Test · TST-Q2-PAY-01
PAY-01 · Payment APIs secured with mTLS, signing and customer 2FA
FailQ2 2026 Unified Program ReviewTested 18 Jun 2026 by Farah Khan, Vikram Mehta · Meridian Internal Audit
Requirement to validation
Requirement
ISO-A.8.24 · ISO-A.8.5 · RBI-DPSC-2021-4 · SOC2-CC6.1 · SOC2-CC6.7
mapped
Policy
Payments Security Policy
pol-payments
Control
PAY-01
Payment APIs secured with mTLS, signing and customer 2FA
Application
PayGate Payment Gateway · Meridian Customer Portal
mapped
Evidence · Q3
2 items
2 approved · 0 pending · 0 rejected
Test · Q3
Pass
TST-RBI-PAY-01 · High confidence
Finding
F-IAQ2-PAY-01 · High
Closed
Action
Deepa Menon
REM-F-IAQ2-PAY-01 · Closed
Validation
Validated
as recorded
Procedure and result
- Procedure
- API gateway config, portal auth service. Tests: PayGate Payment Gateway: mTLS enforced on payout API; Meridian Customer Portal: Payment initiation requires 2FA. Frequency continuous.
- Sample
- 25 items sampled (Q2 baseline)
- Expected
- Integrations with the payment gateway use mutual TLS and signed requests; customer-initiated payments on the portal require OTP / device-bound second factor.
- Observed
- The portal's bulk-payout endpoint accepted signed requests without a second factor for 2 of 12 corporate customers on a legacy plan.
- Confidence
- High