India AI rules mapped to ISO/IEC 27001
Each row is one legal duty recorded for India and the clause of ISO/IEC 27001:2022 it corresponds to. Use it to find which duties your existing evidence already reaches.
Coverage of this crosswalk
1 of 4 recorded India duties carry a mapping
The denominator is the number of duties this platform has broken out for India, not the number of duties the law contains. Unmapped duties are ones no reviewer has crosswalked yet, not ones the standard fails to address.
The mapping
| Legal duty | Binding? | ISO/IEC 27001 clause | Why they correspond | Confidence |
|---|---|---|---|---|
| Implement reasonable security safeguards and notify breaches India DPDP Act, Section 8(5) and 8(6); DPDP Rules on breach intimation | Legal requirement | Annex A incident management controls | Original editorial mapping. | medium |
What a mapping means
The duty and the clause ask for overlapping work, so evidence produced for one is likely to be reusable for the other. Confidence records how direct that overlap is.
What it does not mean
ISO/IEC 27001 certification does not discharge a legal duty and carries no force in India. A mapped row still has to be complied with on the statute's own terms.
Instruments in this crosswalk
- India DPDP Act — India
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Does ISO/IEC 27001 certification satisfy India AI rules?
- No. ISO/IEC 27001 is a certifiable management system standard and carries no legal force in India. This crosswalk records that 1 of the 4 duties tracked here have a corresponding clause, which means the evidence may be reusable, not that the duty is discharged.
- How many India AI duties map to ISO/IEC 27001?
- 1 of 4 duties recorded for India carry a mapping to ISO/IEC 27001:2022.