Payments & Regulatory Audit
NPCI & UPI audit services
CERT-In empanelled security audits for TPAPs, PSP banks, merchants and payment platforms operating on NPCI rails — UPI, IMPS, RuPay, NACH, AePS and NETC — scoped to the go-live and periodic audit your sponsor bank or NPCI is asking for.
What we typically deliver
- Pre-go-live security audit for a new UPI/TPAP or NPCI product integration, in the form your PSP or sponsor bank has to file.
- Periodic (typically annual) system and security audit of the live environment, with evidence packaged for the sponsor bank’s own compliance review.
- Application, API and mobile-app testing across the UPI journey — registration, device binding, PIN capture via the NPCI common library, mandates and refunds.
- Payment-data localisation review — where payment system data is stored, processed and mirrored, and what leaves India.
- Findings mapped to the specific control, with reproduction evidence, a prioritised fix list and a retest that confirms closure.
Who this applies to
The obligation reaches further than most teams expect, because it follows the rail rather than the licence. In practice we are engaged by:
- TPAPs — third-party applications offering UPI through a PSP bank, where the sponsor bank carries the regulatory relationship and passes the audit requirement to you contractually.
- PSP and sponsor banks assuring the partners on their BIN or handle.
- Payment aggregators and gateways touching NPCI rails alongside their RBI PA/PG obligations.
- Merchants and platforms at scale — large e-commerce, travel, lending and utility platforms whose UPI integration is deep enough to be in scope.
- Fintechs building on AePS, NACH e-mandates, RuPay or NETC, where the product audit is a precondition of going live.
What actually gets tested
NPCI-rail audits fail on the same handful of things, and almost none of them are exotic cryptography. They are integration and operational controls:
- Key and credential handling — how UPI PIN capture is implemented through the NPCI library, and whether anything sensitive is logged, cached or crash-reported on the way past.
- Device binding and re-registration — the flows most often abused in account-takeover, especially around SIM change and app reinstall.
- API authorisation — whether one customer’s identifiers can be substituted to reach another customer’s data or transaction. This is the single most common serious finding we report.
- Transaction integrity and idempotency — duplicate submission, replay, and the reconciliation gaps that show up as customer disputes rather than security tickets.
- Data localisation and retention — storage location, mirroring, third-party analytics SDKs and what they take with them.
- Logging, monitoring and incident readiness — including the reporting path when something does happen.
Scope, timeline and what changes the cost
Audit scope and frequency depend on the rail, the product, your role on it and what your sponsor bank or NPCI has specified for your integration — which is why we scope before we price rather than quoting a number that changes later. The variables that move the estimate are the number of applications and platforms, whether mobile builds and APIs are both in scope, the number of user roles and environments, and whether you need a pre-go-live audit, a periodic audit, or both in the same cycle. The authoritative requirement for your specific integration comes from NPCI and your sponsor bank; we scope to that, not to a generic template.
Why CyberSigma
We are CERT-In empanelled— the empanelment these audits are normally required to be performed under — and a PCI SSC-listed QSA company, so a payments client can run the NPCI audit, the PCI DSS assessment and the application testing through one team that already understands the environment. Our assessors work with banks, NBFCs, payment aggregators and fintechs on Indian payment rails, which means the report lands in a form your sponsor bank’s compliance team recognises.
Related
Most NPCI-rail clients also carry adjacent obligations: RBI cybersecurity audit where an NBFC licence is involved, PCI DSS wherever card data is touched, and VAPT for the underlying applications and infrastructure.

QSA Authorised
CEMEA · Asia Pacific · USA
NPCI & UPI audit — common questions
Who needs an NPCI or UPI audit?
Entities operating on NPCI rails — TPAPs offering UPI through a PSP bank, PSP and sponsor banks, payment aggregators, and fintechs building on AePS, NACH, RuPay or NETC. In practice the requirement usually reaches a TPAP or merchant contractually, through the sponsor bank that carries the regulatory relationship, rather than directly.
Does the auditor have to be CERT-In empanelled?
Security audits in this space are normally required to be carried out by a CERT-In empanelled organisation, and sponsor banks generally insist on it even where the wording leaves room. CyberSigma is CERT-In empanelled. Confirm the exact expectation for your integration with your sponsor bank, since it can differ by rail and product.
How often is the audit required?
Typically a pre-go-live audit before a new integration or product launch, then a periodic audit — commonly annual — of the live environment. Material change to the integration usually triggers a fresh assessment too. The precise cadence for your product comes from NPCI and your sponsor bank, which is part of what a scoping call establishes.
What is a TPAP audit?
A Third Party Application Provider offers UPI to customers through a PSP bank. The TPAP audit examines that application and its integration — registration and device binding, UPI PIN handling through the NPCI common library, API authorisation, transaction integrity, data storage and localisation, logging and incident readiness — and produces evidence the PSP bank can rely on.
How does this relate to our PCI DSS assessment?
They cover different things. PCI DSS governs cardholder data; an NPCI audit governs your conduct on NPCI rails, which are account-to-account rather than card-based. Organisations doing both often share evidence — testing, access control, logging and change management overlap substantially — which is why running them through one assessor usually reduces total effort.
Do you test the mobile app as well as the backend?
Yes, where the app is in scope. Much of the risk in a UPI journey sits in the mobile client and the APIs behind it — device binding, PIN capture, local storage, and whether one authenticated user can reach another user’s data by changing an identifier. Backend-only testing misses that.
Ready to discuss your NPCI / UPI audit requirement?
CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
