Meridian Alpha

Records

57 tests
As of 9 Oct 2026
TestControlCycleTestedByResultConfidence
TST-ISO-BCP-01BCP-01 · Backup restore and DR are testedQ3 2026 Unified Program Review7 Oct 2026Suresh Pillai · Northgate Certification ServicesPassHigh
TST-ITGC-ACC-02ACC-02 · User access provisioning is approved before grantQ3 2026 Unified Program Review7 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal AuditPassHigh
TST-ITGC-P2P-02P2P-02 · Vendor master changes require dual controlQ3 2026 Unified Program Review7 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal AuditPassHigh
TST-RBI-OPS-01OPS-01 · Backups are performed daily and monitoredQ3 2026 Unified Program Review7 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)PassHigh
TST-ITGC-P2P-01P2P-01 · Purchase orders follow approval thresholds; no self-approvalQ3 2026 Unified Program Review6 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal AuditFailMedium
TST-RBI-CHG-01CHG-01 · Production code changes are peer-reviewed and approvedQ3 2026 Unified Program Review6 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)PassHigh
TST-RBI-PAY-02PAY-02 · Payment release requires maker-checkerQ3 2026 Unified Program Review6 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)PassHigh
TST-ITGC-PAY-02PAY-02 · Payment release requires maker-checkerQ3 2026 Unified Program Review5 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal AuditPassHigh
TST-ITGC-SOD-01SOD-01 · Segregation of incompatible duties in SAPQ3 2026 Unified Program Review5 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal AuditFailMedium
TST-RBI-PAY-01PAY-01 · Payment APIs secured with mTLS, signing and customer 2FAQ3 2026 Unified Program Review5 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)PassHigh
TST-RBI-SOD-01SOD-01 · Segregation of incompatible duties in SAPQ3 2026 Unified Program Review5 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)FailMedium
TST-ITGC-JML-02JML-02 · Mover access is recertified on role changeQ3 2026 Unified Program Review4 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal AuditFailHigh
TST-ITGC-OPS-01OPS-01 · Backups are performed daily and monitoredQ3 2026 Unified Program Review4 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal AuditPassHigh
TST-RBI-JML-02JML-02 · Mover access is recertified on role changeQ3 2026 Unified Program Review4 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)FailHigh
TST-RBI-KYC-01KYC-01 · Customer accounts are activated only with complete KYCQ3 2026 Unified Program Review4 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)FailMedium
TST-ITGC-CHG-03CHG-03 · Developers have no standing production access; deployments via pipeline onlyQ3 2026 Unified Program Review3 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal AuditPassHigh
TST-ITGC-JML-01JML-01 · Leavers are de-provisioned within 24 hoursQ3 2026 Unified Program Review3 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal AuditPassHigh
TST-RBI-ACC-01ACC-01 · MFA and SSO enforced for workforce accessQ3 2026 Unified Program Review3 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)PassHigh
TST-RBI-VEN-03VEN-03 · Supplier security incidents are assessed for impact and trackedQ3 2026 Unified Program Review3 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)FailHigh
TST-SOC2-ACC-01ACC-01 · MFA and SSO enforced for workforce accessQ3 2026 Unified Program Review3 Oct 2026Laura Bennett · Kestrel Assurance LLPPassHigh
TST-SOC2-ACC-02ACC-02 · User access provisioning is approved before grantQ3 2026 Unified Program Review3 Oct 2026Laura Bennett · Kestrel Assurance LLPPassHigh
TST-SOC2-CHG-01CHG-01 · Production code changes are peer-reviewed and approvedQ3 2026 Unified Program Review3 Oct 2026Laura Bennett · Kestrel Assurance LLPPassHigh
TST-SOC2-CHG-02CHG-02 · Emergency changes are retrospectively approvedQ3 2026 Unified Program Review3 Oct 2026Laura Bennett · Kestrel Assurance LLPFailHigh
TST-SOC2-ENC-01ENC-01 · Customer and payment data encrypted at rest and in transitQ3 2026 Unified Program Review3 Oct 2026Laura Bennett · Kestrel Assurance LLPPassHigh
TST-SOC2-JML-01JML-01 · Leavers are de-provisioned within 24 hoursQ3 2026 Unified Program Review3 Oct 2026Laura Bennett · Kestrel Assurance LLPPassHigh
TST-SOC2-JML-02JML-02 · Mover access is recertified on role changeQ3 2026 Unified Program Review3 Oct 2026Laura Bennett · Kestrel Assurance LLPFailHigh
TST-SOC2-LOG-01LOG-01 · Security events are centrally logged and monitored 24x7Q3 2026 Unified Program Review3 Oct 2026Laura Bennett · Kestrel Assurance LLPPassHigh
TST-SOC2-OPS-01OPS-01 · Backups are performed daily and monitoredQ3 2026 Unified Program Review3 Oct 2026Laura Bennett · Kestrel Assurance LLPPassHigh
TST-ITGC-ACC-03ACC-03 · Privileged access is just-in-time and reviewedQ3 2026 Unified Program Review2 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal AuditFailMedium
TST-ITGC-CHG-01CHG-01 · Production code changes are peer-reviewed and approvedQ3 2026 Unified Program Review2 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal AuditPassHigh
TST-RBI-GOV-01GOV-01 · IT Strategy Committee oversees IT and cyber riskQ3 2026 Unified Program Review2 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)PassHigh
TST-RBI-VEN-01VEN-01 · Critical third parties are risk-assessed before onboarding and annuallyQ3 2026 Unified Program Review2 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)FailMedium
TST-RBI-BCP-01BCP-01 · Backup restore and DR are testedQ3 2026 Unified Program Review1 Oct 2026Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell)PassHigh
TST-Q2-BCP-01BCP-01 · Backup restore and DR are testedQ2 2026 Unified Program Review20 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPass with ObservationMedium
TST-Q2-JML-01JML-01 · Leavers are de-provisioned within 24 hoursQ2 2026 Unified Program Review20 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPass with ObservationHigh
TST-Q2-KYC-01KYC-01 · Customer accounts are activated only with complete KYCQ2 2026 Unified Program Review20 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPass with ObservationHigh
TST-Q2-ACC-02ACC-02 · User access provisioning is approved before grantQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh
TST-Q2-ACC-03ACC-03 · Privileged access is just-in-time and reviewedQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh
TST-Q2-ACC-04ACC-04 · Quarterly user access review of in-scope applicationsQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailMedium
TST-Q2-CHG-01CHG-01 · Production code changes are peer-reviewed and approvedQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh
TST-Q2-CHG-02CHG-02 · Emergency changes are retrospectively approvedQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh
TST-Q2-CHG-03CHG-03 · Developers have no standing production access; deployments via pipeline onlyQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh
TST-Q2-LOG-01LOG-01 · Security events are centrally logged and monitored 24x7Q2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh
TST-Q2-OPS-01OPS-01 · Backups are performed daily and monitoredQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh
TST-Q2-P2P-01P2P-01 · Purchase orders follow approval thresholds; no self-approvalQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh
TST-Q2-PAY-01PAY-01 · Payment APIs secured with mTLS, signing and customer 2FAQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh
TST-Q2-SOD-01SOD-01 · Segregation of incompatible duties in SAPQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailMedium
TST-Q2-VEN-01VEN-01 · Critical third parties are risk-assessed before onboarding and annuallyQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailMedium
TST-Q2-VUL-01VUL-01 · Vulnerabilities are scanned and remediated within SLAQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh
TST-Q2-ACC-01ACC-01 · MFA and SSO enforced for workforce accessQ2 2026 Unified Program Review12 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPassHigh
TST-Q2-ENC-01ENC-01 · Customer and payment data encrypted at rest and in transitQ2 2026 Unified Program Review12 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPassHigh
TST-Q2-GOV-01GOV-01 · IT Strategy Committee oversees IT and cyber riskQ2 2026 Unified Program Review12 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPassMedium
TST-Q2-JML-02JML-02 · Mover access is recertified on role changeQ2 2026 Unified Program Review12 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPassHigh
TST-Q2-P2P-02P2P-02 · Vendor master changes require dual controlQ2 2026 Unified Program Review12 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPassHigh
TST-Q2-PAY-02PAY-02 · Payment release requires maker-checkerQ2 2026 Unified Program Review12 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPassHigh
TST-Q2-VEN-02VEN-02 · Provider contracts include data protection and RBI audit clausesQ2 2026 Unified Program Review12 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPassHigh
TST-Q2-VEN-03VEN-03 · Supplier security incidents are assessed for impact and trackedQ2 2026 Unified Program Review12 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPassHigh