How to Verify a CERT-In Empanelled Auditor Before You Sign an RBI SAR Engagement
If a mandate requires a CERT-In empanelled auditor, the single most important due-diligence step is confirming that empanelment is genuine and current before work begins. RBI will not accept a System Audit Report (SAR) signed by a non-empanelled vendor, and the same applies to most MeitY and SEBI audits. Here is exactly how to verify empanelment and what to check in the engagement.
Why empanelment verification matters
CERT-In (the Indian Computer Emergency Response Team) maintains a list of empanelled information-security auditing organisations. For RBI SAR covering payment aggregators, payment gateways, banks and NBFCs, the auditor must appear on that list for the report to be accepted. Engaging an unempanelled firm means re-doing the audit — lost time against a regulatory deadline (SAR is generally due by 31 May after financial-year end).
Step-by-step: how to verify a CERT-In empanelled auditor
- Check the official CERT-In list. Confirm the auditing organisation's name appears on the current CERT-In empanelment list published on cert-in.org.in.
- Confirm the validity window. Empanelment is granted for a defined period and renewed in cycles — verify the current cycle covers your audit dates.
- Match the legal entity. Ensure the empanelled entity name matches the company you are contracting with, not a sister brand or reseller.
- Ask for the empanelment reference. A genuine auditor will readily share their empanelment reference and scope.
- Confirm auditor credentials. Look for lead auditors holding CISA, CISM, or ISO 27001 Lead Auditor certifications alongside the organisational empanelment.
What to confirm in the engagement scope
Empanelment is necessary but not sufficient — the scope must match the mandate. For RBI SAR, confirm the audit covers network, application, and data security, IT governance, BCP/DR, and, where applicable, data-localization verification (full transaction data stored only in India). Ask for a regulator-ready report format suitable for RBI submission, and confirm re-testing after remediation is included.
Frequently asked questions
How do I check if an auditor is CERT-In empanelled?
Verify the auditing organisation's name on the official CERT-In empanelment list, confirm the empanelment period covers your audit dates, and match the legal entity to your contracting party.
Is CERT-In empanelment mandatory for RBI SAR?
Yes. RBI requires that the System Audit Report for payment aggregators, payment gateways, banks and NBFCs be conducted by a CERT-In empanelled auditor. A report from a non-empanelled vendor is not accepted.
Does empanelment cover MeitY and SEBI audits too?
CERT-In empanelment is the common credential accepted for MeitY compliance, SEBI's cyber-security framework, and most government tenders, in addition to RBI SAR.
What credentials should the audit team hold?
Beyond organisational empanelment, look for lead auditors with CISA, CISM, or ISO 27001 Lead Auditor certifications for technical assurance.
Praxis-Q delivers CERT-In-aligned audits with regulator-ready reporting, fast-tracked in weeks by certified assessors. Explore our CERT-In Empanelled Audit service, or see how it supports RBI SAR audit submissions.
Free Consultation
Ready to Get Compliant?
ISO 27001, PCI DSS, HIPAA, SOC 2 & more — fast-track in a few weeks.
Tags
Share this article
Sahil Dubey
Compliance & Security Expert
CISA, ISO 27001 LA, AWS Certified. 11+ years in information security, cloud services, and compliance. Founder of Praxis-Q.