Live 16 practitioner certifications live · First lesson free on every course Back to main site →

How the India AI Governance Guidelines sit on top of ISO 42001

The India AI Governance Guidelines released by MeitY in November 2025 are non-binding but they shape the direction of Indian AI regulation. This lesson walks the seven sutras and six pillars, shows how they map onto the ISO 42001 clause structure, and explains why designing your AIMS with the sutras in mind is what turns a foreign standard into an Indian operating system.

Free preview 12 min read Under review
Legal basis
ISO/IEC 42001 primary-source stack current to 19 September 2026. Core: ISO/IEC 42001:2023 first edition December 2023 (ten clauses 0-10 plus Annex A with 38 controls across groups A.2 Policies related to AI, A.3 Internal organisation, A.4 Resources for AI systems, A.5 Assessing impacts of AI systems on individuals or groups and societies, A.6 AI system lifecycle, A.7 Data for AI systems, A.8 Information for interested parties of AI systems, A.9 Use of AI systems, A.10 Third-party and customer relationships, plus Annex B implementation guidance, Annex C AI-related organisational objectives, Annex D use of AIMS across domains). Companion standards: ISO/IEC 23894:2023 (guidance on AI risk management), ISO/IEC 23053:2022 (framework for AI systems using machine learning), ISO/IEC 42005:2025 (AI system impact assessment), ISO/IEC 22989:2022 (AI concepts and terminology), ISO/IEC TR 24028:2020 (trustworthiness in AI). Integration standards: ISO/IEC 27001:2022 for the AIMS-on-top-of-ISMS pattern, ISO/IEC 27701:2025 for the PIMS integration. India-specific stack: India AI Governance Guidelines released by MeitY in November 2025 (seven sutras Trust / People-first / Innovation over restraint / Fairness and equity / Accountability / Understandability by design / Safety resilience sustainability, across six pillars Infrastructure / Capacity building / Policy and regulation / Risk mitigation / Accountability / Institutions, with Annexure 6 recommending ISO/IEC 42001), Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 notified 10 February 2026 effective 20 February 2026 introducing Synthetically Generated Information as a due-diligence category with visual labelling audio disclosure metadata embedding and 2 to 3 hour takedown for deepfake harm, MeitY AI Advisory dated March 2024 on labelling AI-generated content operative until superseded on labelling by the 2026 Rules, SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 (Advisory on emerging advanced AI tools for vulnerability detection, Cyber-suraksha.ai task force, applies to every regulated entity in the Indian securities market), Report of the RBI Committee on FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) chaired by Professor Pushpak Bhattacharyya of IIT Bombay released 13 August 2025 (seven sutras 26 recommendations six pillars Infrastructure Policy Capacity Governance Protection Assurance), DPDP Act 2023 and DPDP Rules 2025 notified November 2025 with phased commencement (no equivalent to GDPR Article 22, no right to explanation), BIS adoption as IS/ISO/IEC 42001:2023 identical to ISO text, IndiaAI Mission approved March 2024 with ₹10,371 crore outlay over five years across seven pillars including Safe & Trusted AI (13 projects funded as of July 2026 on deepfake and bias), IndiaAI Safety Institute announced January 2025. Global adjacent regulation for extraterritorial reach and crosswalk: EU AI Act Regulation (EU) 2024/1689 phased application 2 February 2025 prohibited practices and AI literacy live, 2 August 2025 GPAI transparency for new models, 2 August 2026 general application and Article 50 transparency, 2 December 2026 new prohibited practices on synthetic intimate content and CSAM, 2 December 2027 Annex III high-risk (pushed back from August 2026 by Digital Omnibus), 2 August 2028 Annex I product-embedded high-risk. NIST AI Risk Management Framework 1.0 (January 2023) four functions Govern Map Measure Manage with official crosswalk to ISO/IEC 42001 published by NIST AIRC. OECD AI Principles (2019 updated 2024). UNESCO Recommendation on the Ethics of AI (2021). Council of Europe AI Framework Convention (opened for signature September 2024). Certification body landscape referenced: A-LIGN, BSI India, Bureau Veritas India, DNV Business Assurance India, Schellman, SGS India, TÜV SÜD South Asia, TÜV Nord India, Intertek India (accredited under ANAB, UKAS, RvA pending NABCB scheme extension). Personal certification schemes referenced (not primary): PECB Lead Implementer and Lead Auditor for ISO 42001, BSI ISO 42001 Lead Implementer, operating under ISO/IEC 17024. India first-mover organisational certifications referenced: Mphasis (first Indian IT services company to certify, 2025) and KPMG India (certified by SGS December 2025). Items requiring ongoing verification and flagged inside the relevant lessons: NABCB scheme extension timeline for ISO 42001; any ISO/IEC 42001 amendment beyond first edition; Digital India Act draft status and eventual enactment; RBI conversion of FREE-AI Report recommendations into binding master directions; DPDP Board of India Chairperson appointment status; new India AI-specific legislation.

