Meridian Alpha
Regulatory Library
Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
As of 9 Oct 2026
India · Central · Banking & Financial
RBI · Know Your Customer
RBI Master Direction – Know Your Customer (KYC) Direction, 2016 (as amended)
Legal entity
Meridian Alpha Pvt. Ltd.
Applicability
Applicable · Customer onboarding (Salesforce, Customer Portal) and VeriKYC
Locations
Mumbai Head Office (Bandra Kurla Complex)
Reporting cycle
Ongoing · periodic updation by risk category
Requirement coverage · compliance position: gaps to close
3
requirements
- Covered 00%
- Partially covered 3100%
- Evidence unavailable 00%
Controls
5
3 failed testing
Evidence approved
6/11
current cycle
Open findings (gaps)
4
2 high
Open actions
4
0 overdue
Requirements and the controls that meet them
| Ref | Requirement | Applicability | Control objective | Controls | Coverage |
|---|---|---|---|---|---|
| §16 | Customer due diligence completed before an account-based relationship | Applicable | Customers are onboarded and refreshed with complete KYC | KYC-01KYC-02 | Partially covered |
| §38 | Periodic updation of KYC by customer risk category | Applicable | Customers are onboarded and refreshed with complete KYC | KYC-01KYC-02 | Partially covered |
| §14 | CDD performed by third parties remains the regulated entity's responsibility | Applicable | Third parties are assessed, contracted and monitored | VEN-01VEN-02VEN-03 | Partially covered |
Controls and current position
| Control | What it checks | Systems | Test | Evidence | Open findings |
|---|---|---|---|---|---|
| KYC-01 | Customer accounts are activated only with complete KYC | Meridian Customer Portal, Salesforce (Sales + Financial Services Cloud) | Fail | 2 / 3 | 1 |
| KYC-02 | Periodic KYC updation based on customer risk | Salesforce (Sales + Financial Services Cloud) | Not tested | 0 / 0 | 0 |
| VEN-01 | Critical third parties are risk-assessed before onboarding and annually | PayGate Payment Gateway, Salesforce (Sales + Financial Services Cloud) | Fail | 2 / 3 | 1 |
| VEN-02 | Provider contracts include data protection and RBI audit clauses | Salesforce (Sales + Financial Services Cloud) | Not tested | 0 / 1 | 1 |
| VEN-03 | Supplier security incidents are assessed for impact and tracked | PayGate Payment Gateway, Meridian Customer Portal | Fail | 2 / 4 | 1 |
Open actions
| Action | Issue | Owner | Due | Status |
|---|---|---|---|---|
| REM-F-RBI-04 | Credit line activated before KYC completion (KYC MD §16) | Arjun Kapoor | 22 Oct 2026 | In Progress |
| REM-F-RBI-02 | Material outsourcing: lapsed assurance and overdue reassessment (Outsourcing of IT Services 2023 §6/§9) | Sanjay Kulkarni | 20 Oct 2026 | Open |
| REM-F-ISO-02 | Supplier agreement lacks information security clauses (A.5.20) | Sanjay Kulkarni | 31 Oct 2026 | In Progress |
| REM-F-RBI-03 | Payment provider incident — incomplete credential rotation | Deepa Menon | 10 Oct 2026 | In Progress |
Regulatory reporting for management, audit and compliance review. Applicability is as assessed in Prismet. Statutory returns and regulator filings are not prepared or submitted from Prismet.