Article details
- Category
- Regulation Update
- Published
- Reading time
- 6 min read
- Author
- AutoSec Academy · Compliance Practice
AIS 190 addresses software update management for the Indian market, mirroring the intent of UNECE R156: an update must not compromise safety, must not silently invalidate a type approval, and must be traceable to the vehicles that received it.
Configuration traceability is the hard part
The security controls around an update — signing, integrity verification, rollback protection — are usually in reasonable shape. What fails assessment is the record-keeping: identifying, for any given vehicle, exactly which software versions are installed and which approved configuration they correspond to.
- A software identification scheme that survives supplier part changes
- Records linking vehicle identity to installed versions
- An assessment of whether a given update affects type-approval relevant parameters
- A defined and tested rollback path
As with AIS 189, confirm applicability and timelines through the Indian regulatory process; the requirements are revised as the framework matures.