AI Governance Officer India Practitioner
The India-regulator operational layer for AI. MeitY, DPDP, SEBI, RBI, IRDAI, IT Rules 2026 and the international reference frame, taught end to end in Indian English.
The hands-on practitioner course for the AI Governance Officer role every Indian deployer and developer of AI now needs. Built on the MeitY India AI Governance Guidelines of 5 November 2025 (the 7 Sutras and 6 Pillars), the RBI FREE-AI Committee Report of 13 August 2025 that birthed the Sutras, the SEBI AI Vulnerability Advisory of 5 May 2026 (HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026), the DPDP Act 2023 Section 10(2)(c) proviso on algorithmic due diligence, the DPDP Rules 2025 Rule 13 SDF obligations, the IRDAI Information and Cyber Security Guidelines of 6 April 2026, the Telecommunications (Telecom Cyber Security) Rules 2024, the IT Rules 2026 amendment of 10 February 2026 introducing the Synthetically Generated Information category, the IndiaAI Mission launched 7 March 2024, and the international reference layer of EU AI Act, NIST AI RMF, OECD AI Principles update of 3 May 2024 and ISO/IEC 42001:2023. The capstone walks you through a complete ten-week AI governance programme on Aarti Capital Markets, a fictional Mumbai SEBI-registered mid-size broker and AMC with Rs 8,400 crore AUM deploying AI across onboarding, trade surveillance and portfolio recommendations. Updated through 9 October 2026.
What you will learn
- Serve as the named AI Governance Officer for an Indian deployer or developer of AI
- Apply the MeitY 7 Sutras and 6 Pillars to a working AI governance programme
- Operate the RBI FREE-AI 26 Recommendations in a bank or NBFC
- Comply with the SEBI AI Vulnerability Advisory of 5 May 2026 including SBOM and M-SOC obligations
- Build an AI DPIA aligned to DPDP Act Section 10(2)(c) proviso and DPDP Rules 2025 Rule 13
- Operate under the IT Rules 2026 synthetic-media regime (labelling, provenance, 3-hour takedown)
- Design pre-deployment testing (bias, robustness, security) and post-deployment monitoring (drift, feedback)
- Build model cards, datasheets for datasets and user-facing AI transparency notices
- Operate a human-in-the-loop oversight SOP for high-impact decisions
- Run an AI incident response under RBI FREE-AI, SEBI CSCRF and DPDP breach notification regimes
- Map an India AI governance programme to EU AI Act, NIST AI RMF, ISO/IEC 42001 and OECD Principles for GCC compliance architecture
- Deliver a complete ten-week AI governance programme file for Aarti Capital Markets
Prerequisites
- A working understanding of what machine learning is and how an AI model gets trained and deployed. If you have ever sat in an engineering review of an ML pipeline, you are fine.
- No prior AI governance certification required. ISO/IEC 42001, IAPP AIGP and DSCI DCAGP alumni will find the India-regulator operational depth here that global certifications omit.
- The dcomply ISO/IEC 42001 Practitioner course is a helpful standards-layer prerequisite but not required. This course assumes operational literacy and teaches India-regulator craft.
Who this is for
- Chief AI Officer, AI Risk Lead, Responsible AI Specialist at any Indian company training or deploying AI
- CISO and DPO extending scope to cover model risk
- Product managers at IndiaAI Mission startups and BFSI AI deployers
- GCC compliance teams in Bengaluru, Hyderabad, Gurugram, Pune running EU AI Act + India dual compliance
- Chartered Accountants, Company Secretaries and advocates advising BFSI clients on model risk
- CISOs scoping SEBI CSCRF AI audit expansion post the 5 May 2026 Advisory
- Head of Data at mid-market Indian firms deploying generative AI
- What we collect: name, email, IP address (for security logging), and course progress.
- Why: to email you the one-click access link, deliver lessons, issue your certificate, and (with your consent) send course updates plus a Day-7 follow-up about dcomply.
- How long: kept until you unsubscribe or request erasure.
- Your rights under the DPDP Act 2023: access, correction, erasure, and grievance redressal. Write to [email protected] to exercise any of them.
- Unsubscribe any time using the link in every email we send you.
Syllabus
12 modules, 60 lessons. Click any module to expand.
A working picture of the whole regime in one module. The named AI Governance Officer role. How RBI FREE-AI (13 August 2025) birthed the MeitY Guidelines (5 November 2025) and the 7 Sutras they both share. The function-based accountability model (developer, deployer, data provider). The regulator map across MeitY, DPDP Board, SEBI, RBI, IRDAI, TRAI and ED. The ten-week engagement map that frames every later module. This module is free preview so buyers can validate depth and voice before purchasing.
- 1. The named AI Governance Officer role, and why your organisation must create one in 2026 12 min
- 2. RBI FREE-AI to MeitY. How India's AI governance stack was built in two documents 12 min
- 3. The function-based accountability model. Developer vs deployer vs data provider 12 min
- 4. The regulator map. MeitY, DPDP Board, SEBI, RBI, IRDAI, TRAI and the Enforcement Directorate 12 min
- 5. The ten-week engagement map. What you will build and in what order 12 min
The 7 Sutras of Responsible AI with the Indian context behind each. The 6 Pillars across Enablement, Regulation and Oversight. Deployer, developer and data provider duties as three mutually reinforcing lines of accountability. Transparency reporting under Sutra 6 Understandable by Design. The three institutions (AIGG, TPEC, AISI) and how to track their stand-up status. The voluntary-now-mandatory-signalled posture and what that means for your 2026-27 planning.
- 1. The 7 Sutras, one by one, with the Indian context behind each 13 min
- 2. The 6 Pillars across Enablement, Regulation and Oversight, and the two Pillars where you actually spend time 12 min
- 3. Developer, deployer, data provider. Three functions, three parallel sets of duties documented, signed and defended 13 min
- 4. Transparency reporting under Sutra 6, aligned to DPDP, and what a disclosure a regulator can understand actually looks like 12 min
- 5. AIGG, TPEC and AISI. The three institutions, the current state on 9 October 2026 and how to track 12 min
The FREE-AI Committee, the Report of 13 August 2025 and the 26 Recommendations that preceded the MeitY Guidelines. The RBI Draft Model Risk Circular of 5 August 2024 and the expanded 2026 cycle (comments closed 24 July 2026). AI in credit underwriting including borrower scoring, bias testing and challenger models. The AI kill-switch expectation and the indicative AI incident reporting form. What a bank or NBFC Board policy on AI must say.
- 1. The FREE-AI Committee, the Report of 13 August 2025 and the 26 Recommendations that preceded MeitY 13 min
- 2. The Model Risk Management Framework. RBI Draft of 5 August 2024 and the expanded 2026 cycle 13 min
- 3. AI in credit underwriting. Borrower scoring, bias testing and challenger models at an NBFC gold-loan and personal-loan book 13 min
- 4. The AI kill-switch and incident reporting. FREE-AI expectations, the Chapter 5 form and the CERT-In six-hour interface 13 min
- 5. The Bank and NBFC Board policy on AI. The twelve-clause specimen outline 13 min
The SEBI Advisory HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 of 5 May 2026, line by line. The 10-item Annexure A with practical implementation on AI VA tools (Item 2), M-SOC onboarding (Item 6c), SBOM for all critical applications (Item 9) and the long-term plan for agentic mitigation (Item 10). The Mythos threat context. The project-cyber-suraksha.ai task force. Interaction with the SEBI CSCRF and the audit-scope expansion. Aarti Capital Markets as the running case study across the three AI use cases.
- 1. The SEBI AI Vulnerability Advisory of 5 May 2026. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 12 min
- 2. Annexure A, ten items. The deep walk through items 2, 6c, 9 and 10 14 min
- 3. Market SOC onboarding. What M-SOC is, what it ingests and how an entity integrates 12 min
- 4. How the AI Advisory expands CSCRF audit scope. project-cyber-suraksha.ai and advisor obligations 12 min
- 5. Running the SEBI AI programme end-to-end on Aarti Capital Markets 14 min
Section 10 Significant Data Fiduciary criteria and the six-factor test. Section 10(2)(c) proviso on algorithmic due diligence as the single clearest AI-governance hook in Indian law today. Rule 13 periodic DPIA, independent audit and specified Board reporting. Rule 7 commencement 14 May 2027 and AI incident breach notification. The Indian design choice to omit a GDPR Article 22 right against solely automated decisions, and what Section 10(2)(c) proviso does instead.
- 1. Section 10 Significant Data Fiduciary. The six-factor test and why nobody has been notified yet 12 min
- 2. Section 10(2)(c) proviso. Algorithmic due diligence, verbatim text and operational meaning 13 min
- 3. Rule 13. Twelve-month DPIA, independent audit and the Board reporting cadence 13 min
- 4. Rule 7 breach notification. AI incidents, the DPB clock, the MeitY expectation and the CERT-In six-hour window 13 min
- 5. Why DPDP has no Article 22. India chose a de facto automated decision regime through Section 10(2)(c) 13 min
The role itself. The appointment Board resolution with the five authorities. The AI inventory and model register, row structure and sourcing. The twelve-clause internal AI governance policy. The Board reporting cadence and the five KPIs that matter (model inventory coverage, DPIA completion, incident count, bias-test outcomes, training-data provenance). Personal liability and the due-diligence defence available under Indian law.
