Skip to main content
CERT-In Empanelled — Mandatory auditor credential for RBI PA-PG system audits

RBI Payment Aggregator and Payment Gateway (PA-PG) Audit

Annual system audit including cybersecurity audit by CERT-In empanelled auditors, mandated under the RBI 2025 PA Master Direction. Security Brigade delivers regulator-ready PA-PG compliance with technical depth that goes beyond checkbox audits.

PA + PG
Audit Coverage
RBI-Aligned
Methodology
6,700+
Assessments
Since 2008
CERT-In Empanelled

Payment Aggregators operating under RBI authorisation must undergo annual system audits conducted by CERT-In empanelled auditors. Security Brigade combines deep payment ecosystem expertise with cybersecurity-first audit methodology to deliver PA-PG compliance that satisfies regulators and strengthens your security posture. Trusted by leading payment aggregators, fintechs, and banks across India.

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

What is in force

One Master Direction replaced three circulars, and the framing changed with them

The Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025 took effect on issue. If your compliance programme is built on the 2020 guidelines, it is built on a repealed text.

WhatAs the Directions state itReference
Who they apply to All bank and non-bank entities undertaking the business of Payment Aggregator as defined in the Directions, and additionally all Authorised Dealer banks and Scheduled Commercial Banks which engage with entities undertaking PA business, to the extent specified. Payment Gateway is defined in the Directions as an entity providing the technology infrastructure to route and facilitate processing of a payment transaction. Para 3(a)
What they replaced The Guidelines on Regulation of Payment Aggregators and Payment Gateways of 17 March 2020 and 31 March 2021, and the PA – Cross Border directions of 31 October 2023, are repealed with the issuance of this Master Direction, subject to savings for applications already pending. Chapter VI
The audit "An annual system audit, including cyber security audit, conducted by CERT-In empanelled auditors shall be carried out and report thereof shall be submitted to the respective Regional Office of DPSS, RBI within such timelines as may be prescribed by RBI." The auditor credential is named in the instrument itself, and the report has a stated destination. Quoted from the Directions
Net worth A minimum net worth of ₹15 crore at the time of tendering the application for authorisation, rising to ₹25 crore by the end of the third financial year, and maintained on an ongoing basis thereafter. Computation follows the RBI circular of 16 January 2015 on computation of net worth, with compulsorily convertible preference shares included. Chapter II
Data storage A PA shall comply with the data storage requirements applicable to Payment System Operators as laid out in the RBI circular of 6 April 2018, the storage-of-payment-system-data circular. The obligation is inherited by reference and never restated, which is why PA programmes routinely miss it. Storage of Payment System Data
Form of entity A non-bank PA shall be a company incorporated in India under the Companies Act, 2013, and its Memorandum of Association should cover the proposed activity of operating as a Payment Aggregator. Merchant funds sit in a separate escrow account with a Scheduled Commercial Bank in India. Chapters II and V

Who they apply to

As the Directions state it
All bank and non-bank entities undertaking the business of Payment Aggregator as defined in the Directions, and additionally all Authorised Dealer banks and Scheduled Commercial Banks which engage with entities undertaking PA business, to the extent specified. Payment Gateway is defined in the Directions as an entity providing the technology infrastructure to route and facilitate processing of a payment transaction.
Reference
Para 3(a)

What they replaced

As the Directions state it
The Guidelines on Regulation of Payment Aggregators and Payment Gateways of 17 March 2020 and 31 March 2021, and the PA – Cross Border directions of 31 October 2023, are repealed with the issuance of this Master Direction, subject to savings for applications already pending.
Reference
Chapter VI

The audit

As the Directions state it
"An annual system audit, including cyber security audit, conducted by CERT-In empanelled auditors shall be carried out and report thereof shall be submitted to the respective Regional Office of DPSS, RBI within such timelines as may be prescribed by RBI." The auditor credential is named in the instrument itself, and the report has a stated destination.

Net worth

As the Directions state it
A minimum net worth of ₹15 crore at the time of tendering the application for authorisation, rising to ₹25 crore by the end of the third financial year, and maintained on an ongoing basis thereafter. Computation follows the RBI circular of 16 January 2015 on computation of net worth, with compulsorily convertible preference shares included.
Reference
Chapter II

Data storage

As the Directions state it
A PA shall comply with the data storage requirements applicable to Payment System Operators as laid out in the RBI circular of 6 April 2018, the storage-of-payment-system-data circular. The obligation is inherited by reference and never restated, which is why PA programmes routinely miss it.

