Fristine Infotech
Book a session

What your compliance team will ask us, answered

This page is written for the person who has to sign off on us. It sets out, regulator by regulator, what the obligation is, what we do about it, and where the evidence lives. Forward it to your compliance, risk or information security team.

DPDPRBISEBI CSCRFIRDAICERT In

For our general security and certification posture across all industries, see Trust & Compliance. This page covers financial sector specifics.

BFSI compliance and regulatory framework

Regulator to obligation map

DPDP Act 2023 + Rules 2025

The obligation

You are the Data Fiduciary; processors must be bound by contract to reasonable security safeguards.

What we do

DPDP aligned data processing agreement; encryption in transit and at rest; role based access; logging; backups; retention and deletion support; consent artefact and Consent Manager integration readiness.

Evidence

Signed DPA, access control matrix, encryption standards document, deletion runbook.

RBI Master Direction on Outsourcing of IT Services (2023)

The obligation

REs must retain right to audit, control subcontracting, plan exit, disclose locations, report incidents.

What we do

Right to audit clauses for you and RBI; named subcontractors with prior consent; documented exit and data portability plan; BCP DR with tested RTO/RPO; incident notification without undue delay; disclosed processing locations.

Evidence

Contract annexure, subcontractor register, exit plan, DR test reports, incident response SLA.

RBI FREE AI (August 2025)

The obligation

Seven sutras, twenty six recommendations: board approved AI policy, AI audit capability, AI incident reporting, explainability.

What we do

Agent governance aligned to the sutras; model inventory per client; decision logs supporting explainability; AI incident classification and reporting into your framework.

Evidence

Model inventory, AI governance note, decision log exports.

SEBI CSCRF

The obligation

Applies to brokers, DPs, AMCs, RTAs, PMs, IAs. VAPT by CERT In empanelled auditors, SOC coverage, regulatory data in India, graded obligations by RE category.

What we do

Development and deployment practices that support your CSCRF posture; India region data residency; VAPT participation; log retention aligned to your category; support for your Cyber Capability Index evidence where applicable.

Evidence

VAPT reports, residency attestation, log retention configuration.

SEBI on AI/ML tools

The obligation

The RE is responsible for outcomes of AI tools it deploys, including third party tools.

What we do

Human in the loop by default; confidence thresholds set by you; immutable decision logs; evaluation suites retained as evidence; documented accountability split before go live.

Evidence

Control design document, evaluation results, accountability matrix.

IRDAI Information & Cyber Security Guidelines 2023

The obligation

Applies to brokers and intermediaries; ISMS, CISO, annual audit by CERT In empanelled auditor, VAPT, incident reporting.

What we do

Flow down controls in our delivery and support processes; audit cooperation; incident reporting into your process.

Evidence

Control mapping, audit cooperation clause.

CERT In Directions 2022

The obligation

Cyber incidents reported within six hours; logs retained 180 days within India.

What we do

Incident detection and notification process meeting your six hour obligation; log retention configured in Indian regions.

Evidence

Incident response runbook, log configuration evidence.

AI specific governance

The frameworks above were mostly written for systems that do not make judgements. Agents do, so we add controls that regulators are increasingly asking about explicitly.

Immutable decision logs

Every agent decision writes a timestamped, append only entry recording: the input records used, the source document and page where relevant, the extracted or inferred values, the confidence score, the model and version, the prompt version, and the human who approved or overrode it. Exportable in a format your auditors can read.

Confidence thresholds you own

You set the level below which a case must go to a human. We recommend a starting point from experience in your sub vertical and then tune it against real volume. The number is your risk decision, documented and version controlled.

Permission inheritance

An agent operates with the entitlements of the user who invoked it. It cannot retrieve a record that person could not open. This is the control that prevents an AI assistant becoming a data leakage path.

Model change control

Model upgrades and prompt changes go through the evaluation suite before production, with a diff and a test result. Providers deprecate and update models on their own schedule; without change control your behaviour changes silently.

Evaluation as evidence

A labelled set of your real cases, re run on a schedule and on every change, retained. This is both how we know accuracy has not drifted and what we hand your auditor when they ask how you assured yourself the tool works.

Accountability, in writing

Before go live we document who owns the agent’s output, who reviews exceptions, who authorises threshold changes, and who is notified on an AI incident. Regulators hold you responsible; that only works if the split is explicit.

Data residency and deployment

Data stays in India

AWS Mumbai (ap south 1) / Hyderabad (ap south 2); Azure Central, South and West India; GCP Mumbai (asia south1) / Delhi NCR (asia south2); Zoho India data centres (Mumbai, Chennai).

Payment system data in India only

Deployment restricted to Indian regions; foreign leg copies only where RBI permits for cross border transactions.

Processing inside your own environment

Agents and applications deployed into your cloud tenant or VPC, behind your controls, where that is your requirement.

Model inference location

Configurable: regional endpoints where the provider offers them; documented per deployment before build.

What we do not claim

We would rather be trusted than impressive, so three plain statements:

We are not a substitute for your compliance function. We build to your interpretation of your obligations. Where interpretation is genuinely unsettled, and parts of the AI guidance are, we will say so rather than assert certainty.

We do not claim certifications we do not hold. Our current certifications are listed on Trust & Compliance. Anything we are pursuing is described as pursued, not held.

No vendor can promise a fixed accuracy number for a language model on your data before seeing your cases. We commit to measuring it honestly, reporting it, and telling you when it moves.

Sub vertical compliance notes

Stock broking and DPs

SEBI CSCRF category determines your obligations; regulatory data residency and log retention are the clauses that matter most in our contract.

View sub vertical

AMCs and mutual fund distribution

CSCRF applies, plus distributor data handling under DPDP where you process investor information through partners.

View sub vertical

NBFCs and gold loan

RBI IT Outsourcing MD and IT Governance MD are the governing frameworks; branch level document handling is usually the biggest DPDP exposure.

View sub vertical

Insurance broking

IRDAI ICS Guidelines 2023 with vendor flow down; claims and health data raise the sensitivity classification.

View sub vertical

Wealth management

SEBI IA/PM obligations plus the highest client confidentiality expectations in the sector; permission inheritance matters most here.

View sub vertical

Questions your compliance team usually asks

Will you sign our outsourcing agreement and RBI annexure without amendment?

We work with standard RBI outsourcing annexures routinely. We review rather than sign blind, and we will tell you which clauses we are negotiating and why.

Can we audit you? Can our regulator?

Yes, both. Right to audit for you and your regulator is in our contract, including on site where required.

Who are your subcontractors?

Disclosed in a register, with prior consent required for changes affecting your data. Cloud and model providers are named explicitly.

Where are the agent’s decision logs stored, and for how long?

In your environment or an Indian region you nominate, retained for the period your framework requires. 180 days minimum under CERT In, longer where SEBI or RBI retention applies. Configured to your policy, not ours.

What happens on a data breach?

We notify you without undue delay under the DPA, support your investigation with logs and forensics, and support your reporting into the DPBI, CERT In and your regulator. You report; we equip you to report.

How do you handle personal data in test environments?

Masked or synthetic data by default. Production data in non production environments only with your written approval and equivalent controls.

Ready to talk compliance?

Bring your vendor questionnaire. We will walk through it with you.

Book a working session