Meridian Alpha
Overview
Q3 2026 Unified Program Review
As of 9 Oct 2026
As of 9 Oct 2026
Filters
Controls tested
i
Controls tested
Controls tested in the current audit cycle, out of the controls in scope.
- Period
- Q3 2026
- Filters
- Third-Party Risk · Medium
- Updated
- 9 Oct 2026
- Source
- Meridian Alpha · assurance records (tests, findings, actions, validations, evidence)
2/3
67% of scope
Controls effective
i
Controls effective
Tested controls rated effective, as a share of all controls tested.
- Period
- Q3 2026
- Filters
- Third-Party Risk · Medium
- Updated
- 9 Oct 2026
- Source
- Meridian Alpha · assurance records (tests, findings, actions, validations, evidence)
0%
0 effective · 0 with observation
-67 pts vs Q2 2026
Open findings
i
Open findings
Findings not yet closed.
- Period
- All cycles
- Filters
- Third-Party Risk · Medium
- Updated
- 9 Oct 2026
- Source
- Meridian Alpha · assurance records (tests, findings, actions, validations, evidence)
2
0 high · 2 medium
2 raised in Q3 2026 vs 1
Open actions
i
Open actions
Remediation actions not yet closed. Overdue means past the target date.
- Period
- All cycles
- Filters
- Third-Party Risk · Medium
- Updated
- 9 Oct 2026
- Source
- Meridian Alpha · assurance records (tests, findings, actions, validations, evidence)
2
0 overdue · 1 owner team
Validations passed
i
Validations passed
Retests of completed remediation. Failed means the fix did not hold.
- Period
- All cycles
- Filters
- Third-Party Risk · Medium
- Updated
- 9 Oct 2026
- Source
- Meridian Alpha · assurance records (tests, findings, actions, validations, evidence)
0/3
1 failed · 2 pending
Evidence approved
i
Evidence approved
Evidence reviewed and approved, out of all evidence collected.
- Period
- All cycles
- Filters
- Third-Party Risk · Medium
- Updated
- 9 Oct 2026
- Source
- Meridian Alpha · assurance records (tests, findings, actions, validations, evidence)
54%
7 of 13 · all cycles · 3 in review
Control testing results by domain · Q3 2026
Internal controlsEffectiveEffective with observationIneffective
- 2 of 2 controls failed testing in Q3 2026 (1 in Q2 2026); 0 high-severity findings are open.
- 1 remediation failed retest; 2 retests are pending.
- Salesforce (Sales + Financial Services Cloud) has the most open findings; Sanjay Kulkarni holds the most open actions.
- Continuous monitoring last ran on 9 Oct 2026.
Findings by severity
All findingsHighMediumLow
Q2 20261
Q3 20262
Open findings by application
Open actions by owner
ActionsOpen actions
Top open issues
All open findings| Issue | Control | Rating | Owner | Due | Status |
|---|---|---|---|---|---|
| Supplier agreement lacks information security clauses (A.5.20) | VEN-02 | Medium | Sanjay Kulkarni | 31 Oct 2026 | In Progress |
| Material outsourcing: lapsed assurance and overdue reassessment (Outsourcing of IT Services 2023 §6/§9) | VEN-01 | Medium | Sanjay Kulkarni | 20 Oct 2026 | Open |
Remediation status
3
actions
- Closed 133%
- In progress 133%
- Open 133%
Actions due by month
View2Oct 2026
OpenIn progress0 overdue
Continuous monitoring
Security & access8findings on 8 of 27 controls
Last run 9 Oct 2026
0 controls with no run recorded
Regulatory change
RegulatoryRBI · Strengthening cyber resilience and digital payment security for regulated entities
6 controls affected · 3 gaps · effective 1 Apr 2027
Third-party
Third partyPayGate Payments Pvt. Ltd. · Security incident PG-SEC-2026-014
3 applications · 2 of 4 actions validated