Test · TST-RBI-PAY-01

PAY-01 · Payment APIs secured with mTLS, signing and customer 2FA

PassQ3 2026 Unified Program ReviewTested 5 Oct 2026 by Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)

Requirement to validation

Procedure and result

Procedure
API gateway config, portal auth service. Tests: PayGate Payment Gateway: mTLS enforced on payout API; Meridian Customer Portal: Payment initiation requires 2FA. Frequency continuous.
Sample
2 items sampled (reperformance)
Expected
Integrations with the payment gateway use mutual TLS and signed requests; customer-initiated payments on the portal require OTP / device-bound second factor.
Observed
Operating effectiveness confirmed for PayGate, Meridian Customer Portal; no exceptions in 2 sample(s).
Confidence
High