CUSTOMER ASSURANCE RESPONSE PACK
Supplier assessment response for Northstar Bank AG
Lumen Payments GmbH responding to Northstar Bank AG
Approved and submitted
01What this response covers
Counts are taken from the submitted snapshot, so the pack always matches what was actually sent.
02Coverage by topic
The assessment is never only about security. Each topic shows how many requirements carry an approved answer.
03Answers and their sources
Four of the 42 answers are shown. Each one keeps the fact version and the document version it was written from.
REQUIREMENT 07 · INFORMATION SECURITY
Describe how access to production systems holding bank data is granted, reviewed and revoked, and state the review frequency.
Access to production systems is granted only through documented role requests approved by the system owner. Roles follow least privilege and are reviewed quarterly by the Head of Security, who records the outcome of each review. Leavers are revoked within one working day through the joiner-mover-leaver process, and revocation is confirmed against the HR record.
SOURCES BEHIND THIS ANSWER- Fact: Access review frequency · quarterly (v4, approved 04 Mar 2026)
- Document: Access Control Policy v3.2 (uploaded 11 Feb 2026)
- Document: Q1 2026 access review record (uploaded 02 Apr 2026)
Approved by J. Roth, Head of Security · 12 June 2026
REQUIREMENT 19 · OPERATIONAL RESILIENCE
State your recovery time objective and recovery point objective for the service, and confirm when they were last tested.
The recovery time objective for card settlement reporting is four hours and the recovery point objective is 15 minutes. Both were tested in the failover exercise of 18 April 2026, which met the objectives. The exercise report and the corrective action from it are attached to this response.
SOURCES BEHIND THIS ANSWER- Fact: RTO 4h · RPO 15min (v2, approved 21 Apr 2026)
- Document: Failover exercise report, 18 Apr 2026 (uploaded 22 Apr 2026)
Approved by M. Chen, Platform Operations · 12 June 2026
REQUIREMENT 24 · SUBCONTRACTORS
List the subcontractors that process bank data, the country of processing, and the notice period for changes.
Three subcontractors process data for this service: the cloud platform provider (Ireland), the transactional email provider (Germany) and the error-monitoring provider (Netherlands). The current list, including processing purpose and location, is maintained in the subprocessor register attached. Material changes are notified at least 30 days in advance, and the contract gives Northstar Bank the right to object within that period.
SOURCES BEHIND THIS ANSWER- Document: Subprocessor register v6 (uploaded 09 Jun 2026)
- Document: Master services agreement, clause 14.3 (uploaded 06 Jan 2026)
Approved by A. Novak, Legal Counsel · 12 June 2026
REQUIREMENT 31 · CERTIFICATIONS
Provide your current ISO 27001 certificate or equivalent, including scope and expiry date.
Lumen Payments holds ISO/IEC 27001:2022 certification covering the development and operation of the card settlement reporting service. The certificate, issued 14 January 2026 and valid to 13 January 2029, is attached with the statement of applicability. The surveillance audit is scheduled for November 2026 and the date is tracked as a commitment to Northstar Bank.
SOURCES BEHIND THIS ANSWER- Fact: ISO 27001 certificate expiry · 13 Jan 2029 (v1, approved 20 Jan 2026)
- Document: ISO 27001 certificate (uploaded 20 Jan 2026)
Approved by J. Roth, Head of Security · 12 June 2026
04Open items sent with the response
Gaps are disclosed rather than hidden, each with the person who owns it and the date it is due.
| Item | Why it is still open | Owner | Due | Status |
|---|---|---|---|---|
| Penetration test summary, 2026 | The customer asks for a test no older than 12 months. The most recent report on file is from May 2025. | J. Roth, Head of Security | 30 June 2026 | Due soon |
| Exit and data-return plan for the service | A draft exists but has not been approved internally, so it is not being shared with the customer yet. | A. Novak, Legal Counsel | 15 July 2026 | Open |
| Fourth-party notification in the cloud provider contract | The customer asked whether the 30-day notice reaches fourth parties. The clause is being confirmed with the provider. | S. Iqbal, Vendor Manager | 22 July 2026 | Open |
05What happens after go-live
The commitments this customer is owed, taken from the contract and the assessment, with the next date for each.
| Commitment | Frequency | Owner | Next |
|---|---|---|---|
| Quarterly service performance report | Every quarter, 10 working days after period end | M. Chen, Platform Operations | Next: 14 Jul 2026 |
| Penetration test summary | Annually | J. Roth, Head of Security | Next: 30 Jun 2026 |
| Notice of subcontractor changes | At least 30 days before any change | S. Iqbal, Vendor Manager | Ongoing |
| Annual supplier reassessment | Annually, on the anniversary of go-live | Customer-led | Next: 12 Jun 2027 |
06How a pack like this is produced
AI drafts from your own material
MatchAudit reads the customer’s request, matches each requirement to facts and documents your team has approved, and writes a draft answer with the source attached.
Your team approves every answer
Nothing reaches the customer without a named approver. The approval, the person and the date stay with the answer.
The snapshot does not move
Later document versions are used for later work. What you sent on the day stays exactly as it was sent, so follow-up questions are answered from the right facts.
About this sample. Lumen Payments GmbH and Northstar Bank AG do not exist. Every name, date, reference, certificate and document in this pack is invented to show the structure of a response, not to describe any real company or assessment outcome. The layout reflects the record MatchAudit keeps for a submitted response; the exact fields depend on what your customer asks for and what your team approves. Nothing here is legal or regulatory advice, and no regulator has reviewed or endorsed this format.