News
Data Privacy and AI Governance Enter Automotive Vendor Cybersecurity Assessments
Privacy, cloud data and AI governance now appear as mandatory sections in automotive vendor assessments, bringing DPDP duties into a commercial process.
Neha Dvivedi · September 13, 2026
Indian auto component manufacturers are now facing broader cybersecurity checks from vehicle manufacturers and other customers. These assessments no longer stop at traditional information security controls. They increasingly include data privacy, cloud data protection and artificial intelligence governance.
This shift makes DPDP Act compliance part of manufacturing companies’ commercial cybersecurity process. Customers increasingly ask suppliers to show how they protect personal data, manage cloud services, and control the use of Artificial Intelligence (AI).
New Areas Added to Cybersecurity Assessments
Traditional supplier assessments usually focus on areas such as access control, system logs, configuration management and physical security. However, newer assessments are adding separate sections for data privacy, cloud data privacy and AI security.
Data Privacy
Customers are asking suppliers to identify the personal data they collect and process. They also want suppliers to maintain an inventory of this data and apply suitable security measures.
Suppliers may also need to determine whether they act as a Data Fiduciary or Data Processor under India's data protection framework. These requirements connect with ISO/IEC 27701 and the Digital Personal Data Protection (DPDP) Act, 2023.
This means manufacturers need to understand not only where their data is stored but also why they collect it and who can access it.
Data Privacy in Cloud Services
Cloud services have also become an important part of supplier assessments. Customers may ask whether suppliers store or process personal data through cloud platforms.
They may also ask whether the organisation has formally reviewed and approved the cloud services it uses.
ISO/IEC 27017 provides guidance for information security controls in cloud environments. ISO/IEC 27018 focuses on protecting personally identifiable information in public cloud services.
Artificial Intelligence (AI) Security
Artificial Intelligence (AI) has become another focus of supplier assessment. Customers may ask whether a manufacturer uses AI in its operations or decision-making processes.
They may also ask whether any AI system works without human oversight and whether the organisation has assessed the risks linked to its use.
ISO/IEC 42001 provides a management system framework for organisations that develop or use artificial intelligence systems.
Artificial Intelligence governance is significant because many organisations are still developing formal rules for how employees and business systems should use AI.
Indian Data Protection Laws Bring New Compliance Requirements
The cybersecurity assessment from a customer is generally a contractual requirement. Data protection obligations are different because they can apply directly to the organisation under Indian law.
The Digital Personal Data Protection (DPDP) Act, 2023 establishes requirements for organisations that process digital personal data. This can include employee and customer information handled by manufacturing companies.
The CERT-In Directions issued in April 2022 also introduced requirements related to cybersecurity incident reporting and the retention of certain logs.
Section 43A of the Information Technology Act, 2000 and the related rules on reasonable security practices also remain relevant to organisations handling sensitive personal data or information.
This creates an important practical connection between customer assessments and legal compliance. When a supplier prepares its privacy controls for a customer assessment, much of the same work can also support its wider compliance responsibilities.
Why Automotive Suppliers Face New Cybersecurity Requirements
Cybersecurity requirements are becoming more important across the automotive supply chain. One of the developments in India is AIS-189, which covers Cyber Security Management Systems for vehicles.
AIS-189 is linked to the broader cybersecurity requirements being developed for vehicles and their supply chains. AIS-190 addresses software update management.
These requirements are based on international automotive cybersecurity frameworks, including UNECE R155, UNECE R156 and ISO/SAE 21434.
The Ministry of Road Transport and Highways has also proposed changes involving Rules 125-T and 125-U. However, the relevant rules and implementation timelines are subject to the applicable government notifications and final regulatory position.
Suppliers should therefore verify the latest requirements from the Ministry of Road Transport and Highways before making compliance decisions based on proposed dates.
Cybersecurity Requirements Extend to Tier 2 Suppliers
Automotive cybersecurity does not stop with the vehicle manufacturer. Modern vehicles depend on a large network of component manufacturers, software providers, service providers and other suppliers.
Under the automotive cybersecurity approach, vehicle manufacturers need to understand and manage cybersecurity risks across their supply chain. Hence, this requirement can create a cascading effect for Tier 1 and Tier 2 suppliers.
A supplier may therefore receive cybersecurity requirements even when it does not directly manufacture the final vehicle.
Customer assessments help manufacturers understand whether their suppliers have suitable controls in place. They can also help identify weaknesses before those weaknesses affect a wider automotive supply chain.
Recent Cybersecurity Incidents Increase Supply Chain Concerns
Recent cyber incidents have also highlighted the risks faced by the automotive sector.
In June 2026, reports emerged about an extortion group publishing a large dataset that was reportedly more than 630 GB in size. The data was reported to include component design documentation associated with global manufacturers.
During the same month, a ransomware incident affecting Bajaj Auto's corporate IT infrastructure and an engineering subsidiary was also reported. The incident was reported to CERT-In under India's applicable cybersecurity framework.
These incidents show why manufacturers and suppliers need to protect more than their internal IT systems. Sensitive engineering documents, product information, employee data and supplier information can all become targets.
How Can Auto Suppliers Prepare for Cybersecurity Requirements?
Manufacturers do not always need to begin by purchasing new technology. A good first step is to understand what information and systems the organisation already has.
Suppliers should begin by creating an inventory of the personal data they collect and process. They should identify where this data is stored and who can access it.
They should also review whether personal data is processed through cloud platforms. The organisation should document which cloud services it uses and how those services are approved and monitored.
Manufacturers should also establish a clear position on AI use. If the organisation uses AI tools, it should document where and how they are used.
If the organisation does not use AI systems for decisions without human oversight, it should also document this position. A clear and documented approach can help the organisation respond to customer assessment questions more effectively.
How ISO Standards Support Automotive Cybersecurity Readiness?
A structured management system can help manufacturers bring these requirements together instead of handling every customer questionnaire separately.
ISO/IEC 27701 can help organisations establish a structured approach to privacy information management. It can support organisations in managing personal data and defining privacy-related responsibilities.
ISO/IEC 27001 can help organisations establish and maintain an information security management system. It provides a structured approach to identifying information security risks and implementing appropriate controls.
ISO/IEC 27017 and ISO/IEC 27018 can support organisations in addressing security and privacy considerations related to cloud services.
For organisations that use artificial intelligence, ISO/IEC 42001 provides a framework for establishing an AI management system.
These standards do not replace Indian laws or contractual customer requirements. Instead, they can help organisations create documented and repeatable processes that support their wider compliance efforts.
How Can Suppliers Prepare for Customer Cybersecurity Assessments?
A customer cybersecurity assessment should not be treated as a last-minute questionnaire. Suppliers can prepare in advance by reviewing their information security, privacy, cloud and AI practices.
A readiness assessment can help identify missing policies, unclear responsibilities, weak documentation and gaps between actual practices and customer requirements.
MSCi supports automotive suppliers with ISO consultancy and compliance readiness services. The consultancy helps organisations prepare their systems for assessment and certification requirements.
Organisations can also use the free ISO readiness checklist to identify areas that may require attention before an assessment.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
September 13, 2026
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
September 13, 2026
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
September 13, 2026
