Meridian Alpha
Regulatory Library
Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
As of 9 Oct 2026
India · Central · Corporate & Finance
Companies Act · Internal financial controls
Companies Act, 2013 · s.134(5)(e) and s.143(3)(i); CARO 2020
Legal entity
Meridian Alpha Pvt. Ltd.
Applicability
Applicable · Meridian Alpha Pvt. Ltd.
Locations
Mumbai Head Office (Bandra Kurla Complex), Bengaluru Technology Centre
Reporting cycle
Annual · directors' report
Requirement coverage · compliance position: gaps to close
5
requirements
- Covered 120%
- Partially covered 480%
- Evidence unavailable 00%
Controls
8
3 failed testing
Evidence approved
22/26
current cycle
Open findings (gaps)
3
3 high
Open actions
3
0 overdue
Requirements and the controls that meet them
| Ref | Requirement | Applicability | Control objective | Controls | Coverage |
|---|---|---|---|---|---|
| s.134(5)(e) | Purchase-to-pay controls operating | Applicable | Purchases are approved within delegated thresholds | P2P-01P2P-02 | Partially covered |
| s.134(5)(e) | Order-to-cash controls operating | Applicable | Payments and settlements are authorised | PAY-02PAY-01 | Covered |
| s.134(5)(e) | Financial close controls operating | Applicable | Ledger posting and payment release are controlled | SOD-01PAY-02 | Partially covered |
| s.134(5)(e) | Segregation of duties in finance systems | Applicable | Conflicting duties are segregated in SAP | SOD-01PAY-02 | Partially covered |
| s.143(3)(i) | IT general controls over financial systems | Applicable | Changes are approved, tested and traceable | CHG-01CHG-02CHG-03 | Partially covered |
Controls and current position
| Control | What it checks | Systems | Test | Evidence | Open findings |
|---|---|---|---|---|---|
| P2P-01 | Purchase orders follow approval thresholds; no self-approval | SAP S/4HANA | Fail | 2 / 2 | 1 |
| P2P-02 | Vendor master changes require dual control | SAP S/4HANA | Pass | 1 / 1 | 0 |
| PAY-02 | Payment release requires maker-checker | SAP S/4HANA | Pass | 2 / 2 | 0 |
| PAY-01 | Payment APIs secured with mTLS, signing and customer 2FA | PayGate Payment Gateway, Meridian Customer Portal | Pass | 2 / 2 | 0 |
| SOD-01 | Segregation of incompatible duties in SAP | SAP S/4HANA | Fail | 2 / 2 | 2 |
| CHG-01 | Production code changes are peer-reviewed and approved | GitHub Enterprise Cloud, Meridian Customer Portal | Pass | 9 / 9 | 0 |
| CHG-02 | Emergency changes are retrospectively approved | GitHub Enterprise Cloud, ServiceNow ITSM | Fail | 2 / 5 | 0 |
| CHG-03 | Developers have no standing production access; deployments via pipeline only | Amazon Web Services (ap-south-1), GitHub Enterprise Cloud | Pass | 2 / 3 | 0 |
Open actions
| Action | Issue | Owner | Due | Status |
|---|---|---|---|---|
| REM-F-ITGC-03 | Purchase order released by requester above delegation threshold | Priya Sharma | 20 Oct 2026 | In Progress |
| REM-F-ITGC-01 | Unmitigated SoD conflict: payments approval and GL posting held by transferred employee | Priya Sharma | 10 Oct 2026 | In Progress |
| REM-F-RBI-01 | Access of transferred staff not revoked — SoD breach in payment approval (MD-ITGRCA §7.1) | Priya Sharma | 5 Nov 2026 | In Progress |
Regulatory reporting for management, audit and compliance review. Applicability is as assessed in Prismet. Statutory returns and regulator filings are not prepared or submitted from Prismet.