Live 16 practitioner certifications live · First lesson free on every course Back to main site →

Why you can trust this course

We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.

Legal basis snapshot: ISO/IEC 42001 primary-source stack current to 19 September 2026. Core: ISO/IEC 42001:2023 first edition December 2023 (ten clauses 0-10 plus Annex A with 38 controls across groups A.2 Policies related to AI, A.3 Internal organisation, A.4 Resources for AI systems, A.5 Assessing impacts of AI systems on individuals or groups and societies, A.6 AI system lifecycle, A.7 Data for AI systems, A.8 Information for interested parties of AI systems, A.9 Use of AI systems, A.10 Third-party and customer relationships, plus Annex B implementation guidance, Annex C AI-related organisational objectives, Annex D use of AIMS across domains). Companion standards: ISO/IEC 23894:2023 (guidance on AI risk management), ISO/IEC 23053:2022 (framework for AI systems using machine learning), ISO/IEC 42005:2025 (AI system impact assessment), ISO/IEC 22989:2022 (AI concepts and terminology), ISO/IEC TR 24028:2020 (trustworthiness in AI). Integration standards: ISO/IEC 27001:2022 for the AIMS-on-top-of-ISMS pattern, ISO/IEC 27701:2025 for the PIMS integration. India-specific stack: India AI Governance Guidelines released by MeitY in November 2025 (seven sutras Trust / People-first / Innovation over restraint / Fairness and equity / Accountability / Understandability by design / Safety resilience sustainability, across six pillars Infrastructure / Capacity building / Policy and regulation / Risk mitigation / Accountability / Institutions, with Annexure 6 recommending ISO/IEC 42001), Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 notified 10 February 2026 effective 20 February 2026 introducing Synthetically Generated Information as a due-diligence category with visual labelling audio disclosure metadata embedding and 2 to 3 hour takedown for deepfake harm, MeitY AI Advisory dated March 2024 on labelling AI-generated content operative until superseded on labelling by the 2026 Rules, SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 (Advisory on emerging advanced AI tools for vulnerability detection, Cyber-suraksha.ai task force, applies to every regulated entity in the Indian securities market), Report of the RBI Committee on FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) chaired by Professor Pushpak Bhattacharyya of IIT Bombay released 13 August 2025 (seven sutras 26 recommendations six pillars Infrastructure Policy Capacity Governance Protection Assurance), DPDP Act 2023 and DPDP Rules 2025 notified November 2025 with phased commencement (no equivalent to GDPR Article 22, no right to explanation), BIS adoption as IS/ISO/IEC 42001:2023 identical to ISO text, IndiaAI Mission approved March 2024 with ₹10,371 crore outlay over five years across seven pillars including Safe & Trusted AI (13 projects funded as of July 2026 on deepfake and bias), IndiaAI Safety Institute announced January 2025. Global adjacent regulation for extraterritorial reach and crosswalk: EU AI Act Regulation (EU) 2024/1689 phased application 2 February 2025 prohibited practices and AI literacy live, 2 August 2025 GPAI transparency for new models, 2 August 2026 general application and Article 50 transparency, 2 December 2026 new prohibited practices on synthetic intimate content and CSAM, 2 December 2027 Annex III high-risk (pushed back from August 2026 by Digital Omnibus), 2 August 2028 Annex I product-embedded high-risk. NIST AI Risk Management Framework 1.0 (January 2023) four functions Govern Map Measure Manage with official crosswalk to ISO/IEC 42001 published by NIST AIRC. OECD AI Principles (2019 updated 2024). UNESCO Recommendation on the Ethics of AI (2021). Council of Europe AI Framework Convention (opened for signature September 2024). Certification body landscape referenced: A-LIGN, BSI India, Bureau Veritas India, DNV Business Assurance India, Schellman, SGS India, TÜV SÜD South Asia, TÜV Nord India, Intertek India (accredited under ANAB, UKAS, RvA pending NABCB scheme extension). Personal certification schemes referenced (not primary): PECB Lead Implementer and Lead Auditor for ISO 42001, BSI ISO 42001 Lead Implementer, operating under ISO/IEC 17024. India first-mover organisational certifications referenced: Mphasis (first Indian IT services company to certify, 2025) and KPMG India (certified by SGS December 2025). Items requiring ongoing verification and flagged inside the relevant lessons: NABCB scheme extension timeline for ISO 42001; any ISO/IEC 42001 amendment beyond first edition; Digital India Act draft status and eventual enactment; RBI conversion of FREE-AI Report recommendations into binding master directions; DPDP Board of India Chairperson appointment status; new India AI-specific legislation.

How this ISO/IEC 42001 AI Management System Practitioner Certification register is built

This trust page is the citation register for the ISO/IEC 42001 AI Management System Practitioner Certification course. It cites 76 authorities across 18 statutory instruments, drawn from the legal basis snapshot above (ISO/IEC 42001 primary-source stack current to 19 September 2026. Core: ISO/IEC 42001:2023 first edition December 2023 (ten clauses 0-10 plus Annex A with 38 controls across groups A.2 Policies related to AI, A.3 Internal organisation, A.4 Resources for AI systems, A.5 Assessing impacts of AI systems on individuals or groups and societies, A.6 AI system lifecycle, A.7 Data for AI systems, A.8 Information for interested parties of AI systems, A.9 Use of AI systems, A.10 Third-party and customer relationships, plus Annex B implementation guidance, Annex C AI-related organisational objectives, Annex D use of AIMS across domains). Companion standards: ISO/IEC 23894:2023 (guidance on AI risk management), ISO/IEC 23053:2022 (framework for AI systems using machine learning), ISO/IEC 42005:2025 (AI system impact assessment), ISO/IEC 22989:2022 (AI concepts and terminology), ISO/IEC TR 24028:2020 (trustworthiness in AI). Integration standards: ISO/IEC 27001:2022 for the AIMS-on-top-of-ISMS pattern, ISO/IEC 27701:2025 for the PIMS integration. India-specific stack: India AI Governance Guidelines released by MeitY in November 2025 (seven sutras Trust / People-first / Innovation over restraint / Fairness and equity / Accountability / Understandability by design / Safety resilience sustainability, across six pillars Infrastructure / Capacity building / Policy and regulation / Risk mitigation / Accountability / Institutions, with Annexure 6 recommending ISO/IEC 42001), Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 notified 10 February 2026 effective 20 February 2026 introducing Synthetically Generated Information as a due-diligence category with visual labelling audio disclosure metadata embedding and 2 to 3 hour takedown for deepfake harm, MeitY AI Advisory dated March 2024 on labelling AI-generated content operative until superseded on labelling by the 2026 Rules, SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 (Advisory on emerging advanced AI tools for vulnerability detection, Cyber-suraksha.ai task force, applies to every regulated entity in the Indian securities market), Report of the RBI Committee on FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) chaired by Professor Pushpak Bhattacharyya of IIT Bombay released 13 August 2025 (seven sutras 26 recommendations six pillars Infrastructure Policy Capacity Governance Protection Assurance), DPDP Act 2023 and DPDP Rules 2025 notified November 2025 with phased commencement (no equivalent to GDPR Article 22, no right to explanation), BIS adoption as IS/ISO/IEC 42001:2023 identical to ISO text, IndiaAI Mission approved March 2024 with ₹10,371 crore outlay over five years across seven pillars including Safe & Trusted AI (13 projects funded as of July 2026 on deepfake and bias), IndiaAI Safety Institute announced January 2025. Global adjacent regulation for extraterritorial reach and crosswalk: EU AI Act Regulation (EU) 2024/1689 phased application 2 February 2025 prohibited practices and AI literacy live, 2 August 2025 GPAI transparency for new models, 2 August 2026 general application and Article 50 transparency, 2 December 2026 new prohibited practices on synthetic intimate content and CSAM, 2 December 2027 Annex III high-risk (pushed back from August 2026 by Digital Omnibus), 2 August 2028 Annex I product-embedded high-risk. NIST AI Risk Management Framework 1.0 (January 2023) four functions Govern Map Measure Manage with official crosswalk to ISO/IEC 42001 published by NIST AIRC. OECD AI Principles (2019 updated 2024). UNESCO Recommendation on the Ethics of AI (2021). Council of Europe AI Framework Convention (opened for signature September 2024). Certification body landscape referenced: A-LIGN, BSI India, Bureau Veritas India, DNV Business Assurance India, Schellman, SGS India, TÜV SÜD South Asia, TÜV Nord India, Intertek India (accredited under ANAB, UKAS, RvA pending NABCB scheme extension). Personal certification schemes referenced (not primary): PECB Lead Implementer and Lead Auditor for ISO 42001, BSI ISO 42001 Lead Implementer, operating under ISO/IEC 17024. India first-mover organisational certifications referenced: Mphasis (first Indian IT services company to certify, 2025) and KPMG India (certified by SGS December 2025). Items requiring ongoing verification and flagged inside the relevant lessons: NABCB scheme extension timeline for ISO 42001; any ISO/IEC 42001 amendment beyond first edition; Digital India Act draft status and eventual enactment; RBI conversion of FREE-AI Report recommendations into binding master directions; DPDP Board of India Chairperson appointment status; new India AI-specific legislation.).

Primary sources: ISO/IEC 42001:2023 (57 entries), EU AI Act 2024/1689 (2 entries), Public ISO 42001 Certification (2 entries).

Every claim in every ISO/IEC 42001 AI Management System Practitioner Certification lesson traces back to a Section, Rule, or judgment listed below. If a lesson references a specific obligation, click the [Lx-Cy] marker in that lesson to jump to the verbatim text in the register.

Our verification promise

  1. Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the [Lx-Cy] marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013.
  2. Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
  3. Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
  4. Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
8
modules
40
lessons
76
cited authorities
recent
last reviewed

The full citation register

Every authority used in any lesson appears below. Click a row to expand the verbatim text.

IS/ISO/IEC 42001:2023 BIS adoption , BIS national standard adoption 01 Jun 2024
Plain summary: The Bureau of Indian Standards has adopted ISO/IEC 42001:2023 as an Indian national standard designated IS/ISO/IEC 42001:2023, identical to the ISO text. Indian organisations can therefore certify to the Indian standard number without changing content. Referenced in Annexure 6 of the India AI Governance Guidelines November 2025.
IS/ISO/IEC 42001:2023 is the Indian identical adoption of ISO/IEC 42001:2023 Information technology Artificial intelligence Management system.

DPDP Act 2023 no Article 22 equivalent , Automated decisions not restricted 11 Aug 2023
Plain summary: The DPDP Act 2023 contains no equivalent to GDPR Article 22 (right not to be subject to a decision based solely on automated processing) and no right to explanation. Automated decision-making is not restricted per se by the DPDP Act. However Section 10 Significant Data Fiduciary (SDF) designation carries DPIA and audit obligations that catch material AI use in practice.
The Digital Personal Data Protection Act, 2023 does not include a provision equivalent to Article 22 of the GDPR, and does not include a general right to an explanation of automated decisions.

DPDP Rules 2025 notified Nov 2025 , Phased commencement 14 Nov 2025
Plain summary: The Digital Personal Data Protection Rules 2025 were notified in November 2025 with phased commencement. Draft rules were released for consultation in January 2025. SDF criteria and DPIA thresholds under the Rules catch organisations deploying AI for high-impact decisions such as credit, hiring, admission or eligibility.
The Digital Personal Data Protection Rules, 2025 have been notified and provide for phased commencement of the DPDP Act, 2023.

EU AI Act Article 5 prohibited practices , Prohibited practices live Feb 2025 02 Feb 2025
Plain summary: Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, prohibited practices (Article 5) and AI literacy obligations (Article 4) became applicable on 2 February 2025. From that date organisations must have stopped social scoring, subliminal manipulation and workplace emotion inference in the EU. Indian exporters whose products place AI systems on the EU market or affect EU users are within extraterritorial reach.
Chapter II of the Regulation on prohibited artificial intelligence practices applies from 2 February 2025.
EU AI Act general application 2-Aug-2026 , General application + Article 50 02 Aug 2026
Plain summary: The EU AI Act becomes generally applicable on 2 August 2026, including Article 50 transparency obligations (every chatbot must disclose AI, every synthetic content must be labelled). New prohibited practices around synthetic intimate content and CSAM apply from 2 December 2026. Annex III high-risk conformity obligations pushed to 2 December 2027 by the Digital Omnibus; Annex I product-embedded high-risk to 2 August 2028.
The Regulation shall apply from 2 August 2026, with the exceptions specified for prohibited practices (from 2 February 2025), GPAI provisions (from 2 August 2025), and high-risk AI system obligations (from 2 December 2027 for Annex III and 2 August 2028 for Annex I).

IndiaAI Mission Mar 2024 approval , Rs 10,371 cr five-year outlay 07 Mar 2024
Plain summary: The Union Cabinet approved the IndiaAI Mission on 7 March 2024 with an outlay of Rs 10,371 crore over five years. Seven pillars: IndiaAI Compute, Foundation Models, AIKosh, IndiaAI Application Development Initiative, FutureSkills, Startup Financing, Safe & Trusted AI. Safe & Trusted AI pillar funded 13 projects on deepfake and bias as of July 2026. IndiaAI Safety Institute announced January 2025 promotes responsible AI development, deployment and evaluation.
The IndiaAI Mission builds a comprehensive AI ecosystem with an outlay of Rs 10,371.92 crore over five years, structured across seven pillars including Safe and Trusted AI.

ISO 31000:2018 Risk management , General risk management guidance 15 Feb 2018
Plain summary: ISO 31000:2018 provides guidelines on managing risk faced by organisations. ISO/IEC 23894:2023 explicitly builds on 31000 for AI-specific risk management. Understanding 31000's core process (establishing context, risk assessment split into identification-analysis-evaluation, risk treatment, monitoring and review, communication and consultation) is helpful background for the AI methodology.
This document provides guidelines on managing risk faced by organizations. The application of these guidelines can be customized to any organization and its context. This document provides a common approach to managing any type of risk and is not industry or sector specific.

ISO/IEC 22989:2022 AI terminology , AI concepts and terminology 26 Jul 2022
Plain summary: ISO/IEC 22989:2022 defines AI concepts and terminology. Non-normative reference used across the ISO/IEC 42001 family. Sets the meaning of terms like AI system, machine learning, training data, model, that Clauses across 42001 assume.
This document establishes terminology for AI and describes concepts in the field of AI.

ISO/IEC 23053:2022 ML framework , Framework for AI using ML 13 Jun 2022
Plain summary: ISO/IEC 23053:2022 provides a framework for describing AI systems using machine learning. Reference architecture. Non-normative. Useful for AIIA and AIMS scope work when the organisation needs to describe what the AI system actually does at a functional level for the auditor.
This document establishes an AI and Machine Learning (ML) framework for describing a generic AI system using ML technology. The framework describes the system components and their functions in the AI ecosystem.

ISO/IEC 23894:2023 AI risk management , Guidance on AI risk management 06 Feb 2023
Plain summary: ISO/IEC 23894:2023 provides guidance on how organisations that develop, produce, deploy or use AI systems can manage AI-related risks. Non-certifiable companion to ISO 42001. Builds on ISO 31000:2018 risk management framework but adapts it for AI-specific risk sources: data quality, model bias, opacity, robustness, adversarial manipulation, autonomy and human oversight. Referenced by ISO 42001 Clause 6.1.2 as the guidance an auditor expects a risk methodology to follow.
This document provides guidance on how organizations that develop, produce, deploy or use products, systems and services that utilize artificial intelligence can manage risks specifically related to AI. The guidance also aims to assist organizations to integrate risk management into their AI-related activities and functions.

