The data-localisation requirement
The RBI directive of 6 April 2018 requires that all data relating to payment systems operated in India is stored only within India. That covers the full end-to-end transaction detail and the payment data collected, carried or processed as part of the message or payment instruction.
A System Audit Report (SAR) is how you evidence this to the regulator. It verifies your data-storage architecture, access controls, data-transfer mechanisms and security practices, and confirms — with independent audit evidence — that payment data is held and processed within India.
Who needs a data-localisation SAR
The requirement applies across the payment-system ecosystem — anyone who stores or processes payment data in India:
- Banks — commercial, co-operative and digital-banking platforms handling payment transactions.
- Payment gateways, aggregators and payment processors moving merchant and customer transaction data.
- Digital wallets, prepaid instrument issuers and UPI providers storing wallet and transaction data.
- Card networks, ATM and white-label ATM operators, bill-payment and cross-border payment providers.
- Fintech and payment-technology providers whose infrastructure carries payment data.
CyberSigma’s role
We are the independent auditor. We scope the environment, map your payment-data flows, review your storage architecture and controls, test them against the RBI localisation requirement, and prepare the System Audit Report. Our independence from your build and operations is what gives the SAR its assurance value.
The regulator’s role
The Reserve Bank of India sets the data-localisation requirement and receives the SAR. The report is submitted to RBI as evidence of compliance. We prepare an accurate, evidence-based SAR; the regulator reviews it. Remediation of any gaps we find is carried out by your teams, so our audit stays independent.
How we deliver
Scoping & data mapping
We establish the boundary of the audit — the payment systems, applications, databases and infrastructure that store or process payment data — and map how that data flows across your environment, integrations and any third-party or cloud services.
Data-storage & residency review
We examine your server environments, databases, hosting and cloud architecture to verify that payment data is stored and processed only within India, and check for any replication, backup or logging that places data outside the country.
Data-flow & cross-border check
We trace system integrations, network paths and third-party services to confirm that sensitive payment data does not move outside India, and identify any cross-border transfers that breach the localisation requirement.
Security & access-control assessment
We review the authentication, privileged access, encryption and security controls that protect payment data across your applications, infrastructure and storage — the safeguards RBI expects around localised data.
System Audit Report (SAR) preparation
We document the findings, compliance status, risks and remediation recommendations in a System Audit Report in the form RBI expects, ready for submission to the Reserve Bank of India.
What you receive
- System Audit Report (SAR) documenting compliance status, observations and audit conclusions for RBI submission
- Data-residency compliance report confirming payment data is stored and processed within India
- Data-architecture review of the infrastructure, databases and hosting environments holding financial data
- Data-flow assessment showing how payment data moves across systems, checked against localisation requirements
- Security-control evaluation of the safeguards protecting financial data across applications and infrastructure
- Remediation recommendations to close compliance gaps and strengthen controls
Indicative timeline
A data-localisation SAR typically runs a few weeks from scoping to a submission-ready report, depending on the number of payment systems in scope, the complexity of your data flows, and how much cloud and third-party infrastructure is involved.
Timelines vary with scope and readiness; we confirm a schedule after the scoping stage. RBI expects a SAR periodically and after significant changes to payment infrastructure.
What we assess
The audit covers the systems and controls that determine whether payment data stays within India:
- Data-storage architecture — databases, servers and hosting environments holding payment data.
- Cloud deployments and third-party or vendor services that store or process financial data.
- Data flows and integrations, including replication, backups and logging that could place data offshore.
- Access controls, authentication, privileged access and encryption protecting payment data.
- Logging and monitoring that would detect unauthorised data access or cross-border transfer.
Representative engagement
A payment-technology provider needed to evidence data-localisation compliance to its sponsor bank and to RBI. We scoped its payment applications and databases, mapped the transaction-data flows across its cloud and on-premise infrastructure, identified backup and logging paths that risked placing data outside India, and produced a System Audit Report setting out findings and remediation for submission to the regulator. Named client references are available under NDA on request.
Who leads your engagement
Your engagement is led by a senior auditor with financial-sector and payment-systems experience, supported by infrastructure and security specialists. Every finding is evidenced and the report passes independent quality review before it reaches you or the regulator. We introduce your named lead on the first call.
Not sure where you stand on RBI data localisation / SAR audit?
Get a free RBI data localisation / SAR audit scope and readiness review — share your work email and a senior consultant maps your gaps and next steps. No obligation.
Frequently asked questions
What is RBI Data Localization Audit (SAR)?
RBI Data Localization Audit (SAR) is a regulatory assessment that verifies your payment system data is stored and processed within India, as required by RBI guidelines.
What does SAR stand for in RBI data localization?
SAR stands for System Audit Report. It documents your compliance with RBI data localization requirements.
Why is RBI Data Localization important?
It keeps sensitive financial and payment data within India, which supports regulatory oversight and stronger data security.
What is the objective of SAR Audit?
The audit verifies data residency, evaluates infrastructure security and confirms that payment data stays within India.
What is included in a System Audit Report (SAR)?
A System Audit Report covers compliance findings, an infrastructure review, data flow analysis, security observations and remediation recommendations.
How often should SAR Audit be conducted?
Most organisations run a SAR audit annually or whenever payment infrastructure changes significantly.
What systems are reviewed during SAR Audit?
Auditors review payment applications, databases, infrastructure, cloud environments and data storage systems.
What are common risks identified during SAR audits?
Common issues include cross-border data transfers, cloud misconfigurations, weak access controls and improper data storage practices.
Does SAR Audit include cloud infrastructure review?
Yes. Auditors evaluate cloud deployments to confirm payment data is stored within India.
What is data flow analysis in SAR Audit?
It examines how payment data moves across applications, networks and third-party systems.
