Meridian Alpha

Regulatory Library

Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
India · Central · Payments

RBI · Digital payment security controls

RBI Master Direction on Digital Payment Security Controls, 18 February 2021

Open in Studio
Legal entity
Meridian Alpha Pvt. Ltd.
Applicability
Applicable · Payment Gateway and customer portal
Locations
Mumbai Head Office (Bandra Kurla Complex), Bengaluru Technology Centre
Reporting cycle
Annual · board review

Requirement coverage · compliance position: gaps to close

5
requirements
  • Covered 120%
  • Partially covered 360%
  • Evidence unavailable 120%
Controls
13
2 failed testing
Evidence approved
47/57
current cycle
Open findings (gaps)
1
0 high
Open actions
1
0 overdue

Requirements and the controls that meet them

RefRequirementApplicabilityControl objectiveControlsCoverage
Para 7Application security life cycle and change controlApplicableChanges are approved, tested and traceableCHG-01CHG-02CHG-03Partially covered
Para 8Authentication and access to payment systemsApplicableAccess is approved, reviewed and removed on exit or role changeACC-01ACC-02ACC-04JML-01JML-02Partially covered
Para 13Vulnerability assessment and penetration testingApplicableVulnerabilities are remediated on timeVUL-01Evidence unavailable
Para 21Logging and monitoring of payment transactions and systemsApplicableSecurity events are logged, retained and monitoredLOG-01LOG-02Partially covered
Para 24Network security and segregationApplicablePayment channels and data in transit are protectedPAY-01ENC-01Covered

Controls and current position

ControlWhat it checksSystemsTestEvidenceOpen findings
CHG-01Production code changes are peer-reviewed and approvedGitHub Enterprise Cloud, Meridian Customer PortalPass9 / 90
CHG-02Emergency changes are retrospectively approvedGitHub Enterprise Cloud, ServiceNow ITSMFail2 / 50
CHG-03Developers have no standing production access; deployments via pipeline onlyAmazon Web Services (ap-south-1), GitHub Enterprise CloudPass2 / 30
ACC-01MFA and SSO enforced for workforce accessAmazon Web Services (ap-south-1), Microsoft Entra ID, GitHub Enterprise CloudPass6 / 60
ACC-02User access provisioning is approved before grantMicrosoft Entra ID, SAP S/4HANA, ServiceNow ITSMPass6 / 60
ACC-04Quarterly user access review of in-scope applicationsMicrosoft Entra ID, Salesforce (Sales + Financial Services Cloud), SAP S/4HANANot tested0 / 50
JML-01Leavers are de-provisioned within 24 hoursDarwinbox HRMS, Microsoft Entra ID, SAP S/4HANAPass6 / 60
JML-02Mover access is recertified on role changeDarwinbox HRMS, Microsoft Entra ID, SAP S/4HANAFail9 / 91
VUL-01Vulnerabilities are scanned and remediated within SLAAmazon Web Services (ap-south-1), GitHub Enterprise CloudNot tested0 / 00
LOG-01Security events are centrally logged and monitored 24x7Amazon Web Services (ap-south-1), Microsoft Entra ID, Meridian Customer PortalPass3 / 40
LOG-02Audit logs retained 180 days online and 5 years archived, tamper-protectedAmazon Web Services (ap-south-1), SAP S/4HANANot tested0 / 00
PAY-01Payment APIs secured with mTLS, signing and customer 2FAPayGate Payment Gateway, Meridian Customer PortalPass2 / 20
ENC-01Customer and payment data encrypted at rest and in transitAmazon Web Services (ap-south-1), Meridian Customer PortalPass2 / 20

Open actions

ActionIssueOwnerDueStatus
REM-F-SOC2-02Mover access not removed timely (deviation in CC6.2 testing)Neha Iyer31 Oct 2026Open

Regulatory reporting for management, audit and compliance review. Applicability is as assessed in Prismet. Statutory returns and regulator filings are not prepared or submitted from Prismet.