Finding · F-ISO-02

Supplier agreement lacks information security clauses (A.5.20)

OpenVEN-02 · Provider contracts include data protection and RBI audit clausesThird-Party RiskQ3 2026 Unified Program Review
Fraud indicator
Rating
No
High
Medium
Low

Requirement to validation

Observation
Raised 2026-10-02 in the ISO/IEC 27001:2022 Surveillance Audit — 2026 (Northgate Certification Services). Classified as a minor nonconformity. VeriKYC processes Aadhaar offline XML and PAN data but no DPA with RBI audit-right and 6-hour breach notification clauses has been executed.
Applications: Salesforce (Sales + Financial Services Cloud).
Potential risk
The control may not operate consistently, weakening reliance by auditors and the regulator.
Root cause
Supplier onboarding checklist did not require a DPA before go-live for KYC processors.
Agreed action plan

DPA with VeriKYC in legal negotiation; target execution 2026-10-31. Tracked as T-012 in Prismet Tasks.

Management response: DPA with VeriKYC in legal negotiation; target execution 2026-10-31.

Owner (FPR)
Sanjay Kulkarni
Target date
31 Oct 2026
Priority
Medium
Status
In Progress

Evidence for this control (2)

Open list →
EvidenceTitleControlSource systemCollectedStatus
Q2-EV-034Salesforce (Sales + Financial Services Cloud) · ticket sample (Q2)VEN-02Salesforce (Sales + Financial Services Cloud)5 Jun 2026Accepted
SOC2-REQ-039Salesforce: Contract clause checklist per vendorVEN-026 Oct 2026Under review

Tests of this control (1)

Open list →
TestControlCycleTestedByResultConfidence
TST-Q2-VEN-02VEN-02 · Provider contracts include data protection and RBI audit clausesQ2 2026 Unified Program Review12 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPassHigh