๐ŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
GRC starter kit ยท paid plan

GRC Starter Kit โ€” Meridian Global Bank Edition

Eighty audit-ready policies, procedures, standards, guidelines, and internal-audit documents, all written for one fully worked fictional global bank โ€” a 104-country, four-cloud, twenty-firewall-zone institution โ€” so every document has real, consistent detail instead of bracketed placeholders. Download any document on its own as a PDF, or take the whole kit as a ZIP and adapt it to whatever organization you're actually working with.

Kit progress80 of 80 documents ready
Download entire kit (ZIP) 10 audit findings reviewed & corrected across 4 passes
About the reference organization

Meridian Global Bank is a fictional universal bank headquartered in Zurich, Switzerland, founded in 1962. It employs approximately 185,000 people and serves 42 million retail customers, 220,000 commercial and corporate clients, and 1,100 institutional clients through licensed retail, commercial, or wealth operations in 104 countries.

The bank operates four primary data centers โ€” Zurich (home region), Ashburn, Virginia (Americas), Frankfurt (EMEA), and Singapore (APAC) โ€” plus a fifth disaster-recovery site. Its cloud footprint spans four environments: AWS (the primary cloud, roughly 55% of workloads), Microsoft Azure (about 25%, largely Microsoft 365 and EU data-residency workloads), Google Cloud (about 15%, home to the AI and analytics platform), and MeridianPrivateCloud, an on-premises OpenStack environment carrying the payment switch and other systems too sensitive to place in a public cloud.

More than twenty SaaS platforms support the business, including Salesforce, Workday, ServiceNow, Okta, SailPoint, Snowflake, Datadog, GitHub Enterprise Cloud, and Genesys Cloud, among others. Identity is split across four systems in various stages of consolidation: Okta as the primary workforce identity provider, a legacy Microsoft Entra ID tenant retained from a 2019 acquisition, Ping Identity as the customer-facing identity platform for 42 million consumer identities, and a legacy on-premises Active Directory forest still authenticating core-banking terminals in twelve countries.

The network is segmented into 20 security zones enforced by roughly 165 firewalls โ€” a mix of Palo Alto Networks appliances at the data-center edge and Fortinet devices at the regional and branch level โ€” with Cisco in the core and distribution layers and Juniper at the WAN edge. F5 and Cloudflare provide web application firewall and edge protection for internet-facing digital banking and public APIs, backed by a scrubbing-center arrangement with a Tier-1 carrier for volumetric attacks against the branch and ATM network.

An internal AI platform, built on Google Cloud Vertex AI with some Azure OpenAI Service instances, runs fraud detection, credit risk scoring, AML transaction monitoring, and a staff-facing generative AI assistant, all sitting behind a dedicated AI security gateway that inspects prompts and responses, redacts personal data, and watches for model abuse. Telephony is mid-migration from a legacy Avaya PBX to Microsoft Teams Phone and Zoom Phone, with card-related call center traffic handled separately through Genesys Cloud for PCI scope reasons.

The bank issues co-badged Visa and Mastercard cards, operates as a direct merchant acquirer in 40 countries, and runs approximately 9,000 ATMs. Its core ledger runs on Temenos T24 in most regions, with a legacy IBM mainframe still processing the original correspondent-banking ledger in Zurich pending a migration targeted for 2029. Payment rails include SWIFT, SEPA, Fedwire and ACH, and a dozen local real-time payment schemes.

Security is led by a Chief Information Security Officer reporting to the Chief Risk Officer, supported by regional CISOs for the Americas, EMEA, and APAC, a Head of Identity and Access Management, a Head of Corporate Security responsible for branch and office physical security, and a follow-the-sun Security Operations Center running continuously out of Zurich, Singapore, and a US site. The bank protects 35 designated executives through a combined physical and digital executive protection program. Primary regulators include FINMA (home), the Federal Reserve and OCC (US), the ECB and BaFin (EU/Germany), and MAS (Singapore), alongside roughly sixty additional local banking regulators across its footprint, with obligations spanning Basel III, PCI DSS, SWIFT Customer Security Programme, GDPR, and local data-protection and data-residency law in each of its 104 countries.

