RESOURCES

Regulatory coverage

Every control AssureNode executes traces to a published clause in a named instrument. This page records what we map today, what is being mapped, and how these instruments keep moving.

Coverage

What we map, and what is next.

A regulator appears as Live only when every obligation on it is bound to a clause and verified against the current instrument. Coverage expands with client scope, not with a roadmap slide.

  1. 01

    RBI

    Digital lending · Outsourcing · IT governance · Fraud risk management

    Live
  2. 02

    DPDP

    Erasure on request · Erasure on event · Consent purpose

    Live
  3. 03

    Internal policy

    Your own policies, treated exactly like regulation

    Live
  4. 04

    NPCI

    Mandate velocity caps and retry limits

    Mapping
  5. 05

    SEBI

    Intermediary obligations, reporting timelines

    Queued
  6. 06

    IRDAI

    Policyholder protection, outsourcing

    Queued
  7. 07

    CDSCO and FDA

    Batch records, adverse event clocks

    Queued
  8. 08

    CEA and CERC

    Safety incident reporting, regulatory returns

    Queued

Mapped today

Two regulators, at clause level.

01

Reserve Bank of India

Digital lending.
Directions, 2025 · RBI/2025-26/36, 8 May 2025. Disbursement and repayment must run directly between borrower and lender, with no third-party, pass-through or pooled account in either path. Sections 9(i) and 9(ii). This repealed the September 2022 Guidelines outright.
Outsourcing.
Managing Risks in Outsourcing Directions, 2025 · 28 November 2025. Inventory including supply chain, due diligence at onboarding and renewal, monitoring and SLA adherence, audits including sub-contractors, exit terms, and a provider cyber incident reported to RBI within six hours of detection. Eight separate Directions, one per entity class.
IT governance.
Directions, 2023 · RBI/2023-24/107, effective 1 April 2024. Audit and system logging on every application touching critical or sensitive information, detailed enough to serve as forensic evidence. Access only where a valid business need exists. Documented approval for changes.
Fraud risk management.
Directions, 2024 · 15 July 2024. A Board-approved EWS and red-flagging framework. Examination concluded within 180 days of CRILC red-flagging. A Show Cause Notice with complete transaction details and not less than 21 days to respond. The Fraud Monitoring Return filed within 14 days of classification.
02

Digital Personal Data Protection

The Act, 2023.
Section 8, general obligations of a Data Fiduciary. Section 12, right to correction and erasure.
The Rules, 2025.
Notified 14 November 2025, with an eighteen-month phased compliance period. A separate, clear consent notice stating the specific purpose. Displayed contact details for personal-data queries. A maximum of ninety days to answer a request for access, correction, updating or erasure.

Two erasure obligations, not one.

12(3) is request-driven.
A Data Principal asks, and the data must be erased unless retention is necessary for the specified purpose or under law.
8(7) is event-driven.
No request involved. Erasure is owed when consent is withdrawn or the purpose is no longer served, whichever is earlier.

Most implementations treat erasure as a request queue, which satisfies 12(3) and misses 8(7) entirely. AssureNode evaluates both, separately, and records which obligation triggered each erasure. The purge itself executes only on human approval.

Why this page exists

The same obligation now lives in eight documents.

On 28 November 2025 the Reserve Bank restructured a substantial part of its rulebook into entity-class-specific Directions. Outsourcing risk became eight separate instruments. Digital banking channel authorisation was split the same way on the same day.

The obligations are close to identical. The instruments are not. The six-hour incident reporting obligation is paragraph 14 in the all India financial institutions Direction and paragraph 61 in the one for non-banking financial companies. Same obligation, same regulator, same day of issue, different entity class.

Six months earlier, the Digital Lending Directions, 2025 repealed the September 2022 Guidelines outright. The obligation survived almost unchanged. Every document citing the 2022 circular became wrong on the same day.

A control register maintained by hand does not notice either event. It keeps pointing at a repealed circular, or at the wrong entity class, and stays internally consistent while being externally wrong. Nothing fails. Nobody is alerted. The gap surfaces during an inspection.

That is why AssureNode binds every control to a clause in a named instrument, and why the binding is a versioned object rather than a footnote.

This page records the instruments AssureNode maps obligations against. It is a summary for orientation, not legal advice, and it is not a substitute for the instruments themselves. Regulations change; where a page here and a published instrument differ, the instrument governs.

Ask about an obligation we have not published yet.

A free scoping review. One obligation, one source system, two weeks.