The erased limit change
An administrator changes a refund limit and later removes the application log entry. A reviewer then sees only the refund, not the rule change that allowed it. Send audit events to a separate write path with restricted deletion rights, and check that every sensitive action has a linked decision record.
Log the decision and the result
For sensitive actions, record the actor ID, role, request ID, payment ID, action, decision, result, and timestamp. Keep secrets and full payment credentials out of the log. OWASP ASVS calls for logging authentication operations and failed authorization attempts.
Separate storage and access
Send events to storage that the payment service cannot rewrite after delivery. Limit deletion rights and track changes to retention settings. A hash chain can show a missing or changed record, but it only helps if its checkpoints are kept outside the same editable store.
Avoid logging sensitive payloads
Log who made the decision, what policy version applied, and which object changed. Do not copy full card data, authentication secrets, or identity documents into the audit event. When an investigator needs a source record, store a protected reference rather than the whole payload. Test redaction on successful and denied actions because error paths often log raw requests. Keep a retention rule for both the audit trail and its off-system checkpoints.
Verify edits, omissions, and delivery gaps
Test three different failures. First, change event 42 in a copied sequence 41–43; its digest must fail against a trusted checkpoint. Next, delete 42; sequence and chain checks must show the gap. Finally, omit the whole event pair for action A-2 while retaining valid events for A-1 and A-3. Compare required action IDs with logged action IDs to find A-2. A valid chain cannot prove that an action was logged in the first place.
Case PAY-06 covers a deleted middle event. PAY-06B checks missing decision and outcome pairs under a test rule that requires both. Define your own event contract: a denied action needs its decision record; it does not need a made-up execution result. Keep checkpoint sequence ranges and expected counts outside the payment administrator’s write access so a missing final batch is visible too.
Stop the log sink during a limit change. For high-risk changes, choose a written rule: block the change, or commit a durable audit outbox row with the change and alert on delivery delay. Record oldest unsent event, queue count, retry state, and the person paged. Recovery must drain the queue without editing the original records. Retention expiry and key rotation need their own dated audit events and verification policy.
Evidence to retain
Keep the event sequence, off-system checkpoint, integrity-check result, and alert from a deleted test event. A normal application log file alone is weak proof.
Sources
Put this into practice
Choose one high risk action, such as raising a payout limit, and test its log path through creation, storage, review, and retention. See our what to look for in a pentest report and payment gateway testing service. To check a live flow, request a security review.