IndiaAI Mission Alignment Guide
Security, governance, and compliance requirements for organisations participating in India's ₹10,371 crore IndiaAI Mission across all 7 pillars.
🏛️ IndiaAI Mission — 7 Pillars
🎯 Who Needs This Guide
| Organisation Type | IndiaAI Touchpoint | Primary Obligation | Urgency |
|---|---|---|---|
| AI Startups seeking funding | Pillar 6 — Startup Financing | Safe & Trusted AI self-certification required for investment | High |
| Research institutions | Pillars 1 + 2 (Compute, IAIC) | Data governance, model documentation, ethics framework | High |
| Government agencies | Pillar 4 — Application Development | AI security assessment, CERT-In alignment, bias audit | High |
| Private sector using NAICF compute | Pillar 1 — Compute Capacity | Access controls, data classification, job logging | Medium |
| Universities / EdTech | Pillar 5 — FutureSkills | Curriculum compliance, student data handling (DPDP) | Medium |
| Data contributors | Pillar 3 — Datasets Platform | Anonymisation standards, consent documentation, DPDP Act | High |
🛡️ Safe & Trusted AI — Requirements
The Safe & Trusted AI pillar applies to every organisation participating in any IndiaAI pillar. It draws from MeitY's Responsible AI Framework, NITI Aayog's principles, and global standards including NIST AI RMF and EU AI Act concepts.
Mandatory Requirements — All Participants
| Requirement | Description | Evidence Required | Status |
|---|---|---|---|
| AI Impact Assessment | Document potential harms before deployment — safety, fairness, privacy, security risks. Structured assessment following MeitY template. | Signed AIA document, CISO sign-off | Guidance issued |
| Bias Audit | Test models for demographic bias — gender, caste, religion, language, geography. Independent audit required for High-risk AI systems. | Audit report by accredited body | Framework pending |
| Explainability Documentation | Document how the AI system makes decisions. For high-stakes decisions (credit, healthcare, legal), provide explanation to affected individuals. | Model card, explainability report | Recommended |
| Human Oversight Mechanism | All High-risk AI decisions must have a human review option. Document the override and appeal process. | Process document, audit log capability | Guidance issued |
| Data Governance Policy | Document data sources, quality controls, consent basis, retention schedule. DPDP Act compliance for personal data in training or inference. | Data governance policy, DPA register | Mandatory — DPDP |
| Security Assessment | AI system security review: model security, API security, data pipeline, access controls, CERT-In alignment. | Security assessment report | Mandatory |
| Incident Reporting | AI safety incidents (harm, bias discovery, security breach) reported to MeitY/IndiaAI. CERT-In 6-hour rule applies to security incidents. | Incident log, documented reporting process | Framework pending |
AI Risk Classification
| Risk Level | Examples | Requirements |
|---|---|---|
| High Risk | Healthcare diagnosis, judicial decisions, credit scoring, critical infrastructure, law enforcement, biometric surveillance | Mandatory conformity assessment, independent bias audit, human oversight, MeitY registration, continuous monitoring |
| Medium Risk | HR/recruitment, education assessment, public services, insurance underwriting, content moderation | AI Impact Assessment, explainability documentation, data governance policy, internal audit annually |
| Low Risk | Customer chatbots (non-critical), content recommendation, productivity tools, research tools | Transparency disclosure to users, basic model card, DPDP compliance for personal data |
| Minimal Risk | Spam filters, captcha, routine automation, non-personal analytics | Voluntary code of conduct, best practice guidelines |
💻 Pillar 1: Compute Security Requirements
Organisations accessing the National AI Computing Facility (NAICF) must meet security and data governance requirements at onboarding. These are conditions of access, not recommendations.