Annex A A.10 Third-party customer relations , Group A.10 third-party 18 Dec 2023
Plain summary: Annex A group A.10 covers third-party and customer relationships. A.10.2 allocation of responsibilities, A.10.3 suppliers, A.10.4 customers. In a landscape where most Indian organisations use LLM APIs, cloud providers and specialist AI vendors, this group governs how AIMS responsibility is contractually allocated up and down the supply chain.
The organization shall ensure that its responsibilities and those of any third party relating to the AI system are clearly allocated.
Annex A A.10.3 Suppliers , Supplier controls 18 Dec 2023
Plain summary: Annex A control A.10.3 requires the organisation to ensure that AI suppliers understand the AI-specific expectations of the organisation and can meet them. In practice this is contractual — supplier contracts must express AI-specific SLAs, transparency, AIIA cooperation, and incident cooperation.
The organization shall ensure that its suppliers understand and act consistently with its AI-related principles, policies, requirements and expectations regarding AI systems.
Annex A A.10.4 Customers , Customer obligations 18 Dec 2023
Plain summary: Annex A control A.10.4 requires the organisation to ensure customers understand and act consistently with the AI-related principles when using AI systems supplied by the organisation. This is customer-facing terms, acceptable use policies, and channels for customer concerns about AI use.
The organization shall ensure that customers understand and can act consistently with the AI-related principles, policies, requirements and expectations regarding AI systems.
Annex A A.2.2 AI Policy , AI policy documented 18 Dec 2023
Plain summary: Annex A control A.2.2 requires the organisation to document, review, communicate and enforce an AI policy that expresses management commitment to responsible AI, aligns with the organisational context and other policies, and is available to relevant interested parties. This is not the same as Clause 5.2 which requires a policy in principle. A.2.2 controls what has to be inside that policy.
The organization shall document a policy for the development or use of AI systems. This policy shall be aligned with other organizational policies, take into account the objectives of the organization and its interested parties, and be reviewed at planned intervals.
Annex A A.2.3 Alignment with other policies , Policy alignment 18 Dec 2023
Plain summary: Annex A control A.2.3 requires the organisation to align the AI policy with other organisational policies (information security, privacy, quality, HR, procurement) so contradictions are avoided. In an integrated management system where ISO 27001 is already in place, this control is the operational anchor for keeping ISMS and AIMS policies consistent.
The organization shall ensure that the AI policy is aligned with other relevant organizational policies.
Annex A A.2.4 Review of AI policy , Policy review at intervals 18 Dec 2023
Plain summary: Annex A control A.2.4 requires the organisation to review the AI policy at planned intervals or when significant changes occur to ensure its continuing suitability, adequacy and effectiveness. Review outputs must be documented. Typical cadence: annually plus on any material change to context, regulation, or the AI systems in scope.
The AI policy shall be reviewed at planned intervals or if significant changes occur to ensure its continuing suitability, adequacy and effectiveness.
Annex A A.3.2 AI roles , AI roles and responsibilities 18 Dec 2023
Plain summary: Annex A control A.3.2 requires the organisation to document AI roles and responsibilities across the AI lifecycle. This complements Clause 5.3 but goes further, requiring role-level clarity for AI development, deployment, operation, monitoring and decommissioning. In practice, this is a RACI matrix at role granularity, not just at department granularity.
AI roles and responsibilities shall be defined and allocated according to the needs of the organization.
Annex A A.3.3 Reporting of concerns , Concerns reporting channel 18 Dec 2023
Plain summary: Annex A control A.3.3 requires the organisation to define a process for reporting concerns about AI systems. Concerns can come from internal staff (an engineer noticing a fairness issue) or external interested parties (an affected individual raising harm). The channel must be documented, accessible, and integrated with the incident and nonconformity processes. Auditors will test whether the channel exists on paper AND is used in practice.
The organization shall define and put in place a process for reporting concerns about the AI systems developed, provided or used by the organization.
Annex A A.4 Resources for AI systems , Group A.4 resources 18 Dec 2023
Plain summary: Annex A group A.4 covers five controls on resources for AI systems: A.4.2 data resources, A.4.3 tooling resources, A.4.4 system and computing resources, A.4.5 human resources, A.4.6 financial resources. Each requires the organisation to document what resources are used, how they are selected, how they are governed and how they are retired.
The organization shall document information about the resources of the AI system including data resources, tooling resources, system and computing resources, human resources, and financial resources.
Annex A A.4.2 Data resources , Data resources 18 Dec 2023
Plain summary: Annex A control A.4.2 requires the organisation to document information about data resources utilised for the AI system, including sources, ownership, licensing, quality and lineage. Feeds into A.7 Data controls which go deeper.
The organization shall document information about data resources utilized for the AI system.
Annex A A.4.3 Tooling resources , Tooling resources 18 Dec 2023
Plain summary: Annex A control A.4.3 requires the organisation to document tooling resources used for AI system development, deployment and operation, including third-party libraries, model registries, MLOps platforms, fairness testing tools and vendor selection rationale.
The organization shall document information about the tooling resources utilized for the AI system.
Annex A A.4.4 System computing resources , Compute resources 18 Dec 2023
Plain summary: Annex A control A.4.4 requires the organisation to document system and computing resources used, including cloud providers, on-premise infrastructure, GPU/TPU allocation, capacity planning and disaster recovery arrangements. For India this typically overlaps with CERT-In Directions on log retention and cross-border data location.
The organization shall document information about the system and computing resources utilized for the AI system.
Annex A A.4.5 Human resources , Human resources for AI 18 Dec 2023
Plain summary: Annex A control A.4.5 requires the organisation to document human resources utilised for the AI system including roles, competences (feeds Clause 7.2), and third-party human contributors (crowd labellers, red-teamers, expert reviewers).
The organization shall document information about the human resources utilized for the AI system.
Annex A A.4.6 Financial resources , Financial resources 18 Dec 2023
Plain summary: Annex A control A.4.6 requires the organisation to document financial resources allocated to the AI system across its lifecycle, including development budget, operating cost, third-party licensing and reserved contingency for AI-specific incidents or model retraining.
The organization shall document information about the financial resources utilized for the AI system.
Annex A A.5.2 AI Impact Assessment , AIIA process required 18 Dec 2023
Plain summary: Annex A control A.5.2 requires the organisation to establish a process for assessing the impact of AI systems on individuals, groups and societies. Impact must cover both intended and reasonably foreseeable unintended use. This is the AI Impact Assessment (AIIA). ISO/IEC 42005:2025 is the companion standard providing methodology.
The organization shall establish a process to assess the potential consequences to individuals, groups of individuals, and societies that can result from the development or use of AI systems throughout their life cycle.
Annex A A.5.3 AIIA documentation , AIIA documented per system 18 Dec 2023
Plain summary: Annex A control A.5.3 requires the organisation to document the AI system impact assessment for each AI system in scope. Documentation must include the methodology, the assessment results, mitigations, residual impact and review triggers. Feeds Clause 8.4 execution.
The organization shall document the results of the AI system impact assessment.
Annex A A.5.4 Impact on individuals groups , Impact on individuals and groups 18 Dec 2023
Plain summary: Annex A control A.5.4 requires the AIIA to explicitly consider impact on individuals and groups of individuals. This includes fairness across demographic groups, effect on vulnerable populations, and effect on those who are subject to the AI system's decisions without opting in (loan applicants, hiring candidates, insurance policyholders).
The AI system impact assessment shall consider potential impact of the AI system on individuals or groups of individuals.
Annex A A.5.5 Impact on societies , Impact on societies 18 Dec 2023
Plain summary: Annex A control A.5.5 requires the AIIA to explicitly consider impact on societies at large. This includes environmental impact, informational impact (misinformation, deepfakes — reads directly onto IT Amendment Rules 2026 SGI obligations), impact on labour markets, and impact on public discourse.
The AI system impact assessment shall consider potential impact on societies.
Annex A A.6 AI system life cycle , Group A.6 AI lifecycle 18 Dec 2023
Plain summary: Annex A group A.6 covers AI system lifecycle management. A.6.1 requires objectives for responsible AI system development. A.6.2 sub-controls cover the lifecycle stages: A.6.2.2 processes for responsible design and development, A.6.2.3 AI system requirements and specifications, A.6.2.4 documentation of AI system design and development, A.6.2.5 AI system verification and validation, A.6.2.6 AI system deployment, A.6.2.7 AI system operation and monitoring, A.6.2.8 AI system technical documentation, A.6.2.9 AI system event logs. Together these implement the AI lifecycle from requirements to decommissioning.
The organization shall define and document specific objectives to guide the development of the AI system throughout the life cycle.
Annex A A.6.2.5 V and V , Verification and validation 18 Dec 2023
Plain summary: Annex A control A.6.2.5 requires the organisation to define and implement verification and validation measures for the AI system and specify criteria to be met. V and V is where fairness testing, robustness testing, adversarial testing, and acceptance testing live. This is the most audit-tested lifecycle control for ML systems.
The organization shall define and implement verification and validation measures for the AI system and specify criteria to be met.
Annex A A.6.2.7 Operation and monitoring , Operation and monitoring 18 Dec 2023
Plain summary: Annex A control A.6.2.7 requires the organisation to define and document processes and criteria for the operation and monitoring of the AI system. Includes performance drift, fairness drift, incident detection, human oversight cadence and rollback triggers.
The organization shall define and document the necessary processes and criteria for the operation and monitoring of the AI system.
Annex A A.6.2.9 AI system event logs , AI system event logs 18 Dec 2023
Plain summary: Annex A control A.6.2.9 requires the organisation to determine at which phases event logs are automatically generated and be able to analyse them. For an Indian AIMS this control also serves the CERT-In Direction 6-hour reporting timeline where an AI-related cyber incident happens.
The organization shall determine at which phases of the AI system life cycle event logs are automatically generated and be able to analyse them.
Annex A A.7 Data for AI systems , Group A.7 data 18 Dec 2023
Plain summary: Annex A group A.7 covers data for AI systems. A.7.2 data for development and enhancement, A.7.3 acquisition of data, A.7.4 quality of data, A.7.5 data provenance, A.7.6 data preparation. Under Indian DPDP Act 2023, any personal data flowing through these controls triggers additional DPDP obligations layered on top of A.7.
