Skip to content
72 Networks

Assure

Deploy AI you can defend

Under SEBI Regulation 16C, a regulated entity is solely responsible for the outputs of its AI systems, whoever built them. RBI's FREE-AI framework shapes financial-sector deployment. DPDP obligations land in stages through May 2027. The IT Amendment Rules 2026 have governed synthetically generated content since February.

None of it is optional, and all of it requires the same starting point: knowing what you actually have.

  • Six to ten weeks
  • Board-ready assurance report
  • Surveillance retainer, monthly

The first finding is usually the inventory

Organisations typically declare three or four AI systems. We usually find between twenty and forty: departmental SaaS with embedded AI, browser extensions, personal LLM accounts being used on company data, and vendor systems with model components nobody disclosed.

Scope

Discovery

  • AI system inventory, including shadow AI
  • Data-flow mapping per system
  • Contract review of every AI-touching vendor agreement

Assessment

  • DPDP gap assessment and DPIA framework
  • Model risk register
  • Bias and robustness testing on decision-affecting systems
  • Adversarial evaluation, including prompt injection and data exfiltration
  • Multi-regulator control matrix in a single view

Remediation

  • Prioritised plan with owners and dates
  • Control implementation
  • Policy set
  • Board-ready assurance report

Six weeks of evidence beats six months of opinion.