Meridian Alpha
Regulatory Library
Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
As of 9 Oct 2026
European Union · EU-wide · Banking & Financial
DORA · ICT risk and third-party register
Digital Operational Resilience Act, Regulation (EU) 2022/2554 · Articles 9, 17 and 28
Legal entity
Meridian Alpha
Applicability
Not applicable to Meridian Alpha · scoped for EU financial services entity
Locations
Bengaluru Technology Centre
Reporting cycle
Annual · register of information
Requirement coverage · compliance position: gaps to close
4
requirements
- Covered 00%
- Partially covered 4100%
- Evidence unavailable 00%
Controls
8
4 failed testing
Evidence approved
23/36
current cycle
Open findings (gaps)
4
1 high
Open actions
4
0 overdue
Requirements and the controls that meet them
| Ref | Requirement | Applicability | Control objective | Controls | Coverage |
|---|---|---|---|---|---|
| Art. 9 | ICT protection and prevention | Not applicable | Privileged access is just-in-time and restricted | ACC-03CHG-03 | Partially covered |
| Art. 9(4)(e) | ICT change management | Not applicable | Changes are approved, tested and traceable | CHG-01CHG-02CHG-03 | Partially covered |
| Art. 17 | ICT incident management | Not applicable | Incidents, including supplier incidents, are assessed and reported | VEN-03LOG-01 | Partially covered |
| Art. 28 | Register of ICT third-party arrangements | Not applicable | Third parties are assessed, contracted and monitored | VEN-01VEN-02VEN-03 | Partially covered |
Controls and current position
| Control | What it checks | Systems | Test | Evidence | Open findings |
|---|---|---|---|---|---|
| ACC-03 | Privileged access is just-in-time and reviewed | Amazon Web Services (ap-south-1), Microsoft Entra ID, SAP S/4HANA | Fail | 3 / 7 | 1 |
| CHG-03 | Developers have no standing production access; deployments via pipeline only | Amazon Web Services (ap-south-1), GitHub Enterprise Cloud | Pass | 2 / 3 | 0 |
| CHG-01 | Production code changes are peer-reviewed and approved | GitHub Enterprise Cloud, Meridian Customer Portal | Pass | 9 / 9 | 0 |
| CHG-02 | Emergency changes are retrospectively approved | GitHub Enterprise Cloud, ServiceNow ITSM | Fail | 2 / 5 | 0 |
| VEN-03 | Supplier security incidents are assessed for impact and tracked | PayGate Payment Gateway, Meridian Customer Portal | Fail | 2 / 4 | 1 |
| LOG-01 | Security events are centrally logged and monitored 24x7 | Amazon Web Services (ap-south-1), Microsoft Entra ID, Meridian Customer Portal | Pass | 3 / 4 | 0 |
| VEN-01 | Critical third parties are risk-assessed before onboarding and annually | PayGate Payment Gateway, Salesforce (Sales + Financial Services Cloud) | Fail | 2 / 3 | 1 |
| VEN-02 | Provider contracts include data protection and RBI audit clauses | Salesforce (Sales + Financial Services Cloud) | Not tested | 0 / 1 | 1 |
Open actions
| Action | Issue | Owner | Due | Status |
|---|---|---|---|---|
| REM-F-ITGC-02 | Standing privileged access in production AWS | Rahul Nair | 16 Oct 2026 | In Progress |
| REM-F-RBI-03 | Payment provider incident — incomplete credential rotation | Deepa Menon | 10 Oct 2026 | In Progress |
| REM-F-RBI-02 | Material outsourcing: lapsed assurance and overdue reassessment (Outsourcing of IT Services 2023 §6/§9) | Sanjay Kulkarni | 20 Oct 2026 | Open |
| REM-F-ISO-02 | Supplier agreement lacks information security clauses (A.5.20) | Sanjay Kulkarni | 31 Oct 2026 | In Progress |
Regulatory reporting for management, audit and compliance review. Applicability is as assessed in Prismet. Statutory returns and regulator filings are not prepared or submitted from Prismet.