Test · TST-RBI-VEN-03
VEN-03 · Supplier security incidents are assessed for impact and tracked
FailQ3 2026 Unified Program ReviewTested 3 Oct 2026 by Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)
Requirement to validation
Requirement
ISO-A.5.19 · ISO-A.5.24 · RBI-CSF-NBFC-Annex-1-2 · RBI-OITS-2023-9 · SOC2-CC7.3 · SOC2-CC9.2
mapped
Policy
Vendor & IT Outsourcing Risk Policy
pol-vendor
Control
VEN-03
Supplier security incidents are assessed for impact and tracked
Application
PayGate Payment Gateway · Meridian Customer Portal
mapped
Evidence · Q3
4 items
2 approved · 1 pending · 1 rejected
Test · Q3
Fail
TST-RBI-VEN-03 · High confidence
Finding
F-RBI-03 · High
In Progress
Action
Deepa Menon
REM-F-RBI-03 · In Progress
Validation
Pending
as recorded
Procedure and result
- Procedure
- Prismet external intelligence -> relationship graph -> tasks; continuous monitoring verifies key rotation. Tests: PayGate Payment Gateway: Provider API keys rotated after incident; Meridian Customer Portal: Payment webhook signatures valid. Frequency on-demand.
- Sample
- 25 items sampled (reperformance)
- Expected
- On notice of a security incident at a critical provider, an impact assessment covering services, applications, controls and customers is completed within 24 hours, credentials are rotated where relevant, and regulatory notification is made when required.
- Observed
- Payment provider incident — incomplete credential rotation.
- Confidence
- High
- Evidence
- RBI-REQ-030RBI-REQ-031