Download as docx, pdf, or txt
Download as docx, pdf, or txt
You are on page 1of 1

S/N RISKS AREAS AUDIT STEPS

1. Fraudulent merchants may 1. Evaluate the process of merchant acquisition for procedural
be acquired or merchant control adequacies against signing on of terrorists, merchants
may change their line of dealing in illegal & illicit businesses.
business without 2. Verify that there is periodic merchant monitoring to detect when
notification. merchant changes their line of business.
3. Verify the existence of clauses in the merchant agreement to
mitigate against these.

2. Configuration of merchants 1. Review procedural and application controls for merchant


with wrong details may registration.
lead to financial loss, delay 2. Evaluate the physical and logical security for storage of
in problem resolution, merchant details
customer dissatisfaction.

3. Inadequate security 1. Review training frequency, materials and documentations


awareness training for web 2. Interview sample merchants to ascertain level of awareness and
merchants may lead poor effectiveness of the training.
security implementations
and fraud.
4. Mismanagement of Data 1. Ensure that all data SIM cards are used on POS only by
SIM cards used for POS evaluating the payment schedule against the schedule of SIM
deployment. cards used in POS deployments.
2. Review process of handling retrieved SIM cards from faulty or
damage POS machine.

5. POS software may not be 1. Review POS software update history on the internet and
updated with latest security compare with the version running on the POS machines.
patches. 2. Review sample POS machines to ensure that they all have the
latest version of software running on them.

6. Merchants may not sign 1. Take sample merchants and verify the existence of signed
the WEMA merchant agreements.
agreement prior to going 2. Verify that the agreement has been reviewed by Legal unit.
live for web merchants or 3. Verify that the agreements are signed by authorized personnel
POS deployment. in merchant office.

You might also like