NPCI and UPI Security and Compliance Audit
End-to-end compliance audit for PSPs, TPAPs, sponsor banks, BBPS/BBPOU, and RuPay participants. CERT-In empanelled auditors delivering regulator-ready reports with no open findings, against the annual cadence NPCI circular OC-215 sets.
Trusted by India's leading enterprises
Which role are you
The ecosystem has five positions and they carry different exposure
Most scoping errors here are role errors. What you are in the transaction decides what an assessment has to reach.
| State | What it means | What follows |
|---|---|---|
| PSP bank | Holds the UPI handle relationship and the mapper entries, runs the PSP application, and carries the customer-authentication path. | The heaviest scope. Authentication, device binding, mapper integrity and the switch interface all sit here, and so does the largest share of fraud exposure. |
| TPAP | The consumer-facing application operating through a sponsor PSP bank, holding the user experience and often the device. | Exposure concentrates in the mobile application, device binding, session handling and the SDK surface, and in the boundary with the sponsor bank, where ownership is least clear. |
| Sponsor and acquiring bank | Provides the regulated rails a TPAP or merchant operates on, and carries settlement and reconciliation. | The assessment has to cover what you are accountable for in someone else’s application, which is a contractual question before it is a technical one. |
| BBPS participant or BBPOU | Operates in the bill-payment ecosystem with its own onboarding, agent and settlement flows. | Agent onboarding and the biller integration path are the areas least often tested, and the ones where business-logic flaws survive longest. |
| RuPay participant | Card issuance, acceptance or processing on the RuPay network. | Overlaps materially with the card-data obligations under PCI DSS, so scoping the two together avoids testing the same estate twice. |
- Heaviest scope
- Boundary risk with a counterparty
- Scope it with adjacent work
The cadence
An annual audit by a CERT-In empanelled auditor
NPCI circular OC-215 of 26 April 2025 requires PSP banks and acquiring banks to audit their systems by a CERT-In empanelled auditor on an immediate basis, and annually hereafter. The credential is the part worth understanding properly, because it is the part that is checked: empanelment attaches to the auditing firm and not to a report, a person or a project, it runs for a defined period, and CERT-In publishes who holds it. So the question behind the requirement is a question about dates: whether the firm was on the published list across the days the work was performed, not on the day the engagement was signed or the day the report was issued. Security Brigade has held CERT-In empanelment continuously since 2008, among the earliest cohorts empanelled in India. The annual cadence has a second consequence that is easy to miss when the first audit is being commissioned: an assessment designed as a one-off produces a report, while an assessment designed for a cycle produces an evidence base that next year starts from. The difference shows up in year two as a materially smaller engagement, and it is entirely a function of whether findings were tracked to verified closure with retest evidence attached, or closed in a spreadsheet.
What we test
The payment path, and the three places it is usually not tested
Applications and the mobile surface
The consumer application, device binding, session handling, local storage and the SDK surface. Mobile is where UPI risk is most concentrated and where automated testing reaches least far.
IntegrationAPIs and the switch interface
Authorisation logic across every API in the transaction path, including partner and internal interfaces. Entitlement flaws here are the findings that matter and the ones a scanner will not produce.
UnderneathNetwork and infrastructure
Segmentation around the payment estate, management interfaces, key handling and the hosts the transaction path depends on.
Onboarding and settlement logic
Merchant and agent onboarding, limits, refunds, disputes and reconciliation. These are business flows, not endpoints, so an assessment scoped to components steps around them entirely.
The counterparty boundary
Where your obligation ends and a sponsor bank’s or TPAP’s begins. We scope this explicitly instead of assuming it belongs to the other side, because both parties commonly assume the same thing.
Where the data actually sits
Payment data residency across production, backups, disaster recovery, logs, analytics and third-party processors. Worth establishing during scoping; the storage obligations that may apply to your entity are a separate instrument and a separate conversation.
What you receive
A report that closes, not a report that lists
| Output | What it contains | Who reads it |
|---|---|---|
| Submission-ready audit report | The assessment written for the submission it is going into, with scope, method, findings, closure status and retest evidence. | The recipient of the submission |
| Technical findings | Each finding with reproduction steps, proof, severity and the specific fix, written so an engineer can act without a follow-up call. | Engineering |
| Executive view | The risk picture, what changed since the last cycle, and what remains open with an owner and a date against it. | Board and leadership |
| Closure trail in Lemon | Every finding tracked to verified closure with the retest attached, which is what makes next year’s cycle smaller instead of identical. | You, continuously |
Submission-ready audit report
- What it contains
- The assessment written for the submission it is going into, with scope, method, findings, closure status and retest evidence.