The organization shall define and document its data management processes related to the development or use of the AI system across the AI system life cycle.
Annex A A.7.4 Quality of data , Data quality for AI 18 Dec 2023
Plain summary: Annex A control A.7.4 requires the organisation to define and document requirements for data quality and ensure that data used to develop and operate the AI system meets these requirements. Auditors test whether data quality standards are actually enforced with sampling and rejection criteria.
The organization shall define and document requirements for data quality and ensure that data used to develop and operate the AI system meets these requirements.
Annex A A.7.5 Data provenance , Data provenance 18 Dec 2023
Plain summary: Annex A control A.7.5 requires the organisation to define and document a process for recording the provenance of data used in an AI system. Provenance covers origin, licensing, transformations applied, and chain of custody. Critical for LLM fine-tuning and for defending against copyright and DPDP claims.
The organization shall define and document a process for recording the provenance of data used for the AI system.
Annex A A.8 Information for interested parties , Group A.8 information 18 Dec 2023
Plain summary: Annex A group A.8 covers information for interested parties. A.8.2 system documentation and information for users, A.8.3 external reporting, A.8.4 communication of incidents, A.8.5 information for interested parties. Reads directly onto IT Amendment Rules 2026 SGI labelling obligations and DPDP Section 8 notice obligations for AI systems processing personal data.
The organization shall determine and provide the necessary information for AI system users and other interested parties.
Annex A A.8.2 System documentation for users , System doc for users 18 Dec 2023
Plain summary: Annex A control A.8.2 requires the organisation to determine and provide system documentation and information necessary for users of the AI system. Includes what the system does, how it should be used, known limitations, and how to interpret outputs.
The organization shall determine and provide the necessary information for users of the AI system.
Annex A A.9 Use of AI systems , Group A.9 use 18 Dec 2023
Plain summary: Annex A group A.9 covers responsible use of AI systems. A.9.2 processes for responsible use, A.9.3 objectives for responsible use, A.9.4 intended use of AI systems. Ensures the AI system is used only within its intended scope, with human oversight where required.
The organization shall define and document processes for the responsible use of the AI system.
Annex A A.9.2 Processes for responsible use , Responsible use processes 18 Dec 2023
Plain summary: Annex A control A.9.2 requires the organisation to define and document processes for the responsible use of the AI system. Includes access control to sensitive AI features, appropriate use policies, and rollback procedures when misuse is detected.
The organization shall define and document processes for the responsible use of the AI system.
Annex B.4.1 Guidance context of org , Annex B guidance on Clause 4 18 Dec 2023
Plain summary: Annex B.4.1 of ISO/IEC 42001:2023 provides implementation guidance for Clause 4 on organisational context. Guidance points expressly to regulatory environment, ethics, societal impact, technological dependencies and organisational culture as inputs the AIMS context analysis should cover. Non-normative but auditors read evidence expecting shape derived from Annex B.
The organization should determine the external and internal issues that affect its ability to achieve the intended outcomes of its AI management system. External issues can include regulatory environment, ethics, societal impact, and technological dependencies.
Clause 10.1 Continual improvement , AIMS continual improvement 18 Dec 2023
Plain summary: Clause 10.1 requires the organisation to continually improve the suitability, adequacy and effectiveness of the AIMS. Not a one-time achievement — a state of ongoing improvement measured across the certification cycle. Auditors like to see year-over-year metrics.
The organization shall continually improve the suitability, adequacy and effectiveness of the AI management system.
Clause 10.2 Nonconformity and CAPA , Handling nonconformities 18 Dec 2023
Plain summary: Clause 10.2 requires the organisation, when a nonconformity occurs, to react by controlling and correcting it and dealing with the consequences, evaluate the need for action to eliminate the causes so that it does not recur or occur elsewhere, implement any action needed, review the effectiveness of any corrective action taken, and make changes to the AIMS if necessary. Documented information as evidence of the nature of nonconformity and any subsequent actions must be retained.
When a nonconformity occurs, the organization shall: a) react to the nonconformity, and as applicable: 1) take action to control and correct it; 2) deal with the consequences; b) evaluate the need for action to eliminate the cause(s) of the nonconformity, in order that it does not recur or occur elsewhere.
Clause 4.1 Understanding the organisation , Internal and external issues for AIMS 18 Dec 2023
Plain summary: Clause 4.1 requires the organisation to determine internal and external issues relevant to its purpose and that affect its ability to achieve the intended outcomes of its AIMS. For AI, external issues explicitly include the societal and ethical context of AI use, not only market context. Annex B guidance points toward regulatory environment, ethics, societal impact and technology dependencies as expected inputs.
The organization shall determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcome(s) of its AI management system.
Clause 4.2 Interested parties , Interested parties for AIMS 18 Dec 2023
Plain summary: Clause 4.2 requires the organisation to determine interested parties relevant to the AIMS, their requirements, and which of those requirements will be addressed. For AI, interested parties expressly include affected individuals and groups who are not customers — a broader stakeholder map than ISO 27001, and one that maps directly to the India AI Governance Guidelines People-first sutra.
The organization shall determine: a) interested parties that are relevant to the AI management system; b) the relevant requirements of these interested parties; c) which of these requirements will be addressed through the AI management system.
Clause 4.3 Scope of the AIMS , AIMS scope statement 18 Dec 2023
Plain summary: Clause 4.3 requires the organisation to determine the boundaries and applicability of the AIMS to establish its scope. The scope shall be documented and available. For AI, the scope statement must specifically identify the AI systems in scope which is significantly harder than an ISMS scope because AI capabilities are often embedded in wider products rather than run as separate systems.
The organization shall determine the boundaries and applicability of the AI management system to establish its scope. The scope shall be available as documented information.
Clause 5.1 Leadership and commitment , Top management commitment 18 Dec 2023
Plain summary: Clause 5.1 requires top management to demonstrate leadership and commitment with respect to the AIMS. Ten specific commitments are listed including ensuring the AI policy and AI objectives are established, ensuring integration of AIMS requirements into organisational processes, ensuring resources, communicating importance of the AIMS and supporting relevant management roles. This is the clause where an auditor tests whether the AIMS has real executive backing or is a paper project.
Top management shall demonstrate leadership and commitment with respect to the AI management system by: a) ensuring the AI policy and AI objectives are established and are compatible with the strategic direction of the organization; b) ensuring the integration of the AI management system requirements into the organization's processes; c) ensuring that the resources needed for the AI management system are available; d) communicating the importance of effective AI management and of conforming to the AI management system requirements.
Clause 5.2 AI policy , AI policy requirements 18 Dec 2023
Plain summary: Clause 5.2 requires top management to establish an AI policy that is appropriate to the purpose of the organisation, provides a framework for setting AI objectives, includes a commitment to satisfy applicable requirements, and includes a commitment to continual improvement of the AIMS. The policy must be documented, communicated and available to interested parties as appropriate. Annex A.2.2 controls what must be inside the policy.
Top management shall establish an AI policy that: a) is appropriate to the purpose of the organization; b) provides a framework for setting AI objectives; c) includes a commitment to satisfy applicable requirements; d) includes a commitment to continual improvement of the AI management system.
Clause 5.3 Roles responsibilities auth , AI roles and authorities 18 Dec 2023
Plain summary: Clause 5.3 requires top management to ensure that responsibilities and authorities for roles relevant to the AIMS are assigned and communicated. Two specific assignments must be documented: ensuring the AIMS conforms to the standard, and reporting on AIMS performance to top management. Annex A.3.2 and A.3.3 add operational controls: AI roles and responsibilities, and the reporting-of-concerns channel.
Top management shall ensure that the responsibilities and authorities for roles relevant to the AI management system are assigned and communicated within the organization. Top management shall assign the responsibility and authority for: a) ensuring that the AI management system conforms to the requirements of this document; b) reporting on the performance of the AI management system to top management.
Clause 6.1.1 Actions to address risk , Risks and opportunities 18 Dec 2023
Plain summary: Clause 6.1.1 requires the organisation to determine risks and opportunities that need to be addressed to give assurance the AIMS can achieve its intended outcomes, to prevent or reduce undesired effects, and to achieve continual improvement. This is the umbrella clause under which the AI risk assessment (6.1.2) and risk treatment (6.1.3) run.
When planning for the AI management system, the organization shall consider the issues referred to in 4.1 and the requirements referred to in 4.2 and determine the risks and opportunities that need to be addressed to: a) give assurance that the AI management system can achieve its intended outcome(s); b) prevent or reduce undesired effects; c) achieve continual improvement.
Clause 6.1.2 AI risk assessment , AI risk assessment process 18 Dec 2023
Plain summary: Clause 6.1.2 requires the organisation to define and apply an AI risk assessment process that establishes and maintains AI risk criteria, ensures repeated AI risk assessments produce consistent valid and comparable results, identifies risks associated with achievement of AI objectives, analyses AI risks, and evaluates AI risks against risk criteria. ISO/IEC 23894:2023 provides the operational guidance.
The organization shall define and apply an AI risk assessment process that: a) establishes and maintains AI risk criteria; b) ensures that repeated AI risk assessments produce consistent, valid and comparable results; c) identifies the AI risks associated with the achievement of AI objectives; d) analyses the AI risks; e) evaluates the AI risks.
Clause 6.1.3 AI risk treatment , Risk treatment and SoA 18 Dec 2023
Plain summary: Clause 6.1.3 requires the organisation to define and apply an AI risk treatment process to select appropriate risk treatment options, determine the controls necessary to implement the chosen options, compare the controls with those in Annex A, and produce a Statement of Applicability containing all necessary controls and justification for inclusions and exclusions. The SoA is the single most-audited artefact.
