Archyno
UMLPráctica del modelado

Un sistema bancario en UML

La mayoría de los ejemplos bancarios modelan una cuenta como un saldo con un método ingresar, que es justo lo único que ningún banco hace. Aquí está la versión basada en la partida doble, más la máquina de estados que decide qué puede hacer a continuación una transferencia.

8 min de lecturaUML 2.5.121 de 23

11..*10..*12Customer- id: UUID- name: String- kycTier: TierAccount- iban: IBAN- currency: Currency- status: Status+ balance(): MoneyPosting- amount: Money- bookedAt: InstantTransaction- id: UUID- reference: String
The ledger. Note what Account does not have: a balance attribute. It has balance() - an operation that sums the postings - and that single decision is what keeps the model honest.

01The account has no balance

Nearly every banking example on the internet gives Account a balance attribute and a pair of methods that add to it and subtract from it. It is the first thing to delete, because no ledger that has to be auditable works that way.

A stored balance is a second copy of a fact the postings already contain. Two copies of a fact can disagree, and when they do - a partial failure, a retried message, a migration - there is no way to tell which is right, because the balance carries no history to check it against. Deriving it, as balance() on the figure above, makes disagreement impossible by construction.

02A transfer is one thing with two effects

The composition on the right of the hero figure is the second load-bearing decision. A Transaction is composed of exactly two Postings - the multiplicity says 2, not 0..* - and by convention they sum to zero: money leaves one account and arrives at another.

Drawing an association from Account straight to Account, which is the obvious first attempt, loses both halves of that. It loses atomicity, because two arrows can exist independently and a transfer cannot half-happen. And it loses the reference: a transaction is a thing customers ask about by number, dispute, and reverse, which means it is an entity and not a line between two others.

The filled diamond then says the postings die with the transaction. That is correct and it is also a constraint on the code: you cannot delete half a transfer, and a reversal is a new transaction rather than an edit to the old one. The class diagram guide has the full rules for when a diamond is filled.

03What a transfer is allowed to do next

authorisesettlereject [limit]RequestedAuthorisedSettledRejected
The transfer lifecycle. Four states, and the useful part is what is missing: there is no arrow from Rejected back to Authorised, and none from Settled to anywhere.

A state machine earns its place whenever an object has a lifecycle that rules depend on, and money moving is the archetype. The value is not the four boxes, which anybody could guess - it is the transitions that are absent.

Settled has no outgoing transition. That says a settled transfer is final, and a reversal is a different transaction rather than a state change, which is the same claim the composition on the domain model made. Rejected has none either: an approval after a rejection starts a new transfer. Guards make the rest explicit - reject [limit]names why, and a diagram that says only "reject" leaves the reason to the reader.

In one line each

  1. 01Delete the balance attribute - derive it from postings, or two copies of one fact will disagree.
  2. 02A transfer is one Transaction composed of exactly two Postings that sum to zero.
  3. 03Composition, not association: you cannot delete half a transfer, and a reversal is a new one.
  4. 04Model the lifecycle where rules depend on it, and read the missing transitions first.
  5. 05Name the guard on a transition; "reject" alone leaves the reason to the reader.
  6. 06Channels - ATM, app, branch - belong on a component diagram, not on the ledger.

For the same treatment of a different domain, see e-commerce architecture, modelled. For the data-modelling half of a ledger - keys, cardinality and the schema underneath - see ER diagrams.

04Preguntas frecuentes

¿Cómo se modela el saldo de una cuenta en UML?

Como una operación derivada y no como un atributo almacenado: balance() suma los apuntes de la cuenta. Un saldo almacenado es una segunda copia de un dato que el libro ya tiene, y el día que ambos discrepen no hay forma de saber cuál está mal, que es justo por lo que los libros reales no lo guardan.

¿Cómo se representa una transferencia entre dos cuentas?

Como una Transacción compuesta por exactamente dos apuntes, uno negativo y otro positivo, que suman cero. Una flecha de una cuenta a otra pierde el hecho de que una transferencia es una sola cosa atómica con dos efectos, y es esa atomicidad lo que el modelo existe para proteger.

¿Qué diagramas UML necesita un sistema bancario?

Un diagrama de clases para el libro mayor, una máquina de estados para todo lo que tenga ciclo de vida - transferencias, tarjetas, solicitudes - y uno de componentes para la frontera con los esquemas de pago y el core bancario. Los de secuencia sirven para los dos o tres flujos realmente discutidos.

¿Debe aparecer un cajero en el mismo diagrama que las cuentas?

No. Un cajero es un canal y va en un diagrama de componentes o de despliegue junto a los demás canales; el diagrama del libro mayor trata de qué es una transacción. Mezclarlos produce el diagrama de ejercicio clásico donde un aparato aparece asociado a un concepto contable.

Todos los artículos