GRC for Indian regulated firms
GRC,simplified.
One GRC platform for co-operative banks, NBFCs, insurers and brokers regulated by RBI, SEBI and IRDAI.

Who it is for
Same regulations. Smaller teams. Smaller budgets.
- Co-operative banks
- NBFCs
- Microfinance lenders
- Insurance brokers
- RBI, SEBI, IRDAI and CERT-In issue circulars faster than a small team can map them to controls.
- Co-operative banks and NBFCs run GRC on spreadsheets and email, so the board sees several versions of the truth.
- The DPDP Act 2023 and DPDP Rules 2025 add consent, breach notice and data protection duties on top of sector rules.
Same RBI circulars. Same CERT-In deadlines. Same penalties.
A fraction of the team and budget.
Our aim Affordable, easy-to-use, enterprise-grade GRC for every small and mid-size firm.
Industry content packs
Packs for the industries we serve in India.
A pack is the regulations, controls, risks, policies and audit tests for one industry, mapped before you start. Banking and finance ships today; the rest follow.
- Available
Banking and finance
Co-operative banks, NBFCs, microfinance lenders, insurers and brokers
Maps to RBI CSF, SEBI CSCRF, IRDAI, DPDP, CERT-In
- Coming
IT and ITES
Software, services and BPO firms serving regulated clients
Maps to CERT-In directions, DPDP, ISO 27001, SOC 2
- Coming
Telecom
Licensed operators, ISPs and tower companies
Maps to DoT licence conditions, TRAI, CERT-In, DPDP
- Coming
Manufacturing
Plants with OT, supply chains and export customers
Maps to ISO 27001, IEC 62443, DPDP
- Coming
Energy and utilities
Power generators, distribution companies, oil and gas
Maps to CEA cyber security guidelines, NCIIPC, ISO 27001
Why this matters now
GRC failures now cost real money, not just audit points.
- 353
penalties imposed by the RBI on banks and other regulated entities in FY25
Business Standard, June 2025 (opens in a new tab) - ₹25.5 cr
average cost of a data breach in India, 2026
IBM Cost of a Data Breach, 2026 (opens in a new tab) - ₹250 cr
maximum penalty under the DPDP Act
DPDP Act 2023, Schedule (opens in a new tab) - 6 hours
to report a cyber incident to CERT-In
CERT-In Directions, April 2022 (opens in a new tab)
India figures, each linked to its source.
What makes it different
Same breadth as the global suites. Built for smaller firms.
One control library that every framework maps to, with six things the global suites do not give a smaller firm.
Your regulator, already inside.
RBI CSF, SEBI CSCRF, CERT-In directions and DPDP come mapped to controls, risks, policies and audit tests.
See the frameworksLive in minutes.
Describe your organisation. Sastrum scopes your risk universe, suggests your controls and drafts your first policies, the same day.
See risk scopingAI a regulator can audit.
Lumina suggests and drafts, and shows the clauses it relied on. A named person approves every decision, and every AI action is logged.
Lumina drafts. People sign.
How Lumina worksOne record, separate lanes.
Risk, compliance and audit share the same controls and evidence. Each keeps its own data and approvals. The board sees one view across three lines of defence.
Explore the platformOne licence.
Governance, compliance, audit and incidents under one licence. In our cloud, your private cloud or on your premises, with the same features.
Security and deploymentPlatform plus people.
With the product come our services: virtual CISO, managed GRC and security testing.
Talk to us
Our experience, built into the product
20years of GRC advisory and regulatory audits
We did not start from a blank page. Every lesson from those years has gone into the product, so you buy the learning with the software.
- GRC advisory
- Regulatory audits
- Learning, built in
Built with a national bank against 300 tendered requirements.
What we are working on now
This is just the start.
Board
Board-level risk simulation
Coming soon
Chief Risk Officer
Risk quantification and predictive risk
Coming soon
Chief Compliance Officer
Continuous compliance and regulation-change impact simulation
Coming soon · Q4 2026
CISO
Continuous control monitoring and quantum computing impact simulation
Coming soon
Chief Internal Auditor
Automatic work papers
Coming soon
Data Protection Officer
Continuous data protection
Coming soon
Build the next chapter with us.
See Sastrum run on your own regulators, help shape it for your sector, or join as a founding customer.
See it running
Thirty minutes, opened on a risk universe already scoped to your sector and regulators.
Partners
Design partners shape the content for their sector or country. Consultants, integrators and regulatory experts take Sastrum to each launch market.
Founding customers
Founding-customer terms and a seat on our product council.
Born in India. Built for the world.