RBI has placed trust on CERT IN empanelled Auditors…. But…Are we ready?

The Reserve Bank of India (RBI) has recently placed three transformational compliance responsibilities before banks:

  • Compliance with the Digital Personal Data Protection Act, 2023 (DPDPA);
  • Compliance with the RBI Guidance on Artificial Intelligence; and
  • Compliance with the Draft Guidance on Data Governance.

Each of these is significant by itself. Together, they redefine the manner in which banks are expected to govern information, deploy technology and demonstrate regulatory accountability.

Among these, one provision in the Data Governance Guidance deserves closer examination.

The draft guidance expects Regulated Entities (REs) to obtain independent audits from CERT-In empanelled auditors. At first glance, this appears to be a logical choice since CERT-In has, for many years, maintained a respected panel of Information Security Auditors.

However, an important question arises.

Is a Data Governance Audit merely an Information Security Audit under a different name?

The answer is No.

The Difference Between Security Audit and Data Governance Audit

Traditional Information Security Audits have largely focused on technical controls designed to preserve the Confidentiality, Integrity and Availability (CIA) of information assets.

A Data Governance Audit, on the other hand, is expected to examine issues such as:

  • Data ownership and stewardship;
  • Data quality and the concept of a Single Source of Truth (SSOT);
  • Regulatory compliance under DPDPA;
  • AI governance and algorithmic accountability;
  • Data lifecycle management;
  • Ethical use of data;
  • Board oversight and governance structures;
  • Documentation, policies and accountability mechanisms;
  • Risk management and evidence of compliance.

Many of these areas lie outside the traditional domain of cyber security.

An auditor may be an outstanding network security expert and still have limited exposure to privacy law, data governance frameworks, AI risk management or regulatory accountability.

The RBI guidance therefore represents not merely a new audit assignment, but the emergence of an entirely new professional discipline.

India Needs Independent Data Auditors

For several years, FDPPI has maintained that India requires a separate profession of Independent Data Auditors (IDAs).

The DPDPA already envisages independent data audits for Significant Data Fiduciaries. RBI’s guidance now reinforces the need for auditors who possess multidisciplinary expertise spanning:

  • Law
  • Technology
  • Data Governance
  • Privacy
  • AI Governance
  • Information Security
  • Risk Management
  • Audit Methodology

No single traditional discipline is sufficient.

Accordingly, FDPPI has developed an ecosystem for Independent Data Auditors with structured capability development through:

  • Probationary Independent Data Auditor (PIDA)
  • Accredited Independent Data Auditor (AIDA)
  • Certified Independent Data Auditor (CIDA)

The objective is not to replace cyber security auditors but to complement them by building competencies that today’s regulatory environment demands.

Data Audit is More Than Technical Compliance

One misconception that deserves correction is the assumption that compliance can be demonstrated merely by examining technical controls.

DPDPA compliance involves legal interpretation.

AI governance involves evaluation of explainability, accountability, human oversight, fairness and risk management.

Data governance involves organisational processes, ownership structures, metadata management, data quality and regulatory accountability.

None of these can be adequately assessed through vulnerability assessments, penetration testing or infrastructure reviews alone.

Consequently, India needs professionals who understand the convergence of law, governance and technology.

Time to Expand the CERT-In Ecosystem

CERT-In has performed an invaluable role in creating and nurturing India’s cyber security audit ecosystem.

The next logical evolution would be to broaden this ecosystem to accommodate professionals specialising in Data Governance and Data Protection.

One possible approach would be to establish an additional empanelment category specifically for Independent Data Auditors possessing recognised qualifications in data governance, privacy and AI governance.

Another equally important step would be to encourage existing CERT-In empanelled auditors to acquire these additional competencies through structured certification programmes.

Such an approach would strengthen—not dilute—the existing CERT-In framework.

Academic Rigor Matters

Professional certification cannot rely solely on experience.

It requires structured learning, objective assessment and continuous professional development.

Recognising this, FDPPI has entered into a collaboration with MYRA School of Business, Mysuru, an AICTE-accredited institution, to strengthen the academic foundation of Independent Data Auditor certifications.

The Certified Independent Data Auditor (CIDA) programme combines practical regulatory understanding with formal evaluation, thereby providing reasonable assurance regarding the competency of certified professionals.

Building India’s Data Governance Capacity

India is entering an era where Data Governance will become as important as Cyber Security.

The success of DPDPA implementation, trustworthy AI deployment and RBI’s regulatory expectations will depend not merely on issuing guidelines but on creating an ecosystem of competent professionals capable of evaluating compliance objectively and independently.

The regulatory framework has already begun evolving.

Professional capability must evolve with equal speed.

The challenge before India is therefore not whether Data Governance Audits should be conducted, but whether we have enough professionals who can perform them with the required multidisciplinary competence.

That is the conversation the industry must begin today.


P.S: 

FDPPI is conducting a three-day Certified Independent Data Auditor (CIDA) programme on 21–23 August 2026 at Fairfield by Marriott, Bengaluru. The programme covers DPDPA compliance, RBI’s AI Guidance, RBI’s Data Governance Guidance and the DGPSI framework for Data Governance and Protection. Professionals interested in developing expertise in this emerging discipline may visit www.aidai.org.in and www.naavi.org for further information.

Naavi

About Vijayashankar Na

Naavi is a veteran Cyber Law specialist in India and is presently working from Bangalore as an Information Assurance Consultant. Pioneered concepts such as ITA 2008 compliance, Naavi is also the founder of Cyber Law College, a virtual Cyber Law Education institution. He now has been focusing on the projects such as Secure Digital India and Cyber Insurance
This entry was posted in Privacy. Bookmark the permalink.