the
entire enterprise.
• Key Feature: It often uses an ESB (Enterprise Service Bus), a central communication
hub that manages the traffic between all systems.
• Difference from Microservices: SOA is about reusing components across different
applications in a company, whereas Microservices is about breaking one application into
small parts.

5. Event-Driven Architecture (EDA)

• Definition: A system designed to react to "events" (changes in state) in real-time, rather


than waiting for a request.
• How it works: It uses a "Push" model. Instead of the Warehouse asking "Do we have a
new order?" every minute, the Sales System pushes a notification ("Event: Order
Placed") immediately when it happens.
• Key Components:
o Producer: The system that creates the event.
o Consumer: The system that listens for and reacts to the event.
• Why use it? It is highly decoupled and perfect for real-time systems (e.g., Uber matching
a driver the second you request a ride).
6. Cloud-Native and Serverless Architectures

• Cloud-Native: Designing applications specifically to live in the cloud (using Containers


and Kubernetes) rather than just taking an old server and putting it online. It is built to be
resilient and auto-scalable.
• Serverless: A model where you write code (functions) but do not manage any servers.
o How it works: You upload a piece of code (e.g., "Resize Image"). The cloud
provider (like AWS or Google) automatically runs it when needed and turns it off
when finished.
o Benefit: You strictly pay only for the milliseconds the code is running, rather
than paying for a server to sit idle.

4. Resilience & Scalability Concepts

How do we keep the system running?

• Redundancy:
o Active-Active: Running two identical live sites. If one fails, the other handles
traffic.
o Active-Passive: One main site, one "sleeping" backup site.
• Scalability Types:
o Vertical Scaling: Making the single server bigger (More RAM/CPU).
o Horizontal Scaling: Adding more servers (Cluster).
• Resilience Tools:
o Load Balancing: Distributes incoming traffic across multiple servers so no single
server is overwhelmed.
o Circuit Breaker: Automatically stops sending traffic to a failing service to
prevent it from crashing the whole system.

Implementation Strategies for Enterprise Architecture

The right implementation strategy depends on the organization’s goals, culture, and resources.

Here is a detailed breakdown of each strategy, including the specific pros, cons, and examples
provided in your course material.

1. Top-Down vs. Bottom-Up Approach

This strategy determines who drives the change.

A. Top-Down Strategy

• Definition: The initiative is driven by senior management (e.g., CEO, CIO) and is strictly
aligned with the high-level business strategy.
• Pros:
o Ensures the architecture aligns perfectly with the company's long-term strategic
goals.
o Governance is easier because the mandate comes from the top.
• Cons:
o May face resistance from operational teams (the people actually doing the work)
if they feel ignored or not fully onboard.
• Example: A CEO mandates an organization-wide cloud adoption policy that everyone
must follow.

B. Bottom-Up Strategy

• Definition: The initiative is started by individual departments or IT teams to solve


immediate, specific technical needs.
• Pros:
o Encourages innovation and experimentation at the ground level.
• Cons:
o Risk of misalignment with the overall business goals if not properly governed
(e.g., IT builds something cool that the business doesn't need).
• Example: An IT team starts using microservices for a small project, and because it works
well, the method is later adopted by the rest of the organization.
2. Big Bang vs. Incremental Implementation

This strategy determines the speed and scope of the rollout.

A. Big Bang Approach

• Definition: Complete implementation happens in one go, transforming the whole


enterprise simultaneously.
• Pros:
o Delivers quick results.
o Achieves large-scale transformation instantly (no "in-between" state).
• Cons:
o High Risk: If it fails, everything fails.
o Resource-intensive and highly disruptive to daily operations.
• Example: Implementing a new ERP system across all departments (Finance, HR, Sales)
on the same day.

B. Incremental Approach

• Definition: A gradual, phased implementation that focuses on individual business units


or functions one at a time.
• Pros:
o Lower risk (you can fix mistakes in phase 1 before moving to phase 2).
o Easier management and allows for continuous improvement.
• Cons:
o It takes much longer to realize the full benefits of the new system.
• Example: Deploying cloud-based systems in stages (e.g., moving Email first, then HR,
then Finance).

