Open risks
4
1 critical · 2 medium · 1 low
DPDPA 72h · INC-007
48h 22m
Remaining · DPO notified
Open DSARs
2
1 access · 1 erasure · 86d earliest
Coverage score
87%
12 controls · 3 gaps open
Compliance overview · June 2026
Live across Risk · Privacy · Governance · RecordsOpen itemsRisk · Audit · Vendor · Incident
| Area | Open | Detail |
|---|---|---|
| Risks | 4 | RSK-001 PII breach critical · 3 controls in gap |
| Internal audit findings | 3 | 2 high · 1 medium · PII breach audit in fieldwork |
| Vendor DPA | 6 | 28 / 34 signed · 4 cross-border §16 · 2 expiring 30d |
| Incident · INC-007 | 1 | CERT-In 6h + DPDPA 72h clocks active |
Privacy postureDPDPA · ROPA · Consent · DSAR
| Metric | Value | Detail |
|---|---|---|
| Systems mapped | 11 | ROPA export ready · DPB-submission format |
| Cross-border §16 | 2 | Non-notified countries · SCC in progress |
| Active consents | 287 | 148 employees · 139 customers · 4 withdrawn 30d |
| DSARs · 90-day | 2 | 86d earliest · 4 closed · 100% on-time |
Framework coverage5 frameworks · 87% overall · 4 tests due Q3
ISO 27001 78%
PoSH (SHe-Box mapped)70%
DPDPA 65%
SOC 2 52%
SEBI CSCRF Mandatory Apr 202541%
Risks · total
4
1 critical · 2 medium · 1 low
Controls · active
12
3 gaps open
Coverage score
87%
4 tests due Q3
DPDPA 72h · INC-007
48h 22m
Remaining · DPO notified
tapAdvisor · GSTR-9 filing window — act before 31 Dec to avoid ₹ 30,200 late penalty
Recommended
Without action · late filing
GSTR-9 annual return due 31 Dec 2026 · Turnover ₹3.8 Cr (above ₹2 Cr mandatory threshold)
₹ 30,200 penalty
₹200/day × 151 days if filed 31 May 2027 · plus GSTN late-fee notice and audit exposure
With action · file by 31 Dec
Compliance module pre-populates GSTR-9 from FY invoices + GSTR-3B history · 212-day early alert open now
₹ 30,200 saved
Penalty fully avoided · clean compliance posture for statutory auditors and ROC chain
Cited provision: CGST Act 2017 §44 · GSTR-9 annual return mandatory if turnover > ₹2 Cr · late fee ₹200/day (₹100 CGST + ₹100 SGST), capped at 0.5% of turnover · Source: thetaxcorp.in · India Compliance Calendar FY 2026-27 (sample)
⚠ AI-generated guidance based on CGST Act 2017 §44 and company turnover data. tapestree does not provide tax advice. Confirm with your CA before acting.
Pending CA approval · 212 days remaining in alert window
Risk register · June 2026
4 risks · DPDPA §8 · ISO 27001 · SOC 2 · PoSH · SEBI CSCRFRisk list4 risks · sorted by score
RSK-001 · Customer PII breach
Score 64 · L×I×V · DPDPA §8 · CERT-In 6h + 72h timers active
RSK-002 · GST filing delay
Score 18 · GSTN · auto-reminder C-004 live
RSK-003 · Vendor MSME non-compliance
Score 12 · MSMED Act §15 (45-day payment) · Income-tax Act 1961 §43B(h) disallowance · flag live in Procurement
RSK-004 · Employee data consent
Score 3 · DPDPA §6 · consent form updated
RSK-001 · Controls & breach timersINC-007 active
CERT-In 6h · criminal liability
2h 08m
Remaining · CERT-In Directions 2022
