Finding · F-IAQ2-VEN-01

Critical vendor reassessments not tracked

Fraud indicator
Rating
No
High
Medium
Low

Requirement to validation

Observation
Raised 2026-06-20 in the Q2 2026 internal audit baseline. Annual risk reassessments for 2 of 4 critical third parties had no evidence of completion; the tracker had no due-date alerting.
Applications: PayGate Payment Gateway, Salesforce (Sales + Financial Services Cloud).
Potential risk
The control may not operate consistently, weakening reliance by auditors and the regulator.
Root cause
Third-party reassessment calendar maintained manually by one analyst.
Agreed action plan

Remediate: critical vendor reassessments not tracked.

Management response: Management agreed and committed to remediate before the Q3 review.

Owner (FPR)
Sanjay Kulkarni
Target date
31 Jul 2026
Priority
Medium
Status
Closed

Evidence for this control (5)

Open list →
EvidenceTitleControlSource systemCollectedStatus
Q2-EV-032Salesforce (Sales + Financial Services Cloud) · configuration report (Q2)VEN-01Salesforce (Sales + Financial Services Cloud)19 Jun 2026Rejected
Q2-EV-033PayGate Payment Gateway · ticket sample (Q2)VEN-01PayGate Payment Gateway24 Jun 2026Rejected
RBI-REQ-027Salesforce: Vendor assessment records currentVEN-019 Oct 2026Accepted
RBI-REQ-028PayGate: PayGate assurance artefacts currentVEN-018 Oct 2026Accepted
SOC2-REQ-038PayGate: PayGate assurance artefacts currentVEN-016 Oct 2026Under review

Tests of this control (2)

Open list →
TestControlCycleTestedByResultConfidence
TST-RBI-VEN-01VEN-01 · Critical third parties are risk-assessed before onboarding and annuallyQ3 2026 Unified Program Review2 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)FailMedium
TST-Q2-VEN-01VEN-01 · Critical third parties are risk-assessed before onboarding and annuallyQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailMedium