Skip to main content
🛡️ Compliance

Compliance documents

DPDP, Vendor DPA, InfoSec, AML/KYC, anti-bribery, whistleblower, consumer-protection notices.

Vendor DPA

BETA

Data Processing Agreement between a Data Fiduciary and its Data Processor. Compliant with India's DPDP Act 2023 and optionally EU GDPR Article 28. Covers sub-processors, security measures, breach notification, and audit rights.

Information Security Policy

BETA

Information Security Policy aligned with ISO 27001:2022 and SOC 2 Trust Services Criteria. Covers access control, asset management, incident response, BCDR, cryptography, and security awareness.

HIPAA Security Rule Policy

BETA

Security policy for electronic protected health information aligned to the HIPAA Security Rule, 45 CFR Part 164 Subpart C.

HIPAA Notice of Privacy Practices (NPP)

BETA

HIPAA Notice of Privacy Practices (NPP) for a covered entity under the HIPAA Privacy Rule, 45 CFR §164.520. Describes how protected health information (PHI) is used and disclosed, uses requiring authorization, individual rights, the entity's duties, and how to complain to the entity and to HHS OCR.

HIPAA Business Associate Agreement (BAA)

BETA

HIPAA Business Associate Agreement between a Covered Entity and a Business Associate under 45 CFR §164.502(e) and §164.504(e). Covers permitted and required uses and disclosures of PHI, safeguards including Security Rule compliance for ePHI, breach and security-incident reporting, subcontractor flow-down, individual access/amendment/accounting support, HHS access, and return or destruction of PHI on termination.

HIPAA Breach Notification Policy

BETA

HIPAA Breach Notification Policy aligned with the HIPAA Breach Notification Rule (45 CFR §§164.400–414). Covers the definition of breach and its exceptions, the four-factor risk assessment, notification to individuals, HHS, and media, business-associate reporting, and the documentation and burden-of-proof requirements.

AI Management System (AIMS) Policy — ISO/IEC 42001:2023

BETA

AI Management System (AIMS) Policy aligned with ISO/IEC 42001:2023. Establishes a full management system — not a plain AI-use policy — covering the AI policy and objectives, context and interested parties, leadership and roles, AI risk management and the AI system impact assessment process (Clause 6.1.4 / Annex A.5, guided by ISO/IEC 42005), the Annex A control areas (A.2–A.10), responsible-AI principles, and continual improvement. Optionally aligns to the EU AI Act and NIST AI RMF.

AI System Impact Assessment (AIIA)

BETA

AI System Impact Assessment record aligned with ISO/IEC 42001:2023 (Clauses 6.1.4 and 8.4) and ISO/IEC 42005:2025 guidance. Documents system description, intended purpose, affected individuals and groups, potential harms (bias, safety, privacy, security, transparency, autonomy, environmental), likelihood and severity, mitigations, human oversight, residual impact and the acceptability decision. Supports EU AI Act fundamental-rights and conformity context.

AI System Inventory & Register

BETA

Central register of every AI system with owner, provider, EU AI Act risk tier, impact-assessment status and review dates.

Threat Intelligence Policy

BETA

Governs how the organisation collects, analyses and disseminates cyber threat intelligence, aligned to ISO/IEC 27001:2022 Annex A control 5.7.

Information Security in Project Management Policy

BETA

Policy for embedding information security into every project, aligned with ISO/IEC 27001:2022 Annex A 5.8. Covers security-by-design from initiation, per-project risk assessment, security requirements and acceptance criteria at project gates, roles, and post-project review.

Configuration & Hardening Management Policy

BETA

Configuration & Hardening Management Policy aligned with ISO/IEC 27001:2022 Annex A 8.9 (new control), SOC 2 CC7.1, and PCI DSS Requirement 2. Covers secure baseline configurations, hardening standards (CIS Benchmarks), configuration control and approval, drift detection and monitoring, documentation and inventory, and periodic review.

Data Masking, Deletion & Loss Prevention Standard

BETA

A control standard covering secure information deletion, data masking / pseudonymisation / anonymisation for non-production and display, and data leakage prevention across email, web, endpoint and cloud. Maps to ISO/IEC 27001:2022 A.8.10, A.8.11 and A.8.12, SOC 2 CC6.7 and the DPDP Act, 2023.

Capacity Management Policy

BETA

Capacity Management Policy aligned with ISO/IEC 27001:2022 A.8.6 (Capacity management) and SOC 2 Availability (A1.1). Covers monitoring of compute, storage, network and personnel capacity; forecasting and trend analysis; utilisation thresholds and alerting; performance tuning and scaling (including auto-scaling); and linkage to availability RTO/RPO targets and the Business Continuity Plan.

Legal, Regulatory & Contractual Requirements Register

BETA

A living register of the legal, statutory, regulatory and contractual requirements the organisation must meet, aligned with ISO/IEC 27001:2022 controls A.5.31–A.5.34. India-first coverage of the DPDP Act 2023, IT Act 2000 with CERT-In Directions, Copyright Act 1957, and sectoral rules, plus GDPR where operating abroad.

