Inspection Body
Scheme for Inspection of Critical Sector Entities
AWARDS &
RECOGNITIONS







See how brands like yours secure their IoT products with Payatu.
AWARDS &
RECOGNITIONS
See how brands like yours secure their IoT products with Payatu.
Payatu Security Consulting Pvt. Ltd. (“Payatu”) provides independent inspection services in accordance with applicable inspection criteria, contractual requirements, and relevant regulatory/scheme requirements.
Our inspection services validate the security posture of an organization’s Critical Information Infrastructure (CII) through independent, technical testing and assessment complementing management-system-focused certifications such as CSMS (Cyber Security Management System).
Payatu operates as a Type A Inspection Body as defined under ISO/IEC 17020:2012. As a Type A inspection body, Payatu is independent of the parties involved in the items it inspects and does not engage in the design, manufacture, supply, installation, purchase, ownership, use, or maintenance of the items inspected. Payatu is not linked to any separate legal entity engaged in such activities through common ownership, common appointees, shared higher-level management, or contractual commitments that could influence the outcome of an inspection.
Payatu provides inspection services within the scope defined in its approved scheme(s), competence framework, and applicable contractual/regulatory requirements. The scope of inspection services may include, as applicable:
The exact scope, criteria, deliverables, and methodology applicable to a particular inspection engagement shall be defined in the proposal/agreement.
Payatu is a certified inspection body for the following types of management system inspections:
The audit criteria for each scheme are as outlined in the applicable ISO standard (e.g. ISO/IEC 27001:2022) and any other normative documents specified by the relevant scheme owner. Where a client requires an explanation of how these criteria apply to its specific inspection programme, this is provided by Payatu’s inspection committee.
Payatu is committed to maintaining impartiality, objectivity, and independence in all inspection activities. To safeguard impartiality:
Payatu reviews impartiality risks on an ongoing basis and takes appropriate action to eliminate or minimize such risks. This process is overseen by Payatu’s committee for safeguarding impartiality, which meets at least annually to review identified risks and the effectiveness of mitigating actions.
Payatu respects the confidentiality of all information obtained or created during the course of inspection activities. Accordingly:
Payatu follows a defined inspection process to ensure that inspection activities are planned, executed, reviewed, and reported consistently.
The inspection process begins when a prospective client submits an enquiry or request for inspection, typically by completing an application form covering basic organizational information, the people involved, and operational processes. Payatu may obtain further relevant information such as:
Payatu reviews the request to determine: whether the scope of work is clearly defined; whether Payatu has the competence and resources to perform the inspection; whether impartiality or conflict-of-interest risks exist; whether the inspection criteria are appropriate and agreed; and whether any subcontracting, remote assessment, or special arrangements are necessary.
Based on this review, Payatu furnishes a proposal to the client containing complete details, including costing, methodology, requirements, accreditation scope, timescales, terms and conditions, and general requirements.
Following the client’s acceptance of the proposal, an agreement is signed between the client and Payatu. Payatu confirms the inspection scope, applicable criteria, timelines, and deliverables. The inspection is scheduled only after the requirements are adequately understood and agreed by both parties.
Post-agreement,Payatu prepares a detailed audit/inspection plan, which is shared with and agreed upon by the client. The plan may include, as applicable: scope and objectives of inspection; inspection criteria/references; inspection locations/systems/processes; inspection dates and timelines; assigned inspection personnel; sampling approach where relevant; documentation/access requirements; and reporting and communication arrangements.
The inspection may be carried out on-site, remotely, or through a combination of methods, depending on the nature of the inspection and applicable requirements. For management system inspections, the inspection is conducted in two stages:
At the conclusion of the inspection, Payatu documents the inspection outcome in an inspection report or other applicable inspection document. The inspection output may include, as applicable: identification of the client/inspected entity; description of the subject of inspection; scope and criteria of inspection; date(s) of inspection; inspection activities performed; observations, findings, and conclusions; nonconformities/deviations/opportunities for improvement, where applicable; limitations, exclusions, or conditions affecting the inspection outcome; and authorized approval/issue details.
