Cadres IT Operations & Infrastructure
Sheet MER-00 Rev 2026.08
Start Trial

Manual — Audit & Compliance Manual

Meridian manual.

Meridian covers programs, controls, evidence, audits, reporting, remediation, trust workflows, and SOX-capable oversight.

Audience: Compliance, risk, audit, and operating leads Focus: Programs, evidence, audits, and remediation

Meridian is the Cadres operating system for audit, compliance, and control follow-through. It brings programs, controls, evidence, reporting, remediation, and stakeholder visibility into one working model.

This manual is written for the teams who need Meridian to stay understandable in production. It starts with the public operating model, then layers in detailed operator guides drawn from the product manuals without exposing private implementation or setup material.

Compliance Core2 sheets
Oversight & Follow-through1 sheet
Detailed Operator Guides17 sheets
MER-04 Programs Program structure, scope ownership, framework planning, and the operating boundary for a compliance effort. MER-05 Controls Control creation, ownership, mapping, exceptions, testing, and the workflow that makes a control library usable. MER-06 Control Intelligence Coverage analysis, control relationships, and higher-signal views that help teams manage a control estate as it grows. MER-07 Evidence Evidence collection, review state, freshness, and the working practices that keep evidence tied to real controls. MER-08 Evidence Coverage Coverage visibility, readiness gaps, and the relationship between controls, evidence, and audit confidence. MER-09 Gap Analysis Requirement coverage, gaps, exceptions, and the review model teams use to judge audit readiness honestly. MER-10 Audit Workflow Audit planning, request handling, operator coordination, and the cadence that keeps audit work from becoming a scramble. MER-11 Auditor Portal Bounded external access, auditor collaboration, and the model Meridian uses to share review material without losing control. MER-12 Audit Reports Audit outputs, review packages, and the reporting layer teams use to communicate current audit state clearly. MER-13 Access Reviews Periodic access review execution, reviewer accountability, and the workflow that keeps sensitive access visible. MER-14 Executive Summary Leadership-facing posture views, concise status communication, and the summaries used to explain program state without flattening it. MER-15 Reporting Operational reporting, stakeholder visibility, and the reporting surfaces used to track posture over time. MER-16 Scheduled Reports Recurring reporting cadence, audience targeting, and the operational discipline around scheduled compliance output. MER-17 Remediation Bridge Findings-to-action workflow, ownership handoff, and the model Meridian uses to keep remediation tied to real systems and teams. MER-18 Trust Center Controlled external communication, trust materials, and the process for showing posture without oversharing it. MER-19 Risks Risk tracking, ownership, and the way Meridian keeps exposure tied to the controls and findings that drive it. MER-20 Risk Heatmap Concentration of exposure, prioritization signals, and the visual model teams use to discuss risk with leadership.
Read pathWhere teams usually start
  1. Start with Programs, Controls & Evidence to understand how Meridian organizes programs, control ownership, evidence, and posture.
  2. Move to Evidence & Audit Operations when audit readiness, auditor collaboration, and review workflow are the immediate concern.
  3. Use Reporting, Remediation & Trust for executive visibility, trust communication, ongoing follow-through, and connected operating work.
BridgesHow Meridian connects · optional
B-01

Portal

Portal supplies identity and access context that Meridian can use for reviews, evidence, and access-related controls.

B-02

Keystone

Keystone gives Meridian business and financial operating context when commercial or finance controls need to be monitored.

B-03

Relay

Relay gives Meridian operational signals and remediation context when infrastructure or endpoint control becomes part of the control environment.