Test · TST-Q2-GOV-01
GOV-01 · IT Strategy Committee oversees IT and cyber risk
PassQ2 2026 Unified Program ReviewTested 12 Jun 2026 by Farah Khan, Vikram Mehta · Meridian Internal Audit
Requirement to validation
Requirement
ISO-A.5.1 · RBI-ITGRCA-2023-11 · RBI-ITGRCA-2023-3 · SOC2-CC1.2
mapped
Policy
IT Governance Policy (RBI-aligned)
pol-itgov
Control
GOV-01
IT Strategy Committee oversees IT and cyber risk
Application
Meridian Customer Portal
mapped
Evidence · Q3
2 items
1 approved · 1 pending · 0 rejected
Test · Q3
Pass
TST-RBI-GOV-01 · High confidence
Finding
None
Action
None
Validation
Not planned
Procedure and result
- Procedure
- ITSC calendar; minutes uploaded to Prismet. Tests: Meridian Customer Portal: ITSC minutes uploaded for quarter. Frequency quarterly.
- Sample
- 4 items sampled (Q2 baseline)
- Expected
- The Board's IT Strategy Committee meets at least quarterly, reviews IT/cyber risk, IS audit results and major incidents, and minutes are retained.
- Observed
- No exceptions in the sample; board-level IT governance operated as designed.
- Confidence
- Medium
- Evidence
- Q2-EV-042