INDUS White Paper v1.0 — Pithonix AI — May 2026 ← Back to GCC Playbook
White Paper — Version 1.0

INDUS: India's GCC
Certification Standard

Integrated National Digital Unified Standard for Global Capability Centres

Government of Telangana
May 2026
Government Validation Draft
Pithonix AI India Pvt Ltd
U62090TS2026PTC213220
1.0 — Pre-MoU Draft
Confidential — Not for Distribution Without Written Consent of Pithonix AI India Private Limited

Executive Summary

India hosts over 53% of the world's Global Capability Centres. No other country comes close. Yet the compliance and certification landscape these GCCs navigate is borrowed from standards built for manufacturing plants, software companies, and financial institutions. None of it was designed for a captive entity that serves a foreign parent, employs Indian talent, handles cross-border data, and operates under two or more regulatory jurisdictions simultaneously.

INDUS is India's response to that gap. The Integrated National Digital Unified Standard for Global Capability Centres is a purpose-built certification framework, designed specifically for GCCs operating in India, that converges the governance work behind ISO 9001, ISO 27001, SOC 2, and regional standards into a single unified assessment, so a GCC pays once for the underlying work instead of repeating it across every certification.

Eight assessment domains cover every dimension of GCC maturity: governance alignment, cross-border data integrity, talent ecosystem maturity, operational integration, multi-jurisdiction regulatory compliance, AI and digital readiness, business continuity, and innovation contribution. Three certification levels serve GCCs at every stage of their lifecycle. The standard is governed by the INDUS Board, endorsed by the Government of Telangana, and powered by the Pithonix AI technology platform.

INDUS is India's opportunity to do for GCC excellence what UPI did for digital payments: define the global standard from the country that owns the market.

The Problem: Standards Built for Someone Else

A GCC in Hyderabad serving a US-headquartered parent in financial services currently spends Rs 28 to 63 Lakhs per year maintaining overlapping certifications: ISO 9001 for quality management, ISO 27001 for information security, SOC 2 for parent company audit requirements, GDPR documentation for European data flows, SEBI-aligned controls for financial data, and SEZ compliance for tax obligations.

Each of these audits uses a different framework, a different audit firm, different documentation formats, and different review cycles. A GCC team wastes 4 to 6 months per year on compliance theatre. The auditors are not wrong. The standards are not wrong. They were simply designed for different entities.

Applying ISO standards to a GCC is like measuring a submarine with an aircraft's flight checklist. Both are engineering marvels. Both require rigorous standards. But the frameworks must match the operating reality. INDUS is that match.

The 8 Assessment Domains

Every INDUS assessment evaluates the GCC across eight domains. Domain weightings adjust by certification level, reflecting what matters most at each stage of GCC maturity. Weights shown as percentage of total score.

Blue = INDUS Ready Green = INDUS Certified Purple = INDUS Prime
D1
Governance Alignment
12% 12% 10%

Assesses whether the GCC has a clearly defined governance structure that aligns with the parent company mandate, local regulatory obligations, and Indian statutory requirements. Covers board composition, delegation of authority, fiduciary accountability, and reporting integrity.

  • Board and governance structure documented
  • Delegation of authority matrix defined
  • Regulatory filings current (ROC, RBI, FEMA)
  • Internal audit function operational
  • Stakeholder reporting cadence established
D2
Cross-Border Data Integrity
15% 15% 14%

Evaluates the GCC's ability to manage, protect, and govern data that flows between India operations and the parent entity or third parties across jurisdictions. Covers DPDPA 2023 compliance, data localisation, encryption standards, and cross-border transfer agreements.

  • DPDPA 2023 compliance framework in place
  • Data classification policy documented
  • Cross-border data transfer agreements signed
  • Encryption standards (AES-256 minimum) enforced
  • Data localisation requirements mapped and met
  • Data breach response plan tested
D3
Talent Ecosystem Maturity
14% 13% 12%

Measures the depth, stability, and strategic value of the GCC's talent engine. Covers attrition management, career architecture, local talent development, leadership pipeline, and workforce planning aligned to GCC growth.

  • Attrition rate below sector benchmark
  • Career architecture and levelling framework documented
  • Leadership pipeline programme operational
  • Local talent development initiatives active
  • Workforce plan tied to 3-year GCC roadmap
  • Diversity and inclusion metrics tracked
D4
Operational Integration
13% 14% 13%

Assesses how deeply the GCC is embedded into the parent organisation's operational workflows. Covers SLA adherence, process ownership, technology integration, and the degree to which the GCC operates as a genuine capability centre rather than a cost-arbitrage unit.

  • SLAs defined and tracked for all major functions
  • Process ownership documented end-to-end
  • Technology stack integrated with parent systems
  • Quality management system operational
  • Continuous improvement programme active
  • Knowledge management framework in place
D5
Regulatory Multi-Jurisdiction
18% 17% 15%
⚠ Automatic Disqualification Domain — Non-Compliant on ANY single criterion in D5 results in immediate assessment failure, regardless of scores in all other domains.

Evaluates the GCC's compliance posture across all applicable jurisdictions: India (MCA, RBI, SEBI, SEZ/IT Act, labour law), parent-country regulations (GDPR, SOX, CCPA where applicable), and sector-specific obligations. The highest-weighted domain in INDUS Ready and Certified assessments.

  • MCA annual filings current
  • FEMA compliance documented (ODI/FDI flows)
  • SEZ / IT park obligations met (if applicable)
  • Labour law compliance confirmed (EPFO, ESIC, Shops Act)
  • Parent-country regulations mapped and addressed
  • Sector-specific compliance (IRDAI, SEBI, RBI as applicable)
  • Export control compliance (if technology transfer involved)
D6
AI and Digital Readiness
10% 11% 13%

Measures the GCC's adoption of AI, automation, and digital tools to deliver value beyond cost reduction. Covers AI governance, responsible AI practices, digital capability building, and the GCC's role in the parent's digital transformation.

  • AI adoption roadmap documented
  • Responsible AI policy in place
  • Automation initiatives active with measurable outcomes
  • Digital skills programme for employees
  • AI governance committee or owner designated
  • Data quality standards for AI and ML use cases
D7
Business Continuity (Captive)
9% 10% 10%

Assesses the GCC's resilience against operational disruption. Covers BCP/DR planning, crisis management, redundancy architecture, and tested recovery capabilities tailored to a captive entity that serves as the parent's operational backbone.

  • BCP documented and tested annually
  • DR site or cloud failover operational
  • Crisis management protocol defined
  • Key person dependency risk mitigated
  • Vendor concentration risk assessed
  • Insurance coverage adequate and current
D8
Innovation and Value Contribution
9% 8% 23%

Evaluates the GCC's strategic contribution beyond its original mandate. Covers IP creation, patents, product and platform ownership, global leadership roles held by India team members, and measurable innovation outcomes. This is the most heavily weighted domain in INDUS Prime, distinguishing true Centres of Excellence from high-function delivery centres.

  • Innovation charter or mandate from parent
  • Patents filed or granted from India operations
  • Products or platforms owned or co-owned by India team
  • Global leadership roles held by GCC employees
  • R&D spend tracked and reported
  • Innovation outcomes presented to parent board annually
  • Collaboration with Indian academia or startups

Three Certification Levels

INDUS serves GCCs at every stage of their lifecycle. The three levels are progressive but not mandatory in sequence: a GCC that meets INDUS Certified criteria can apply directly at that level.

Badge Target GCC Mode Validity Fee (INR Lakhs)
INDUS READY New GCCs (0 to 2 years), beginning formalisation Self-assessment with platform verification 1 year 1.5 to 2.5
INDUS CERTIFIED Established GCCs (2 to 5 years) with operational maturity On-site assessment by accredited assessor 2 years 3.5 to 5
INDUS PRIME Mega GCCs (5,000+ employees), R&D hubs, Centres of Excellence Full independent audit, board-level review 3 years 7 to 10

The 7-Step Certification Journey

Total duration: 38 to 60 days depending on GCC size, complexity, and responsiveness.

  1. 1
    Application Submission (Day 1 to 3) GCC submits application via the INDUS digital platform with company details, current certifications, headcount, and self-declared domain scores.
  2. 2
    Eligibility Review (Day 3 to 8) INDUS Board secretariat reviews the application for completeness and assigns the appropriate certification level based on GCC age, size, and declared maturity.
  3. 3
    Document Upload and Verification (Day 8 to 18) GCC uploads supporting documentation for all 8 domains. Platform performs automated checks on regulatory filing dates, SLA templates, and policy documents.
  4. 4
    Assessor Assignment (Day 18 to 21) For INDUS Certified and INDUS Prime, an accredited assessor firm is assigned. GCC confirms assessor within 5 business days.
  5. 5
    On-site Assessment (Day 21 to 31) Assessor conducts on-site review across all 8 domains. Structured interviews with GCC leadership, functional heads, and HR. Document verification and process walkthroughs. INDUS Ready assessments are conducted remotely.
  6. 6
    Assessment Report and Score (Day 31 to 38) Assessor submits domain-by-domain scores and narrative report. GCC receives preliminary scores and has 5 days to submit factual corrections only. No disputes on scoring methodology at this stage.
  7. 7
    Certification Decision and Badge Issuance (Day 38 to 43) INDUS Board reviews the report and issues the final certification decision. Digital badge issued within 2 business days of decision. Physical plaque dispatched within 15 days. GCC listed on the INDUS Public Registry.

Assessment Fees and Revenue Split

Assessment fees are annual certification maintenance fees. Initial assessment may carry a one-time assessor mobilisation charge of Rs 50,000 to Rs 1,50,000 depending on location and GCC size.

Certification Level Annual Fee (INR Lakhs) Notes
INDUS READY 1.5 to 2.5 Lower end for GCCs under 500 employees. Self-assessment mode.
INDUS CERTIFIED 3.5 to 5.0 On-site assessment included. Higher end for multi-city GCCs.
INDUS PRIME 7.0 to 10.0 Full audit. Price includes board-level review session.

Revenue Split

60%
Accredited Assessor Firm
30%
INDUS Board (Governance)
10%
Pithonix AI (Technology Platform)

Implementation Timeline

Month 1 to 2
Government Validation MoU signing with Government of Telangana. INDUS Board constituted with representation from government, industry, and academia. Legal framework for IP ownership and governance authority established.
Month 2 to 4
Assessor Accreditation Programme First cohort of INDUS-accredited assessor firms trained and certified. Assessment methodology documented and published. Assessor code of conduct signed.
Month 4 to 6
Pilot Cohort 10 to 15 GCCs participate in pilot assessments across all three levels. Framework calibrated based on real-world findings. D5 auto-disqualification criteria stress-tested in the field.
Month 6 to 8
Framework Refinement Pilot feedback incorporated. Domain weightings validated. Scoring rubrics updated based on pilot assessor findings. Published as INDUS v1.1.
Month 8 to 10
INDUS Registry Launch Public INDUS Registry live at gcc-playbook.pithonix.ai/indus-registry. First certified GCCs listed. Registry searchable by city, industry, certification level, and domain scores.
Month 10 to 12
Formal Publication Formal publication through the empanelled INDUS Board. Auditor accreditation programme fully launched. First official INDUS certifications issued at scale. Industry-wide awareness campaign launched.
Month 12+
State Integration and Global Pathway Other state GCC policy integration. Commercial licensing for states and bodies that wish to adopt INDUS. Engagement with ISO/TC for potential global GCC standard based on INDUS.

The Role of Pithonix AI

Pithonix AI serves as the technical architect and digital infrastructure provider for INDUS. The GOT (Graph of Thought) engine already reasons across 8 domains for GCC decision-making. The same 8-domain architecture maps directly to the INDUS assessment framework. JEET ERP serves as the continuous compliance monitoring layer for INDUS-certified GCCs: real-time dashboards, domain-by-domain compliance status, not point-in-time annual audits.

Pithonix does not seek to own the standard. Standards must be industry-governed and publicly accessible to gain trust and adoption. The INDUS Board will be constituted with representation from government, industry, and academia. Pithonix provides the technology that makes INDUS practical, scalable, and digitally native from day one. The 10% platform fee reflects this role: a technology provider, not a gatekeeper.

The INDUS Public Registry, the digital assessment platform, the assessor portal, and the GCC compliance dashboard are all built and maintained by Pithonix AI under the terms of the MoU with the Government of Telangana.

Addendum IV — Version 1.0 — June 2026

Addendum IV: Solving the Dual Compliance Cost Problem

How INDUS maps to ISO 27001, SOC 2, and Zero Trust — without adding cost to the GCC. Audience: MeitY, NABCB, State IT Departments, GCC CFOs and CISOs.

Executive Summary

Every GCC operating in India today carries the cost of multiple parallel compliance certifications: ISO 27001 for international recognition, SOC 2 Type II for the US parent company's procurement team, DPDP Act compliance for Indian data protection law, and CERT-In directives for incident reporting. If INDUS were added as a fourth or fifth layer, it would not strengthen the framework. It would weaken adoption and damage the credibility of Indian policy itself.

This addendum solves that problem at the design level. INDUS is positioned as the India-native certification framework that structurally maps to the global standards GCCs already pay for. A GCC that achieves INDUS certification has simultaneously completed 60 to 70 percent of the documentation, controls, and governance work required for ISO 27001:2022. Through formal recognition pathways with NABCB and bundled audit arrangements with AICPA-licensed CPA firms, INDUS becomes the on-ramp to global compliance, not a parallel track.

The result is a single assessment process that produces three outputs: the INDUS certificate for Indian government incentives, the ISO 27001 certificate for international recognition, and the SOC 2 Type II report for the US parent company. One audit team. One evidence collection cycle. Total compliance cost reduced by 40 to 50 percent compared to running each separately.

The core principle of this addendum: INDUS adds value to a GCC by reducing total compliance cost, never by adding to it. If a GCC pays twice for the same governance work, the policy has failed.

1. The Dual Cost Problem — As It Stands Today

A typical mid-size GCC operating in India in 2026 carries the following compliance footprint:

CertificationIssued ByRequired ForTypical Cost (Yr 1)
ISO 27001:2022Accredited certification body (NABCB-recognised)International recognition; mandatory in EU under NIS2Rs 18–35 lakh
SOC 2 Type IIAICPA-licensed US CPA firmUS parent company procurement and vendor onboardingRs 22–45 lakh
DPDP Act complianceSelf-attested; audited by Significant Data Fiduciary auditorIndian law for personal data of Indian residentsRs 8–18 lakh
CERT-In complianceSelf-attested; reviewed by MeitYMandatory in India for incident reportingRs 3–8 lakh
INDUS (proposed)INDUS Empanelled Board (Government of India)Indian government incentive tiers; strategic recognitionTo be determined

Total compliance cost in Year 1 for a mid-size GCC, before INDUS, ranges from Rs 51 lakh to Rs 1.06 crore. Recurring annual cost ranges from Rs 25 to 55 lakh. These are not theoretical numbers — these are what GCC CFOs are paying today, in 2026.

Why Each Layer Exists — And Why None Can Simply Be Removed

ISO 27001 cannot be replaced by Indian frameworks. It is an international standard certified under the International Accreditation Forum's mutual recognition arrangement; India is a signatory through NABCB. INDUS can map to ISO 27001 controls, but it cannot replace the international audit.

SOC 2 Type II cannot be replaced by any framework outside the AICPA. Only AICPA-licensed CPA firms can issue a SOC 2 report, and this is a contractual requirement embedded in master services agreements between the parent and the GCC. INDUS is not AICPA-licensed and cannot become AICPA-licensed.

DPDP and CERT-In are statutory obligations under Indian law, not optional, and cannot be replaced by any private or international certification.

The conclusion: INDUS cannot replace any of these certifications. But INDUS can be designed so that a GCC pays once for the underlying governance work, and the same work satisfies INDUS, ISO 27001, and the foundational controls required for SOC 2 and DPDP simultaneously.

2. The INDUS Design Principle — Convergence, Not Duplication

ISO 27001 and SOC 2 already overlap by approximately 80 percent in the underlying controls they test: access management, change control, incident response, data classification, third-party risk management, business continuity, and physical security. ISO 27001:2022 specifies 93 controls across four themes: Organisational, People, Physical, and Technological. By structuring INDUS assessment criteria explicitly to mirror these controls, INDUS becomes a pre-certification pathway — one body of documentation work, one set of evidence collection, one governance implementation cycle, used for both INDUS and ISO 27001.

  1. 1
    INDUS Assessment Criteria Mapped to ISO 27001:2022 Annex A ControlsEvery INDUS criterion references the corresponding ISO 27001:2022 control, designed in collaboration with NABCB-recognised ISO 27001 auditors. The mapping is reviewed annually and updated for new ISO versions.
  2. 2
    NABCB Bilateral Recognition PathwayPithonix AI, with MeitY, engages NABCB to recognise INDUS as a pre-certification framework. A GCC holding INDUS certification presents it to an ISO 27001 certification body as evidence that ~60–70% of implementation work is complete. Impact: ISO 27001 audit timeline drops from 6–9 months to 6–8 weeks; audit cost drops from Rs 18–35 lakh to Rs 3–6 lakh.
  3. 3
    Bundled INDUS-Plus-SOC2 Audit Through CPA Partner NetworkThe same evidence used in an INDUS assessment is ~75% of the evidence required for SOC 2 Type II. Pithonix AI establishes a network of AICPA-licensed CPA firms in India who conduct INDUS assessment and SOC 2 Type II audit as one bundled engagement, billed 35–45% lower than two separate engagements. This bundled audit is the most important commercial innovation of the INDUS framework.

3. The INDUS-to-ISO 27001:2022 Mapping Table

This mapping is the basis for the structural alignment that makes single-evidence, multi-certification possible.

INDUS DomainISO 27001:2022 ThemeSpecific ISO ControlsOverlap %
Strategic Governance & Capability MaturityOrganisational (A.5)A.5.1, A.5.2, A.5.4, A.5.19, A.5.3185%
People & Workforce QualityPeople (A.6)A.6.1–A.6.680%
Operational Excellence & ProcessOrganisational (A.5) & Technological (A.8)A.5.30, A.5.37, A.8.16, A.8.3270%
Infrastructure & Physical SecurityPhysical (A.7)A.7.1, A.7.2, A.7.4, A.7.8, A.7.1090%
Technology & Information SecurityTechnological (A.8)A.8.1, A.8.3, A.8.5, A.8.16, A.8.23, A.8.2875%
Data Governance & DPDP AlignmentOrganisational (A.5) & Technological (A.8)A.5.12, A.5.13, A.5.34, A.8.10, A.8.1170%
Business Continuity & ResilienceOrganisational (A.5)A.5.29, A.5.30, A.8.13, A.8.1485%

Aggregate overlap across all seven INDUS domains: 79 percent. A GCC implementing INDUS to the required maturity tier has already completed 79 percent of the ISO 27001:2022 implementation work. The remaining 21 percent is formal ISMS documentation, Statement of Applicability, risk treatment plan, and the Stage 1/Stage 2 audit only an accredited certification body can conduct.

4. How DPDP Act 2023 and CERT-In Compliance Are Embedded in INDUS

The DPDP Act 2023 and DPDP Rules 2025 establish India's statutory data protection framework: annual Data Protection Impact Assessments, independent audits, breach notification within prescribed timelines, consent artefact management, and grievance redressal. These obligations require privacy-by-design, federated data models, tokenised consent, zero-trust access controls, and cryptographic auditability — patterns that overlap with both ISO 27001 controls and INDUS data governance criteria.

A GCC achieving INDUS Gold or Platinum tier has, by definition, demonstrated DPDP and CERT-In compliance exceeding the statutory minimum. INDUS becomes the consolidated India-side compliance anchor.

5. The Bundled Cost Outcome — What the GCC Actually Pays

CertificationWithout INDUS MappingWith INDUS Mapping
ISO 27001:2022Rs 18–35 lakhRs 3–6 lakh
SOC 2 Type IIRs 22–45 lakhRs 12–22 lakh (bundled)
DPDP & CERT-InRs 11–26 lakhEmbedded in INDUS
INDUS CertificationNot applicableRs 8–15 lakh
Total Year 1 costRs 51 lakh – Rs 1.06 croreRs 23–43 lakh

A mid-size GCC adopting INDUS through the structural mapping pathway saves Rs 28 to 63 lakh in compliance costs in the first year alone, and Rs 1.4 to 3.2 crore over a 5-year operating period — direct and defensible savings, arriving in the GCC's P&L from Year 1.

Under this design, the GCC CFO does not view INDUS as an additional government compliance burden. The CFO views INDUS as the cost-reducing mechanism for certifications the GCC is already required to obtain. Indian government incentives layered on top — SEZ tax holidays, employment generation subsidies, rental reimbursements, PoC grants — are additional value, not the primary reason for adoption. INDUS is not a cost. INDUS is a cost reducer.

6. Implementation Pathway

MeitY formally recognises INDUS as the consolidated India-side compliance framework, publishes the INDUS-to-ISO 27001 mapping table, and engages NABCB. NABCB recognises INDUS as a pre-certification pathway and guides accredited certification bodies on accepting INDUS certificates as partial ISO 27001 readiness evidence. The INDUS Empanelled Board empanels AICPA-licensed CPA firms as bundled audit providers and maintains the mapping table. Pithonix AI operates the technology platform on which assessments are recorded, evidence is uploaded, and certificates are issued.

Months 1–6
Policy FinalisationMeitY publishes INDUS policy with mapping table; NABCB recognition pathway formalised; INDUS Empanelled Board constituted; mapping reviewed by 3 NABCB-accredited certification bodies.
Months 7–12
CPA Partner NetworkAICPA-licensed CPA firms empanelled; bundled audit pricing established; pilot bundled audits with 5–8 voluntary GCCs in Telangana and Karnataka.
Months 13–18
Pilot ValidationPilot GCC outcomes evaluated; cost-saving claims validated against actual audit invoices; framework refinements published; ISO 27001 certification body feedback incorporated.
Months 19–24
National RolloutINDUS opens to all GCCs nationally; Simulator integration goes live; state IT departments link INDUS tier to incentive disbursement.
Ongoing
Annual ReviewMapping table reviewed annually; updated for ISO 27001 revisions; CPA partner network expanded; cross-recognition pursued with NIS2 and HIPAA.

7. Safeguards — Preventing Misuse of the Framework

Conclusion — INDUS as the Cost-Reducing Layer

With 2,117 GCCs operating in India across 3,728 units in 2026 and a projected 2,500+ by 2030, the cost of fragmented, parallel compliance certifications has become a measurable drag on the sector's competitiveness. INDUS solves this — not by replacing the international standards, which it cannot and should not attempt, but by becoming the structural framework that maps to ISO 27001, carries embedded DPDP and CERT-In compliance, and is delivered through bundled audits with AICPA-licensed CPA firms that simultaneously produce the SOC 2 Type II report. One assessment. Three outputs. Cost reduced by 40 to 50 percent.

This is more tangible than tax holidays, more immediate than employment subsidies, and more universal than state-specific incentives. The Indian government has the policy authority. NABCB has the technical authority to recognise the mapping. AICPA-licensed CPA firms operating in India are willing commercial partners. Pithonix AI provides the technology platform, the GCC Playbook Simulator, and the operational expertise to manage the framework at scale.

INDUS is the only India-native framework designed from inception to reduce a GCC's total compliance cost, not add to it. The remaining step is policy formalisation by MeitY and recognition by NABCB.

◆ ◆ ◆
End of Addendum IV — Pithonix AI India Private Limited — June 2026

Intellectual Property and Copyright

Copyright Notice and Ownership

PITHONIX AI INDIA PRIVATE LIMITED
U62090TS2026PTC213220
AAQCP8532M
Hyderabad, Telangana, India
18th March 2026, Companies Act 2013
info@pithonix.ai

The INDUS framework, including its name, methodology, 8-domain architecture, scoring rubrics, certification levels, badge designations, assessment process, revenue split model, and all associated documentation, is the sole and exclusive intellectual property of PITHONIX AI INDIA PRIVATE LIMITED.

The Government of Telangana holds governance and endorsement authority through the INDUS Board, as defined in the MoU between Pithonix AI India Private Limited and the Government of Telangana. Governance authority does not constitute ownership of the underlying IP.

Commercial licensing is required for adoption of INDUS by any other state government, central government body, industry association, or private entity. Licensing enquiries: satyajitv.d@pithonix.ai