Test · TST-RBI-PAY-01
PAY-01 · Payment APIs secured with mTLS, signing and customer 2FA
PassQ3 2026 Unified Program ReviewTested 5 Oct 2026 by Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)
Requirement to validation
Requirement
ISO-A.8.24 · ISO-A.8.5 · RBI-DPSC-2021-4 · SOC2-CC6.1 · SOC2-CC6.7
mapped
Policy
Payments Security Policy
pol-payments
Control
PAY-01
Payment APIs secured with mTLS, signing and customer 2FA
Application
PayGate Payment Gateway · Meridian Customer Portal
mapped
Evidence · Q3
2 items
2 approved · 0 pending · 0 rejected
Test · Q3
Pass
TST-RBI-PAY-01 · High confidence
Finding
F-IAQ2-PAY-01 · High
Closed
Action
Deepa Menon
REM-F-IAQ2-PAY-01 · Closed
Validation
Validated
as recorded
Procedure and result
- Procedure
- API gateway config, portal auth service. Tests: PayGate Payment Gateway: mTLS enforced on payout API; Meridian Customer Portal: Payment initiation requires 2FA. Frequency continuous.
- Sample
- 2 items sampled (reperformance)
- Expected
- Integrations with the payment gateway use mutual TLS and signed requests; customer-initiated payments on the portal require OTP / device-bound second factor.
- Observed
- Operating effectiveness confirmed for PayGate, Meridian Customer Portal; no exceptions in 2 sample(s).
- Confidence
- High
- Evidence
- RBI-REQ-035RBI-REQ-036