Meridian Alpha
Regulatory Library
Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
As of 9 Oct 2026
India · Central · Banking & Financial
RBI · IT governance, risk, controls and assurance
RBI Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices, 7 November 2023
Legal entity
Meridian Alpha Pvt. Ltd.
Applicability
Applicable · Regulated payments business
Locations
Mumbai Head Office (Bandra Kurla Complex), Bengaluru Technology Centre
Reporting cycle
Annual · board review
Requirement coverage · compliance position: gaps to close
8
requirements
- Covered 113%
- Partially covered 675%
- Evidence unavailable 113%
Controls
17
4 failed testing
Evidence approved
59/78
current cycle
Open findings (gaps)
3
1 high
Open actions
3
0 overdue
Requirements and the controls that meet them
| Ref | Requirement | Applicability | Control objective | Controls | Coverage |
|---|---|---|---|---|---|
| Ch. III | Access to IT systems on least privilege, reviewed periodically | Applicable | Access is approved, reviewed and removed on exit or role change | ACC-01ACC-02ACC-04JML-01JML-02 | Partially covered |
| Ch. III | Privileged access controlled and monitored | Applicable | Privileged access is just-in-time and restricted | ACC-03CHG-03 | Partially covered |
| Ch. IV | Change and patch management | Applicable | Changes are approved, tested and traceable | CHG-01CHG-02CHG-03 | Partially covered |
| Ch. IV | Vulnerability assessment and remediation | Applicable | Vulnerabilities are remediated on time | VUL-01 | Evidence unavailable |
| Ch. V | Security operations and log monitoring | Applicable | Security events are logged, retained and monitored | LOG-01LOG-02 | Partially covered |
| Ch. VI | Incident management | Applicable | Incidents, including supplier incidents, are assessed and reported | VEN-03LOG-01 | Partially covered |
| Ch. II | IT Strategy Committee oversight of IT and cyber risk | Applicable | IT and cyber risk are governed by the IT Strategy Committee | GOV-01GOV-02 | Partially covered |
| Ch. VII | Business continuity and DR tested against objectives | Applicable | Backups are taken and restores tested against the RTO | OPS-01BCP-01 | Covered |
Controls and current position
| Control | What it checks | Systems | Test | Evidence | Open findings |
|---|---|---|---|---|---|
| ACC-01 | MFA and SSO enforced for workforce access | Amazon Web Services (ap-south-1), Microsoft Entra ID, GitHub Enterprise Cloud | Pass | 6 / 6 | 0 |
| ACC-02 | User access provisioning is approved before grant | Microsoft Entra ID, SAP S/4HANA, ServiceNow ITSM | Pass | 6 / 6 | 0 |
| ACC-04 | Quarterly user access review of in-scope applications | Microsoft Entra ID, Salesforce (Sales + Financial Services Cloud), SAP S/4HANA | Not tested | 0 / 5 | 0 |
| JML-01 | Leavers are de-provisioned within 24 hours | Darwinbox HRMS, Microsoft Entra ID, SAP S/4HANA | Pass | 6 / 6 | 0 |
| JML-02 | Mover access is recertified on role change | Darwinbox HRMS, Microsoft Entra ID, SAP S/4HANA | Fail | 9 / 9 | 1 |
| ACC-03 | Privileged access is just-in-time and reviewed | Amazon Web Services (ap-south-1), Microsoft Entra ID, SAP S/4HANA | Fail | 3 / 7 | 1 |
| CHG-03 | Developers have no standing production access; deployments via pipeline only | Amazon Web Services (ap-south-1), GitHub Enterprise Cloud | Pass | 2 / 3 | 0 |
| CHG-01 | Production code changes are peer-reviewed and approved | GitHub Enterprise Cloud, Meridian Customer Portal | Pass | 9 / 9 | 0 |
| CHG-02 | Emergency changes are retrospectively approved | GitHub Enterprise Cloud, ServiceNow ITSM | Fail | 2 / 5 | 0 |
| VUL-01 | Vulnerabilities are scanned and remediated within SLA | Amazon Web Services (ap-south-1), GitHub Enterprise Cloud | Not tested | 0 / 0 | 0 |
| LOG-01 | Security events are centrally logged and monitored 24x7 | Amazon Web Services (ap-south-1), Microsoft Entra ID, Meridian Customer Portal | Pass | 3 / 4 | 0 |
| LOG-02 | Audit logs retained 180 days online and 5 years archived, tamper-protected | Amazon Web Services (ap-south-1), SAP S/4HANA | Not tested | 0 / 0 | 0 |
| VEN-03 | Supplier security incidents are assessed for impact and tracked | PayGate Payment Gateway, Meridian Customer Portal | Fail | 2 / 4 | 1 |
| GOV-01 | IT Strategy Committee oversees IT and cyber risk | Meridian Customer Portal | Pass | 1 / 2 | 0 |
| GOV-02 | RBI regulatory changes are assessed for impact within 30 days | Meridian Customer Portal | Not tested | 0 / 0 | 0 |
| OPS-01 | Backups are performed daily and monitored | Amazon Web Services (ap-south-1), Microsoft Azure (corporate) | Pass | 6 / 6 | 0 |
| BCP-01 | Backup restore and DR are tested | Amazon Web Services (ap-south-1), Microsoft Azure (corporate) | Pass | 4 / 6 | 0 |
Open actions
| Action | Issue | Owner | Due | Status |
|---|---|---|---|---|
| REM-F-SOC2-02 | Mover access not removed timely (deviation in CC6.2 testing) | Neha Iyer | 31 Oct 2026 | Open |
| REM-F-ITGC-02 | Standing privileged access in production AWS | Rahul Nair | 16 Oct 2026 | In Progress |
| REM-F-RBI-03 | Payment provider incident — incomplete credential rotation | Deepa Menon | 10 Oct 2026 | In Progress |
Regulatory reporting for management, audit and compliance review. Applicability is as assessed in Prismet. Statutory returns and regulator filings are not prepared or submitted from Prismet.