The Compliance Ledgercomplianceledger.in
FAQ · KNOWLEDGE BASE & REGULATORY PRIMER

Frequently Asked Questions

Key questions regarding The Compliance Ledger’s proactive AI audit methodology, Indian statutory jurisprudence (DPDPA 2023, RBI, CCPA), and the SutraCheck deterministic engine.

Showing all 12 questions
Mission & ScopeQ01

What is The Compliance Ledger and what is its primary purpose?

The Compliance Ledger is India's first open, evidence-qualified publication dedicated to proactive artificial intelligence gap analysis. We evaluate automated decision systems deployed in sensitive Indian sectors—such as credit underwriting, algorithmic hiring, clinical healthcare triage, and adaptive ed-tech—against binding Indian statutory law and open voluntary frameworks before algorithmic harms or enforcement actions occur.

Mission & ScopeQ02

How does The Compliance Ledger differ from global AI incident databases?

Existing global trackers, such as the AI Incident Database and MIT AI Risk Repository, document algorithmic failures retrospectively after harm has already occurred, and focus almost exclusively on US and European legal contexts (e.g., EU AI Act, FTC consent decrees). The Compliance Ledger evaluates Indian automated systems proactively before harm occurs, benchmarking public disclosures directly against domestic Indian statutes (DPDPA 2023, RBI Digital Lending Guidelines, Consumer Protection Act 2019) and the SutraCheck rubric.

Mission & ScopeQ03

Does The Compliance Ledger access proprietary model weights, training datasets, or source code?

No. All assessments are conducted strictly on publicly accessible, verifiable documentation—including published privacy policies, terms of service, developer APIs, regulatory filings, engineering whitepapers, and customer-facing disclosures. We evaluate what enterprises disclose to Indian citizens, consumers, and regulators under applicable transparency mandates.

Indian RegulationsQ04

Which Indian statutory frameworks does the Ledger benchmark automated systems against?

Evaluations benchmark against key statutory and technical governance frameworks: 1) The Digital Personal Data Protection Act (DPDPA 2023), specifically Section 5 consent notices, Section 6 purpose limitation, and Section 9 protections for minors; 2) The Reserve Bank of India (RBI) Digital Lending Guidelines (2022/2023), enforcing underwriting accountability and prohibiting unauthorized device telemetry scraping; 3) The Consumer Protection Act 2019 & CCPA Rules, targeting algorithmic unfair trade practices, hidden dark patterns, and automated customer lock-outs; alongside technical baselines such as 4) Telecommunications Engineering Centre Standard TEC 57090:2025 (AI Incident Database Schema & Taxonomy).

Indian RegulationsQ05

What is the distinction between "Binding Statutory Gaps" and "Voluntary Governance Gaps"?

To ensure legal defensibility and prevent false equivalence, The Compliance Ledger physically segregates evaluations into two distinct columns: Column 1 ("Binding Law") flags instances where public disclosures fail to substantiate compliance with mandatory Indian statutory requirements carrying direct legal penalties. Column 2 ("Voluntary Governance") tracks progressive industry benchmarks—such as demographic fairness parity, human-in-the-loop escalation workflows for borderline denials, and plain-language adverse decision explainability—derived from the open SutraCheck rubric.

Indian RegulationsQ06

How do DPDPA 2023 rules on children and minors affect automated recommendation systems?

Under Section 9 of the DPDPA 2023, Data Fiduciaries are strictly prohibited from undertaking behavioural tracking, targeted advertising, or algorithmic profiling directed at individuals under 18 years of age without verifiable parental consent. In sectors like EdTech and online platforms, systems that ingest student biometric data, attention metrics, or usage patterns without verifiable parental workflows are flagged for statutory non-compliance.

Deterministic EngineQ07

What makes SutraCheck’s evaluation engine deterministic rather than generative or LLM-based?

Unlike generative LLM-as-a-judge approaches that produce variable, non-repeatable opinions and hallucinate citations, SutraCheck uses a static Boolean rule-based runtime. It maps verified evidentiary facts directly to codified statutory triggers, producing identical classification outputs, matrix scores, and cryptographic SHA-256 verification hashes for identical inputs.

Deterministic EngineQ08

Why does The Compliance Ledger enforce standardized hedged language in all report findings?

To preserve journalistic objectivity and prevent defamatory assertions of illegality, all findings are formulated through a strict evidentiary template: "No public evidence found of [specific mechanism], as of [date], based on review of [source]." We report the verifiable absence or presence of public technical documentation rather than asserting conclusive legal guilt.

Deterministic EngineQ09

What are "Synthetic & Composite" audits, and why are they released prior to named entities?

Composite cases (such as Composite — Digital Lending) model archetypal AI deployments across Indian industries using synthesized, representative facts. They allow the research community and industry participants to inspect and stress-test the rubric's logic on messy real-world scenarios without prematurely naming individual corporations.

Process & Right of ReplyQ10

How does the mandatory 7-day pre-publication Right of Reply operate for audited companies?

Prior to publishing an audit of any named corporate entity, a draft copy of the gap analysis is formally delivered to the subject's designated Grievance Officer or legal counsel. The organization is granted 7 business days to submit factual corrections or updated public documentation. If verified, the report is amended accordingly, and the enterprise's formal statement is published alongside the audit verbatim.

Process & Right of ReplyQ11

How can organizations voluntarily request an opt-in evaluation under Feature 5?

Enterprises deploying automated decision systems in India can submit an evaluation request via our Feature 5 Opt-In Track at complianceledger.in/request. Our team verifies public documentation against the two-column matrix, providing an objective public benchmark of governance and compliance readiness that builds trust with regulators, enterprise clients, and end users.

Process & Right of ReplyQ12

How are post-audit fixes, remediation, and updated disclosures handled?

When an evaluated organization updates its public documentation, algorithms, or compliance policies, it can request a re-evaluation. Re-evaluations are recorded as dated revisions in the report's Version History table, ensuring an immutable, transparent historical record of the enterprise's compliance progression.

// Editorial & Audit Inquiries

Have a question regarding an AI deployment or audit in India?

Whether you are an enterprise deploying automated decision systems seeking an opt-in review, or a researcher with evidentiary questions, our team is available.