founded1962
headquartersZurich, Switzerland
employees~185,000
countries104
retail Customers42 million
commercial Clients220,000
institutional Clients1,100
data Centers4 primary regions (Zurich, Ashburn VA, Frankfurt, Singapore) + 1 DR site
cloudsAWS (~55%), Microsoft Azure (~25%), Google Cloud (~15%), MeridianPrivateCloud (~5%, on-prem OpenStack)
saas Count20+
identity ProvidersOkta (workforce), Microsoft Entra ID (legacy EU estate), Ping Identity (42M consumer identities), legacy on-prem Active Directory (12 countries)
firewalls~165 (Palo Alto Networks + Fortinet)
security Zones20
network VendorsCisco (core/distribution), Juniper (WAN edge)
waf EdgeF5 + Cloudflare, with Tier-1 carrier DDoS scrubbing
telephonyAvaya PBX migrating to Microsoft Teams Phone / Zoom Phone; Genesys Cloud for PCI-scoped call center traffic
ai PlatformMeridian AI Platform (GCP Vertex AI + Azure OpenAI Service) behind a dedicated AI security gateway
core BankingTemenos T24 (most regions) + legacy IBM mainframe in Zurich (correspondent banking, migrating by 2029)
payment RailsSWIFT, SEPA, Fedwire, ACH, and local real-time payment schemes
atms~9,000
card Acquiring40 countries
exec Protection35 designated executives, physical + digital protection program
regulatorsFINMA (home), Federal Reserve/OCC (US), ECB/BaFin (EU), MAS (Singapore), ~60 additional local banking regulators
security OrgCISO reports to Chief Risk Officer; regional CISOs for Americas, EMEA, APAC; Head of Identity and Access Management; Head of Corporate Security; follow-the-sun SOC in Zurich, Singapore, and the US

Governance & Core Policy

Policy#1

Information Security Policy

The umbrella policy that establishes Meridian Global Bank's information security program, the authority behind every subordinate policy, standard, and procedure, and the obligations that apply to every employee, contractor, and third party with access to bank systems or data.

Download PDF
Policy#2

Risk Management Policy

Defines how Meridian Global Bank identifies, assesses, treats, and monitors technology and cyber risk as an integral part of enterprise risk management, and how that risk is escalated through the governance structure described in the Information Security Policy.

Download PDF
Policy#3

Cyber Risk Appetite Statement

Sets the boundaries within which Meridian Global Bank is willing to accept cyber and technology risk in pursuit of its business objectives, translating board-level risk tolerance into thresholds the Chief Information Security Officer and business units can act on.

Download PDF
Policy#4

Acceptable Use Policy

Sets out what every employee, contractor, and third party may and may not do with Meridian Global Bank's systems, networks, devices, and accounts, covering everyday use of corporate technology, SaaS platforms, and the bank's email and messaging systems.

Download PDF
Policy#5

Asset Management Policy

Establishes how Meridian Global Bank inventories, classifies, and assigns ownership to every hardware, software, cloud, and data asset it operates, so that every system in the four-cloud, twenty-zone estate has a named owner and a known lifecycle status.

Download PDF
Policy#6

Data Classification and Handling Policy

Defines the four data classification tiers Meridian Global Bank uses, the handling rules that attach to each tier, and how classification is applied consistently across the bank's core banking systems, data lake, and SaaS estate.

Download PDF
Policy#7

Data Protection and Privacy Policy

Sets Meridian Global Bank's commitments for lawful, fair, and transparent processing of personal data for its 42 million retail customers and 185,000 employees across 104 countries, and the controls that give those commitments effect.

Download PDF
Policy#8

Security Awareness and Training Policy

Establishes mandatory security awareness training for all 185,000 employees and contractors, role-based training for privileged and technical staff, and the phishing simulation program that measures whether the training is actually working.

Download PDF
Policy#9

Insider Threat Program Policy

Establishes a formal, cross-functional program to detect and respond to risk from employees, contractors, and trusted third parties who misuse legitimate access, whether through malicious intent, negligence, or coercion.

Download PDF
Policy#10

Security Metrics and Board Reporting Framework

Defines the metrics Meridian Global Bank uses to measure the effectiveness of its security program and the cadence and format in which those metrics are reported to executive management and the Board Risk Committee.

