AI Governance & Compliance Platform

AI Governance
Frameworks & Compliance

Comprehensive reference for AI governance — NIST AI RMF, ISO 42001, DPDP Act 2023, RBI AI guidelines, EU AI Act, and AI ethics. Interactive compliance tools built for Indian enterprises deploying AI in regulated sectors.

6
Frameworks
DPDP
Act 2023
RBI
Guidelines
EU AI
Act 2024
ISO
42001
AI Regulatory Feed
NEWEU AI Act enforcement begins Aug 2026 — high-risk AI systems require conformity assessments
INDIADPDP Rules 2025 draft: AI automated decision-making disclosure requirements finalized
NISTNIST AI RMF 1.0 + Generative AI Profile — mandatory for US federal AI deployments
RBIRBI Model Risk Management guidelines cover ML/AI in BFSI — explainability required
NEWISO 42001:2023 — first international AI management system standard now certifiable
SEBISEBI AI/ML framework for capital markets — algo trading audit trail requirements updated
INDIAMeitY AI Advisory 2023 — transparency and accountability guidelines for AI in India
NEWEU AI Act: General Purpose AI (GPAI) models >10^25 FLOPs face systemic risk obligations
RBIRBI circular: AI-based credit scoring must provide human-reviewable rejection reasons
INDIADPDP Act 2023 — AI automated decisions affecting Indians require disclosure + human review option| EUEU AI Act — high-risk AI systems require conformity assessment before EU market deployment| NISTNIST AI RMF Govern + Map + Measure + Manage — four functions for trustworthy AI| RBIRBI Model Risk Management — ML models in BFSI require explainability, bias testing, human oversight| ISOISO 42001:2023 — AI Management System Standard — first certifiable international AI governance framework| INDIADPDP Act penalty up to Rs.250 Crore — biometric AI processing without consent is highest risk| INDIADPDP Act 2023 — AI automated decisions affecting Indians require disclosure + human review option| EUEU AI Act — high-risk AI systems require conformity assessment before EU market deployment| NISTNIST AI RMF Govern + Map + Measure + Manage — four functions for trustworthy AI| RBIRBI Model Risk Management — ML models in BFSI require explainability, bias testing, human oversight| ISOISO 42001:2023 — AI Management System Standard — first certifiable international AI governance framework| INDIADPDP Act penalty up to Rs.250 Crore — biometric AI processing without consent is highest risk|
⚖️

AI Governance & Compliance Platform

6-module deep-dive into AI governance frameworks — from NIST AI RMF and ISO 42001 to India-specific DPDP Act 2023 and RBI guidelines. Interactive tools for compliance assessment, risk registers, policy generation, and ethical AI evaluation.

NIST AI RMF ISO 42001 DPDP 2023 RBI Guidelines EU AI Act
International Frameworks
NIST🏛️

NIST AI RMF 1.0

Four-function framework (Govern, Map, Measure, Manage) with GenAI profile — practical implementation guide for trustworthy AI.

ISO📋

ISO 42001:2023

The first international AI Management System standard. Gap analysis, clause-by-clause requirements, and certification roadmap.

EU 2024🇪🇺

EU AI Act

Risk-based AI regulation — prohibited AI, high-risk obligations, GPAI model rules, and timeline for enforcement. India exposure assessment.

India-Specific Compliance
INDIA🇮🇳

DPDP Act 2023

Complete obligation mapper for AI systems processing Indian personal data — consent, automated decisions, cross-border transfers, penalties.

RBI🏦

RBI AI Guidelines

Model risk management for BFSI — credit scoring, fraud detection, KYC/AML, algo trading compliance with RBI + SEBI + IRDAI requirements.

Tools⚖️

AI Ethics & Red Team

Responsible AI assessment: fairness, transparency, accountability, harm prevention. Red team exercise builder and AI ethics impact assessment.

🏛️

NIST AI Risk Management Framework 1.0

Published January 2023 by NIST, the AI RMF provides a flexible, voluntary framework for managing AI risks throughout the AI lifecycle. Organised around four core functions — Govern, Map, Measure, Manage — with a GenAI Profile extension for LLMs.