- 1. The appointment Board resolution in detail. Five authorities, eleven paragraphs, one specimen 13 min
- 2. The AI inventory and model register. Columns, worked rows, and the "one-page in thirty minutes" test 13 min
- 3. The twelve-clause AI governance policy. Scope to third-party management, one clause at a time 14 min
- 4. The Board reporting cadence and the five KPIs that matter 13 min
- 5. Personal liability and the due-diligence defence. DPDP Schedule, sectoral penalties, Section 79 safe harbour 14 min
Risk classification by use case including the practical test for a "high-impact decision" where MeitY has not notified a numerical threshold. The AI-specific DPIA format aligned to Section 10(2)(c) proviso. Pre-deployment testing covering bias, robustness and security. Post-deployment monitoring covering drift, concept shift and feedback loops. Change control, retraining triggers and the end-to-end incident response.
- 1. High-impact decision classification. The method MeitY left to you 13 min
- 2. The AI-specific DPIA. Ten sections that satisfy DPDP Section 10(2)(c) and Rule 13 13 min
- 3. Pre-deployment testing. Bias, robustness and security batteries that satisfy a regulator 13 min
- 4. Post-deployment monitoring. Drift, feedback loops, shadow mode and the thresholds that trigger review 13 min
- 5. Change control, retraining and incident response. Closing the lifecycle loop 13 min
User-facing transparency notices under MeitY Sutra 6 Understandable by Design. Model documentation using model cards, system cards and datasheets for datasets. Explainability techniques for high-impact decisions (post-hoc explanations, counterfactuals, feature importance). Human-in-the-loop design patterns across pre-decision, decision and post-decision stages. Audit trail and immutable logging for AI decisions that must be explained three years after they were made.
- 1. User-facing transparency notices. Operationalising Sutra 6 for Aarti Capital's three AI use cases 12 min
- 2. Model cards and datasheets for datasets. The two documents a regulator will ask for first 13 min
- 3. Explainability for high-impact decisions. What SHAP, LIME and counterfactuals buy you, and where they fail 13 min
- 4. Human-in-the-loop oversight. Three stages, one SOP, and how to document that a human actually reviewed 12 min
- 5. Audit trail and immutable logging. Reconstructing a specific AI decision three years later 13 min
The IT Rules 2026 amendment notified 10 February 2026 and in force 20 February 2026. The new "Synthetically Generated Information" category and what counts. Mandatory labelling and permanent provenance metadata requirements. The three-hour takedown window under Rule 3(1)(d) for court or government-flagged unlawful content and the separate two-hour window for non-consensual sexual imagery including morphed and deepfake nudity. The deepfake case law from Rashmika Mandanna (October 2023) through 2024 Lok Sabha election incidents to the Images Bazaar PIL. The MeitY 1 March 2024 advisory and the 15 March 2024 revision read together.
- 1. The new Synthetically Generated Information category under the IT Rules 2026 amendment 12 min
- 2. Labelling and provenance metadata. Watermarks, C2PA and metadata that survives re-encoding 13 min
- 3. The three-hour takedown and the two-hour non-consensual sexual imagery window 13 min
- 4. Deepfake case law. Rashmika Mandanna, Lok Sabha 2024 and Images Bazaar PIL 13 min
- 5. The MeitY advisories of 1 March and 15 March 2024. How India iterates fast 13 min
The IRDAI AI Working Group of 19 June 2026 and the expected Q1-Q2 2027 framework circular. The IRDAI Information and Cyber Security Guidelines of 6 April 2026 and AI as a threat vector in insurance. The Telecom Cyber Security Rules 2024 and the AI silence inside the generic defend obligation. The TRAI AIDAI proposal of 20 July 2023 and why MeitY went a different way with AIGG, TPEC and AISI. Healthcare, education and public-services AI governance.
- 1. IRDAI AI Working Group and the framework insurers should pre-build 12 min
- 2. The IRDAI 2026 Cyber Security Guidelines and AI as a threat vector 12 min
- 3. The Telecom Cyber Security Rules 2024 and where AI sits in a silent framework 12 min
- 4. TRAI's AIDAI proposal and why MeitY picked AIGG, TPEC and AISI instead 12 min
- 5. Healthcare, education and public-services AI: the gaps and the practitioner playbook 13 min
EU AI Act Regulation 2024/1689 and the four risk tiers, with phased application through 2 December 2027 and 2 August 2028. NIST AI RMF 1.0 (AI 100-1) and the Generative AI Profile (AI 600-1) with its 12 risk categories. OECD AI Principles update of 3 May 2024. ISO/IEC 42001:2023 crosswalk to the MeitY 7 Sutras. The GCC compliance architecture question of when an Indian subsidiary of a multinational must meet EU + India + US expectations simultaneously.
