Let me close Module 1 by walking the Indian regulatory reality that sits on top of the ISO baseline. Because if you build an ISO 42001 AIMS in Indian conditions without paying attention to what MeitY is saying, what SEBI is saying and what RBI is saying, you are going to build a technically correct AIMS that misses the political and regulatory context of the country you are operating in. That is a real risk. Auditors will still give you the certificate. Regulators may still ask a different question.
The India AI Governance Guidelines, in short
MeitY released the India AI Governance Guidelines in November 2025 [L5-C3]. They were released ahead of the India AI Impact Summit that Bharat hosted in February 2026. The Guidelines are non-binding. They do not carry statutory force. But they were drafted by a committee constituted by MeitY specifically to shape India's approach to AI governance, and Annexure 6 of the Guidelines names ISO/IEC 42001 as the recommended management-system standard. When MeitY names an ISO standard in an official policy document, procurement teams inside government contractors, PSUs and government-adjacent enterprises start listing that standard in their tender documents. Whether or not you personally care about the Guidelines, your customers will start caring, and quickly.
The Guidelines are organised around seven sutras and six pillars. Let me walk each.
The seven sutras
The Guidelines use the word "sutra" deliberately. Sutra in Sanskrit means a thread — a short, memorable formula that runs through everything. The drafting committee chose the word because they wanted principles that were both memorable and durable. The seven are:
- Trust — AI systems and the organisations that deploy them must earn the trust of users, affected individuals and the wider society.
- People-first governance — decisions about AI must centre the interests of people, especially those affected by the AI, not only those benefiting from it.
- Innovation over restraint — the framework should enable AI development, not stifle it with heavy-handed prohibition.
- Fairness and equity — AI systems must be tested for bias and designed to serve diverse Indian users equitably.
- Accountability — clear responsibility for AI outcomes must sit with identifiable people and organisations.
- Understandability by design — AI systems must be explainable to the level the stakeholder requires.
- Safety, resilience and sustainability — AI systems must be safe in operation, resilient to failure, and sustainable in resource use.
Notice how these seven sutras contain the same concepts that the ISO 42001 Annex A controls operationalise. Trust and Accountability map to Annex A.2 Policies and A.3 Internal Organisation. People-first governance maps to Annex A.5 Impact Assessment. Fairness maps to Annex A.5 and A.6 lifecycle. Understandability maps to Annex A.8 Information for Interested Parties. Safety maps to Annex A.6 lifecycle. This is not coincidence. The drafting committee explicitly drew from international management-system practice.
The six pillars
The six pillars are the operational programmes recommended to translate the sutras into action across the country:
- Infrastructure — increasing compute capacity and data access, integration of AI with Digital Public Infrastructure (Aadhaar, UPI, DigiLocker).
- Capacity building — capacity development within government, law enforcement and citizens; AI skills in smaller cities.
- Policy and regulation — evaluation of existing laws in relation to AI, and regulatory sandboxes for new frameworks.
- Risk mitigation — India-specific AI risk classification and a national AI incident reporting framework.
- Accountability — clarification of how current laws apply to AI, and mandatory complaint-filing options for affected individuals.
- Institutions — establishment of new institutional bodies to govern AI (the IndiaAI Safety Institute announced in January 2025 is the first of these).
You will notice these pillars are less operational for a single organisation than the sutras are. The sutras are what your AIMS operationalises. The pillars are what the country as a whole is trying to build.
Mapping the sutras onto the ISO 42001 clauses
When you sit down to design your AIMS, do this mapping deliberately. Do not leave it implicit. Write it into your AI Policy under Clause 5.2 and reference it in your AIIA methodology under Annex A.5.2. Here is the mapping I would use as a starting point:
| Sutra | Where it lives in the AIMS |
|---|---|
| Trust | Clause 5.2 AI Policy top-management commitment; Annex A.2.2 AI Policy; Annex A.8 Information for Interested Parties |
| People-first governance | Clause 4.2 Interested Parties (must include affected individuals, not only customers); Annex A.5 Impact Assessment |
| Innovation over restraint | Clause 6.2 AI Objectives (should be enabling, not only restrictive); Annex A.9 Use of AI Systems (responsible use process should encourage development within guardrails) |
| Fairness and equity | Annex A.5.4 Impact on individuals and groups; Annex A.6.2 AI life cycle controls; Annex A.7 Data quality controls |
| Accountability | Clause 5.3 Roles and Responsibilities; Annex A.3.2 AI roles; Annex A.3.3 Reporting of concerns; Annex A.10 Third-party relationships |
| Understandability by design | Annex A.8 Information for Interested Parties; Annex A.8.3 Information for users; Annex A.6.2 AI lifecycle controls on documentation |
| Safety, resilience, sustainability | Annex A.6 AI life cycle (deployment, operation, monitoring, decommissioning); Annex A.9 Responsible use |
When your customer or your regulator later asks "how are you addressing the India AI Governance Guidelines," you point at this table and at the specific AIMS artefacts each row references. That is a defensible answer.
