Skip to main content
CERT-In Empanelled — Since 2008 — one of the earliest cybersecurity firms in India

NPCI and UPI Security and Compliance Audit

End-to-end compliance audit for PSPs, TPAPs, sponsor banks, BBPS/BBPOU, and RuPay participants. CERT-In empanelled auditors delivering regulator-ready reports with no open findings, against the annual cadence NPCI circular OC-215 sets.

NPCI
Compliance Audits
UPI · IMPS
Coverage
6,700+
Assessments
Since 2008
CERT-In Empanelled

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

Which role are you

The ecosystem has five positions and they carry different exposure

Most scoping errors here are role errors. What you are in the transaction decides what an assessment has to reach.

The ecosystem has five positions and they carry different exposure
StateWhat it meansWhat follows
PSP bank Holds the UPI handle relationship and the mapper entries, runs the PSP application, and carries the customer-authentication path. The heaviest scope. Authentication, device binding, mapper integrity and the switch interface all sit here, and so does the largest share of fraud exposure.
TPAP The consumer-facing application operating through a sponsor PSP bank, holding the user experience and often the device. Exposure concentrates in the mobile application, device binding, session handling and the SDK surface, and in the boundary with the sponsor bank, where ownership is least clear.
Sponsor and acquiring bank Provides the regulated rails a TPAP or merchant operates on, and carries settlement and reconciliation. The assessment has to cover what you are accountable for in someone else’s application, which is a contractual question before it is a technical one.
BBPS participant or BBPOU Operates in the bill-payment ecosystem with its own onboarding, agent and settlement flows. Agent onboarding and the biller integration path are the areas least often tested, and the ones where business-logic flaws survive longest.
RuPay participant Card issuance, acceptance or processing on the RuPay network. Overlaps materially with the card-data obligations under PCI DSS, so scoping the two together avoids testing the same estate twice.
Key
  • Heaviest scope
  • Boundary risk with a counterparty
  • Scope it with adjacent work

The cadence

An annual audit by a CERT-In empanelled auditor

NPCI circular OC-215 of 26 April 2025 requires PSP banks and acquiring banks to audit their systems by a CERT-In empanelled auditor on an immediate basis, and annually hereafter. The credential is the part worth understanding properly, because it is the part that is checked: empanelment attaches to the auditing firm and not to a report, a person or a project, it runs for a defined period, and CERT-In publishes who holds it. So the question behind the requirement is a question about dates: whether the firm was on the published list across the days the work was performed, not on the day the engagement was signed or the day the report was issued. Security Brigade has held CERT-In empanelment continuously since 2008, among the earliest cohorts empanelled in India. The annual cadence has a second consequence that is easy to miss when the first audit is being commissioned: an assessment designed as a one-off produces a report, while an assessment designed for a cycle produces an evidence base that next year starts from. The difference shows up in year two as a materially smaller engagement, and it is entirely a function of whether findings were tracked to verified closure with retest evidence attached, or closed in a spreadsheet.

What you receive

A report that closes, not a report that lists

OutputWhat it containsWho reads it
Submission-ready audit report The assessment written for the submission it is going into, with scope, method, findings, closure status and retest evidence. The recipient of the submission
Technical findings Each finding with reproduction steps, proof, severity and the specific fix, written so an engineer can act without a follow-up call. Engineering
Executive view The risk picture, what changed since the last cycle, and what remains open with an owner and a date against it. Board and leadership
Closure trail in Lemon Every finding tracked to verified closure with the retest attached, which is what makes next year’s cycle smaller instead of identical. You, continuously

Submission-ready audit report

What it contains
The assessment written for the submission it is going into, with scope, method, findings, closure status and retest evidence.
Who reads it
The recipient of the submission

Technical findings

What it contains
Each finding with reproduction steps, proof, severity and the specific fix, written so an engineer can act without a follow-up call.
Who reads it
Engineering

Executive view

What it contains
The risk picture, what changed since the last cycle, and what remains open with an owner and a date against it.
Who reads it
Board and leadership

Closure trail in Lemon

What it contains
Every finding tracked to verified closure with the retest attached, which is what makes next year’s cycle smaller instead of identical.
Who reads it
You, continuously

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade delivers NPCI/UPI audits as a cybersecurity-first engagement, not a checklist exercise. We validate real systems, test actual applications and APIs, verify data localisation at the infrastructure level, and work with your engineering teams to close findings before final submission.

