AI Governance & Policy
AI governance is the set of rules your organisation runs on: what tools staff may use, what data may go into them, who approves new deployments, and how you demonstrate compliance if asked. Most Indian businesses have staff using AI daily and no policy at all, which is an exposure that costs nothing to close.
Who it's for
Companies where staff are already pasting client data into public chatbots.
What changes
Clear rules before an incident forces you to write them.
- Starting at
- ₹75,000
- Timeline
- 2–4 weeks for an audit
- Category
- AI Consulting & Enablement
- Built from
- Vashi, Navi Mumbai
Key takeaways
- Your team is already using AI tools — the only question is whether there are rules.
- Pasting customer data into a consumer AI tool is a disclosure with DPDP consequences.
- A policy nobody can follow is worse than none; it must map to real work.
- Enterprise and international clients increasingly ask about this in procurement.
- Two to four weeks from ₹1,25,000.
The gap between what is happening and what is authorised
In almost every organisation we assess, staff are using AI tools that were never approved, on data that should not have left the building, with no record of any of it.
This is not misconduct. Nobody told them not to, the tools are free and useful, and the boundary is genuinely not obvious — summarising a client email feels different from uploading a contract, though legally they are closer than they appear.
The fix is not prohibition, which does not work and drives usage underground. It is a clear, short set of rules people can actually follow, plus approved tools that make following them easy.
What the policy has to cover
Short and specific beats comprehensive and unread. These are the sections that matter.
| Section | What it answers | Why it matters |
|---|---|---|
| Approved tools | What may be used, for what | Removes ambiguity |
| Data classification | What may be pasted where | The core protection |
| Prohibited uses | What is never acceptable | Decisions, HR, legal advice |
| Review and disclosure | When output must be checked or labelled | Quality and honesty |
| Approval route | How a new tool gets adopted | Prevents shadow adoption |
| Incident handling | What to do when something goes wrong | Reduces the cost of mistakes |
| Record keeping | What is logged and retained | Demonstrable compliance |
Where the DPDP Act actually bites
The Digital Personal Data Protection Act treats sending personal data to an AI provider as processing by a third party. That carries consequences most staff have never considered.
You need a lawful basis for it, the purpose must be one the person was told about, the provider is a processor you are responsible for, and any use of that data for training needs separate consideration. A free consumer tool whose terms permit training on inputs is not a suitable processor for customer data, whatever its quality.
Sensitive categories — health, financial, biometric — carry additional obligations, and children's data more still. The policy states these plainly with examples from your own work rather than as an abstract summary of the statute.
Approving tools without becoming a bottleneck
New AI tools appear constantly and staff will want to use them. A process requiring a committee review for each one means nobody asks and everyone proceeds anyway.
The workable approach is tiered. Tools used only on public or internal non-sensitive information get a light check. Tools that will touch customer or confidential data get a proper review of terms, data handling and location. Anything making or influencing decisions about people gets the full treatment.
We build the review checklist so your team can run the light and medium tiers themselves, with escalation only for the ones that genuinely warrant it.
Why clients are starting to ask
Procurement questionnaires from larger Indian companies and from international clients now routinely include questions about AI use — whether their data may be processed by AI systems, under what controls, and whether you have a policy.
"We do not have one" is an answer that costs deals, and it is an unnecessary one to give.
Several clients have commissioned this specifically because a customer asked. The document that results is short, and having it available turns an awkward question into a two-minute answer.
What is delivered and how
Two to four weeks from ₹1,25,000: an assessment of what is currently being used, the policy itself written for your organisation and your work, the data classification guide, the tool approval process, incident procedures, and a staff briefing session.
The briefing matters. A policy circulated by email is read by few; a forty-minute session where people can ask whether their specific task is allowed is what makes it operative.
We also set a review date, since the tools and the regulatory position both move. An annual revision is usually adequate.
FAQ
AI Governance & Policy — your questions
Is there an AI law in India we need to comply with?
There is no dedicated AI statute at present. What applies is the DPDP Act for personal data, sectoral regulation where you are in a regulated industry, IT rules for intermediaries and content, and ordinary contract and confidentiality obligations to your own clients. The absence of a specific AI law does not mean an absence of applicable rules — most exposure in this area comes from data protection and client confidentiality, both of which are already in force.
Should we just ban AI tools instead?
It does not work. Prohibition drives usage onto personal devices and personal accounts, where you have no visibility and no control at all — a considerably worse position than governed use. It also puts you at a disadvantage against competitors whose teams are working faster. Every client who has asked us about a ban has ended up with a governed-use policy instead, once the practical consequences were laid out.
Do we need this if we are only ten people?
The document is shorter but the exposure is the same, and often the reasoning is simpler to establish. A ten-person firm handling client contracts or customer data has the same obligations as a large one. What changes is the process weight — a small firm needs clear rules and a named person who approves tools, not a governance committee. We scale the engagement accordingly rather than delivering a corporate framework to a small team.
What about AI systems we have built ourselves?
Those are covered too, and they carry additional considerations: where the data goes, whether outputs are reviewed, what happens when the system is wrong, and who is accountable for it. For systems that affect people — hiring, credit, pricing — the governance requirements are heavier and we cover them specifically. This is also where the record-keeping matters, since demonstrating that a system was monitored and reviewed is difficult to do retrospectively.
Can you help if a client sends us a security questionnaire?
Yes, and it is a common follow-on request. We help you answer accurately, which sometimes means identifying gaps that need closing before you can answer well. Answering a procurement questionnaire optimistically is a poor idea — the answers frequently become contractual representations, and a claim you cannot support is a worse position than a gap you disclosed and are addressing.
More in AI Consulting & Enablement
View all 7- AI Readiness AuditA clear, costed shortlist instead of a vague ambition.
- AI Strategy RoadmapA plan you can fund and hold people to.
- RAG Knowledge SystemInstitutional memory that survives people leaving.
- Custom LLM Fine-TuningA model that speaks your business's language.
- Prompt Engineering & Team TrainingEveryone gets better at it, with rules everyone knows.
- AI Agent Monitoring & MaintenanceYou find out about quality drift before your customers do.
Next step
Want a AI Governance & Policy for your business?
Tell us what the process looks like today and we'll tell you what it would look like automated — and what it would cost.