Skip to content

AI Consulting & Enablement

AI Governance & Policy

AI governance is the set of rules your organisation runs on: what tools staff may use, what data may go into them, who approves new deployments, and how you demonstrate compliance if asked. Most Indian businesses have staff using AI daily and no policy at all, which is an exposure that costs nothing to close.

Who it's for

Companies where staff are already pasting client data into public chatbots.

What changes

Clear rules before an incident forces you to write them.

Starting at
₹75,000
Timeline
2–4 weeks for an audit
Built from
Vashi, Navi Mumbai

Key takeaways

  • Your team is already using AI tools — the only question is whether there are rules.
  • Pasting customer data into a consumer AI tool is a disclosure with DPDP consequences.
  • A policy nobody can follow is worse than none; it must map to real work.
  • Enterprise and international clients increasingly ask about this in procurement.
  • Two to four weeks from ₹1,25,000.

The gap between what is happening and what is authorised

In almost every organisation we assess, staff are using AI tools that were never approved, on data that should not have left the building, with no record of any of it.

This is not misconduct. Nobody told them not to, the tools are free and useful, and the boundary is genuinely not obvious — summarising a client email feels different from uploading a contract, though legally they are closer than they appear.

The fix is not prohibition, which does not work and drives usage underground. It is a clear, short set of rules people can actually follow, plus approved tools that make following them easy.

What the policy has to cover

Short and specific beats comprehensive and unread. These are the sections that matter.

SectionWhat it answersWhy it matters
Approved toolsWhat may be used, for whatRemoves ambiguity
Data classificationWhat may be pasted whereThe core protection
Prohibited usesWhat is never acceptableDecisions, HR, legal advice
Review and disclosureWhen output must be checked or labelledQuality and honesty
Approval routeHow a new tool gets adoptedPrevents shadow adoption
Incident handlingWhat to do when something goes wrongReduces the cost of mistakes
Record keepingWhat is logged and retainedDemonstrable compliance

Where the DPDP Act actually bites

The Digital Personal Data Protection Act treats sending personal data to an AI provider as processing by a third party. That carries consequences most staff have never considered.

You need a lawful basis for it, the purpose must be one the person was told about, the provider is a processor you are responsible for, and any use of that data for training needs separate consideration. A free consumer tool whose terms permit training on inputs is not a suitable processor for customer data, whatever its quality.

Sensitive categories — health, financial, biometric — carry additional obligations, and children's data more still. The policy states these plainly with examples from your own work rather than as an abstract summary of the statute.

Approving tools without becoming a bottleneck

New AI tools appear constantly and staff will want to use them. A process requiring a committee review for each one means nobody asks and everyone proceeds anyway.

The workable approach is tiered. Tools used only on public or internal non-sensitive information get a light check. Tools that will touch customer or confidential data get a proper review of terms, data handling and location. Anything making or influencing decisions about people gets the full treatment.

We build the review checklist so your team can run the light and medium tiers themselves, with escalation only for the ones that genuinely warrant it.

Why clients are starting to ask

Procurement questionnaires from larger Indian companies and from international clients now routinely include questions about AI use — whether their data may be processed by AI systems, under what controls, and whether you have a policy.

"We do not have one" is an answer that costs deals, and it is an unnecessary one to give.

Several clients have commissioned this specifically because a customer asked. The document that results is short, and having it available turns an awkward question into a two-minute answer.

What is delivered and how

Two to four weeks from ₹1,25,000: an assessment of what is currently being used, the policy itself written for your organisation and your work, the data classification guide, the tool approval process, incident procedures, and a staff briefing session.

The briefing matters. A policy circulated by email is read by few; a forty-minute session where people can ask whether their specific task is allowed is what makes it operative.

We also set a review date, since the tools and the regulatory position both move. An annual revision is usually adequate.

FAQ

AI Governance & Policy — your questions

Is there an AI law in India we need to comply with?

There is no dedicated AI statute at present. What applies is the DPDP Act for personal data, sectoral regulation where you are in a regulated industry, IT rules for intermediaries and content, and ordinary contract and confidentiality obligations to your own clients. The absence of a specific AI law does not mean an absence of applicable rules — most exposure in this area comes from data protection and client confidentiality, both of which are already in force.

Should we just ban AI tools instead?

It does not work. Prohibition drives usage onto personal devices and personal accounts, where you have no visibility and no control at all — a considerably worse position than governed use. It also puts you at a disadvantage against competitors whose teams are working faster. Every client who has asked us about a ban has ended up with a governed-use policy instead, once the practical consequences were laid out.

Do we need this if we are only ten people?

The document is shorter but the exposure is the same, and often the reasoning is simpler to establish. A ten-person firm handling client contracts or customer data has the same obligations as a large one. What changes is the process weight — a small firm needs clear rules and a named person who approves tools, not a governance committee. We scale the engagement accordingly rather than delivering a corporate framework to a small team.

What about AI systems we have built ourselves?

Those are covered too, and they carry additional considerations: where the data goes, whether outputs are reviewed, what happens when the system is wrong, and who is accountable for it. For systems that affect people — hiring, credit, pricing — the governance requirements are heavier and we cover them specifically. This is also where the record-keeping matters, since demonstrating that a system was monitored and reviewed is difficult to do retrospectively.

Can you help if a client sends us a security questionnaire?

Yes, and it is a common follow-on request. We help you answer accurately, which sometimes means identifying gaps that need closing before you can answer well. Answering a procurement questionnaire optimistically is a poor idea — the answers frequently become contractual representations, and a claim you cannot support is a worse position than a gap you disclosed and are addressing.

Next step

Want a AI Governance & Policy for your business?

Tell us what the process looks like today and we'll tell you what it would look like automated — and what it would cost.