HomeCirculars › RBI/2010-11/476

System Audit Qualification Mandate for Payment Operators

Current · Source: Reserve Bank of India · RBI/2010-11/476 · issued 15 Apr 2011 · ~1 min read
Quick answerRBI now requires system audits for payment operators to be done only by CISA-certified (ISACA) or DISA-qualified (ICAI) auditors, replacing earlier broader criteria.
The rule, in the simplest words
How it plays out — a real example

Rohit, a senior audit manager at a payment gateway in Mumbai, receives a request to audit the new transaction‑processing system. He checks that the external auditor, Ms. Priya Sharma, holds a CISA certification from ISACA, confirms the registration is current, and then proceeds with the audit. After completing the work, Rohit submits the audit report to RBI, confident it meets the new qualification requirement.

What changed

RBI partially modified earlier circulars from December 2009 and December 2010 on system audit submissions. The key change: system audits must now be conducted exclusively by a Certified Information Systems Auditor (CISA) registered with ISACA or a holder of a Diploma in Information System Audit (DISA) from ICAI.

What it means for you

Payment system operators and entities must now ensure their system auditors hold specific, recognized certifications—CISA or DISA. This raises the bar for audit quality and consistency, potentially limiting the pool of eligible auditors and increasing compliance costs for smaller operators.

What you must do

Who it affects

All authorised payment system operators, All authorised payment system entities, System audit firms and auditors serving payment operators

❓ Common questions

What qualifications are now mandatory for system auditors under this circular?

The auditor must be a Certified Information Systems Auditor (CISA) registered with ISACA, or hold a Diploma in Information System Audit (DISA) from ICAI.

Does this circular replace all earlier system audit instructions?

No, it only partially modifies the instructions in the earlier circulars of December 2009 and December 2010. Other requirements from those circulars remain in force.

What should I do if my current auditor does not have CISA or DISA?

You need to engage a new auditor who meets the specified qualification criteria before your next system audit submission to RBI.

📜 Read the original circular — full text as issued by RBI
RBI/2010-11/476 DPSS.CO.OSD. No. 2374 /06.11.001/2010-2011 April 15, 2011 To all Authorised Payment System Operators & Entities Dear Sir, Submission of system audit reports Please refer to our earlier circulars DPSS.AD.No./1206/02.27.005/2009-2010 dated December 7, 2009 and DPSS.1444/ 06.11.001/ 2010-2011 dated December 27, 2010 on the captioned subject. In partial modification of the instructions contained therein, it is advised that the system audit may be conducted by a Certified Information Systems Auditor (CISA) and registered with Information Systems Audit and Control Association (ISACA) or by a holder of a Diploma in Information System Audit (DISA) qualification of the Institute of Chartered Accountants of India (ICAI). Please acknowledge receipt. Yours faithfully, G. Srinivas (General Manager)
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2010-11/476 · issued 15 Apr 2011. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Topics: Digital Payments / UPI
Key dataSee the live numbers behind this topic: RBI Penalty Tracker, Credit & Deposit Growth — updated from official RBI data.
Key termsPlain-English definitions of terms in this circular — see the full Indian banking glossary. UPI · KYC / AML · Deposit insurance (DICGC) · NEFT / RTGS
Who does what — compliance checklist
💻 IT / Systems
  • Verify that your current system auditor holds a valid CISA (ISACA) or DISA (ICAI) qualification.
  • Ensure future system audit reports are submitted only after audits by qualified CISA or DISA auditors.
📜 Compliance
  • Update your vendor/auditor empanelment criteria to match the new qualification requirements.
  • Acknowledge receipt of this circular to RBI as instructed.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are an IT/Systems lead at a bank this circular applies to (All authorised payment system operators, All authorised payment system entities, System audit firms and auditors serving payment operators), your first concrete step on “System Audit Qualification Mandate for Payment Operators” is: “Verify that your current system auditor holds a valid CISA (ISACA) or DISA (ICAI) qualification.” (RBI issued this 15 Apr 2011).

  1. Circular: RBI/2010-11/476 -- System Audit Qualification Mandate for Payment Operators
  2. Issued: 15 Apr 2011
  3. Action required: Verify that your current system auditor holds a valid CISA (ISACA) or DISA (ICAI) qualification.
  4. Action required: Update your vendor/auditor empanelment criteria to match the new qualification requirements.
  5. Action required: Ensure future system audit reports are submitted only after audits by qualified CISA or DISA auditors.
  6. Action required: Acknowledge receipt of this circular to RBI as instructed.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=6344&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