Do we require a Fundamental Rights Protection Assessment in AIGSI?

One of the most overlooked aspects of the EU AI Act is not its classification of AI systems into prohibited, high-risk or limited-risk categories. Nor is it the much-discussed governance framework or conformity assessment process. Its most profound contribution lies elsewhere—in recognizing that Artificial Intelligence is capable of affecting not merely privacy, but the entire spectrum of fundamental human rights.

This recognition has led the European Union to introduce the concept of a Fundamental Rights Impact Assessment (FRIA).

For India, which is embarking on its own journey of AI governance while implementing the Digital Personal Data Protection Act, 2023 (DPDPA), this development deserves careful attention.

The Limitations of Data Protection

The DPDPA is a law governing the processing of digital personal data. It protects informational privacy and regulates the relationship between Data Fiduciaries, Data Processors and Data Principals.

However, AI systems have the potential to cause harms that extend well beyond data protection.

Consider a few examples.

    • An AI-based recruitment tool may discriminate against women or older candidates without processing any sensitive personal data unlawfully.
    • An AI-driven credit scoring system may deny financial opportunities to deserving individuals because of biased models.
    • An AI-supported medical diagnosis may jeopardize patient safety.
    • A predictive policing algorithm may affect liberty and equality.
    • A generative AI system may influence freedom of speech, democratic discourse or access to information.

In each of these situations, privacy may not be the principal concern.

The affected rights could include equality, dignity, fairness, consumer protection, access to justice, education, employment and several other constitutional guarantees.

This is precisely why a conventional Data Protection Impact Assessment (DPIA) is no longer sufficient.

What is the Fundamental Rights Impact Assessment?

The EU AI Act requires deployers of specified high-risk AI systems to evaluate how the deployment of AI may affect the fundamental rights guaranteed under the Charter of Fundamental Rights of the European Union.

Unlike a DPIA, which concentrates on risks arising from processing personal data, the FRIA evaluates the possible impact on a broad set of rights such as:

    • Human dignity
    • Equality before law
    • Non-discrimination
    • Privacy
    • Protection of personal data
    • Freedom of expression
    • Freedom of thought
    • Rights of children
    • Rights of persons with disabilities
    • Consumer protection
    • Workers’ rights
    • Right to education
    • Freedom to conduct business
    • Access to justice
    • Healthcare
    • Effective legal remedies

The list extends to more than twenty fundamental rights that AI systems may directly or indirectly affect.

The philosophy behind the FRIA is simple:

Artificial Intelligence must be evaluated not merely for what it does with data, but for what it does to people.

This is perhaps one of the most important conceptual shifts in AI governance.

India’s Constitutional Foundation

India does not have an equivalent of the EU Charter.

However, the Indian Constitution already provides a rich framework of fundamental rights that can serve the same purpose.

Among the most relevant are:

    • Article 14 – Equality before law
    • Article 19 – Freedom of speech and expression
    • Article 21 – Protection of life and personal liberty, including the Right to Privacy recognised in the Justice K.S. Puttaswamy judgment
    • Constitutional guarantees against arbitrary State action
    • Principles of natural justice
    • Consumer rights recognised under statutory law
    • Labour protections
    • Rights of children
    • Rights of persons with disabilities

The constitutional philosophy is already available.

What is presently missing is a structured methodology to evaluate whether an AI system threatens these rights.

India Needs an Indian Fundamental Rights Impact Assessment

As AI becomes embedded in banking, healthcare, education, insurance, public administration and law enforcement, organizations should not limit themselves to asking:

“Is this AI system compliant with DPDPA?”

They must also ask:

    • Is the system fair?
    • Does it discriminate?
    • Does it reduce human autonomy?
    • Does it affect dignity?
    • Does it create barriers to justice?
    • Does it unfairly deny opportunities?
    • Does it threaten democratic values?

These questions belong outside the traditional DPIA.

They require a broader governance instrument.

India therefore needs an Indian Fundamental Rights Impact Assessment (IFRIA).

Integrating IFRIA with DGPSI-AI

The DGPSI-AI framework already adopts a governance-oriented approach instead of treating AI merely as a technological problem.

An expanded governance model could consist of four complementary assessments.

1. Data Protection Impact Assessment (DPIA) with a focus on :

    • Compliance with DPDPA
    • Personal data processing
    • Privacy risks
    • Consent and lawful processing

2. AI Risk Assessment (AIRA) with a focus on:

    • Model reliability
    • Bias
    • Hallucinations
    • Security
    • Robustness
    • Operational risks

3. Indian Fundamental Rights Impact Assessment (IFRIA) with a focus on :

    • Equality
    • Fairness
    • Human dignity
    • Constitutional rights
    • Consumer interests
    • Employee rights
    • Public interest

4. Algorithmic Accountability Assessment with a focus on :

    • Explainability
    • Transparency
    • Auditability
    • Human oversight
    • Traceability
    • Governance effectiveness

Together, these four assessments would provide a comprehensive governance architecture that is significantly broader than current compliance approaches.

Moving Beyond Compliance

Many organizations still perceive AI governance as another compliance exercise. That could be a mistake. Good governance is not merely about avoiding penalties. It is about earning trust.

AI systems influence employment, healthcare, finance, justice and democratic participation. Consequently, governance must protect not only data but also the constitutional values upon which society is built.

The EU has acknowledged this reality through the Fundamental Rights Impact Assessment.

India has the opportunity to adapt the same philosophy within its own constitutional framework rather than merely copying foreign regulations.

The Road Ahead

The next generation of AI governance in India should move beyond the traditional focus on privacy. Privacy remains an essential right. But it is only one among many rights that intelligent systems may affect.

As India develops its own AI governance ecosystem, the objective should be to protect human rights, not merely personal data. The DGPSI-AI, implementation specification no 9 supporting the Governance principle of “Ethics” states,

“The Deployer of an AI shall take all such measures that are essential to ensure that the AI does not harm the society at large…”

Under this provision, an Indian Fundamental Rights Impact Assessment could be considered as part of the best practice.

A structured Indian Fundamental Rights Impact Assessment (IFRIA), integrated with DGPSI-AI and the proposed AI Governance Standard of India (AIGSI), would represent a significant step in that direction.

The future of AI governance will not be determined solely by the sophistication of algorithms.

It will ultimately be judged by how effectively those algorithms preserve human dignity, constitutional freedoms and the rights of every individual whose life they influence.

Comments are welcome.

Naavi

Posted in Privacy | Leave a comment

CIDA Program of August 21-23 enriched with AIGSI and and Data Governance audit for Banks

The August 21-23 program on CIDA (Certified Independent Data Auditors) has been further enriched with the addition of the following coverage.

RBI Guidelines on AI usage in Banks and REs

RBI guidance on Data Governance in Banks and REs

AIGSI: AI Governance standard of India.

This should be of interest to Bankers and CERT IN auditors in particualar

Register before August 8 to catch with the Master Class on CEDPO as a preparation for the course.

Naavi

Posted in Privacy | Leave a comment

Inviting Cert In empanelled Auditors to join the forum of Independent Data Auditors

For more details on Independent Data Auditors, visit www.aidai.org.in

Naavi

Posted in Privacy | Leave a comment

RBI has placed trust on CERT IN empanelled Auditors…. But…Are we ready?

The Reserve Bank of India (RBI) has recently placed three transformational compliance responsibilities before banks:

  • Compliance with the Digital Personal Data Protection Act, 2023 (DPDPA);
  • Compliance with the RBI Guidance on Artificial Intelligence; and
  • Compliance with the Draft Guidance on Data Governance.

Each of these is significant by itself. Together, they redefine the manner in which banks are expected to govern information, deploy technology and demonstrate regulatory accountability.

Among these, one provision in the Data Governance Guidance deserves closer examination.

The draft guidance expects Regulated Entities (REs) to obtain independent audits from CERT-In empanelled auditors. At first glance, this appears to be a logical choice since CERT-In has, for many years, maintained a respected panel of Information Security Auditors.

However, an important question arises.

Is a Data Governance Audit merely an Information Security Audit under a different name?

The answer is No.

The Difference Between Security Audit and Data Governance Audit

Traditional Information Security Audits have largely focused on technical controls designed to preserve the Confidentiality, Integrity and Availability (CIA) of information assets.

A Data Governance Audit, on the other hand, is expected to examine issues such as:

  • Data ownership and stewardship;
  • Data quality and the concept of a Single Source of Truth (SSOT);
  • Regulatory compliance under DPDPA;
  • AI governance and algorithmic accountability;
  • Data lifecycle management;
  • Ethical use of data;
  • Board oversight and governance structures;
  • Documentation, policies and accountability mechanisms;
  • Risk management and evidence of compliance.

Many of these areas lie outside the traditional domain of cyber security.

An auditor may be an outstanding network security expert and still have limited exposure to privacy law, data governance frameworks, AI risk management or regulatory accountability.

The RBI guidance therefore represents not merely a new audit assignment, but the emergence of an entirely new professional discipline.

India Needs Independent Data Auditors

For several years, FDPPI has maintained that India requires a separate profession of Independent Data Auditors (IDAs).

The DPDPA already envisages independent data audits for Significant Data Fiduciaries. RBI’s guidance now reinforces the need for auditors who possess multidisciplinary expertise spanning:

  • Law
  • Technology
  • Data Governance
  • Privacy
  • AI Governance
  • Information Security
  • Risk Management
  • Audit Methodology

No single traditional discipline is sufficient.

Accordingly, FDPPI has developed an ecosystem for Independent Data Auditors with structured capability development through:

  • Probationary Independent Data Auditor (PIDA)
  • Accredited Independent Data Auditor (AIDA)
  • Certified Independent Data Auditor (CIDA)

The objective is not to replace cyber security auditors but to complement them by building competencies that today’s regulatory environment demands.

Data Audit is More Than Technical Compliance

One misconception that deserves correction is the assumption that compliance can be demonstrated merely by examining technical controls.

DPDPA compliance involves legal interpretation.

AI governance involves evaluation of explainability, accountability, human oversight, fairness and risk management.

Data governance involves organisational processes, ownership structures, metadata management, data quality and regulatory accountability.

None of these can be adequately assessed through vulnerability assessments, penetration testing or infrastructure reviews alone.

Consequently, India needs professionals who understand the convergence of law, governance and technology.

Time to Expand the CERT-In Ecosystem

CERT-In has performed an invaluable role in creating and nurturing India’s cyber security audit ecosystem.

The next logical evolution would be to broaden this ecosystem to accommodate professionals specialising in Data Governance and Data Protection.

One possible approach would be to establish an additional empanelment category specifically for Independent Data Auditors possessing recognised qualifications in data governance, privacy and AI governance.

Another equally important step would be to encourage existing CERT-In empanelled auditors to acquire these additional competencies through structured certification programmes.

Such an approach would strengthen—not dilute—the existing CERT-In framework.

Academic Rigor Matters

Professional certification cannot rely solely on experience.

It requires structured learning, objective assessment and continuous professional development.

Recognising this, FDPPI has entered into a collaboration with MYRA School of Business, Mysuru, an AICTE-accredited institution, to strengthen the academic foundation of Independent Data Auditor certifications.

The Certified Independent Data Auditor (CIDA) programme combines practical regulatory understanding with formal evaluation, thereby providing reasonable assurance regarding the competency of certified professionals.

Building India’s Data Governance Capacity

India is entering an era where Data Governance will become as important as Cyber Security.

The success of DPDPA implementation, trustworthy AI deployment and RBI’s regulatory expectations will depend not merely on issuing guidelines but on creating an ecosystem of competent professionals capable of evaluating compliance objectively and independently.

The regulatory framework has already begun evolving.

Professional capability must evolve with equal speed.

The challenge before India is therefore not whether Data Governance Audits should be conducted, but whether we have enough professionals who can perform them with the required multidisciplinary competence.

That is the conversation the industry must begin today.


P.S: 

FDPPI is conducting a three-day Certified Independent Data Auditor (CIDA) programme on 21–23 August 2026 at Fairfield by Marriott, Bengaluru. The programme covers DPDPA compliance, RBI’s AI Guidance, RBI’s Data Governance Guidance and the DGPSI framework for Data Governance and Protection. Professionals interested in developing expertise in this emerging discipline may visit www.aidai.org.in and www.naavi.org for further information.

Naavi

Posted in Privacy | Leave a comment

Calling attention of Bank Boards

Three different compliance requirements are confronting the Indian Banks right now. While most Banks were leisurely planning for DPDPA implementation, RBI unleashed the AI guideline first and before the next heart beat landed the Digital Governance requirement.

To rub salt to the wound, the Bank of Baroda data breach has also surfaced.

These developments have made it necessary for Banks to scramble around for quick action starting first with understanding these frameworks and later initiating the implementation.

Fortunately, there is one organization in India namely FDPPI that is ready to assist the Banks with its structured approach to compliance.

The DGPSI-Banks and DGPSI-Bank Branch were two frameworks that FDPPI had already introduced to meet the requirements of DPDPA compliance. Now the two other compliance requirements of AI and Data governance have also been incorporated into the Compliance training schedule.

let us first understand the challenge..before working on the implementation.

Request Bank Chairmen to start acting and in the next board meeting or earlier, start action to conduct a training program for the HO staff on how to address the requirements.

Call Naavi if required before it is too late since all Banks and REs will be scrambling for the scarce resources for training.

Naavi

Posted in Privacy | Leave a comment

FDPPI introduces a master Training program for Bankers

In the last one month, RBI has come up with the AI Guidelines and Data Governance Guidelines . In addition, Banks are trying to be compliant with DPDPA Act and the Rules.

All the three together are providing a huge challenge to Bankers for Compliance.

In the meantime the Bank of Baroda data breach has ignited a state of urgency in the Banking sector on how to go about the three way compliance.

Even before the compliance Banks need to conduct and awareness program on all these three compliance requirements so that the necessary action plan can be developed.

FDPPI recognizing this urgent need has developed

a) Framework for DPDPA Compliance in Banks namely DGPSI-Banks

b) Artificial Intelligence Governance Standard of India (AIGSI) which is a supplement to DGPSI Banks

c) Data Governance framework as a supplement to DGPSI-Banks

d) DGPSI Banks itself is also addressed as DGPSI-Bank Branch to address the special need of Banks with large number of Branches

Incorporating all these, FDPPI is developing two training programs namely

a) Certified DPDPA Champion -Bank Branch or CDC-Bank Branch (2 days)

b) Data Governance and Protection in Banks (2 days)

Interested Banks may contact FDPPI/Naavi

Naavi

Posted in Privacy | Leave a comment