Cadres IT Operations & Infrastructure
Plate 05 / 06 Rev 2026.08
Start Trial

Unit 05 — Audit & Compliance

Compliance without the screenshot ritual.

Meridian is the Cadres compliance platform for evidence, programs, SOX, internal audit, vendor risk, and auditor workflows. It seeds 24 frameworks, from SOC 2 and ISO 27001 through PCI DSS, FedRAMP Moderate, NIS2, and the EU AI Act, with over 1,700 cross-mappings between them, and a deterministic intelligence layer that scores control fit and detects gaps without calling any external API. AI can draft words here. It never issues verdicts.

Scope — What Meridian owns

Multi-framework programs with built-in intelligence

Add a second framework and the system calculates how much of it your existing controls already cover, from over 1,700 cross-mappings. The Control Intelligence engine scores every control candidate from five deterministic signals: requirement overlap, framework domain, governance peers, evidence overlap, and text similarity, and surfaces gaps and near-duplicates. Need a framework we do not seed? Build it, or import it through OSCAL.

Audit workflow with real evidence accountability

An audit cycle runs planning, fieldwork, reporting, complete. Test executions are immutable once saved. Cycle closure is gated: any control test with zero executions in the fieldwork window blocks completion, with an override that requires a reason and produces an audit record. Evidence packages are deterministic SHA-256 manifest ZIPs, and share tokens reveal their URL exactly once. The internal audit suite carries the same discipline upstream: portfolio planning, engagement execution, assurance mapping, and committee reporting.

SOX from ICFR to audit committee

SOX programs run COSO controls across financial accounts with PCAOB assertion linkage. Walkthroughs enforce separation of duties at the backend: the preparer cannot approve their own work. §302 sub-certifications dispatch to named respondents; only the named respondent can complete or decline. Deficiency aggregation, escalations, roll-forward, and representation letters carry the program through year end.

Auditors, vendors, and remediation that closes

External auditors accept an invite via OTP and work in a read-only portal scoped to a single cycle; every evidence download is SHA-256 verified and every page view is logged. Vendor risk runs the full lifecycle with questionnaire campaigns. The remediation bridge opens Jira tickets automatically when a finding is finalized or a control test fails, syncs status back, and advances the management action plan when the ticket closes.

Something you can show an auditor, not just explain to one.

Meridian is in early access. It stands on its own for compliance programs, SOX, internal audit, vendor risk, and access reviews, and it pairs naturally with the rest of Cadres when evidence should come from the operating record.

Frameworks24 seeded · 1,700+ mappings
EvidenceSHA-256 verified
SOXICFR · §302 · SoD enforced
ProgramEarly Access
Start Trial