The organization shall define and apply an AI risk treatment process to: a) select appropriate AI risk treatment options; b) determine all controls that are necessary to implement the AI risk treatment options; c) compare the controls determined in b) above with those in Annex A; d) produce a Statement of Applicability that contains: 1) the necessary controls and justification for their inclusion; 2) whether the necessary controls are implemented; and 3) the justification for excluding any of the Annex A controls.
Clause 6.1.4 AI system impact assessment , AIIA as a planning input 18 Dec 2023
Plain summary: Clause 6.1.4 requires the organisation to define and apply an AI system impact assessment process that addresses the impacts of the AI system on individuals, groups of individuals, and societies. This is the first time AIIA appears in the normative text — it also reappears in Annex A.5.2 as a control. The clause treats AIIA as a planning-stage input, not only an operational control.
The organization shall define and apply a process for AI system impact assessment as described in 8.4.
Clause 6.2 AI objectives and planning , AI objectives 18 Dec 2023
Plain summary: Clause 6.2 requires the organisation to establish AI objectives at relevant functions and levels. Objectives must be consistent with the AI policy, measurable where practicable, take into account applicable requirements and results of AI risk assessment and AI impact assessment, be monitored, communicated and updated as appropriate. Nine specific attributes are listed for planning how to achieve AI objectives (what will be done, resources, responsibility, timeline, evaluation).
The organization shall establish AI objectives at relevant functions and levels. The AI objectives shall: a) be consistent with the AI policy; b) be measurable (if practicable); c) take into account applicable requirements; d) take into account the results of AI risk assessment and AI system impact assessment; e) be monitored; f) be communicated; g) be updated as appropriate; h) be available as documented information.
Clause 6.3 Planning of changes , Change control 18 Dec 2023
Plain summary: Clause 6.3 requires that when the organisation determines the need for changes to the AIMS, the changes shall be carried out in a planned manner. This mirrors ISO 27001:2022 Clause 6.3. In the AIMS context, it applies to changes to policy, methodology, objectives, controls, roles, and — importantly — changes to AI systems in scope which trigger AIIA re-assessment.
When the organization determines the need for changes to the AI management system, the changes shall be carried out in a planned manner.
Clause 7.1 Resources , Resources for the AIMS 18 Dec 2023
Plain summary: Clause 7.1 requires the organisation to determine and provide the resources needed for the establishment, implementation, maintenance and continual improvement of the AIMS. Resources cover people, tools, budget, data, compute and time.
The organization shall determine and provide the resources needed for the establishment, implementation, maintenance and continual improvement of the AI management system.
Clause 7.2 Competence , Competence requirements 18 Dec 2023
Plain summary: Clause 7.2 requires the organisation to determine the necessary competence of persons doing work under its control that affects the AIMS performance, ensure those persons are competent on the basis of appropriate education training or experience, take actions to acquire competence where needed, and retain documented information as evidence.
The organization shall: a) determine the necessary competence of person(s) doing work under its control that affects the performance of the AI management system; b) ensure that these persons are competent on the basis of appropriate education, training or experience; c) where applicable, take actions to acquire the necessary competence and evaluate the effectiveness of the actions taken; d) retain appropriate documented information as evidence of competence.
Clause 7.3 Awareness , AIMS awareness 18 Dec 2023
Plain summary: Clause 7.3 requires persons doing work under the organisations control to be aware of the AI policy, their contribution to AIMS effectiveness, benefits of improved AIMS performance, and implications of not conforming to AIMS requirements.
Persons doing work under the organization's control shall be aware of: a) the AI policy; b) their contribution to the effectiveness of the AI management system, including the benefits of improved AI management system performance; c) the implications of not conforming with the AI management system requirements.
Clause 7.4 Communication , Internal and external communication 18 Dec 2023
Plain summary: Clause 7.4 requires the organisation to determine internal and external communications relevant to the AIMS, including on what to communicate, when, with whom, how and by whom. For an AIMS this includes AI incident notifications, transparency reporting to interested parties, and internal coordination between AI teams, ethics, security and DPO.
The organization shall determine the internal and external communications relevant to the AI management system, including: a) on what it will communicate; b) when to communicate; c) with whom to communicate; d) how to communicate; e) who will communicate.
Clause 7.5 Documented information , What must be documented 18 Dec 2023
Plain summary: Clause 7.5 specifies the documented information the AIMS must include. Mandatory documented information across ISO 42001 includes: AIMS scope (4.3), AI policy (5.2), AI risk assessment process and results (6.1.2), AI risk treatment process and Statement of Applicability (6.1.3), AIIA process and results (6.1.4 + Annex A.5), AI objectives (6.2), competence evidence (7.2), operational planning and control evidence (8.1), monitoring and measurement results (9.1), internal audit programme and results (9.2), management review results (9.3), nonconformity and corrective action (10.1). Additional records the organisation determines necessary.
The organization's AI management system shall include: a) documented information required by this document; b) documented information determined by the organization as being necessary for the effectiveness of the AI management system.
Clause 8.1 Operational planning control , Operational execution 18 Dec 2023
Plain summary: Clause 8.1 requires the organisation to plan, implement and control the processes needed to meet AIMS requirements and to implement the actions determined in Clause 6. This is the operational execution of the planning done under Clauses 6.1, 6.2 and 6.3. Includes control of planned changes, review of unintended changes, mitigation of adverse effects, and control of externally-provided processes.
The organization shall plan, implement and control the processes needed to meet AI management system requirements, and to implement the actions determined in Clause 6, by: a) establishing criteria for the processes; b) implementing control of the processes in accordance with the criteria.
Clause 8.2 AI risk assessment execution , Executing the risk assessment 18 Dec 2023
Plain summary: Clause 8.2 requires the organisation to perform AI risk assessments at planned intervals and when significant changes are proposed or occur, taking into account the criteria established in Clause 6.1.2. Documented information of the results shall be retained.
The organization shall perform AI risk assessments at planned intervals or when significant changes are proposed or occur, taking account of the criteria established in 6.1.2. The organization shall retain documented information of the results of the AI risk assessments.
Clause 8.3 AI risk treatment execution , Executing risk treatment 18 Dec 2023
Plain summary: Clause 8.3 requires the organisation to implement the AI risk treatment plan and retain documented information of the results. This is where SoA controls actually get built and operated. Auditors sample the SoA rows marked as "implemented" and test whether they really are.
The organization shall implement the AI risk treatment plan. The organization shall retain documented information of the results of the AI risk treatment.
Clause 8.4 AI system impact assessment op , AIIA operational execution 18 Dec 2023
Plain summary: Clause 8.4 requires the organisation to perform AI system impact assessments in accordance with the process established under 6.1.4, at planned intervals or when significant changes are proposed or occur, and retain documented information of the results. AIIA runs per AI system, not organisation-wide. ISO/IEC 42005:2025 provides methodology.
The organization shall perform AI system impact assessments in accordance with the process established under 6.1.4 at planned intervals or when significant changes are proposed or occur.
Clause 9.1 Monitoring measurement analysis , AIMS performance measurement 18 Dec 2023
Plain summary: Clause 9.1 requires the organisation to determine what needs to be monitored and measured, methods for monitoring measurement analysis and evaluation, when monitoring shall be performed, when results shall be analysed and evaluated. Documented information as evidence of results shall be retained. For AIMS, monitoring covers AI system performance (accuracy, fairness, drift), AIMS process performance (AIIA completion, risk assessment cadence), and outcomes (incidents, concerns raised).
The organization shall determine: a) what needs to be monitored and measured; b) the methods for monitoring, measurement, analysis and evaluation, as applicable, to ensure valid results; c) when the monitoring and measuring shall be performed; d) when the results from monitoring and measurement shall be analyzed and evaluated.
Clause 9.2 Internal audit , Internal audit programme 18 Dec 2023
Plain summary: Clause 9.2 requires the organisation to conduct internal audits at planned intervals to provide information on whether the AIMS conforms to organisational requirements and the standard, and is effectively implemented and maintained. Requires a documented internal audit programme covering frequency, methods, responsibilities, planning requirements and reporting. Selected auditors must be objective and impartial — cannot audit their own work.
The organization shall conduct internal audits at planned intervals to provide information on whether the AI management system: a) conforms to the organization's own requirements for its AI management system and the requirements of this document; b) is effectively implemented and maintained.
Clause 9.3 Management review , Management review inputs and outputs 18 Dec 2023
Plain summary: Clause 9.3 requires top management to review the AIMS at planned intervals. Mandatory inputs include status of previous review actions, changes in external and internal issues, feedback on AIMS performance including nonconformities, corrective actions, monitoring and measurement results, audit results, fulfilment of AI objectives, information from interested parties, results of risk assessment and status of risk treatment plan, opportunities for continual improvement. Mandatory outputs include decisions on continual improvement and any need for changes.
Top management shall review the organization's AI management system, at planned intervals, to ensure its continuing suitability, adequacy and effectiveness.
ISO/IEC 42001:2023 (Dec 2023 first edition) , AI management systems Requirements 18 Dec 2023
Plain summary: ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system. First edition published 18 December 2023 by ISO/IEC JTC 1/SC 42 (AI subcommittee). The worlds first international management-system standard specifically for artificial intelligence. Structure: ten main clauses (0 Introduction through 10 Improvement) following the Annex SL harmonised structure shared with ISO 27001 and ISO 9001, plus Annex A (38 controls across 9 control groups A.2 through A.10), Annex B (implementation guidance for Annex A controls), Annex C (potential AI-related organisational objectives and risk sources), and Annex D (using an AIMS in specific domains).
This document specifies the requirements and provides guidance for establishing, implementing, maintaining and continually improving an AI management system within the context of an organization. It is intended for use by an organization providing or using products or services that utilize AI systems.