NIST AI RMF 1.0 GenAI Profile Voluntary Framework
NIST AI RMF Structure

The AI RMF is built around Trustworthiness characteristics — valid & reliable, safe, secure & resilient, explainable & interpretable, privacy-enhanced, fair with managed bias, accountable & transparent. These map to four operational functions.

FunctionPurposeKey ActivitiesWho Leads
GOVERNEstablish AI risk culture, policies, rolesAI policy creation, accountability, workforce training, risk tolerance definitionC-Suite, CISO, Board
MAPCategorize AI risk contextIdentify affected stakeholders, classify AI system, document intended/unintended usesProduct/AI Teams
MEASUREAnalyze & assess AI risksTest for bias, robustness, explainability, security; benchmark metrics; third-party auditML/Security Engineers
MANAGEPrioritize & address AI risksRisk treatment decisions, incident response, continuous monitoring, decommissioningRisk/Operations Teams
ℹ️ While the AI RMF is voluntary, it is referenced by US federal procurement requirements and increasingly by Indian regulators (MeitY, RBI) as a best-practice benchmark for AI governance maturity.
GOVERN — Establishing AI Risk Culture

GOVERN is the foundational function — it creates the conditions under which all other RMF activities operate. Without governance structures, MAP/MEASURE/MANAGE activities lack authority, accountability, and sustainability.

