As a prelude to the CIDA program on August 21,22 and 23, FDPPI will be conducting an introductory crash program on CEDPO to assist participants of CIDA program refresh the implementation aspects of DPDPA.
The program will be virtual and at 10.00 am.
For those who have not registered for CIDA, the same crash program would be made available at a fee of Rs 3000/- plus GST of Rs 540/-. Total Rs 3540/- They can register for this program here
This can be adjusted with the final registration fee for CIDA.
After payment kindly send a confirmation with email to naavi. If you are filling up the registration form indicate your physical address (for GST purpose) and proper email.
One of the most overlooked aspects of the EU AI Act is not its classification of AI systems into prohibited, high-risk or limited-risk categories. Nor is it the much-discussed governance framework or conformity assessment process. Its most profound contribution lies elsewhere—in recognizing that Artificial Intelligence is capable of affecting not merely privacy, but the entire spectrum of fundamental human rights.
This recognition has led the European Union to introduce the concept of a Fundamental Rights Impact Assessment (FRIA).
For India, which is embarking on its own journey of AI governance while implementing the Digital Personal Data Protection Act, 2023 (DPDPA), this development deserves careful attention.
The Limitations of Data Protection
The DPDPA is a law governing the processing of digital personal data. It protects informational privacy and regulates the relationship between Data Fiduciaries, Data Processors and Data Principals.
However, AI systems have the potential to cause harms that extend well beyond data protection.
Consider a few examples.
An AI-based recruitment tool may discriminate against women or older candidates without processing any sensitive personal data unlawfully.
An AI-driven credit scoring system may deny financial opportunities to deserving individuals because of biased models.
An AI-supported medical diagnosis may jeopardize patient safety.
A predictive policing algorithm may affect liberty and equality.
A generative AI system may influence freedom of speech, democratic discourse or access to information.
In each of these situations, privacy may not be the principal concern.
The affected rights could include equality, dignity, fairness, consumer protection, access to justice, education, employment and several other constitutional guarantees.
This is precisely why a conventional Data Protection Impact Assessment (DPIA) is no longer sufficient.
What is the Fundamental Rights Impact Assessment?
The EU AI Act requires deployers of specified high-risk AI systems to evaluate how the deployment of AI may affect the fundamental rights guaranteed under the Charter of Fundamental Rights of the European Union.
Unlike a DPIA, which concentrates on risks arising from processing personal data, the FRIA evaluates the possible impact on a broad set of rights such as:
Human dignity
Equality before law
Non-discrimination
Privacy
Protection of personal data
Freedom of expression
Freedom of thought
Rights of children
Rights of persons with disabilities
Consumer protection
Workers’ rights
Right to education
Freedom to conduct business
Access to justice
Healthcare
Effective legal remedies
The list extends to more than twenty fundamental rights that AI systems may directly or indirectly affect.
The philosophy behind the FRIA is simple:
Artificial Intelligence must be evaluated not merely for what it does with data, but for what it does to people.
This is perhaps one of the most important conceptual shifts in AI governance.
India’s Constitutional Foundation
India does not have an equivalent of the EU Charter.
However, the Indian Constitution already provides a rich framework of fundamental rights that can serve the same purpose.
Among the most relevant are:
Article 14 – Equality before law
Article 19 – Freedom of speech and expression
Article 21 – Protection of life and personal liberty, including the Right to Privacy recognised in the Justice K.S. Puttaswamy judgment
Constitutional guarantees against arbitrary State action
Principles of natural justice
Consumer rights recognised under statutory law
Labour protections
Rights of children
Rights of persons with disabilities
The constitutional philosophy is already available.
What is presently missing is a structured methodology to evaluate whether an AI system threatens these rights.
India Needs an Indian Fundamental Rights Impact Assessment
As AI becomes embedded in banking, healthcare, education, insurance, public administration and law enforcement, organizations should not limit themselves to asking:
“Is this AI system compliant with DPDPA?”
They must also ask:
Is the system fair?
Does it discriminate?
Does it reduce human autonomy?
Does it affect dignity?
Does it create barriers to justice?
Does it unfairly deny opportunities?
Does it threaten democratic values?
These questions belong outside the traditional DPIA.
They require a broader governance instrument.
India therefore needs an Indian Fundamental Rights Impact Assessment (IFRIA).
Integrating IFRIA with DGPSI-AI
The DGPSI-AI framework already adopts a governance-oriented approach instead of treating AI merely as a technological problem.
An expanded governance model could consist of four complementary assessments.
1. Data Protection Impact Assessment (DPIA) with a focus on :
Compliance with DPDPA
Personal data processing
Privacy risks
Consent and lawful processing
2. AI Risk Assessment (AIRA) with a focus on:
Model reliability
Bias
Hallucinations
Security
Robustness
Operational risks
3. Indian Fundamental Rights Impact Assessment (IFRIA) with a focus on :
Equality
Fairness
Human dignity
Constitutional rights
Consumer interests
Employee rights
Public interest
4. Algorithmic Accountability Assessment with a focus on :
Explainability
Transparency
Auditability
Human oversight
Traceability
Governance effectiveness
Together, these four assessments would provide a comprehensive governance architecture that is significantly broader than current compliance approaches.
Moving Beyond Compliance
Many organizations still perceive AI governance as another compliance exercise. That could be a mistake. Good governance is not merely about avoiding penalties. It is about earning trust.
AI systems influence employment, healthcare, finance, justice and democratic participation. Consequently, governance must protect not only data but also the constitutional values upon which society is built.
The EU has acknowledged this reality through the Fundamental Rights Impact Assessment.
India has the opportunity to adapt the same philosophy within its own constitutional framework rather than merely copying foreign regulations.
The Road Ahead
The next generation of AI governance in India should move beyond the traditional focus on privacy. Privacy remains an essential right. But it is only one among many rights that intelligent systems may affect.
As India develops its own AI governance ecosystem, the objective should be to protect human rights, not merely personal data. The DGPSI-AI, implementation specification no 9 supporting the Governance principle of “Ethics” states,
“The Deployer of an AI shall take all such measures that are essential to ensure that the AI does not harm the society at large…”
Under this provision, an Indian Fundamental Rights Impact Assessment could be considered as part of the best practice.
A structured Indian Fundamental Rights Impact Assessment (IFRIA), integrated with DGPSI-AI and the proposed AI Governance Standard of India (AIGSI), would represent a significant step in that direction.
The future of AI governance will not be determined solely by the sophistication of algorithms.
It will ultimately be judged by how effectively those algorithms preserve human dignity, constitutional freedoms and the rights of every individual whose life they influence.
The Reserve Bank of India (RBI) has recently placed three transformational compliance responsibilities before banks:
Compliance with the Digital Personal Data Protection Act, 2023 (DPDPA);
Compliance with the RBI Guidance on Artificial Intelligence; and
Compliance with the Draft Guidance on Data Governance.
Each of these is significant by itself. Together, they redefine the manner in which banks are expected to govern information, deploy technology and demonstrate regulatory accountability.
Among these, one provision in the Data Governance Guidance deserves closer examination.
The draft guidance expects Regulated Entities (REs) to obtain independent audits from CERT-In empanelled auditors. At first glance, this appears to be a logical choice since CERT-In has, for many years, maintained a respected panel of Information Security Auditors.
However, an important question arises.
Is a Data Governance Audit merely an Information Security Audit under a different name?
The answer is No.
The Difference Between Security Audit and Data Governance Audit
Traditional Information Security Audits have largely focused on technical controls designed to preserve the Confidentiality, Integrity and Availability (CIA) of information assets.
A Data Governance Audit, on the other hand, is expected to examine issues such as:
Data ownership and stewardship;
Data quality and the concept of a Single Source of Truth (SSOT);
Regulatory compliance under DPDPA;
AI governance and algorithmic accountability;
Data lifecycle management;
Ethical use of data;
Board oversight and governance structures;
Documentation, policies and accountability mechanisms;
Risk management and evidence of compliance.
Many of these areas lie outside the traditional domain of cyber security.
An auditor may be an outstanding network security expert and still have limited exposure to privacy law, data governance frameworks, AI risk management or regulatory accountability.
The RBI guidance therefore represents not merely a new audit assignment, but the emergence of an entirely new professional discipline.
India Needs Independent Data Auditors
For several years, FDPPI has maintained that India requires a separate profession of Independent Data Auditors (IDAs).
The DPDPA already envisages independent data audits for Significant Data Fiduciaries. RBI’s guidance now reinforces the need for auditors who possess multidisciplinary expertise spanning:
Law
Technology
Data Governance
Privacy
AI Governance
Information Security
Risk Management
Audit Methodology
No single traditional discipline is sufficient.
Accordingly, FDPPI has developed an ecosystem for Independent Data Auditors with structured capability development through:
Probationary Independent Data Auditor (PIDA)
Accredited Independent Data Auditor (AIDA)
Certified Independent Data Auditor (CIDA)
The objective is not to replace cyber security auditors but to complement them by building competencies that today’s regulatory environment demands.
Data Audit is More Than Technical Compliance
One misconception that deserves correction is the assumption that compliance can be demonstrated merely by examining technical controls.
DPDPA compliance involves legal interpretation.
AI governance involves evaluation of explainability, accountability, human oversight, fairness and risk management.
Data governance involves organisational processes, ownership structures, metadata management, data quality and regulatory accountability.
None of these can be adequately assessed through vulnerability assessments, penetration testing or infrastructure reviews alone.
Consequently, India needs professionals who understand the convergence of law, governance and technology.
Time to Expand the CERT-In Ecosystem
CERT-In has performed an invaluable role in creating and nurturing India’s cyber security audit ecosystem.
The next logical evolution would be to broaden this ecosystem to accommodate professionals specialising in Data Governance and Data Protection.
One possible approach would be to establish an additional empanelment category specifically for Independent Data Auditors possessing recognised qualifications in data governance, privacy and AI governance.
Another equally important step would be to encourage existing CERT-In empanelled auditors to acquire these additional competencies through structured certification programmes.
Such an approach would strengthen—not dilute—the existing CERT-In framework.
Academic Rigor Matters
Professional certification cannot rely solely on experience.
It requires structured learning, objective assessment and continuous professional development.
Recognising this, FDPPI has entered into a collaboration with MYRA School of Business, Mysuru, an AICTE-accredited institution, to strengthen the academic foundation of Independent Data Auditor certifications.
The Certified Independent Data Auditor (CIDA) programme combines practical regulatory understanding with formal evaluation, thereby providing reasonable assurance regarding the competency of certified professionals.
Building India’s Data Governance Capacity
India is entering an era where Data Governance will become as important as Cyber Security.
The success of DPDPA implementation, trustworthy AI deployment and RBI’s regulatory expectations will depend not merely on issuing guidelines but on creating an ecosystem of competent professionals capable of evaluating compliance objectively and independently.
The regulatory framework has already begun evolving.
Professional capability must evolve with equal speed.
The challenge before India is therefore not whether Data Governance Audits should be conducted, but whether we have enough professionals who can perform them with the required multidisciplinary competence.
That is the conversation the industry must begin today.
P.S:
FDPPI is conducting a three-day Certified Independent Data Auditor (CIDA) programme on 21–23 August 2026 at Fairfield by Marriott, Bengaluru. The programme covers DPDPA compliance, RBI’s AI Guidance, RBI’s Data Governance Guidance and the DGPSI framework for Data Governance and Protection. Professionals interested in developing expertise in this emerging discipline may visit www.aidai.org.in and www.naavi.org for further information.
Three different compliance requirements are confronting the Indian Banks right now. While most Banks were leisurely planning for DPDPA implementation, RBI unleashed the AI guideline first and before the next heart beat landed the Digital Governance requirement.
To rub salt to the wound, the Bank of Baroda data breach has also surfaced.
These developments have made it necessary for Banks to scramble around for quick action starting first with understanding these frameworks and later initiating the implementation.
Fortunately, there is one organization in India namely FDPPI that is ready to assist the Banks with its structured approach to compliance.
The DGPSI-Banks and DGPSI-Bank Branch were two frameworks that FDPPI had already introduced to meet the requirements of DPDPA compliance. Now the two other compliance requirements of AI and Data governance have also been incorporated into the Compliance training schedule.
let us first understand the challenge..before working on the implementation.
Request Bank Chairmen to start acting and in the next board meeting or earlier, start action to conduct a training program for the HO staff on how to address the requirements.
Call Naavi if required before it is too late since all Banks and REs will be scrambling for the scarce resources for training.