Finding · F-RBI-03

Payment provider incident — incomplete credential rotation

In ProgressVEN-03 · Supplier security incidents are assessed for impact and trackedThird-Party RiskQ3 2026 Unified Program Review
Fraud indicator
Rating
No
High
Medium
Low

Requirement to validation

Observation
Raised 2026-10-05 in the RBI Regulatory Controls — Q4 2026 Periodic Internal Audit (Meridian Internal Audit (IS Audit cell)). Rated critical by the engagement. After PayGate incident PG-SEC-2026-014, 2 of 3 Meridian API credentials were rotated. The settlement-report API key (created 2025-11-02) is still active. Related controls: PAY-01.
Applications: PayGate Payment Gateway, Meridian Customer Portal.
Potential risk
Unauthorised or erroneous transactions could go undetected and expose Meridian to financial loss and regulatory action.
Root cause
Credential inventory for PayGate integrations omitted the settlement-report API key.
Agreed action plan

Remaining settlement-report key rotation scheduled with PayGate on 2026-10-10; RBI updated on 2026-10-06. Tracked as T-009, T-010, T-011 in Prismet Tasks.

Management response: Remaining settlement-report key rotation scheduled with PayGate on 2026-10-10; RBI updated on 2026-10-06.

Owner (FPR)
Deepa Menon
Target date
10 Oct 2026
Priority
High
Status
In Progress

Evidence for this control (6)

Open list →
EvidenceTitleControlSource systemCollectedStatus
Q2-EV-035PayGate Payment Gateway · access review (Q2)VEN-03PayGate Payment Gateway10 Jun 2026Accepted
Q2-EV-036Meridian Customer Portal · policy document (Q2)VEN-03Meridian Customer Portal15 Jun 2026Accepted
RBI-REQ-030PayGate: Provider API keys rotated after incidentVEN-037 Oct 2026Accepted
RBI-REQ-031Meridian Customer Portal: Payment webhook signatures validVEN-03Meridian Customer Portal6 Oct 2026Accepted
SOC2-REQ-040PayGate: Provider API keys rotated after incidentVEN-035 Oct 2026Rejected
SOC2-REQ-041Meridian Customer Portal: Payment webhook signatures validVEN-03Meridian Customer Portal4 Oct 2026Under review

Tests of this control (2)

Open list →
TestControlCycleTestedByResultConfidence
TST-RBI-VEN-03VEN-03 · Supplier security incidents are assessed for impact and trackedQ3 2026 Unified Program Review3 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)FailHigh
TST-Q2-VEN-03VEN-03 · Supplier security incidents are assessed for impact and trackedQ2 2026 Unified Program Review12 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPassHigh