CASA stands for current account and savings account, a core deposit relationship used widely in retail banking. It describes accounts that support routine deposits and withdrawals while helping banks retain low-cost funding and customer engagement. In onboarding, CASA demands strong identity checks because transaction access is broad.
What CASA Means in Banking
CASA, or current account and savings account, refers to the core retail deposit relationships banks use for everyday transactions, customer retention, and relatively low-cost funding. It is a product category, but also a funding and access relationship.
Why CASA Matters to Banking Operations
CASA is valuable because it anchors recurring customer activity: salary credits, bill payments, transfers, cash withdrawals, card-linked spending, and balance maintenance. That makes it operationally important for liquidity planning, deposit stickiness, and customer engagement.
Because CASA is designed for frequent use, the surrounding banking controls must support both convenience and assurance. The account type itself is not a control, but it often sits inside onboarding, servicing, and transaction workflows where identity proofing, entitlement checks, and fraud monitoring are necessary.
CASA in Onboarding and Access Design
In onboarding, CASA usually requires stronger customer verification than a passive balance-only relationship because the account can support broad transaction access. Banks need confidence that the person opening or managing the account is the legitimate holder, especially when remote onboarding, digital channels, or delegated access are involved.
That makes CASA part of the wider access design for retail banking: the account is the financial container, while authentication, authorization, and customer identity controls determine who can operate it. The practical question is not just whether the account exists, but whether the right person can safely use it across channels.
CASA as a Funding and Customer Relationship Model
From a bank perspective, CASA combines two functions, cheap deposits and active customer relationship depth. Current accounts tend to support higher transaction frequency, while savings accounts can encourage retention and deposit accumulation. Together they help banks reduce dependence on more expensive funding sources.
This is why CASA is often discussed in treasury, retail banking, and product strategy at the same time. A healthy CASA base can indicate stable customer engagement, but it also increases the importance of reliable servicing, reconciliation, account controls, and dispute handling across high-volume transaction flows.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | CASA onboarding for retail customers depends on proving customer identity before account access. |
| AC-2 — Account Management | CASA is an account relationship that requires lifecycle management for opening, use, and closure. | |
| IA-5 — Authenticator Management | CASA access depends on credential and authenticator handling for digital banking channels. | |
| Recommendation — Apply IA-8 to verify customer identity before enabling CASA transaction access. Use AC-2 to govern CASA account creation, activation, review, and termination. Apply IA-5 to manage credentials and authenticators used for CASA access. | ||
| NIST CSF 2.0 | PR.AA-01 — Identity Management, Authentication and Access Control | CASA hinges on identity verification and access decisions for customer banking interactions. |
| Recommendation — Map CASA onboarding and servicing to PR.AA-01 to enforce identity and access controls. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | CASA requires controlled access to customer banking functions and account operations. |
| Recommendation — Use A.5.15 to restrict who can access and operate CASA functions. | ||
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org