Indian MSMEs can reach RFP-ready AI compliance hygiene in 30 days: inventory personal data in training and inference, document lawful grounds, list subprocessors, ship immutable logs and human override for high-impact flows, and package a short annex for buyers. This is operational readiness — not a substitute for counsel on regulated deals.
You do not need a six-month “AI governance programme” to stop failing security questionnaires. You need a sprint with owners and artefacts. Use this beside the DPDP training guide, RFP questionnaire explainer, and MeitY framework news.
What Changed
- Enterprise buyers now expect DPDP + AI oversight evidence before pilots.
- MSMEs lose deals to missing tables, not missing ISO certificates.
- Chatbots and RAG on Indian customer data are the common blast radius — not giant foundation-model labs.
- Templates beat blank Notion pages: AI Compliance Starter Kit (₹999) and AI Readiness Audit (₹4,999).
- Track evolving instruments on the Policy Tracker.
The Details
Before day 1 — set the operating rules
| Rule | Why |
|---|---|
| One accountable owner | Committees without a named owner stall at vendor emails |
| 30-minute weekly standup | Surface blockers; do not reinvent governance theatre |
| Definition of done = annex + dry run | Policies without artefacts still fail RFPs |
| Counsel only for regulated / novel training | Hygiene first; legal opinion second |
Team size assumption: 5–15 people, one production chatbot or RAG product, selling to Indian enterprises.
Week 1 — Inventory and purpose (days 1–7)
Owner: Founder or Head of Product.
| Day | Task | Output |
|---|---|---|
| 1 | List every AI feature in prod/pilot | Feature inventory sheet |
| 2–3 | Mark personal fields in prompts, indexes, fine-tunes, logs | Draft data map |
| 4 | Write one purpose sentence per field; flag purpose creep | Purpose column filled |
| 5–6 | Draft/refresh customer notice covering model improvement + logging | Notice v1 |
| 7 | Review with eng; lock owners | Data map v1 signed |
Exit criteria: Spreadsheet or workspace board with stage → fields → purpose → owner.
Common miss: Treating embeddings as “not personal data” when the source text names customers. If free text can identify a person, map it.
Week 2 — Vendors and regions (days 8–14)
Owner: Engineering lead.
| Day | Task | Output |
|---|---|---|
| 8 | Email every model/API/observability vendor: train-on-inputs? region? delete SLA? | Vendor questionnaire sent |
| 9–10 | Build subprocessor table (API, vector DB, logs, email, support) | Table v1 |
| 11 | Document India-hosting options for BFSI/health prospects | Region notes |
| 12 | Ban “paste prod data into public ChatGPT” — redacted eval sets only | Team policy + sample set |
| 13–14 | Chase vendor replies; escalate missing DPAs | Subprocessor table v1.1 |
Exit criteria: Subprocessor table + named deletion contact.
Copy-ready vendor email (short):
We process Indian personal data in prompts/logs. Please confirm in writing: (1) whether you train on our inputs, (2) processing regions, (3) deletion SLA on request, (4) subprocessor list URL. Needed for enterprise DPDP diligence.
Week 3 — Oversight and logs (days 15–21)
Owner: Eng + ops.
| Day | Task | Output |
|---|---|---|
| 15 | Tier features: low (FAQ) vs high (credit, hiring, medical triage) | Risk tier table |
| 16–17 | High-tier: human review path, override, stop-the-model step | Runbook draft |
| 18 | Implement log fields in staging | Sample log line |
| 19 | Incident stub: who pages if model leaks personal data | On-call note |
| 20–21 | Drill kill switch once; fix gaps | Drill log + date |
Minimum log fields: model_version, prompt_hash, output_hash, reviewer_id, decision, ts_utc.
Exit criteria: Runbook Markdown/PDF + sample log line in staging + drill date.
If you sell into fintech, extend Week 3 with the RBI model-risk checklist — board MRMF language will show up in bank RFPs even when you are “only a vendor.”
Week 4 — RFP annex and dry run (days 22–30)
Owner: Founder + sales engineer.
| Day | Task | Output |
|---|---|---|
| 22–24 | Assemble 4–6 page annex for the eight RFP questions | Annex v1 |
| 25–26 | Dry-run with friendly security contact or internal red team | Punch list |
| 27–28 | Fix gaps; version annex | Annex v1.1 |
| 29 | Put quarterly review on calendar | Calendar invite |
| 30 | Optional: book AI Readiness Audit before a bank pilot | Scorecard request |
Cost band (desk estimate)
| Item | Low | High | Notes |
|---|---|---|---|
| Internal time (5–15 person team) | ₹25,000 | ₹80,000 | Mostly founder + eng lead hours |
| Compliance kit templates | ₹999 | ₹999 | AI Compliance Starter Kit |
| Readiness audit (optional) | — | ₹4,999 | AI Readiness Audit |
| External counsel (if regulated) | ₹50,000+ | Deal-dependent | BFSI/health/gov training on PII |
But here’s what others won’t tell you: Week 2 is where sprints die. Teams love Week 1 inventories and Week 3 architecture diagrams; they avoid calling vendors to ask “do you train on our prompts?” Put vendor emails on day 8, not day 28.
Failure modes (and fixes)
| Failure | Symptom | Fix |
|---|---|---|
| Inventory theatre | 40 features listed, zero owners | Cap to production + next pilot only |
| Vendor ghosting | Empty region column at day 14 | Default to “unknown — do not use for BFSI” until confirmed |
| Log theatre | Policy says logging; prod has none | Ship staging sample before writing the annex |
| Annex bloat | 40-page PDF, no tables | Cut to six artefacts; link policies |
| No drill | Kill switch exists on paper | Run one stop test; record date |
Copy-ready 10-point checklist
- AI feature inventory complete (prod + next pilot)
- Personal-data map for training + inference
- Purpose / ground documented per field
- Notices updated
- Subprocessor table with regions + review date
- Deletion owner named
- High-tier HITL + stop procedure drilled
- Log fields in staging
- Incident stub written
- RFP annex drafted, versioned, dry-runned
What This Means for Indian MSME Founders and CTOs
- Time-box 30 days with a single accountable owner — committee theatre fails.
- Buy templates (kit) instead of blank docs if your team is under 20 people.
- Do not wait for a final MeitY rulebook to start DPDP hygiene buyers already require.
- Reuse this sprint before every new AI feature launch — append rows, don’t restart.
- Escalate to counsel for BFSI/health/government personal-data training — see AI regulation guide.
- If you sell into fintech, extend Week 3 with the RBI model-risk checklist.
Frequently Asked Questions
Can an MSME finish AI compliance hygiene in 30 days?
Yes for operational hygiene — data map, notices, logging, vendor list, and HITL for high-tier flows. Regulated BFSI/health programmes and full legal opinions take longer and need counsel.
What does a 30-day AI compliance sprint cost?
IndiaAIBrief desk estimate: ₹25,000–₹80,000 in internal time for a 5–15 person product team, plus ₹999–₹4,999 if you use our kit or readiness audit — before external counsel.
Do we need MeitY registration to start the sprint?
No. Start with DPDP purpose mapping and oversight controls buyers already ask for. Track MeitY instruments on the Policy Tracker as they firm up.
What is the minimum deliverable after 30 days?
A living data map, subprocessor table, log field list, human-override runbook for high-risk flows, and a 4–6 page RFP annex you can reuse.
Who should own the sprint if we have no compliance hire?
Name one accountable owner (usually founder or Head of Product) with Eng lead as co-owner for vendors/logs. A rotating “AI ethics committee” without a single owner fails Week 2.