Download PDF

Identity, Access & Endpoint

Policy#11

Access Control and Identity Management Policy

Establishes the principles governing who may access Meridian Global Bank systems and data, across its four identity providers and 185,000-strong workforce, built on least privilege and need-to-know.

Download PDF
Standard#12

Privileged Access Management Standard

Sets the technical and process controls that apply to every privileged account across Meridian Global Bank's four clouds, on-premises estate, and network infrastructure, given that privileged accounts carry the highest blast radius of any credential in the bank.

Download PDF
Standard#13

Password and Authentication Standard

Defines the authentication requirements for workforce and customer-facing systems, reflecting current guidance that favors phishing-resistant multi-factor authentication over legacy password-complexity rules alone.

Download PDF
Procedure#14

Joiner-Mover-Leaver Access Provisioning Procedure

Documents the step-by-step process for granting, adjusting, and revoking access as an employee joins, changes role within, or leaves Meridian Global Bank โ€” the single highest-volume identity process across the 185,000-person workforce.

Download PDF
Policy#15

Remote Access Policy

Governs how employees and contractors connect to Meridian Global Bank systems from outside a bank facility, reflecting the bank's hybrid workforce across 104 countries.

Download PDF
Policy#16

Bring Your Own Device (BYOD) Policy

Sets the terms under which personally owned devices may access Meridian Global Bank systems, limited strictly to non-privileged staff and a defined set of low-risk applications.

Download PDF
Standard#17

Mobile Device Management Standard

Sets the technical baseline for every corporate-managed mobile device and laptop across Meridian Global Bank's 104-country workforce, and the enrollment, monitoring, and wipe procedures that apply to them.

Download PDF
Standard#18

Endpoint Protection Standard

Defines the endpoint detection and response, anti-malware, and hardening baseline required on every laptop, server, and ATM endpoint across Meridian Global Bank.

Download PDF
Standard#19

Wireless Network Security Standard

Sets the security requirements for wireless networks across Meridian Global Bank's data centers, corporate offices, and branch network spanning 104 countries.

Download PDF
Standard#20

Physical and Branch Security Standard

Sets the physical access control, surveillance, and cash-handling security baseline for Meridian Global Bank's branch network and corporate offices across 104 countries.

Download PDF

Network, Cloud & Infrastructure

Policy#21

Network Security Policy

Establishes the principles governing Meridian Global Bank's network architecture, segmentation, and perimeter defense across its four data centers, twenty security zones, and roughly 165 firewalls.

Download PDF
Standard#22

Network Segmentation and Zone Architecture Standard

Formally defines Meridian Global Bank's twenty network security zones, what each zone contains, and the inter-zone traffic rules enforced by the bank's roughly 165 firewalls.

Download PDF
Standard#23

Firewall Management and Change Standard

Sets the change control, rule hygiene, and review requirements for Meridian Global Bank's roughly 165 firewalls enforcing its twenty security zones.

Download PDF
Standard#24

Router and Switch Security Configuration Standard

Sets the hardening baseline for Meridian Global Bank's Cisco core and distribution switching fabric and Juniper WAN edge routing infrastructure.

Download PDF
Standard#25

Web Application Firewall and Edge Protection Standard

Sets the requirements for Meridian Global Bank's F5 and Cloudflare web application firewall and edge protection layer, guarding every internet-facing digital banking service and public API.

Download PDF
Policy#26

Cloud Security Policy

Sets the governance principles that apply across Meridian Global Bank's four cloud environments โ€” AWS, Microsoft Azure, Google Cloud, and MeridianPrivateCloud โ€” with provider-specific implementation detail in the three public-cloud security baselines.

Download PDF
Standard#27

AWS Security Baseline

Sets the mandatory configuration baseline for Meridian Global Bank's AWS environment, the bank's primary cloud, hosting roughly 55% of workloads.

Download PDF
Standard#28

Azure Security Baseline

Sets the mandatory configuration baseline for Meridian Global Bank's Microsoft Azure environment, hosting roughly 25% of workloads including Microsoft 365 and EU data-residency-sensitive systems.