3. Centralized vs. Federated Governance

This strategy determines who controls the rules.

A. Centralized Model

• Definition: A single team (often a dedicated EA team) manages and controls the
architecture for the entire organization.
• Pros:
o Ensures absolute consistency and compliance across all departments.
• Cons:
o Can be rigid and slow, limiting flexibility for individual units that have unique
needs.
• Example: A centralized EA office defines all infrastructure and application standards for
every global branch.

B. Federated Model

• Definition: Combines central governance (for high-level rules) with autonomy for
individual units (for local implementation).
• Pros:
o Balances consistency with flexibility.
• Cons:
o Requires strong coordination to avoid fragmentation (where different units start
drifting too far apart).
• Example: A multinational bank has a central EA team providing high-level guidance,
while regional teams (e.g., Asia-Pacific team) manage their local implementations.

4. Waterfall vs. Agile Implementation

This strategy determines the process methodology.

A. Waterfall Approach

• Definition: Linear, phase-based implementation with clear milestones (Plan -> Design ->
Build -> Deploy).
• Pros:
o Predictable and structured; you know exactly what will be done and when.
• Cons:
o Limited flexibility; it is very hard to make changes once the project has started.
• Example: Government projects with strict legal timelines and fixed budgets.

B. Agile Approach

• Definition: Iterative development with continuous feedback and adaptability.


• Pros:
o More flexible; can adapt to changing user needs during the project.
o Faster delivery of functional parts.
• Cons:
o Requires a cultural change (teams must communicate constantly).
• Example: A bank using Agile sprints to release updates to its digital banking app every
two weeks.
Week – 14

Info-sec

1. The Core Framework: The CIA Triad

Everything in Information Security revolves around these three pillars. If one fails, the system is
compromised.

• Confidentiality: Preventing unauthorized access.


o Definition: Only the right people can see the data.
o Example: A bank teller can see your balance, but the janitor cannot.
o Breach Example: A hacker leaks a database of customer passwords.
• Integrity: Protecting against unauthorized modifications.
o Definition: The data is accurate and hasn't been changed (accidentally or
maliciously).
o Example: When you transfer $100, the system deducts exactly $100, not $1000.
o Breach Example: An employee changing a vendor's bank account number in the
invoice system to their own.
• Availability: Ensuring timely access for authorized users.
o Definition: The system works when you need it.
o Example: The payroll system must be online on the 30th of the month.
o Breach Example: A DDoS attack crashing the company website on Black Friday.

2. Common Security Threats (The Bad Stuff)

The slides highlight five specific threat categories you need to know.

• 1. Malware (Malicious Software):


o Virus/Worms: Self-replicating code that spreads between computers.
o Ransomware: Encrypts company data and demands payment to unlock it.
o Real-World Example: The WannaCry attack that shut down hospitals by
encrypting patient records.
• 2. Phishing & Social Engineering:
o Phishing: Deceptive emails pretending to be legitimate to steal credentials.
o Social Engineering: Manipulating people into giving up confidential info
(hacking the human, not the machine).
o Example: An email looking like it's from "IT Support" asking you to click a link
to reset your password.
• 3. Insider Threats:
o Threats coming from within the organization (employees, contractors).
o Example: A disgruntled salesperson downloading the client list to a USB drive
before quitting to join a competitor.
• 4. DDoS (Distributed Denial of Service):
o Overwhelming a server with traffic to make it crash (attacking Availability).
o Example: Using a botnet (network of infected devices) to spam a bank's login
page so real customers can't log in.
• 5. APT (Advanced Persistent Threats):
o Long-term, stealthy attacks (often state-sponsored or corporate espionage). They
get in and stay quiet to steal data over months.
o Example: Competitors infiltrating a research lab’s network to steal the blueprint
for a new product.