Let me close Module 1 by walking the Indian regulatory reality that sits on top of the ISO baseline. Because if you build an ISO 42001 AIMS in Indian conditions without paying attention to what MeitY is saying, what SEBI is saying and what RBI is saying, you are going to build a technically correct AIMS that misses the political and regulatory context of the country you are operating in. That is a real risk. Auditors will still give you the certificate. Regulators may still ask a different question.

The India AI Governance Guidelines, in short

MeitY released the India AI Governance Guidelines in November 2025 [L5-C3]. They were released ahead of the India AI Impact Summit that Bharat hosted in February 2026. The Guidelines are non-binding. They do not carry statutory force. But they were drafted by a committee constituted by MeitY specifically to shape India's approach to AI governance, and Annexure 6 of the Guidelines names ISO/IEC 42001 as the recommended management-system standard. When MeitY names an ISO standard in an official policy document, procurement teams inside government contractors, PSUs and government-adjacent enterprises start listing that standard in their tender documents. Whether or not you personally care about the Guidelines, your customers will start caring, and quickly.

The Guidelines are organised around seven sutras and six pillars. Let me walk each.

The seven sutras

The Guidelines use the word "sutra" deliberately. Sutra in Sanskrit means a thread — a short, memorable formula that runs through everything. The drafting committee chose the word because they wanted principles that were both memorable and durable. The seven are:

  1. Trust — AI systems and the organisations that deploy them must earn the trust of users, affected individuals and the wider society.
  2. People-first governance — decisions about AI must centre the interests of people, especially those affected by the AI, not only those benefiting from it.
  3. Innovation over restraint — the framework should enable AI development, not stifle it with heavy-handed prohibition.
  4. Fairness and equity — AI systems must be tested for bias and designed to serve diverse Indian users equitably.
  5. Accountability — clear responsibility for AI outcomes must sit with identifiable people and organisations.
  6. Understandability by design — AI systems must be explainable to the level the stakeholder requires.
  7. Safety, resilience and sustainability — AI systems must be safe in operation, resilient to failure, and sustainable in resource use.

Notice how these seven sutras contain the same concepts that the ISO 42001 Annex A controls operationalise. Trust and Accountability map to Annex A.2 Policies and A.3 Internal Organisation. People-first governance maps to Annex A.5 Impact Assessment. Fairness maps to Annex A.5 and A.6 lifecycle. Understandability maps to Annex A.8 Information for Interested Parties. Safety maps to Annex A.6 lifecycle. This is not coincidence. The drafting committee explicitly drew from international management-system practice.

The six pillars

The six pillars are the operational programmes recommended to translate the sutras into action across the country:

  1. Infrastructure — increasing compute capacity and data access, integration of AI with Digital Public Infrastructure (Aadhaar, UPI, DigiLocker).
  2. Capacity building — capacity development within government, law enforcement and citizens; AI skills in smaller cities.
  3. Policy and regulation — evaluation of existing laws in relation to AI, and regulatory sandboxes for new frameworks.
  4. Risk mitigation — India-specific AI risk classification and a national AI incident reporting framework.
  5. Accountability — clarification of how current laws apply to AI, and mandatory complaint-filing options for affected individuals.
  6. Institutions — establishment of new institutional bodies to govern AI (the IndiaAI Safety Institute announced in January 2025 is the first of these).

You will notice these pillars are less operational for a single organisation than the sutras are. The sutras are what your AIMS operationalises. The pillars are what the country as a whole is trying to build.

Mapping the sutras onto the ISO 42001 clauses

When you sit down to design your AIMS, do this mapping deliberately. Do not leave it implicit. Write it into your AI Policy under Clause 5.2 and reference it in your AIIA methodology under Annex A.5.2. Here is the mapping I would use as a starting point:

SutraWhere it lives in the AIMS
TrustClause 5.2 AI Policy top-management commitment; Annex A.2.2 AI Policy; Annex A.8 Information for Interested Parties
People-first governanceClause 4.2 Interested Parties (must include affected individuals, not only customers); Annex A.5 Impact Assessment
Innovation over restraintClause 6.2 AI Objectives (should be enabling, not only restrictive); Annex A.9 Use of AI Systems (responsible use process should encourage development within guardrails)
Fairness and equityAnnex A.5.4 Impact on individuals and groups; Annex A.6.2 AI life cycle controls; Annex A.7 Data quality controls
AccountabilityClause 5.3 Roles and Responsibilities; Annex A.3.2 AI roles; Annex A.3.3 Reporting of concerns; Annex A.10 Third-party relationships
Understandability by designAnnex A.8 Information for Interested Parties; Annex A.8.3 Information for users; Annex A.6.2 AI lifecycle controls on documentation
Safety, resilience, sustainabilityAnnex A.6 AI life cycle (deployment, operation, monitoring, decommissioning); Annex A.9 Responsible use

When your customer or your regulator later asks "how are you addressing the India AI Governance Guidelines," you point at this table and at the specific AIMS artefacts each row references. That is a defensible answer.

Where the IT Amendment Rules 2026 sit

The IT Amendment Rules 2026 [L5-C4] are not the same thing as the Guidelines. The Rules are binding subordinate legislation under the Information Technology Act 2000. They came into force on 20 February 2026, ten days after notification. Their key change is the introduction of Synthetically Generated Information (SGI) as a due-diligence category for intermediaries. If your organisation is an intermediary — and the definition of intermediary is broad — you must clearly label AI-generated content, embed metadata identifying the computer resource where feasible, and comply with expedited takedown timelines for deepfake harm.

For an AIMS, the practical effect is that Annex A.8 Information for Interested Parties controls now have a hard legal minimum. Your labelling process, your metadata embedding, your takedown workflow — these are not just good AI hygiene; they are subordinate law compliance. Document them accordingly in your SoA. Module 8 walks the operational implementation.

SEBI and RBI overlays

If your organisation is a SEBI-regulated entity — an exchange, depository, broker, mutual fund, custodian, credit rating agency, merchant banker, portfolio manager or investment advisor — the SEBI Circular of 5 May 2026 [L5-C5] is directly applicable. Its focus is on advanced AI-driven vulnerability detection tools, but its structural requirement is that regulated entities strengthen their cybersecurity posture, run AI-assisted vulnerability assessments, and onboard onto the centralised Market SOC platform. In an AIMS, this maps to Annex A.9 Responsible Use and Annex A.6.2 lifecycle controls covering AI system security. Module 8 walks the mapping.

If your organisation is RBI-regulated — a bank, NBFC, HFC, all-India financial institution, credit information company or payment system operator — the RBI FREE-AI Committee Report of 13 August 2025 [L5-C6] sets the direction. The report is not a binding master direction today, but Committee reports of this weight in RBI history tend to convert into master directions within twelve to twenty-four months. Building your AIMS in a way that already addresses the FREE-AI Report's seven sutras (RBI's own, distinct from MeitY's) and six pillars means that when the master direction lands, you are already substantially compliant. Module 8 walks the FREE-AI structure.

What Module 1 has given you

By now, if you have followed all five lessons in Module 1, you should be able to say:

  • What ISO/IEC 42001:2023 is, when it was published, and who owns it
  • The difference between the standard, the AIMS, the certificate and the accreditation chain
  • Why 2026 turned ISO 42001 from an optional badge into a procurement gate for Indian companies selling to European buyers
  • The ten clauses and 38 Annex A controls of ISO 42001, and how it uses the Annex SL Harmonised Structure to integrate with ISO 27001
  • How ISO 42001 differs from NIST AI RMF (voluntary, US, four functions) and the EU AI Act (binding law, extraterritorial, phased through 2028)
  • Why ISO 42001 is the vehicle through which you demonstrate compliance with the EU AI Act and alignment with NIST AI RMF using a single documented system
  • The twelve-to-eighteen month path from decision to first certificate — ten artefacts, Stage 1 and Stage 2 audits, the three-year sustain cycle
  • The India regulatory overlay — seven sutras and six pillars of the India AI Governance Guidelines, IT Amendment Rules 2026 SGI obligations, SEBI 5 May 2026 Advisory, RBI FREE-AI direction

That is a solid foundation. In Module 2, we will start reading the clauses. I will walk each of Clauses 4, 5 and 6 in the same voice — direct, patient, grounded in what actually happens in an implementation. If Module 1 is what you paid for, Modules 2 through 8 are what you get.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview complete You've read every free lesson in Module 1

Ready for the rest of ISO/IEC 42001 AI Management System Practitioner Certification?

