ATM and POS
Security Audit Checklist
The obligation to control an ATM Switch service provider sits with the bank and is discharged by contract. The work sits with the provider. Two readers, opposite problems — and each half of this checklist is written for one of them.
ATM and POS Security Audit Checklist
Enter your work email for the printable worksheet — the estate inventory, the contract gate at paras 136 to 139, the evidence the service provider has to produce, and a channel-by-channel scope table.
Check your inbox
We've emailed you a link to download ATM and POS Security Audit Checklist.
The link expires in 48 hours. If it hasn't arrived in a few minutes, check your spam folder.
Something went wrong. Please try again.
Who this is for
The obligation and the work sit in different places
If you are the bank
Paragraph 136 cross-references the controls that apply, 137 requires them in the contract, and 138 enumerates the twenty-four the bank shall mandate contractually. Your exposure is a contract that does not carry them — and a provider that performs a control without being obliged to does not discharge the obligation.
The contract gate is section 4 of the worksheet.
If you are the service provider
Your customers are now contractually obliged to demand these controls of you. Your exposure is being asked for evidence you have never had to produce — and under the Urban Co-operative Bank provisions, one provider can owe the same evidence to a great many institutions at once.
The evidence gate is section 5.
The contract gate
Four of the twenty-four, cited precisely
These four are the ones this document can cite by clause number. The worksheet deliberately does not paraphrase the other twenty — naming a control we have not verified against the source, in a document a bank may attach to a vendor contract, is worse than omitting it. It gives you the rows to work through your own copy instead.
¶138(12)
Source-code audits, by professionally competent personnel or service providers.
¶138(19)
Vulnerability assessment and penetration testing conducted by the service provider.
¶138(20)
Sharing those reports with the bank and with RBI — a separate obligation from performing the test.
¶138
PCI-DSS and PCI-SSF, as applicable to the service provided.
Urban Co-operative Banks
The mirrored enumeration is paragraph 85 and runs to thirty-seven controls rather than twenty-four, with VA/PT at 85(34), report sharing at 85(35), the provider’s Cyber Security Operations Centre inside 85(36), and PCI-DSS/PCI-SSF at 85(37). Under paragraph 117, a UCB on a shared Core Banking System provider has its CBS application and hosting infrastructure tested through that provider.
Estate
Every channel, counted
Counts drive sampling, so an estimate at the inventory stage becomes an argument at the report stage. The worksheet asks for a count, an owner and a scope decision per channel.
Related
Where this fits
Need the audit, or the evidence your customers are asking for?
Security Brigade has been CERT-In empanelled since 2008 and tests the payment chain end to end — terminals, transaction logic, cardholder data flows, segmentation, key management and switch integration.
Talk to a payments lead