For our general security and certification posture across all industries, see Trust & Compliance. This page covers financial sector specifics.
Regulator to obligation map
DPDP Act 2023 + Rules 2025
You are the Data Fiduciary; processors must be bound by contract to reasonable security safeguards.
DPDP aligned data processing agreement; encryption in transit and at rest; role based access; logging; backups; retention and deletion support; consent artefact and Consent Manager integration readiness.
Signed DPA, access control matrix, encryption standards document, deletion runbook.
RBI Master Direction on Outsourcing of IT Services (2023)
REs must retain right to audit, control subcontracting, plan exit, disclose locations, report incidents.
Right to audit clauses for you and RBI; named subcontractors with prior consent; documented exit and data portability plan; BCP DR with tested RTO/RPO; incident notification without undue delay; disclosed processing locations.
Contract annexure, subcontractor register, exit plan, DR test reports, incident response SLA.
RBI FREE AI (August 2025)
Seven sutras, twenty six recommendations: board approved AI policy, AI audit capability, AI incident reporting, explainability.
Agent governance aligned to the sutras; model inventory per client; decision logs supporting explainability; AI incident classification and reporting into your framework.
Model inventory, AI governance note, decision log exports.
SEBI CSCRF
Applies to brokers, DPs, AMCs, RTAs, PMs, IAs. VAPT by CERT In empanelled auditors, SOC coverage, regulatory data in India, graded obligations by RE category.
Development and deployment practices that support your CSCRF posture; India region data residency; VAPT participation; log retention aligned to your category; support for your Cyber Capability Index evidence where applicable.
VAPT reports, residency attestation, log retention configuration.
SEBI on AI/ML tools
The RE is responsible for outcomes of AI tools it deploys, including third party tools.
Human in the loop by default; confidence thresholds set by you; immutable decision logs; evaluation suites retained as evidence; documented accountability split before go live.
Control design document, evaluation results, accountability matrix.
IRDAI Information & Cyber Security Guidelines 2023
Applies to brokers and intermediaries; ISMS, CISO, annual audit by CERT In empanelled auditor, VAPT, incident reporting.
Flow down controls in our delivery and support processes; audit cooperation; incident reporting into your process.
Control mapping, audit cooperation clause.
CERT In Directions 2022
Cyber incidents reported within six hours; logs retained 180 days within India.
Incident detection and notification process meeting your six hour obligation; log retention configured in Indian regions.
Incident response runbook, log configuration evidence.
AI specific governance
The frameworks above were mostly written for systems that do not make judgements. Agents do, so we add controls that regulators are increasingly asking about explicitly.
Immutable decision logs
Every agent decision writes a timestamped, append only entry recording: the input records used, the source document and page where relevant, the extracted or inferred values, the confidence score, the model and version, the prompt version, and the human who approved or overrode it. Exportable in a format your auditors can read.
Confidence thresholds you own
You set the level below which a case must go to a human. We recommend a starting point from experience in your sub vertical and then tune it against real volume. The number is your risk decision, documented and version controlled.
Permission inheritance
An agent operates with the entitlements of the user who invoked it. It cannot retrieve a record that person could not open. This is the control that prevents an AI assistant becoming a data leakage path.
Model change control
Model upgrades and prompt changes go through the evaluation suite before production, with a diff and a test result. Providers deprecate and update models on their own schedule; without change control your behaviour changes silently.
Evaluation as evidence
A labelled set of your real cases, re run on a schedule and on every change, retained. This is both how we know accuracy has not drifted and what we hand your auditor when they ask how you assured yourself the tool works.
Accountability, in writing
Before go live we document who owns the agent’s output, who reviews exceptions, who authorises threshold changes, and who is notified on an AI incident. Regulators hold you responsible; that only works if the split is explicit.
Data residency and deployment
AWS Mumbai (ap south 1) / Hyderabad (ap south 2); Azure Central, South and West India; GCP Mumbai (asia south1) / Delhi NCR (asia south2); Zoho India data centres (Mumbai, Chennai).
Deployment restricted to Indian regions; foreign leg copies only where RBI permits for cross border transactions.
Agents and applications deployed into your cloud tenant or VPC, behind your controls, where that is your requirement.
Configurable: regional endpoints where the provider offers them; documented per deployment before build.
What we do not claim
We would rather be trusted than impressive, so three plain statements:
We are not a substitute for your compliance function. We build to your interpretation of your obligations. Where interpretation is genuinely unsettled, and parts of the AI guidance are, we will say so rather than assert certainty.
We do not claim certifications we do not hold. Our current certifications are listed on Trust & Compliance. Anything we are pursuing is described as pursued, not held.
No vendor can promise a fixed accuracy number for a language model on your data before seeing your cases. We commit to measuring it honestly, reporting it, and telling you when it moves.
Sub vertical compliance notes
Stock broking and DPs
SEBI CSCRF category determines your obligations; regulatory data residency and log retention are the clauses that matter most in our contract.
View sub verticalAMCs and mutual fund distribution
CSCRF applies, plus distributor data handling under DPDP where you process investor information through partners.
View sub verticalNBFCs and gold loan
RBI IT Outsourcing MD and IT Governance MD are the governing frameworks; branch level document handling is usually the biggest DPDP exposure.
View sub verticalInsurance broking
IRDAI ICS Guidelines 2023 with vendor flow down; claims and health data raise the sensitivity classification.
View sub verticalWealth management
SEBI IA/PM obligations plus the highest client confidentiality expectations in the sector; permission inheritance matters most here.
View sub verticalQuestions your compliance team usually asks
Will you sign our outsourcing agreement and RBI annexure without amendment?
We work with standard RBI outsourcing annexures routinely. We review rather than sign blind, and we will tell you which clauses we are negotiating and why.
Can we audit you? Can our regulator?
Yes, both. Right to audit for you and your regulator is in our contract, including on site where required.
Who are your subcontractors?
Disclosed in a register, with prior consent required for changes affecting your data. Cloud and model providers are named explicitly.
Where are the agent’s decision logs stored, and for how long?
In your environment or an Indian region you nominate, retained for the period your framework requires. 180 days minimum under CERT In, longer where SEBI or RBI retention applies. Configured to your policy, not ours.
What happens on a data breach?
We notify you without undue delay under the DPA, support your investigation with logs and forensics, and support your reporting into the DPBI, CERT In and your regulator. You report; we equip you to report.
How do you handle personal data in test environments?
Masked or synthetic data by default. Production data in non production environments only with your written approval and equivalent controls.
Ready to talk compliance?
Bring your vendor questionnaire. We will walk through it with you.
Book a working session