Control · PAY-01
Payment APIs secured with mTLS, signing and customer 2FA
Payments SecuritySOC 2 · ISO 27001 · RBIRisk High
Requirement to validation
Requirement
ISO-A.8.24 · ISO-A.8.5 · RBI-DPSC-2021-4 · SOC2-CC6.1 · SOC2-CC6.7
mapped
Policy
Payments Security Policy
pol-payments
Control
PAY-01
Payment APIs secured with mTLS, signing and customer 2FA
Application
PayGate Payment Gateway · Meridian Customer Portal
mapped
Evidence · Q3
2 items
2 approved · 0 pending · 0 rejected
Test · Q3
Pass
TST-RBI-PAY-01 · High confidence
Finding
F-IAQ2-PAY-01 · High
Closed
Action
Deepa Menon
REM-F-IAQ2-PAY-01 · Closed
Validation
Validated
as recorded
What should be true
Integrations with the payment gateway use mutual TLS and signed requests; customer-initiated payments on the portal require OTP / device-bound second factor.
- Requirements
- ISO-A.8.24 A.8.24 · Use of cryptographyISO-A.8.5 A.8.5 · Secure authenticationRBI-DPSC-2021-4 RBI-DPSC-2021 §4 · Digital payment security — application security, API security, transaction authentication (RBI Master Direction on Digital Payment Security Controls, 2021)SOC2-CC6.1 CC6.1 · Logical access security software, infrastructure and architecturesSOC2-CC6.7 CC6.7 · Restricts transmission and movement of information; encryption in transit
- Applications
- PayGate Payment GatewayMeridian Customer Portal
- Third parties
- PayGate Payments Pvt. Ltd.
- Testing procedure
- API gateway config, portal auth service. Tests: PayGate Payment Gateway: mTLS enforced on payout API; Meridian Customer Portal: Payment initiation requires 2FA. Frequency continuous.
Findings (1)
| Finding | Observation | Control | Applications | Severity | Status | Owner | Action | Validation |
|---|---|---|---|---|---|---|---|---|
| F-IAQ2-PAY-01 | Bulk payout API accepted requests without customer 2FA | PAY-01 | PayGate Payment Gateway, Meridian Customer Portal | High | Closed | Deepa Menon | REM-F-IAQ2-PAY-01 · Closed | Validated |
Evidence (4)
| Evidence | Title | Control | Source system | Collected | Status |
|---|---|---|---|---|---|
| Q2-EV-039 | PayGate Payment Gateway · system export (Q2) | PAY-01 | PayGate Payment Gateway | 6 Jun 2026 | Rejected |
| Q2-EV-040 | Meridian Customer Portal · configuration report (Q2) | PAY-01 | Meridian Customer Portal | 11 Jun 2026 | Rejected |
| RBI-REQ-035 | PayGate: mTLS enforced on payout API | PAY-01 | 4 Oct 2026 | Accepted | |
| RBI-REQ-036 | Meridian Customer Portal: Payment initiation requires 2FA | PAY-01 | Meridian Customer Portal | 9 Oct 2026 | Accepted |
Tests (2)
| Test | Control | Cycle | Tested | By | Result | Confidence |
|---|---|---|---|---|---|---|
| TST-RBI-PAY-01 | PAY-01 · Payment APIs secured with mTLS, signing and customer 2FA | Q3 2026 Unified Program Review | 5 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell) | Pass | High |
| TST-Q2-PAY-01 | PAY-01 · Payment APIs secured with mTLS, signing and customer 2FA | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |