Skip to main content
RBI Directions, 2026 · PCI DSS v4.0 · EMV

ATM and POS
Security Audit Checklist

The obligation to control an ATM Switch service provider sits with the bank and is discharged by contract. The work sits with the provider. Two readers, opposite problems — and each half of this checklist is written for one of them.

24
Baseline controls at ¶138
¶136–139
The governing range
9
Payment channels in scope

ATM and POS Security Audit Checklist

Enter your work email for the printable worksheet — the estate inventory, the contract gate at paras 136 to 139, the evidence the service provider has to produce, and a channel-by-channel scope table.

By downloading, you agree to receive relevant communications. We respect your privacy.

Who this is for

The obligation and the work sit in different places

If you are the bank

Paragraph 136 cross-references the controls that apply, 137 requires them in the contract, and 138 enumerates the twenty-four the bank shall mandate contractually. Your exposure is a contract that does not carry them — and a provider that performs a control without being obliged to does not discharge the obligation.

The contract gate is section 4 of the worksheet.

If you are the service provider

Your customers are now contractually obliged to demand these controls of you. Your exposure is being asked for evidence you have never had to produce — and under the Urban Co-operative Bank provisions, one provider can owe the same evidence to a great many institutions at once.

The evidence gate is section 5.

The contract gate

Four of the twenty-four, cited precisely

These four are the ones this document can cite by clause number. The worksheet deliberately does not paraphrase the other twenty — naming a control we have not verified against the source, in a document a bank may attach to a vendor contract, is worse than omitting it. It gives you the rows to work through your own copy instead.

¶138(12)

Source-code audits, by professionally competent personnel or service providers.

¶138(19)

Vulnerability assessment and penetration testing conducted by the service provider.

¶138(20)

Sharing those reports with the bank and with RBI — a separate obligation from performing the test.

¶138

PCI-DSS and PCI-SSF, as applicable to the service provided.

Urban Co-operative Banks

The mirrored enumeration is paragraph 85 and runs to thirty-seven controls rather than twenty-four, with VA/PT at 85(34), report sharing at 85(35), the provider’s Cyber Security Operations Centre inside 85(36), and PCI-DSS/PCI-SSF at 85(37). Under paragraph 117, a UCB on a shared Core Banking System provider has its CBS application and hosting infrastructure tested through that provider.

Estate

Every channel, counted

Counts drive sampling, so an estimate at the inventory stage becomes an argument at the report stage. The worksheet asks for a count, an owner and a scope decision per channel.

ATMsCash Deposit MachinesKiosksPOS terminalsMicroATMsAadhaar-enabled payment devicesNFC / tap-to-payPayment middlewareSwitch integration

Need the audit, or the evidence your customers are asking for?

Security Brigade has been CERT-In empanelled since 2008 and tests the payment chain end to end — terminals, transaction logic, cardholder data flows, segmentation, key management and switch integration.

Talk to a payments lead