GV-1: AI Risk Management Policy
Documented AI risk policy approved at board/executive level. Defines risk tolerance, accountability, and integration with enterprise risk management. Reviewed annually and after significant AI incidents.
GV-2: Accountability & Roles
Clear roles: AI Risk Owner (business accountability), AI Developer (technical), CISO (security), DPO (privacy), Ethics Lead. Documented RACI. Executive sponsor for AI governance program.
GV-3: Organizational Culture
Workforce training on AI risk. Psychological safety to raise AI concerns. Incentive structures that reward responsible AI behaviour. AI risk integrated into performance management.
GV-4: Organisational Teams
AI governance committee with cross-functional membership (legal, security, product, ethics, compliance). Regular meeting cadence. Documented escalation paths for AI risk decisions.
GV-5: Policies for AI Lifecycle
Policies cover the full AI lifecycle: development, deployment, monitoring, and decommissioning. Include third-party AI procurement, open-source model use, and data governance for AI training.
GV-6: Risk Tolerance
Documented AI risk appetite by use case category. Higher risk tolerance for internal productivity tools; lower for customer-facing decisions, safety systems, or regulated domain applications.
MAP — Categorizing AI Risk Context
MP-1: AI System Categorization
Classify AI system by: domain (healthcare, BFSI, HR), decision autonomy level (advisory vs autonomous), data sensitivity, stakeholder impact scope, and reversibility of decisions. Determines required governance rigor.
MP-2: Scientific Validity
Verify that the AI approach is scientifically valid for the stated purpose. Inappropriate model selection (e.g., LLM for precise numerical prediction) is itself a risk. Consult domain experts.
MP-3: Stakeholder Identification
Map all stakeholders: AI developers, deployers, and affected individuals. For Indian enterprises: include data principals under DPDP Act, regulatory bodies (RBI, SEBI, MeitY), and communities affected by AI outcomes.
MP-4: Risk Identification
Document both beneficial and harmful impacts. Use structured risk identification: data risks, model risks, operational risks, societal risks. Include second-order effects and tail risks.
MP-5: Context of Use
Document intended use, foreseeable misuse, and out-of-scope uses. AI systems used beyond intended context are a primary governance failure mode. Establish use restrictions and communicate to all users.
MEASURE — Analysing & Assessing AI Risks
Measure CategoryWhat to TestMethodsFrequency
Accuracy & ReliabilityPerformance on representative test sets, distribution shift detectionHoldout evaluation, A/B testing, shadow deploymentPre-launch + monthly
Bias & FairnessDisparate impact across protected groups (gender, caste, religion, age)Demographic parity, equalized odds, counterfactual fairnessPre-launch + quarterly
Robustness & SecurityAdversarial inputs, distribution shift, model extraction, prompt injectionRed team, adversarial testing, ATLAS-based attack simulationsPre-launch + after incidents
ExplainabilityCan outcomes be explained to affected individuals?LIME, SHAP, attention visualization, counterfactual explanationsPre-launch + on demand