DPDPA §8(6) · 72h
48h 22m
DPB notify by 03 Jun 09:00 IST
C-001 · AES-256 at rest · KMS rotated 90d · Tested 1 Jun · ISO 27001 A.10.1
C-002 · Immutable audit trail · S3 Object Lock · 7yr retention · Tested 28 May · SOC 2 CC6.1
C-003 · 72h breach notification workflow · Gap · DR-449
KRI auto-monitoring
⬤ Amber · API query volume +42% vs baseline
⬤ Green · Key rotation · 18d remaining
⬤ Green · Audit log · no gaps
Framework coverage5 frameworks
ISO 27001 78%
DPDPA 65%
SOC 2 52%
PoSH (SHe-Box mapped)70%
SEBI CSCRF Mandatory Apr 202541%
Risk scores · Likelihood × Impact × VelocityDynamic · 0–64 range
| Risk | Likelihood | Impact | Velocity | Score | KRI | Treatment |
|---|---|---|---|---|---|---|
| RSK-001 · PII breach | 4 · Likely | 4 · Critical | 4 · Fast | 64 | Amber | In-progress · C-003 gap |
| RSK-002 · GST delay | 3 · Possible | 3 · Moderate | 2 · Medium | 18 | Green | Mitigated · C-004 live |
| RSK-003 · MSME non-comp. | 2 · Unlikely | 3 · Moderate | 2 · Medium | 12 | Green | Mitigated · 45-day flag |
| RSK-004 · Employee consent | 1 · Rare | 3 · Moderate | 1 · Slow | 3 | Green | Accepted |
AI · control recommendationcompliance.ai_regulatory_alerts
- C-003 gap · RSK-001 — DPDPA 72h + CERT-In 6h breach notification workflow not deployed. Recommend: DPB filing template + CERT-In portal API before 15 Jun. DR-449 open.
- SEBI CSCRF (mandatory Apr 2025) — 41% coverage; 7 controls unmapped. Quick lift: map existing C-001 (encryption) and C-002 (audit trail) to CSCRF domains — +20% coverage in one sprint.
- Control testing schedule — C-001 and C-002 next test due Sep 2026. Calendar blocks created. C-004 (GSTR-3B auto-reminder) test due Oct 2026 before Q3 filing.
Policy library6 policies · HR acknowledgment linked
| Policy | Version | Owner | Next review | Ack status |
|---|---|---|---|---|
| POL-001 · Information Security Policy | v2.1 | CISO | Sep 2026 | 148 / 148 |
| POL-002 · DPDPA Privacy Policy | v1.3 | DPO | Nov 2026 | 140 / 148 · 8 pending |
| POL-003 · Acceptable Use | v3.0 | IT | Mar 2027 | 148 / 148 |
| POL-004 · Whistleblower & Vigil | v1.0 | Legal | Apr 2027 | 148 / 148 |
| POL-005 · PoSH Policy | v2.0 | HR | Jan 2027 | 148 / 148 |
| POL-006 · Vendor Code of Conduct | v1.1 | Procurement | Jun 2027 | Vendor-facing |
Systems mapped
11
Auto-populated from tapestree modules
Cross-border §16 ⚠
2
Non-notified countries · SCC in progress
ROPA export
Ready
PDF · DPB-submission format
DPDP Rules 2025
Rule 3
Itemised notice — inventory is prerequisite
PII data inventory · ROPA
Processing Activity Register — auto-populated from HR, CRM, Finance, Payroll modulestapestree auto-populates your DPDPA inventory — competitors require weeks of manual entry
Because Compliance runs on the same tenant as HR, CRM, Finance, and Payroll, tapestree pre-fills the data map. OneTrust charges $50k+ for a manual inventory project. Sprinto, Vanta, and Drata have no ERP data at all — they cannot do this.