Discovery
01

Scoping and Role Mapping

Define your NPCI ecosystem role (PSP, TPAP, sponsor bank, BBPOU, RuPay). Map applicable UPI features (AutoPay, Credit on UPI, International UPI, merchant QR). Identify all in-scope applications, APIs, infrastructure, databases, cloud regions, and third-party integrations.

02

Architecture and Data Flow Review

Review application architecture, UPI integration design, PSP-bank connectivity, device binding mechanisms, and VPA/account linking flows. Map complete UPI transaction data flows from frontend through backend, APIs, databases, logs, backups, and third-party processors. Validate India-only data storage at every layer.

Testing
03

Security Testing and Technical Validation

Application and API security testing using B-52. Mobile app testing for UPI apps including SDK integration, device binding, session controls, and authentication. Backend and infrastructure assessment. Network segmentation verification. Encryption validation in transit and at rest. Cloud configuration review for data localisation evidence.

04

NPCI Control Mapping and Gap Assessment

Map every finding and observation against the NPCI/UPI checklist and role-specific requirements. Produce a gap assessment with risk-ranked findings, evidence gaps, and recommended remediation. Cover fraud monitoring, reconciliation, dispute handling, incident response, and SDLC controls.

Delivery
05

Remediation Support and Closure Validation

Work directly with your CTO, DevOps, security engineering, and compliance teams to close findings. Lemon tracks every finding with owner, severity, target closure date, and validation evidence. Revalidation testing confirms each fix is effective. No finding is marked closed without evidence.

06

Final Compliance Report Submission

Issue the final NPCI/UPI Security Audit Report with no open findings. Includes role-specific checklist mapping, technical annexures, data localisation evidence, executive summary for CISO and compliance leadership, and the closure validation pack. Report is structured for direct submission to NPCI.

"We ship 50 deploys a week. Traditional pentesting firms take three weeks to deliver a report that's already stale. Security Brigade's B-52 engine generates structured test plans and validates coverage in days, not weeks. Their AI doesn't replace testers — it makes sure nothing gets missed. We've caught business logic flaws in our payment orchestration that SAST and DAST both labelled 'low priority.'"
Head of Platform Engineering, Fintech Unicorn
Head of Platform Engineering

Read more client stories →

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

FAQ

NPCI and UPI audits, answered

Role, scope and cadence. Talk to our team about where you sit in the ecosystem.

Contact us
Who needs this audit and how often?+
NPCI circular OC-215 of 26 April 2025 requires PSP banks and acquiring banks to audit their systems by a CERT-In empanelled auditor on an immediate basis, and annually hereafter. In practice the engagements we run also cover TPAPs, sponsor banks, BBPS participants and BBPOUs, and RuPay participants, because the counterparty boundary is where scope is most often left uncovered by both sides.
Does the auditor have to be CERT-In empanelled?+
Yes. Empanelment attaches to the auditing firm and not to a report or an individual, runs for a defined period, and CERT-In publishes who holds it, so what is actually verified is whether the firm was on that list across the days the work was performed. Security Brigade has held CERT-In empanelment continuously since 2008.
What should be in scope for a PSP bank?+
The PSP application and the customer-authentication path, device binding, the mapper relationship, the switch interface, and the APIs across the whole transaction path. Beyond the payment path itself, the areas most often left out are merchant and agent onboarding, limits, refunds, disputes and reconciliation. Those are business flows, not components, which an assessment scoped by system will step around.
We operate as a TPAP. What changes?+
The centre of gravity moves to the mobile application, device binding, session handling and the SDK surface, and to the boundary with your sponsor PSP bank. That boundary is the part worth settling explicitly at scoping: in our experience both parties frequently assume a given control belongs to the other, and the assumption is only tested when something goes wrong.
Can this be run alongside our other compliance testing?+
Usually, and it is worth doing. RuPay participation overlaps materially with card-data obligations under PCI DSS, and banks in this ecosystem carry cybersecurity obligations under the RBI Directions that the same testing evidence supports. Running them as one programme means the estate is tested once and reported several ways, instead of tested several times.

Start Your NPCI/UPI Compliance Audit Today

The NPCI audit obligation recurs every year. CERT-In empanelled auditors, platform-backed execution, and a no-open-findings commitment.

Typically responds within 1 business day · No commitment required

Request a Scoping Call