PrivacyMembership inference risk, PII in training data, model inversionPrivacy audit, differential privacy measurement, red teamPre-launch + annually
TransparencyStakeholders can understand AI system purpose and limitationsModel cards, system cards, documentation reviewPre-launch + on change
MANAGE — Prioritising & Addressing AI Risks
MG-1: Risk Treatment
For each identified risk: Accept (documented, within tolerance), Mitigate (implement controls), Transfer (insurance, contractual), or Avoid (don't deploy). Document decisions and residual risk.
MG-2: Risk Prioritisation
Prioritise risks by: likelihood × impact × stakeholder harm. Use risk register with owner, mitigation actions, target residual risk, and review date. High-impact low-probability risks (tail risks) need explicit treatment plans.
MG-3: Continuous Monitoring
Ongoing measurement of AI system performance, fairness, and security post-deployment. Dashboard with model drift alerts, bias drift, adversarial input detection. Trigger re-evaluation on significant distribution shift.
MG-4: Incident Response
AI-specific incident response plan: what constitutes an AI incident, classification severity, escalation path, rollback procedure, stakeholder notification, and post-incident review. Integrate with enterprise IR processes.
MG-5: Decommissioning
Formal process for retiring AI systems: data retention/deletion, model artifact disposal, documentation archival, stakeholder communication. DPDP Act right to erasure may require model retraining on retirement.
NIST GenAI Profile — LLM-Specific Risks
ℹ️ NIST published the Generative AI Profile (NIST AI 600-1) in 2024 specifically addressing risks unique to LLMs and generative AI systems.
GenAI RiskDescriptionKey Controls
CBRN InformationLLM assists in creating weapons of mass destruction informationTraining data filtering, output content classifiers, prohibited query detection
ConfabulationModel generates plausible but false information (hallucination)Retrieval augmentation, confidence scoring, human review for high-stakes outputs
Data Privacy ViolationsPII or sensitive data included in training or generated in outputsTraining data audit, output filtering, differential privacy, membership inference testing
Harmful Bias & HomogenisationSystematically biased outputs disadvantage protected groupsBias benchmarks (BBQ, WinoBias), red team for demographic harm, diverse evaluation sets
Human-AI ConfigurationMisalignment between intended and actual human oversight levelDocument intended automation level, test for automation bias in users, HITL procedures
Information IntegritySynthetic media or generated text used for disinformationContent provenance (C2PA), watermarking, detection model deployment
Intellectual PropertyModel memorises and reproduces copyrighted training dataTraining data licensing, memorisation testing, output filtering
NIST AI RMF Maturity Scorer

Rate your organisation's implementation of each RMF function (0=None, 1=Partial, 2=Implemented, 3=Optimised).

📋

ISO/IEC 42001:2023 — AI Management System

The first international standard for AI management systems — certifiable like ISO 27001. Published December 2023, it provides requirements for establishing, implementing, maintaining, and continually improving an AI management system within organisations.

