Finding · F-RBI-03
Payment provider incident — incomplete credential rotation
In ProgressVEN-03 · Supplier security incidents are assessed for impact and trackedThird-Party RiskQ3 2026 Unified Program Review
Fraud indicator
Rating
No
High
Medium
Low
Requirement to validation
Requirement
ISO-A.5.19 · ISO-A.5.24 · RBI-CSF-NBFC-Annex-1-2 · RBI-OITS-2023-9 · SOC2-CC7.3 · SOC2-CC9.2
mapped
Policy
Vendor & IT Outsourcing Risk Policy
pol-vendor
Control
VEN-03
Supplier security incidents are assessed for impact and tracked
Application
PayGate Payment Gateway · Meridian Customer Portal
mapped
Evidence · Q3
4 items
2 approved · 1 pending · 1 rejected
Test · Q3
Fail
TST-RBI-VEN-03 · High confidence
Finding
F-RBI-03 · High
In Progress
Action
Deepa Menon
REM-F-RBI-03 · In Progress
Validation
Pending
as recorded
Observation
Raised 2026-10-05 in the RBI Regulatory Controls — Q4 2026 Periodic Internal Audit (Meridian Internal Audit (IS Audit cell)). Rated critical by the engagement. After PayGate incident PG-SEC-2026-014, 2 of 3 Meridian API credentials were rotated. The settlement-report API key (created 2025-11-02) is still active. Related controls: PAY-01.
Applications: PayGate Payment Gateway, Meridian Customer Portal.
Potential risk
Unauthorised or erroneous transactions could go undetected and expose Meridian to financial loss and regulatory action.
Root cause
Credential inventory for PayGate integrations omitted the settlement-report API key.
Agreed action plan
Remaining settlement-report key rotation scheduled with PayGate on 2026-10-10; RBI updated on 2026-10-06. Tracked as T-009, T-010, T-011 in Prismet Tasks.
Management response: Remaining settlement-report key rotation scheduled with PayGate on 2026-10-10; RBI updated on 2026-10-06.
- Action
- REM-F-RBI-03
- Owner (FPR)
- Deepa Menon
- Target date
- 10 Oct 2026
- Priority
- High
- Status
- In Progress
- Validation
- Pending · planned 10 Oct 2026
Evidence for this control (6)
| Evidence | Title | Control | Source system | Collected | Status |
|---|---|---|---|---|---|
| Q2-EV-035 | PayGate Payment Gateway · access review (Q2) | VEN-03 | PayGate Payment Gateway | 10 Jun 2026 | Accepted |
| Q2-EV-036 | Meridian Customer Portal · policy document (Q2) | VEN-03 | Meridian Customer Portal | 15 Jun 2026 | Accepted |
| RBI-REQ-030 | PayGate: Provider API keys rotated after incident | VEN-03 | 7 Oct 2026 | Accepted | |
| RBI-REQ-031 | Meridian Customer Portal: Payment webhook signatures valid | VEN-03 | Meridian Customer Portal | 6 Oct 2026 | Accepted |
| SOC2-REQ-040 | PayGate: Provider API keys rotated after incident | VEN-03 | 5 Oct 2026 | Rejected | |
| SOC2-REQ-041 | Meridian Customer Portal: Payment webhook signatures valid | VEN-03 | Meridian Customer Portal | 4 Oct 2026 | Under review |
Tests of this control (2)
| Test | Control | Cycle | Tested | By | Result | Confidence |
|---|---|---|---|---|---|---|
| TST-RBI-VEN-03 | VEN-03 · Supplier security incidents are assessed for impact and tracked | Q3 2026 Unified Program Review | 3 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell) | Fail | High |
| TST-Q2-VEN-03 | VEN-03 · Supplier security incidents are assessed for impact and tracked | Q2 2026 Unified Program Review | 12 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Pass | High |