3. Defense Layers (The Solution)


Security is not just one thing; it is layers (Defense in Depth).

A. Hardware & Network Security

• Firewalls: The barrier between the trusted internal network and the untrusted internet. It
filters traffic based on rules.
• VPN (Virtual Private Network): Creates a secure, encrypted tunnel for remote
employees to access the office network.
• IDS/IPS (Intrusion Detection/Prevention Systems): Monitors network traffic for
suspicious activity (like a burglar alarm).

B. Software & Data Security

• Encryption: Scrambling data so it is unreadable without a key.


o At Rest: Encrypting the hard drive (if a laptop is stolen, data is safe).
o In Transit: Using HTTPS/TLS (so hackers can't intercept data moving over Wi-
Fi).
• Patch Management: Updating software regularly to fix known holes.

C. Access Control (Crucial for EIS)

• MFA (Multi-Factor Authentication): Using two methods to log in.


o Something you know: Password.
o Something you have: Phone (OTP)/Hardware token.
o Something you are: Fingerprint/FaceID.
• RBAC (Role-Based Access Control): You only get access based on your job title.
o Example: An "Intern" role has Read-Only access, while a "Manager" role has Edit
access.

4. Cloud vs. Local Data Center (DC)

This is a major strategic decision for enterprises today.

Local Data Center (On-Premise)

• Pros: Total control, data stays in your building (good for strict compliance).
• Cons: Expensive (buy hardware, pay for electricity/cooling), hard to scale up quickly.
• Security: You are responsible for everything (locks on doors, firewalls, patching).

Cloud Environments

• Pros: Scalable, flexible, pay-as-you-go.


• Cons: You trust a third party (AWS, Azure) with your data.
• Security Model: Shared Responsibility Model.
• Provider (AWS/Azure) secures: The Cloud (Hardware, Global Infrastructure, Physical
Security of servers).
• You (The Customer) secure: What's IN the Cloud (Your data, your passwords, your
access settings).

5. Compliance & Standards

You don't just secure data because it's good; you do it because it's the law/standard.

• ISO/IEC 27001: The international standard for Information Security Management


Systems (ISMS).
• NIST Cybersecurity Framework: Identify, Protect, Detect, Respond, Recover. (Very
popular in the US).
• GDPR: (General Data Protection Regulation) - European law protecting user privacy.

6. Emerging Trends

• AI in Threat Detection: Using AI to spot hackers faster than humans can.


• Zero Trust Architecture: "Never trust, always verify." (Even if you are inside the
office, you still need to authenticate).
• IoT Security: Securing smart devices (cameras, sensors) which are often weak entry
points for hackers.

Additional information
Malware vs Virus

1. The Relationship (The Umbrella)


• Malware is the Category (Genus).1
• Virus is a Type (Species).2

Think of it this way:

• Malware is like the word "Vehicle."3


• Virus is like the word "Car."

(All cars are vehicles, but not all vehicles are cars. A truck is a vehicle, but it's not
a car.)
2. Technical Definitions
Malware (Malicious Software)
• Definition: Any software intentionally designed to cause damage to a computer,
server, client, or network.4
• Scope: It is the umbrella term that covers everything bad.5
• Includes: Viruses, Worms, Trojan Horses, Ransomware, Spyware, Adware.6

Virus
• Definition: A specific type of malware that attaches itself to a clean file (host)
and replicates when that file is executed.7
• Key Behavior:
o Needs a Host: It cannot live alone; it must "infect" a PDF, EXE, or Doc
file.8
o Needs Human Action: It usually requires you to run the infected program
or open the infected file to start spreading.9
o Self-Replicating: Once active, it copies itself into other files on your
system.10

Summary Table for the Exam

Feature Malware Virus

The general category of "bad


What is it? A specific sub-type of malware.
code".

Requirement Can be anything. Needs a host file (like .exe or .docx).

Needs Human Interaction (you must


Activation Varies (some run automatically).
open the file).

