DISHA 4.0 HCOS

RESPONSIBLE AI

AI Should Expand Human Possibility Not Reduce Human Agency.

DISHA 4.0 HCOS uses artificial intelligence to help people understand capability, discover opportunities, learn, make decisions and act. Because these systems can affect real people and real choices, we design them around human oversight, evidence, transparency, privacy, security, fairness, accountability and continuous evaluation.

A transparent AI pathway: Evidence → Model/Agent → Explanation → Human Review → Action → Feedback.

Evidence→Model / Agent→Explanation→Human Review→Action→Feedback

Human Review sits inside the pathway itself — outputs are not “done” when the model finishes; they are done when accountable people have the authority and information to act.

Responsible AI Governance & Transparency Centre · Page spec v1.0 · [PLACEHOLDER — RESPONSIBLE AI POLICY OWNER / APPROVING AUTHORITY] · [PLACEHOLDER — EFFECTIVE DATE]

“AI can be useful without being unquestionable. DISHA is designed so that AI outputs can be understood in context, challenged when appropriate, reviewed by accountable people, and improved when evidence shows that a system is not behaving as intended.”

Important: this describes the intended governance architecture. Individual products, models, agents and customer deployments may have different controls depending on purpose, risk, data and configuration.

What Responsible AI means at DISHA

At DISHA, responsible AI is not a single model property or a compliance checkbox. It is a lifecycle discipline covering how we define a problem, collect and govern data, select models, design prompts and agents, evaluate outputs, deploy systems, monitor behaviour, handle incidents and learn from real-world use.

Human agency

AI supports people; accountable humans retain appropriate authority over consequential actions.

Inspect

Who owns the decision, what AI did, and what human review is required.

Purpose limitation

AI is used for a defined purpose rather than unrestricted profiling.

Inspect

Purpose, permitted use, prohibited use and context.

Evidence & provenance

Outputs should connect to relevant evidence where technically possible.

Inspect

Evidence, source, timestamp, freshness and provenance.

Transparency

People should know when AI is involved and understand capabilities and limitations.

Inspect

AI disclosure, explanation, limitations and interaction notices.

Fairness

Potentially harmful differences are identified and managed according to context.

Inspect

Evaluation population, metrics, thresholds and remediation.

Privacy

Personal data is minimized, protected and used for defined purposes.

Inspect

Data categories, purpose, controls, retention and rights routes.

Security & robustness

Systems are protected against misuse, manipulation, failure and security threats.

Inspect

Security controls, testing and incident pathway.

Accountability

A named owner and governance process exists for material AI systems.

Inspect

Owner, approval state, review date and escalation route.

Contestability

People can question, correct or appeal relevant outputs where applicable.

Inspect

Correction, feedback, appeal or human-review mechanism.

Continuous improvement

Systems are evaluated after deployment and controls updated when evidence changes.

Inspect

Monitoring, evaluation cadence, change history and incident learnings.

The DISHA Responsible AI lifecycle

01 · DEFINE

Identify purpose, affected people, decision context, intended users, foreseeable misuse and risk category.

02 · DATA

Identify sources, provenance, quality, permissions, minimization, retention, representativeness and limitations.

03 · DESIGN

Define human role, user disclosure, explanation requirements, escalation, accessibility and prohibited uses.

04 · DEVELOP

Implement model, retrieval, prompts, agent tools, guardrails, access controls and logging.

05 · EVALUATE

Test validity, reliability, safety, security, privacy, fairness, robustness, hallucination/error behaviour and usability.

06 · APPROVE

Complete documented risk review and obtain required technical, product, security, privacy/legal and accountable-owner approvals.

07 · DEPLOY

Release only the approved version into the approved context.

08 · MONITOR

Track performance, drift, incidents, feedback, override patterns and relevant subgroup behaviour.

09 · RESPOND

Triage incidents, restrict/rollback/disable systems where necessary and communicate material issues.

10 · LEARN

Feed validated evidence into product, model, data and governance improvements.

Human oversight — the core design principle

Human oversight is not a button labelled “human in the loop”. It is a defined responsibility. For each consequential AI-supported workflow, DISHA should specify who can review an output, what information they receive, what authority they have to override it, when escalation is required, and how the action is recorded.

Use caseAI may assist withHuman responsibility
Career explorationGenerate and explain possible pathwaysHuman: User decides whether a pathway is relevant.
Learning recommendationsIdentify learning options against a goal/gapHuman: Learner or authorised advisor decides.
Talent discoverySurface candidates against defined requirementsHuman: Authorised hiring personnel make decisions under applicable policy.
Skills intelligenceMap evidence to skills and identify possible gapsHuman: Human validates material evidence and context.
Workforce planningModel scenarios and capability gapsHuman: Authorised leaders decide strategy, budget and workforce actions.
Decision intelligenceFrame options, evidence and scenariosHuman: Accountable decision-maker owns the decision.

[PLACEHOLDER — INSERT EXACT HUMAN-OVERSIGHT RULES BY PRODUCT/MODULE AFTER PRODUCT GOVERNANCE REVIEW]

AI system inventory

A public inventory of the material AI capabilities actually operating in DISHA 4.0 HCOS today. It exposes approved public fields only; the canonical internal registry and evaluation records are internal.

NaviBuddy™ explanation assistant

R1 — Assistive

Explains on-screen elements in plain language using an approved, versioned knowledge registry; refuses honestly when no approved record exists. Grounded explanations only — no free generation.

Human roleFully user-controlled; explains, never acts on the page.

Status & known limitationsImplemented. Limitation: explains only what has an approved knowledge record; evaluation summary not yet published.

AI Command Center governed agent

R1 — Assistive

Answers human-capital questions with governed tool access (readiness, semantic retrieval) and source-linked citations; read-only tools with caller-scoped permissions.

Human roleUser reviews every answer; tools are read-only; human owns all decisions.

Status & known limitationsImplemented. Limitation: answers depend on governed data currency; unsupported questions are refused rather than guessed.

Semantic retrieval & reranking

R0 — Informational

Orders knowledge and resources against a query using lexical plus LLM-assisted reranking over approved content.

Human roleUser chooses what to open; results are views over approved content.

Status & known limitationsImplemented. Limitation: retrieval quality depends on corpus freshness; no individual profiling.

New or materially changed AI capabilities are added here only after governance review. No system is listed until its public record is approved.

AI use-case classification

Not every AI use is equally consequential. DISHA maintains an internal risk taxonomy; this is the public summary. Exact classification is defined by DISHA governance and mapped to applicable law and customer context — a governance control alone is never claimed as legal compliance.

R0 — Informational

Low-impact explanation, navigation or drafting

Posture: Transparency, quality, privacy/security controls.

R1 — Assistive

Recommendations/analysis where user retains direct control

Posture: Disclosure, explanation, evidence, feedback and monitoring.

R2 — Consequential support

AI materially informs employment, education, access or significant decisions

Posture: Enhanced validation, human authority, documented evaluation, auditability and appeal/correction controls.

R3 — Restricted / Prohibited

Uses creating unacceptable or legally prohibited risk

Posture: Do not deploy; maintain prohibited-use register.

Fairness & bias management

AI can reproduce or amplify patterns in data, design choices or human processes. DISHA therefore treats fairness as an evaluation and governance problem, not as a claim that a model is permanently “bias-free.”

Approach

  • Identify the population affected and the decision context.
  • Document protected or sensitive attributes only where lawful and necessary for evaluation.
  • Test meaningful differences in errors, access, recommendations or outcomes where the use case warrants it.
  • Evaluate data coverage and known limitations.
  • Test both model-level and end-to-end workflow behaviour.
  • Where a material issue is identified, define remediation, owner, deadline and re-evaluation.

Boundaries

  • Do not infer protected attributes merely because they might be useful for prediction.
  • Do not collect sensitive data for fairness testing without documented purpose and lawful basis.

[PLACEHOLDER — APPROVED PUBLIC FAIRNESS METRICS, POPULATIONS, PERIOD, THRESHOLDS AND REMEDIATION STATUS]

Explainability & “Why?”

Explanation should describe the actual mechanism or evidence used. DISHA does not provide a plausible post-hoc story that the model did not actually use — and never exposes hidden chain-of-thought or proprietary internal reasoning.

The “Why?” standard — nine things an explanation may show

  1. 01Show the user's stated goal/context.
  2. 02Show the relevant input evidence categories.
  3. 03Show factors/evidence used, to the extent technically meaningful and safe.
  4. 04Show what the system did not know.
  5. 05Show confidence/uncertainty only where a validated measure exists.
  6. 06Show relevant limitations.
  7. 07Show alternative interpretations or options where applicable.
  8. 08Show what a human can correct or challenge.
  9. 09Show the date/version of the underlying system where appropriate.

This pattern is live in the product

NaviBuddy's explanation cards already follow this anatomy: a plain-language summary, why it matters, where it fits, explicit caveats, and a provenance line naming the knowledge version — with an honest refusal card when no approved record exists.

NaviBuddy™ · plain-language explanation

What does this mean? → summary

Why it matters → whyItMatters

Where it fits → whereItFits

caveat → explicit caveat when one applies

Grounded in approved DISHA knowledge · vX · explains — never acts

Inspect an AI output

A sandboxed demonstration that exposes evidence → output → review. It does not pretend to reveal hidden chain-of-thought or proprietary internal reasoning.

ILLUSTRATIVE — NOT A REAL PERSON / NOT A REAL DECISION

Choose a scenario

Goal: become a data analyst in 12 months.
Evidence available to the AI: completed coursework (statistics, spreadsheets); one flagged gap (SQL); stated weekly study time; no employer data.
Suggested next module: applied SQL for analysts — because the flagged gap sits directly on the stated goal path.

Why: the recommendation maps the measured gap (SQL) to the stated goal; module difficulty matches evidenced coursework. The system did not use employment data — none was provided.

Data governance & privacy

ControlPublic explanation
Purpose limitationData is used for defined purposes rather than unlimited secondary profiling.
Data minimizationCollect/use only what is necessary for the stated purpose.
ProvenanceMaintain source and lineage information for material inputs where feasible.
QualityTrack freshness, completeness and known quality limitations.
Access controlLimit who and what systems can access AI inputs/outputs.
RetentionApply defined retention/deletion rules.
Deletion/correctionProvide applicable routes for correction, deletion or rights requests.
Model training useClearly state whether user/customer data may be used for training, improvement or evaluation.
Third-party processingIdentify material external model/service categories and relevant controls.

[PLACEHOLDER — EXACT DISHA POLICY ON WHETHER CUSTOMER / USER DATA IS USED FOR FOUNDATION-MODEL TRAINING OR INTERNAL MODEL IMPROVEMENT]

Generative AI & agentic AI

DISHA's Responsible AI programme addresses LLMs, retrieval systems, tool-using agents and automated workflows — not only predictive models.

Prompt governance

Approved system instructions, access boundaries and change control.

Retrieval governance

Authoritative knowledge sources, freshness and provenance.

Tool governance

Tools restricted by role, purpose and least privilege.

Action governance

Read-only assistance distinguished from actions that change records or affect people.

Human confirmation

Confirmation required for defined high-impact actions.

Prompt injection resistance

Retrieval and agents tested against malicious or conflicting instructions.

Output controls

Hallucination, unsafe content, privacy leakage and unsupported claims monitored.

Content provenance

AI-generated/assisted content labelled where required.

Conversation privacy

Storage, retention, access and deletion rules defined.

Model/vendor changes

Material changes re-evaluated.

In the current build, agent tools are read-only and caller-scoped, and answers carry source-linked citations; the remaining controls are in progressive implementation and are not claimed as complete.

Model & agent evaluation framework

ValidityDoes the system address the intended task?
ReliabilityDoes behaviour remain stable under relevant conditions?
Accuracy / qualityHow well does it perform against an appropriate reference?
GroundingDoes generated content remain supported by available evidence?
FairnessAre material disparities detected and managed?
PrivacyCan the system expose or infer information beyond the permitted purpose?
SecurityCan the system be manipulated, exfiltrated or misused?
RobustnessHow does it behave under noisy/adversarial inputs?
Human factorsCan users understand, challenge and appropriately use outputs?
AccessibilityCan people use and understand the AI interaction?
DriftDoes behaviour change as data, users, models or context change?
Agent safetyCan an agent take unintended actions or cross boundaries?

Evaluation records include system version, evaluation date, test population/data, methodology, metrics, thresholds, known limitations, reviewer, result, remediation and re-test date.

[PLACEHOLDER — PUBLIC AI EVALUATION / MODEL CARD LIBRARY]

AI incidents, errors & safety events

AI systems can fail. Responsible deployment requires a way to recognise failures, contain them, learn from them and provide affected people with an appropriate route for correction or escalation.

