How to Verify a CERT-In Empanelled Auditor (RBI SAR Guide)

CERT-In mandates Indian orgs report breaches; ISO 27001 is voluntary certification. Learn which standard applies to your role—sector rules, compliance timelines & audit scope explained.

S
Sahil Dubey
July 24, 2026
3 min read
7 views

How to Verify a CERT-In Empanelled Auditor Before You Sign an RBI SAR Engagement

If a mandate requires a CERT-In empanelled auditor, the single most important due-diligence step is confirming that empanelment is genuine and current before work begins. RBI will not accept a System Audit Report (SAR) signed by a non-empanelled vendor, and the same applies to most MeitY and SEBI audits. Here is exactly how to verify empanelment and what to check in the engagement.

Why empanelment verification matters

CERT-In (the Indian Computer Emergency Response Team) maintains a list of empanelled information-security auditing organisations. For RBI SAR covering payment aggregators, payment gateways, banks and NBFCs, the auditor must appear on that list for the report to be accepted. Engaging an unempanelled firm means re-doing the audit — lost time against a regulatory deadline (SAR is generally due by 31 May after financial-year end).

Step-by-step: how to verify a CERT-In empanelled auditor

  • Check the official CERT-In list. Confirm the auditing organisation's name appears on the current CERT-In empanelment list published on cert-in.org.in.
  • Confirm the validity window. Empanelment is granted for a defined period and renewed in cycles — verify the current cycle covers your audit dates.
  • Match the legal entity. Ensure the empanelled entity name matches the company you are contracting with, not a sister brand or reseller.
  • Ask for the empanelment reference. A genuine auditor will readily share their empanelment reference and scope.
  • Confirm auditor credentials. Look for lead auditors holding CISA, CISM, or ISO 27001 Lead Auditor certifications alongside the organisational empanelment.

What to confirm in the engagement scope

Empanelment is necessary but not sufficient — the scope must match the mandate. For RBI SAR, confirm the audit covers network, application, and data security, IT governance, BCP/DR, and, where applicable, data-localization verification (full transaction data stored only in India). Ask for a regulator-ready report format suitable for RBI submission, and confirm re-testing after remediation is included.

Frequently asked questions

How do I check if an auditor is CERT-In empanelled?

Verify the auditing organisation's name on the official CERT-In empanelment list, confirm the empanelment period covers your audit dates, and match the legal entity to your contracting party.

Is CERT-In empanelment mandatory for RBI SAR?

Yes. RBI requires that the System Audit Report for payment aggregators, payment gateways, banks and NBFCs be conducted by a CERT-In empanelled auditor. A report from a non-empanelled vendor is not accepted.

Does empanelment cover MeitY and SEBI audits too?

CERT-In empanelment is the common credential accepted for MeitY compliance, SEBI's cyber-security framework, and most government tenders, in addition to RBI SAR.

What credentials should the audit team hold?

Beyond organisational empanelment, look for lead auditors with CISA, CISM, or ISO 27001 Lead Auditor certifications for technical assurance.

Praxis-Q delivers CERT-In-aligned audits with regulator-ready reporting, fast-tracked in weeks by certified assessors. Explore our CERT-In Empanelled Audit service, or see how it supports RBI SAR audit submissions.

Free Consultation

Ready to Get Compliant?

ISO 27001, PCI DSS, HIPAA, SOC 2 & more — fast-track in a few weeks.

Book Free Audit →

Tags

pillar:cert-in-empanelled-auditCERT-In AuditISO 27001 CertificationIndia CybersecurityCompliance StandardsData Protection

Share this article

S

Sahil Dubey

Compliance & Security Expert

CISA, ISO 27001 LA, AWS Certified. 11+ years in information security, cloud services, and compliance. Founder of Praxis-Q.

Related compliance and security services