Control · GOV-01
IT Strategy Committee oversees IT and cyber risk
GovernanceSOC 2 · ISO 27001 · RBIRisk Medium
Requirement to validation
Requirement
ISO-A.5.1 · RBI-ITGRCA-2023-11 · RBI-ITGRCA-2023-3 · SOC2-CC1.2
mapped
Policy
IT Governance Policy (RBI-aligned)
pol-itgov
Control
GOV-01
IT Strategy Committee oversees IT and cyber risk
Application
Meridian Customer Portal
mapped
Evidence · Q3
2 items
1 approved · 1 pending · 0 rejected
Test · Q3
Pass
TST-RBI-GOV-01 · High confidence
Finding
None
Action
None
Validation
Not planned
What should be true
The Board's IT Strategy Committee meets at least quarterly, reviews IT/cyber risk, IS audit results and major incidents, and minutes are retained.
- Requirements
- ISO-A.5.1 A.5.1 · Policies for information securityRBI-ITGRCA-2023-11 RBI-ITGRCA-2023 §11 · Information systems audit — risk-based periodic IS audit (RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023)RBI-ITGRCA-2023-3 RBI-ITGRCA-2023 §3 · IT Governance — Board-approved IT strategy; IT Strategy Committee oversight (RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023)SOC2-CC1.2 CC1.2 · Board independence and oversight of internal control
- Applications
- Meridian Customer Portal
- Third parties
- —
- Testing procedure
- ITSC calendar; minutes uploaded to Prismet. Tests: Meridian Customer Portal: ITSC minutes uploaded for quarter. Frequency quarterly.
Findings (0)
○ No data available
Evidence (3)
| Evidence | Title | Control | Source system | Collected | Status |
|---|---|---|---|---|---|
| Q2-EV-042 | Meridian Customer Portal · ticket sample (Q2) | GOV-01 | Meridian Customer Portal | 21 Jun 2026 | Accepted |
| RBI-REQ-001 | Meridian Customer Portal: ITSC minutes uploaded for quarter | GOV-01 | Meridian Customer Portal | 9 Oct 2026 | Accepted |
| SOC2-REQ-045 | Meridian Customer Portal: ITSC minutes uploaded for quarter | GOV-01 | Meridian Customer Portal | 8 Oct 2026 | Under review |
Tests (2)
| Test | Control | Cycle | Tested | By | Result | Confidence |
|---|---|---|---|---|---|---|
| TST-RBI-GOV-01 | GOV-01 · IT Strategy Committee oversees IT and cyber risk | Q3 2026 Unified Program Review | 2 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell) | Pass | High |
| TST-Q2-GOV-01 | GOV-01 · IT Strategy Committee oversees IT and cyber risk | Q2 2026 Unified Program Review | 12 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Pass | Medium |