25% of India Account Aggregator Framework (RBI) you already have
GDPR already covers about 25% of India Account Aggregator Framework (RBI), leaving
6 of 8 controls as genuinely new work.
Already covered 0
Likely covered 2
New work 6
No control in GDPR
maps directly to one in India Account Aggregator Framework (RBI). Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in GDPR reaches these. This is the list to scope.
RBI-AA-Audit-Logging-IT-System-Audit-Consent-Lifecycle-AuthenticationRBI AA Audit + Logging - IT System Audit + Consent Lifecycle Logging + Customer Authentication + Bi-Annual Audit + RBI Inspection + Sahamati Compliance Reporting
RBI-AA-CustomerProtection-Grievance-Redressal-Fees-Transparency-RBI-OmbudsmanRBI AA Customer Protection - Grievance Redressal Mechanism + Fee Transparency + RBI Integrated Ombudsman + Customer Awareness + Internal Grievance Officer + Sahamati Dispute Resolu
RBI-AA-IT-DataProtection-Transience-NoStorage-E2EE-DataLocalisation-IS-PolicyFrameworkRBI AA IT + Data Protection - Data Transience + No Storage at AA + End-to-End Encryption + Data Localisation in India + Information Security Policy + RBI IT Framework for NBFC-AA
RBI-AA-IncidentResponse-Resilience-RBI-CERT-In-BCP-DR-ContinuityRBI AA Incident Response + Resilience - Cyber Incident Reporting to RBI + CERT-In + Business Continuity + Disaster Recovery + Resilience + Customer Communication + Forensics
RBI-AA-Registration-Licensing-NBFC-AA-NetOwnedFunds-FitAndProper-MD2016RBI AA Registration + Licensing - NBFC-Account Aggregator (NBFC-AA) Category + Net Owned Funds + Fit and Proper Criteria + RBI Master Direction 2016 + Governance
RBI-AA-Sahamati-SRO-IndustryStandards-DPDPAct-RBI-CSF-Coord-DPI-IndiaStackRBI AA Sahamati SRO + Industry Standards + DPDP Act 2023 + RBI Cyber Security Framework + Coordination with DPI India Stack + Cross-Sector + International AA Equivalents
Show the 2 you already have
RBI-AA-ConsentArchitecture-ConsentArtefact-ExplicitConsent-PurposeLimitation-CustomerDashboard-ORS-CMPRBI AA Consent Architecture - Consent Artefact + Explicit Customer Consent + Purpose Limitation + Customer Consent Dashboard + Online Revocation Service + Consent Management Provid
RBI-AA-Ecosystem-FIPs-FIUs-Interoperability-Onboarding-Sahamati-DPI-IndiaStackRBI AA Ecosystem - Financial Information Providers (FIPs) + Financial Information Users (FIUs) + Interoperability + Sahamati SRO Onboarding + DPI India Stack + Cross-Sector Regulat
How this is calculated
Already covered means a mapping runs from a control in GDPR to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition