Indian companies with EU customers, EU operations, or EU-based employees are subject to the General Data Protection Regulation regardless of…
SOC 2 Type II has become a commercial prerequisite for Indian ITeS and BPO companies serving enterprise clients in North…
ISO 27001:2022 reorganised the Annex A control set from 114 controls across 14 domains to 93 controls across four themes.…
The Insurance Regulatory and Development Authority of India's Information and Cyber Security Guidelines, 2023 apply to all insurers, re-insurers, and…
The Securities and Exchange Board of India's Cybersecurity and Cyber Resilience Framework applies to all SEBI-regulated entities: stock brokers, depository…
The Reserve Bank of India's 2023 Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices applies to all…
Your organisation is likely operating under more than one compliance framework. RBI if you are a bank or NBFC. SEBI…
The Digital Personal Data Protection Act, 2023 is not a policy compliance exercise. The obligations it creates land directly on…
Here is a question worth asking your compliance team: how long would it take to produce the evidence package for…
When did you last run a compliance evidence collection that did not surface something unexpected? Not a gap in your…