Control · VEN-03
Supplier security incidents are assessed for impact and tracked
Third-Party RiskSOC 2 · ISO 27001 · RBIRisk High
Requirement to validation
Requirement
ISO-A.5.19 · ISO-A.5.24 · RBI-CSF-NBFC-Annex-1-2 · RBI-OITS-2023-9 · SOC2-CC7.3 · SOC2-CC9.2
mapped
Policy
Vendor & IT Outsourcing Risk Policy
pol-vendor
Control
VEN-03
Supplier security incidents are assessed for impact and tracked
Application
PayGate Payment Gateway · Meridian Customer Portal
mapped
Evidence · Q3
4 items
2 approved · 1 pending · 1 rejected
Test · Q3
Fail
TST-RBI-VEN-03 · High confidence
Finding
F-RBI-03 · High
In Progress
Action
Deepa Menon
REM-F-RBI-03 · In Progress
Validation
Pending
as recorded
What should be true
On notice of a security incident at a critical provider, an impact assessment covering services, applications, controls and customers is completed within 24 hours, credentials are rotated where relevant, and regulatory notification is made when required.
- Requirements
- ISO-A.5.19 A.5.19 · Information security in supplier relationshipsISO-A.5.24 A.5.24 · Information security incident management planning and preparationRBI-CSF-NBFC-Annex-1-2 RBI-CSF-NBFC Annex 1 §2 · Cyber security — SOC monitoring, vulnerability management, incident reporting (RBI Cyber Security Framework for NBFCs (IT Framework for the NBFC Sector))RBI-OITS-2023-9 RBI-OITS-2023 §9 · Outsourcing — ongoing monitoring of service providers and incident notification (RBI Master Direction on Outsourcing of Information Technology Services, 2023)SOC2-CC7.3 CC7.3 · Evaluates security events to determine whether they are incidentsSOC2-CC9.2 CC9.2 · Assesses and manages risks associated with vendors and business partners
- Applications
- PayGate Payment GatewayMeridian Customer Portal
- Third parties
- PayGate Payments Pvt. Ltd.
- Testing procedure
- Prismet external intelligence -> relationship graph -> tasks; continuous monitoring verifies key rotation. Tests: PayGate Payment Gateway: Provider API keys rotated after incident; Meridian Customer Portal: Payment webhook signatures valid. Frequency on-demand.
Findings (1)
| Finding | Observation | Control | Applications | Severity | Status | Owner | Action | Validation |
|---|---|---|---|---|---|---|---|---|
| F-RBI-03 | Payment provider incident — incomplete credential rotation | VEN-03 | PayGate Payment Gateway, Meridian Customer Portal | High | In Progress | Deepa Menon | REM-F-RBI-03 · In Progress | Pending |
Evidence (6)
| Evidence | Title | Control | Source system | Collected | Status |
|---|---|---|---|---|---|
| Q2-EV-035 | PayGate Payment Gateway · access review (Q2) | VEN-03 | PayGate Payment Gateway | 10 Jun 2026 | Accepted |
| Q2-EV-036 | Meridian Customer Portal · policy document (Q2) | VEN-03 | Meridian Customer Portal | 15 Jun 2026 | Accepted |
| RBI-REQ-030 | PayGate: Provider API keys rotated after incident | VEN-03 | 7 Oct 2026 | Accepted | |
| RBI-REQ-031 | Meridian Customer Portal: Payment webhook signatures valid | VEN-03 | Meridian Customer Portal | 6 Oct 2026 | Accepted |
| SOC2-REQ-040 | PayGate: Provider API keys rotated after incident | VEN-03 | 5 Oct 2026 | Rejected | |
| SOC2-REQ-041 | Meridian Customer Portal: Payment webhook signatures valid | VEN-03 | Meridian Customer Portal | 4 Oct 2026 | Under review |
Tests (2)
| Test | Control | Cycle | Tested | By | Result | Confidence |
|---|---|---|---|---|---|---|
| TST-RBI-VEN-03 | VEN-03 · Supplier security incidents are assessed for impact and tracked | Q3 2026 Unified Program Review | 3 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell) | Fail | High |
| TST-Q2-VEN-03 | VEN-03 · Supplier security incidents are assessed for impact and tracked | Q2 2026 Unified Program Review | 12 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Pass | High |