Ransomware, Spyware, Trojans,


Examples ILOVEYOU, Melissa, CIH.
Viruses.
Shared security model in Clouds
The Core Concept: The "Golden Rule"

The Shared Responsibility Model divides security tasks between the Cloud Provider
(AWS/Azure) and You (The Customer).

• Cloud Provider (AWS/Azure): Responsible for Security OF the Cloud.


o They protect the hardware, the concrete building, the global cables, and the
virtualization software.
• You (The Customer): Responsible for Security IN the Cloud.
o You protect the data you put there, the passwords you create, and the operating
systems you install.

How the Responsibility Shifts (IaaS vs. PaaS vs. SaaS)

The "line" of responsibility moves depending on what kind of service you are buying. This is a
guaranteed exam question.

1. IaaS (Infrastructure as a Service)

• Analogy: Renting an empty house.


• Provider Does: Maintains the physical building, electricity, and water pipes.
• You Do: You bring the furniture, you lock the front door, you fix the broken window
inside, and you patch the walls.
• Technical: You manage the Operating System (Windows/Linux), Firewalls, Apps,
and Data.
• Maximum responsibility for you.

2. PaaS (Platform as a Service)

• Analogy: Renting a hotel room.


• Provider Does: Maintains the building AND cleans the room, fixes the AC, and provides
the bed.
• You Do: You just bring your clothes (Code) and keep your luggage safe (Data).
• Technical: Provider manages the OS and Runtime. You only manage the Application
Code and Data.

3. SaaS (Software as a Service)

• Analogy: Eating at a restaurant.


• Provider Does: Cooks the food, sets the table, cleans the dishes, maintains the building.
• You Do: You just decide what to eat and pay the bill.
• Technical: Provider manages Everything (App, OS, Hardware). You only manage User
Accounts (IAM) and Data Access.
• Minimum responsibility for you.

What is Zero Trust Architecture?

Definition: A security framework requiring all users, whether in or outside the organization's
network, to be authenticated, authorized, and continuously validated for security configuration
and posture before being granted or keeping access to applications and data.

Core Principle: "Never Trust, Always Verify"

• Traditional Security (The "Castle and Moat" Model): Once you logged into the office
network (crossed the moat), the system trusted you. You could move around freely.
• Zero Trust Model: The system assumes breach. It does not trust you just because you
are on the office Wi-Fi or logged in via VPN.
o Micro-segmentation: It breaks the network into small zones. Gaining access to
one zone (e.g., Email) does not give you access to another (e.g., HR Database).
o Continuous Verification: Every time you try to access a new file or server, the
system checks your identity and device health again.

Why it is under IAM in your slides?

It is listed under Identity and Access Management because Zero Trust relies heavily on
knowing exactly who (User Identity) and what (Device Identity) is trying to access a resource,
rather than just where they are (Network Location).

Scenerio Based Questions


Here are three scenario-based questions derived from your Week 14 - InfoSec slides, designed
to test your application of the concepts.

Scenario 1: The "Fix-It" Manager

The Situation: You have just been hired as the IT Manager for a mid-sized logistics company.
The CEO admits their security is "weak" and out of date. Clients are threatening to leave unless
you prove the data is safe. You need to bring the company up to standard. What is your
roadmap?

The Solution (Strategic Approach): You cannot just "install antivirus" and be done. You need
a holistic framework.

1. Adopt a Framework: Immediately align with an industry standard like ISO/IEC 27001
or the NIST Cybersecurity Framework to identify gaps.
2. Establish Policy: Implement formal Security Policies that define acceptable use and
penalties for non-compliance.
3. Secure the Basics (CIA Triad):
o Confidentiality: Implement Role-Based Access Control (RBAC) so employees
only see what they need.
o Integrity: Ensure data isn't being changed by unauthorized users.
o Availability: Set up Redundant Systems and Backups so business continues if a
server fails.
4. The Human Firewall: Since "Phishing and Social Engineering" are top threats, start
Employee Awareness Training immediately.

