Compliance

Compliance is not
a feature. It's the floor.

Every EAIP deployment ships with DPDP consent capture, 7-year hash-chained audit trails — beyond CERT-In's 180-day floor — Cedar deny-wins policy enforcement, and India data residency. Not options — defaults.

RBI Master Direction April 10, 2026 — IT outsourcing compliance window open now. Banks and NBFCs deploying AI tools must demonstrate governance frameworks. EAIP ships the governance layer pre-wired.

Statute → mechanism → evidence

Not certifications.
Runtime enforcement.

Every obligation maps to a named mechanism in the platform and an evidence artifact you can produce on demand. This is what an inspection-ready AI deployment looks like.

DPDP Act 2023 + Rules 2025

Runtime-enforced

Consent Manager: Nov 13, 2026 · Binding: May 13, 2027

  • consent_gate workflow node — runs fail without a matching consent record for the stated purpose (loan origination, KYC, credit assessment, collections…)
  • Consent records and erasure receipts with cascade across memory and traces
  • PII redaction membrane on every model call — data minimisation by default
  • Cross-border transfer only behind a recorded organisation opt-in

Evidence: Consent lineage per run · erasure verification query

RBI FREE-AI Framework (Aug 2025)

Runtime-enforced

Advisory today · Master Direction incorporation expected

  • Agent registry with approval workflow — a live AI inventory, not a spreadsheet
  • Explainable decisions: the reference credit agent cites rules and ships SHAP explanations
  • Per-agent cost and token budgets with enforce mode
  • Human-in-the-loop nodes for high-stakes lending decisions

Evidence: Board-reportable governance center · model inventory

RBI Outsourcing + Digital Lending Directions

Runtime-enforced

Outsourcing transition deadline: Apr 10, 2026 — passed

  • India-resident processing, not just storage — inference pinned to ap-south-1 / asia-south1
  • Region derived from the tenant server-side; never trusted from a request
  • Bring-your-own model keys — your provider relationship, your boundary
  • Architecture built for regulator and customer audit access

Evidence: Per-call inference_region in the audit trail

CERT-In Directions 2022

Runtime-enforced

Active enforcement

  • 6-hour incident reporting pipeline
  • NTP synchronised to time.nplindia.in (IST, no DST ambiguity)
  • SHA-256 hash-chained, append-only trace store
  • 7-year retention — beyond the 180-day CERT-In floor, aligned to PMLA-grade record-keeping

Evidence: Hash-chain continuity proof, verified in-product