Meridian Alpha

Regulatory Intelligence

Entered in Prismet
Effective 1 Apr 2027
Obligation changes
4
from RBI update
Material
2
require control change
Policies affected
3
revision required
Controls affected
6
3 with a gap
Actions open
3
3 owners
Population
—
No data available

What this change affects

Pulses follow recorded relationships from the event to the people who must act.
RegulationObligationsPoliciesControlsOwners · actionsRBI · Strengthening cyber…effective 1 Apr 2027Audit-log retention and t…Changed · MaterialPayment API security and …Clarified · MaterialRegulatory change impact …New · ModerateThird-party incident repo…Clarified · Moderatepol-itgov · IT Governance…Revision requiredpol-payments · Payments S…Revision requiredpol-logging · Logging & S…Revision requiredPAY-01 · Payment APIs sec…Operating · key rotation in pro…LOG-01 · Security events …OperatingLOG-02 · Audit logs retai…AI-drafted · pending approval (…VEN-03 · Supplier securit…Exception · F-RBI-03ACC-03 · Privileged acces…Remediation in progress · F-ITG…VUL-01 · Vulnerabilities …Evidence pending (T-019)Sanjay KulkarniT-017Meera JoshiT-014Rahul NairT-019

Obligation changes

ObligationChangeRequirementMateriality
Audit-log retention and tamper protectionChanged180 days online, 5 years archivedMaterial
Payment API security and credential hygieneClarifiedRotate credentials on provider incidentsMaterial
Regulatory change impact assessmentNewAssess and record impact within 30 daysModerate
Third-party incident reportingClarifiedNotify RBI / CERT-In within 6 hoursModerate

Affected controls

ControlStatementSystemsPosition
PAY-01Payment APIs secured with mTLS, signing and customer 2FAPayGate Payment Gateway · Meridian Customer PortalOperating · key rotation in progress
LOG-01Security events are centrally logged and monitored 24x7Amazon Web Services (ap-south-1) · Meridian Customer PortalOperating
LOG-02Audit logs retained 180 days online and 5 years archivedAmazon Web Services (ap-south-1) · SAP S/4HANAAI-drafted · pending approval (T-014)
VEN-03Supplier security incidents are assessed for impact and trackedPayGate Payment GatewayException · F-RBI-03
ACC-03Privileged access is just-in-time and reviewedAmazon Web Services (ap-south-1) · Microsoft Entra IDRemediation in progress · F-ITGC-02
VUL-01Vulnerabilities are scanned and remediated within SLAAmazon Web Services (ap-south-1) · GitHub Enterprise CloudEvidence pending (T-019)

Actions and owners

Actions →
ActionOwnerDueStatusValidation
T-017 Impact assessment: RBI circular on cyber resilience & digital payment securitySanjay Kulkarni29 Oct 2026In ProgressPending
T-014 Review and approve AI-drafted control LOG-02 (log retention)Meera Joshi11 Oct 2026OpenNot planned
T-019 Connect AWS Inspector delegated admin account for VUL-01 evidenceRahul Nair13 Oct 2026OpenPending

Review population

○ No data available
Policies
PolicyTitleStatus
pol-itgovIT Governance Policy (RBI-aligned)Revision required
pol-paymentsPayments Security PolicyRevision required
pol-loggingLogging & Security Monitoring StandardRevision required