- Who reads it
- The recipient of the submission
Technical findings
- What it contains
- Each finding with reproduction steps, proof, severity and the specific fix, written so an engineer can act without a follow-up call.
- Who reads it
- Engineering
Executive view
- What it contains
- The risk picture, what changed since the last cycle, and what remains open with an owner and a date against it.
- Who reads it
- Board and leadership
Closure trail in Lemon
- What it contains
- Every finding tracked to verified closure with the retest attached, which is what makes next year’s cycle smaller instead of identical.
- Who reads it
- You, continuously
Methodology
How a compliance engagement runs
Every engagement follows this process through Lemon, our proprietary audit management platform.
Security Brigade delivers NPCI/UPI audits as a cybersecurity-first engagement, not a checklist exercise. We validate real systems, test actual applications and APIs, verify data localisation at the infrastructure level, and work with your engineering teams to close findings before final submission.
Scoping and Role Mapping
Define your NPCI ecosystem role (PSP, TPAP, sponsor bank, BBPOU, RuPay). Map applicable UPI features (AutoPay, Credit on UPI, International UPI, merchant QR). Identify all in-scope applications, APIs, infrastructure, databases, cloud regions, and third-party integrations.
Architecture and Data Flow Review
Review application architecture, UPI integration design, PSP-bank connectivity, device binding mechanisms, and VPA/account linking flows. Map complete UPI transaction data flows from frontend through backend, APIs, databases, logs, backups, and third-party processors. Validate India-only data storage at every layer.
Security Testing and Technical Validation
Application and API security testing using B-52. Mobile app testing for UPI apps including SDK integration, device binding, session controls, and authentication. Backend and infrastructure assessment. Network segmentation verification. Encryption validation in transit and at rest. Cloud configuration review for data localisation evidence.
NPCI Control Mapping and Gap Assessment
Map every finding and observation against the NPCI/UPI checklist and role-specific requirements. Produce a gap assessment with risk-ranked findings, evidence gaps, and recommended remediation. Cover fraud monitoring, reconciliation, dispute handling, incident response, and SDLC controls.
Remediation Support and Closure Validation
Work directly with your CTO, DevOps, security engineering, and compliance teams to close findings. Lemon tracks every finding with owner, severity, target closure date, and validation evidence. Revalidation testing confirms each fix is effective. No finding is marked closed without evidence.
Final Compliance Report Submission
Issue the final NPCI/UPI Security Audit Report with no open findings. Includes role-specific checklist mapping, technical annexures, data localisation evidence, executive summary for CISO and compliance leadership, and the closure validation pack. Report is structured for direct submission to NPCI.
"We ship 50 deploys a week. Traditional pentesting firms take three weeks to deliver a report that's already stale. Security Brigade's B-52 engine generates structured test plans and validates coverage in days, not weeks. Their AI doesn't replace testers — it makes sure nothing gets missed. We've caught business logic flaws in our payment orchestration that SAST and DAST both labelled 'low priority.'"
Continuous Compliance with ShadowMap
The audit gives you a snapshot. ShadowMap gives you the always-on view.
An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.
Threat Intelligence
1,000+ threat actor profiles, CVE tracking against your stack, IOC monitoring, and geographic threat analysis.
Know which threats are coming for you specifically.
Explore on ShadowMapDark Web Monitoring
12B+ breach records indexed; monitors Telegram, paste sites, criminal forums, and ransomware leak sites for credentials, leaked data, and threat actor mentions.
Find leaked data before regulators do.
Explore on ShadowMapFAQ
NPCI and UPI audits, answered
Role, scope and cadence. Talk to our team about where you sit in the ecosystem.
Contact usWho needs this audit and how often?
Does the auditor have to be CERT-In empanelled?
What should be in scope for a PSP bank?
We operate as a TPAP. What changes?
Can this be run alongside our other compliance testing?
Start Your NPCI/UPI Compliance Audit Today
The NPCI audit obligation recurs every year. CERT-In empanelled auditors, platform-backed execution, and a no-open-findings commitment.
Typically responds within 1 business day · No commitment required