Download PDF
Standard#29

GCP Security Baseline

Sets the mandatory configuration baseline for Meridian Global Bank's Google Cloud environment, home to the Meridian AI Platform and roughly 15% of the bank's workloads.

Download PDF
Standard#30

Zero Trust Network Access Standard

Defines the architecture and rollout of Meridian Global Bank's Zero Trust Network Access platform, which brokers per-application access for remote and, increasingly, on-premises users rather than relying on broad network-level trust.

Download PDF

Application, Data & Emerging Tech

Policy#31

Secure Software Development Policy

Sets the secure development lifecycle requirements for every application Meridian Global Bank builds in-house, across its digital banking platforms, internal tools, and the Meridian AI Platform.

Download PDF
Standard#32

API Security Standard

Sets the security requirements for every API Meridian Global Bank exposes or consumes, spanning internal service-to-service APIs, partner integrations, and public open-banking endpoints.

Download PDF
Standard#33

Container and Kubernetes Security Standard

Sets the security requirements for containerized workloads and Kubernetes clusters running across Meridian Global Bank's AWS, Azure, GCP, and MeridianPrivateCloud environments.

Download PDF
Policy#34

Cryptography and Key Management Policy

Sets the approved cryptographic algorithms, key management lifecycle, and usage requirements for protecting data across Meridian Global Bank's four data centers, four cloud environments, and payment infrastructure.

Download PDF
Standard#35

PKI and Certificate Lifecycle Standard

Sets the requirements for issuing, deploying, monitoring, and renewing digital certificates across Meridian Global Bank's internet-facing services, internal systems, and device fleet.

Download PDF
Policy#36

Data Loss Prevention Policy

Sets the controls Meridian Global Bank uses to detect and prevent unauthorized movement of Restricted and Confidential data out of its managed environment, across email, SaaS platforms, endpoints, and cloud storage.

Download PDF
Policy#37

AI Governance and Ethics Policy

Establishes how Meridian Global Bank governs the development, approval, and ongoing oversight of AI systems, including the Meridian AI Platform's fraud detection, credit risk, AML monitoring, and generative AI capabilities.

Download PDF
Standard#38

AI System Security and Protection Standard

Sets the technical security controls protecting the Meridian AI Platform and every model, pipeline, and AI security gateway in Meridian Global Bank's AI ecosystem.

Download PDF
Standard#39

AI Model Risk and Adversarial Testing Standard

Sets the ongoing testing regime for AI models in production at Meridian Global Bank, covering both traditional model risk (accuracy, drift, bias) and adversarial security risk specific to AI systems.

Download PDF
Policy#40

Core Banking and Payment Systems Security Policy

Sets the security requirements for Meridian Global Bank's core banking ledger, payment switch, card issuing and acquiring systems, and ATM network โ€” the systems carrying the bank's highest transaction and regulatory exposure.

Download PDF

Operations, Monitoring & Third Parties

Policy#41

Logging and Monitoring Policy

Sets the requirements for security-relevant logging, retention, and monitoring across Meridian Global Bank's four data centers, four cloud environments, and twenty network security zones, feeding the Security Operations Center's detection capability.

Download PDF
Policy#42

Security Operations Center Charter

Establishes the mission, structure, and operating model of Meridian Global Bank's follow-the-sun Security Operations Center, which monitors the bank's entire technology estate around the clock from Zurich, Singapore, and a US site.

Download PDF
Policy#43

Threat Intelligence Program Policy

Establishes how Meridian Global Bank collects, analyzes, and acts on threat intelligence relevant to its specific footprint as a global bank across 104 countries, four clouds, and the payment systems it operates.

Download PDF
Policy#44

Vulnerability and Patch Management Policy

Sets the vulnerability scanning, risk-rating, and remediation timeline requirements across Meridian Global Bank's four data centers, four cloud environments, network infrastructure, and endpoint fleet.

Download PDF
Policy#45

Change Management Policy

Sets the approval, testing, and rollback requirements for changes to production systems across Meridian Global Bank's technology estate, ensuring changes are deliberate, reviewed, and reversible.

Download PDF
Policy#46

Third-Party and Vendor Risk Management Policy

Sets the assessment, contracting, and ongoing monitoring requirements for every third party Meridian Global Bank relies on, from its more than twenty SaaS platforms to its cloud providers, correspondent banks, and card network partners.

