Skip to main content
🪔 Dharma Governance

Dharma Governance documents

Governance & compliance framework charter, board governance posture, adopted frameworks (DPDP, ISO 27001, SOC 2, CARO), risk ownership and the policy stack.

Governance and Compliance Framework Charter

BETA

Board-approved governance and compliance charter with full global frameworks register. ISO certifications (27001, 27701, 27017, 27018, 42001, 9001, 22301, 20000, 14001), SOC 1/2/3, 19 privacy regimes (DPDP, GDPR, UK GDPR, CCPA, LGPD, Singapore PDPA, UAE PDPL, Saudi PDPL, Qatar, Bahrain, Egypt, Morocco, POPIA, Kenya, Nigeria, Ghana, Australia, Japan APPI, Canada PIPEDA), and sector frameworks (PCI DSS, HIPAA, NIST CSF, NIS2, DORA, EU AI Act, GLBA, CMMC, FedRAMP, APRA CPS 234, RBI, Cyber Essentials, FCA Resilience, POSH), plus governance bodies, risk ownership, policy stack and review cadence.

DPDP Data-Protection Readiness Assessment

BETA

Self-assessment of readiness under the Digital Personal Data Protection Act, 2023, covering data inventory, lawful basis and consent, data-principal rights, retention, cross-border transfers, breach response and processor agreements, with a readiness score and a gap list.

AI Use and Governance Policy

BETA

Board-approved policy governing how the organisation builds and uses AI: an AI inventory, EU AI Act risk classification, human oversight, transparency, data governance, prohibited uses, accountability and review. Aligns to the EU AI Act, NIST AI RMF and ISO/IEC 42001.

Incident Response Plan

BETA

A board-approved incident response plan: severity tiers, roles, detection, containment and recovery, and regulator and data-principal notification timelines (GDPR 72 hours, India CERT-In 6 hours, DPDP breach reporting). Supports ISO 27001, SOC 2 and DPDP readiness.

Risk Register

BETA

A board-ready risk register with impact and likelihood scoring, treatment, owner and review cadence, plus a computed risk heat summary. Supports ISO 31000, ISO 27001 and SOC 2 risk-assessment requirements.

Data Retention Schedule

BETA

A data retention and disposal schedule: record types, categories, retention periods, lawful basis and disposal method. Supports the storage-limitation principle under GDPR and the erasure duty under the DPDP Act, plus ISO 27001 records control.

Business Continuity Plan

BETA

A business continuity and disaster recovery plan: critical functions, recovery objectives (RTO and RPO), backups, alternate site, and testing. Aligns to ISO 22301 and supports SOC 2 availability and DORA resilience expectations.

Acceptable Use Policy

BETA

An acceptable use policy governing how staff and contractors use the organisation's systems, devices and data: permitted and prohibited use, BYOD, monitoring notice and enforcement. Supports ISO 27001 acceptable-use control and SOC 2 access expectations.

Access Control Policy

BETA

A policy governing logical and physical access to systems and data: least privilege, role-based access, multi-factor authentication, joiner-mover-leaver, privileged access and access reviews. Aligns to ISO 27001 A.5.15 to A.5.18 and SOC 2 CC6.

Data Classification and Handling Policy

BETA

A policy that defines data classification levels and the handling, storage, sharing and disposal rules for each. Aligns to ISO 27001 information classification (A.5.12 and A.5.13) and supports DPDP and GDPR data-handling obligations.

Change Management Policy

BETA

A policy governing how changes to systems, infrastructure and software are requested, reviewed, tested, approved, released and rolled back, including emergency changes. Aligns to SOC 2 CC8 and ISO 27001 change-control expectations.

Statement of Applicability (ISO 27001)

BETA

The ISO 27001 Statement of Applicability, assessed control-by-control across all 93 ISO/IEC 27002:2022 Annex A controls — applicability, justification, and recorded exclusions. A mandatory ISMS document under ISO 27001 clause 6.1.3.

Logging and Monitoring Policy

BETA

A policy for logging and monitoring system and access activity: what is logged, log protection and retention, monitoring and alerting, and review. Aligns to ISO 27001 logging controls, SOC 2 monitoring (CC7) and PCI DSS logging.

Vulnerability Management Policy

BETA

A policy for identifying, prioritising and remediating vulnerabilities: scanning, patching cadence, severity-based remediation SLAs and penetration testing. Aligns to ISO 27001, SOC 2 and PCI DSS vulnerability requirements.

Asset Management Policy

BETA

A policy for managing information and technology assets: inventory, ownership, classification, acceptable use, secure configuration and end-of-life disposal. Aligns to ISO 27001 asset-management controls and SOC 2.