ISO 42001 (AI Management System) and India's DPDP Act 2023 are the two governance instruments every Indian AI team must implement by 2026. They overlap on data governance and AI impact assessment, but neither substitutes for the other. The minimum implementation is a documented AI policy, a 12-category risk register, a per-system impact assessment, a consent and purpose register, a third-party AI register, an incident runbook, and a quarterly review cadence.
- ISO 42001 + DPDP stack
- The combined governance baseline for an Indian AI team in 2026: ISO 42001 covers the AI Management System (governance, risk, lifecycle, third-party AI, impact assessment); DPDP covers personal-data fiduciary duties, consent, purpose, SDF designation and cross-border transfer. Together they form the minimum stack to sell into Indian regulated buyers and EU/UK enterprise.
- ISO 42001 = AI Management System. DPDP = personal-data law. Both, not either.
- ISO 42001 is voluntary but becoming a procurement gate.
- DPDP penalties go up to ₹250 cr per breach class — board-risk item.
- Minimum stack ships in ~4 months of partial allocation from a senior lead.
- Validate each frame with a ₹1,799 guided audit before paying for a certification body.
Where the two overlap
| Topic | ISO 42001 | DPDP Act 2023 |
|---|---|---|
| Scope | AI systems & their management | Personal data of individuals in India |
| Governance | Policy, roles, board oversight | Data fiduciary duties, DPO for SDFs |
| Risk | AI risk register, AI impact assessment | DPIA for high-risk processing |
| Data | Provenance, quality, lineage | Consent, purpose limitation, retention |
| Third-party | Third-party AI register & controls | Processor contracts |
| Penalties | Procurement / certification loss | Up to ₹250 cr per breach class |
The minimum implementation
- Documented AI policy signed by the board or CEO.
- 12-category AI risk register with likelihood × severity × detectability scoring.
- Per-system AI impact assessment (ISO 42001 A.6 + EU AI Act art. 27 style).
- Consent and purpose register for both training and inference data (DPDP §6, §7).
- Third-party AI register with named owners and renewal dates.
- Incident response runbook covering model failures, data breaches and misuse.
- Quarterly review cadence — annual-only fails Stage 2 ISO 42001 audits.
Frequently asked
- Are ISO 42001 and DPDP the same thing?
- No. ISO 42001 is an AI Management System standard covering governance, risk, lifecycle, third-party AI and impact assessment. DPDP is India's personal-data law covering consent, purpose, fiduciary duties, SDF designation and cross-border. They overlap on data governance and AI impact assessment, but neither substitutes for the other.
- Is ISO 42001 mandatory in India?
- No. It is voluntary but is rapidly becoming a procurement gate for selling AI into EU/UK/US enterprise, and a credible governance signal for Indian regulators and large buyers.
- What's the maximum DPDP penalty?
- Up to ₹250 crore per breach class. Failure to take reasonable security safeguards leading to a personal-data breach carries the headline penalty. AI governance is now a board-risk item, not an engineering item.
- What is the minimum stack to satisfy both?
- A documented AI policy, a 12-category AI risk register, a per-system AI impact assessment, a consent and purpose register for training and inference data, a third-party AI register, an incident response runbook, and a quarterly review cadence.
- Can a small Indian startup implement this?
- Yes. The realistic floor is ~4 months of partial allocation from a senior compliance lead, with ₹1,799 guided audits to validate each frame before a formal certification body engagement.
Map your ISO 42001 + DPDP gap in 30 minutes.
Run a ₹1,799 guided audit on the ISO 42001 or DPDP frame and get a per-frame report you can take to your board.
Dr. Nitnem Singh Sodhi is a Lead Auditor for ISO/IEC 42001, 27001 and 27701, accredited by ANSI/ABICB since March 2025.
— Bharat NeuroTech · /dr-sodhi
