Harun Raaj & AssociatesHarun Raaj & Associates
AI GovernanceHRA / AI-GOVERNANCE / FY 2026-27

AI Governance — Advisory & Assurance

ISO 42001, NIST AI RMF, DPDP, EU AI Act

End-to-end AI governance: pre-launch policy build (advisory) and annual signed CA assurance report (audit) under ISO 42001, NIST AI RMF, DPDP Rules 2025, EU AI Act, and pending RBI FREE-AI + MeitY guidelines.

Two engagement lanes: (1) Advisory — build the policy stack, model inventory, and DPIA equivalents before you ship; (2) Audit & Assurance — an annual signed CA assurance report against ISO 42001, NIST AI RMF, and DPDP SDF obligations. Free pre-sales checklist at /insights/ai-governance-audit-checklist. EU AI Act module available for Indian exporters.

Honest scope note: ISO 42001 and NIST AI RMF are voluntary frameworks; RBI FREE-AI is a committee report, not a notified framework; MeitY’s March 2025 guidelines are advisory. DPDP Rules 2025 Rule 12 obligations phase in to 13-May-2027. HRA advises on and audits against these frameworks — it is not an ISO 42001 certification body (certification is a separate accredited-body engagement), and no statutory audit mandate for AI exists under Indian law yet.

Talk to a CABrowse all servicesFree: the 40-question AI Governance Audit Checklist
Focus Areas

What this hub covers

Model inventory and AI risk classificationGovernance policies — roles, oversight, kill-switchesDPIA equivalents under DPDP Rules 2025 for AI decisioningEU AI Act Article 6/50 exposure assessment for exportersVendor due diligence questionnaires (AI DDQs)Annual AI governance audit with CA-signed assurance memo
Statutory Anchors
ISO/IEC 42001:2023 (AI Management System, published 18-Dec-2023)NIST AI RMF 1.0 (NIST AI 100-1, 26-Jan-2023)DPDP Act 2023 s.10 + DPDP Rules 2025, G.S.R. 846(E) 13-Nov-2025 (phased to 13-May-2027)EU AI Act, Regulation (EU) 2024/1689 (in force 1-Aug-2024) — Articles 6, 50, Annex IIIMeitY AI Governance Guidelines (4-Mar-2025, advisory)RBI FREE-AI Committee report (24-Nov-2024, framework pending)CERT-In Directions 28-Apr-2022 (6-hour incident reporting)
Lifecycle Map

Typical engagement flow

Inventory

Catalogue every AI model and use case — vendor or in-house, purpose, data categories, deployment stage.

Classify

Risk-classify each system against ISO 42001 Annex A and NIST AI RMF Map; flag EU AI Act Article 6 high-risk triggers for exporters.

Build

Draft the governance policy stack — roles, oversight, kill-switch authority, DPIA equivalents, vendor DDQs.

Assure

Test the controls annually and issue the signed CA assurance memo, distinguishing management representation from control-testing evidence.

Services

Related services in this lifecycle

01

AI Governance Advisory

Advisory

Pre-launch policy build — model inventory, risk classification, governance policies, DPIA equivalents, EU AI Act exposure, vendor DDQs. Signed CA policy memo + roadmap.

02

AI Governance Audit & Assurance

Audit

Annual signed CA assurance report — ISO 42001 clauses 6-10 + Annex A, NIST AI RMF Measure/Manage, DPDP Rule 12 SDF measures, kill-switch verification.

FAQs

Common questions

Is ISO 42001 certification included in your service?

No. HRA advises on and audits against ISO/IEC 42001:2023 as a voluntary framework. External certification is a separate engagement with an accredited certification body. We prepare the documentation and controls so certification, if pursued, is straightforward.

Does the EU AI Act apply to Indian companies?

It can. Regulation (EU) 2024/1689 applies to providers placing AI systems on the EU market or whose system output is used in the EU. Article 6 high-risk classification triggers the obligations we map in the advisory engagement and verify in the audit.

Is there a statutory AI audit mandate in India yet?

No statutory audit mandate for AI exists under Indian law as of September 2026. RBI FREE-AI is a committee report and the MeitY March 2025 guidelines are advisory. The audit is voluntary and preparatory for anticipated regulation — the report says so explicitly.

What do the DPDP Rules 2025 require for AI?

Significant Data Fiduciaries carry s.10 obligations — DPO appointment, DPIAs, and algorithmic-decision audits — with Rule 12 setting SDF-specific measures. Under G.S.R. 846(E) (13-Nov-2025), commencement of Rules 3, 5-16, and 22-23 phases to 13-May-2027.

How is this different from an Information Systems audit?

Traditional IS audit covers IT general controls and systems assurance. AI governance adds model inventory, risk classification, human-oversight verification, and model documentation. For traditional ITGC and IS-audit standards, see our is-audit service.

What does the assurance report actually say?

It tests controls against ISO 42001 clauses 6-10 and Annex A, the NIST AI RMF Measure/Manage functions, and DPDP Rule 12 measures, and — for EU-facing systems — verifies Article 50 transparency notices. Where steps rely on management representation rather than control-testing evidence, the report distinguishes them explicitly.

Need the right filing or advisory path?

We can map the facts, confirm the statutory route, and move from draft to execution without the usual back-and-forth.

Talk to a CABack to Services