Where the IT Amendment Rules 2026 sit
The IT Amendment Rules 2026 [L5-C4] are not the same thing as the Guidelines. The Rules are binding subordinate legislation under the Information Technology Act 2000. They came into force on 20 February 2026, ten days after notification. Their key change is the introduction of Synthetically Generated Information (SGI) as a due-diligence category for intermediaries. If your organisation is an intermediary — and the definition of intermediary is broad — you must clearly label AI-generated content, embed metadata identifying the computer resource where feasible, and comply with expedited takedown timelines for deepfake harm.
For an AIMS, the practical effect is that Annex A.8 Information for Interested Parties controls now have a hard legal minimum. Your labelling process, your metadata embedding, your takedown workflow — these are not just good AI hygiene; they are subordinate law compliance. Document them accordingly in your SoA. Module 8 walks the operational implementation.
SEBI and RBI overlays
If your organisation is a SEBI-regulated entity — an exchange, depository, broker, mutual fund, custodian, credit rating agency, merchant banker, portfolio manager or investment advisor — the SEBI Circular of 5 May 2026 [L5-C5] is directly applicable. Its focus is on advanced AI-driven vulnerability detection tools, but its structural requirement is that regulated entities strengthen their cybersecurity posture, run AI-assisted vulnerability assessments, and onboard onto the centralised Market SOC platform. In an AIMS, this maps to Annex A.9 Responsible Use and Annex A.6.2 lifecycle controls covering AI system security. Module 8 walks the mapping.
If your organisation is RBI-regulated — a bank, NBFC, HFC, all-India financial institution, credit information company or payment system operator — the RBI FREE-AI Committee Report of 13 August 2025 [L5-C6] sets the direction. The report is not a binding master direction today, but Committee reports of this weight in RBI history tend to convert into master directions within twelve to twenty-four months. Building your AIMS in a way that already addresses the FREE-AI Report's seven sutras (RBI's own, distinct from MeitY's) and six pillars means that when the master direction lands, you are already substantially compliant. Module 8 walks the FREE-AI structure.
What Module 1 has given you
By now, if you have followed all five lessons in Module 1, you should be able to say:
- What ISO/IEC 42001:2023 is, when it was published, and who owns it
- The difference between the standard, the AIMS, the certificate and the accreditation chain
- Why 2026 turned ISO 42001 from an optional badge into a procurement gate for Indian companies selling to European buyers
- The ten clauses and 38 Annex A controls of ISO 42001, and how it uses the Annex SL Harmonised Structure to integrate with ISO 27001
- How ISO 42001 differs from NIST AI RMF (voluntary, US, four functions) and the EU AI Act (binding law, extraterritorial, phased through 2028)
- Why ISO 42001 is the vehicle through which you demonstrate compliance with the EU AI Act and alignment with NIST AI RMF using a single documented system
- The twelve-to-eighteen month path from decision to first certificate — ten artefacts, Stage 1 and Stage 2 audits, the three-year sustain cycle
- The India regulatory overlay — seven sutras and six pillars of the India AI Governance Guidelines, IT Amendment Rules 2026 SGI obligations, SEBI 5 May 2026 Advisory, RBI FREE-AI direction
That is a solid foundation. In Module 2, we will start reading the clauses. I will walk each of Clauses 4, 5 and 6 in the same voice — direct, patient, grounded in what actually happens in an implementation. If Module 1 is what you paid for, Modules 2 through 8 are what you get.