System Audit Report (SAR) for Data Localisation and Payment Compliance
SAR is a family of regulator-mandated audits required by RBI, NPCI, CDSL, and SEBI. Security Brigade delivers CERT-In empanelled, regulator-ready System Audit Reports across data localisation, PA-PG, PPI, BBPOU, UPI TPAP, and depository participant mandates.
Trusted by India's leading enterprises
The circular
One paragraph in 2018 moved every payment system in India
RBI/2017-18/153, issued 6 April 2018 to payment system operators and to scheduled commercial, cooperative, payment, small finance and local area banks.
The operative sentence is short: all system providers shall ensure that the entire data relating to payment systems operated by them are stored in a system only in India. What counts as that data is drawn widely: the full end-to-end transaction details and the information collected, carried or processed as part of the message or payment instruction, so it reaches further than a database of card numbers. Where a transaction has a foreign leg, the data relating to that leg may also be stored abroad. The circular then set two dates. Compliance within six months, reported to the Reserve Bank by 15 October 2018; and a System Audit Report submitted on completion of the requirement, conducted by CERT-In empanelled auditors certifying that the activity was completed, approved by the board of the system provider, and submitted to the Reserve Bank not later than 31 December 2018. Two things in that paragraph decide how an engagement is scoped even now. The audit certifies completion against a storage requirement; it does not score a control set. The report goes to your board before it goes to the regulator, which makes board-readable evidence part of the deliverable instead of an afterthought.
What the report covers
RBI named the four areas in its own FAQ
The FAQ of 26 June 2019 states that the SAR, from a CERT-In empanelled auditor, should inter alia include these. "Inter alia" is doing work: it is a floor, not a scope.
Data Storage
Where the data physically sits, and whether anything in the end-to-end path writes a copy somewhere the storage requirement does not permit. In practice this is the area where architecture diagrams and reality diverge: logs, queues, analytics pipelines and disaster-recovery targets are all storage.
Maintenance of Database
How the database is administered and by whom, including the access paths of anyone operating it from outside the jurisdiction the data has to stay in.
Data Backup Restoration
Not just that backups exist and are held in the right place, but that a restore has been exercised. A backup that has never been restored is an assumption, not a control.
Data Security
The protection applied to the data while it is stored and while it moves, the part that overlaps most with a conventional assessment, and the part an audit scoped only to storage location misses.
Which audit you owe
SAR is a category, not a document, and the instrument decides
"System Audit Report" names several different obligations under different instruments. Reading one instrument’s cadence onto another is the most common error we see in a scoping call.
| State | What it means | What follows |
|---|---|---|
| Data localisation SAR | RBI/2017-18/153 of 6 April 2018. The SAR is submitted on completion of the storage requirement, conducted by CERT-In empanelled auditors, approved by your board, and submitted to the Reserve Bank. The circular set 31 December 2018 as the outside date for that first report. | The storage obligation itself is continuous. Material change to where or how payment data is stored is what brings the question back, and not a date in the calendar. |
| PA-PG system audit | The Payment Aggregator and Payment Gateway Master Direction, which the 31 July 2026 consolidation of 628 circulars left untouched and which is administered separately. | An annual system audit including a cybersecurity audit, and the instrument names the auditor: CERT-In empanelled. If you hold a PA authorisation, this is the one with a yearly clock. |
| Your other authorisations | Entities frequently hold more than one licence, and each instrument sets its own audit, its own scope and its own filing route. | Which audits recur for you follows from which authorisations you hold. Settle it in scoping; discovering it at filing is expensive. |
- This page’s subject
- Annual, by its own instrument
- Depends on your licences
The engagement
Board first, regulator second
The circular puts your board between the audit and the Reserve Bank, which changes what the report has to be able to do.
-
Establish where the data actually goes
Traced, not diagrammed. The end-to-end path as the circular describes it: collected, carried, processed, including the places a copy is written that no architecture document mentions.
-
Audit against the four named areas, and wider
Storage, database maintenance, backup restoration and data security as the floor RBI named, with the surrounding infrastructure and application testing that makes the storage conclusion defensible.
-
Report your board can approve
The circular requires board approval before submission, so the report has to be legible to directors and evidenced enough for the regulator behind them. Those are two audiences and one document.
-
Submission, and what changes next
The report goes to the Reserve Bank. After that, the thing to watch is material change: a new processor, a new region, a new analytics pipeline. The storage obligation is continuous even where the certification was a point in time.
Methodology
How a compliance engagement runs
Every engagement follows this process through Lemon, our proprietary audit management platform.
Security Brigade's SAR methodology goes beyond checklist completion. Every engagement validates real systems — applications, APIs, infrastructure, databases, backups, cloud regions, logs, payment data flows, and third-party processors — and maps evidence to the specific regulatory requirements applicable to your licence and business model. The methodology is consistent across all SAR variants, with the regulatory lens adjusted based on RBI, NPCI, CDSL, or SEBI requirements.
Regulatory Scoping and Applicability Mapping
Identify the applicable SAR variant based on license type, regulator, product, payment system, business flow, and entity role. Define audit scope covering all in-scope systems, applications, and data flows.
System and Asset Inventory
Document all applications, APIs, infrastructure, cloud and on-prem systems, databases, third-party systems, logs, backups, and admin interfaces within the audit boundary.
Architecture and Data-Flow Review
Review application, network, infrastructure, database, security, and integration architecture. Map data collection, processing, storage, transmission, logging, backup, archive, and deletion flows.
Data Localisation and Residency Validation
Verify payment data storage exclusively in India across production, replicas, logs, backups, DR, analytics, support tools, and third-party processors. Validate deletion from foreign systems where data is processed abroad.
Security Controls Assessment and Technical Testing
Assess access controls, MFA, encryption, key management, network security, vulnerability management, logging, monitoring, incident response, change management, and backup/DR. Perform application and API security testing where required.
Evidence Review and Gap Assessment
Review configurations, cloud region proof, database settings, backup jobs, access logs, policies, audit trails, VA/PT reports, contracts, and management confirmations. Produce risk-ranked gap assessment with remediation guidance.
Remediation Support and Closure Validation
Track remediation through Lemon platform with owner assignments, evidence expectations, and revalidation. Verify each finding closure before final report generation.
Final SAR Delivery and Regulator Submission
Deliver the regulator-ready System Audit Report, variant-specific checklist, data-flow annexure, executive summary, and final closure report with no open findings for submission.
"I've bought penetration tests from five firms over the last decade. The difference with Security Brigade is that quality isn't dependent on who walks through the door. Their platform enforces the methodology, their senior reviewers catch what juniors miss, and the final report is something you can hand to an enterprise customer's security team without embarrassment. That's rare."
Continuous Compliance with ShadowMap
The audit gives you a snapshot. ShadowMap gives you the always-on view.
An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.
FAQ
What payment system operators ask
Answered from RBI/2017-18/153 and the Reserve Bank’s own FAQ of 26 June 2019.
Contact usWhich circular is this, exactly?
Is the data-localisation SAR annual?
What counts as payment system data?
We process transactions with a foreign leg. What happens to that data?
Does the auditor have to be CERT-In empanelled?
What does the report have to contain?
Who approves it before it goes to RBI?
Ready to Start Your SAR Compliance Journey?
Whether you need a data localisation SAR, PA-PG system audit, PPI audit, BBPOU compliance, UPI TPAP audit, or CDSL system audit, Security Brigade's CERT-In empanelled team delivers regulator-ready reports backed by real technical validation.
Typically responds within 1 business day · No commitment required