AI Governance & Compliance Platform
6-module deep-dive into AI governance frameworks — from NIST AI RMF and ISO 42001 to India-specific DPDP Act 2023 and RBI guidelines. Interactive tools for compliance assessment, risk registers, policy generation, and ethical AI evaluation.
NIST AI RMF 1.0
Four-function framework (Govern, Map, Measure, Manage) with GenAI profile — practical implementation guide for trustworthy AI.
ISO 42001:2023
The first international AI Management System standard. Gap analysis, clause-by-clause requirements, and certification roadmap.
EU AI Act
Risk-based AI regulation — prohibited AI, high-risk obligations, GPAI model rules, and timeline for enforcement. India exposure assessment.
DPDP Act 2023
Complete obligation mapper for AI systems processing Indian personal data — consent, automated decisions, cross-border transfers, penalties.
RBI AI Guidelines
Model risk management for BFSI — credit scoring, fraud detection, KYC/AML, algo trading compliance with RBI + SEBI + IRDAI requirements.
AI Ethics & Red Team
Responsible AI assessment: fairness, transparency, accountability, harm prevention. Red team exercise builder and AI ethics impact assessment.
NIST AI Risk Management Framework 1.0
Published January 2023 by NIST, the AI RMF provides a flexible, voluntary framework for managing AI risks throughout the AI lifecycle. Organised around four core functions — Govern, Map, Measure, Manage — with a GenAI Profile extension for LLMs.
The AI RMF is built around Trustworthiness characteristics — valid & reliable, safe, secure & resilient, explainable & interpretable, privacy-enhanced, fair with managed bias, accountable & transparent. These map to four operational functions.
| Function | Purpose | Key Activities | Who Leads |
|---|---|---|---|
| GOVERN | Establish AI risk culture, policies, roles | AI policy creation, accountability, workforce training, risk tolerance definition | C-Suite, CISO, Board |
| MAP | Categorize AI risk context | Identify affected stakeholders, classify AI system, document intended/unintended uses | Product/AI Teams |
| MEASURE | Analyze & assess AI risks | Test for bias, robustness, explainability, security; benchmark metrics; third-party audit | ML/Security Engineers |
| MANAGE | Prioritize & address AI risks | Risk treatment decisions, incident response, continuous monitoring, decommissioning | Risk/Operations Teams |
GOVERN is the foundational function — it creates the conditions under which all other RMF activities operate. Without governance structures, MAP/MEASURE/MANAGE activities lack authority, accountability, and sustainability.
| Measure Category | What to Test | Methods | Frequency |
|---|---|---|---|
| Accuracy & Reliability | Performance on representative test sets, distribution shift detection | Holdout evaluation, A/B testing, shadow deployment | Pre-launch + monthly |
| Bias & Fairness | Disparate impact across protected groups (gender, caste, religion, age) | Demographic parity, equalized odds, counterfactual fairness | Pre-launch + quarterly |
| Robustness & Security | Adversarial inputs, distribution shift, model extraction, prompt injection | Red team, adversarial testing, ATLAS-based attack simulations | Pre-launch + after incidents |
| Explainability | Can outcomes be explained to affected individuals? | LIME, SHAP, attention visualization, counterfactual explanations | Pre-launch + on demand |
| Privacy | Membership inference risk, PII in training data, model inversion | Privacy audit, differential privacy measurement, red team | Pre-launch + annually |
| Transparency | Stakeholders can understand AI system purpose and limitations | Model cards, system cards, documentation review | Pre-launch + on change |
| GenAI Risk | Description | Key Controls |
|---|---|---|
| CBRN Information | LLM assists in creating weapons of mass destruction information | Training data filtering, output content classifiers, prohibited query detection |
| Confabulation | Model generates plausible but false information (hallucination) | Retrieval augmentation, confidence scoring, human review for high-stakes outputs |
| Data Privacy Violations | PII or sensitive data included in training or generated in outputs | Training data audit, output filtering, differential privacy, membership inference testing |
| Harmful Bias & Homogenisation | Systematically biased outputs disadvantage protected groups | Bias benchmarks (BBQ, WinoBias), red team for demographic harm, diverse evaluation sets |
| Human-AI Configuration | Misalignment between intended and actual human oversight level | Document intended automation level, test for automation bias in users, HITL procedures |
| Information Integrity | Synthetic media or generated text used for disinformation | Content provenance (C2PA), watermarking, detection model deployment |
| Intellectual Property | Model memorises and reproduces copyrighted training data | Training data licensing, memorisation testing, output filtering |
Rate your organisation's implementation of each RMF function (0=None, 1=Partial, 2=Implemented, 3=Optimised).
ISO/IEC 42001:2023 — AI Management System
The first international standard for AI management systems — certifiable like ISO 27001. Published December 2023, it provides requirements for establishing, implementing, maintaining, and continually improving an AI management system within organisations.
| Clause | Title | Key Requirements | ISO 27001 Parallel |
|---|---|---|---|
| 4 | Context of the Organisation | Internal/external issues, interested parties, AIMS scope, AI policy context | Clause 4 |
| 5 | Leadership | Top management commitment, AI policy, organisational roles for AI | Clause 5 |
| 6 | Planning | AI risk & opportunity assessment, AI objectives, planning for changes | Clause 6 |
| 7 | Support | Resources, competence, awareness, communication, documented information | Clause 7 |
| 8 | Operation | AI system impact assessment, AI system lifecycle, data for AI, third-party AI | Clause 8 (A.8) |
| 9 | Performance Evaluation | Monitoring, measurement, internal audit, management review | Clause 9 |
| 10 | Improvement | Nonconformity, corrective action, continual improvement | Clause 10 |
| Annex A | AI Controls Reference | Controls for objectives, risk, impact assessment, data, system lifecycle, transparency | Annex A |
| Control Area | Requirement | Evidence Required |
|---|---|---|
| 8.3 AI System Lifecycle | Documented process covering design, development, testing, deployment, monitoring, and decommissioning | Lifecycle process documentation, stage-gate checklists |
| 8.4 Data for AI | Data governance for AI: data quality, provenance, consent, bias assessment of training data | Data governance policy, training data inventory, bias testing results |
| 8.5 AI System Testing | Testing against intended performance, safety, security, and bias criteria before deployment | Test plans, test results, sign-off records |
| 8.6 Third-Party AI | Governance of procured AI models, datasets, and services — including open-source | Vendor assessment records, procurement security checklist |
| Annex A.6: Transparency | Disclose AI use to affected individuals; provide explanations for AI-based decisions | Transparency disclosures, explanation capability demonstration |
| Annex A.8: Human Oversight | Define and implement appropriate human oversight for each AI system use case | Oversight procedures, HITL logs, escalation records |
Rate your current implementation for each key ISO 42001 requirement.
EU AI Act 2024 — Risk-Based AI Regulation
The EU AI Act (entered into force August 2024) is the world's first comprehensive AI law. Risk-based approach: prohibited AI practices, high-risk obligations, limited-risk transparency requirements, and systemic risk rules for GPAI models. Indian companies exporting to EU must comply.
| Risk Tier | Examples | Obligations | Penalty |
|---|---|---|---|
| Unacceptable PROHIBITED | Social scoring by governments, real-time remote biometric ID in public, subliminal manipulation, emotion recognition in workplaces/education | Complete ban — cannot deploy in EU | Up to €35M or 7% global turnover |
| High Risk | AI in critical infrastructure, education (exam scoring), employment (CV screening), credit scoring, biometric identification, law enforcement, judicial decisions | Conformity assessment, CE marking, registration in EU database, human oversight, transparency, data governance, technical documentation, logging | Up to €15M or 3% global turnover |
| Limited Risk | Chatbots, AI-generated content, deepfakes (non-prohibited), emotion recognition in limited contexts | Transparency disclosure: "You are interacting with an AI." Deepfake labelling. GPAI content labelling. | Up to €7.5M or 1.5% global turnover |
| Minimal Risk | Spam filters, AI in video games, AI-assisted manufacturing (non-safety-critical) | No mandatory requirements — voluntary codes of practice encouraged | N/A |
| Obligation | All GPAI Providers | Systemic Risk Models (>10²⁵ FLOPs) |
|---|---|---|
| Technical documentation | ✅ Required | ✅ Enhanced documentation |
| Training data summary | ✅ Required | ✅ Required |
| Copyright compliance | ✅ EU copyright law compliance | ✅ Enhanced |
| AI content labelling | ✅ Machine-readable AI content marking | ✅ Required |
| Adversarial testing | ❌ Not required | ✅ Red teaming before deployment |
| Cybersecurity measures | ❌ Not required | ✅ Required |
| Incident reporting | ❌ Not required | ✅ Serious incidents to AI Office |
| Energy efficiency | ❌ Not required | ✅ Compute/energy disclosure |
| Date | Milestone | Who Is Affected |
|---|---|---|
| Aug 2024 | Act enters into force | All — starting point for compliance timeline |
| Feb 2025 | Prohibited AI practices ban takes effect | Anyone deploying AI in EU — zero tolerance |
| Aug 2025 | GPAI model obligations apply | Foundation model providers (Anthropic, OpenAI, Google, open-source) |
| Aug 2025 | Governance provisions + AI Office established | Large organisations — designate AI compliance officers |
| Aug 2026 | High-risk AI obligations fully applicable | High-risk AI system providers and deployers — conformity assessments required |
| Aug 2027 | High-risk AI in Annex I sectors | AI in existing regulated sectors (medical devices, machinery, cars) |
Assess your EU AI Act exposure as an Indian organisation.