| Control Area | Requirement | Implementation Guidance |
|---|---|---|
| Identity & Access | MFA on all NAICF portal accounts. Role separation — researchers, operators, billing admin distinct roles. | Aadhaar-linked identity verification at onboarding. OTP/authenticator app MFA enforced by platform. |
| Data Classification | All data uploaded for training must be classified. Personal data requires documented DPDP consent basis. | Submit data classification register at project onboarding. Update when adding new training datasets. |
| Compute Isolation | Training jobs run in isolated tenant environments. No cross-tenant data access. GPU memory wiped between jobs. | Managed by NAICF infrastructure. Verify in SLA before processing sensitive data. |
| Model Output Security | Document IP ownership, access controls, and export controls for model weights produced on NAICF. | IP assignment agreement signed at project start. Maintain model access log with version control. |
| Audit Logging | All compute jobs logged — who ran what, when, data inputs, compute hours, outputs. 2-year minimum retention. | NAICF provides job logs. Supplement with your own access logs and data lineage records. |
| Incident Reporting | Security incidents on NAICF reported to IndiaAI and CERT-In within 6 hours per CERT-In Directions 2022. | Maintain NAICF emergency contacts and CERT-In reporting procedure in your IR runbook. |
🗄️ Pillar 3: Datasets Platform — Data Governance
| Obligation | Requirement | DPDP Act Reference |
|---|---|---|
| Anonymisation standard | Personal data anonymised before upload. Anonymisation method documented. Minimum k-anonymity k=5 recommended. Differential privacy preferred for sensitive domains. | Section 2(t) — anonymisation removes DPDP obligations |
| Consent documentation | If dataset contains personal data (even pseudonymised), original consent must have covered research/AI training use. | Section 6 — valid consent requirements |
| Sensitive data controls | Sensitive personal data (health, financial, biometric, caste, religion) requires explicit consent or explicit exclusion from dataset before upload. | Section 2(t) read with forthcoming rules |
| Data accuracy obligation | Contributor responsible for dataset accuracy and quality. Inaccurate datasets used for government AI carry contributor liability. | Section 8(3) — accuracy obligation of Data Fiduciary |
| Right to erasure mechanism | Mechanism for data principals to request deletion of their records from platform after contribution. | Section 12 — right to erasure by data principal |
| Cross-border transfer | Datasets containing personal data cannot be hosted on infrastructure outside India without RBI/MeitY approval. NAICF infrastructure is India-hosted. | Section 16 — cross-border data transfer restrictions |
✅ IndiaAI Compliance Checklist
🗺️ IndiaAI → Regulatory Framework Mapping
Use this to avoid duplicating compliance work. IndiaAI Safe & Trusted AI requirements heavily overlap with obligations you likely already have.
| IndiaAI Requirement | DPDP Act 2023 | CERT-In 2022 | NIST AI RMF | ISO 42001 |
|---|---|---|---|---|
| AI Impact Assessment | Section 6 (consent), Section 16 (children) | — | MAP 1.1, 1.5 | 6.1.2 |
| Bias Audit | Section 8 (accuracy obligation) | — | MEASURE 2.5, 2.7 | 8.4 |
| Human Oversight | Section 12 (right to correction) | — | GOVERN 6.1 | 6.1.1 |
| Data Governance Policy | Sections 4–12 (full chapter) | Section 4 (data retention) | MAP 3.1 | 8.3 |
| Security Assessment | Section 8(5) (security safeguards) | Section 4 (all controls) | MANAGE 1.3 | 8.5 |
| Incident Reporting | Section 8(6) (breach notification) | Section 3(i) (6-hour report) | RESPOND 1.1 | 10.1 |
| Model Documentation | Section 8(4) (transparency) | — | GOVERN 1.7 | 8.6 |
| Third-Party Assessment | Section 8(2) (processor obligations) | Section 4(j) (vendor audit) | GOVERN 5.2 | 8.7 |
| Explainability | Section 12(b) (right to information) | — | MEASURE 2.6 | 8.4.2 |
Key Contacts & Resources
| Body | Role | Portal |
|---|---|---|
| IndiaAI (MeitY DIC) | Mission implementation, compute access, startup grants | indiaai.gov.in |
| MeitY | AI policy, Safe & Trusted AI framework | meity.gov.in |
| CERT-In | Cybersecurity incident reporting for AI systems | cert-in.org.in |
| Data Protection Board | DPDP Act enforcement, breach notification | dpboard.gov.in (pending) |
| NASSCOM CoE | AI governance support, tooling, training | nasscom.in/ai |
| NITI Aayog | Responsible AI principles, policy guidance | niti.gov.in |