ISO Official Certifiable Dec 2023
ISO 42001 Clause Structure
ClauseTitleKey RequirementsISO 27001 Parallel
4Context of the OrganisationInternal/external issues, interested parties, AIMS scope, AI policy contextClause 4
5LeadershipTop management commitment, AI policy, organisational roles for AIClause 5
6PlanningAI risk & opportunity assessment, AI objectives, planning for changesClause 6
7SupportResources, competence, awareness, communication, documented informationClause 7
8OperationAI system impact assessment, AI system lifecycle, data for AI, third-party AIClause 8 (A.8)
9Performance EvaluationMonitoring, measurement, internal audit, management reviewClause 9
10ImprovementNonconformity, corrective action, continual improvementClause 10
Annex AAI Controls ReferenceControls for objectives, risk, impact assessment, data, system lifecycle, transparencyAnnex A
ℹ️ ISO 42001 is built on the Annex SL High Level Structure — it integrates directly with ISO 27001 (information security) and ISO 9001 (quality). Organisations certified for ISO 27001 can implement ISO 42001 as an extension with significant clause overlap.
Clause 4 — Context & Clause 5 — Leadership
4.1: Understanding the Organisation
Document internal factors (AI strategy, culture, capabilities) and external factors (regulatory environment — DPDP Act, RBI, EU AI Act if applicable — competitive landscape, societal expectations). Reviewed annually.
4.2: Interested Parties
Identify all parties with AI interests: employees, customers (data principals), regulators (MeitY, RBI, SEBI), partners, affected communities. Document their requirements that must be addressed by the AIMS.
4.3: AIMS Scope
Define which AI systems, processes, and organisational units are within scope. The scope statement must be documented. If excluding systems, provide justification. Scope can be expanded as maturity increases.
5.1: Top Management Commitment
Board/C-suite must demonstrate commitment through: approving AI policy, allocating resources, integrating AI risk into enterprise risk, and participating in AIMS management review.
5.2: AI Policy
Documented, board-approved AI policy covering: purpose of AI use, commitment to responsible AI, compliance obligations (DPDP, sector regulators), human oversight commitments, and continual improvement pledge.
5.3: Roles & Responsibilities
Assign and communicate AIMS roles: AIMS Owner (overall accountability), AI Risk Manager, Data Governance Lead, DPO (data protection overlap), and AI system owners for each deployed AI system.
Clause 6 — Planning & Clause 7 — Support
6.1: AI Risk Assessment
Process for identifying, analysing, and evaluating AI-specific risks. Includes risk to individuals (bias, privacy, safety), risk to organisation (legal, reputational), and risk to society. Must consider both beneficial and harmful impacts.
6.1.4: AI System Impact Assessment
Key ISO 42001 requirement: formal impact assessment for each AI system. Assesses potential impacts on individuals, groups, and society. Documented and reviewed on significant changes. Similar to DPIA under DPDP Act but broader scope.
6.2: AI Objectives
Measurable AI objectives aligned to the AI policy. Example: "Reduce false positive rate in fraud detection to <5% while maintaining <0.1% bias differential across demographic groups by Q4 2026."
7.2: Competence
Identify required competencies for AI roles. Provide training. Retain evidence of competence (training records, certifications). AI safety/ethics training for all staff who interact with AI systems.
7.5: Documented Information
Maintain required documents: AIMS scope, AI policy, risk assessment results, AI system impact assessments, AI objectives, training records, audit results. ISO 42001 specifies minimum documentation requirements.
Clause 8 — Operations (Core AI Requirements)
Control AreaRequirementEvidence Required
8.3 AI System LifecycleDocumented process covering design, development, testing, deployment, monitoring, and decommissioningLifecycle process documentation, stage-gate checklists
8.4 Data for AIData governance for AI: data quality, provenance, consent, bias assessment of training dataData governance policy, training data inventory, bias testing results
8.5 AI System TestingTesting against intended performance, safety, security, and bias criteria before deploymentTest plans, test results, sign-off records
8.6 Third-Party AIGovernance of procured AI models, datasets, and services — including open-sourceVendor assessment records, procurement security checklist
Annex A.6: TransparencyDisclose AI use to affected individuals; provide explanations for AI-based decisionsTransparency disclosures, explanation capability demonstration
Annex A.8: Human OversightDefine and implement appropriate human oversight for each AI system use caseOversight procedures, HITL logs, escalation records
Clause 9 — Performance Evaluation & Clause 10 — Improvement
9.1: Monitoring & Measurement
Ongoing monitoring of AI system performance, safety, fairness, and security post-deployment. KPIs against AI objectives. Drift detection triggers re-evaluation. Document monitoring procedures and results.
9.2: Internal Audit
Planned AIMS internal audits at least annually. Audit scope covers all AIMS clauses. Auditors must be independent of the audited function. Results reported to top management. For ISO 42001+27001 integrated AIMS, audits can be combined.
9.3: Management Review
Annual management review of AIMS performance. Agenda: audit results, AI incidents, regulatory changes, AI objective achievement, resource adequacy. Output: decisions and actions with owners and dates.
10.1: Nonconformity & Corrective Action
Documented process for identifying AIMS nonconformities, conducting root cause analysis, implementing corrective actions, and verifying effectiveness. AI incidents and near-misses are prime sources of nonconformity.
ISO 42001 Gap Analysis Tool