Scenario 2: The "War Room" (Active Attack)

The Situation: It is 2:00 PM on a Tuesday. Your SIEM tools (like Splunk) trigger a red alert. A
DDoS attack is hammering your main server, and users are reporting they cannot log in.
Simultaneously, the firewall is detecting unauthorized traffic trying to leave the network (data
exfiltration). What do you do RIGHT NOW?

The Solution (Containment & Defense):

1. Activate the Team: Call in the Incident Response Team (CSIRT) immediately.
2. Block the Attack:
o Use Firewalls and Intrusion Prevention Systems (IPS) to block the malicious
IP addresses causing the DDoS.
o If the DDoS is severe, you might need to reroute traffic (Availability protection).
3. Isolate the Infection: Use Network Segmentation to cut off the affected servers from
the rest of the network so the attacker cannot move laterally (jump to other computers).
4. Monitor: Watch Real-Time Monitoring dashboards to see if the countermeasures are
working.
Scenario 3: The "Aftermath" (Post-Incident)

The Situation: The dust has settled. Last week, a hacker managed to encrypt your HR database
using Ransomware. You managed to restore from backups, but the CEO asks, "How do we
ensure this never happens again, and are we in legal trouble?" What are your next steps?

The Solution (Recovery & Compliance):

1. Recovery: Verify that your Disaster Recovery Plans worked and that the restored data
is clean.
2. Forensics: Conduct a Post-Incident Analysis to find the "Patient Zero" (how they got
in).
3. Compliance Check: Since HR data (personal info) was involved, check if you violated
GDPR or HIPAA. You may legally need to notify the affected employees and the
government.
4. Hardening:
o If it was a password leak, enforce Multi-Factor Authentication (MFA).
o If it was a software bug, review your Patch Management process.
5. Feedback Loop: Use the lessons learned for Continuous Improvement of your security
posture.

Here are "Before and After" scenarios focused only on Information Security, based on the
Week 14 slides.

Scenario 1: Access Control (The "Password Sharing" Problem)

Exam Question: "A company currently allows employees to access the central database with
just a simple password. Several employees share passwords to 'get work done faster,' leading to a
data leak where no one knows who accessed the file. Describe the security posture Before and
After implementing an IAM (Identity and Access Management) solution."

Model Answer:

• Before (Weakness): The company relies on single-factor authentication (passwords


only), which creates a Single Point of Failure. There is no accountability because shared
credentials make it impossible to track Insider Threats.
• After (Solution): The company implements Multi-Factor Authentication (MFA) and
Role-Based Access Control (RBAC).
o Result: Even if a password is shared, the system requires a second factor (like a
phone code). RBAC ensures employees can only access files strictly relevant to
their job, enforcing the principle of Confidentiality.
Scenario 2: Network Defense (The "Open Door" Policy)

Exam Question: "An accounting firm allows employees to access the internal file server from
coffee shops using public Wi-Fi. They have no protective layer between their server and the
internet. Explain the risk (Before) and the technical solution (After) required to secure this."

Model Answer:

• Before (Weakness): Data is being transmitted over unsecured networks, making it


vulnerable to Packet Sniffing or Man-in-the-Middle attacks (Threats to Integrity and
Confidentiality). The server is exposed directly to the internet, increasing the risk of
DDoS attacks.
• After (Solution): The firm implements a VPN (Virtual Private Network) and
Firewalls.
o Result: The VPN encrypts the data in transit (creating a secure tunnel), while the
Firewall filters incoming traffic, ensuring only authorized connections reach the
internal server.

Scenario 3: Disaster Recovery (The Ransomware Hit)

Exam Question: "A hospital stores patient records on a single on-premise server. A ransomware
attack encrypts the drive, and the hospital cannot treat patients because the data is locked.
Contrast this 'Before' state with an 'After' state where proper Availability measures are in place."

