FilterPrompt — AI Firewall logo

ISO/IEC 42001, India's DPDP Act, DORA and the Global Push for Auditable AI Security

Regulation · 2025-01-14 · 10 min read · FilterPrompt Compliance Team

AI governance is not a U.S.- or EU-only story. ISO 42001, India's DPDP Act, the EU's DORA and UK / Singapore / Brazil guidance converge on the same three demands — here's the one program that covers all of them.

AI governance is not a U.S.- or EU-only story. Certification bodies and national regulators worldwide are converging on the same three demands: documented risk management, technical evidence of testing, and continuous monitoring after deployment. The vocabulary changes; the underlying control does not.

ISO/IEC 42001 — the ISO 27001 of AI

Published in December 2023, ISO/IEC 42001 specifies the requirements for establishing, implementing, maintaining and continually improving an AI Management System (AIMS). Annex A lists the controls — including AI risk assessment (A.6), data quality (A.7), AI system lifecycle (A.6.2), and information for interested parties (A.8). Certification requires an accredited audit; auditors ask for the same shape of evidence they ask for under ISO 27001: policies, records, and — critically — technical test results.

India's DPDP Act — GDPR-shaped, AI-relevant

The Digital Personal Data Protection Act 2023 applies to processing of digital personal data of individuals in India. It requires purpose limitation, security safeguards 'to prevent personal data breach', breach notification to the Data Protection Board, and — for Significant Data Fiduciaries — data protection impact assessments and periodic audits. An LLM ingesting Indian customers' data falls squarely inside this. The Section 8(5) 'reasonable security safeguards' language is the hook that pulls continuous LLM vulnerability scanning into scope.

DORA — AI-driven finance in the EU must be operationally resilient

The Digital Operational Resilience Act (Regulation (EU) 2022/2554), applicable from January 2025, requires EU financial entities to have an ICT risk-management framework, threat-led penetration testing (TLPT), and third-party risk oversight. Where an AI or LLM component sits in a critical or important function, DORA's testing and monitoring obligations extend to it — including the ICT third-party providers of the model.

The common pattern — and why one program is enough

  1. Every framework asks for the same three things in different words: assess risk, test continuously, keep auditable records.
  2. Certifiable standards (ISO 42001, ISO 27001) give assessors a checklist; binding laws (DPDP, EU AI Act, DORA) give regulators enforcement power.
  3. A single technical control — continuous prompt/response scanning with structured logging, mapped to OWASP LLM Top 10 and MITRE ATLAS — can generate evidence usable across nearly all of these regimes.
  4. For multinational organizations, build one continuous AI security testing program, then cross-reference the output against whichever regional law or standard an auditor asks about — rather than one program per jurisdiction.

Vulnerability categories every global program should cover

Related