Rate your current implementation for each key ISO 42001 requirement.

🇪🇺

EU AI Act 2024 — Risk-Based AI Regulation

The EU AI Act (entered into force August 2024) is the world's first comprehensive AI law. Risk-based approach: prohibited AI practices, high-risk obligations, limited-risk transparency requirements, and systemic risk rules for GPAI models. Indian companies exporting to EU must comply.

EU Official Force: Aug 2024 India Exposure
EU AI Act — Four Risk Tiers
Risk TierExamplesObligationsPenalty
Unacceptable
PROHIBITED
Social scoring by governments, real-time remote biometric ID in public, subliminal manipulation, emotion recognition in workplaces/educationComplete ban — cannot deploy in EUUp to €35M or 7% global turnover
High RiskAI in critical infrastructure, education (exam scoring), employment (CV screening), credit scoring, biometric identification, law enforcement, judicial decisionsConformity assessment, CE marking, registration in EU database, human oversight, transparency, data governance, technical documentation, loggingUp to €15M or 3% global turnover
Limited RiskChatbots, AI-generated content, deepfakes (non-prohibited), emotion recognition in limited contextsTransparency disclosure: "You are interacting with an AI." Deepfake labelling. GPAI content labelling.Up to €7.5M or 1.5% global turnover
Minimal RiskSpam filters, AI in video games, AI-assisted manufacturing (non-safety-critical)No mandatory requirements — voluntary codes of practice encouragedN/A
Prohibited AI Practices (Article 5)
🔴 Prohibited AI practices cannot be deployed in the EU from February 2025 onwards. Violations carry the highest penalties.
Social Scoring by Public Authorities
AI systems that evaluate or classify individuals based on social behaviour leading to detrimental treatment in unrelated social contexts. Prohibits government social credit systems. Applies to public authorities — private sector similar systems may fall under high-risk.
Real-Time Remote Biometric ID in Public
Mass real-time facial recognition in publicly accessible spaces. Limited exceptions: targeted search for specific suspects, prevention of terrorist attacks, finding missing children — require prior judicial authorisation.
Subliminal Manipulation
AI using techniques beyond conscious perception (subliminal advertising, neurotechnological manipulation) to influence behaviour causing harm. Also covers exploitation of vulnerabilities of specific groups (age, disability).
Emotion Recognition at Work/Education
AI systems inferring emotions in workplace or educational settings. Exception: AI for medical or safety purposes (e.g., drowsiness detection in drivers). Privacy-invasive emotion surveillance is prohibited.
Predictive Policing of Individuals
AI making individual-level risk assessments for criminal behaviour based solely on profiling, not on objective, verifiable facts. General threat assessments (non-individual) are permissible.
Scraping Biometric Data
Untargeted scraping of facial images from internet or CCTV to create facial recognition databases. Applies to mass data collection — not to specific targeted investigations with legal basis.
High-Risk AI — Annex III Use Cases & Obligations
Annex III: High-Risk Use Cases
Biometric ID/categorisation, critical infrastructure, education (admissions, scoring), employment (CV screening, promotion, termination, task allocation), essential services (credit, benefits), law enforcement, migration, justice & democratic processes.
Risk Management System
Continuous risk management throughout lifecycle. Identify and analyse known/foreseeable risks. Estimate and evaluate risks. Adopt risk mitigation measures. Residual risk must be within acceptable levels. Document entire process.
Data & Data Governance
Training, validation, and testing data must be: relevant, sufficiently representative, free of errors and complete as far as possible, have appropriate statistical properties considering intended purpose. Examine for biases. Document data governance practices.
Technical Documentation
Before market placement: detailed technical documentation showing compliance. Must be kept updated. Includes: system description, development process, validation results, monitoring plan, post-market monitoring procedures.
Human Oversight
Human oversight measures enabling humans to: understand system capabilities/limitations, monitor operation, intervene and stop the system, and not solely rely on AI outputs. Must be built into the system by design, not just policy.
Conformity Assessment
Before EU market: self-assessment (most high-risk) or third-party assessment (biometric, critical infrastructure, law enforcement, justice). CE marking + EU AI Act Declaration of Conformity + registration in EU database.
General Purpose AI (GPAI) Model Obligations
ℹ️ GPAI rules apply to foundation model providers (GPT-4, Claude, Gemini, open-source equivalents). Deployers building on GPAI models have separate obligations.
ObligationAll GPAI ProvidersSystemic Risk Models (>10²⁵ FLOPs)
Technical documentation✅ Required✅ Enhanced documentation
Training data summary✅ Required✅ Required
Copyright compliance✅ EU copyright law compliance✅ Enhanced
AI content labelling✅ Machine-readable AI content marking✅ Required
Adversarial testing❌ Not required✅ Red teaming before deployment
Cybersecurity measures❌ Not required✅ Required
Incident reporting❌ Not required✅ Serious incidents to AI Office
Energy efficiency❌ Not required✅ Compute/energy disclosure
EU AI Act Enforcement Timeline
DateMilestoneWho Is Affected
Aug 2024Act enters into forceAll — starting point for compliance timeline
Feb 2025Prohibited AI practices ban takes effectAnyone deploying AI in EU — zero tolerance
Aug 2025GPAI model obligations applyFoundation model providers (Anthropic, OpenAI, Google, open-source)
Aug 2025Governance provisions + AI Office establishedLarge organisations — designate AI compliance officers
Aug 2026High-risk AI obligations fully applicableHigh-risk AI system providers and deployers — conformity assessments required
Aug 2027High-risk AI in Annex I sectorsAI in existing regulated sectors (medical devices, machinery, cars)
⚠️ Indian IT companies exporting AI services to EU customers are subject to the EU AI Act if the AI system output is used in the EU. NASSCOM has flagged this as a compliance priority for Indian IT exporters.
EU AI Act India Exposure Assessment