System-by-system data mapDPDPA §7 lawful basis · §16 cross-border flags · classification labels
| System / Module | Data categories | Purpose | Legal basis | Retention | Processor | Cross-border |
|---|---|---|---|---|---|---|
| HR · employee records | Name · Aadhaar · PAN · salary · health declaration | Employment · payroll · statutory | Contract · legal obligation | 8 yr (Income-tax Act 1961 §44AA · EPF record-keeping) | None | India only |
| CRM · contacts | Name · email · phone · deal history | Sales · support · marketing | Legitimate interest · consent | 5 yr post-activity | None | India only |
| Payroll · salary runs | Bank a/c · UAN · PAN · salary slips | Salary · TDS · statutory | Legal obligation | 8 yr (EPFO) | NSDL · ESIC | India only |
| Finance · invoices | Vendor/customer PAN · GSTIN · address | Billing · GST compliance | Legal obligation | 6 yr (GSTIN) | None | India only |
| Marketing · campaigns | Email · name · behavioural data | Marketing outreach | Consent | 3 yr or till withdrawal | Mailchimp US | ⚠ §16 · non-notified |
| Helpdesk · tickets | Name · email · phone · issue description | Customer support | Contract | 3 yr | Zendesk US | ⚠ §16 · non-notified |
| Contracts · signed docs | Signatory name · PAN · address | Contract execution | Legal obligation | 10 yr (Limitation Act) | None | India only |
| + 4 more systems | — | — | — | — | — | India only |
Classification labels sourced from Documents module governance tags: Public Internal Confidential Restricted
Cross-border remediationDPDPA §16 · 2 systems
Mailchimp (US)
SCC required · DPA draft in progress · est. 30 days
Zendesk (US)
SCC template sent to vendor · response pending
Notified countries list
Not yet published by Central Govt · MeitY gazette monitor live
ROPA export summaryDPB-submission format · Rule 3
Processing activities
11 · all mapped
Legal bases covered
Contract · Legal obligation · Consent · Legitimate interest
Data categories
Employment · Financial · Customer · Vendor
Last exported
Never · click to generate first export
Open DSARs
2
1 access · 1 erasure
90-day deadline
86d left
DPDPA Rules 2025, Rule 12 · earliest request
Closed · 90 days
4
100% on-time
Erasure cascades
1
HR + CRM + Billing auto-dispatched
DSAR workflow · June 2026
Access · Erasure · Correction · Withdrawal — DPDPA §11 (access) + §12 (correction/erasure) · Rules 2025 Rule 12 · 90-day response timerIntake: web form · WhatsApp +91-9XXXXXXXXX · email privacy@sahyadri.in · 90-day clock auto-starts
tapestree auto-logs the request, starts the 90-day countdown, AI-drafts the access summary, and cascades erasure to HR, CRM, and billing records — ERP-native, zero manual tickets. OneTrust requires custom API integrations to achieve this. Sprinto and Vanta have no ERP data at all.
Open requests
| Request ID | Requestor | Type | Received | 90-day deadline | Status | Action |
|---|---|---|---|---|---|---|
| DSAR-0012 | Priya Menon (former employee) | Access | 29 May 2026 | 27 Aug 2026 · 86d left | In progress | |
| DSAR-0011 | Arjun Patel (ex-customer) | Erasure | 20 May 2026 | 18 Aug 2026 · 77d left | Cascade running |
DSAR-0012 · AI-drafted access summaryPriya Menon · former employee
Data held
Name · Aadhaar (masked) · PAN · salary history · payslips (36 months) · leave records
Systems
HR module · Payroll module · Documents (offer letter, Form 16)
Processors shared
NSDL (PAN TDS) · EPFO (UAN) · ESIC
Draft status
AI-drafted · pending DPO review
DSAR-0011 · Erasure cascade · Arjun PatelERP-native auto-dispatch
CRM contact
Deleted · 20 May 14:02
Billing history
Anonymised · txn IDs preserved · PII removed
Marketing emails
Unsubscribed + deleted
48h pre-erasure notice
Sent 18 May · WhatsApp delivery confirmed
DPB notification
Not required · erasure fulfilled within notice period
Vendors tracked
34
Pulled from Procurement module
DPA signed
28 / 34
6 pending
Cross-border §16 ⚠
4
Non-notified country transfer
Expiring 30d
2
Auto-reminder sent
Vendor DPA tracker · June 2026
34 vendors · DPDPA §16 cross-border flags · MSME compliance cross-link · Procurement dataVendor DPA status
| Vendor | Data processed | DPA status | Cross-border | MSME | DDQ | Expiry |
|---|---|---|---|---|---|---|
| Techspark Solutions | Employment (contract staff) | Signed | India only | Registered | Reviewed | Jun 2027 |
| Mailchimp (Intuit US) | Customer email · behavioural | Pending SCC | ⚠ US · non-notified | — | Sent | — |
| Zendesk (US) | Support tickets · PII | Pending | ⚠ US · non-notified | — | Responded | — |
| DataEdge Analytics | Payment analytics (aggregated) | Signed | India only | Registered | Reviewed | Jul 2026 · expiring |
| + 30 more vendors | — | 26 signed | — | — | — | — |
Audit universe
8
Process areas · FY26
Active audits
1
PII breach response · fieldwork
Open findings
3
2 high · 1 medium
SEBI LODR Reg 27(2)
Submitted
AI-drafted · 28 Apr 2026
Internal audit · FY26 plan
SEBI LODR · MCA AOC-4 · Audit Committee report · event-driven triggersAudit universe · FY26
| Process area | Risk rating | Auditor | Last audit | Next planned | Status |
|---|---|---|---|---|---|
| PII / Data security | High | Riya Nair (Internal) | Apr 2026 | Active · Jun 2026 | Fieldwork |
| Payroll & statutory | Medium | External CA | Jan 2026 | Jul 2026 | Planned |
| Procurement & MSME | Medium | Riya Nair | Nov 2025 | Sep 2026 | Planned |
| IT access controls | High | CISO Rajesh K | Mar 2026 | Aug 2026 | Planned |
| Finance & GST | Medium | External CA | Dec 2025 | Oct 2026 | Planned |
| + 3 more areas | — | — | — | — | — |
Active audit · PII & data securityEvent-driven · RSK-001 score ≥ 12
Finding 1
C-003 (breach workflow) not deployed · Draft
Finding 2
CERT-In 6h notification SOP missing · Draft
Finding 3
SEBI CSCRF controls 41% · gap list produced · Mgmt response pending
Audit Committee report · AI-draftedSEBI LODR Reg 27(2)
Status
Submitted · 28 Apr 2026
Key findings
C-003 gap · CERT-In SOP missing · SEBI CSCRF 41%
Mgmt response
C-003 deployment Q3 · CSCRF gap plan in progress
Next due
30 Apr 2027 · AI draft starts 1 Mar 2027
Q2 FY27 campaign
Active
SOC 2 CC6.3 · ISO 27001 A.9
Users to certify
148
Pulled from identity-service
Certified · 30d
112 / 148
36 pending · 7d to escalate
Revocations
4
IT tickets auto-dispatched
Access certification · Q2 FY27
148 users · manager reviewer workflow · SOC 2 CC6.3 evidence auto-generated on closetapestree pulls users from your own identity-service — no CSV or Okta connector required
Vanta and Drata require AWS/GCP/Okta connectors. tapestree's access review is native: roster, roles, and system access all come from the same platform. SOC 2 CC6.3 evidence PDF auto-generated on campaign close.
Campaign · Q2 FY27 · sample rows
| Employee | Role | Systems with access | Reviewer | Decision | Status |
|---|---|---|---|---|---|
| EMP-0001 · Aanya Sharma | CFO | Finance · Payroll · Compliance · CRM | CEO (self) | Approved | Done |
| EMP-0044 · Ravi Kumar | Sales Lead | CRM · Sales · Documents | Aanya S. | Approved | Done |
| EMP-0131 · Exited user | — | Finance · HR · Payroll (stale) | Aanya S. | Revoked | IT ticket dispatched |
| EMP-0218 · Suresh T. | Finance Analyst | Finance · Contracts | Riya Nair | Pending | 7d to escalate |
| + 144 more | — | — | — | 108 approved · 3 revoked | — |
Open reports
2
1 financial misconduct · 1 PoSH
SEBI MII · 60d timer
39d remaining
VIG-001 · Audit Committee
Closed · rolling 90d
6
100% within SEBI deadline
Companies Act §177
Compliant
Listed + ₹50 Cr borrowers
Vigil mechanism / whistleblower portal
Companies Act §177 · SEBI LODR · SEBI MII 60-day timer · PoSH SHe-Box · CARO 2020India's only whistleblower portal with WhatsApp intake + SEBI MII 60-day resolution timer
EthicsPoint (NAVEX Global) and WhistleB are global tools — no WhatsApp intake, no SEBI MII 60-day clock, no PoSH SHe-Box link. Companies Act §177 mandates vigil mechanism for all listed entities and those with ₹50 Cr+ borrowings. SEBI MII resolution: 60-day deadline effective April 2025.
Open reportsMetadata stripped · reporter anonymity preserved
| Report ID | Category | Received | Route | SEBI 60d deadline | Status |
|---|---|---|---|---|---|
| WB-0004 | Financial misconduct · Vendor kickback allegation | 12 May 2026 | Audit Committee | 11 Jul 2026 · 39d remaining | Urgent |
| WB-0005 | Harassment · PoSH complaint | 1 Jun 2026 | Internal Committee | 31 Jul 2026 · 59d remaining | IC notified |
Intake channelsAnonymous · metadata stripped
Web form
whistleblower.sahyadri.in · no login required
WhatsApp
+91-9XXXXXXXXX · anonymous · metadata stripped before routing
Email alias
vigil@sahyadri.in · sender header stripped
Categories
Fraud · Insider trading · Safety · Harassment (PoSH) · Ethics · Data privacy · Other
Admin dashboard · rolling 90d
Total reports
8 (2 open · 6 closed)
Category breakdown
3 Financial · 2 PoSH · 2 Ethics · 1 Safety
Overdue
0 · all within SEBI 60d window
Resolution rate
100% within deadline (closed cases)
SEBI informant flag
WB-0004 · insider trading evidence threshold not yet met
Filings · FY27
48
GST · IT · MCA · SEBI · EPFO · PoSH
Due this month
7
3 GST · 2 EPFO · 1 PT · 1 SEBI
Auto-reminders
42 / 48
6 manual (FEMA / RBI)
On-time rate · FY26
100%
No late filings
Regulatory calendar · FY 2026-27
GST · Income Tax · MCA/ROC · SEBI LODR · FEMA/RBI · EPFO/ESIC · PoSH · CERT-InUpcoming filings · June – December 2026compliance.regulatory_calendar · C-004 GSTR auto-reminder · compliance.ai_regulatory_alerts
| Filing | Regulator | Due date | Owner | Days left | Status |
|---|---|---|---|---|---|
| GSTR-1 · Jun 2026 | GSTN | 11 Jul 2026 | Finance | 39 | Filed |
| PF ECR · Jun 2026 | EPFO | 15 Jul 2026 | Payroll | 43 | Draft |
| ESI · Jun 2026 | ESIC | 15 Jul 2026 | Payroll | 43 | Draft |
| GSTR-3B · Jun 2026 | GSTN | 20 Jul 2026 | Finance | 48 | Prep |
| PT · KA / MH / TN | State CTO | 20 Jul 2026 | Payroll | 48 | Draft |
| SEBI shareholding pattern | SEBI | 21 Jul 2026 | Company Secretary | 49 | Pending CS |
| MCA AOC-4 · financials | MCA | 30 Oct 2026 | Finance + CS | 150 | In prep |
| GSTR-9 · FY26 annual | GSTN | 31 Dec 2026 | Finance | 212 | tapAdvisor · act now |
| PoSH annual report | Labour Dept | 31 Jan 2027 | HR / ICC | 243 | Planned |
AI regulatory alert feedcompliance.ai_regulatory_alerts · MCA / SEBI / RBI / IRDAI gazette RAG
- SEBI CSCRF (mandatory Apr 2025) — Cybersecurity & Cyber Resilience Framework required for listed entities. Current coverage: 41%. tapestree auto-generated CSCRF gap checklist: 7 items open.
- DPDP Rules 2025 · Consent Manager (Nov 2026) — If classified as Significant Data Fiduciary, interoperability with registered Consent Manager required. Assess SDF threshold before Sep 2026 — DPO review flag set.
- CERT-In Directions 2022 · 6h reporting (INC-007 active) — CERT-In 6h clock is STRICTER than DPDPA 72h. Both notifications are independent. Criminal liability + ₹1L fine for non-compliance. C-003 gap is critical dependency.
- MCA · DIR-3 KYC · due 30 Sep 2026 — Annual director KYC for all DIN holders. 3 directors in system — reminder dispatched 1 Jun.
Active consents
287
148 employees · 139 customers
Withdrawn · 30d
4
DSAR-linked withdrawals
Purpose bindings
6
Active purpose categories
Expiring · 90d
12
Renewal notices dispatched
tapestree's consent ledger auto-populates from HR onboarding, CRM contact capture, and Marketing opt-in — no manual data entry
DPDPA 2023 §6 mandates purpose-specific, time-bound consent with documented lawful basis. Consent must be as granular as each purpose. Withdrawal must be as easy as grant. tapestree's cross-module data model makes the DPDPA §9 data principal rights register the natural output — no standalone consent tool required.
