Skip to content

The FY27 Compliance Map: Six Regulators an Indian AI Deployment Must Answer To

The six Indian regulators every AI deployment must map to in FY27 — RBI, SEBI, IRDAI, TRAI, DPDP, sector-specific. The compliance map operators need now.

Siddhesh Joglekar

· 4 min read

Blog image

If your AI roadmap for FY27 maps to one regulator, from a BFSI Sector perspective, it is incomplete. Most Indian AI deployments touch three to four regulators simultaneously and the compliance teams discover this in audit, not in design. The compliance map below is the first artefact your AI programme should produce — before the procurement decision, before the vendor shortlist, before the proof-of-concept. 

1. RBI — for any BFSI deployment

RBI's posture across 2024–25 has been consistent. Discussion papers on AI/ML in supervisory technology, on model risk in lending, on fraud detection. The pattern is the same one we have seen on digital lending and on outsourcing — discussion paper, then market consultation, then master direction with enforcement teeth. FY27 is the master-direction phase. Banks and NBFCs deploying AI for credit, collections, fraud, KYC, or customer interaction should assume formal supervisory expectations land this fiscal year. The right preparation is a model governance committee, documented model validation, and an audit trail mapping decisions to model inputs.

2. SEBI — for any market-facing or advisory deployment

SEBI's focus has tightened across two surfaces — algo trading frameworks and the Research Analyst / Investment Adviser (RA/IA) regime. The signal is unambiguous. AI tools that touch retail investor decisions — robo-advisors, screener services, AI-generated market commentary, fintech apps with portfolio nudges — are migrating into RA/IA scope. Operators with AI-assisted retail products who haven't taken a view on RA/IA registration by Q2 FY27 are gambling with the easiest enforcement action in Mumbai.

3. IRDAI — for any insurance deployment

IRDAI's regulatory architecture has moved fastest on claims-side AI, with parallel work on underwriting fairness and policyholder communication. Insurers using AI for claims triage need a documented appeals path, a non-AI fallback for adverse decisions, and demonstrable absence of protected-class bias. Underwriting AI carries an additional disclosure burden. The penalty surface here is reputational as much as regulatory — a single denied claim with an AI fingerprint reaches the consumer press faster than any IRDAI notice.

4. TRAI — for any voice, IVR, or messaging AI

TRAI has been the quiet regulator in the AI conversation. That is changing. AI-generated voice calls, AI-driven IVR routing, and AI-assisted commercial messaging all sit inside TRAI's commercial communication framework. The Do-Not-Disturb regime applies to AI-generated outreach exactly as it applies to human-dialled calls. Operators planning Hindi/regional voice agents for outbound use cases — collections, lead qualification, customer support — need an explicit TRAI compliance review baked into the deployment plan.

5. The DPDP authority — for everything

The Digital Personal Data Protection Act is the floor under every other regulator. Every AI deployment that touches personal data — and that is essentially every interesting AI deployment — needs purpose limitation, consent architecture, deletion workflows, and an articulated lawful basis. Most Indian operators have treated DPDP as an IT problem. That framing is wrong. DPDP is a product decision: it determines what your AI can be trained on, what it can be evaluated on, and how long it can hold context. Sort that before the rest.

6. Your sectoral floor — MoE, NMC, RERA, AICTE, UGC

Most Indian operators sit inside a sectoral regulator with its own AI posture beyond the financial four. Education deployments answer to MoE, AICTE, and UGC frameworks — including the FY25 AI-in-education advisory. Healthcare deployments answer to NMC's telemedicine and ABDM frameworks. Real-estate-tech answers to RERA's disclosure regime, which is now relevant for any AI-generated property listing or valuation. None of these are optional. All of them are getting sharper through FY27.

The artefact your team should ship by Q1 FY27 close

A one-page regulator map for each AI deployment in your portfolio. Columns: deployment name, primary regulator, secondary regulators, applicable framework/circular, current compliance status, owner, review date. Most Indian operators will discover that a deployment they thought was a marketing project is actually a TRAI plus DPDP plus sectoral concern. Better that discovery happens in the planning room than in the audit.

The Indian regulator does not need to understand your AI. Your AI needs to understand the Indian regulator.

Siddhesh Joglekar

Written by Siddhesh Joglekar

Fractional CMO and AI marketing consultant Siddhesh Joglekar helps founders and growth-stage teams build marketing engines that compound.

Book a Call (opens in a new tab)