Assess your EU AI Act exposure as an Indian organisation.

🇮🇳

DPDP Act 2023 — Complete AI Compliance Guide

The Digital Personal Data Protection Act 2023 is India's primary data protection law — directly applicable to all AI systems processing personal data of Indian citizens. Interactive compliance mapper, obligation reference, and penalty calculator.

DPDP Act 2023 Up to Rs.250Cr India Only
DPDP Act 2023 — Key Definitions for AI
Personal Data
Any data about an identifiable individual. In AI context: names, Aadhaar numbers, biometrics, location data, financial records, health data, behavioural inferences. Pseudonymised data remains personal data if re-identification is possible.
Data Fiduciary
Entity that determines purpose and means of processing personal data. AI system operator = Data Fiduciary. Bears primary obligations: lawful basis, consent management, data principal rights, security, breach notification.
Data Principal
The individual whose personal data is processed. Has rights under DPDP Act: access, correction, erasure, nomination. AI systems must provide mechanisms for data principals to exercise these rights.
Consent Manager
Registered entity enabling data principals to give, manage, review, and withdraw consent. AI systems relying on consent must integrate with a DPBI-registered Consent Manager or have equivalent internal mechanisms.
Significant Data Fiduciary (SDF)
Data fiduciaries notified by the Central Government based on volume/sensitivity of data processed or risk to national security. SDFs face additional obligations: DPO appointment, DPIA, data audit, compliance with additional directives.
Sensitive Personal Data
Health/medical data, official identifiers, biometrics, financial data, sexual orientation, religious/caste/tribal identity. AI processing sensitive data requires additional safeguards and faces higher penalty exposure.
Key Obligations for AI Operators
SectionObligationAI ApplicationPenalty
S.4Lawful basis for processingConsent or "legitimate use" before training or inference on personal dataRs.50Cr
S.6Notice & ConsentClear notice of AI processing purpose; specific, informed, revocable consent; bundled consent insufficientRs.250Cr
S.7Sensitive data protectionEnhanced security for biometrics, health data, financial data in AI systemsRs.200Cr
S.8General obligations of Data FiduciaryData minimisation (don't collect more than needed), accuracy, security safeguards, DPDP-compliant processingRs.250Cr
S.9Children's dataParental/guardian consent; NO profiling, behavioural monitoring, or targeted advertising to childrenRs.200Cr
S.11–12Data principal rightsRight to info (what AI processed), right to correction (fix inaccurate data), right to erasure (delete including training retraining)Rs.50–250Cr
S.16Cross-border data transferAI cloud processing of Indian data: only to countries notified by Central Government (list pending)Rs.200Cr
S.8(7)Breach notificationReport AI-related data breaches to DPBI and affected data principals; specific format and timeline per DPDP RulesRs.250Cr
DPDP AI Compliance Mapper
DPDP Penalty Calculator
Significant Data Fiduciary — Additional Obligations
🇮🇳 Significant Data Fiduciaries (SDFs) are notified by the Central Government. Expected criteria: large-scale processing of sensitive data, national security implications, or high risk to rights of data principals.
Data Protection Officer (DPO)
SDFs must appoint a DPO based in India. DPO represents the SDF before the DPBI, is the point of contact for data principals, and oversees compliance. Must be a senior employee with adequate authority and resources.
Data Protection Impact Assessment (DPIA)
Mandatory periodic DPIA for each AI system processing personal data at scale. Assesses necessity and proportionality, risks to data principals, and safeguards. Must be submitted to DPBI on request. Triggers mandatory if processing sensitive data.
Annual Data Audit
Periodic audit by independent auditor of all data processing activities including AI. Audit covers consent mechanisms, security controls, data minimisation, breach response. Results submitted to DPBI.
Algorithmic Accountability
SDFs must maintain documentation of AI algorithms used for significant decisions affecting data principals. Must be able to explain decisions on request. Audit trail of AI decision-making must be maintained for a defined period.
🏦

RBI AI Guidelines — BFSI Compliance

RBI, SEBI, and IRDAI have issued guidance on AI/ML use in financial services. Model risk management, explainability, bias testing, human oversight, and data localisation requirements for banks, NBFCs, insurers, and capital market intermediaries.

RBI Regulated SEBI IRDAI
RBI Model Risk Management (MRM) for AI/ML

RBI's Master Circular on Risk Management and the IT Framework for banks (2023 update) explicitly address AI/ML model risk. Key principles:

Model Validation
All AI/ML models used in credit, risk, or compliance must undergo independent validation before deployment and annually thereafter. Validation must include: conceptual soundness review, data quality assessment, performance testing, and stress testing.
Explainability
AI-based credit decisions must be explainable to both regulators (on examination) and affected customers (on request). "Black box" AI for credit decisions is not acceptable. Minimum: feature importance explanation or equivalent SHAP analysis.
Human Oversight
AI recommendations in credit, risk, and compliance must have human review at defined thresholds. Fully automated AI decisions are permissible only within pre-approved parameters. Edge cases must escalate to human review.
Model Governance Committee
Banks and NBFCs must have a Model Risk Management (MRM) framework with a Model Governance Committee. Includes: model inventory, model tiering (by risk), validation standards, approval workflow, and model performance monitoring.
Data Localisation
All financial data of Indian customers, including data used to train AI models, must be stored in India. Cross-border processing for AI inference (using cloud AI APIs) requires mirroring in India and RBI approval for exceptions.
Bias & Fairness Testing
AI models in credit and insurance must demonstrate they do not discriminate based on protected characteristics (religion, caste, gender, age). Bias testing results must be documented and available to auditors. Fair lending obligation under RBI.
BFSI AI Use Case Requirements
Use CaseRegulatorKey RequirementsExplainability
Credit Scoring / LoanRBIIndependent model validation, bias testing, explainable rejection reasons, human review for borderline casesMandatory
Fraud Detection (UPI/Cards)RBI / NPCIReal-time monitoring, false positive rate tracking, customer dispute mechanism, audit trailRecommended
KYC / AMLRBI / FIU-INDVideo KYC guidelines, liveness detection standards, AML model validation, STR threshold documentationMandatory
Algorithmic TradingSEBIPre-trade risk controls, circuit breakers, audit trail, co-location rules, algorithmic strategy registrationMandatory
Insurance UnderwritingIRDAIProduct filing for AI-based pricing, non-discriminatory underwriting, actuary sign-off, customer disclosureRecommended
Customer Service (Chatbot)RBI / SEBIEscalation to human for complaints, clear AI disclosure, not for regulated advice, data localisationNot Required
Robo-AdvisorySEBIIA/RA registration, investment advice suitability, human oversight for portfolio rebalancing, conflict disclosureMandatory
SEBI AI/ML Framework for Capital Markets
Algo Trading Regulations
All algorithmic trading strategies must be registered with SEBI. Brokers using AI for order generation must have: pre-trade risk controls, audit trails, kill switches, and co-location approvals. AI trading on behalf of clients requires Registered Investment Adviser compliance.
Surveillance AI
SEBI uses AI for market surveillance (detecting manipulation, insider trading patterns). Market participants' AI systems that interface with exchange data feeds must comply with data usage restrictions and not reverse-engineer surveillance patterns.
Mutual Fund AI
AI-driven fund management requires disclosure in offer documents. Quant funds using AI strategies must disclose the nature of quantitative strategies. Backtesting results cannot be presented as performance projections.
Research Reports & AI
AI-generated research reports are subject to SEBI Research Analyst regulations. Must be: clearly labelled as AI-assisted, reviewed by registered analyst, comply with conflicts of interest disclosures, and meet SEBI research report content standards.
BFSI AI Compliance Checker
⚖️

AI Ethics, Responsible AI & Red Team

Responsible AI goes beyond regulatory compliance — it requires proactive assessment of fairness, transparency, accountability, and harm prevention. Interactive ethics assessment tool, red team exercise builder, and model card generator.

Responsible AI Principles (India Context)
Fairness & Non-Discrimination
AI must not discriminate based on religion, caste, gender, age, disability, or sexual orientation. In India: caste-based discrimination is a specific risk in credit, employment, and education AI. Test for disparate impact across all relevant groups including SC/ST communities.
Transparency & Explainability
Stakeholders must understand that AI is being used and how decisions are made. Tiered transparency: operational transparency (AI was used), decision transparency (why this decision), and algorithmic transparency (how the model works). DPDP Act S.11 creates a legal right to information.
Accountability
Clear accountability for AI system outcomes — human decisions, not "the AI." When AI causes harm, there must be an accountable person. Document accountability chains for each AI system. Consider AI liability framework as India's AI regulation evolves.
Privacy by Design
Data minimisation from the start. Don't collect personal data "just in case" it might be useful for AI. Privacy-enhancing technologies: federated learning, differential privacy, synthetic data. DPDP Act reinforces privacy as a fundamental right.
Safety & Security
AI must not cause harm. For safety-critical AI (healthcare, autonomous vehicles, infrastructure): formal safety analysis, fail-safe defaults, human override capability. Security from adversarial attack is a safety requirement.
Human Agency & Oversight
Humans retain meaningful control over significant AI-assisted decisions. AI augments human judgment — not replaces it in high-stakes contexts. Particularly important for India given scale of AI deployment in government services affecting millions.
AI Ethics Impact Assessment

Rate each dimension of your AI system (1=Very Poor to 5=Excellent). This assessment maps to NIST AI RMF trustworthiness characteristics.

AI Red Team Exercise Builder
Model Card Generator

Model cards document AI system purpose, limitations, and biases. Required by ISO 42001 and good practice for DPDP Act transparency obligations.