RESPONSIBLE AI
AI Should Expand Human Possibility Not Reduce Human Agency.
DISHA 4.0 HCOS uses artificial intelligence to help people understand capability, discover opportunities, learn, make decisions and act. Because these systems can affect real people and real choices, we design them around human oversight, evidence, transparency, privacy, security, fairness, accountability and continuous evaluation.
A transparent AI pathway: Evidence → Model/Agent → Explanation → Human Review → Action → Feedback.
Human Review sits inside the pathway itself — outputs are not “done” when the model finishes; they are done when accountable people have the authority and information to act.
Responsible AI Governance & Transparency Centre · Page spec v1.0 · [PLACEHOLDER — RESPONSIBLE AI POLICY OWNER / APPROVING AUTHORITY] · [PLACEHOLDER — EFFECTIVE DATE]
“AI can be useful without being unquestionable. DISHA is designed so that AI outputs can be understood in context, challenged when appropriate, reviewed by accountable people, and improved when evidence shows that a system is not behaving as intended.”
Important: this describes the intended governance architecture. Individual products, models, agents and customer deployments may have different controls depending on purpose, risk, data and configuration.
What Responsible AI means at DISHA
At DISHA, responsible AI is not a single model property or a compliance checkbox. It is a lifecycle discipline covering how we define a problem, collect and govern data, select models, design prompts and agents, evaluate outputs, deploy systems, monitor behaviour, handle incidents and learn from real-world use.
Human agency
AI supports people; accountable humans retain appropriate authority over consequential actions.
Inspect
Who owns the decision, what AI did, and what human review is required.Purpose limitation
AI is used for a defined purpose rather than unrestricted profiling.
Inspect
Purpose, permitted use, prohibited use and context.Evidence & provenance
Outputs should connect to relevant evidence where technically possible.
Inspect
Evidence, source, timestamp, freshness and provenance.Transparency
People should know when AI is involved and understand capabilities and limitations.
Inspect
AI disclosure, explanation, limitations and interaction notices.Fairness
Potentially harmful differences are identified and managed according to context.
Inspect
Evaluation population, metrics, thresholds and remediation.Privacy
Personal data is minimized, protected and used for defined purposes.
Inspect
Data categories, purpose, controls, retention and rights routes.Security & robustness
Systems are protected against misuse, manipulation, failure and security threats.
Inspect
Security controls, testing and incident pathway.Accountability
A named owner and governance process exists for material AI systems.
Inspect
Owner, approval state, review date and escalation route.Contestability
People can question, correct or appeal relevant outputs where applicable.
Inspect
Correction, feedback, appeal or human-review mechanism.Continuous improvement
Systems are evaluated after deployment and controls updated when evidence changes.
Inspect
Monitoring, evaluation cadence, change history and incident learnings.The DISHA Responsible AI lifecycle
01 · DEFINE
Identify purpose, affected people, decision context, intended users, foreseeable misuse and risk category.
02 · DATA
Identify sources, provenance, quality, permissions, minimization, retention, representativeness and limitations.
03 · DESIGN
Define human role, user disclosure, explanation requirements, escalation, accessibility and prohibited uses.
04 · DEVELOP
Implement model, retrieval, prompts, agent tools, guardrails, access controls and logging.
05 · EVALUATE
Test validity, reliability, safety, security, privacy, fairness, robustness, hallucination/error behaviour and usability.
06 · APPROVE
Complete documented risk review and obtain required technical, product, security, privacy/legal and accountable-owner approvals.
07 · DEPLOY
Release only the approved version into the approved context.
08 · MONITOR
Track performance, drift, incidents, feedback, override patterns and relevant subgroup behaviour.
09 · RESPOND
Triage incidents, restrict/rollback/disable systems where necessary and communicate material issues.
10 · LEARN
Feed validated evidence into product, model, data and governance improvements.
