Meridian Alpha

Regulatory Library

Regulations that apply to Meridian Alpha and the controls that meet them
As of 9 Oct 2026

One control, several regulations

ControlWhat it checksRegulations and standards servedTestEvidenceOpen findings
LOG-01Security events are centrally logged and monitored 24x7RBICERT-InDPDP ActPCI DSSISO 27001SOC 2Pass3 / 40
VEN-03Supplier security incidents are assessed for impact and trackedRBICERT-InDPDP ActPCI DSSISO 27001SOC 2Fail2 / 41
ACC-01MFA and SSO enforced for workforce accessRBIDPDP ActPCI DSSISO 27001SOC 2Pass6 / 60
ACC-02User access provisioning is approved before grantRBIDPDP ActPCI DSSISO 27001SOC 2Pass6 / 60
ACC-04Quarterly user access review of in-scope applicationsRBIDPDP ActPCI DSSISO 27001SOC 2Not tested0 / 50
CHG-01Production code changes are peer-reviewed and approvedRBICompanies ActPCI DSSISO 27001SOC 2Pass9 / 90
CHG-02Emergency changes are retrospectively approvedRBICompanies ActPCI DSSISO 27001SOC 2Fail2 / 50
CHG-03Developers have no standing production access; deployments via pipeline onlyRBICompanies ActPCI DSSISO 27001SOC 2Pass2 / 30
JML-01Leavers are de-provisioned within 24 hoursRBIDPDP ActPCI DSSISO 27001SOC 2Pass6 / 60
JML-02Mover access is recertified on role changeRBIDPDP ActPCI DSSISO 27001SOC 2Fail9 / 91
VEN-02Provider contracts include data protection and RBI audit clausesRBIDPDP ActPCI DSSISO 27001SOC 2Not tested0 / 11
LOG-02Audit logs retained 180 days online and 5 years archived, tamper-protectedRBICERT-InPCI DSSISO 27001Not tested0 / 00
VEN-01Critical third parties are risk-assessed before onboarding and annuallyRBIPCI DSSISO 27001SOC 2Fail2 / 31
VUL-01Vulnerabilities are scanned and remediated within SLARBIPCI DSSISO 27001SOC 2Not tested0 / 00
ENC-01Customer and payment data encrypted at rest and in transitRBIDPDP ActPCI DSSPass2 / 20
PAY-01Payment APIs secured with mTLS, signing and customer 2FARBICompanies ActPCI DSSPass2 / 20
ACC-03Privileged access is just-in-time and reviewedRBIISO 27001Fail3 / 71

One tested control can provide assurance across the requirements it serves, where its test scope covers each requirement. Coverage is still assessed requirement by requirement.