Meridian Alpha
Regulatory Library
Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
As of 9 Oct 2026
United States · Federal · Corporate & Finance
SOX · Internal control over financial reporting
Sarbanes-Oxley Act of 2002 · Section 404, including IT general controls
Legal entity
Meridian Alpha
Applicability
Not applicable to Meridian Alpha · scoped for US-listed reporting
Locations
Mumbai Head Office (Bandra Kurla Complex), Bengaluru Technology Centre
Reporting cycle
Annual · management assessment
Requirement coverage · compliance position: gaps to close
6
requirements
- Covered 117%
- Partially covered 583%
- Evidence unavailable 00%
Controls
13
4 failed testing
Evidence approved
49/58
current cycle
Open findings (gaps)
4
3 high
Open actions
4
0 overdue
Requirements and the controls that meet them
| Ref | Requirement | Applicability | Control objective | Controls | Coverage |
|---|---|---|---|---|---|
| ICFR | Procure-to-pay controls | Not applicable | Purchases are approved within delegated thresholds | P2P-01P2P-02 | Partially covered |
| ICFR | Revenue and order-to-cash controls | Not applicable | Payments and settlements are authorised | PAY-02PAY-01 | Covered |
| ICFR | Financial close and reporting | Not applicable | Ledger posting and payment release are controlled | SOD-01PAY-02 | Partially covered |
| ICFR | Segregation of duties | Not applicable | Conflicting duties are segregated in SAP | SOD-01PAY-02 | Partially covered |
| ITGC | Logical access to financial systems | Not applicable | Access is approved, reviewed and removed on exit or role change | ACC-01ACC-02ACC-04JML-01JML-02 | Partially covered |
| ITGC | Change management | Not applicable | Changes are approved, tested and traceable | CHG-01CHG-02CHG-03 | Partially covered |
Controls and current position
| Control | What it checks | Systems | Test | Evidence | Open findings |
|---|---|---|---|---|---|
| P2P-01 | Purchase orders follow approval thresholds; no self-approval | SAP S/4HANA | Fail | 2 / 2 | 1 |
| P2P-02 | Vendor master changes require dual control | SAP S/4HANA | Pass | 1 / 1 | 0 |
| PAY-02 | Payment release requires maker-checker | SAP S/4HANA | Pass | 2 / 2 | 0 |
| PAY-01 | Payment APIs secured with mTLS, signing and customer 2FA | PayGate Payment Gateway, Meridian Customer Portal | Pass | 2 / 2 | 0 |
| SOD-01 | Segregation of incompatible duties in SAP | SAP S/4HANA | Fail | 2 / 2 | 2 |
| ACC-01 | MFA and SSO enforced for workforce access | Amazon Web Services (ap-south-1), Microsoft Entra ID, GitHub Enterprise Cloud | Pass | 6 / 6 | 0 |
| ACC-02 | User access provisioning is approved before grant | Microsoft Entra ID, SAP S/4HANA, ServiceNow ITSM | Pass | 6 / 6 | 0 |
| ACC-04 | Quarterly user access review of in-scope applications | Microsoft Entra ID, Salesforce (Sales + Financial Services Cloud), SAP S/4HANA | Not tested | 0 / 5 | 0 |
| JML-01 | Leavers are de-provisioned within 24 hours | Darwinbox HRMS, Microsoft Entra ID, SAP S/4HANA | Pass | 6 / 6 | 0 |
| JML-02 | Mover access is recertified on role change | Darwinbox HRMS, Microsoft Entra ID, SAP S/4HANA | Fail | 9 / 9 | 1 |
| CHG-01 | Production code changes are peer-reviewed and approved | GitHub Enterprise Cloud, Meridian Customer Portal | Pass | 9 / 9 | 0 |
| CHG-02 | Emergency changes are retrospectively approved | GitHub Enterprise Cloud, ServiceNow ITSM | Fail | 2 / 5 | 0 |
| CHG-03 | Developers have no standing production access; deployments via pipeline only | Amazon Web Services (ap-south-1), GitHub Enterprise Cloud | Pass | 2 / 3 | 0 |
Open actions
| Action | Issue | Owner | Due | Status |
|---|---|---|---|---|
| REM-F-ITGC-03 | Purchase order released by requester above delegation threshold | Priya Sharma | 20 Oct 2026 | In Progress |
| REM-F-ITGC-01 | Unmitigated SoD conflict: payments approval and GL posting held by transferred employee | Priya Sharma | 10 Oct 2026 | In Progress |
| REM-F-RBI-01 | Access of transferred staff not revoked — SoD breach in payment approval (MD-ITGRCA §7.1) | Priya Sharma | 5 Nov 2026 | In Progress |
| REM-F-SOC2-02 | Mover access not removed timely (deviation in CC6.2 testing) | Neha Iyer | 31 Oct 2026 | Open |
Regulatory reporting for management, audit and compliance review. Applicability is as assessed in Prismet. Statutory returns and regulator filings are not prepared or submitted from Prismet.