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
MeitY AI Governance Guidelines, India AI Governance Guidelines Nov 2025 (Seven sutras + six pillars) L5-C3
MeitY released the India AI Governance Guidelines in November 2025. Techno-legal principle-driven approach anchored by seven sutras: Trust, People-first governance, Innovation over restraint, Fairness and equity, Accountability, Understandability by design, Safety-resilience-sustainability. Six pillars: Infrastructure, Capacity building, Policy and regulation, Risk mitigation, Accountability, Institutions. Non-binding but reflects governmental direction. Annexure 6 recommends ISO/IEC 42001 as the operational management-system standard for organisations.
IT Amendment Rules 2026, IT Rules Amendment 2026 SGI (SGI due-diligence obligations) L5-C4
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 were notified on 10 February 2026 and became effective 20 February 2026. Rule 3(1)(v) introduces Synthetically Generated Information (SGI) as a due-diligence category. Non-prohibited AI-generated content must be clearly and prominently labelled (visual for visual, audio for audio). Metadata must be embedded to trace the computer resource where feasible. Takedown timelines for harmful content reduced from 24-36 hours to 2-3 hours.
SEBI Circular 5-May-2026, SEBI Advisory 5-May-2026 Mythos (AI vulnerability detection advisory) L5-C5
SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 addressed to every regulated entity in the Indian securities market (exchanges, depositories, brokers, mutual funds, custodians, credit rating agencies, merchant bankers, portfolio managers, investment advisors). Response to advanced AI-driven vulnerability detection tools such as Mythos. Requires strengthened cybersecurity, immediate patch management, AI-assisted vulnerability assessments, enhanced API security, continuous SOC monitoring, system hardening and onboarding with the centralised Market SOC platform. Established the Cyber-suraksha.ai task force.
RBI FREE-AI Report, RBI FREE-AI Report 13-Aug-2025 (Bhattacharyya Committee framework) L5-C6
Report of the RBI Committee on FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) chaired by Professor Pushpak Bhattacharyya of IIT Bombay, released 13 August 2025. Seven guiding sutras and 26 recommendations across six pillars: Infrastructure, Policy, Capacity, Governance, Protection, Assurance. Non-binding today; sets RBI direction for future master directions applicable to banks, NBFCs, HFCs, AIFIs and payment system operators.
ISO/IEC 42001:2023, Clause 4.2 Interested parties (Interested parties for AIMS) L5-C7
Clause 4.2 requires the organisation to determine interested parties relevant to the AIMS, their requirements, and which of those requirements will be addressed. For AI, interested parties expressly include affected individuals and groups who are not customers — a broader stakeholder map than ISO 27001, and one that maps directly to the India AI Governance Guidelines People-first sutra.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: What ISO/IEC 42001 actually is, and why it turned into a procurement gate in 2026
Module 2: Reading Clauses 4, 5 and 6: Context, Leadership and Planning
  • Clauses 4.1 and 4.2: understanding your context and identifying interested parties
  • Clause 4.3: writing an AIMS Scope Statement that a certification body will accept
  • Clause 5: Leadership, AI Policy and Roles — where an AIMS becomes real
  • Clause 6.1: the AI risk assessment methodology — the beating heart of the AIMS
  • Clauses 6.2 and 6.3: AI objectives and planning of changes
Module 3: Reading Clauses 7, 8, 9 and 10: Support, Operation, Performance evaluation, Improvement
  • Clauses 7.1 to 7.4: Resources, Competence, Awareness, Communication
  • Clause 7.5: Documented information — what must be in writing, and how it is controlled
  • Clause 8: Operation — executing the risk methodology and running the AIIA
  • Clause 9: Performance evaluation — monitoring, internal audit, management review
  • Clause 10: Continual improvement, nonconformity and the CAPA process
Module 4: Annex A controls Part 1: A.2 Policies, A.3 Internal organisation, A.4 Resources, A.5 Impact assessment
  • Annex A.2 — Policies related to AI: three controls that anchor the AIMS
  • Annex A.3 — Internal organisation: AI roles and the concerns-reporting channel
  • Annex A.4 Part 1 — Data and tooling resources (A.4.2 and A.4.3)
  • Annex A.4 Part 2 — Compute, human and financial resources (A.4.4 to A.4.6)
  • Annex A.5 — AI Impact Assessment: the four controls that decide whether an AIMS is real
Module 5: Annex A controls Part 2: A.6 AI lifecycle, A.7 Data, A.8 Information, A.9 Use, A.10 Third-party
  • Annex A.6 Part 1 — AI lifecycle: requirements, design and development
  • Annex A.6 Part 2 — Verification, deployment, operation, monitoring and event logs
  • Annex A.7 — Data for AI systems: five controls with the DPDP overlay
  • Annex A.8 — Information for interested parties: where the IT Rules 2026 SGI obligations land
  • Annex A.9 and A.10 — Responsible use of AI systems and third-party relationships
Module 6: Building the AIMS end-to-end: inventory, impact assessment, risk assessment, Statement of Applicability, tooling
  • Building the AI system inventory — the foundation everything else hangs on
  • Running an AI Impact Assessment per ISO/IEC 42005:2025 — the operational template
  • Running the AI risk assessment methodology per ISO/IEC 23894:2023
  • Building the Statement of Applicability — the single most-audited document
  • GRC tooling landscape — buy versus build for an AIMS
Module 7: Certification body selection, Stage 1 audit, Stage 2 audit, certificate issuance
  • The accreditation chain — why the certificate means anything, and where NABCB stands on ISO 42001
  • CB selection — the RFP process, scoring criteria and negotiation
  • Stage 1 — the documentation review: what the auditor tests and how to pass first time
  • Stage 2 — the operating-effectiveness audit: sampling, interviews, evidence
  • The three-year sustain cycle — surveillance, recertification and living with the certificate
Module 8: The India overlay + the next five years: AI Governance Guidelines, IT Rules 2026, SEBI, RBI FREE-AI, DPDP, EU AI Act, NIST AI RMF
  • The India AI Governance Guidelines in operational depth — the seven sutras and six pillars, clause by clause
  • IT Amendment Rules 2026 SGI obligations in operational depth — the first binding AI law in India
  • Sector-specific overlays — SEBI 5-May-2026, RBI FREE-AI, and the wider sectoral picture
  • DPDP intersection with AI, and EU AI Act extraterritorial reach on Indian exporters
  • NIST AI RMF crosswalk and the next five years — closing the course