Archyno
UMLPratique de la modélisation

Un système bancaire en UML

La plupart des exemples bancaires modélisent un compte comme un solde doté d'une méthode déposer, c'est-à-dire la seule chose qu'aucune banque ne fait. Voici la version fondée sur la partie double, avec la machine à états qui décide ce qu'un virement a le droit de faire ensuite.

8 min de lectureUML 2.5.121 sur 23

11..*10..*12Customer- id: UUID- name: String- kycTier: TierAccount- iban: IBAN- currency: Currency- status: Status+ balance(): MoneyPosting- amount: Money- bookedAt: InstantTransaction- id: UUID- reference: String
The ledger. Note what Account does not have: a balance attribute. It has balance() - an operation that sums the postings - and that single decision is what keeps the model honest.

01The account has no balance

Nearly every banking example on the internet gives Account a balance attribute and a pair of methods that add to it and subtract from it. It is the first thing to delete, because no ledger that has to be auditable works that way.

A stored balance is a second copy of a fact the postings already contain. Two copies of a fact can disagree, and when they do - a partial failure, a retried message, a migration - there is no way to tell which is right, because the balance carries no history to check it against. Deriving it, as balance() on the figure above, makes disagreement impossible by construction.

02A transfer is one thing with two effects

The composition on the right of the hero figure is the second load-bearing decision. A Transaction is composed of exactly two Postings - the multiplicity says 2, not 0..* - and by convention they sum to zero: money leaves one account and arrives at another.

Drawing an association from Account straight to Account, which is the obvious first attempt, loses both halves of that. It loses atomicity, because two arrows can exist independently and a transfer cannot half-happen. And it loses the reference: a transaction is a thing customers ask about by number, dispute, and reverse, which means it is an entity and not a line between two others.

The filled diamond then says the postings die with the transaction. That is correct and it is also a constraint on the code: you cannot delete half a transfer, and a reversal is a new transaction rather than an edit to the old one. The class diagram guide has the full rules for when a diamond is filled.

03What a transfer is allowed to do next

authorisesettlereject [limit]RequestedAuthorisedSettledRejected
The transfer lifecycle. Four states, and the useful part is what is missing: there is no arrow from Rejected back to Authorised, and none from Settled to anywhere.

A state machine earns its place whenever an object has a lifecycle that rules depend on, and money moving is the archetype. The value is not the four boxes, which anybody could guess - it is the transitions that are absent.

Settled has no outgoing transition. That says a settled transfer is final, and a reversal is a different transaction rather than a state change, which is the same claim the composition on the domain model made. Rejected has none either: an approval after a rejection starts a new transfer. Guards make the rest explicit - reject [limit]names why, and a diagram that says only "reject" leaves the reason to the reader.

In one line each

  1. 01Delete the balance attribute - derive it from postings, or two copies of one fact will disagree.
  2. 02A transfer is one Transaction composed of exactly two Postings that sum to zero.
  3. 03Composition, not association: you cannot delete half a transfer, and a reversal is a new one.
  4. 04Model the lifecycle where rules depend on it, and read the missing transitions first.
  5. 05Name the guard on a transition; "reject" alone leaves the reason to the reader.
  6. 06Channels - ATM, app, branch - belong on a component diagram, not on the ledger.

For the same treatment of a different domain, see e-commerce architecture, modelled. For the data-modelling half of a ledger - keys, cardinality and the schema underneath - see ER diagrams.

04Questions fréquentes

Comment modéliser le solde d'un compte en UML ?

Comme une opération dérivée plutôt qu'un attribut stocké : balance() additionne les écritures du compte. Un solde stocké est une seconde copie d'un fait que le grand livre contient déjà, et le jour où les deux divergent, rien ne dit lequel a tort - raison pour laquelle les vrais grands livres n'en gardent pas.

Comment représenter un virement entre deux comptes ?

Comme une Transaction composée d'exactement deux écritures, une négative et une positive, de somme nulle. Une flèche d'un compte vers l'autre perd le fait qu'un virement est une chose atomique unique à deux effets, et c'est cette atomicité que le modèle existe pour protéger.

Quels diagrammes UML pour un système bancaire ?

Un diagramme de classes pour le grand livre, une machine à états pour tout ce qui a un cycle de vie - virements, cartes, demandes - et un diagramme de composants pour la frontière avec les schémas de paiement et le core banking. Les diagrammes de séquence servent pour les deux ou trois flux réellement disputés.

Un distributeur doit-il figurer sur le diagramme des comptes ?

Non. Un distributeur est un canal et va sur un diagramme de composants ou de déploiement avec les autres canaux ; le diagramme du grand livre porte sur ce qu'est une transaction. Mélanger les deux produit le diagramme d'exercice classique où un appareil est associé à une notion comptable.

Tous les articles