Model Answer:

• Before (Weakness): The system lacks Redundancy. Because the data exists in only one
place without a recovery plan, the attack destroys the Availability of the system, halting
operations.
• After (Solution): The hospital implements Backup and Recovery Mechanisms and
Redundant Systems.
o Result: When the primary server is infected, the IT team can isolate it and
immediately switch to a clean backup or a secondary server. This ensures the
hospital can continue operating with minimal downtime, preserving Business
Continuity.
Missing content.

These notes are designed to fill the specific gaps identified in the "Gap Analysis" so your study
material is 100% complete.

1. Week 1 - Introduction & Key Functions

Missing Concept: The Hierarchy of Data, Information, and Knowledge Your notes cover the
basics, but the slides specifically distinguish "Knowledge" as actionable.

• Data: Raw, unorganized facts and figures without context.


o Example: The number 38.
• Information: Data that has been processed, organized, or structured to provide meaning.
o Example: "The temperature is 38°C."
• Knowledge: The ability to apply information to a specific context to make a decision or
take action.
o Example: "It is 38°C, which is very hot, so I should turn on the air conditioning
or wear light clothes."

Missing Concept: Anthony’s Triangle (Management Levels) The slides map EIS functions to
management levels.

• Strategic Level (Top Management): Long-term planning, unstructured decisions.


o System: Executive Support Systems (ESS).
o Example: Deciding to enter a new market in Asia next year.
• Tactical Level (Middle Management): Medium-term monitoring and control.
o System: Management Information Systems (MIS).
o Example: Reviewing monthly sales reports to adjust the quarterly budget.
• Operational Level (Line Managers): Day-to-day routine transactions.
o System: Transaction Processing Systems (TPS).
o Example: Recording a daily sale or tracking employee attendance.

2. Week 2 - Business Processes

Missing Concept: The Silo Effect

• Definition: A situation where departments (e.g., Sales, Finance, Warehouse) work in


isolation, hoarding data and not communicating effectively.
• Impact: This leads to duplication of work, delays, and errors (e.g., Sales selling an item
that the Warehouse knows is out of stock).
• Solution: EIS (like ERP) breaks down these silos by creating a single central database.

Missing Concept: BPR vs. BPA

• BPA (Business Process Automation): Using technology to make an existing process


faster without changing the steps.
o Example: Replacing paper forms with digital PDFs, but keeping the same
approval chain.
• BPR (Business Process Reengineering): A radical redesign of core business processes
to achieve dramatic improvements. It involves questioning why we do the process at all.
o Example: Ford’s Accounts Payable. Instead of matching invoices (automation),
they eliminated invoices entirely by paying automatically upon receipt of goods
(reengineering).

3. Week 3 - Process Modelling

Missing Concept: BPMN Gateway Types Gateways control the flow of a process (diverging
and converging).

• Exclusive Gateway (X or Empty Diamond): An "OR" decision where only one path
can be taken.
o Example: "Is the credit approved?" If Yes, proceed to shipping. If No, cancel
order. (You cannot do both).
• Parallel Gateway (+ Diamond): An "AND" decision where all outgoing paths happen
simultaneously.
o Example: When an order is received (Path A: Send Confirmation Email) AND
(Path B: Notify Warehouse). Both happen at the same time.

Missing Concept: As-Is vs. To-Be Modelling

• As-Is Model: A diagram representing the current process with all its flaws and
bottlenecks. Used for analysis.
• To-Be Model: A diagram representing the future, optimized process after improvements.
Used for implementation.

4. Week 4 - EIS Integration

Missing Concept: ESB (Enterprise Service Bus)


• Definition: An architecture model used for designing and implementing communication
between mutually interacting software applications in a Service-Oriented Architecture
(SOA).
• Analogy: Instead of connecting every system to every other system (Spaghetti code),
every system plugs into a central "Bus" (Hub). The Bus handles the translation and
routing.
• Benefit: If you replace one system, you only simply unplug it from the bus without
breaking the whole network.