Access Provisioning (Joiner-Mover-Leaver) Procedure

BETA

Joiner-Mover-Leaver access lifecycle procedure covering approval-based provisioning, role changes, SLA-bound de-provisioning, least privilege, privileged access, recertification and break-glass.

Authentication & Password Standard

BETA

A modern authentication and password standard aligning credential, MFA, session and account controls to ISO 27001, SOC 2, PCI DSS v4.0.1 and NIST SP 800-63B.

Endpoint & Anti-Malware Policy

BETA

Endpoint hardening, EDR/anti-malware, disk encryption, patch SLAs, MDM/BYOD and removable-media controls mapped to ISO 27001, SOC 2 and PCI DSS.

Network Security Policy

BETA

Network segmentation and trust zones, default-deny firewalls / network security controls reviewed every six months, secure remote access and VPN, wireless security, DMZ, web/DNS filtering and IDS/IPS aligned to ISO 27001 A.8.20–A.8.23, SOC 2 and PCI DSS.

Security Awareness & Training Programme

BETA

Formal security awareness, competence and role-based training programme with phishing simulations, completion tracking, attestation and sanctions, mapped to ISO 27001, SOC 2 and PCI DSS.

Information Security Risk Management Methodology

BETA

Information Security Risk Management Methodology defining risk and acceptance criteria, an asset/threat/vulnerability approach, 5x5 likelihood and impact scales, risk ownership, treatment options and the link to the Statement of Applicability and Risk Treatment Plan. Aligned with ISO/IEC 27001:2022 Clause 6.1.2 and SOC 2 CC3.1-CC3.4.

Information Security Objectives Register

BETA

A controlled register of SMART, measurable information security objectives set at relevant functions and levels, each with an owner, metric/KPI, baseline, target, deadline, resources, monitoring method and status — linked to the Information Security Policy and risk-assessment results per ISO/IEC 27001:2022 Clause 6.2.

Information Security Roles, Responsibilities & RACI

BETA

Defines the information security governance structure, role-by-role responsibilities, a RACI matrix for key security activities, and segregation-of-duties principles. Aligned with ISO/IEC 27001:2022 Clause 5.3, Annex A.5.2 & A.5.3, and SOC 2 CC1.3.

ISMS Monitoring, Measurement & Metrics Report

BETA

Periodic monitoring, measurement, analysis and evaluation report for an Information Security Management System, aligned with ISO/IEC 27001:2022 Clause 9.1 and SOC 2 CC4.1. Presents the security metrics programme — what is measured, method, frequency, owner — and a target-vs-actual metrics table with trend and analysis for management review.

Documented Information Control Procedure

BETA

ISMS procedure governing how documents and records are identified, versioned, approved, distributed, classified, retained and retired, aligned to ISO/IEC 27001:2022 Clause 7.5.

Personnel (HR) Security Policy

BETA

Human Resources security policy covering the full employment lifecycle — pre-employment background verification, security terms of employment, onboarding, disciplinary process, offboarding, post-employment obligations, and contractor screening. Aligned with ISO/IEC 27001:2022 people controls, SOC 2, and PCI DSS.

Continuous Control Monitoring & Deficiency Management Policy

BETA

Defines how the organisation continuously monitors internal controls, classifies deficiencies by severity, and tracks remediation to closure under SOC 2 CC4.1 and CC4.2.

PCI DSS CDE Scope & Data-Flow

BETA

Defines the cardholder data environment, in-scope system components, account-data flows and the annual PCI DSS scoping-confirmation process.

PCI DSS SAQ Selector & Attestation of Compliance (AOC) Record

BETA

Determines the correct PCI DSS v4.0.1 Self-Assessment Questionnaire type and produces a merchant Attestation-of-Compliance style record.

Cryptography & Key Management Policy

BETA

Approved algorithms, full key lifecycle, HSM/KMS storage, rotation, split knowledge and dual control, and certificate management aligned to ISO 27001 A.8.24, SOC 2 and PCI DSS.

Secure Development (Secure SDLC) Policy

BETA

Secure Software Development Lifecycle (Secure SDLC) Policy aligned with ISO 27001:2022 A.8.25–A.8.31, SOC 2 CC8.1, and PCI DSS v4.0.1 Req 6.2–6.3. Covers threat modelling, secure coding (OWASP Top 10), SAST/DAST/SCA, code review, dependency and patch management, environment separation, change approval, and use of production data in test.

Supplier & Third-Party Security Policy

BETA

Supplier & Third-Party Security Policy aligned with ISO 27001:2022 (A.5.19-A.5.23), SOC 2 CC9.2, and PCI DSS v4.0.1 Req 12.8. Covers supplier risk tiering, due diligence, security clauses, DPAs, right-to-audit, SOC 2/ISO evidence, ongoing monitoring, and offboarding.

Physical & Environmental Security Policy

BETA

Physical zones, access control, visitor management, CCTV, environmental controls, media handling and secure disposal — aligned to ISO 27001 A.7, SOC 2 CC6.4/CC6.5 and PCI DSS Req 9.