Form of entity

As the Directions state it
A non-bank PA shall be a company incorporated in India under the Companies Act, 2013, and its Memorandum of Association should cover the proposed activity of operating as a Payment Aggregator. Merchant funds sit in a separate escrow account with a Scheduled Commercial Bank in India.
Reference
Chapters II and V

Where these audits fail

Four states an audit finds, and only one of them is comfortable

Across payment-aggregator engagements the same four positions recur. The difference between them is almost never the security controls.

Four states an audit finds, and only one of them is comfortable
StateWhat it meansWhat follows
Evidenced, and mapped to the text Controls run, they produce records, and each record is mapped to the provision it answers, so the audit is a reading exercise, not a discovery one. The cheap case. It is cheap because the mapping was done once, when the programme was built, instead of reconstructed annually under time pressure.
Controls without records Access reviews happen, reconciliation happens, vendors are assessed, and none of it leaves an artefact with a date and a name on it. The most common finding by a distance. A system audit reports what it can evidence, so an unevidenced control is indistinguishable from an absent one at the moment it matters.
Scoped to the payment path only The assessment covers the transaction flow and stops there, leaving merchant onboarding, settlement reconciliation, refunds, disputes and the vendor estate outside. An audit that passes and a business that is exposed. Merchant onboarding controls and settlement handling are where aggregator risk concentrates, and they are not on the transaction path.
Data storage assumed Production is in India and nobody has checked the backups, the disaster-recovery copy, the logs, the analytics pipeline or the third-party processors. The obligation arrives by reference from the 2018 circular and not as its own chapter here, so it is read as background. It is the one we most often find unverified.
Key
  • Audit is a reading exercise
  • Fixable, but it costs the audit window
  • Passes the audit, carries the risk

The inherited obligation

Payment data storage is not in this Master Direction, and it still binds you

One clause of the Directions does a great deal of work in a single sentence: a Payment Aggregator shall comply with the data storage requirements applicable to Payment System Operators, as laid out in the Reserve Bank’s circular of 6 April 2018 on storage of payment system data. Nothing else in the chapter elaborates it, and that is exactly why it gets missed. A compliance team reading the Master Direction end to end finds chapters on authorisation, capital, escrow, merchant onboarding and security, and one cross-reference that looks like a footnote. It is not a footnote. It brings the whole of the 2018 storage regime onto the aggregator, including the annual System Audit Report the storage circular requires from a CERT-In empanelled auditor, board-approved before it reaches the Reserve Bank. In practice this means two things for scoping. First, the data question is not answered by where the production database runs: it is answered by where every copy of the data lives, which means backups, the disaster-recovery site, application and transaction logs, analytics and reporting stores, and any third-party processor in the chain. Second, an aggregator that treats the system audit and the storage audit as one exercise, with one evidence base, spends materially less than one that discovers in month eleven that they are two submissions with two audiences. We scope them together for that reason.

How the engagement runs

Four stages, ending at the Regional Office

The Directions name the destination, the respective Regional Office of DPSS, so the report is written for that submission from the start, not adapted for it afterwards.

01 Week one

Scope

What happens
Establish which entity is being audited and against which provisions (PA, PA – Cross Border, or a bank engaging with PA entities), then map the payment estate: merchant integration, transaction processing, escrow and settlement, refunds and disputes, and the vendor chain behind each.
The decision that matters
Whether the data storage obligation is scoped in. It almost always should be, and folding it in here is the difference between one evidence base and two.
02 Weeks two to four

Test

What happens
Application, API, network and infrastructure testing across the systems in scope, performed by a CERT-In empanelled team because the Directions name that credential for this audit. Merchant onboarding and settlement logic are tested as business flows, not only as endpoints.
03 Weeks four to six

Evidence and closure

What happens
Findings tracked to verified closure in Lemon, with retest evidence attached to each. Control records are mapped to the provision each one answers, so the mapping survives into next year instead of being rebuilt.
Why closure matters here
A system audit report reaching a supervisor with open findings and no closure trail invites the follow-up question. Closing first is cheaper than answering it.
04 Week six

Submission

What happens
A report written for the Regional Office of DPSS that the Directions name, with the executive view readable by a board and the technical detail complete enough for an engineer to act on. One document, two audiences.

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade's PA-PG audit methodology is built on our universal SAR (System Audit Report) framework, enhanced with payment-specific controls from the RBI 2025 PA Master Direction. Every phase is tracked through our Lemon audit management platform ensuring complete evidence traceability, structured remediation, and a clean audit trail for regulatory submission.

Discovery
01

Scoping and Regulatory Mapping

We begin by mapping your PA or PG operations against every requirement in the RBI PA Master Direction. This includes identifying systems in scope such as applications, APIs, infrastructure, databases, cloud environments, third-party integrations, payment flows, and data stores. Scope is documented and agreed before fieldwork begins.