Missing Concept: ACID Properties For integration to be reliable (especially in banking/ERP),


transactions must be ACID:

• Atomicity: All parts of the transaction happen, or none do. (No partial updates).
• Consistency: The database moves from one valid state to another.
• Isolation: Transactions occurring at the same time do not interfere with each other.
• Durability: Once a transaction is saved, it is permanent (even if the power fails).

5. Week 5 - ERP

Missing Concept: ERP Evolution Understanding the history is key to understanding the scope.

1. MRP (Material Requirements Planning) - 1970s: Calculated materials needed (e.g.,


"We need 50 tires").
2. MRP II (Manufacturing Resource Planning) - 1980s: Added machines and labor (e.g.,
"We need 50 tires, 2 machines, and 3 workers").
3. ERP (Enterprise Resource Planning) - 1990s: Added Back Office (Finance, HR, Sales).
4. ERP II (Extended ERP) - 2000s: Added Front Office and External links (CRM, SCM,
E-commerce).

6. Week 6 - CRM

Missing Concept: RFM Analysis A marketing technique used to quantitatively rank and group
customers based on their transaction history.

• Recency (R): How recently did the customer purchase? (Last week vs. last year).
• Frequency (F): How often do they purchase? (Every day vs. once a year).
• Monetary Value (M): How much do they spend? ($1000 vs. $10).
• Application: Customers with high R, F, and M scores are your "VIPs" and should get
special treatment.
7. Week 8 - SCM

Missing Concept: The Bullwhip Effect This is the most critical concept in SCM theory.

• Definition: A phenomenon where small fluctuations in demand at the retail level cause
progressively larger fluctuations in demand at the wholesale, distributor, manufacturer,
and raw material supplier levels.
• Cause: Lack of communication and over-reactive ordering (hoarding stock out of fear).
• Example: A customer buys 5% more toothpaste. The retailer panics and orders 10%
more. The wholesaler orders 20% more. The factory produces 40% more.
• Solution: Supply Chain Visibility (sharing real-time sales data).

Missing Concept: Reverse Logistics

• Definition: The process of moving goods from their typical final destination for the
purpose of capturing value, or proper disposal.
• Key Activities: Returns, refurbishment, recycling, and waste management.
• Example: Amazon's return process. When you return a shirt, it goes backwards through
the supply chain to be inspected and resold or recycled.

8. Week 14 - InfoSec

Missing Concept: The CIA Triad The three pillars of Information Security.

• Confidentiality: Ensuring data is not accessed by unauthorized people (e.g., Encryption,


Passwords).
• Integrity: Ensuring data is not altered or tampered with (e.g., Digital Signatures,
changing a grade from F to A).
• Availability: Ensuring systems are up and running when needed (e.g., Preventing DDoS
attacks, Backups).

Missing Concept: Defense in Depth

• Definition: A layered approach to security. If one defense fails, another steps in.
• Layers:
1. Physical (Locked doors).
2. Network (Firewalls).
3. Host (Antivirus).
4. Application (Input validation).
5. Data (Encryption).
• Analogy: A castle has a moat, then a wall, then guards, then a locked keep.
9. EIS Architectures

Missing Concept: Three-Tier Architecture The standard structure for modern web
applications.

1. Presentation Tier (Client): The user interface (what you see on the screen).
2. Logic Tier (Application Server): The code that processes commands, calculations, and
logical decisions.
3. Data Tier (Database): Where the information is stored and retrieved.

• Benefit: You can update the "Look" (Presentation) without breaking the "Data".

Missing Concept: SOA (Service Oriented Architecture)

• Definition: An architectural style where applications are built as a collection of loose


services (like "Print Service," "Payment Service") that talk to each other.
• Importance: It was the precursor to Microservices and allows for reusability (the
"Payment Service" can be used by the Web App and the Mobile App).

10. Project Management

Missing Concept: The Triple Constraint (Iron Triangle)

• Definition: The balance between Scope, Time, and Cost.


