Skip to content
Preptima
hardScenarioMidSeniorStaffLead

A property completion has to happen today and the high-value rail is not available. Walk me through what you do.

You cannot substitute the rail, so the work is triage, finality and communication - deciding which payments genuinely must settle today, whether any alternative gives the receiver the same certainty, and what you tell the customer before the window closes. The backlog on recovery is the second incident.

6 min readUpdated 2026-07-29Target archetype: Enterprise Captive
Practice answering out loud

What the interviewer is scoring

  • Whether the candidate identifies finality in central bank money as the property that cannot be substituted
  • Does the answer triage by consequence of delay rather than by payment value or queue order
  • That an alternative rail is evaluated on limits, finality and receiver acceptance rather than on availability alone
  • Whether the customer is told something truthful in time to act, rather than after the window closes
  • Does the candidate plan the resumption backlog, including ordering and duplicate prevention

Answer

Name the property you cannot replace

The instinct is to look for another way to move the money, and it is the wrong first move because it skips the reason this payment is on this rail. A high-value payment rail settling in real time across accounts at the central bank gives the receiver two things: the money arrives gross rather than as part of a net position, and once it has settled it is final and cannot be unwound. A completion depends on the second property. The solicitor releases the keys because the funds are irrevocably theirs, not because a message said they were coming.

So before you consider alternatives you have to ask whether the alternative delivers finality that the receiving party will accept. Many will not. A rail whose settlement is deferred to a later net cycle, or one whose payments can be recalled, changes the risk the receiver is taking, and their instruction may simply not permit it. This is a legal and commercial constraint rather than a technical one, and a candidate who reaches for a substitute rail without asking whether the beneficiary's solicitor will accept it has not understood what the payment is for.

Triage by consequence, not by value

The queue on a day like this contains thousands of payments, and treating them uniformly guarantees that the ones that matter are handled last. Sort them by what breaks if they are late.

At the top sit payments with a hard external deadline and a third party who acts on receipt: property completions, margin and collateral calls, settlement obligations to a market infrastructure, payments funding another institution's position. Below them are payments that are time-sensitive but survivable: payroll a day early, supplier payments with a payment-terms consequence. Below that, the bulk of the volume, which is genuinely fine tomorrow.

The important structural point is that this ordering has to be knowable before the day. If the only attribute your payment records carry is amount, you will triage on amount, and amount correlates poorly with consequence. A payment purpose, a client-stated deadline, an indicator that the payment funds another party's obligation — these are cheap to capture at instruction time and impossible to reconstruct in an incident.

The corollary is a decision nobody likes: some payments are deliberately not attempted, and someone has to be authorised to say so. Establishing who that is, in advance, is part of the contingency rather than a detail.

Alternatives and their sharp edges

If an alternative is acceptable to the beneficiary, three practical constraints bite. Instant payment rails carry per-transaction limits, frequently well below a property purchase, and the limits your own bank applies may be lower than the scheme's. Splitting a payment across several transfers to get under a limit changes the reconciliation on the receiving side, may breach the receiver's own controls, and can trip your monitoring as structuring, which is a genuine reason your financial-crime team will want to be in the room rather than an obstruction.

Correspondent routing may exist for the same currency, at the cost of another institution's timetable and finality rules. And where the payment is between accounts you both hold, or between two customers of your own bank, you can settle on your own books, which is instant, final and entirely within your control — the option most often forgotten precisely because it does not involve a rail.

The single most useful thing you can do, and it is not a technical intervention, is to speak to the receiving institution and the scheme operator. High-value settlement systems normally have a defined ability to extend the closing time when a disruption warrants it, and the participants are notified rather than left guessing. A payment that misses the window by twenty minutes and a payment that misses it by a day are very different outcomes for a house purchase.

The manual path has to be a real, rehearsed thing

Contingency in this space usually reduces to a smaller number of payments handled with more human involvement: instructions taken and verified out of band, dual authorisation applied by named people, and a written record kept because the automated audit trail is not being generated. That is fine, and it is the honest answer, but it only works if the arrangements exist before the day.

The parts that are always missing when they have not been rehearsed are the credentials and the authority. Who holds the tokens or certificates for the contingency channel, whether they are physically present, whether the standby people have current access, whether the counterparty will accept an instruction from a channel you rarely use, and what the verification procedure is when the normal one is unavailable. A contingency channel whose access rights expired eight months ago is discovered at the moment it is needed, and this is by far the commonest way a documented plan turns out not to exist.

The volume constraint has to be stated too. Manual handling has a throughput measured in tens per hour, not thousands, which is what makes the triage step load-bearing rather than administrative.

Recovery is the second incident

When the rail returns you have a backlog and a shortened window, and three things go wrong in a predictable order. Payments handled manually get replayed automatically, so the same payment goes twice — which is why anything handled out of band must be marked in the source system, with the manual reference recorded against it, before the automated flow is re-enabled. Ordering matters where a payment depends on an incoming credit to fund it, so a naive first-in-first-out drain can stall on a payment that cannot yet settle while later payments that could have gone wait behind it. And your settlement account needs enough liquidity to clear a day's worth of gross payments in a compressed period, which may mean funding it differently from a normal afternoon.

Reconciliation afterwards is not optional bookkeeping. You need to state, by the end of the day, which payments settled, which were sent by an alternative route and which were abandoned, because the answer to each of those is a different conversation with a different customer.

The plan that exists only as a throughput number

The trap in this question is a design document that specifies capacity, latency and failover between your own data centres, and says nothing about the day the rail itself is not there. Your availability is not the constraint in that scenario; the shared infrastructure is, and you cannot engineer around it from inside your own estate. What you can do is capture the payment attributes that make triage possible, maintain a manual path with live credentials and rehearsed authority, agree in advance with the scheme and your correspondents what is permissible, and be able to tell a customer the truth early enough for them to make their own arrangements. That last one is the difference between a bad day and a complaint.

What this failure looks like in the wild

In October 2014, the Bank of England halted CHAPS, the United Kingdom's high-value payment rail, for most of a working day after a fault surfaced during routine maintenance of the settlement system. Time-critical payments, including house purchases completing that day, had to be handled manually and the settlement window was extended into the evening. What this illustrates for a rail design is that the contingency path matters as much as the throughput figure, because a rail that cannot be operated in a reduced manual mode has no answer at all on the day it stops.

Likely follow-ups

  • What would you have to agree with the scheme or the central bank in advance for your contingency to be usable on the day?
  • How do you prevent a payment being sent twice when it was queued manually and then replayed automatically?
  • Which payments would you deliberately not attempt, and who is entitled to make that call?
  • How does your settlement account funding change on a day the rail runs late into the evening?

Related questions

rtgssettlement-finalitypayment-contingencycut-off-timesliquidity