Material incorrect outputPrivacy incidentSecurity eventHarmful recommendationUnfair outcomeUnauthorized actionModel/agent failureData-quality issueContent-provenance issueOther governance concern
REPORT→TRIAGE→CONTAIN→INVESTIGATE→REMEDIATE→VERIFY→COMMUNICATE→LEARN

S1 — Minor

Log, assess, correct and monitor.

S2 — Material

Assign owner, investigate, remediate and document.

S3 — High impact

Immediate containment, accountable governance review and formal remediation.

S4 — Critical

Disable/rollback where necessary, executive/legal/security escalation and notification where required.

[PLACEHOLDER — PUBLIC AI INCIDENT DISCLOSURE POLICY, REPORTING CHANNEL AND TARGET RESPONSE TIMES]

Report an AI concern

Something about an AI output or decision concerns you? Tell us.

Please do not upload or send passwords, authentication secrets or unrelated personal information.

Routing: Product team → responsible AI owner → privacy/security/legal where relevant → accountable business owner → resolution/correction → user communication.

User rights, correction & contestability

You should be able to distinguish an AI-generated suggestion from a decision made by a person. Where applicable, you should also have a way to correct inaccurate information and ask for human review.

  • Explain which outputs are advisory and which can feed into consequential workflows.
  • Provide correction of factual source data separately from disagreement with an AI interpretation.
  • Provide appeal/review where the use case and law/policy require it.
  • Record corrections and propagate them to downstream intelligence where technically appropriate.
  • Do not promise that every AI output can be reversed after an external action.

Prohibited & restricted AI uses

DISHA maintains an internal prohibited-use register; this is the public summary.

AI decisions based on protected or sensitive characteristics where prohibited by law or DISHA policy.

Covert surveillance or monitoring without a legitimate, disclosed and governed purpose.

Emotion or psychological inference from weak signals for consequential decisions unless specifically approved, lawful and scientifically defensible.

Automated employment, education or access decisions without required human authority and safeguards.

Fabrication of credentials, experience, evidence or qualifications.

Deceptive impersonation where disclosure is required.

Unapproved autonomous actions materially affecting rights, access, employment, education, finances or reputation.

Incompatible secondary use of personal data without appropriate lawful basis and governance.

Unsupported predictions presented as facts.

Third-party AI & model providers

Vendor due diligenceSecurity, privacy, legal, reliability and AI-risk review before material use.
Data processingDocument what data is sent, why, where and under what terms.
RetentionUnderstand provider retention and training policies.
Model changesTrack material provider/model version changes.
SubprocessorsMaintain relevant vendor/subprocessor records.
Exit strategyDefine migration/rollback approach for critical functions where practical.
PerformanceEvaluate vendor outputs in DISHA context, not only vendor benchmarks.

[PLACEHOLDER — CURRENT THIRD-PARTY AI PROVIDER / MODEL REGISTER APPROVED FOR PUBLIC DISCLOSURE]

AI governance roles

Board / executive governanceOversight of material AI risk appetite and strategic accountability, where applicable.
Responsible AI ownerPolicy, governance process, risk taxonomy and reporting.
Product ownerIntended purpose, UX, controls and product-level risk.
Model/AI engineeringBuilds, evaluates, documents and monitors technical systems.
Data governanceProvenance, quality, access, retention and permitted use.
Privacy / legalLawful basis, rights, contracts and regulatory requirements.
SecuritySecurity architecture, threat modelling, testing and incidents.
Human reviewer / decision ownerAccountable judgment where human oversight is required.
Audit / assuranceIndependent review where such a function exists.
Users / customersFeedback, error reporting and use within stated limitations.

[PLACEHOLDER — INSERT ACTUAL DISHA GOVERNANCE STRUCTURE, COMMITTEE NAMES, ACCOUNTABLE EXECUTIVES AND REVIEW CADENCE]

Transparency Centre — public artifacts

A library of approved governance artifacts. Every artifact carries version, publication date, owner, approval status and supersession relationship. Artifacts appear here only once approved.

Responsible AI Policy

[PLACEHOLDER — pending approval]

AI Governance Framework

[PLACEHOLDER — pending approval]

AI System Register

Public subset — this page's inventory

Model / System Cards

[PLACEHOLDER — approved cards pending]

Risk Assessment Summaries

[PLACEHOLDER — public versions where appropriate]

Evaluation Reports

[PLACEHOLDER — approved summaries pending]

Fairness / Bias Assessments

[PLACEHOLDER — where meaningful and lawful]

AI Incident Reports

None disclosed to date (no material incidents published)

AI Provider Register

[PLACEHOLDER — if approved]

AI Change Log

Maintained with platform release notes

User Guidance

NaviBuddy guidance + glossary available

Contact / Reporting Channel

Live — Report an AI concern on this page

Responsible AI dashboard

A public governance dashboard — populated ONLY from sourced, maintainable indicators: each card states its definition and source. Indicators that cannot be defined, sourced and maintained honestly (review coverage, remediation times) stay hidden until they can be.

AI systems in the public inventory

3

Source: this page's inventory — grows only after governance review

Governed person records

8

Source: Registry, aggregate count only

Capability claims under governance

7

Source: Data Fabric claims, with provenance

Live governed opportunities

3

Source: D04 governed opportunity lifecycle

Governed organizations

4

Source: Registry, aggregate count only

Public evaluation summaries published

0

None approved yet — the model-card library is a placeholder above

Material AI incidents disclosed

0

None to date; disclosure policy is a governance placeholder

Certification claims displayed

0

Evidence-first rule: no badge without a valid certificate

Deliberately absent: review-coverage and remediation-time percentages — no defensible denominator or period exists for public display yet. Estimation is never used to fill a card.

Regulatory & standards alignment

Frameworks we monitor and design against. Alignment is not certification, and certification is never claimed without formal evidence.

NIST AI RMF

A voluntary framework for organizations designing, developing, deploying or using AI systems to manage AI risks and promote trustworthy/responsible AI — covering validity/reliability, safety, security/resilience, accountability/transparency, explainability, privacy enhancement and fairness with harmful bias managed.

NIST Generative AI Profile

Cross-sector guidance for generative AI risk management; the AI RMF is being revised, so DISHA maintains a versioned standards register.

OECD AI Principles (updated 2024)

Inclusive growth and well-being; human rights and fairness; transparency and explainability; robustness, security and safety; accountability.

ISO/IEC 42001:2023

Requirements for establishing, implementing, maintaining and continually improving an AI management system. DISHA does not describe itself as ISO/IEC 42001 certified — no valid certification exists.

EU AI Act (Regulation (EU) 2024/1689)

A risk-based legal framework with staged application. DISHA maintains jurisdiction-specific legal assessments rather than a blanket “EU AI Act compliant” claim.

DomainNIST AI RMFOECDISO/IEC 42001EU AI Act / other law
Risk managementMap/Govern/Measure/ManageRisk stewardshipAIMS risk/opportunityRisk-based obligations
Human oversightTrustworthiness/governanceHuman agencyOrganizational controlsApplicable requirements
TransparencyAccountability/transparencyTransparency/explainabilityAIMS controlsTransparency obligations
FairnessBias managementFairness/non-discriminationRisk/control processesApplicable requirements
SecuritySecure/resilientRobustness/security/safetyAIMS + ISMS linkageCybersecurity requirements
PrivacyPrivacy-enhancedPrivacy/data protectionAIMS governanceData protection laws
LifecyclePre-design to deployment/evaluationLifecycle stewardshipContinual improvementProvider/deployer obligations

This crosswalk is a governance aid, not legal advice or certification evidence.

[PLACEHOLDER — INDIA-SPECIFIC RESPONSIBLE AI / DPDP / SECTORAL LEGAL CROSSWALK APPROVED BY COUNSEL]

Responsible AI — questions, answered plainly

It means designing, deploying and governing AI with attention to human agency, evidence, transparency, fairness, privacy, security, accountability, safety and continuous evaluation.

AI should be useful. It should also be understandable, governable and accountable.

Explore how DISHA applies responsible AI across human-capital intelligence — or ask us about the governance controls relevant to your deployment.

Prefer evidence over adjectives, limitations over overconfidence, and explicit accountability over vague assurances. The strongest version of this page is the one that clearly tells users what DISHA does, what it does not do, what evidence supports the claims, what remains under development, who is accountable, and how a person can challenge or report a problem.

Responsible AI · Privacy · Data Protection · Security · Terms · Compliance · Accessibility · Report an Issue · System Status · AI & Human Capital Glossary