Download PDF
Standard#47

Vendor Security Assessment Standard

Sets the specific questionnaire, evidence, and scoring methodology used to assess third-party security posture under the Third-Party and Vendor Risk Management Policy.

Download PDF
Policy#48

Shadow IT and Unsanctioned SaaS Policy

Sets how Meridian Global Bank discovers, evaluates, and responds to technology adopted outside the sanctioned catalog of more than twenty SaaS platforms, and defines the path for employees to request a new tool through proper channels.

Download PDF
Policy#49

Supply Chain Security Policy

Sets Meridian Global Bank's approach to managing risk introduced through hardware, firmware, and software supply chains, distinct from the direct vendor-service relationships covered by the Third-Party and Vendor Risk Management Policy.

Download PDF
Policy#50

Telephony and Unified Communications Security Policy

Sets the security requirements for Meridian Global Bank's voice and unified communications systems, spanning the legacy Avaya PBX, its migration to Microsoft Teams Phone and Zoom Phone, and the Genesys Cloud contact center platform.

Download PDF

Resilience, Executive & Physical

Policy#51

Business Continuity Policy

Establishes Meridian Global Bank's commitment to maintaining critical operations through disruption, across its four data centers, branch network in 104 countries, and payment infrastructure.

Download PDF
Policy#52

Disaster Recovery Policy

Sets the technical recovery objectives and testing requirements for Meridian Global Bank's systems, ensuring the bank can restore critical technology services within a defined, tested timeframe.

Download PDF
Procedure#53

Business Continuity Activation Procedure

Documents the step-by-step activation process when a disruption requires Meridian Global Bank to invoke its business continuity or disaster recovery plans.

Download PDF
Procedure#54

Backup and Restore Procedure

Documents the backup schedule, retention, and restore testing process for Meridian Global Bank's data across its four data centers, four cloud environments, and SaaS estate.

Download PDF
Policy#55

Data Center Physical and Environmental Security Policy

Sets the physical access control and environmental protection requirements for Meridian Global Bank's four primary data centers and disaster-recovery site.

Download PDF
Standard#56

Building Management System and OT Security Standard

Sets security requirements for the operational technology (OT) systems controlling Meridian Global Bank's facilities โ€” building management, HVAC, power, and physical security systems โ€” distinct from the IT estate.

Download PDF
Policy#57

Executive and VIP Digital Protection Program

Establishes enhanced digital security protections for Meridian Global Bank's 35 designated executives, whose personal exposure, public profile, and system access make them disproportionately targeted relative to the general workforce.

Download PDF
Procedure#58

Executive Travel and Physical Security Protocol

Sets the physical security protocol for Meridian Global Bank's designated executives when traveling, particularly across the higher-risk jurisdictions within the bank's 104-country footprint.

Download PDF
Procedure#59

Crisis Communication Plan

Sets how Meridian Global Bank communicates internally and externally during a significant incident, outage, or crisis, ensuring messaging is accurate, timely, and coordinated across the bank's 104-country footprint.

Download PDF
Policy#60

Cyber Insurance and Risk Transfer Policy

Sets Meridian Global Bank's approach to transferring residual cyber risk through insurance, and the conditions under which the bank's cyber insurance program can actually be relied upon.

Download PDF

Incident Response & Testing

Policy#61

Incident Response Policy

Establishes Meridian Global Bank's obligation to detect, classify, and respond to security incidents consistently across its four data centers, four cloud environments, and 104-country footprint.

Download PDF
Procedure#62

Incident Response Procedure

Documents the operational playbook the Security Operations Center and incident responders follow when executing the six-phase lifecycle described in the Incident Response Policy.

Download PDF
Procedure#63

Data Breach Notification Procedure

Documents how Meridian Global Bank determines and executes its breach notification obligations across the many regulatory regimes and notification timelines that apply within its 104-country footprint.

Download PDF
Procedure#64

Cyber Tabletop Exercise Program

Sets the recurring schedule and format for tabletop exercises testing Meridian Global Bank's incident response, business continuity, and crisis communication plans against realistic scenarios.

