Finding · F-IAQ2-CHG-03

Developers held standing production access

Fraud indicator
Rating
No
High
Medium
Low

Requirement to validation

Observation
Raised 2026-06-20 in the Q2 2026 internal audit baseline. Five developers retained console access to the production EKS cluster outside the deployment pipeline.
Applications: Amazon Web Services (ap-south-1), GitHub Enterprise Cloud.
Potential risk
Unauthorised or erroneous transactions could go undetected and expose Meridian to financial loss and regulatory action.
Root cause
Break-glass access granted during an incident in April was never revoked.
Agreed action plan

Remediate: developers held standing production access.

Management response: Management agreed and committed to remediate before the Q3 review.

Owner (FPR)
Aditya Singh
Target date
31 Jul 2026
Priority
High
Status
Closed

Evidence for this control (5)

Open list →
EvidenceTitleControlSource systemCollectedStatus
ITGC-REQ-025GitHub: Production environment requires reviewersCHG-035 Oct 2026Accepted
ITGC-REQ-026AWS: No developer roles with prod writeCHG-034 Oct 2026Accepted
Q2-EV-020GitHub Enterprise Cloud · system export (Q2)CHG-03GitHub Enterprise Cloud7 Jun 2026Rejected
Q2-EV-021Amazon Web Services (ap-south-1) · configuration report (Q2)CHG-03Amazon Web Services (ap-south-1)12 Jun 2026Rejected
SOC2-REQ-024GitHub: Production environment requires reviewersCHG-037 Oct 2026Under review

Tests of this control (2)

Open list →
TestControlCycleTestedByResultConfidence
TST-ITGC-CHG-03CHG-03 · Developers have no standing production access; deployments via pipeline onlyQ3 2026 Unified Program Review3 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal AuditPassHigh
TST-Q2-CHG-03CHG-03 · Developers have no standing production access; deployments via pipeline onlyQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh