Vendor · tp-paygate
PayGate Payments Pvt. Ltd.
Controls (4)
| Control | Name | Domain | Applications | Q3 test | Open findings |
|---|---|---|---|---|---|
| VEN-01 | Critical third parties are risk-assessed before onboarding and annually | Third-Party Risk | PayGate Payment Gateway, Salesforce (Sales + Financial Services Cloud) | Fail | 1 |
| VEN-03 | Supplier security incidents are assessed for impact and tracked | Third-Party Risk | PayGate Payment Gateway, Meridian Customer Portal | Fail | 1 |
| PAY-01 | Payment APIs secured with mTLS, signing and customer 2FA | Payments Security | PayGate Payment Gateway, Meridian Customer Portal | Pass | 0 |
| PAY-02 | Payment release requires maker-checker | Payments Security | SAP S/4HANA | Pass | 0 |
Open findings (2)
| Finding | Observation | Control | Applications | Severity | Status | Owner | Action | Validation |
|---|---|---|---|---|---|---|---|---|
| F-RBI-03 | Payment provider incident — incomplete credential rotation | VEN-03 | PayGate Payment Gateway, Meridian Customer Portal | High | In Progress | Deepa Menon | REM-F-RBI-03 · In Progress | Pending |
| F-RBI-02 | Material outsourcing: lapsed assurance and overdue reassessment (Outsourcing of IT Services 2023 §6/§9) | VEN-01 | PayGate Payment Gateway, Salesforce (Sales + Financial Services Cloud) | Medium | Open | Sanjay Kulkarni | REM-F-RBI-02 · Open | Pending |