{"id":968,"date":"2026-08-23T21:05:34","date_gmt":"2026-08-23T21:05:34","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=968"},"modified":"2026-08-23T21:05:34","modified_gmt":"2026-08-23T21:05:34","slug":"system-audit-report-sar","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/system-audit-report-sar\/","title":{"rendered":"System Audit Report (SAR)"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: SYSTEM AUDIT REPORT (SAR)\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">A System Audit Report is the annual document a regulated financial entity files with the Reserve Bank of India to evidence that its technology, data handling and security controls hold up under independent examination.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">India<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>A System Audit Report, usually shortened to SAR, is the output of an independent technology audit that the RBI requires from banks, non-banking financial companies, payment aggregators, prepaid instrument issuers and other payment system operators. It must be produced by a CERT-In empanelled auditor, approved by the board, and submitted to the regulator. You cannot self-certify it, and the auditor who writes it is not permitted to fix what they find.<\/p>\n<\/div>\n\n<p>That last constraint is the one that catches teams out. The audit surfaces gaps and stops there. Everything before it is your problem.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#what\">What a System Audit Report is<\/a><\/li>\n    <li><a href=\"#who\">Who has to file one<\/a><\/li>\n    <li><a href=\"#scope\">What the audit covers<\/a><\/li>\n    <li><a href=\"#fail\">Why first submissions fail<\/a><\/li>\n    <li><a href=\"#vendor\">If you are a vendor inside the scope<\/a><\/li>\n    <li><a href=\"#osto\">How Osto gets you audit-ready<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"what\">What a System Audit Report is<\/h2>\n\n<p>The RBI supervises technology risk in regulated entities partly through periodic independent audit. The System Audit Report is the artefact that carries the result. It is not a certificate and it is not a pass mark. It is a documented assessment, with evidence attached, that the regulator reads.<\/p>\n\n<p>Two distinct strands travel under the same name. The first comes from the RBI directive of 6 April 2018 on storage of payment system data, which requires payment data to be held only in India. The second is the entity-specific system and cyber security audit written into individual licence frameworks. Many companies file a report that covers both.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"The System Audit Report chain: the regulated entity is audited by a CERT-In empanelled auditor, the report is board approved, then submitted to the RBI.\">\n  <defs><marker id=\"sarA\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"14\" y=\"40\" width=\"164\" height=\"82\" rx=\"15\" fill=\"#e9ecfa\"\/>\n  <text x=\"96\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">Regulated entity<\/text>\n  <text x=\"96\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Bank, NBFC, payment<\/text>\n  <text x=\"96\" y=\"107\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">system operator<\/text>\n\n  <line x1=\"184\" y1=\"81\" x2=\"216\" y2=\"81\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#sarA)\"\/>\n\n  <rect x=\"222\" y=\"40\" width=\"164\" height=\"82\" rx=\"15\" fill=\"#e3f0e9\"\/>\n  <text x=\"304\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#3a6f5d\">Empanelled auditor<\/text>\n  <text x=\"304\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Independent, on the<\/text>\n  <text x=\"304\" y=\"107\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">CERT-In panel<\/text>\n\n  <line x1=\"392\" y1=\"81\" x2=\"424\" y2=\"81\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#sarA)\"\/>\n\n  <rect x=\"430\" y=\"40\" width=\"152\" height=\"82\" rx=\"15\" fill=\"#1c267a\"\/>\n  <text x=\"506\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">Board approval<\/text>\n  <text x=\"506\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">The report is signed<\/text>\n  <text x=\"506\" y=\"107\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">off at board level<\/text>\n\n  <line x1=\"588\" y1=\"81\" x2=\"620\" y2=\"81\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#sarA)\"\/>\n\n  <rect x=\"626\" y=\"40\" width=\"120\" height=\"82\" rx=\"15\" fill=\"#f0e6f3\"\/>\n  <text x=\"686\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#6b4576\">Filed with<\/text>\n  <text x=\"686\" y=\"95\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#6b4576\">the RBI<\/text>\n\n  <rect x=\"14\" y=\"148\" width=\"732\" height=\"42\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"174\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">The auditor assesses. The auditor does not remediate. Fixing findings is always your side of the line.<\/text>\n\n  <rect x=\"14\" y=\"198\" width=\"732\" height=\"38\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"380\" y=\"222\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#2f6a89\">An internal IT team or a financial auditor cannot issue a System Audit Report.