AI governance, built for Indian companies

Your team is already using AI. Your policy hasn't caught up.

Oregula builds internal AI governance frameworks for Indian SaaS and BFSI companies, so AI adoption happens on clear rules instead of ad hoc calls.

SECTION 4.2 Third-Party AI Tool Approval

No employee may connect company data to an external AI tool that has not completed the approval checklist in Appendix C.

Approved tools are reviewed quarterly against data classification, vendor terms, and applicable regulatory obligations.

Requests for new tools are routed through the AI Governance Owner, with a decision within five working days.

Excerpt — Core AI Policy Framework

AI adoption is outrunning AI policy

Most Indian companies have engineering, sales, and support teams running AI tools daily, with no internal document defining what's allowed, what's reviewed, and who owns the decision.

Regulation is catching up

The DPDP Act 2023 sets obligations around how personal data is processed, and AI tools are one of the least controlled paths for data to leave a company. RBI has also flagged responsible AI use as a supervisory priority for regulated entities.

Enterprise buyers now ask

Security and vendor questionnaires from enterprise clients increasingly include questions on AI usage and data handling. A SaaS company without a governance document has no good answer.

Tool sprawl is the norm

ChatGPT, Copilot, and a dozen embedded AI features are already inside most workflows, usually adopted by individual teams without any central review.

Founders don't have time to write this

Writing a governance framework from scratch takes weeks a founder or compliance lead doesn't have, and getting it wrong is worse than not having one at all.

One core framework, four ways to work together

Every engagement starts from the same operational foundation: a governance document built around how your company actually uses AI, not a generic template.

Core AI Policy Framework
The master governance document: acceptable use, data handling, tool approval, model risk, and incident response, written for your team to actually follow.
FOUNDATION
Customisation
The framework mapped to your product, data classification, and existing compliance stack, including SOC 2, ISO 27001, or RBI and DPDP obligations.
ADD-ON
Team workshop
A working session with your team to walk through the framework, answer questions, and get real buy-in before rollout.
ADD-ON
Ongoing retainer
Quarterly reviews as your AI stack, headcount, and the regulatory landscape change, so the framework doesn't go stale in a drawer.
RECURRING

Built for two kinds of exposure

Oregula currently works with two types of Indian companies, both under real pressure to show a governance answer, not just good intentions.

SAAS, SERIES A–C

Shipping AI features faster than policy can keep up

  • Engineering already using AI coding tools daily
  • Enterprise prospects sending AI and data security questionnaires
  • Product roadmap includes AI features touching customer data
  • No one internally owns AI governance yet
BFSI & FINTECH

Regulatory exposure that a generic template can't cover

  • Direct exposure to RBI expectations on responsible AI use
  • Customer financial data flowing through AI-assisted workflows
  • Board or audit committee asking for an AI governance position
  • Need a document that a regulator or auditor can actually review

Four steps, no lengthy legal back-and-forth

The process is built to move fast without cutting corners. Most engagements go from first call to a delivered framework within two to three weeks.

01

Discovery call

A structured conversation covering your AI stack, data flows, team structure, and existing compliance obligations.

02

Draft framework

A first version of your governance document, built from a proven structure and written in language your team will actually read.

03

Review round

A working session to walk through gaps, edge cases, and edits, with changes reflected directly into the document.

04

Handover

Final framework delivered, team workshop scheduled if included, and an optional retainer set up for ongoing updates.

Priced by engagement, not by hour

Three ways to start, depending on how much of the framework you need built and how involved you want the process to be.

Pilot review
A focused review of your current AI use, key risks flagged, and a lightweight starter policy you can act on immediately.
₹25,000 – ₹35,000
Full framework
The complete Core AI Policy Framework, customised to your business, plus a team workshop to roll it out.
₹75,000 – ₹1,50,000
Retainer
Ongoing reviews and updates as your AI stack and regulatory obligations evolve, billed quarterly.
From ₹15,000 / month

Final pricing depends on company size, number of tools in use, and depth of customisation. This is discussed and confirmed before any engagement starts.

A focused, solo practice

Oregula is built and run as a solo practice, working directly with founders and compliance leads rather than through a large team. Every framework is researched, drafted, and reviewed personally, using AI tools heavily for research and drafting, and human judgement for everything that matters.

Oregula is not a law firm. The frameworks delivered are operational and governance documents, built to help your company set clear internal rules for AI use. They are not legal advice or a substitute for a qualified lawyer's opinion on regulatory compliance.

For matters requiring a legal opinion, including formal regulatory compliance sign-off, please consult a licensed legal professional. Oregula's frameworks are designed to work alongside your legal counsel, not replace them.

Start with a pilot review

Tell us about your AI stack and current data handling. We'll come back with a short read on your exposure and whether a pilot review makes sense.

Email hello@oregula.com

Or connect on LinkedIn for a quicker first conversation.