Human oversight — the core design principle
Human oversight is not a button labelled “human in the loop”. It is a defined responsibility. For each consequential AI-supported workflow, DISHA should specify who can review an output, what information they receive, what authority they have to override it, when escalation is required, and how the action is recorded.
| Use case | AI may assist with | Human responsibility |
|---|---|---|
| Career exploration | Generate and explain possible pathways | Human: User decides whether a pathway is relevant. |
| Learning recommendations | Identify learning options against a goal/gap | Human: Learner or authorised advisor decides. |
| Talent discovery | Surface candidates against defined requirements | Human: Authorised hiring personnel make decisions under applicable policy. |
| Skills intelligence | Map evidence to skills and identify possible gaps | Human: Human validates material evidence and context. |
| Workforce planning | Model scenarios and capability gaps | Human: Authorised leaders decide strategy, budget and workforce actions. |
| Decision intelligence | Frame options, evidence and scenarios | Human: Accountable decision-maker owns the decision. |
[PLACEHOLDER — INSERT EXACT HUMAN-OVERSIGHT RULES BY PRODUCT/MODULE AFTER PRODUCT GOVERNANCE REVIEW]
AI system inventory
A public inventory of the material AI capabilities actually operating in DISHA 4.0 HCOS today. It exposes approved public fields only; the canonical internal registry and evaluation records are internal.
NaviBuddy™ explanation assistant
R1 — AssistiveExplains on-screen elements in plain language using an approved, versioned knowledge registry; refuses honestly when no approved record exists. Grounded explanations only — no free generation.
Human roleFully user-controlled; explains, never acts on the page.
Status & known limitationsImplemented. Limitation: explains only what has an approved knowledge record; evaluation summary not yet published.
AI Command Center governed agent
R1 — AssistiveAnswers human-capital questions with governed tool access (readiness, semantic retrieval) and source-linked citations; read-only tools with caller-scoped permissions.
Human roleUser reviews every answer; tools are read-only; human owns all decisions.
Status & known limitationsImplemented. Limitation: answers depend on governed data currency; unsupported questions are refused rather than guessed.
Semantic retrieval & reranking
R0 — InformationalOrders knowledge and resources against a query using lexical plus LLM-assisted reranking over approved content.
Human roleUser chooses what to open; results are views over approved content.
Status & known limitationsImplemented. Limitation: retrieval quality depends on corpus freshness; no individual profiling.
New or materially changed AI capabilities are added here only after governance review. No system is listed until its public record is approved.
AI use-case classification
Not every AI use is equally consequential. DISHA maintains an internal risk taxonomy; this is the public summary. Exact classification is defined by DISHA governance and mapped to applicable law and customer context — a governance control alone is never claimed as legal compliance.
R0 — Informational
Low-impact explanation, navigation or drafting
Posture: Transparency, quality, privacy/security controls.
R1 — Assistive
Recommendations/analysis where user retains direct control
Posture: Disclosure, explanation, evidence, feedback and monitoring.
R2 — Consequential support
AI materially informs employment, education, access or significant decisions
Posture: Enhanced validation, human authority, documented evaluation, auditability and appeal/correction controls.
R3 — Restricted / Prohibited
Uses creating unacceptable or legally prohibited risk
Posture: Do not deploy; maintain prohibited-use register.
Fairness & bias management
AI can reproduce or amplify patterns in data, design choices or human processes. DISHA therefore treats fairness as an evaluation and governance problem, not as a claim that a model is permanently “bias-free.”
Approach
- Identify the population affected and the decision context.
- Document protected or sensitive attributes only where lawful and necessary for evaluation.
- Test meaningful differences in errors, access, recommendations or outcomes where the use case warrants it.
- Evaluate data coverage and known limitations.
- Test both model-level and end-to-end workflow behaviour.
- Where a material issue is identified, define remediation, owner, deadline and re-evaluation.
Boundaries
- Do not infer protected attributes merely because they might be useful for prediction.
- Do not collect sensitive data for fairness testing without documented purpose and lawful basis.
[PLACEHOLDER — APPROVED PUBLIC FAIRNESS METRICS, POPULATIONS, PERIOD, THRESHOLDS AND REMEDIATION STATUS]
Explainability & “Why?”
Explanation should describe the actual mechanism or evidence used. DISHA does not provide a plausible post-hoc story that the model did not actually use — and never exposes hidden chain-of-thought or proprietary internal reasoning.
The “Why?” standard — nine things an explanation may show
- 01Show the user's stated goal/context.
- 02Show the relevant input evidence categories.
- 03Show factors/evidence used, to the extent technically meaningful and safe.
- 04Show what the system did not know.
