Application · app-salesforce
Salesforce (Sales + Financial Services Cloud)
Controls (5)
| Control | Name | Domain | Applications | Q3 test | Open findings |
|---|---|---|---|---|---|
| ACC-04 | Quarterly user access review of in-scope applications | Access Control | Microsoft Entra ID, Salesforce (Sales + Financial Services Cloud), SAP S/4HANA | Not tested | 0 |
| VEN-01 | Critical third parties are risk-assessed before onboarding and annually | Third-Party Risk | PayGate Payment Gateway, Salesforce (Sales + Financial Services Cloud) | Fail | 1 |
| VEN-02 | Provider contracts include data protection and RBI audit clauses | Third-Party Risk | Salesforce (Sales + Financial Services Cloud) | Not tested | 1 |
| KYC-01 | Customer accounts are activated only with complete KYC | Customer Onboarding | Meridian Customer Portal, Salesforce (Sales + Financial Services Cloud) | Fail | 1 |
| KYC-02 | Periodic KYC updation based on customer risk | Customer Onboarding | Salesforce (Sales + Financial Services Cloud) | Not tested | 0 |
Open findings (3)
| Finding | Observation | Control | Applications | Severity | Status | Owner | Action | Validation |
|---|---|---|---|---|---|---|---|---|
| F-RBI-04 | Credit line activated before KYC completion (KYC MD §16) | KYC-01 | Meridian Customer Portal, Salesforce (Sales + Financial Services Cloud) | High | Open | Arjun Kapoor | REM-F-RBI-04 · In Progress | Pending |
| F-ISO-02 | Supplier agreement lacks information security clauses (A.5.20) | VEN-02 | Salesforce (Sales + Financial Services Cloud) | Medium | Open | Sanjay Kulkarni | REM-F-ISO-02 · In Progress | Pending |
| F-RBI-02 | Material outsourcing: lapsed assurance and overdue reassessment (Outsourcing of IT Services 2023 §6/§9) | VEN-01 | PayGate Payment Gateway, Salesforce (Sales + Financial Services Cloud) | Medium | Open | Sanjay Kulkarni | REM-F-RBI-02 · Open | Pending |