Skip to main content
CERT-In Empanelled — Mandatory auditor qualification for RBI and SAR-style engagements

System Audit Report (SAR) for Data Localisation and Payment Compliance

SAR is a family of regulator-mandated audits required by RBI, NPCI, CDSL, and SEBI. Security Brigade delivers CERT-In empanelled, regulator-ready System Audit Reports across data localisation, PA-PG, PPI, BBPOU, UPI TPAP, and depository participant mandates.

SAR-Ready
Audit Coverage
RBI-Aligned
Methodology
6,700+
Assessments
Since 2008
CERT-In Empanelled

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

The circular

One paragraph in 2018 moved every payment system in India

RBI/2017-18/153, issued 6 April 2018 to payment system operators and to scheduled commercial, cooperative, payment, small finance and local area banks.

The operative sentence is short: all system providers shall ensure that the entire data relating to payment systems operated by them are stored in a system only in India. What counts as that data is drawn widely: the full end-to-end transaction details and the information collected, carried or processed as part of the message or payment instruction, so it reaches further than a database of card numbers. Where a transaction has a foreign leg, the data relating to that leg may also be stored abroad. The circular then set two dates. Compliance within six months, reported to the Reserve Bank by 15 October 2018; and a System Audit Report submitted on completion of the requirement, conducted by CERT-In empanelled auditors certifying that the activity was completed, approved by the board of the system provider, and submitted to the Reserve Bank not later than 31 December 2018. Two things in that paragraph decide how an engagement is scoped even now. The audit certifies completion against a storage requirement; it does not score a control set. The report goes to your board before it goes to the regulator, which makes board-readable evidence part of the deliverable instead of an afterthought.

What the report covers

RBI named the four areas in its own FAQ

The FAQ of 26 June 2019 states that the SAR, from a CERT-In empanelled auditor, should inter alia include these. "Inter alia" is doing work: it is a floor, not a scope.

Data Storage

Where the data physically sits, and whether anything in the end-to-end path writes a copy somewhere the storage requirement does not permit. In practice this is the area where architecture diagrams and reality diverge: logs, queues, analytics pipelines and disaster-recovery targets are all storage.

Maintenance of Database

How the database is administered and by whom, including the access paths of anyone operating it from outside the jurisdiction the data has to stay in.

Data Backup Restoration

Not just that backups exist and are held in the right place, but that a restore has been exercised. A backup that has never been restored is an assumption, not a control.

Data Security

The protection applied to the data while it is stored and while it moves, the part that overlaps most with a conventional assessment, and the part an audit scoped only to storage location misses.

Which audit you owe

SAR is a category, not a document, and the instrument decides

"System Audit Report" names several different obligations under different instruments. Reading one instrument’s cadence onto another is the most common error we see in a scoping call.

SAR is a category, not a document, and the instrument decides
StateWhat it meansWhat follows
Data localisation SAR RBI/2017-18/153 of 6 April 2018. The SAR is submitted on completion of the storage requirement, conducted by CERT-In empanelled auditors, approved by your board, and submitted to the Reserve Bank. The circular set 31 December 2018 as the outside date for that first report. The storage obligation itself is continuous. Material change to where or how payment data is stored is what brings the question back, and not a date in the calendar.
PA-PG system audit The Payment Aggregator and Payment Gateway Master Direction, which the 31 July 2026 consolidation of 628 circulars left untouched and which is administered separately. An annual system audit including a cybersecurity audit, and the instrument names the auditor: CERT-In empanelled. If you hold a PA authorisation, this is the one with a yearly clock.
Your other authorisations Entities frequently hold more than one licence, and each instrument sets its own audit, its own scope and its own filing route. Which audits recur for you follows from which authorisations you hold. Settle it in scoping; discovering it at filing is expensive.
Key
  • This page’s subject
  • Annual, by its own instrument
  • Depends on your licences

The engagement

Board first, regulator second

The circular puts your board between the audit and the Reserve Bank, which changes what the report has to be able to do.

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade's SAR methodology goes beyond checklist completion. Every engagement validates real systems — applications, APIs, infrastructure, databases, backups, cloud regions, logs, payment data flows, and third-party processors — and maps evidence to the specific regulatory requirements applicable to your licence and business model. The methodology is consistent across all SAR variants, with the regulatory lens adjusted based on RBI, NPCI, CDSL, or SEBI requirements.

Discovery
01

Regulatory Scoping and Applicability Mapping

Identify the applicable SAR variant based on license type, regulator, product, payment system, business flow, and entity role. Define audit scope covering all in-scope systems, applications, and data flows.

