Article details
- Category
- Regulation Update
- Published
- Reading time
- 6 min read
- Author
- AutoSec Academy · Compliance Practice
AIS 189 sets out cybersecurity requirements for vehicles in the Indian market, following the management-system structure that UNECE R155 established internationally. For manufacturers already building toward R155, the conceptual work transfers; the process and submission obligations are what require local attention.
What transfers from an existing CSMS
- Risk identification, assessment and treatment processes
- Supplier assurance and interface responsibilities
- Monitoring, incident response and field capability
- The underlying engineering evidence produced to ISO/SAE 21434
Practical preparation
Map your existing CSMS artefacts against the AIS clause structure before engaging a testing agency. Most global manufacturers find they hold the substance and lack the presentation — evidence organised for one authority rarely reads cleanly to another.
Applicability, vehicle categories and timelines are set through the Indian regulatory process and revised periodically. Confirm the current position with ARAI and the CMVR technical standing committee rather than relying on a secondary summary.