Univate Solutions works with clients in both IT and non-IT sectors. Which standards and laws matter depends on an organisation’s sector and its customers, so this page sets out what applies where and which regulator or issuing body sits behind each requirement. Service detail for every item named here is on our services page.
Banking, financial services and insurance
Indian financial entities answer to sectoral regulators: the Reserve Bank of India for banks, non-banking financial companies and credit information companies, the Securities and Exchange Board of India for market intermediaries, and the Insurance Regulatory and Development Authority of India for insurers. The RBI issued its Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices in November 2023, effective from 1 April 2024, setting board-level expectations for IT governance, risk and assurance. Where card payments are involved, PCI DSS applies as a scheme requirement of the PCI Security Standards Council, not as an RBI instrument.
- ISO/IEC 27001 for the information security management system
- PCI DSS wherever cardholder data is stored, processed or transmitted
- ISO 22301 for business continuity, which regulators expect to be tested rather than documented
- DPDP Act compliance for customer personal data
IT services, ITES and business process outsourcing
For an Indian services company the binding requirement usually comes from the customer’s procurement process, not from a regulator. Vendor security reviews ask for ISO/IEC 27001 or a SOC 2 report, often both, because they answer different questions: ISO/IEC 27001 certifies that a management system exists and is maintained, while a SOC 2 Type 2 report gives a CPA firm’s opinion on how controls operated across a period.
- ISO/IEC 27001, whose 2022 edition carries 93 Annex A controls in four themes
- SOC 2, attested under AICPA standards by a licensed CPA firm
- CMMI appraisal, with the rating published in ISACA’s PARS and valid three years
- ISO/IEC 20000-1 for managed and shared services operations
- GDPR where EU personal data is processed on a client’s behalf
Our case studies here include a CMMI Maturity Level 5 rating for Ceinsys Tech across the Development and Services models.
Healthcare and health information services
An Indian organisation handling health data for United States clients is normally a business associate under HIPAA, US federal law administered by the Department of Health and Human Services. HIPAA has no certificate, so assurance comes from assessment against its Privacy and Security Rules and from the business associate agreement. Within India, provider accreditation is run by the National Accreditation Board for Hospitals and Healthcare Providers, a constituent board of the Quality Council of India, and personal data obligations come from the Digital Personal Data Protection Act, 2023.
- HIPAA assessment for business associates of US covered entities
- ISO/IEC 27701 for a privacy information management system built on ISO/IEC 27001
- Data privacy compliance, including health records work
- ISO 22301 where clinical or claims processing cannot tolerate downtime
Our HealthRecon Connect case study records a CMMI Maturity Level 3 rating.
Manufacturing and engineering
Manufacturing carries the widest spread of management system standards because quality, environment and worker safety are governed separately. Factory safety in India sits under the Factories Act, 1948, and environmental consent is granted by the State Pollution Control Boards under the Central Pollution Control Board. ISO 14001 and ISO 45001 do not replace those statutory duties. They give a system for identifying them and showing they are met.
- ISO 9001 for quality management
- ISO 14001 for environmental management
- ISO 45001 for occupational health and safety
- ISO 55001 where plant and physical assets drive the cost base
- SIRI assessment for digital manufacturing maturity
Automotive and telematics
Suppliers to the automotive industry are assessed under TISAX, governed by the ENX Association on behalf of the VDA, the German association of the automotive industry. TISAX is not an ISO certificate: assessments are performed by ENX-approved audit providers and results are shared with participants through the ENX exchange rather than published publicly.
- TISAX assessment for automotive supply chain participants
- ISO/IEC 27001 as the underlying information security management system
- Vulnerability assessment and penetration testing for connected devices and platforms
Our Infotrack Telematics case study covers CMMI Level 3 consulting and appraisal in this sector.
Logistics, supply chain and retail
Distribution and retail operations are judged on continuity and on how they handle payments and customer data. PCI DSS applies to any retailer or e-commerce operator touching cardholder data, and the Digital Personal Data Protection Act, 2023 applies to the customer records behind loyalty and delivery.
- ISO 9001 for consistent service delivery across sites
- ISO 22301 for business continuity across the network
- PCI DSS for payment environments
- Statutory and regulatory compliance across states
Food and beverage
Food businesses in India are licensed and regulated by the Food Safety and Standards Authority of India, established under the Food Safety and Standards Act, 2006. HACCP, the hazard analysis and critical control point system set out in the Codex Alimentarius, is the method for identifying and controlling food safety hazards. ISO 22000 wraps that method inside a certifiable food safety management system.
- ISO 22000 for a food safety management system
- HACCP for hazard analysis and critical control points
- ISO 9001 where customers audit quality separately from food safety
Government and public sector
Public sector tenders in India frequently set a CMMI maturity level or an ISO/IEC 27001 certificate as an eligibility condition, which makes the rating a bidding requirement rather than an internal improvement exercise. The Indian Computer Emergency Response Team issued directions on 28 April 2022 requiring specified cyber security incidents to be reported to CERT-In within six hours of noticing them. Those directions reach service providers, intermediaries and data centres.
- CMMI appraisal for tender eligibility and delivery maturity
- ISO/IEC 27001 for the security management system named in most tender documents
- NIST Cybersecurity Framework where a control-level baseline is asked for
Frequently asked questions
Does Univate work only with IT companies?
No. Univate Solutions works with clients from both IT and non-IT sectors, and standards such as ISO 9001, ISO 14001, ISO 45001, ISO 22000 and ISO 55001 are sector neutral by design.
Which standards apply to an Indian company serving European clients?
The General Data Protection Regulation, Regulation (EU) 2016/679, applies to an Indian organisation that offers goods or services to people in the European Union or monitors their behaviour there, whether or not it has an EU establishment. Most such organisations pair that work with ISO/IEC 27001 and ISO/IEC 27701.
Which standard should a manufacturer start with?
ISO 9001 is the usual starting point, because it uses the same harmonised structure as ISO 14001 and ISO 45001. Once the quality management system is running, environment and safety can be added to it and audited in a combined visit instead of three separate ones.
Are sector specific schemes audited the same way as ISO standards?
No. An ISO certificate follows accredited certification: Stage 1 and Stage 2 audits, annual surveillance and a three year cycle. A CMMI rating comes from a Benchmark Appraisal led by an ISACA Certified Lead Appraiser, valid three years with no surveillance. TISAX results come from an ENX-approved audit provider. SOC 2 is an attestation report from a CPA firm, not a certificate.






