Compliance is not
a feature. It's the floor.
Every EAIP deployment ships with DPDP consent capture, 7-year hash-chained audit trails — beyond CERT-In's 180-day floor — Cedar deny-wins policy enforcement, and India data residency. Not options — defaults.
RBI Master Direction April 10, 2026 — IT outsourcing compliance window open now. Banks and NBFCs deploying AI tools must demonstrate governance frameworks. EAIP ships the governance layer pre-wired.
Not certifications.
Runtime enforcement.
Every obligation maps to a named mechanism in the platform and an evidence artifact you can produce on demand. This is what an inspection-ready AI deployment looks like.
DPDP Act 2023 + Rules 2025
Runtime-enforcedConsent Manager: Nov 13, 2026 · Binding: May 13, 2027
- consent_gate workflow node — runs fail without a matching consent record for the stated purpose (loan origination, KYC, credit assessment, collections…)
- Consent records and erasure receipts with cascade across memory and traces
- PII redaction membrane on every model call — data minimisation by default
- Cross-border transfer only behind a recorded organisation opt-in
Evidence: Consent lineage per run · erasure verification query
RBI FREE-AI Framework (Aug 2025)
Runtime-enforcedAdvisory today · Master Direction incorporation expected
- Agent registry with approval workflow — a live AI inventory, not a spreadsheet
- Explainable decisions: the reference credit agent cites rules and ships SHAP explanations
- Per-agent cost and token budgets with enforce mode
- Human-in-the-loop nodes for high-stakes lending decisions
Evidence: Board-reportable governance center · model inventory
RBI Outsourcing + Digital Lending Directions
Runtime-enforcedOutsourcing transition deadline: Apr 10, 2026 — passed
- India-resident processing, not just storage — inference pinned to ap-south-1 / asia-south1
- Region derived from the tenant server-side; never trusted from a request
- Bring-your-own model keys — your provider relationship, your boundary
- Architecture built for regulator and customer audit access
Evidence: Per-call inference_region in the audit trail
CERT-In Directions 2022
Runtime-enforcedActive enforcement
- 6-hour incident reporting pipeline
- NTP synchronised to time.nplindia.in (IST, no DST ambiguity)
- SHA-256 hash-chained, append-only trace store
- 7-year retention — beyond the 180-day CERT-In floor, aligned to PMLA-grade record-keeping
Evidence: Hash-chain continuity proof, verified in-product