FDPPI opens a new Vision of Data Audit

As part of the new developments in FDPPI, a new system of Data audit for large organizations involving multiple Branch units has been introduced.

Many major Banks like Canara Bank and SBI have already announced substantial investments in software for compliance. Many of them have also engaged the services of Big4 auditing agencies.

We are aware that neither the software companies nor the Big4 audit firms have fully integrated the concepts that FDPPI is proposing. They may also defend their current software or systems as adequate for organizations like SBI or Canara Bank.

We at FDPPI have however decided that such enterprise level audits have to follow the model of  “Aggreagtion of Branch level Audits” . FDPPI has prepared its audit system for this purpose and introduced the standard procedures to make such audits to be conducted on a common standard and under a common organizational control of AIDAI.

AIDAI has actually published a new Code of Ethics for its empanelled Data Auditors which incorproates the principles of Lead Enterprise Data Auditor and Compenent Data Auditors.

We expect the Big4 to follow suit.

We hope the Banks posess the necessary knowledge to ask the right questions with their consultants to ensure that they are not finalizing compliance decisions solely because the audit is being performed by an organization which has large turnover. Going by some of the developments at NABARD and Bank of Baroda, it is difficult to be confident that there is a satisfatory level of understanding of the DPDPA problem at some of these Banks before they entered into multi crore contracts at public cost.

It will be after 2 years that we will be reviewing the effectiveness of the current decisions made by these Banks when customer complaints may  start showing up at DPB.

Many of these banks may require “Peer Audit” either before completing their exercise of initial audit before 13th May 2027 or there after.

AIDAI/FDPPI however believes that we need to build a strong army of data auditors who can undertake the audits of multiple compliance units which can be aggregated into an enterprise level audit.

We are also conducting a specific training program to introduce the framework AIDAI-SOP-DA 600 and the modified Code of Ethics in our special Jnaana Vardhini session on 16th September 2026.

These will be the standards for the future and defining the course of DPDPA Compliance in India.

Naavi

(Comments are welcome)

 

About Vijayashankar Na

Naavi is a veteran Cyber Law specialist in India and is presently working from Bangalore as an Information Assurance Consultant. Pioneered concepts such as ITA 2008 compliance, Naavi is also the founder of Cyber Law College, a virtual Cyber Law Education institution. He now has been focusing on the projects such as Secure Digital India and Cyber Insurance
This entry was posted in Privacy. Bookmark the permalink.