All insights

Sovereignty & Data Residency

A Sovereignty Maturity Model for Departments

· 10 minute read

Maturity is not a vendor badge. Score your own department on purpose, perimeter, erasure, compute and operations, then fund the next level, not the next slogan.

The principal secretary wanted a number. Are we a three or a four on AI? The CIO had a vendor-supplied maturity rainbow that ended in transformative. The DPO had a stack of unmapped processors. The SDC head had two GPUs and no egress policy. They were not on the same scale, so they invented a four and put it in a review presentation.

Maturity models are dangerous when they become stickers. They are useful when they force a department to admit which muscle is missing. This one has five dimensions and five levels. It is not notified. It is not scientific. It is better than a rainbow.

Score a workflow first, then the department as the minimum of its high-risk workflows. A brilliant research chatbot does not lift a leaky pension agent.

Five dimensions

Levels 1 and 3 exist between these columns. Do not skip them on a slide.
DimensionLevel 0Level 2 (typical target this year)Level 4
PurposeOfficers paste live records into public toolsEach workflow has a named basis and an ownerChange control treats new tools as new purposes; shadow use is measured
PerimeterUnknown outboundAllow-list, fail closed, named subprocessorsAir-gap or equivalent for the high class; verified after every patch
Erasure and exitNo write-set listDelete-by-principal on core stores; certificate templateDrilled on all stores including eval and adapters; exit tested
Compute and artefactsOnly hosted APIsLocal or instructed serving; hashes of weights; buyer-owned adaptersRestore test onto a clean box; spare and degrade plan
OperationsHeroic individualsLocal logs meet CERT-In clocks; on-call; eval setTwo-person control on promotion; tabletop incidents; measured quality

How to score without lying

A level is only as high as the evidence. A policy PDF is Level 1 at best. A tested control is Level 2 or 3. A control that survived a patch and a staff change is Level 4.

Do not average dimensions into one number for the press. A department at 4 on compute and 0 on purpose is a well-equipped leak. Report a radar, or report the minimum.

Level 1 and Level 3, so nobody skips

Level 1 on purpose is a written acceptable-use note and a banned-paste list that officers have actually seen. It is not yet a basis table, but it is no longer a free-for-all. Level 3 on purpose is the Level 2 table plus a change board that has refused at least one new tool in the last year. If the board has never refused anything, you are not at 3.

Level 1 on perimeter is an inventory of outbound hosts, even if some of them are still open. You cannot close what you have not named. Level 3 is fail-closed plus a post-patch capture that is filed. The capture is what separates a policy from a habit.

Level 1 on erasure is a ticket store you can delete from. Level 3 includes vectors, traces and the eval copy. Level 1 on compute is a local serve of someone else’s hosted API in front of a GPU you never turned on — which is to say, you are still at 0 and should not lie. Level 3 on operations is an on-call roster that has taken a real page, not a WhatsApp group that goes quiet at 6 p.m.

Write those intermediate marks on the scoring sheet. People skip what they cannot see. Skipping is how a department jumps from a rainbow slide to a claimed Level 4 and then fails the first erasure request.

Objections

This will embarrass us. Yes. That is the budget conversation you have been avoiding.

NIST already has an AI RMF. Use it for risk process. This model is narrower: it scores sovereignty-shaped controls for an Indian department. They can sit side by side.

We will game the levels. Then require evidence dates. Gaming a dated egress test is harder than gaming an adjective.

How to use the radar in budget season

A maturity model that does not change a sanction is a poster. Bring the radar to the budget meeting with two priced climbs attached. Climb A is purpose and perimeter on the pension agent. Climb B is compute on the public FAQ. If money buys only one, buy A. The FAQ can stay hosted a year longer. The pension agent cannot stay at Level 0 on purpose.

Refuse vendor-funded maturity workshops that end with a transformative roadmap and no dated evidence. If a consultant wants to help, they can sit in the scoring room and argue about whether a control is Level 1 or 2. They cannot award you a 4 on a flipchart.

Publish the radar inside the department. Do not publish it as a press number. Internal visibility is how shadow ChatGPT use gets measured instead of denied. External visibility is how you will be forced to inflate the score.

Pair the radar with the posture table from the air-gap article. A workflow can be Level 2 on perimeter in an on-prem fail-closed estate and that can be enough. Do not let a defence-adjacent visitor talk you into an air-gap you cannot operate just to paint a cell darker.

