Meridian Alpha
Regulatory Library
Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026
As of 9 Oct 2026
One control, several regulations
| Control | What it checks | Regulations and standards served | Test | Evidence | Open findings |
|---|---|---|---|---|---|
| LOG-01 | Security events are centrally logged and monitored 24x7 | RBICERT-InDPDP ActPCI DSSISO 27001SOC 2 | Pass | 3 / 4 | 0 |
| VEN-03 | Supplier security incidents are assessed for impact and tracked | RBICERT-InDPDP ActPCI DSSISO 27001SOC 2 | Fail | 2 / 4 | 1 |
| ACC-01 | MFA and SSO enforced for workforce access | RBIDPDP ActPCI DSSISO 27001SOC 2 | Pass | 6 / 6 | 0 |
| ACC-02 | User access provisioning is approved before grant | RBIDPDP ActPCI DSSISO 27001SOC 2 | Pass | 6 / 6 | 0 |
| ACC-04 | Quarterly user access review of in-scope applications | RBIDPDP ActPCI DSSISO 27001SOC 2 | Not tested | 0 / 5 | 0 |
| CHG-01 | Production code changes are peer-reviewed and approved | RBICompanies ActPCI DSSISO 27001SOC 2 | Pass | 9 / 9 | 0 |
| CHG-02 | Emergency changes are retrospectively approved | RBICompanies ActPCI DSSISO 27001SOC 2 | Fail | 2 / 5 | 0 |
| CHG-03 | Developers have no standing production access; deployments via pipeline only | RBICompanies ActPCI DSSISO 27001SOC 2 | Pass | 2 / 3 | 0 |
| JML-01 | Leavers are de-provisioned within 24 hours | RBIDPDP ActPCI DSSISO 27001SOC 2 | Pass | 6 / 6 | 0 |
| JML-02 | Mover access is recertified on role change | RBIDPDP ActPCI DSSISO 27001SOC 2 | Fail | 9 / 9 | 1 |
| VEN-02 | Provider contracts include data protection and RBI audit clauses | RBIDPDP ActPCI DSSISO 27001SOC 2 | Not tested | 0 / 1 | 1 |
| LOG-02 | Audit logs retained 180 days online and 5 years archived, tamper-protected | RBICERT-InPCI DSSISO 27001 | Not tested | 0 / 0 | 0 |
| VEN-01 | Critical third parties are risk-assessed before onboarding and annually | RBIPCI DSSISO 27001SOC 2 | Fail | 2 / 3 | 1 |
| VUL-01 | Vulnerabilities are scanned and remediated within SLA | RBIPCI DSSISO 27001SOC 2 | Not tested | 0 / 0 | 0 |
| ENC-01 | Customer and payment data encrypted at rest and in transit | RBIDPDP ActPCI DSS | Pass | 2 / 2 | 0 |
| PAY-01 | Payment APIs secured with mTLS, signing and customer 2FA | RBICompanies ActPCI DSS | Pass | 2 / 2 | 0 |
| ACC-03 | Privileged access is just-in-time and reviewed | RBIISO 27001 | Fail | 3 / 7 | 1 |
One tested control can provide assurance across the requirements it serves, where its test scope covers each requirement. Coverage is still assessed requirement by requirement.