Meridian Alpha

Regulatory Library

Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
European Union · EU-wide · Banking & Financial

DORA · ICT risk and third-party register

Digital Operational Resilience Act, Regulation (EU) 2022/2554 · Articles 9, 17 and 28

Open in Studio
Legal entity
Meridian Alpha
Applicability
Not applicable to Meridian Alpha · scoped for EU financial services entity
Locations
Bengaluru Technology Centre
Reporting cycle
Annual · register of information

Requirement coverage · compliance position: gaps to close

4
requirements
  • Covered 00%
  • Partially covered 4100%
  • Evidence unavailable 00%
Controls
8
4 failed testing
Evidence approved
23/36
current cycle
Open findings (gaps)
4
1 high
Open actions
4
0 overdue

Requirements and the controls that meet them

RefRequirementApplicabilityControl objectiveControlsCoverage
Art. 9ICT protection and preventionNot applicablePrivileged access is just-in-time and restrictedACC-03CHG-03Partially covered
Art. 9(4)(e)ICT change managementNot applicableChanges are approved, tested and traceableCHG-01CHG-02CHG-03Partially covered
Art. 17ICT incident managementNot applicableIncidents, including supplier incidents, are assessed and reportedVEN-03LOG-01Partially covered
Art. 28Register of ICT third-party arrangementsNot applicableThird parties are assessed, contracted and monitoredVEN-01VEN-02VEN-03Partially covered

Controls and current position

ControlWhat it checksSystemsTestEvidenceOpen findings
ACC-03Privileged access is just-in-time and reviewedAmazon Web Services (ap-south-1), Microsoft Entra ID, SAP S/4HANAFail3 / 71
CHG-03Developers have no standing production access; deployments via pipeline onlyAmazon Web Services (ap-south-1), GitHub Enterprise CloudPass2 / 30
CHG-01Production code changes are peer-reviewed and approvedGitHub Enterprise Cloud, Meridian Customer PortalPass9 / 90
CHG-02Emergency changes are retrospectively approvedGitHub Enterprise Cloud, ServiceNow ITSMFail2 / 50
VEN-03Supplier security incidents are assessed for impact and trackedPayGate Payment Gateway, Meridian Customer PortalFail2 / 41
LOG-01Security events are centrally logged and monitored 24x7Amazon Web Services (ap-south-1), Microsoft Entra ID, Meridian Customer PortalPass3 / 40
VEN-01Critical third parties are risk-assessed before onboarding and annuallyPayGate Payment Gateway, Salesforce (Sales + Financial Services Cloud)Fail2 / 31
VEN-02Provider contracts include data protection and RBI audit clausesSalesforce (Sales + Financial Services Cloud)Not tested0 / 11

Open actions

ActionIssueOwnerDueStatus
REM-F-ITGC-02Standing privileged access in production AWSRahul Nair16 Oct 2026In Progress
REM-F-RBI-03Payment provider incident — incomplete credential rotationDeepa Menon10 Oct 2026In Progress
REM-F-RBI-02Material outsourcing: lapsed assurance and overdue reassessment (Outsourcing of IT Services 2023 §6/§9)Sanjay Kulkarni20 Oct 2026Open
REM-F-ISO-02Supplier agreement lacks information security clauses (A.5.20)Sanjay Kulkarni31 Oct 2026In Progress

Regulatory reporting for management, audit and compliance review. Applicability is as assessed in Prismet. Statutory returns and regulator filings are not prepared or submitted from Prismet.