Assure
Deploy AI you can defend
Under SEBI Regulation 16C, a regulated entity is solely responsible for the outputs of its AI systems, whoever built them. RBI's FREE-AI framework shapes financial-sector deployment. DPDP obligations land in stages through May 2027. The IT Amendment Rules 2026 have governed synthetically generated content since February.
None of it is optional, and all of it requires the same starting point: knowing what you actually have.
- Six to ten weeks
- Board-ready assurance report
- Surveillance retainer, monthly
The first finding is usually the inventory
Organisations typically declare three or four AI systems. We usually find between twenty and forty: departmental SaaS with embedded AI, browser extensions, personal LLM accounts being used on company data, and vendor systems with model components nobody disclosed.
Scope
Discovery
- AI system inventory, including shadow AI
- Data-flow mapping per system
- Contract review of every AI-touching vendor agreement
Assessment
- DPDP gap assessment and DPIA framework
- Model risk register
- Bias and robustness testing on decision-affecting systems
- Adversarial evaluation, including prompt injection and data exfiltration
- Multi-regulator control matrix in a single view
Remediation
- Prioritised plan with owners and dates
- Control implementation
- Policy set
- Board-ready assurance report