Acquiring and refund control testing
Targeted tests of the automated and people-dependent controls that protect authorisation rules, voids, refunds, and release of settlement.
When the application is already in production and the question is whether its controls actually operated in the period, we test them. Typical coverage includes who can change merchant limits, who can issue a refund above a threshold, maker-checker on voiding, completeness of capture against authorisation, and the lock that is supposed to freeze a settlement file before it leaves.
We design tests from the control description you already use, or from a walkthrough if that description is missing. Evidence is taken from application logs, ticket records, and the settlement run itself — not from a policy binder alone.
This engagement is often commissioned after an internal finding, ahead of an external review, or when a payments owner has changed. It can stand alone or feed the payment application audit.