Live Founding Cohort open, limited seats remaining Back to main site →
Our Build Method

How we build a course that a practitioner can actually rely on.

Most compliance training in India is a repackaged summary of a summary. Every dcomply Academy course starts with the primary text of the law, gets written by hand, verified against the gazette, and rebuilt when the statute moves. This page walks through the five steps, what we refuse to do, and what happens when Parliament, the ministry, or the regulator changes the rules.

The five-step build

Every module of every course goes through the same sequence. No shortcuts, no drafts written from ChatGPT summaries of the law.

1

Primary source only

Before a single lesson is drafted, we list every applicable instrument: the parent Act, the notified Rules, ministry notifications, regulator circulars, technical clarifications, sectoral directions. We work from the gazette copy or the regulator's official upload. Secondary explainers, blog posts, and vendor whitepapers do not enter the outline.

CERT-In course source stack: IT Act 2000 s.70B, Directions dated 28 Apr 2022, FAQ dated 18 May 2022, extension dated 27 Jun 2022, Jan Vishwas Act 2023, DPDP Rules 2025 Rule 7, RBI and SEBI and IRDAI sectoral overlays. Twelve primary documents. Zero secondary summaries.
2

Rule-by-rule outline (citation anchoring)

Every lesson is mapped to a specific Section, Rule, Schedule paragraph, or circular clause before we write a word of it. If we cannot point to a location in the primary text that a claim comes from, the claim does not go into the lesson. This is what we mean when we say a course is citation-anchored.

Example lesson mapping: DPDP Rules 2025 Rule 8 (Notice of personal data breach) is taught across three lessons: what triggers the 72-hour clock, what the intimation to the Board must contain, and how the Data Fiduciary must notify affected Data Principals. Each lesson opens with the exact Rule text.
3

Human writing, no filler

Lessons are written by a person, not generated. The house style is direct practitioner prose: hyphens, commas, and periods only. No em-dashes. No opening phrases like "In today's digital landscape". No unnecessary bullet lists where a paragraph is clearer. If a section reads like it was produced by a chatbot, it gets rewritten before it ships.

What you will never find in a dcomply lesson: "In an ever-evolving regulatory environment", "leverage synergies", "embark on a journey", "unlock the power of", "at the end of the day". Every one of those phrases is on our stop-list.
4

Verify against the gazette

Every drafted lesson is walked through a manual verification checklist. A qualified reader (in-house counsel, subject matter attorney, or the course's named instructor) reads each claim, cross-checks the citation against the actual gazette text or regulator upload, and marks the lesson as verified. This is a database field with an audit trail, not a marketing badge.

Every published lesson carries verification_status = 'verified' and verified_by = a named person or institution. Lessons that fail verification are held back until the correction ships. You can inspect this on any course's Trust page.
5

Ship with a legal-basis version, and track amendments

Every course records the exact set of primary instruments it teaches to, and the date those instruments were current as of. When Parliament passes an amendment, the ministry notifies a Rule, or the regulator issues a fresh circular, the course is updated within seven days. Enrolled learners get an email flagging what changed and where in the course it landed.

CERT-In course legal_basis_version, current as of 10 Aug 2026: IT Act 2000 s.70B, Directions 28 Apr 2022, FAQ 18 May 2022, extension 27 Jun 2022, Jan Vishwas Act 2023, DPDP Rules 2025 (notified 14 Nov 2025), RBI Master Direction on IT Governance (7 Nov 2023), SEBI CSCRF Master Circular (20 Aug 2024 + 28 Aug 2025 clarifications), IRDAI Cyber Security Guidelines 2026, DoT Telecom Cybersecurity Rules 2024, UIDAI Aadhaar (Data Security) Regulations 2016.

What we refuse to do

A short list of things you will find in every other compliance course on the Indian market, and will not find in ours.

No generic "cybersecurity awareness" videos

Awareness content that could apply to a business anywhere in the world does not teach an Indian compliance officer how to comply with Indian law. Every lesson we ship is anchored to a specific Indian statute, rule, or regulator circular.

No uncited claims

If a lesson says "the fiduciary must notify within 72 hours", the citation is on the same page: Rule 8(1), DPDP Rules 2025. If we cannot point at the source, the sentence does not appear.

No rehashed DSCI or ISACA content

We do not adapt other people's syllabi. Each course is built from the primary instruments listed above by a named author or the dcomply cyber practice, from scratch.

No removed dates or hidden versions

Some vendors strip publication dates so old material feels evergreen. Every one of our courses shows its legal_basis_version, the date it was last verified, and when the next scheduled review is due.

Proof, not marketing copy

Every published course has a public Trust page. It shows the verbatim regulator quote behind every headline claim, the verification status of every lesson, and the exact instrument citations.

See a Trust page in the wild.

The DPDP Act course Trust page carries the verbatim text of the Sections and Rules it teaches to, the verifier's name, and the last-reviewed date. Every other course has the same page at the same URL pattern: /courses/{slug}/trust.

Open the DPDP Act Trust page →

Our commitments to a paying learner

If any of these break, you get a full refund and we take the course down until it is corrected.

  • Every lesson carries a verifiable citation to a primary Indian legal instrument. No secondary sources.
  • Every course is updated within seven days of a material amendment to the Acts, Rules, or regulator circulars it teaches to.
  • You will be emailed when your enrolled course is amended, with a summary of what changed and where.
  • The verification status of every lesson and the verifier's name are publicly visible on the course Trust page.
  • Certificates carry a public verification URL that resolves to the exact legal_basis_version the course taught when you completed it.
  • If a claim in a lesson turns out to be wrong, the lesson is patched inside 48 hours of the flag reaching us, and the correction is emailed to every enrolled learner.

Ready to see the method in a live course?

Every published dcomply Academy course is built the same way. Module 1 of each paid course is free to read without an account.

Browse the course catalog →