<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Independence is structural. It is why readiness work has to happen before the engagement starts.<\/figcaption>\n<\/figure>\n\n<h2 id=\"who\" class=\"c-sage\">Who has to file one<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Entity<\/th><th>Why the System Audit Report applies<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Payment aggregators<\/td><td>The <a href=\"https:\/\/www.osto.one\/resources\/glossary\/payment-aggregator\/\">payment aggregator<\/a> Directions require an annual system and cyber security audit report filed with the RBI<\/td><\/tr>\n    <tr><td>Prepaid instrument issuers, bill payment operators, card networks and other payment system operators<\/td><td>Licence conditions and the payment data storage directive both bite<\/td><\/tr>\n    <tr><td>Banks and non-banking financial companies<\/td><td>Information systems audit obligations, weighted by where the company sits in the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/nbfc-regulatory-layers\/\">NBFC regulatory layers<\/a><\/td><\/tr>\n    <tr><td>Cross-border payment aggregators<\/td><td>Payment data localisation plus foreign exchange handling both fall inside scope<\/td><\/tr>\n    <tr><td>Software vendors to any of the above<\/td><td>Not filers, but reachable through the third-party sections of someone else&#8217;s report<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"scope\" class=\"c-apri\">What the audit covers<\/h2>\n\n<p>Scope varies by licence, but the recurring domains are consistent enough to prepare against.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Domain<\/th><th>What the auditor looks for<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Payment data storage and residency<\/td><td>Where data physically sits, end-to-end flows, and evidence that anything processed abroad was purged there and returned to India within the permitted window<\/td><\/tr>\n    <tr><td>System architecture and network design<\/td><td>Current diagrams that match reality, segmentation, and documented interfaces<\/td><\/tr>\n    <tr><td>Access management<\/td><td>Least privilege, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">multi-factor authentication<\/a>, privileged account handling and joiner-mover-leaver evidence<\/td><\/tr>\n    <tr><td>Cryptographic controls<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">Encryption in transit and at rest<\/a>, key management, and no plaintext card credentials<\/td><\/tr>\n    <tr><td>Vulnerability assessment and penetration testing<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> across in-scope applications and infrastructure, with findings mapped to requirements and a retest attached<\/td><\/tr>\n    <tr><td>Logging, monitoring and incident management<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">Correlated logging<\/a> with retention, plus a response plan that has actually been exercised<\/td><\/tr>\n    <tr><td>Backup, restoration and business continuity<\/td><td>Recovery targets that were measured rather than asserted<\/td><\/tr>\n    <tr><td>Third-party and outsourcing risk<\/td><td>Due diligence records, contractual audit rights and exit planning for material providers<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"fail\" class=\"c-plum\">Why first submissions fail<\/h2>\n\n<p>A System Audit Report engagement typically runs three to nine weeks, and most of that variance is remediation, not testing. The audit finds the same things repeatedly.<\/p>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Documentation that lags the build<\/p>\n    <p>Architecture diagrams and data flow maps describe last year&#8217;s system. The auditor cannot certify what nobody can accurately describe.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Gaps found during, not before<\/p>\n    <p>Open vulnerabilities and missing logs surface inside the engagement, so the clock is already running while you fix them.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Evidence that does not exist yet<\/p>\n    <p>Controls may work in practice but leave no trail. An auditor cannot sign off on a process without records of it operating.<\/p>\n  <\/div>\n<\/div>\n\n<div class=\"callout\">\n  <p class=\"k\">The submission is not the end of it<\/p>\n  <p>Findings and their closure status are visible to the supervisor, and RBI supervisory workflow now runs through platforms such as <a href=\"https:\/\/www.osto.one\/resources\/glossary\/rbi-daksh\/\">DAKSH<\/a>. An open finding carried into the next cycle is a pattern the regulator can see. Non-compliance on payment data localisation in particular has drawn business restrictions, not just correspondence.<\/p>\n<\/div>\n\n<h2 id=\"vendor\">If you are a vendor inside the scope<\/h2>\n\n<p>Most technology companies never file a System Audit Report of their own. They land inside a customer&#8217;s. If a regulated entity processes payment data on your platform, or your software sits in the settlement path, the third-party and data-flow sections of their report reach you.