02

Architecture and Data-Flow Review

We document your complete payment data flow from merchant integration through transaction processing, escrow management, settlement, refund, and dispute handling. This includes data localisation verification ensuring payment data resides exclusively in India across production, backups, DR, logs, analytics, and third-party processors.

Testing
03

Control Assessment and Evidence Review

We validate each control area against the PA Master Direction requirements: merchant onboarding KYC, escrow controls, settlement flows, card and payment data handling, PCI-DSS/PA-DSS relevance, baseline technology controls, access management, encryption, key management, change management, backup, DR, and vendor controls. Evidence is collected and mapped in Lemon.

04

Cybersecurity Audit and VAPT

The dedicated cybersecurity audit component covers vulnerability assessment, penetration testing of payment applications and APIs, security configuration review, network segmentation validation, incident response readiness, and alignment with the RBI cyber security framework. Testing is executed through our B-52 audit engine for consistent coverage.

Delivery
05

Gap Assessment and Remediation Support

Every non-compliance and control gap is documented with risk rating, evidence expectation, and practical remediation guidance. We work with your CTO, engineering, security, and compliance teams to close gaps. Lemon tracks each item through to closure with validation evidence.

06

Report Delivery and Regulatory Submission

We deliver the final PA-PG System Audit Report including the cybersecurity audit report, control matrix, data-flow annexures, technical findings, and board-ready executive summary. The report is structured for RBI submission and includes the closure validation pack confirming all identified gaps have been addressed.

"We needed an assessment on a 3-week timeline because of a partner integration deadline. Security Brigade turned it around in 18 days, including the L2 and L3 reviews. The report was regulator-ready — we submitted it to our partner's compliance team unchanged. When speed and credibility both matter, they're the only call we make."
VP Engineering, Retail & Quick Commerce
Vice President — Engineering

Read more client stories →

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

FAQ

PA audits, answered against the 2025 Directions

The questions that decide scope and timing. Talk to our team about your payment estate.

Contact us
Which instrument governs the audit now?+
The Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025, issued on 15 September 2025 under the Payment and Settlement Systems Act, 2007 and FEMA, 1999, and effective immediately unless a specific provision says otherwise. It replaced the Guidelines on Regulation of Payment Aggregators and Payment Gateways of March 2020 and March 2021 and the PA – Cross Border directions of October 2023, all of which are repealed by its Repeal and Savings chapter.
Who do the 2025 Directions apply to?+
Para 3(a) states it directly: all bank and non-bank entities undertaking the business of Payment Aggregator as defined in the Directions, and also all Authorised Dealer banks and Scheduled Commercial Banks which engage with entities undertaking PA business, to the extent specified. Payment Gateway is defined in the Directions as an entity providing technology infrastructure to route and facilitate processing of a payment transaction. If you are unsure which description fits your operation, that is the first hour of a scoping call and it decides everything downstream.
Does the auditor have to be CERT-In empanelled?+
Yes, and the Directions say so in terms: the annual system audit including cyber security audit is to be conducted by CERT-In empanelled auditors, with the report submitted to the respective Regional Office of DPSS. Security Brigade has held CERT-In empanelment continuously since 2008. The question a supervisor actually asks is about dates: whether the firm held empanelment on the days the work was performed.
What are the net worth requirements?+
A minimum net worth of ₹15 crore at the time of tendering the application for authorisation, rising to ₹25 crore by the end of the third financial year and maintained on an ongoing basis thereafter. Computation follows the Reserve Bank’s circular of 16 January 2015 on computation of net worth, and compulsorily convertible preference shares are included. A statutory auditor’s certificate evidencing compliance accompanies the application.
Do we also have to deal with payment data storage?+
Yes, and it arrives by cross-reference and not as its own chapter, which is why it is the obligation we most often find unverified. The Directions require a PA to comply with the data storage requirements applicable to Payment System Operators under the Reserve Bank’s circular of 6 April 2018. That brings the storage regime and its System Audit Report onto the aggregator. Scope it with the system audit and it is one evidence base; scope it separately and it is two submissions with two timelines.
How long does the engagement take?+
Six weeks is typical from scoping to a submission-ready report for a mid-size aggregator, and the variables are the size of the merchant and vendor estate and how quickly remediation can be retested, not the framework itself. Scoping is the first week and it moves the estimate most, because whether the data storage obligation is folded in changes both the testing surface and the number of reports at the end.

Ready to Get PA-PG Compliant?

Talk to our compliance team about your annual PA-PG system audit requirements

Typically responds within 1 business day · No commitment required

Request a Scoping Call