From Indian regulation to clear action.
Regulens monitors 780+ Central and state authorities, scopes every notification against your entities, sites and licences, and decomposes each applicable instrument into testable obligations — propagated through your organisation down to the plant, function, process and person responsible for acting on it.
Three-week scoped pilot on your own footprint. No self-serve trial — the product is only meaningful once it is configured against your entities and sites.
- Obligations mapped
- 69,000+Obligations mapped
Decomposed from Central Acts, Rules, state legislation and municipal bye-laws.
- States & UTs tracked
- 28States & UTs tracked
Every state variant maintained separately, because they genuinely differ.
- Authorities monitored
- 780+Authorities monitored
Central ministries, regulators, state departments and local bodies.
- Clauses with jail risk
- 26,000+Clauses with jail risk
Obligations carrying imprisonment exposure for directors and officers.
Regulatory radar
Published by our research desk
- Notificationtoday
MeitY opens consent manager registration and clarifies the DPDP phase-in
MeitY · India — Central
- Notificationyesterday
Nine more states notify rules under the Labour Codes — and they do not match
State Labour Departments · All States
- Notification2 days ago
DPIIT notifies Quality Control Orders covering 34 further industrial chemicals
DPIIT / Bureau of Indian Standards · India — Central
- Circular / Guidance5 days ago
SEBI confirms BRSR Core value chain disclosure timeline for top 1000 entities
SEBI · India — Central
- Notification6 days ago
CPCB revises environmental compensation rates for EPR plastic shortfall
CPCB · India — Central
Trusted by compliance functions in manufacturing, pharma, IT, BFSI and retail
The problem
Regulatory programmes rarely fail by missing a rule
They fail in the gap between knowing a rule exists and knowing what it means for you. That gap has four parts, and a publication feed addresses only the first.
Detection
Something was notified. This is the least demanding stage — gazettes and state portals publish openly, and the raw feed costs nothing to obtain.
8% of the effort
Applicability
Does it apply to this site, this state, this licence, this category? Not to the sector in general — to this specific plant.
19% of the effort
Decomposition
Converting an Act, its Rules and the relevant state amendment into individual obligations that can be owned, controlled and tested. Skilled, unglamorous work.
30% of the effort
Impact
Determining which site, function, process and owner must act — including the second and third-order impacts that manual review typically misses.
43% of the effort
Figures from our 2026 benchmark of 268 Indian compliance functions. For a six-state mid-size group, these four stages together consume roughly 324 hours a month — approximately two full-time equivalents, before any remediation work begins.
The platform
One connected model, built up in stages
Each stage builds on the register and the organisational graph the stage before it created. There is no starting again to move from knowing to acting to proving.
Know and assess
Find every Central, state and municipal obligation that applies to each of your sites, break it into atomic obligations, and understand precisely which division, plant and person is affected.
- Continuous monitoring of 780+ Central and state authorities
- Applicability scoping against your entities, sites, states and licences
- Obligation decomposition with section-level traceability
- Impact analysis down to site, function, process and system
- Automated insight digests and board-ready reporting
Translate into action
Turn an obligation into the artefacts a compliance or change programme actually needs: updated SOPs and policies, and complete business requirements documents.
- Policy impact mapping — which SOP clauses a notification breaks
- AI-assisted drafting and redlining with section-level citations
- Full policy lifecycle: draft, review, approve, attest, version
- End-to-end BRD generation from obligation to acceptance criteria
- Two-way sync with Jira, Azure DevOps and ServiceNow
Prove compliance continuously
Connect to ERP, HRMS and plant systems so the platform can test whether you actually comply — continuously, and against any new rule you point at it.
- Read-only connectors into ERP, payroll, plant and transaction systems
- Rules compiled into executable tests over real records
- Continuous control monitoring with exception workflow
- "Am I compliant with this new rule?" answered against live data
- Immutable evidence trail for inspectors and internal audit
Modules
Eight modules that share one obligation register
Adopt the modules you need. Each one reads from and writes to the same graph, so value compounds as coverage grows.
Regulatory Intelligence
Generally available
Every rule that touches you, the day it lands
Read moreObligations Library
Generally available
Regulations broken into things you can actually test
Read moreImpact Analysis
Generally available
From a rule change to a ranked list of who must act
Read moreInsights & Reporting
Generally available
The board pack that writes itself
Read morePolicy Automation
Early access
SOPs and policies that stay tied to the rules underneath them
Read moreBRD Automation
Early access
From regulatory notification to business requirements document, automatically
Read moreCompliance Audit
Design partner
Test the rule against the actual records
Read moreRegulens Copilot
Generally available
One prompt across every Act, Rule, state variant, policy and record
Read moreWhy Regulens
Six things we do differently, stated plainly
Primary sources, not a summary of a newsletter
We read the gazette, not a summary of a summary. Every obligation carries a citation anchor to the section it came from, and that anchor survives amendment.
Scoped to your sites, not your sector
Generic sector feeds tell a Bengaluru IT firm about Maharashtra factory rules it will never meet. Regulens scopes against your entities, sites, states and licences and shows its reasoning.
The state layer is not an afterthought
All 28 states and 8 union territories are maintained as separate variants — thresholds, forms, return dates — because a Central rule and a state rule are frequently not the same obligation.
Obligations as the unit of work
Decomposition into atomic, testable obligations is what makes control mapping, policy linkage and automated testing possible. It is the hardest part and it is the foundation.
AI that refuses rather than invents
In this domain a confident wrong answer is a liability — particularly one built on reasoning imported from a legal system that does not apply here. Every claim is cited and verified against its source.
Built for the inspector at the gate
Immutable audit trails, evidence packs assembled by obligation, and a defensible record of who knew what and when — because that is what the conversation is eventually about, and because personal liability makes it personal.
Category
Not a feed. Not a GRC platform.
Both have their place. Neither answers the question that occupies most of your team’s week.
| Dimension | Horizon scanning feed | GRC platform | Regulens |
|---|---|---|---|
| Primary question answered | What was notified? | Are our controls working? | Which of our sites does this land on, what does it require, and who acts? |
| Content source | Summaries of Central notifications | Content you load yourself | Central, state and municipal primary sources, decomposed into obligations |
| State coverage | Rarely, and rarely maintained | Not applicable | All 28 states and UTs maintained as separate variants |
| Scoping | Sector level | Not applicable | Site, state, headcount, category and licence — with reasoning shown |
| Licence conditions | Not covered | Stored as documents | Extracted from each consent and licence, tracked as obligations |
| Personal liability | Not covered | Not modelled | Named role register with imprisonment exposure mapped per obligation |
Most customers retain their existing GRC platform and integrate with it. Regulens provides the intelligence, obligation and impact layer that sits above it.
Outcomes
What compliance teams use the platform for
Regulatory change management
Run the full lifecycle from gazette notification to implemented control as one instrumented pipeline — detection, scoping, assessment, action, evidence — with SLAs and ownership at every stage.
- Central, state and municipal sources monitored together
- Automated impact propagation across entities, plants and functions
- Handoff to delivery tooling with traceability preserved
- Complete, immutable audit trail of every decision
Multi-state and multi-site compliance
The defining Indian problem: one Central rule, thirty-six state variants, and municipal rules underneath. Each site gets exactly the obligations that apply to it, with the state delta made explicit.
- All 28 states and 8 union territories maintained separately
- Municipal bye-laws and trade licence obligations included
- Per-site scoping by state, category, capacity and process
- State delta shown against the Central position
Licence and consent management
Build the complete licence inventory most organisations discover they have never had, extract the conditions written into each one, and manage renewals against real application lead times.
- Every licence, consent and registration per site
- Conditions extracted and tracked as obligations
- Renewal alerting based on lead time, not expiry date
- Named holder and personal exposure recorded
Director and officer liability
A large share of Indian compliance obligations carry imprisonment exposure for named individuals. Make that exposure visible to the people who carry it, and evidence the systems that mitigate it.
- 26,000+ clauses with imprisonment exposure identified
- Named occupier, officer-in-default and KMP mapping
- Evidence supporting the Section 134(5) assertion
- Time-stamped record of detection, assignment and closure
Compliance domains
One set of domains applies regardless of what you make
Corporate, labour, EHS, data, tax and product standards obligations attach to being an employer, an occupier and a company — not to your sector code.
Corporate & Secretarial
The obligations that attach to the entity, whatever it makes
1,400+ obligations
Labour & Employment
Four Codes, thirty-six sets of state rules, one payroll
11,200+ obligations across states
EHS & Environment
Consents, waste, emissions and the compensation formula
4,600+ obligations
Data, Privacy & Cyber
DPDP, CERT-In and a sectoral layer on top
2,100+ obligations
Tax, GST & Customs
One company, many GSTINs, and a re-sectioned Income-tax Act
3,300+ obligations
Product Standards & Quality
QCOs, labelling and the six-month window before your product is illegal
2,800+ obligations
Sectoral Licensing
The licence conditions nobody reads after the licence is granted
5,400+ obligations
Competition & Consumer
Dark patterns, deal value thresholds and endorser liability
900+ obligations
Industries
Coverage tuned to the regimes you actually operate under
Sectoral licensing and product rules stack on top of the horizontal domains. Depth and taxonomy differ by sector, and so does what we can honestly claim.
Manufacturing & Engineering
Every plant is its own compliance jurisdiction
9,400+ manufacturing obligations across states
Pharma & Life Sciences
Schedule M, CDSCO and every export market at once
3,900+ pharma and device obligations
IT, ITeS & Global Capability Centres
DPDP, CERT-In and state labour law for a distributed workforce
2,600+ obligations for a multi-centre IT firm
Banking & Financial Services
RBI, SEBI, IRDAI and everything that applies to any company
4,800+ BFSI obligations including cross-cutting law
Energy, Power & Utilities
Central regulator, state commission, and a carbon market arriving
3,100+ energy sector obligations
Automotive & Mobility
Homologation, CAFE, scrappage and a deep supplier chain
3,400+ automotive obligations
Chemicals & Petrochemicals
MSIHC, PESO and the highest personal liability exposure in Indian industry
4,200+ chemical sector obligations
FMCG, Retail & E-commerce
Labelling, EPR and dark patterns, per state and per SKU
3,700+ consumer sector obligations
Healthcare & Hospitals
Clinical registration, biomedical waste, AERB and patient data
2,900+ healthcare obligations
Infrastructure & Real Estate
RERA per state, EC conditions per project, labour per site
3,300+ infrastructure and real estate obligations
Logistics & Transport
E-way bills, state permits and warehouses in twenty states
2,400+ logistics obligations
Telecom, Media & Entertainment
Authorisation conditions, content rules and a six-hour cyber clock
2,200+ telecom and media obligations
Regulatory news desk
Published daily by our research team
Primary-source analysis of what changed and what it means operationally — not a summary of a press release.
MeitY opens consent manager registration and clarifies the DPDP phase-in
Registration for consent managers opens with a ₹12 crore net worth requirement, and MeitY confirms that notice, consent and breach obligations become enforceable from 13 May 2027.
Nine more states notify rules under the Labour Codes — and they do not match
Karnataka, Gujarat and Tamil Nadu publish diverging registers, thresholds and return formats, confirming that Central consolidation has not produced ground-level uniformity.
DPIIT notifies Quality Control Orders covering 34 further industrial chemicals
Mandatory BIS certification extends to a new chemical tranche with a nine-month transition, catching importers whose overseas suppliers are not yet licensed.
SEBI confirms BRSR Core value chain disclosure timeline for top 1000 entities
Assured value chain sustainability disclosure applies from FY 2027-28, covering upstream and downstream partners accounting for 75% of purchases and sales.
In their words
What changed for our customers
“The first honest answer to "what applies to this plant" took us three weeks to produce manually. It now takes a click, and it is more complete than the answer we produced.”
“Our named occupier had never been shown the specific obligations he could be prosecuted for. Showing him changed how the site ran within a month.”
“We stopped arguing about whether we had seen a notification and started arguing about which of our sites it landed on. That is a much better argument to be having.”
“The copilot saying "the rules for that state have not been notified yet" is the feature that made our legal team trust the rest of it.”
From the blog
Practitioner writing, not thought leadership
One rule, thirty-six variants: why Indian compliance does not scale
The Labour Codes were meant to simplify. GST was meant to unify. Both did, at Central level, and neither changed what happens at your third plant in a different state. Here is why, and what to do about it.
Ananya Bhat · 15 Aug 2026
Compliance operationsDecomposing an Indian statute into obligations you can actually assign
How to turn an Act, its Rules, the state amendment and three circulars into atomic obligations with an owner and a deadline — including the judgement calls that decide whether the register survives.
Rohit Menon · 8 Aug 2026
See it scoped to your own sites, not a demo tenant
We configure your entities, sites and states, then run live intelligence for three weeks so you can compare the output against what your team found in the same period. If the platform does not outperform your current process, we will tell you.