DPDP Act 2023 — Complete AI Compliance Guide
The Digital Personal Data Protection Act 2023 is India's primary data protection law — directly applicable to all AI systems processing personal data of Indian citizens. Interactive compliance mapper, obligation reference, and penalty calculator.
| Section | Obligation | AI Application | Penalty |
|---|---|---|---|
| S.4 | Lawful basis for processing | Consent or "legitimate use" before training or inference on personal data | Rs.50Cr |
| S.6 | Notice & Consent | Clear notice of AI processing purpose; specific, informed, revocable consent; bundled consent insufficient | Rs.250Cr |
| S.7 | Sensitive data protection | Enhanced security for biometrics, health data, financial data in AI systems | Rs.200Cr |
| S.8 | General obligations of Data Fiduciary | Data minimisation (don't collect more than needed), accuracy, security safeguards, DPDP-compliant processing | Rs.250Cr |
| S.9 | Children's data | Parental/guardian consent; NO profiling, behavioural monitoring, or targeted advertising to children | Rs.200Cr |
| S.11–12 | Data principal rights | Right to info (what AI processed), right to correction (fix inaccurate data), right to erasure (delete including training retraining) | Rs.50–250Cr |
| S.16 | Cross-border data transfer | AI cloud processing of Indian data: only to countries notified by Central Government (list pending) | Rs.200Cr |
| S.8(7) | Breach notification | Report AI-related data breaches to DPBI and affected data principals; specific format and timeline per DPDP Rules | Rs.250Cr |
RBI AI Guidelines — BFSI Compliance
RBI, SEBI, and IRDAI have issued guidance on AI/ML use in financial services. Model risk management, explainability, bias testing, human oversight, and data localisation requirements for banks, NBFCs, insurers, and capital market intermediaries.
RBI's Master Circular on Risk Management and the IT Framework for banks (2023 update) explicitly address AI/ML model risk. Key principles:
| Use Case | Regulator | Key Requirements | Explainability |
|---|---|---|---|
| Credit Scoring / Loan | RBI | Independent model validation, bias testing, explainable rejection reasons, human review for borderline cases | Mandatory |
| Fraud Detection (UPI/Cards) | RBI / NPCI | Real-time monitoring, false positive rate tracking, customer dispute mechanism, audit trail | Recommended |
| KYC / AML | RBI / FIU-IND | Video KYC guidelines, liveness detection standards, AML model validation, STR threshold documentation | Mandatory |
| Algorithmic Trading | SEBI | Pre-trade risk controls, circuit breakers, audit trail, co-location rules, algorithmic strategy registration | Mandatory |
| Insurance Underwriting | IRDAI | Product filing for AI-based pricing, non-discriminatory underwriting, actuary sign-off, customer disclosure | Recommended |
| Customer Service (Chatbot) | RBI / SEBI | Escalation to human for complaints, clear AI disclosure, not for regulated advice, data localisation | Not Required |
| Robo-Advisory | SEBI | IA/RA registration, investment advice suitability, human oversight for portfolio rebalancing, conflict disclosure | Mandatory |
AI Ethics, Responsible AI & Red Team
Responsible AI goes beyond regulatory compliance — it requires proactive assessment of fairness, transparency, accountability, and harm prevention. Interactive ethics assessment tool, red team exercise builder, and model card generator.
Rate each dimension of your AI system (1=Very Poor to 5=Excellent). This assessment maps to NIST AI RMF trustworthiness characteristics.
Model cards document AI system purpose, limitations, and biases. Required by ISO 42001 and good practice for DPDP Act transparency obligations.