Empanelment & Routes
GIGW and STQC Together: The Audit Path
· 11 minute read
If citizens meet your agent through a government website or app, GIGW still applies. STQC's quality-certification path is how many departments prove it. The model behind the site does not get a waiver.
A Bhubaneswar municipal team added a 'smart assistant' to the citizen grievance portal the week before a minister's visit. The assistant sat in a DIV on the same hostname. The portal had an older GIGW-oriented certificate story. Nobody asked whether a new conversational surface changed accessibility, language, security, or content governance. A later STQC-oriented review treated the assistant as part of the website. Of course it was part of the website. Citizens could see it.
GIGW — Guidelines for Indian Government Websites, now in a 3.0 generation hosted at guidelines.india.gov.in — is the NIC-associated standard for government websites, portals, web applications and, in the current framing, apps. STQC, the Standardisation Testing and Quality Certification Directorate under MeitY, runs the website quality certification path (CQW) against those guidelines. CERT-In's cyber advice is woven into the current GIGW story. These are public facts. They are not a startup's invention.
An agentic backend that never faces citizens — an officer-only tool on an intranet — may sit outside a public-site GIGW certificate. The moment you put a chat widget, a voice bot, or an 'apply with AI' flow on the public host, you are back in GIGW land. Do not let a vendor say 'AI is exempt'.
This is a path guide, not an audit. STQC's live process pages win. Book them early. Not legal advice.
Who does what
NIC (with partners named in the GIGW 3.0 story, including STQC and CERT-In) publishes the guidelines. Departments implement. STQC and its processes provide the quality certification many organisations are expected to obtain — the CQW path described on stqc.gov.in. Cyber aspects in the current generation also point at CERT-In empanelled assessment and 'safe to host' style evidence. Read the current GIGW introduction for the exact split; it has been refined on purpose.
Vendors implement the site and the agent. They do not issue GIGW certificates. A vendor slide that says 'GIGW compliant' without a departmental certificate and a scope is a self-score.
The certificate has a scope and a validity. A 2022 certificate on a portal that has since grown a bot is a certificate of a different animal. Recertification and change management are the plot.
| Surface | Typical GIGW relevance | What to do before go-live |
|---|---|---|
| Public .gov.in portal with a chat widget | In scope of the site | Treat as a website change; accessibility, content, security, language |
| Mobile app on stores with an assistant | Current GIGW generation speaks to apps | Do not assume a website certificate covers the app |
| Officer-only intranet agent, no public UI | May be out of public-site certificate; still has security and DPDP duties | Do not hide a public kiosk 'for awareness' |
| Embedded agent on a PSU marketing site | If it is a government organisation site, assume GIGW applies | Ask legal whether the site is in the government-website class |
| PDF circulars the agent cites | Content governance is a GIGW theme | Cite current circulars; expired schemes are a content failure, not only an AI failure |
The audit path, in field order
Read GIGW 3.0 at guidelines.india.gov.in. Identify the chapters that hit you: accessibility, identity and branding, content, design, security, quality, lifecycle. The AI widget will touch accessibility (keyboard, screen readers, language), content (who approves answers), and security (injection, data leaks, third-party scripts).
Gap-assess the existing site plus the widget. Fix the site's old sins first. Auditors will not ignore a contrast failure because your bot is clever.
Lock the agent's public behaviour: a corpus of approved FAQs, a refusal policy, a human handoff, a language policy, no invention of schemes. This is content governance. GIGW has always cared about it. Agents make the failure faster.
Security: if the widget calls an API, that API is part of the site's attack surface. CSP, authentication, rate limits, no third-party model script dropped into the page from a random CDN if the security chapter would hate it. Prefer a same-origin, department-hosted front end talking to an on-prem runtime.
Book STQC's website quality certification process as it stands on the day you book. They will tell you the current evidence list, fees, and whether a surveillance or recert is needed. Do not use a 2019 blog's step list as a contract.
Keep CERT-In logging and incident practice aligned. GIGW 3.0 explicitly wants cyber guidance to travel with the website standard.
- Decide the scope: which hosts, which apps, which widget.
- Read GIGW 3.0 and the STQC WQC page.
- Gap-assess with someone who has done a CQW, not only an AI engineer.
- Fix accessibility and content ownership before you tune the model.
- Stabilise the architecture (same-origin, no surprise JS).
- Apply, audit, close non-conformities, certificate, calendar the expiry.
AI failures an auditor can see without being an ML engineer
A widget that cannot be used with a keyboard or a screen reader. That is accessibility, not taste.
A bot that answers only in English on a site that claims bilingual content. GIGW language expectations are not optional decoration.
A bot that invents a closed scheme. That is a content-governance fail with newspaper consequences.
A third-party script that sends keystrokes to a foreign host. That is security and possibly a transfer. It is also how an air-gap story dies on a public page.
No owner for the corpus. GIGW wants roles. An agent without a corpus owner is an unowned publication.
What GIGW/STQC is not
It is not ISO 27001. Different standard, different auditor class. You may want both. See the ISO piece.
It is not a model certification. STQC is not blessing your weights.
It is not DPDP compliance by itself. A beautiful, accessible site can still process personal data without a lawful basis.
It is not a substitute for a procurement path. A certified site can still have been bought badly.
Objections you will hear — and what to do with them
These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.
The agent is not the website; it is a service.
If it is on the page, it is the website. Auditors follow the citizen, not your microservices diagram.
We will certify after the launch because politics is waiting.
Then launch a non-conversational page. Adding an ungoverned bot to hit a date is how you certify a scandal.
STQC is too slow for AI.
Then the public surface is too early. Officer-only tools can move first. Public widgets wait for the path.
Our vendor is ISO 27001 so GIGW is redundant.
ISO does not score Hindi content ownership or Indian government identity guidelines. Different questions.
A 90-day public-widget plan
Start this when someone says 'put a bot on the portal', not the week of the audit.
- Days 1–15: read GIGW 3.0 and STQC WQC pages. Write the scope. Name the content owner.
- Days 16–45: accessibility and content fixes on the existing site. Freeze the corpus. Kill third-party scripts you cannot justify.
- Days 46–70: implement the widget same-origin, with refusal policy and human handoff. Security review with CERT-In practice in mind.
- Days 71–90: apply / recertify as STQC currently requires. Calendar expiry. Do not launch a second widget during the audit.
How this shows up in the file
File note: 'The proposed assistant is in scope of the public website. GIGW 3.0 applies. STQC certification path is [new / recert / surveillance] as advised on the STQC page dated … Content owner: … Security owner: … Third-party scripts: none / listed. This is not a model certification and not a DPDP opinion.'
Vendors: put GIGW cooperation in the SOW — evidence packs, not a fake 'we are certified' logo.
This article is informational field guidance for Indian public institutions and their vendors, not legal, tax, procurement or engineering advice. Confirm the live circular, RFE, GCC, GeM term, state G.O. and your counsel before you file anything. Incentives, ceilings and portal screens change.
How to run the route without confusing the letterhead
“GIGW and STQC Together: The Audit Path” is a route problem. A P4 Security/CISO should know which legal person they are talking to — NIC, NICSI, a state IT corporation, iDEX, or a GeM buyer — and which paper that person can actually issue. Searching “GIGW STQC audit” is not the same as being on a panel that can receive a work order.
If citizens meet your agent through a government website or app, GIGW still applies. STQC's quality-certification path is how many departments prove it. The model behind the site does not get a waiver. Empanelment letters are not purchase orders. DPIIT recognition is not a technical score. Reserved startup seats, if a notice writes them, are local to that notice. IndiaAI compute empanelment is not NICSI application-software empanelment.
Keep a warm evidence pack: CIN, GST, DPIIT, Udyam, financials, work-completion letters, architecture one-pager, DPA draft. Renewals are lost by people who treat the panel as a trophy.
- Screenshot the live RFE paragraph you are relying on, dated.
- Match the bidding entity name across every certificate.
- Do not mix iDEX, TDF, NICSI and GeM clocks on one tracker cell.
- Record the validity end date 90 days before it dies.
Close this loop before the next CAB
Put “GIGW and STQC Together: The Audit Path” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P4 Security/CISO, not “the vendor.”
Revisit the item when the model, the GeM term, the region, or the SI changes. “GIGW STQC audit” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.
Questions this usually raises
- Does every government AI system need STQC GIGW certification?
- Public government websites and apps generally sit under GIGW, and many organisations are expected to obtain STQC quality certification. An officer-only agent with no public surface is a different scope question. When in doubt, ask the department's website owner.
- Is GIGW 3.0 mandatory?
- Government organisations are expected to implement the current guidelines and to pursue the stated certification path. Read the live GIGW introduction and your ministry's circulars rather than a vendor summary.
- Who issues the certificate?
- STQC's website quality certification process issues the CQW-style certificate. Vendors do not. Put that in the file next to “GIGW STQC audit” so a stranger can reconstruct it. A one-line yes/no under “GIGW and STQC Together: The Audit Path” is not an answer a secretary can defend. Confirm against the live Gazette, circular or GeM term; this is not legal advice.
- Does a GIGW certificate expire?
- Certificates are time-bounded and scoped. A major change such as adding an agent is a reason to talk to STQC about recertification or surveillance. Do not assume a three-year sleep.
- Can an air-gapped officer tool skip GIGW?
- If it is not a public government website or app, GIGW may not be the governing standard. Security, logs and DPDP do not skip. If you later publish a window onto it, you are back in GIGW.