Test · TST-Q2-PAY-01

PAY-01 · Payment APIs secured with mTLS, signing and customer 2FA

FailQ2 2026 Unified Program ReviewTested 18 Jun 2026 by Farah Khan, Vikram Mehta · Meridian Internal Audit

Requirement to validation

Procedure and result

Procedure
API gateway config, portal auth service. Tests: PayGate Payment Gateway: mTLS enforced on payout API; Meridian Customer Portal: Payment initiation requires 2FA. Frequency continuous.
Sample
25 items sampled (Q2 baseline)
Expected
Integrations with the payment gateway use mutual TLS and signed requests; customer-initiated payments on the portal require OTP / device-bound second factor.
Observed
The portal's bulk-payout endpoint accepted signed requests without a second factor for 2 of 12 corporate customers on a legacy plan.
Confidence
High