When the reader and pin-pad are not paired or the pairing is lost, the terminal is allowing the transaction to continue without asking for Pin. Is it correct? It's still going online for host approval. Is there any way we can restrict the transaction if the pairing is lost?
It is correct to continue the transaction when PIN PAD is not available. In fact, there is Amex test case Amex L3 AEIPS Test for this (see below)
If you don't want the transaction to go online, you can configure the reader to deny the transaction by setting the DF14 tag Byte 3 bit 5 to "1".