02

System and Asset Inventory

Document all applications, APIs, infrastructure, cloud and on-prem systems, databases, third-party systems, logs, backups, and admin interfaces within the audit boundary.

03

Architecture and Data-Flow Review

Review application, network, infrastructure, database, security, and integration architecture. Map data collection, processing, storage, transmission, logging, backup, archive, and deletion flows.

Testing
04

Data Localisation and Residency Validation

Verify payment data storage exclusively in India across production, replicas, logs, backups, DR, analytics, support tools, and third-party processors. Validate deletion from foreign systems where data is processed abroad.

05

Security Controls Assessment and Technical Testing

Assess access controls, MFA, encryption, key management, network security, vulnerability management, logging, monitoring, incident response, change management, and backup/DR. Perform application and API security testing where required.

Delivery
06

Evidence Review and Gap Assessment

Review configurations, cloud region proof, database settings, backup jobs, access logs, policies, audit trails, VA/PT reports, contracts, and management confirmations. Produce risk-ranked gap assessment with remediation guidance.

07

Remediation Support and Closure Validation

Track remediation through Lemon platform with owner assignments, evidence expectations, and revalidation. Verify each finding closure before final report generation.

08

Final SAR Delivery and Regulator Submission

Deliver the regulator-ready System Audit Report, variant-specific checklist, data-flow annexure, executive summary, and final closure report with no open findings for submission.

"I've bought penetration tests from five firms over the last decade. The difference with Security Brigade is that quality isn't dependent on who walks through the door. Their platform enforces the methodology, their senior reviewers catch what juniors miss, and the final report is something you can hand to an enterprise customer's security team without embarrassment. That's rare."
CTO, Enterprise SaaS Company
Chief Technology Officer

Read more client stories →

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

FAQ

What payment system operators ask

Answered from RBI/2017-18/153 and the Reserve Bank’s own FAQ of 26 June 2019.

Contact us
Which circular is this, exactly?+
RBI/2017-18/153, DPSS.CO.OD No.2785/06.08.005/2017-2018, dated 6 April 2018, titled Storage of Payment System Data. It is addressed to all payment system providers and to scheduled commercial, cooperative, payment, small finance and local area banks. The Reserve Bank issued a clarifying FAQ on 26 June 2019.
Is the data-localisation SAR annual?+
The 2018 circular requires the System Audit Report on completion of the storage requirement, conducted by CERT-In empanelled auditors, certifying completion, approved by the board and submitted to the Reserve Bank, with 31 December 2018 set as the outside date for that report. The storage obligation itself is continuous. Separately, if you hold a payment aggregator or gateway authorisation, the PA-PG Master Direction sets an annual system audit including a cybersecurity audit under its own terms. Which audits recur for you therefore follows from which authorisations you hold, and that belongs in scoping, well before filing.
What counts as payment system data?+
The circular describes the full end-to-end transaction details and the information collected, carried or processed as part of the message or payment instruction. That is wider than the payment instrument itself and routinely reaches logs, message queues, analytics stores and disaster-recovery copies, which is where scoping conversations usually turn out to be about architecture and not about policy.
We process transactions with a foreign leg. What happens to that data?+
The circular provides that in the case of a transaction with a foreign component, the data relating to the foreign leg may also be stored abroad. The word is "also": the domestic storage requirement continues to apply to the transaction, and mapping which records belong to which leg is a scoping exercise best done before the audit.
Does the auditor have to be CERT-In empanelled?+
The circular states that the audit should be conducted by CERT-In empanelled auditors, and the 2019 FAQ repeats that the SAR is from a CERT-In empanelled auditor. Security Brigade has been empanelled continuously since 2008.
What does the report have to contain?+
RBI’s FAQ says the SAR should inter alia include Data Storage, Maintenance of Database, Data Backup Restoration and Data Security. "Inter alia" sets a floor, not a boundary, so a report confined to exactly those four headings and nothing else answers the FAQ instead of the question your board is being asked to approve.
Who approves it before it goes to RBI?+
Your board. The circular requires the SAR to be duly approved by the board of the system provider before submission to the Reserve Bank, which is why the report has to work for directors as well as for a supervisor: one document, two audiences, and the reason we write the executive view to be read instead of skipped.

Ready to Start Your SAR Compliance Journey?

Whether you need a data localisation SAR, PA-PG system audit, PPI audit, BBPOU compliance, UPI TPAP audit, or CDSL system audit, Security Brigade's CERT-In empanelled team delivers regulator-ready reports backed by real technical validation.

Typically responds within 1 business day · No commitment required

Request a Scoping Call