The Compliance Ledgercomplianceledger.in
Institutional Document // Compliance Ledger

Subject Selection & Review Methodology

The formal operational criteria governing how The Compliance Ledger chooses, evaluates, and publishes proactive AI gap analysis reports in India.

Effective: September 2026·Verified Public Record

1. Purpose and Guiding Principle

The Compliance Ledger is a proactive, public AI-compliance gap-analysis publication. Our mission is to evaluate automated decision-making and machine learning systems against Indian statutory law and open voluntary frameworks before systemic failures or consumer harms occur.

To preserve legal defensibility, journalistic integrity, and research objectivity, all review subjects are selected according to a strict, non-discriminatory public methodology. We do not engage in selective targeting, commercial retaliation, or punitive investigations.

Every report published by The Compliance Ledger strictly adheres to three foundational selection filters:

  1. Domain Sensitivity & Impact Severity
  2. Sufficiency of Public & Verifiable Evidence
  3. Relevance to Current Regulatory Moments

2. Criterion 1 — Domain Risk Classification

We prioritize sectors where automated algorithmic determinations directly impact fundamental consumer rights, economic livelihoods, physical well-being, or equal opportunity.

The Compliance Ledger restricts its audit pipeline to four high-risk sectors:

Sector High-Risk Algorithmic Vectors Applicable Regulatory Frameworks
Retail Lending & Credit Scoring Automated underwriting, alternative telemetry scoring, straight-through rejections RBI Digital Lending Guidelines, CPA 2019, DPDPA 2023
HR & Recruitment Automation Automated CV filtering, video interview sentiment analysis, ranking algorithms Equal Remuneration Act, DPDPA 2023, Fundamental Rights (Art 14/16 principles)
Healthcare Diagnostic & Triage AI Symptom triage bots, radiological classification, patient prioritization Medical Devices Rules, Telemedicine Guidelines, Clinical Establishments Act
Ed-Tech & Automated Assessment Automated exam proctoring, student ranking, adaptive qualification gates UGC Online Education Regulations, DPDPA 2023 (Children’s Data Protection)

Entities outside these four priority sectors are not reviewed unless they enter via our Feature 5 Opt-In Review Track.


3. Criterion 2 — Sufficiency of Public & Verifiable Evidence

A fundamental legal safeguard of The Compliance Ledger is that we never rely on leaks, unauthorized system breaches, or conjecture about internal black-box architecture.

An entity is only eligible for review if sufficient public documentation exists in the public domain, specifically:

  • Published Privacy Policies & Terms of Service: Providing itemized disclosures of data collection, processing purposes, and grievance officers.
  • Official Engineering Blogs & Whitepapers: Published by the company’s technical teams describing model families, training datasets, and inference pipelines.
  • Public Job Postings & Patent Filings: Providing verifiable disclosures of the algorithmic tools, libraries, or vendor systems integrated into their stack.
  • Regulatory Filings & Disclosures: Public lists of partners, Regulated Entities (REs), and certified compliance certifications.

If a company’s public footprint is insufficient to verify its algorithmic pipeline objectively, we will not publish a named report.


4. Criterion 3 — Relevance to Current Regulatory Moments

Audits are sequenced to coincide with active regulatory developments in India:

  • The ongoing operationalization of the Digital Personal Data Protection Act (DPDPA 2023) rules.
  • Scrutiny by the Central Consumer Protection Authority (CCPA) regarding algorithmic transparency, dark patterns, and automated customer lock-out.
  • Industry implementation of the Telecommunications Engineering Centre (TEC) AI Incident Database Standard (TEC 57090:2025).
  • Reserve Bank of India (RBI) digital lending and algorithmic audit directives.

5. Structural Guardrails & Defensibility Rules

Every report generated under this methodology is bound by five non-negotiable rules:

Rule 1: The Hedged Language Mandate

Bare assertions of illegality (e.g., “Company X violates the law”) are strictly prohibited by our template schema. All observations must be phrased as:

“No public evidence found of [specific mechanism], as of [date], based on review of [source].”

We strictly maintain separate evaluation tracks. Conflating voluntary adherence to the SutraCheck framework with a violation of binding Indian law is methodologically prohibited.

Rule 3: Mandatory Pre-Publication Right of Reply (7-Day Window)

Before any named corporate entity’s gap analysis is published, a draft is transmitted to their designated grievance officer or communications counsel. The entity is granted a minimum of 7 business days to submit corrections, clarifications, or evidence of updated public disclosures. Any verified response is published verbatim alongside the report.

Rule 4: Synthetic & Composite Staging

Prior to auditing named entities, the Ledger releases anonymized Composite Cases (e.g., Composite — Lending). This stress-tests the rubric and validates our scoring logic against messy real-world practices without premature reputational exposure.