Following the inspection stage, once corrective actions (where required) have been verified, the inspector recommends certification to Payatu’s inspection committee, which comprises three members. The inspection decision is taken by person(s) different from those who carried out the inspection. The committee’s review includes:
Upon verification of the inspector’s report and acceptance by the committee, the certificate is granted to the client within fifteen working days of verification of corrective actions.
Where the inspection scheme, contract, or nature of findings requires follow-up verification, Payatu may conduct a follow-up or repeat inspection to verify corrective actions or reassess the inspected scope.
Re-inspection audits are carried out to verify the continuing effectiveness, improvement, and achievement of the client’s policies and objectives. These audits follow the same Inspection Process described in Section 5 above.
PAYATU does not, in the normal course of events, suspend certified clients, and will only do so under exceptional circumstances and on a case-by-case basis. While a certificate is under suspension, the certified management system is invalid until the suspension is lifted; this is reflected on PAYATU’s client directory. Circumstances that may lead to suspension include, but are not limited to:
Failure to resolve the issues that resulted in a suspension within the time established by PAYATU may result in withdrawal or reduction of the scope of inspection.
Intermediate audits may be carried out in the following scenarios:
Information about certificates granted, suspended, or withdrawn, and the means to confirm the validity of a given certificate, is maintained by PAYATU. For ISO/IEC 27001:2022 certificates, validity can be confirmed via www.iafcertsearch.org. Certificate status information is updated within 90 days of the date of release of the certificate, or of any subsequent update to that information.
To enable Payatu to perform inspection activities effectively, clients are expected to:
Payatu has a documented process for handling complaints relating to its inspection activities, personnel, conduct, or inspection outputs. A complaint may be submitted by a client or any interested party, by e-mail, fax, written, or verbal means, through the designated communication channels of Payatu. Payatu accepts complaints only with proper identification of the complainant, and acknowledges receipt of each complaint.
Complaint handling principles:
Confidentiality is maintained throughout the complaint handling process, both as it relates to the complainant and to the subject of the complaint. Progress on complaint handling is shown to and discussed with Payatu’s impartiality committee.
Payatu has a documented process for handling complaints relating to its inspection activities, personnel, conduct, or inspection outputs. A complaint may be submitted by a client or any interested party, by e-mail, fax, written, or verbal means, through the designated communication channels of Payatu. Payatu accepts complaints only with proper identification of the complainant, and acknowledges receipt of each complaint.
Complaint handling principles:
Confidentiality is maintained throughout the complaint handling process, both as it relates to the complainant and to the subject of the complaint. Progress on complaint handling is shown to and discussed with Payatu’s impartiality committee.
Clients shall not use Payatu’s name, logo, inspection mark, inspection reports, certificates, or references to inspection in a misleading or unauthorized manner.Payatu has a legally enforceable arrangement with certified clients covering the following conditions of use:
Misuse of inspection outputs, status, or marks, or incorrect reference to inspection status, may result in Payatu requesting corrective action, suspension or withdrawal of the certificate, publication of the transgression, or, where necessary, legal action.
For enquiries regarding inspection services, complaints, appeals, or verification of inspection-related information, clients and interested parties may contact Payatu through the official communication channels published here as.
Payatu Security Consulting Pvt. Ltd.
Office no. 704 (7th floor, Sky Vista, Mhada Colony, Viman Nagar, Pune, Maharashtra 411014
Email : [email protected]
TRUSTED BY BRANDS AROUND THE WORLD


















Fill in your details and get your copy of the datasheet in few seconds
Fill in your details and get your copy of the ebook in your inbox
Fill in your details and get your copy of sample report in few seconds
Fill in your details and get your copy of sample report in few seconds
Fill in your details and get your copy of sample report in few seconds
Fill in your details and get your copy of sample report in few seconds
Fill in your details and get your copy of sample report in few seconds
Fill in your details and get your copy of sample report in few seconds
Fill in your details and get your copy of sample report in few seconds
Fill in your details and get your copy of sample report in few seconds
Fill in your details and get your copy of sample report in few seconds
Fill in your details and get your copy of sample report in few seconds
Let’s make cyberspace secure together!
Requirements
What our clients are saying!
Trusted by