Meridian Alpha
Regulatory Library
Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
As of 9 Oct 2026
United States · State · California · Privacy
CCPA · Consumer privacy
California Consumer Privacy Act as amended by CPRA · §1798.100(e) and §1798.150
Legal entity
Meridian Alpha
Applicability
Not applicable to Meridian Alpha · scoped for California customer data
Locations
Bengaluru Technology Centre
Reporting cycle
Ongoing
Requirement coverage · compliance position: gaps to close
2
requirements
- Covered 00%
- Partially covered 2100%
- Evidence unavailable 00%
Controls
7
1 failed testing
Evidence approved
29/35
current cycle
Open findings (gaps)
2
0 high
Open actions
2
0 overdue
Requirements and the controls that meet them
| Ref | Requirement | Applicability | Control objective | Controls | Coverage |
|---|---|---|---|---|---|
| §1798.100(e) | Reasonable security for personal information | Not applicable | Customer and payment data is protected, including at providers | ENC-01VEN-02 | Partially covered |
| §1798.150 | Prevent unauthorised access to personal information | Not applicable | Access is approved, reviewed and removed on exit or role change | ACC-01ACC-02ACC-04JML-01JML-02 | Partially covered |
Controls and current position
| Control | What it checks | Systems | Test | Evidence | Open findings |
|---|---|---|---|---|---|
| ENC-01 | Customer and payment data encrypted at rest and in transit | Amazon Web Services (ap-south-1), Meridian Customer Portal | Pass | 2 / 2 | 0 |
| VEN-02 | Provider contracts include data protection and RBI audit clauses | Salesforce (Sales + Financial Services Cloud) | Not tested | 0 / 1 | 1 |
| ACC-01 | MFA and SSO enforced for workforce access | Amazon Web Services (ap-south-1), Microsoft Entra ID, GitHub Enterprise Cloud | Pass | 6 / 6 | 0 |
| ACC-02 | User access provisioning is approved before grant | Microsoft Entra ID, SAP S/4HANA, ServiceNow ITSM | Pass | 6 / 6 | 0 |
| ACC-04 | Quarterly user access review of in-scope applications | Microsoft Entra ID, Salesforce (Sales + Financial Services Cloud), SAP S/4HANA | Not tested | 0 / 5 | 0 |
| JML-01 | Leavers are de-provisioned within 24 hours | Darwinbox HRMS, Microsoft Entra ID, SAP S/4HANA | Pass | 6 / 6 | 0 |
| JML-02 | Mover access is recertified on role change | Darwinbox HRMS, Microsoft Entra ID, SAP S/4HANA | Fail | 9 / 9 | 1 |
Open actions
| Action | Issue | Owner | Due | Status |
|---|---|---|---|---|
| REM-F-ISO-02 | Supplier agreement lacks information security clauses (A.5.20) | Sanjay Kulkarni | 31 Oct 2026 | In Progress |
| REM-F-SOC2-02 | Mover access not removed timely (deviation in CC6.2 testing) | Neha Iyer | 31 Oct 2026 | Open |
Regulatory reporting for management, audit and compliance review. Applicability is as assessed in Prismet. Statutory returns and regulator filings are not prepared or submitted from Prismet.