- 05Show confidence/uncertainty only where a validated measure exists.
- 06Show relevant limitations.
- 07Show alternative interpretations or options where applicable.
- 08Show what a human can correct or challenge.
- 09Show the date/version of the underlying system where appropriate.
This pattern is live in the product
NaviBuddy's explanation cards already follow this anatomy: a plain-language summary, why it matters, where it fits, explicit caveats, and a provenance line naming the knowledge version — with an honest refusal card when no approved record exists.
NaviBuddy™ · plain-language explanation
What does this mean? → summary
Why it matters → whyItMatters
Where it fits → whereItFits
caveat → explicit caveat when one applies
Grounded in approved DISHA knowledge · vX · explains — never acts
Inspect an AI output
A sandboxed demonstration that exposes evidence → output → review. It does not pretend to reveal hidden chain-of-thought or proprietary internal reasoning.
ILLUSTRATIVE — NOT A REAL PERSON / NOT A REAL DECISION
Choose a scenario
Why: the recommendation maps the measured gap (SQL) to the stated goal; module difficulty matches evidenced coursework. The system did not use employment data — none was provided.
Data governance & privacy
| Control | Public explanation |
|---|---|
| Purpose limitation | Data is used for defined purposes rather than unlimited secondary profiling. |
| Data minimization | Collect/use only what is necessary for the stated purpose. |
| Provenance | Maintain source and lineage information for material inputs where feasible. |
| Quality | Track freshness, completeness and known quality limitations. |
| Access control | Limit who and what systems can access AI inputs/outputs. |
| Retention | Apply defined retention/deletion rules. |
| Deletion/correction | Provide applicable routes for correction, deletion or rights requests. |
| Model training use | Clearly state whether user/customer data may be used for training, improvement or evaluation. |
| Third-party processing | Identify material external model/service categories and relevant controls. |
[PLACEHOLDER — EXACT DISHA POLICY ON WHETHER CUSTOMER / USER DATA IS USED FOR FOUNDATION-MODEL TRAINING OR INTERNAL MODEL IMPROVEMENT]
Generative AI & agentic AI
DISHA's Responsible AI programme addresses LLMs, retrieval systems, tool-using agents and automated workflows — not only predictive models.
Prompt governance
Approved system instructions, access boundaries and change control.
Retrieval governance
Authoritative knowledge sources, freshness and provenance.
Tool governance
Tools restricted by role, purpose and least privilege.
Action governance
Read-only assistance distinguished from actions that change records or affect people.
Human confirmation
Confirmation required for defined high-impact actions.
Prompt injection resistance
Retrieval and agents tested against malicious or conflicting instructions.
Output controls
Hallucination, unsafe content, privacy leakage and unsupported claims monitored.
Content provenance
AI-generated/assisted content labelled where required.
Conversation privacy
Storage, retention, access and deletion rules defined.
Model/vendor changes
Material changes re-evaluated.
In the current build, agent tools are read-only and caller-scoped, and answers carry source-linked citations; the remaining controls are in progressive implementation and are not claimed as complete.
Model & agent evaluation framework
| Validity | Does the system address the intended task? |
| Reliability | Does behaviour remain stable under relevant conditions? |
| Accuracy / quality | How well does it perform against an appropriate reference? |
| Grounding | Does generated content remain supported by available evidence? |
| Fairness | Are material disparities detected and managed? |
| Privacy | Can the system expose or infer information beyond the permitted purpose? |
| Security | Can the system be manipulated, exfiltrated or misused? |
| Robustness | How does it behave under noisy/adversarial inputs? |
| Human factors | Can users understand, challenge and appropriately use outputs? |
| Accessibility | Can people use and understand the AI interaction? |
| Drift | Does behaviour change as data, users, models or context change? |
| Agent safety | Can an agent take unintended actions or cross boundaries? |
Evaluation records include system version, evaluation date, test population/data, methodology, metrics, thresholds, known limitations, reviewer, result, remediation and re-test date.
[PLACEHOLDER — PUBLIC AI EVALUATION / MODEL CARD LIBRARY]
AI incidents, errors & safety events
AI systems can fail. Responsible deployment requires a way to recognise failures, contain them, learn from them and provide affected people with an appropriate route for correction or escalation.
S1 — Minor
Log, assess, correct and monitor.
S2 — Material
Assign owner, investigate, remediate and document.
S3 — High impact
Immediate containment, accountable governance review and formal remediation.
S4 — Critical
Disable/rollback where necessary, executive/legal/security escalation and notification where required.
[PLACEHOLDER — PUBLIC AI INCIDENT DISCLOSURE POLICY, REPORTING CHANNEL AND TARGET RESPONSE TIMES]
Report an AI concern
Something about an AI output or decision concerns you? Tell us.
Please do not upload or send passwords, authentication secrets or unrelated personal information.
Routing: Product team → responsible AI owner → privacy/security/legal where relevant → accountable business owner → resolution/correction → user communication.
User rights, correction & contestability
You should be able to distinguish an AI-generated suggestion from a decision made by a person. Where applicable, you should also have a way to correct inaccurate information and ask for human review.
- Explain which outputs are advisory and which can feed into consequential workflows.
- Provide correction of factual source data separately from disagreement with an AI interpretation.
- Provide appeal/review where the use case and law/policy require it.
- Record corrections and propagate them to downstream intelligence where technically appropriate.
- Do not promise that every AI output can be reversed after an external action.
Prohibited & restricted AI uses
DISHA maintains an internal prohibited-use register; this is the public summary.
AI decisions based on protected or sensitive characteristics where prohibited by law or DISHA policy.
Covert surveillance or monitoring without a legitimate, disclosed and governed purpose.
Emotion or psychological inference from weak signals for consequential decisions unless specifically approved, lawful and scientifically defensible.
Automated employment, education or access decisions without required human authority and safeguards.
Fabrication of credentials, experience, evidence or qualifications.
Deceptive impersonation where disclosure is required.
Unapproved autonomous actions materially affecting rights, access, employment, education, finances or reputation.
Incompatible secondary use of personal data without appropriate lawful basis and governance.
Unsupported predictions presented as facts.
Third-party AI & model providers
| Vendor due diligence | Security, privacy, legal, reliability and AI-risk review before material use. |
| Data processing | Document what data is sent, why, where and under what terms. |
| Retention | Understand provider retention and training policies. |
| Model changes | Track material provider/model version changes. |
| Subprocessors | Maintain relevant vendor/subprocessor records. |
| Exit strategy | Define migration/rollback approach for critical functions where practical. |
| Performance | Evaluate vendor outputs in DISHA context, not only vendor benchmarks. |
[PLACEHOLDER — CURRENT THIRD-PARTY AI PROVIDER / MODEL REGISTER APPROVED FOR PUBLIC DISCLOSURE]
AI governance roles
| Board / executive governance | Oversight of material AI risk appetite and strategic accountability, where applicable. |
| Responsible AI owner | Policy, governance process, risk taxonomy and reporting. |
| Product owner | Intended purpose, UX, controls and product-level risk. |
| Model/AI engineering | Builds, evaluates, documents and monitors technical systems. |
| Data governance | Provenance, quality, access, retention and permitted use. |
| Privacy / legal | Lawful basis, rights, contracts and regulatory requirements. |
| Security | Security architecture, threat modelling, testing and incidents. |
| Human reviewer / decision owner | Accountable judgment where human oversight is required. |
| Audit / assurance | Independent review where such a function exists. |
| Users / customers | Feedback, error reporting and use within stated limitations. |
[PLACEHOLDER — INSERT ACTUAL DISHA GOVERNANCE STRUCTURE, COMMITTEE NAMES, ACCOUNTABLE EXECUTIVES AND REVIEW CADENCE]
Transparency Centre — public artifacts
A library of approved governance artifacts. Every artifact carries version, publication date, owner, approval status and supersession relationship. Artifacts appear here only once approved.
Responsible AI Policy
[PLACEHOLDER — pending approval]
AI Governance Framework
[PLACEHOLDER — pending approval]
AI System Register
Public subset — this page's inventory
Model / System Cards
[PLACEHOLDER — approved cards pending]
Risk Assessment Summaries
[PLACEHOLDER — public versions where appropriate]
Evaluation Reports
[PLACEHOLDER — approved summaries pending]
Fairness / Bias Assessments
[PLACEHOLDER — where meaningful and lawful]
AI Incident Reports
None disclosed to date (no material incidents published)
AI Provider Register
[PLACEHOLDER — if approved]
AI Change Log
Maintained with platform release notes
User Guidance
NaviBuddy guidance + glossary available
Contact / Reporting Channel
Live — Report an AI concern on this page
Responsible AI dashboard
A public governance dashboard — populated ONLY from sourced, maintainable indicators: each card states its definition and source. Indicators that cannot be defined, sourced and maintained honestly (review coverage, remediation times) stay hidden until they can be.
AI systems in the public inventory
3
Source: this page's inventory — grows only after governance review
Governed person records
…
Source: Registry, aggregate count only
Capability claims under governance
…
Source: Data Fabric claims, with provenance
Live governed opportunities
…
Source: D04 governed opportunity lifecycle
Governed organizations
…
Source: Registry, aggregate count only
Public evaluation summaries published
0
None approved yet — the model-card library is a placeholder above
Material AI incidents disclosed
0
None to date; disclosure policy is a governance placeholder
Certification claims displayed
0
Evidence-first rule: no badge without a valid certificate
Deliberately absent: review-coverage and remediation-time percentages — no defensible denominator or period exists for public display yet. Estimation is never used to fill a card.
Regulatory & standards alignment
Frameworks we monitor and design against. Alignment is not certification, and certification is never claimed without formal evidence.
NIST AI RMF
A voluntary framework for organizations designing, developing, deploying or using AI systems to manage AI risks and promote trustworthy/responsible AI — covering validity/reliability, safety, security/resilience, accountability/transparency, explainability, privacy enhancement and fairness with harmful bias managed.
NIST Generative AI Profile
Cross-sector guidance for generative AI risk management; the AI RMF is being revised, so DISHA maintains a versioned standards register.
OECD AI Principles (updated 2024)
Inclusive growth and well-being; human rights and fairness; transparency and explainability; robustness, security and safety; accountability.
ISO/IEC 42001:2023
Requirements for establishing, implementing, maintaining and continually improving an AI management system. DISHA does not describe itself as ISO/IEC 42001 certified — no valid certification exists.
EU AI Act (Regulation (EU) 2024/1689)
A risk-based legal framework with staged application. DISHA maintains jurisdiction-specific legal assessments rather than a blanket “EU AI Act compliant” claim.
| Domain | NIST AI RMF | OECD | ISO/IEC 42001 | EU AI Act / other law |
|---|---|---|---|---|
| Risk management | Map/Govern/Measure/Manage | Risk stewardship | AIMS risk/opportunity | Risk-based obligations |
| Human oversight | Trustworthiness/governance | Human agency | Organizational controls | Applicable requirements |
| Transparency | Accountability/transparency | Transparency/explainability | AIMS controls | Transparency obligations |
| Fairness | Bias management | Fairness/non-discrimination | Risk/control processes | Applicable requirements |
| Security | Secure/resilient | Robustness/security/safety | AIMS + ISMS linkage | Cybersecurity requirements |
| Privacy | Privacy-enhanced | Privacy/data protection | AIMS governance | Data protection laws |
| Lifecycle | Pre-design to deployment/evaluation | Lifecycle stewardship | Continual improvement | Provider/deployer obligations |
This crosswalk is a governance aid, not legal advice or certification evidence.
[PLACEHOLDER — INDIA-SPECIFIC RESPONSIBLE AI / DPDP / SECTORAL LEGAL CROSSWALK APPROVED BY COUNSEL]
Responsible AI — questions, answered plainly
It means designing, deploying and governing AI with attention to human agency, evidence, transparency, fairness, privacy, security, accountability, safety and continuous evaluation.
AI should be useful. It should also be understandable, governable and accountable.
Explore how DISHA applies responsible AI across human-capital intelligence — or ask us about the governance controls relevant to your deployment.
Prefer evidence over adjectives, limitations over overconfidence, and explicit accountability over vague assurances. The strongest version of this page is the one that clearly tells users what DISHA does, what it does not do, what evidence supports the claims, what remains under development, who is accountable, and how a person can challenge or report a problem.
Responsible AI · Privacy · Data Protection · Security · Terms · Compliance · Accessibility · Report an Issue · System Status · AI & Human Capital Glossary
