Per product
Baseline limits for every card product — the default a new card inherits.
Card Prime / Lifecycle
One status machine, one history, one set of controls — read the same way by the ATM, the switch, the branch and the app.
| Module | Specification |
|---|---|
| Card lifecycle | PAN generation (BIN + sequence + Luhn), status machine (active, blocked, temporarily blocked, closed, replaced, renewed, reissued), add-on cards, bulk generation, immutable history. |
| Onboarding & KYC | Customer registration, document types, duplicate and eligibility checks, instant KYC hooks for branch and KIOSK. |
| Instant issuance | Pre-generated stock, on-the-spot print, immediate PIN set via HSM, pre-activation. |
| Embossing — multi-vendor | Vendor profiles with per-vendor perso formats (embossing text, tracks, ICC data), PGP encryption, SFTP exchange, acknowledgement and rejection handling, vendor switching. |
| Limits & controls | Per product, per card, per channel (ATM, POS, e-commerce, OFF-US) and per currency; temporary controls. |
| PIN, CVV & HSM | PVV and IBM offset PIN methods; CVV1, CVV2 and iCVV inside the HSM only; secure PIN set and reset via OTP; key-ID indirection. |
| KIOSK journey | Guided onboarding, KYC, product selection, instant card and PIN — the same API surface as every other channel, English and Arabic. |
| Digital cards — MDES | Issuer-side token lifecycle (provision, suspend, resume, delete), cardholder verification, token-to-card mapping. |
| Virtual Card SDK | Android and iOS SDK: create and display a virtual card, freeze and unfreeze, controls, tap-and-pay enablement. |
| Back office (UMS) | Role and menu-based access, maker-checker queues, audit reports, user administration, static content, end-of-day jobs, English and Arabic. |
| Card type | Form factor | Issuance channel | Activation |
|---|---|---|---|
| Personalized debit | Chip + contactless (dual interface) | Branch or back office → embossing vendor | On receipt, or pre-activated |
| Instant debit | Chip + contactless, pre-printed stock | Branch or KIOSK, printed on the spot | Immediate, PIN set via HSM |
| Digital card | Mastercard token (MDES) | Mobile app provisioning | On provisioning |
| Virtual card | SDK in the bank's own app | Mobile app | Immediate |
A limit is resolved from the product, the card, the channel and the currency together. Temporary controls carry an expiry, so an override set at a branch counter does not become permanent by accident.
Baseline limits for every card product — the default a new card inherits.
Overrides on a single card, with reason and actor recorded.
ATM, POS, e-commerce and OFF-US each carry their own ceiling and count.
USD, SAR and USD limits held separately, not converted at check time.
Because PIN and CVV operations happen only inside the hardware module, there is no configuration, no log level and no support procedure that can expose them. That is a property of the design rather than a policy anyone has to enforce.
Every menu and action is granted by role, scoped by institution and region. A user sees only the entities they administer.
Card, limit and configuration changes are proposed by one user and approved by another, with the queue visible and audited.
Who changed what, when, from where and why — exportable for internal audit and for the regulator.
Scheduled jobs for cut-off, reconciliation files, report generation and housekeeping.
Tell us your BIN plan, card products and where the customer starts — branch, KIOSK or app. We will come back with an issuance design, an embossing plan and a delivery schedule.