Meridian Alpha

Regulatory Library

Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
United States · State · California · Privacy

CCPA · Consumer privacy

California Consumer Privacy Act as amended by CPRA · §1798.100(e) and §1798.150

Open in Studio
Legal entity
Meridian Alpha
Applicability
Not applicable to Meridian Alpha · scoped for California customer data
Locations
Bengaluru Technology Centre
Reporting cycle
Ongoing

Requirement coverage · compliance position: gaps to close

2
requirements
  • Covered 00%
  • Partially covered 2100%
  • Evidence unavailable 00%
Controls
7
1 failed testing
Evidence approved
29/35
current cycle
Open findings (gaps)
2
0 high
Open actions
2
0 overdue

Requirements and the controls that meet them

RefRequirementApplicabilityControl objectiveControlsCoverage
§1798.100(e)Reasonable security for personal informationNot applicableCustomer and payment data is protected, including at providersENC-01VEN-02Partially covered
§1798.150Prevent unauthorised access to personal informationNot applicableAccess is approved, reviewed and removed on exit or role changeACC-01ACC-02ACC-04JML-01JML-02Partially covered

Controls and current position

ControlWhat it checksSystemsTestEvidenceOpen findings
ENC-01Customer and payment data encrypted at rest and in transitAmazon Web Services (ap-south-1), Meridian Customer PortalPass2 / 20
VEN-02Provider contracts include data protection and RBI audit clausesSalesforce (Sales + Financial Services Cloud)Not tested0 / 11
ACC-01MFA and SSO enforced for workforce accessAmazon Web Services (ap-south-1), Microsoft Entra ID, GitHub Enterprise CloudPass6 / 60
ACC-02User access provisioning is approved before grantMicrosoft Entra ID, SAP S/4HANA, ServiceNow ITSMPass6 / 60
ACC-04Quarterly user access review of in-scope applicationsMicrosoft Entra ID, Salesforce (Sales + Financial Services Cloud), SAP S/4HANANot tested0 / 50
JML-01Leavers are de-provisioned within 24 hoursDarwinbox HRMS, Microsoft Entra ID, SAP S/4HANAPass6 / 60
JML-02Mover access is recertified on role changeDarwinbox HRMS, Microsoft Entra ID, SAP S/4HANAFail9 / 91

Open actions

ActionIssueOwnerDueStatus
REM-F-ISO-02Supplier agreement lacks information security clauses (A.5.20)Sanjay Kulkarni31 Oct 2026In Progress
REM-F-SOC2-02Mover access not removed timely (deviation in CC6.2 testing)Neha Iyer31 Oct 2026Open

Regulatory reporting for management, audit and compliance review. Applicability is as assessed in Prismet. Statutory returns and regulator filings are not prepared or submitted from Prismet.