ISO/IEC 42005:2025 AI impact assessment , AI system impact assessment 01 Jun 2025
Plain summary: ISO/IEC 42005:2025 provides guidance on conducting an AI system impact assessment (AIIA). Companion to ISO 42001 Annex A control A.5.2. Methodology covers stakeholder identification, impact identification across fairness, safety, transparency, privacy, security, human oversight, environmental impact and society-level impact; scoring; documentation; and lifecycle re-assessment.
This document provides guidance for organizations performing artificial intelligence system impact assessments for individuals and societies that can be affected by an AI system and its intended and foreseeable applications throughout its lifecycle.

IT Rules Amendment 2026 SGI , SGI due-diligence obligations 10 Feb 2026
Plain summary: The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026 were notified on 10 February 2026 and became effective 20 February 2026. Rule 3(1)(v) introduces Synthetically Generated Information (SGI) as a due-diligence category. Non-prohibited AI-generated content must be clearly and prominently labelled (visual for visual, audio for audio). Metadata must be embedded to trace the computer resource where feasible. Takedown timelines for harmful content reduced from 24-36 hours to 2-3 hours.
The 2026 amendment brings synthetically generated information within platform due-diligence obligations for the first time. Intermediaries must clearly and prominently label AI-generated content, embed permanent metadata identifiers where feasible, and comply with expedited takedown timelines.

