Meridian Alpha

Regulatory Library

Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
United States · Federal · Cyber & Technology

SEC · Cybersecurity risk management and incident disclosure

SEC Regulation S-K Item 106 · Form 10-K Item 1C; Form 8-K Item 1.05

Open in Studio
Legal entity
Meridian Alpha
Applicability
Not applicable to Meridian Alpha · scoped for US-listed reporting
Locations
Mumbai Head Office (Bandra Kurla Complex), Bengaluru Technology Centre
Reporting cycle
Annual 10-K; material incidents within 4 business days

Requirement coverage · compliance position: gaps to close

3
requirements
  • Covered 00%
  • Partially covered 267%
  • Evidence unavailable 133%
Controls
5
2 failed testing
Evidence approved
7/12
current cycle
Open findings (gaps)
3
1 high
Open actions
3
0 overdue

Requirements and the controls that meet them

RefRequirementApplicabilityControl objectiveControlsCoverage
Item 106(b)Processes to assess, identify and manage cyber riskNot applicableVulnerabilities are remediated on timeVUL-01Evidence unavailable
Item 106(b)Oversight of third-party service providersNot applicableThird parties are assessed, contracted and monitoredVEN-01VEN-02VEN-03Partially covered
8-K 1.05Determine materiality and disclose cyber incidentsNot applicableIncidents, including supplier incidents, are assessed and reportedVEN-03LOG-01Partially covered

Controls and current position

ControlWhat it checksSystemsTestEvidenceOpen findings
VUL-01Vulnerabilities are scanned and remediated within SLAAmazon Web Services (ap-south-1), GitHub Enterprise CloudNot tested0 / 00
VEN-01Critical third parties are risk-assessed before onboarding and annuallyPayGate Payment Gateway, Salesforce (Sales + Financial Services Cloud)Fail2 / 31
VEN-02Provider contracts include data protection and RBI audit clausesSalesforce (Sales + Financial Services Cloud)Not tested0 / 11
VEN-03Supplier security incidents are assessed for impact and trackedPayGate Payment Gateway, Meridian Customer PortalFail2 / 41
LOG-01Security events are centrally logged and monitored 24x7Amazon Web Services (ap-south-1), Microsoft Entra ID, Meridian Customer PortalPass3 / 40

Open actions

ActionIssueOwnerDueStatus
REM-F-RBI-02Material outsourcing: lapsed assurance and overdue reassessment (Outsourcing of IT Services 2023 §6/§9)Sanjay Kulkarni20 Oct 2026Open
REM-F-ISO-02Supplier agreement lacks information security clauses (A.5.20)Sanjay Kulkarni31 Oct 2026In Progress
REM-F-RBI-03Payment provider incident — incomplete credential rotationDeepa Menon10 Oct 2026In Progress

Regulatory reporting for management, audit and compliance review. Applicability is as assessed in Prismet. Statutory returns and regulator filings are not prepared or submitted from Prismet.