Not content marketing, field notes. What we learn running GRC programmes, breach clocks and board packs for regulated Indian businesses, written down.
The Rules were gazetted in November 2025 with a staggered clock. Here's what becomes enforceable when, and what to build first.
CCAPThe maths of point-in-time audits, and the operating model that replaces them.
RBI · SEBIWhat supervisors actually ask for, and how to render it without a reporting scramble.
VAPTWhy raw vulnerability counts mislead, and how a risk-based model gets remediation where it matters first.
40 points, ten obligation clusters, every item traced to the section or rule.
Download the checklist