MeitY AI Advisory 15-Mar-2024 , AI content labelling advisory 15 Mar 2024
Plain summary: MeitY issued an advisory in March 2024 emphasising the importance of labelling AI-generated content, particularly deepfake-prone content. The earlier requirement for platforms to seek government approval for AI models was revoked in the same advisory. Superseded on labelling by the IT Amendment Rules 2026 which convert the advisory into binding due-diligence obligations.
Platforms and intermediaries should ensure that AI-generated content is labelled to inform users that the content is generated using AI, particularly content susceptible to misuse as deepfakes.

India AI Governance Guidelines Nov 2025 , Seven sutras + six pillars 05 Nov 2025
Plain summary: MeitY released the India AI Governance Guidelines in November 2025. Techno-legal principle-driven approach anchored by seven sutras: Trust, People-first governance, Innovation over restraint, Fairness and equity, Accountability, Understandability by design, Safety-resilience-sustainability. Six pillars: Infrastructure, Capacity building, Policy and regulation, Risk mitigation, Accountability, Institutions. Non-binding but reflects governmental direction. Annexure 6 recommends ISO/IEC 42001 as the operational management-system standard for organisations.
The Guidelines adopt a techno-legal, principle-driven approach anchored in seven guiding sutras: Trust; People-first governance; Innovation over restraint; Fairness and equity; Accountability; Understandability by design; and Safety, resilience, and sustainability.

NIST AI RMF 1.0 four functions , Govern Map Measure Manage 26 Jan 2023
Plain summary: NIST AI Risk Management Framework Version 1.0 published 26 January 2023. Voluntary. Four core functions: GOVERN (cultivates a culture of AI risk management), MAP (establishes context for risks related to each AI system), MEASURE (quantitative and qualitative analysis), MANAGE (risk resources, treatments, incident response). GOVERN applies at all stages of MAP MEASURE MANAGE. Official crosswalk to ISO/IEC 42001 published by NIST AIRC maps 71 AI RMF requirements to corresponding ISO 42001 sections.
The AI RMF Core provides outcomes and actions that enable dialogue, understanding, and activities to manage AI risks and responsibly develop trustworthy AI systems. The Core is composed of four functions: GOVERN, MAP, MEASURE, and MANAGE.

Mphasis first Indian IT services ISO 42001 , Mphasis 2025 certification 15 Jun 2025
Plain summary: Mphasis became the first Indian IT services firm publicly known to hold ISO/IEC 42001:2023 certification. Widely covered in Indian IT trade press through 2025 as the beginning of an Indian IT services rush to certify. Public reference point when illustrating that certification of Indian services companies is operationally feasible today.
Mphasis was the first Indian IT services firm to hold ISO/IEC 42001 credentials, marking the beginning of a broader adoption trend across the Indian technology services sector.
KPMG India ISO 42001 by SGS Dec 2025 , KPMG India certification 15 Dec 2025
Plain summary: KPMG India obtained ISO/IEC 42001 certification from SGS in December 2025. Referenced in Indian trade press for illustrating the audit-firm-doing-its-own-certification recursion and the growing adoption of ISO 42001 across the Big Four in India.
KPMG India was certified against ISO/IEC 42001 by SGS in December 2025, becoming one of the first Big Four member firms in India to hold the credential.

RBI FREE-AI Report 13-Aug-2025 , Bhattacharyya Committee framework 13 Aug 2025
Plain summary: Report of the RBI Committee on FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) chaired by Professor Pushpak Bhattacharyya of IIT Bombay, released 13 August 2025. Seven guiding sutras and 26 recommendations across six pillars: Infrastructure, Policy, Capacity, Governance, Protection, Assurance. Non-binding today; sets RBI direction for future master directions applicable to banks, NBFCs, HFCs, AIFIs and payment system operators.
The Committee, constituted in December 2024, has been tasked with recommending a robust, comprehensive and adaptable AI framework for the financial sector, addressing IT outsourcing, technology risk, governance and controls, operational risks and resilience.

SEBI Advisory 5-May-2026 Mythos , AI vulnerability detection advisory 05 May 2026
Plain summary: SEBI Circular No. HO/13/19/12(1)2026-ITD-1_CIMGI/10873/2026 dated 5 May 2026 addressed to every regulated entity in the Indian securities market (exchanges, depositories, brokers, mutual funds, custodians, credit rating agencies, merchant bankers, portfolio managers, investment advisors). Response to advanced AI-driven vulnerability detection tools such as Mythos. Requires strengthened cybersecurity, immediate patch management, AI-assisted vulnerability assessments, enhanced API security, continuous SOC monitoring, system hardening and onboarding with the centralised Market SOC platform. Established the Cyber-suraksha.ai task force.
AI-driven vulnerability detection tools heighten risks for regulated entities by enabling rapid identification and possible exploitation of vulnerabilities, while also raising concerns around data confidentiality, application integrity, and reliability of outputs.

Found an error? We pay for it.

If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.

  • ₹1,000 credit for the first report of any verifiable factual error.
  • ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
  • Credit on your dcomply Academy account usable against any future course.

We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.

On this page
  • 🟢 Our verification promise
  • 📊 Course statistics
  • 📚 Full citation register
  • 🐛 Bug bounty for errors

Maintained by the dcomply Academy editorial team. Last reviewed recently.