Meridian Alpha

Regulatory Library

Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
United States · Federal · Corporate & Finance

SOX · Internal control over financial reporting

Sarbanes-Oxley Act of 2002 · Section 404, including IT general controls

Open in Studio
Legal entity
Meridian Alpha
Applicability
Not applicable to Meridian Alpha · scoped for US-listed reporting
Locations
Mumbai Head Office (Bandra Kurla Complex), Bengaluru Technology Centre
Reporting cycle
Annual · management assessment

Requirement coverage · compliance position: gaps to close

6
requirements
  • Covered 117%
  • Partially covered 583%
  • Evidence unavailable 00%
Controls
13
4 failed testing
Evidence approved
49/58
current cycle
Open findings (gaps)
4
3 high
Open actions
4
0 overdue

Requirements and the controls that meet them

RefRequirementApplicabilityControl objectiveControlsCoverage
ICFRProcure-to-pay controlsNot applicablePurchases are approved within delegated thresholdsP2P-01P2P-02Partially covered
ICFRRevenue and order-to-cash controlsNot applicablePayments and settlements are authorisedPAY-02PAY-01Covered
ICFRFinancial close and reportingNot applicableLedger posting and payment release are controlledSOD-01PAY-02Partially covered
ICFRSegregation of dutiesNot applicableConflicting duties are segregated in SAPSOD-01PAY-02Partially covered
ITGCLogical access to financial systemsNot applicableAccess is approved, reviewed and removed on exit or role changeACC-01ACC-02ACC-04JML-01JML-02Partially covered
ITGCChange managementNot applicableChanges are approved, tested and traceableCHG-01CHG-02CHG-03Partially covered

Controls and current position

ControlWhat it checksSystemsTestEvidenceOpen findings
P2P-01Purchase orders follow approval thresholds; no self-approvalSAP S/4HANAFail2 / 21
P2P-02Vendor master changes require dual controlSAP S/4HANAPass1 / 10
PAY-02Payment release requires maker-checkerSAP S/4HANAPass2 / 20
PAY-01Payment APIs secured with mTLS, signing and customer 2FAPayGate Payment Gateway, Meridian Customer PortalPass2 / 20
SOD-01Segregation of incompatible duties in SAPSAP S/4HANAFail2 / 22
ACC-01MFA and SSO enforced for workforce accessAmazon Web Services (ap-south-1), Microsoft Entra ID, GitHub Enterprise CloudPass6 / 60
ACC-02User access provisioning is approved before grantMicrosoft Entra ID, SAP S/4HANA, ServiceNow ITSMPass6 / 60
ACC-04Quarterly user access review of in-scope applicationsMicrosoft Entra ID, Salesforce (Sales + Financial Services Cloud), SAP S/4HANANot tested0 / 50
JML-01Leavers are de-provisioned within 24 hoursDarwinbox HRMS, Microsoft Entra ID, SAP S/4HANAPass6 / 60
JML-02Mover access is recertified on role changeDarwinbox HRMS, Microsoft Entra ID, SAP S/4HANAFail9 / 91
CHG-01Production code changes are peer-reviewed and approvedGitHub Enterprise Cloud, Meridian Customer PortalPass9 / 90
CHG-02Emergency changes are retrospectively approvedGitHub Enterprise Cloud, ServiceNow ITSMFail2 / 50
CHG-03Developers have no standing production access; deployments via pipeline onlyAmazon Web Services (ap-south-1), GitHub Enterprise CloudPass2 / 30

Open actions

ActionIssueOwnerDueStatus
REM-F-ITGC-03Purchase order released by requester above delegation thresholdPriya Sharma20 Oct 2026In Progress
REM-F-ITGC-01Unmitigated SoD conflict: payments approval and GL posting held by transferred employeePriya Sharma10 Oct 2026In Progress
REM-F-RBI-01Access of transferred staff not revoked — SoD breach in payment approval (MD-ITGRCA §7.1)Priya Sharma5 Nov 2026In Progress
REM-F-SOC2-02Mover access not removed timely (deviation in CC6.2 testing)Neha Iyer31 Oct 2026Open

Regulatory reporting for management, audit and compliance review. Applicability is as assessed in Prismet. Statutory returns and regulator filings are not prepared or submitted from Prismet.