- 1. EU AI Act. The four risk tiers and the phased timeline that quietly binds Indian GCCs 13 min
- 2. NIST AI RMF 1.0 and the GenAI Profile. Four functions and twelve generative risks 13 min
- 3. OECD AI Principles. The common vocabulary that lets a Mumbai team talk to a Munich team 12 min
- 4. ISO/IEC 42001. The voluntary conformity path and the clause-by-clause map to the MeitY 7 Sutras 13 min
- 5. The GCC compliance architecture. One baseline plus two overlays, when EU plus India plus US arrives at once 13 min
The capstone walks you through a complete ten-week AI governance programme on Aarti Capital Markets Pvt Ltd, a fictional Mumbai SEBI-registered mid-size broker and AMC combo with Rs 8,400 crore AUM across 180 employees, deploying AI for client-onboarding risk scoring, real-time trade surveillance and portfolio recommendations. You produce every artifact from Modules 1-11 on this one entity and submit a complete programme file. The final exam is 45 questions drawn from a 70-item pool, covering every module, with each question anchored to a specific Section, Rule, Guideline, Advisory, Circular or international standard clause cited in the course.
- 1. Build your ten-week AI governance programme. The scope document and the stakeholder map 11 min
- 2. Weeks 1-10 Gantt and the twelve artifacts of the capstone workbook 11 min
- 3. The Board briefing deck and the year-1 operating calendar 11 min
- 4. The 25-anchor exam reference card 10 min
- 5. The final exam. 45 questions from a 70-item pool, 90 minutes, 75 percent pass 10 min
Everything a buyer usually asks
Who is this course for?
Is there a free preview?
What do I get when I enrol?
Is there a certificate on completion?
How much does the course cost?
How long do I have to complete the course?
Can I retake the final exam?
How do you keep the course current when the law changes?
Is this course legal advice?
This course is a paid practitioner training programme. Every statutory and regulatory claim is anchored to a primary source cited in the lesson. As of 9 October 2026 several items are still in motion: the MeitY India AI Governance Guidelines of 5 November 2025 are voluntary and the AI Governance Group (AIGG) was formally constituted on 16 April 2026 and the Technology and Policy Expert Committee (TPEC) on 18 April 2026; the IndiaAI Safety Institute (AISI) Director recruitment closed 2 June 2026 with appointment pending public confirmation as of 9 October 2026; the IRDAI AI Working Group report is expected September 2026 with a draft AI framework circular likely Q1-Q2 2027; the RBI final Guidance on Model Risk Management is expected after the 24 July 2026 comments window; a standalone Digital India Act or AI Bill is in drafting (announced July 2026) but no draft is in Parliament; the TRAI AIDAI proposal of 20 July 2023 has been overtaken by the MeitY AIGG + TPEC + AISI pathway but not formally withdrawn; MeitY has not notified a numerical threshold for "high-impact decisions" under its Guidelines. The course flags each live-frontier item in the lesson where it appears.
This course is not legal advice. For specific compliance decisions on your organisation, retain a qualified advocate.
MeitY India AI Governance Guidelines dated 5 November 2025 (PIB PRID 2186639). Reserve Bank of India FREE-AI Committee Report dated 13 August 2025. RBI Draft Guidance on Regulatory Principles for Management of Model Risk in Credit (press release 5 August 2024; expanded draft 2026 cycle, comments window closed 24 July 2026). SEBI Advisory on Emerging Advanced AI Tools for Vulnerability Detection HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026. SEBI Master Circular on Cyber Security and Cyber Resilience Framework (CSCRF). DPDP Act 2023 (No. 22 of 2023), Section 10 Significant Data Fiduciary obligations and Section 10(2)(c) proviso on algorithmic due diligence. DPDP Rules 2025 notified 13 November 2025 via Gazette Notifications G.S.R. 843(E) to 846(E), with phased commencement culminating 13 May 2027. IRDAI Information and Cyber Security Guidelines dated 6 April 2026. IRDAI AI Working Group constituted 19 June 2026. Telecommunications (Telecom Cyber Security) Rules 2024 notified 21 November 2024 under the Telecommunications Act 2023. TRAI Recommendations on Leveraging AI and Big Data in the Telecommunication Sector dated 20 July 2023. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 notified 10 February 2026 (Synthetically Generated Information category). MeitY Advisory of 1 March 2024 and Revised Advisory of 15 March 2024. IndiaAI Mission approved by Union Cabinet 7 March 2024 (budget Rs 10,371.92 crore over five years). EU AI Act (Regulation 2024/1689) in force 1 August 2024 with phased application through 2 December 2027 and 2 August 2028. NIST AI Risk Management Framework 1.0 (AI 100-1) dated January 2023 and NIST Generative AI Profile (AI 600-1) dated July 2024. OECD AI Principles update dated 3 May 2024. ISO/IEC 42001:2023, ISO/IEC 23894:2023, ISO/IEC 23053:2022. Standing Committee on Communications and IT Report on Impact of Emergence of AI and Related Issues dated 30 March 2026.