• Rule: You cannot change one without affecting the others.
o Example: If you want to increase Scope (add features), you must either increase
Cost (hire more people) or increase Time (delay the deadline).
• Quality: Quality sits in the middle and is affected if the triangle is unbalanced.
Shutterstock

Missing Concept: Scope Creep

• Definition: The uncontrolled expansion of project scope without adjustments to time,


cost, and resources.
• Cause: Poorly defined initial requirements or "Gold Plating" (adding extra features just
to be nice).
• Result: Project delays and budget overruns.

Common questions

Powered by AI

CDPs enhance CRM functions by consolidating customer data from multiple sources, including social media, websites, and ads, into a 'Golden Record.' This holistic view allows businesses to analyze customer behavior more precisely, leading to better-targeted marketing, personalized customer interaction, and informed decision-making. The integration of AI can further provide predictive insights and automate customer engagement strategies .

Digital wallets integrate with e-commerce platforms using APIs that allow automatic filling of payment details, thus speeding up the checkout process and reducing the risk of input errors. For users, this offers convenience and enhanced security, as their card details remain hidden. Merchants benefit from increased transaction speed and lower cart abandonment rates, leading to improved sales performance .

Deploying an ERP system incrementally allows organizations to manage change effectively and reduce operational risk by focusing on one module at a time, such as starting with Finance before HR. This approach enables better resource allocation during training, smoother transition phases, and allows for resolving unforeseen issues with minimal impact. It also facilitates gaining user buy-in progressively, improving the likelihood of overall project success .

The key elements of SCM include the flow of goods, information, and finances. They interlink through a coordinated system where procurement, inventory, and logistics management interact seamlessly. Efficiency is achieved by minimizing waste and optimizing transportation and inventory levels. Simultaneously, real-time information flow ensures transparency and timely decision-making, enhancing customer satisfaction by ensuring products are delivered accurately and on time .

ERP systems centralize data by storing information from various departments (Finance, HR, Sales) in a single database, eliminating data silos where different departments maintain separate copies of the same data. This integration ensures data consistency across the organization, leading to better decision-making and improved overall efficiency. By having real-time access to data, managers can make more informed decisions without waiting for end-of-period reports, thus enhancing operational agility .

ERP systems support real-time decision-making by providing managers with immediate access to integrated data across departments, such as sales, finance, and HR. This allows for quick adjustments to operations, such as reallocating resources to meet demand spikes or addressing inventory shortages promptly. As a result, businesses can enhance agility, optimize operations, and improve customer service by responding swiftly to changes in the business environment .

Cloud-based payment solutions offer scalability, cost-effectiveness, and rapid deployment of new features compared to traditional on-premises systems. They allow businesses to handle traffic spikes efficiently and reduce upfront infrastructure costs. However, they may introduce concerns regarding data security and ownership, as well as reliance on third-party providers for service continuity and compliance with data protection regulations .

AI/ML enhances security by analyzing transaction data in real time to detect patterns indicative of fraud, thereby enabling immediate blocking of suspicious activities. For example, AI can identify improbable geographic spending patterns, flagging them as potential account compromises. However, limitations include the potential for false positives, lack of adaptability to entirely new fraud tactics, and the significant data resources required to train AI models effectively .

Middleware serves as a bridge between old ERP systems and modern CRM platforms by translating data into compatible formats. This integration reduces the need for manual data entry, thus lowering errors and improving process efficiency. By enabling seamless data exchange, middleware enhances the functionality of legacy systems and extends their lifespan while avoiding the substantial cost of full system replacement .

Customization of ERP systems, especially when it involves altering core code, can lead to future update challenges, increased complexity, and support difficulties. This often results in high maintenance costs and loss of vendor support for standard updates. To mitigate these pitfalls, organizations should prioritize configurations over customizations, employ a phased implementation approach, and ensure alignment with best practices that involve minimal interference with core ERP functionality .

You might also like