Resources

Guides for building a modern risk & compliance program.

Practical playbooks on compliance frameworks, third-party risk and operational resilience, written for the people who actually run these programs.

Filter
Featured guide

SEBI CSCRF Readiness Assessment: How to Know You're Ready

ComplianceSEBI CSCRF

Before the deadline and before the auditor, you need to know where you actually stand. A readiness assessment is the honest gap-check against CSCRF for your category. Here's how to run one, including a self-assessment you can use today.

10 min readRead guide
Operational ResilienceRBI Guidelines

RBI Operational Resilience: The Guidance Note Explained

In 2024 the RBI raised the bar from managing operational risk to proving operational resilience: the ability to keep delivering critical services through disruption. Here's what the Guidance Note asks of banks and NBFCs, and how to meet it.

11 min read
ComplianceDPDPA

DPDPA for Fintechs: What the Law Requires of You

Fintechs sit at the sharp end of the DPDPA: high volumes of sensitive personal and financial data, likely Significant Data Fiduciary status, and obligations that sit on top of RBI, SEBI and PCI. Here's what the law actually asks of you.

11 min read
ComplianceSEBI CSCRF

SEBI CSCRF Incident Response and Reporting Requirements

Under CSCRF, how you handle and report an incident is itself a compliance obligation. Late or missing reports are a violation in their own right. Here's what a compliant response and reporting process looks like.

11 min read
ComplianceSEBI CSCRF

SEBI CSCRF Audit and VAPT Requirements

CSCRF does not take your word for it. It builds in independent assurance through cyber audits, VAPT and, for larger entities, a Cyber Capability Index. Here's what each involves and how often.

11 min read
ComplianceSEBI CSCRF

SEBI CSCRF Timelines and Deadlines: How to Find Yours

There isn't one SEBI CSCRF deadline. Dates have been phased and revised, and yours depends on your entity type and category. Here's how to find your date and plan back from it.

9 min read
ComplianceSEBI CSCRF

SEBI CSCRF Logging and SOC Requirements Explained

CSCRF's detect function turns logging and a SOC from nice-to-haves into obligations. Here's what to log, how long to keep it, the SOC coverage expected of your category, and the Market SOC option for smaller entities.

11 min read
ComplianceDPDPA

DPDPA Consent Requirements: What Valid Consent Looks Like

Under the DPDPA, a banner and a stored flag are not enough. Consent has to be free, specific, informed and unambiguous, as easy to withdraw as to give, and provable on demand. Here is exactly what the law requires and how to operationalise it.

11 min read
ComplianceRBI Guidelines

RBI Information System Audit: What Banks & NBFCs Need to Know

For banks and NBFCs, the Information System Audit isn't optional, RBI mandates an independent, periodic audit of your IT ecosystem, with board oversight and tracked remediation. Here's what it covers and how to walk in ready.

10 min read
ComplianceSEBI CSCRF

Data Localisation Under SEBI CSCRF: What Must Stay in India

One of the least understood parts of SEBI's CSCRF is where your data is allowed to live. For any regulated entity running on foreign cloud or SaaS, data localisation is where compliance quietly breaks, here's what actually has to stay in India, and how to prove it.

10 min read
ComplianceSEBI CSCRF

SEBI CSCRF Penalties: What Non-Compliance Actually Costs

SEBI CSCRF doesn't come with its own rupee-value penalty schedule, but non-compliance is very much enforceable. Here's what SEBI can actually do, from a deficiency letter to a cancelled registration, and the costs that dwarf the fine.

10 min read
ComplianceSEBI CSCRF

SEBI CSCRF Applicability: Which Regulated Entities Must Comply

The most common question about SEBI's Cyber Security and Cyber Resilience Framework isn't how to comply, it's whether it even applies to you, and by when. Here's how to place your entity in the right category.

11 min read
ComplianceSEBI CSCRF

SEBI CSCRF Compliance Checklist: What Regulated Entities Need

SEBI's CSCRF raises the bar for regulated entities across six functions. Here's a plain-English, item-by-item checklist of what you need in place, plus the SOC, VAPT and audit expectations, and how to prove each one.

12 min read
ComplianceISO 27001

ISO 27001 vs SOC 2: Which Should You Pursue First?

Two of the most requested security credentials for B2B software. Here's how ISO 27001 and SOC 2 differ, who asks for which, and how to avoid doing the work twice.

7 min read
Third-Party Risk

A Practical Guide to Third-Party Risk Management (TPRM)

Your risk increasingly lives outside your own walls. This guide walks through the third-party risk lifecycle and how lean teams keep up with a growing vendor base.

9 min read
Operational Resilience

What Is Operational Resilience? A Framework for Regulated Firms

Operational resilience is more than disaster recovery. It's the ability to keep delivering critical services through disruption, and increasingly, a regulatory expectation.

7 min read
ComplianceDPDPA

DPDPA Compliance Checklist: A Practical Guide for Indian Businesses

India's DPDPA changes how organisations must handle personal data. Here's a plain-English checklist of what to put in place, and how to keep it evidenced.

8 min read
ComplianceSOC 2

SOC 2 Compliance Checklist: What You Need for Your First Audit

Heading into your first SOC 2? Here's a plain-English checklist of what auditors look for, and how to keep the evidence ready across the observation window.

8 min read
Third-Party Risk

Vendor Risk Assessment: A Step-by-Step Guide

A vendor risk assessment is only useful if it's structured and repeatable. Here's a step-by-step approach, and how to keep scores current instead of stale.

7 min read
CompliancePCI DSS

PCI DSS Requirements: The 12 Requirements Explained

PCI DSS is organised into 12 requirements across six objectives. Here's what each one actually asks for, and where teams usually get caught.

9 min read
ComplianceGDPR

GDPR Compliance Checklist: A Practical Guide

The GDPR is principles-based, which makes it easy to nod along to and hard to operationalise. Here's a concrete, item-by-item checklist of what to actually put in place, and how to prove it.

11 min read
ComplianceTiSAX

TiSAX Certification: A Guide for Automotive Suppliers

If an OEM has asked for TiSAX, here's what it actually involves, the VDA ISA catalogue, assessment levels and labels, and how to prepare efficiently.

8 min read
ComplianceHIPAA

HIPAA Compliance Checklist for Health-Tech Companies

If your product touches protected health information, HIPAA applies. Here's a practical checklist of the safeguards and agreements you need.

8 min read
ComplianceNIST CSF

NIST CSF Compliance: The Six Functions and How to Comply

NIST CSF is voluntary, but it has become the common yardstick for demonstrating a mature security program. Here's what NIST CSF compliance actually involves, function by function, and how to prove it.

11 min read
Operational ResilienceISO 22301

RTO vs RPO: Business Continuity Metrics Explained

RTO and RPO get confused constantly. Here's the plain-English difference, and the other continuity metrics that drive your recovery planning.

7 min read
ComplianceRBI Guidelines

RBI Cyber Security Framework: What Regulated Entities Need to Know

The RBI's cyber expectations are spread across directions that differ by entity type. Here's what regulated entities need in place, and how proportionality works.

8 min read
ComplianceOJK-DFA

OJK Compliance in Indonesia: A Guide for Financial Services

If you operate in Indonesian financial services, OJK sets the expectations. Here's a practical overview and how to build a program that's ready for supervision.

7 min read

See Pelta on your posture

Book a walkthrough and see how agentic AI, a connected Evidence Engine and Pelta GPT unify your GRC, third-party risk and resilience programs.