Consent receipt ledger · DPDPA §6
287 active · purpose-bound · withdrawal-auditedConsent receipts · sampleSourced from HR · CRM · Marketing · Payroll modules
| Data subject | Type | Purpose | Granted | Expiry | Module source | Status |
|---|---|---|---|---|---|---|
| Priya Menon · EMP-0044 | Employee | Payroll processing + attendance monitoring | 15 Apr 2022 | 31 Mar 2027 | HR module | Active |
| Arjun Patel · CUS-0089 | Customer | Sales communications · CRM activity tracking | 20 Jan 2025 | Withdrawn 20 May 2026 | CRM module | Withdrawn · DSAR-0011 |
| Kavya Ramesh · EMP-0091 | Employee | Health insurance nomination · medical data | 1 Jun 2023 | 31 May 2028 | HR module | Active |
| Suresh Murthy · CUS-0201 | Customer | Marketing email campaigns | 15 Mar 2025 | Withdrawn 15 Mar 2026 | Marketing module | Withdrawn · DSAR-0009 |
| + 283 more consent records | — | — | — | — | — | — |
Purpose binding summary · DPDPA §6(2)
Purpose-specific · granular · withdrawal-tracked| Purpose | Data type / sensitivity | Data subjects | Retention | Active consents |
|---|---|---|---|---|
| Payroll processing | Financial · DPDPA sensitive | Employees | 8 years (CGST §36) | 148 |
| Sales communications | Contact data · commercial | Customers | 3 years | 139 |
| Health insurance nomination | Health data · DPDPA sensitive | Employees | 5 years | 148 |
| Marketing email | Email · behavioural | Customers + prospects | 3 years | 1,247 |
| CCTV monitoring | Biometric-adjacent · sensitive | Employees + visitors | 30 days | 200+ |
| Biometric attendance | Biometric · DPDPA Art. 9 equivalent | Employees | 1 year | 87 · separate consent receipt required |
INC-007 · CERT-In 6h
48h 22m
⚠ Critical · DPO notified
INC-007 · DPDPA 72h
23h 38m
DPB filing not yet submitted
Incidents · FY26
3
1 active · 2 closed
DPB notifications filed
1
INC-005 · filed & acknowledged
INC-007 · CERT-In 6h clock active · DPB notification required within 72h — both are independent obligations
CERT-In Directions 2022 require reporting within 6 hours of detection — criminal liability and ₹1L fine for non-compliance. DPDPA §8(6) requires separate DPB notification within 72 hours. C-003 gap (DR-449) means this is the first time both workflows are being run from within tapestree.
Incident register · FY26
CERT-In 6h · DPDPA §8(6) 72h · parallel first-class workflows| Incident ID | Detected | Category | CERT-In 6h | DPDPA 72h | DPB filed | Status |
|---|---|---|---|---|---|---|
| INC-007 | 2 Jun 2026 · 10:04 IST | Data breach · employee PII exported without auth | ⚠ 48h 22m | ⚠ 23h 38m | Not filed | Active |
| INC-006 | 15 Apr 2026 · 14:30 IST | Phishing attempt · credential not compromised | Notified ✓ | N/A · no PII breach | Not required | Closed |
| INC-005 | 10 Jan 2026 · 09:17 IST | Unauthorized access · customer DB exposed 4h | Filed ✓ · 5h 12m | Filed ✓ · 68h | Acknowledged | Closed |
INC-007 · Incident detailActive · dual notification required
Detection time
2 Jun 2026 · 10:04 IST
Category
Data breach · unauthorised export of employee PII (names, Aadhaar partial, salary data · 42 records)
Data principals
42 employees · Aadhaar partial · PAN · salary data
Detection method
tapestree audit trail anomaly alert — unusual bulk export at 09:58 IST by EMP-0131 (exited user)
Immediate measures
Access revoked · session terminated · forensic copy preserved · DPO notified 10:12 IST
Assigned to
DPO Anita Rao · CISO Rajesh K · Legal
Notification status · INC-007Two independent obligations
CERT-In deadline
2 Jun 2026 · 16:04 IST · 48h 22m remaining
CERT-In status
Not filed — file immediately
DPB deadline
4 Jun 2026 · 10:04 IST · 23h 38m remaining
DPB status
Not filed — draft ready for DPO sign-off
Late penalty
CERT-In: criminal liability + ₹1L fine · DPB: regulatory action under DPDPA §33
Quantitative Risk Scoring (FAIR model)Roadmap
Replace abstract Likelihood × Impact scores with ₹-denominated risk exposure using the FAIR methodology — giving boards and CFOs a rupee figure for residual risk, not a coloured dot. RBI-regulated entities are beginning to mandate this approach.
ADR 3NNNRequires finance integration · FAIR India calibration dataset
Regulatory Inspection TrackerRoadmap
Log every government inspection — factory inspector, GST survey, SEBI examination, IRDAI audit — with findings, responses, and closure status. India SMBs face surprise inspections with no digital log of past interactions; no competitor addresses this.
ADR 3NNNIndia-only category · MSME and manufacturing heavy
DPIA Workflow (Privacy Impact Assessment)Roadmap
Structured DPIA for Significant Data Fiduciaries under DPDPA and for any high-risk processing activity — templates, risk scoring, DPO sign-off, and annual refresh. Required before launching any new product feature processing personal data at scale.
ADR 3NNNDepends on DPDPA SDF notification · MeitY gazette monitoring
Federated Compliance BenchmarkRoadmap
See how your compliance posture compares to anonymised peer companies in your industry — control coverage %, average DPDPA score, CERT-In readiness — using privacy-preserving federated aggregates. No raw data leaves any tenant.
ADR 3NNNRequires tapestree network scale · differential privacy infrastructure
ISO/IEC 42001 AI Governance ChecklistRoadmap
Compliance checklist and evidence collection for ISO 42001 (AI management systems) and EU AI Act alignment — bridging tapestree's existing ai-governance-service into the Compliance module as a mapped control set. EU AI Act enforcement begins August 2026.
ADR 3NNNDepends on ai-governance-service API · EU AI Act enforcement timeline
DPDPA Consent Manager IntegrationRoadmap
Interoperability with the DPDPA Consent Manager framework (operational November 2026) — enabling tapestree to act as or integrate with a registered Consent Manager for Significant Data Fiduciaries, covering consent lifecycle, withdrawal processing, and DPB reporting.
ADR 3NNNDepends on MeitY CM framework notification · SDF threshold publication
Agentic Audit TestingRoadmap
AI-driven audit sample selection and automated finding drafts from Finance and HR transaction logs — compressing internal audit fieldwork from weeks to hours. tapestree uses its own ERP data natively; this is the structural edge over AuditBoard Accelerate (which must integrate with external GL/HR systems).
ADR 3NNNRequires ai-governance gate wiring · Finance + HR API scope for audit
Dual Breach Notification — CERT-In 6h + DPDPA 72hRoadmap
Parallel notification workflows: CERT-In 6h (criminal liability, ₹1L fine) and DPDPA §8(6) 72h — two separate draft templates, two independent DPO sign-off chains, two filing queues. No competitor ships CERT-In 6h as a first-class native workflow; this is a genuine first-mover opportunity.
ADR 3NNNC-003 (breach workflow MVP gap) is prerequisite · CERT-In portal API access
ESG Scope 1/2/3Roadmap
Compute Scope 1, 2, and 3 greenhouse-gas emissions from facility energy, fleet, and supplier-spend ledgers into a BRSR / GRI-aligned ESG report — one governed disclosure built from data the suite already holds.
ADR 3NNNNew slug: compliance.esg_scope123 · depends on facility energy meters + supply-chain Scope-3 feed
Enterprise SOX SODRoadmap
Continuous segregation-of-duties analysis over the RBAC matrix — flag toxic role combinations (e.g. create-vendor + approve-payment) and produce SOX 404 control evidence without a manual access review.
ADR 3NNNNew slug: compliance.sox_sod · depends on platform RBAC role catalogue + finance approval graph
CBAMRoadmap
Generate the EU Carbon Border Adjustment Mechanism quarterly report for exporters — embedded-emissions per shipment line drawn from the product and logistics ledger, formatted for the CBAM transitional registry.
ADR 3NNNNew slug: compliance.cbam · depends on Scope-3 emissions-factor master + export shipment data · EU-export tenants only