Download PDF
Policy#65

Penetration Testing and Red Team Policy

Sets the requirements for offensive security testing โ€” penetration testing and red team exercises โ€” across Meridian Global Bank's internet-facing systems, internal network, cloud environments, and AI platform.

Download PDF
Policy#66

Bug Bounty and Responsible Disclosure Policy

Establishes how Meridian Global Bank accepts and rewards vulnerability reports from external security researchers, and the safe-harbor terms under which good-faith research is welcomed rather than treated as an attack.

Download PDF
Policy#67

Secure Disposal and Media Sanitization Policy

Sets the requirements for securely erasing or destroying data-bearing media and hardware before disposal, resale, or reallocation, across Meridian Global Bank's four data centers, endpoint fleet, and ATM network.

Download PDF
Procedure#68

IT Asset Decommissioning Procedure

Documents the step-by-step process for retiring a hardware asset, cloud resource, or software system from Meridian Global Bank's environment, ensuring nothing is decommissioned without proper data handling and inventory cleanup.

Download PDF
Procedure#69

Regulatory Change Management Procedure

Documents how Meridian Global Bank monitors, assesses, and implements changes to cyber-relevant regulation across its 104-country footprint, ensuring new or amended requirements translate into concrete control changes rather than staying theoretical.

Download PDF
Procedure#70

Cloud Account Provisioning and Deprovisioning Procedure

Documents how new AWS, Azure, GCP, and MeridianPrivateCloud accounts or projects are provisioned with baseline security controls in place from day one, and how they are safely deprovisioned when no longer needed.

Download PDF

Internal Audit & Compliance

Audit template#71

Annual Internal Audit Plan โ€” Cyber Domain

Sets the risk-based schedule of independent internal audits covering Meridian Global Bank's cyber and technology risk domain for the coming year, ensuring every major control area in this GRC library is independently tested on a defined cycle.

Download PDF
Audit template#72

IT General Controls Audit Program

Provides the detailed test program Internal Audit executes annually to assess IT general controls โ€” access management, change management, and operations โ€” across Meridian Global Bank's core systems.

Download PDF
Audit template#73

Firewall Rule Review and Audit Checklist

Provides the checklist used to independently verify that Meridian Global Bank's roughly 165 firewalls, enforcing its twenty security zones, are configured and managed consistently with the Firewall Management and Change Standard.

Download PDF
Audit template#74

Access Recertification Audit Report Template

Provides the standard reporting format for documenting the outcome of each quarterly access recertification cycle required under the Access Control and Identity Management Policy.

Download PDF
Audit template#75

Cloud Security Posture Audit Report Template

Provides the standard reporting format for the semi-annual independent audit of Meridian Global Bank's AWS, Azure, GCP, and MeridianPrivateCloud environments against their respective security baselines.

Download PDF
Audit template#76

Vendor Risk Audit Report Template

Provides the standard reporting format for the annual independent audit of Meridian Global Bank's third-party and vendor risk management program.

Download PDF
Audit template#77

AI System Risk Audit Report Template

Provides the standard reporting format for the annual independent audit of AI governance, security, and model risk controls across the Meridian AI Platform, examining compliance with the AI Governance and Ethics Policy, the AI System Security and Protection Standard, and the AI Model Risk and Adversarial Testing Standard.

Download PDF
Audit template#78

Audit Finding and Remediation Tracker

Provides the standard tracking structure Meridian Global Bank uses to record, assign, and follow every audit finding โ€” internal, regulatory, or third-party โ€” through to verified closure.

Download PDF
Audit template#79

Regulatory Compliance Mapping

Maps Meridian Global Bank's major cyber-relevant regulatory obligations to the specific GRC library documents and controls that satisfy them, providing a single reference for regulatory examinations across the bank's 104-country footprint.

Download PDF
Architecture#80

Reference Architecture and Cyber PMO Project Plan

Ties together the security architecture described across this GRC library into a single reference view, and sets out a prioritized program of work to close the architectural debt items this library has identified along the way.

Download PDF
Every document is a real PDF generated from structured content โ€” no Markdown files, no placeholder brackets left in.
GRC Starter Kit โ€” Meridian Global Bank Edition ยท PlayCISO