← QuickTurn / 209a4fb7-3ab7-4fdd
BLANK.Standard_SIG_2026_v2.xlsx
Customer: Meridian · Project: Q2 Security Review
A.1Is there a formalized risk governance policy approved by management?Yes, there is a formalized Enterprise Risk Management (ERM) Policy approved by management on January 1, 2026. The policy defines the requirements of the ERM program...answered
A.1.1Does the risk governance program include risk management policies, procedures, and internal controls?Yes, the risk governance program at Stark includes risk management policies, procedures, and internal controls as outlined in the formalized Enterprise Risk Management (ERM) Policy...answered
A.1.2Does the risk governance program include range of assets: people, processes, data, and technology?Yes, the risk governance program includes a range of assets encompassing people, processes, data, and technology, as integrated into the ERM Policy...answered
A.1.3Does the governing body define accountabilities and obligations of the Board of Directors for risk management?Yes, the governing body at Stark defines the accountabilities and obligations of the Board of Directors for risk management, as outlined in the ERM Policy...answered
A.1.4Is the risk management program approved by senior management and/or board of directors?Yes, the risk governance program at Stark is approved by senior management and the governing body, as the policy defines the...answered
A.1.5Is training provided to employees regarding risk expectations and their obligations?Yes, training is provided to employees regarding risk expectations and their obligations as part of the risk governance program...answered
A.1.6Does the risk management program include processes that analyze risk at the enterprise level?Yes, the organization’s risk management program includes processes that analyze risk at the enterprise level while keeping stakeholders informed...pending