The AramGRC blog

Analysis from the front line of AI governance.

ISO/IEC 42001, the EU AI Act, NIST AI RMF and the operating practice of running a credible governance program.

Building Trust in AI: A Third-Party Assurance Framework for Enterprises (US & India)
LatestAI AssuranceAI GovernanceAI Red Teaming·13 min read

Building Trust in AI: A Third-Party Assurance Framework for Enterprises (US & India)

How do you build trust in AI at enterprise scale? AramGRC co-founder Anand shares a practical third-party AI assurance framework — inventory, governance, conformance, red teaming and independent reporting — built for the US and India.

By Sakthi Thangavelu, Co-founder, AramGRC
What Is an AI Audit? Types, Scope, and What a Good Audit Report Looks Like
AI AuditAI Assurance

What Is an AI Audit? Types, Scope, and What a Good Audit Report Looks Like

What is an AI audit — and why does "AI audit" mean five different things to five different people? AramGRC co-founder Anand breaks down the types of AI audit, what a good one covers, and exactly what a strong audit report should include.

Anand Prabhu · 11 min
AI Assurance for Indian AI Companies: DPDP, MeitY & What Global Buyers Expect
AI AssuranceIndia

AI Assurance for Indian AI Companies: DPDP, MeitY & What Global Buyers Expect

How do Indian AI companies win global trust? AramGRC co-founder Anand explains AI assurance for India — the DPDP Act, MeitY's AI guidelines, and what US and EU buyers actually expect from Indian AI vendors.

Sakthi Thangavelu · 11 min
ISO/IEC 42001 Assurance: How Independent Audits Prove Your AI Is Trustworthy
ISO 42001AI Assurance

ISO/IEC 42001 Assurance: How Independent Audits Prove Your AI Is Trustworthy

What is ISO/IEC 42001, and why does an independent audit matter more than "alignment"? AramGRC co-founder Anand explains ISO 42001 certification — the audit process, what auditors check, and how it proves your AI is trustworthy.

Anand Prabhu · 11 min
EU AI Act Conformity Assessment: When You Need a Third-Party Assessor
EU AI ActAI Compliance

EU AI Act Conformity Assessment: When You Need a Third-Party Assessor

Does the EU AI Act require a third-party assessor? AramGRC co-founder Anand explains conformity assessment in plain English — self-assessment vs a notified body, and exactly when high-risk AI providers need an independent assessor.

Sakthi Thangavelu · 11 min
LLM Red Teaming: How to Test Large Language Models for Safety & Security
AI Red TeamingLLM Security

LLM Red Teaming: How to Test Large Language Models for Safety & Security

How do you red team a large language model? AramGRC co-founder Sakthi explains LLM red teaming step by step — the OWASP LLM Top 10 threats, the tools like Garak and PyRIT, the attack categories, and how to test LLMs for safety and security.

Anand Prabhu · 12 min
AI Penetration Testing vs AI Red Teaming vs AI Audit: What's the Difference?
AI AssuranceAI Red Teaming

AI Penetration Testing vs AI Red Teaming vs AI Audit: What's the Difference?

AI penetration testing, AI red teaming and AI audit are not the same thing — and buying the wrong one is expensive. AramGRC co-founder Anand explains the difference, how they overlap, and which one your AI product team actually needs.

Sakthi Thangavelu · 10 min
How to Choose an AI Red Teaming Partner: A Checklist for AI Product Teams
AI Red TeamingAI Assurance

How to Choose an AI Red Teaming Partner: A Checklist for AI Product Teams

How do you choose an AI red teaming partner? AramGRC co-founder Sakthi shares a practical checklist for AI product teams — what to ask, what a good report looks like, and the red flags to walk away from.

Anand Prabhu · 11 min
AI Red Teaming: The Complete Guide (How It Works + What a Report Includes)
AI Red TeamingAI Assurance

AI Red Teaming: The Complete Guide (How It Works + What a Report Includes)

What is AI red teaming, how does it work, and what belongs in a good report? AramGRC co-founder Sakthi shares a hands-on guide — the process, the tools (Garak, PyRIT, promptfoo), and exactly what an AI red teaming report should include.

Sakthi Thangavelu · 12 min
Third-Party AI Assurance: What It Is and Why Internal Audits Aren't Enough
AI AssuranceAI Red Teaming

Third-Party AI Assurance: What It Is and Why Internal Audits Aren't Enough

What is AI assurance, and why isn't an internal audit enough? An AramGRC co-founder explains third-party AI assurance, how it differs from an AI audit, why passing red-teaming tools like Garak and PyRIT isn't sufficient, and what a good assurance report looks like.

Anand Prabhu · 11 min
Is there a value in independent AI Red teaming?
AI Red Teaming

Is there a value in independent AI Red teaming?

A common objection to independent AI red teaming goes like this: "The engineers who built the system understand it better than anyone. How can an outside team find what they missed?" The question assumes that building and breaking sit on the same skill ladder, and that the breaker must stand on a higher rung. They don't, and they needn't.

Sakthi Thangavelu · 5 min
AI-Agent

AIUC-1: A New Standard for Trustworthy AI Agents

AIUC‑1 offers a new, governance‑focused way to address AI malfunctions in the age of agentic systems. Instead of only checking whether security and AI policies exist, it tests how AI agents behave under attack, whether they can be jailbroken, leak sensitive data, or misuse tools autonomously. Positioned alongside standards like ISO/IEC 27001, ISO/IEC 42001, SOC 2, and GDPR, AIUC‑1 adds what those frameworks largely lack: independent, behaviour‑based assurance and documented human oversight through human‑in‑the‑loop workflows. With 50+ technical, operational, and legal safeguards and frequent adversarial testing, it shifts the core question from “Is the AI compliant on paper?” to “Can this AI be trusted to operate safely, securely, and under human control in real‑world enterprise environments?”

Anand Prabhu · 5 min
IRDAIAI

IRDAI’s Approach to AI: Building Safe Insurance Systems

How IRDAI, India’s insurance regulator, is responding to the growing use of artificial intelligence in insurance by focusing on governance rather than bans. It shows how AI is improving underwriting, claims and fraud detection, but also creating risks around bias, privacy and opaque decisions. It then highlights IRDAI’s steps setting up an AI working group, urging insurers to “AI‑proof” systems before integrating with the Bima Sugam digital marketplace, and insisting that AI tools be fair, transparent, explainable and accountable, so that innovation can continue while policyholders’ data, rights and trust stay protected.

Sakthi Thangavelu · 7 min
AgenticAI

Agentic AI in Retail Brokerages: When the Model Stops Asking Permission

The leap from Generative AI to Agentic AI in India’s financial sector is happening faster than our compliance frameworks can adapt. It is one thing for a language model to suggest a market trend; it is a fundamentally different risk when an autonomous agent is given the API keys to act on it.

Anand Prabhu · 8 min
AI Governance Through ISO 42001: Practical Guide for Practitioners
ISO42001

AI Governance Through ISO 42001: Practical Guide for Practitioners

AI is transitioning from experimental pilots to mission‑critical systems that impact customers, employees, and regulators. That evolution makes strong governance indispensable. ISO 42001 — the developing international standard for AI management systems — provides organisations with a structured, auditable framework to manage AI risk, compliance, and performance across the entire lifecycle.

Sakthi Thangavelu · 5 min
Shadow AIBFSI

Shadow AI is the BFSI governance blind spot nobody put on the risk register

Every Indian bank, NBFC and insurer now runs an AI program it never approved, never inventoried and cannot see. Shadow AI has quietly become the fastest-growing attack surface in financial services.

Anand Prabhu · 9 min
MicrofinanceIndia

AI in microfinance: the inclusion promise and the over-indebtedness risk

The same alternative-data model that brings a first-time borrower into the formal system can also push a vulnerable household into a debt spiral. The governance scaffolding to tell the two apart is mostly missing.

Sakthi Thangavelu · 9 min
HealthcareShadow AI

Shadow AI in the clinic: healthcare's quiet patient-data leak

The most common AI deployment in an Indian hospital today is not the radiology triage tool the board approved. It is the resident pasting a discharge summary into a free chatbot at 2 a.m.

Anand Prabhu · 10 min
Agentic AIBFSI

Agentic AI in BFSI: when the model stops asking permission

Generative AI drafts. Agentic AI acts. The shift from a model that suggests a reply to a system that opens accounts, moves money, files disputes and emails customers without a human in each loop is the defining governance challenge of 2026 — and most BFSI risk frameworks were not written for it.

Sakthi Thangavelu · 9 min
ResponsibleAI

Incentivizing Responsible AI Within Organizations

Most companies have a "responsible AI" page on their website. Fewer have a reason for their employees to actually act on it. That gap is not usually a values problem — it's an incentives problem. When a recent study surveyed product managers, the people who make the daily calls on what AI features actually ship, only about one in five said their organization gave them any clear incentive to use generative AI responsibly. Meanwhile, promotion cycles, OKRs, and roadmap pressure all reward one thing: shipping fast. Ask someone to optimize for speed and safety simultaneously, without rewarding the second one, and you already know which one wins.

Anand Prabhu · 5 min
ISO 42001India

ISO/IEC 42001 as the control layer that unifies India and the Middle East

When an enterprise faces five regulators across three jurisdictions, the instinct is to run five compliance projects. The discipline is to run one management system and map it to all five.

Sakthi Thangavelu · 8 min
MicrofinanceBFSI

Synthetic identity and AI fraud at the bottom of the pyramid

The deepfake-CEO stories grab the headlines, but the highest-volume AI fraud in 2026 is happening quietly in microfinance, rural lending and first-time digital onboarding.

Anand Prabhu · 8 min
Shadow AIBusiness Case

The boardroom number: putting a rupee figure on shadow AI

Boards approve AI governance budgets when shadow AI stops being an IT anecdote and becomes a number on a slide. Here are the four numbers that turn an invisible risk into a quantified one.

Sakthi Thangavelu · 8 min
WhatsApp