Information Backup Policy

BETA

Information Backup Policy aligned with ISO 27001:2022 A.8.13, SOC 2 Availability (A1.2), and PCI DSS v4.0.1 Req. 12.10. Covers backup scope, the 3-2-1 rule, encryption, geographic separation, retention, restore-testing cadence, RTO/RPO alignment, and immutability / ransomware protection.

ISMS Scope Statement

BETA

Documented ISO 27001 scope statement defining ISMS boundaries, context, interested parties, interfaces and justified exclusions.

Risk Treatment Plan

BETA

ISO 27001 risk treatment plan linking the risk register and SoA to per-risk treatment options, Annex A controls, owners, target dates and residual-risk sign-off.

ISMS Internal Audit Report

BETA

ISO/IEC 27001:2022 Clause 9.2 internal audit report recording scope, methodology, classified findings, per-clause and Annex A results, conclusions and the link to corrective action.

ISMS Management Review Minutes

BETA

Minutes of the top-management review of the ISMS, capturing the mandatory Clause 9.3.2 inputs and 9.3.3 decisions as audit evidence.

Nonconformity & Corrective Action (CAPA) Register

BETA

A controlled register recording each ISMS nonconformity, its root cause, correction, corrective action, owner, due date and effectiveness verification.

CERT-In Incident Reporting SOP

BETA

Standard Operating Procedure for mandatory 6-hour cyber incident reporting to CERT-In under s.70B(6) IT Act 2000 (Directions dated 28.04.2022).

SOC 2 System Description

BETA

Management's Description of the System for a SOC 2 report, built to the AICPA 2018 Description Criteria (DC section 200, DC1-DC9, with revised implementation guidance 2022). Covers services, service commitments and system requirements, the five system components, boundaries, control environment, the applicable Trust Services Criteria, system incidents, complementary user-entity controls (CUECs), subservice organisations (carve-out / inclusive) and CSOCs.

DPDP Privacy Notice

BETA

Privacy Notice compliant with the Digital Personal Data Protection Act, 2023 (DPDP Act). Covers categories of data collected, purposes, consent, data principals' rights, and grievance redressal.

GST Tax Invoice

BETA

GST-compliant tax invoice for supply of goods or services. Covers B2B and B2C transactions, IGST (inter-state) and CGST+SGST (intra-state), HSN/SAC codes, reverse charge mechanism, and e-invoicing IRN/QR code fields. Mandatory fields as per CGST Rules 2017 Rule 46.

Professional Tax — Employer Monthly Working

BETA

Monthly professional tax deduction working sheet and challan summary for employers. Covers all major PT states — Maharashtra, Karnataka, West Bengal, AP/Telangana, Tamil Nadu, Gujarat, MP, Odisha, Kerala — with applicable salary slabs, deduction amounts, and payment due dates. Includes employee-wise register and Form III / annual return reference.

Form 16 — Salary TDS Certificate Working

BETA

Form 16 working sheet — TDS certificate for salary income. Covers Part A (TDS deducted and deposited quarter-wise, TRACES-generated data) and Part B (detailed income computation: gross salary, exemptions, deductions, taxable income, tax under old and new regime). Mandatory issuance by employer by 15 June each year.

Bank Balance Confirmation Letter

BETA

External confirmation letter requesting a bank to verify an entity's account balances, loan facilities and securities held, sent directly to the statutory auditor following the external-confirmation procedures in Standard on Auditing (SA) 505.

Creditors Balance Confirmation Letter

BETA

External confirmation letter asking a supplier (creditor) to confirm the balance payable by the entity directly to the auditor, supporting verification of trade payables under Standard on Auditing (SA) 505.

Debtors Balance Confirmation Letter

BETA

External confirmation letter asking a customer (debtor) to confirm the balance receivable by the entity directly to the auditor, supporting verification of trade receivables under Standard on Auditing (SA) 505.

Audit Planning Memorandum

BETA

Audit planning memorandum recording the overall audit strategy, assessed risk areas, materiality thresholds, timelines and team responsibilities for a statutory audit, in line with the risk-based planning approach set out in the Standards on Auditing.

Statutory Audit Report

BETA

Independent statutory auditor's report on a company's financial statements, expressing the audit opinion and reporting the matters required under Section 143 of the Companies Act, 2013 and the applicable Standards on Auditing.

CARO 2020 Checklist and Report

BETA

Working checklist mapping each clause of the Companies (Auditor's Report) Order, 2020 (CARO 2020) to the auditor's verification steps and comments, helping ensure the statutory audit report addresses every reporting matter the Order requires.

Management Representation Letter

BETA

Management representation letter in which a company's management confirms in writing to its auditors its responsibility for the financial statements and the completeness of the information provided, as contemplated by Standard on Auditing (SA) 580.

Compliance Baseline Checklist / Report

BETA

Annual compliance baseline checklist and report for corporate governance and statutory compliance tracking