India Regulatory Landscape
Every question maps to a statute
No proprietary frameworks. Every gap finding cites the exact Indian regulation your organization must address.
Incident Response
CERT-In Directions 2022
6-hour breach reporting, 180-day log retention, NTP sync, empaneled auditor requirement. Applies to all organisations, intermediaries, and government bodies.
CERT-In Directions §3 • Audit Policy 2025
Data Protection
DPDP Act 2023 + Rules 2025
Consent management, Data Principal rights, breach notification to Data Protection Board. Penalties up to ₹250 crore. Rules notified Nov 2025.
DPDP Act §6, §8, §12–14, §25 • DPDP Rules 2025
AI Governance
MeitY AI Guidelines Nov 2025
Seven sutras: Trust, People First, Fairness & Equity, Accountability, Understandable by Design, Safety & Resilience, Innovation over Restraint.
MeitY AI Governance Guidelines • IndiaAI Mission
Financial Sector AI
RBI FREE-AI Aug 2025
26 recommendations across 6 pillars: Infrastructure, Policy, Capacity, Governance, Protection, Assurance. Mandatory for banks, NBFCs, and RBI-regulated entities.
RBI FREE-AI Committee Report • Aug 2025
Critical Infrastructure
NCIIPC Guidelines
Protection of Critical Information Infrastructure. Power, telecom, banking, transport, government, and strategic sectors. Mandatory reporting to NCIIPC.
IT Act §70A • NCIIPC Sector Guidelines
Synthetic Content
IT (SGI) Rules Feb 2026
Synthetically Generated Information: detection, labeling, traceability for AI-generated text, images, audio, and video. Applies to platforms and deployers.
IT (Intermediary) Amendment Rules 2026 • MeitY
International Standard
NIST AI RMF 1.0
Four core functions: GOVERN (policies, accountability), MAP (context, risk identification), MEASURE (evaluation, monitoring), MANAGE (response, tracking). 39 categories mapped directly to India regulatory requirements.
NIST AI 100-1 (Jan 2023) • GOVERN 1.5 • MEASURE 2.2/2.8 • MANAGE 1.1/3.1
International Standard
ISO/IEC 42001:2023
First international standard for AI management systems. Certifiable. Covers AI policy, risk assessment (§6.1.2), AI system impact assessment (§8.4), performance evaluation (§9.1), and continual improvement (§10.2).
ISO/IEC 42001:2023 • §4.2 §5.2 §6.1.2 §8.2 §8.3 §8.4 §8.5 §9.1 §10.2