Finding · F-IAQ2-PAY-01

Bulk payout API accepted requests without customer 2FA

ClosedPAY-01 · Payment APIs secured with mTLS, signing and customer 2FAPayments SecurityQ2 2026 Unified Program Review
Fraud indicator
Rating
No
High
Medium
Low

Requirement to validation

Observation
Raised 2026-06-20 in the Q2 2026 internal audit baseline. The portal's bulk-payout endpoint accepted signed requests without a second factor for 2 of 12 corporate customers on a legacy plan.
Applications: PayGate Payment Gateway, Meridian Customer Portal.
Potential risk
Unauthorised or erroneous transactions could go undetected and expose Meridian to financial loss and regulatory action.
Root cause
Legacy API plan was excluded from the 2FA rollout.
Agreed action plan

Remediate: bulk payout api accepted requests without customer 2fa.

Management response: Management agreed and committed to remediate before the Q3 review.

Owner (FPR)
Deepa Menon
Target date
31 Jul 2026
Priority
High
Status
Closed

Evidence for this control (4)

Open list →
EvidenceTitleControlSource systemCollectedStatus
Q2-EV-039PayGate Payment Gateway · system export (Q2)PAY-01PayGate Payment Gateway6 Jun 2026Rejected
Q2-EV-040Meridian Customer Portal · configuration report (Q2)PAY-01Meridian Customer Portal11 Jun 2026Rejected
RBI-REQ-035PayGate: mTLS enforced on payout APIPAY-014 Oct 2026Accepted
RBI-REQ-036Meridian Customer Portal: Payment initiation requires 2FAPAY-01Meridian Customer Portal9 Oct 2026Accepted

Tests of this control (2)

Open list →
TestControlCycleTestedByResultConfidence
TST-RBI-PAY-01PAY-01 · Payment APIs secured with mTLS, signing and customer 2FAQ3 2026 Unified Program Review5 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)PassHigh
TST-Q2-PAY-01PAY-01 · Payment APIs secured with mTLS, signing and customer 2FAQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh