24 tests
As of 9 Oct 2026
As of 9 Oct 2026
Filtered byResult: Fail ✕
| Test | Control | Cycle | Tested | By | Result | Confidence |
|---|---|---|---|---|---|---|
| TST-ITGC-P2P-01 | P2P-01 · Purchase orders follow approval thresholds; no self-approval | Q3 2026 Unified Program Review | 6 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit | Fail | Medium |
| TST-ITGC-SOD-01 | SOD-01 · Segregation of incompatible duties in SAP | Q3 2026 Unified Program Review | 5 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit | Fail | Medium |
| TST-RBI-SOD-01 | SOD-01 · Segregation of incompatible duties in SAP | Q3 2026 Unified Program Review | 5 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell) | Fail | Medium |
| TST-ITGC-JML-02 | JML-02 · Mover access is recertified on role change | Q3 2026 Unified Program Review | 4 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit | Fail | High |
| TST-RBI-JML-02 | JML-02 · Mover access is recertified on role change | Q3 2026 Unified Program Review | 4 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell) | Fail | High |
| TST-RBI-KYC-01 | KYC-01 · Customer accounts are activated only with complete KYC | Q3 2026 Unified Program Review | 4 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell) | Fail | Medium |
| TST-RBI-VEN-03 | VEN-03 · Supplier security incidents are assessed for impact and tracked | Q3 2026 Unified Program Review | 3 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell) | Fail | High |
| TST-SOC2-CHG-02 | CHG-02 · Emergency changes are retrospectively approved | Q3 2026 Unified Program Review | 3 Oct 2026 | Laura Bennett · Kestrel Assurance LLP | Fail | High |
| TST-SOC2-JML-02 | JML-02 · Mover access is recertified on role change | Q3 2026 Unified Program Review | 3 Oct 2026 | Laura Bennett · Kestrel Assurance LLP | Fail | High |
| TST-ITGC-ACC-03 | ACC-03 · Privileged access is just-in-time and reviewed | Q3 2026 Unified Program Review | 2 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit | Fail | Medium |
| TST-RBI-VEN-01 | VEN-01 · Critical third parties are risk-assessed before onboarding and annually | Q3 2026 Unified Program Review | 2 Oct 2026 | Vikram Mehta, Farah Khan · Meridian Internal Audit (IS Audit cell) | Fail | Medium |
| TST-Q2-ACC-02 | ACC-02 · User access provisioning is approved before grant | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |
| TST-Q2-ACC-03 | ACC-03 · Privileged access is just-in-time and reviewed | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |
| TST-Q2-ACC-04 | ACC-04 · Quarterly user access review of in-scope applications | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | Medium |
| TST-Q2-CHG-01 | CHG-01 · Production code changes are peer-reviewed and approved | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |
| TST-Q2-CHG-02 | CHG-02 · Emergency changes are retrospectively approved | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |
| TST-Q2-CHG-03 | CHG-03 · Developers have no standing production access; deployments via pipeline only | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |
| TST-Q2-LOG-01 | LOG-01 · Security events are centrally logged and monitored 24x7 | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |
| TST-Q2-OPS-01 | OPS-01 · Backups are performed daily and monitored | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |
| TST-Q2-P2P-01 | P2P-01 · Purchase orders follow approval thresholds; no self-approval | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |
| TST-Q2-PAY-01 | PAY-01 · Payment APIs secured with mTLS, signing and customer 2FA | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |
| TST-Q2-SOD-01 | SOD-01 · Segregation of incompatible duties in SAP | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | Medium |
| TST-Q2-VEN-01 | VEN-01 · Critical third parties are risk-assessed before onboarding and annually | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | Medium |
| TST-Q2-VUL-01 | VUL-01 · Vulnerabilities are scanned and remediated within SLA | Q2 2026 Unified Program Review | 18 Jun 2026 | Farah Khan, Vikram Mehta · Meridian Internal Audit | Fail | High |