A 90-day climb, one workflow

  1. Days 1–10: score the five dimensions with evidence or blanks.
  2. Days 11–30: pick the two lowest dimensions on the highest-risk workflow.
  3. Days 31–75: implement only those two. Do not start a new chatbot.
  4. Days 76–90: rescore. Put the radar in the file the secretary sees.

What goes in the file

  • The radar with dates and evidence links, not a cartoon.
  • The workflow chosen as the departmental minimum.
  • The two dimensions funded this quarter.
  • A note that the model is internal and not a notified standard.

Prcept AI can sit on the compute and operations axes. We cannot award you a purpose level. That one is yours.

How to defend this in the file

A P1 CIO/CTO will be asked to explain “A Sovereignty Maturity Model for Departments” to a secretary who has ten minutes. Do not start with the model. Start with the store, the hop, the clause, or the residual risk. “AI sovereignty maturity model” is a search phrase. The file needs a decision.

Maturity is not a vendor badge. Score your own department on purpose, perimeter, erasure, compute and operations, then fund the next level, not the next slogan. DPDP does not define sovereign AI. Transfers can be lawful and still be a bad idea. Sector circulars can be stricter than DPDP. Write which instrument you are using.

If you cannot name the Data Fiduciary, the processor, the location of traces, and the erasure method, you are not ready for production personal data — whatever the architecture PDF says.

  • One sentence on lawful basis or the procurement rule you are invoking.
  • One sentence on where prompts, embeddings and logs live.
  • One sentence on who can compel the operator.
  • One artefact: packet capture, DPA schedule, or deletion certificate template.

Close this loop before the next CAB

Put “A Sovereignty Maturity Model for Departments” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P1 CIO/CTO, not “the vendor.”

Revisit the item when the model, the GeM term, the region, or the SI changes. “AI sovereignty maturity model” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.

Score yourselves this quarter

Pick five workflows. Mark each 0–2 on facility, keys, model path, telemetry, exit. Average nothing. A zero on telemetry is a programme, not a rounding error. Publish the sheet to the CIO. Maturity models that stay in workshops do not move racks.

Re-score after the next model change. If the score cannot fall, it is not a model. It is a poster.

What the next noting must contain

“A Sovereignty Maturity Model for Departments” belongs in a file, not only in a search result. A P1 CIO/CTO should be able to point at one artefact that proves “AI sovereignty maturity model”: a packet capture, a processing schedule, a scored evaluation row, a dated notice, or a refusal rule. If the only evidence is a slide, you have a heading.

Maturity is not a vendor badge. Score your own department on purpose, perimeter, erasure, compute and operations, then fund the next level, not the next slogan. DPDP 2023 does not define sovereign AI and does not write a blanket localisation rule for every model hop. CERT-In’s 28 April 2022 directions still set specified incident clocks and 180-day log retention in India for in-scope events. The November 2025 AI governance text is guidance, not a statute. A Proprietary Article Certificate, when it is lawful, lives in GFR Rule 166 — not Rule 161.

Write three dated sentences under C1 Sovereignty & Data Residency: what was decided, which designation owns it after the next posting order, and when it will be re-checked. Unsigned sentences are souvenirs. Dated sentences are controls.

  • Name the designation that owns “AI sovereignty maturity model”, plus a deputy.
  • Attach one artefact a stranger can open next year.
  • Name the instrument you are actually using — Act, direction, GFR clause, GeM term, or guideline paragraph.
  • Leave unsourced percentages, GMV slides and house forecasts out of the noting.
  • Revisit when the model, the SI, the notice, the region or the posting changes.

Questions this usually raises

Is this an official MeitY model?
No. It is a field framework for departmental self-scoring. Do not put it in an RFP as if it were a notified standard.
Do we need to be Level 4 on everything?
No. A public FAQ can live at a lower perimeter level. A beneficiary-eligibility agent cannot. Score per workflow, then look at the department’s worst high-data-class score.
Can a vendor sell us a level?
A vendor can move compute and some operations. They cannot give you a lawful-basis table or a working erasure certificate. Those are your levels.
How often should we rescore?
After every new workflow and at least twice a year. A patch can drop you a perimeter level overnight.
Where does air-gap sit?
Air-gap is a high perimeter posture, not a maturity prize. You can be operationally immature and air-gapped, which is how projects freeze.

Sources