27 controls
As of 9 Oct 2026
As of 9 Oct 2026
| Control | Name | Domain | Applications | Q3 test | Open findings |
|---|---|---|---|---|---|
| ACC-01 | MFA and SSO enforced for workforce access | Access Control | Amazon Web Services (ap-south-1), Microsoft Entra ID, GitHub Enterprise Cloud | Pass | 0 |
| ACC-02 | User access provisioning is approved before grant | Access Control | Microsoft Entra ID, SAP S/4HANA, ServiceNow ITSM | Pass | 0 |
| ACC-03 | Privileged access is just-in-time and reviewed | Access Control | Amazon Web Services (ap-south-1), Microsoft Entra ID, SAP S/4HANA | Fail | 1 |
| ACC-04 | Quarterly user access review of in-scope applications | Access Control | Microsoft Entra ID, Salesforce (Sales + Financial Services Cloud), SAP S/4HANA | Not tested | 0 |
| JML-01 | Leavers are de-provisioned within 24 hours | Joiner/Mover/Leaver | Darwinbox HRMS, Microsoft Entra ID, SAP S/4HANA | Pass | 0 |
| JML-02 | Mover access is recertified on role change | Joiner/Mover/Leaver | Darwinbox HRMS, Microsoft Entra ID, SAP S/4HANA | Fail | 1 |
| SOD-01 | Segregation of incompatible duties in SAP | Segregation of Duties | SAP S/4HANA | Fail | 2 |
| P2P-01 | Purchase orders follow approval thresholds; no self-approval | Procure-to-Pay | SAP S/4HANA | Fail | 1 |
| P2P-02 | Vendor master changes require dual control | Procure-to-Pay | SAP S/4HANA | Pass | 0 |
| CHG-01 | Production code changes are peer-reviewed and approved | Change Management | GitHub Enterprise Cloud, Meridian Customer Portal | Pass | 0 |
| CHG-02 | Emergency changes are retrospectively approved | Change Management | GitHub Enterprise Cloud, ServiceNow ITSM | Fail | 0 |
| CHG-03 | Developers have no standing production access; deployments via pipeline only | Change Management | Amazon Web Services (ap-south-1), GitHub Enterprise Cloud | Pass | 0 |
| VUL-01 | Vulnerabilities are scanned and remediated within SLA | Security Operations | Amazon Web Services (ap-south-1), GitHub Enterprise Cloud | Not tested | 0 |
| LOG-01 | Security events are centrally logged and monitored 24x7 | Logging & Monitoring | Amazon Web Services (ap-south-1), Microsoft Entra ID, Meridian Customer Portal | Pass | 0 |
| LOG-02 | Audit logs retained 180 days online and 5 years archived, tamper-protected | Logging & Monitoring | Amazon Web Services (ap-south-1), SAP S/4HANA | Not tested | 0 |
| OPS-01 | Backups are performed daily and monitored | Operations & Resilience | Amazon Web Services (ap-south-1), Microsoft Azure (corporate) | Pass | 0 |
| BCP-01 | Backup restore and DR are tested | Operations & Resilience | Amazon Web Services (ap-south-1), Microsoft Azure (corporate) | Pass | 0 |
| ENC-01 | Customer and payment data encrypted at rest and in transit | Data Protection | Amazon Web Services (ap-south-1), Meridian Customer Portal | Pass | 0 |
| VEN-01 | Critical third parties are risk-assessed before onboarding and annually | Third-Party Risk | PayGate Payment Gateway, Salesforce (Sales + Financial Services Cloud) | Fail | 1 |
| VEN-02 | Provider contracts include data protection and RBI audit clauses | Third-Party Risk | Salesforce (Sales + Financial Services Cloud) | Not tested | 1 |
| VEN-03 | Supplier security incidents are assessed for impact and tracked | Third-Party Risk | PayGate Payment Gateway, Meridian Customer Portal | Fail | 1 |
| KYC-01 | Customer accounts are activated only with complete KYC | Customer Onboarding | Meridian Customer Portal, Salesforce (Sales + Financial Services Cloud) | Fail | 1 |
| KYC-02 | Periodic KYC updation based on customer risk | Customer Onboarding | Salesforce (Sales + Financial Services Cloud) | Not tested | 0 |
| PAY-01 | Payment APIs secured with mTLS, signing and customer 2FA | Payments Security | PayGate Payment Gateway, Meridian Customer Portal | Pass | 0 |
| PAY-02 | Payment release requires maker-checker | Payments Security | SAP S/4HANA | Pass | 0 |
| GOV-01 | IT Strategy Committee oversees IT and cyber risk | Governance | Meridian Customer Portal | Pass | 0 |
| GOV-02 | RBI regulatory changes are assessed for impact within 30 days | Governance | Meridian Customer Portal | Not tested | 0 |