<\/p>\n\n<p>In practice that means answering where data is stored, producing a current penetration test, showing how your staff access the environment, and committing to an incident notification timeline that lets your customer meet its own. Getting asked mid-audit is the expensive version. The same pattern shows up in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/escrow-account\/\">escrow account<\/a> controls and in ordinary enterprise vendor review.<\/p>\n\n<h2 id=\"osto\" class=\"c-sage\">How Osto gets you audit-ready<\/h2>\n\n<p>Osto covers the technical half of a System Audit Report by default rather than as separate purchases. Expert-led <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> and continuous scanning find what the auditor would find, with retests attached. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">Cloud posture management<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API discovery<\/a> close the configuration and endpoint gaps that dominate findings. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">Correlated logging<\/a> produces the retention and audit trail the report asks you to demonstrate.<\/p>\n\n<p>The evidence layer is purpose-built for exactly this. One control set answers the RBI reviewer, a regulated customer&#8217;s vendor questionnaire, <a href=\"https:\/\/osto.one\/resources\/blog\/soc-2-for-startups\/\" target=\"_blank\" rel=\"noopener\">SOC 2<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> at once. Osto prepares your evidence and gets you through the review. The audit itself is performed by the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cert-in-empanelment\/\">CERT-In empanelled auditor<\/a>, and that separation is deliberate on both sides.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Walk into the audit with nothing left to find<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto finds and fixes what an empanelled auditor would flag, then holds the evidence. VAPT, cloud posture, code security, logging and compliance in one platform.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Audit-ready in days &middot; RBI, SEBI and DPDP mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is a System Audit Report?<\/summary>\n  <p>A System Audit Report is the documented result of an independent technology and security audit that the Reserve Bank of India requires from regulated entities. It covers architecture, payment data handling, access controls, testing, logging and continuity, and is submitted to the regulator after board approval.<\/p>\n<\/details>\n\n<details>\n  <summary>Who can prepare a System Audit Report?<\/summary>\n  <p>A CERT-In empanelled auditing organisation. The lead auditor is commonly expected to hold the Certified Information Systems Auditor credential. An internal team, a general financial auditor or a non-empanelled security firm cannot issue it for RBI submission.<\/p>\n<\/details>\n\n<details>\n  <summary>How often must a System Audit Report be submitted?<\/summary>\n  <p>Annually for most regulated entities, and additionally whenever the Reserve Bank of India asks for one. Some licence frameworks also trigger a fresh audit on material change to systems or on authorisation.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between a System Audit Report and a penetration test?<\/summary>\n  <p>A <a href=\"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/\">penetration test<\/a> is one input. The System Audit Report is a wider assessment covering governance, data residency, access management, cryptography, logging, continuity and third-party risk, with the test results forming one section of it.<\/p>\n<\/details>\n\n<details>\n  <summary>What happens if the audit finds problems?<\/summary>\n  <p>Findings are recorded with severity and a remediation plan, and the auditor typically revalidates closure. Unresolved items carry into the report the regulator reads. Sustained non-compliance, particularly on payment data localisation, has previously led to restrictions on onboarding new customers.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> CERT-In Empanelment &middot; Payment Aggregator &middot; Escrow Account &middot; NBFC Regulatory Layers &middot; RBI DAKSH &middot; VAPT &middot; Penetration Testing &middot; SIEM<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A System Audit Report is the annual document a regulated financial entity files with the Reserve Bank of India to\u2026<\/p>\n","protected":false},"author":8,"featured_media":969,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[428,427],"class_list":["post-968","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-rbi-system-audit-report-requirements","tag-system-audit-report"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/968","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=968"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/968\/revisions"}],"predecessor-version":[{"id":970,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/968\/revisions\/970"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/969"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=968"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=968"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=968"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}