An AIS-189/190 readiness checklist for Indian OEMs

A practical, sequenced checklist to get a CSMS and SUMS to an assessable state

8 Aug 20264 min readAutoSifu

What "ready" means

Ready does not mean you have written a policy. It means an assessor can open your evidence and see that a cyber security management system (CSMS) and a software update management system (SUMS) exist, are owned, and were actually followed on a real programme. AIS-189 is aligned to UN R155 and AIS-190 to UN R156, so the bar is the same one those regulations set: processes that are real and evidenced across the vehicle lifecycle.

Note one thing before you start planning: AIS-189/190 enforcement in India is at the draft stage — MoRTH draft G.S.R. 503(E) (17 June 2026), inserting CMVR Rules 125-T and 125-U, proposes a phased timeline from October 2026 to October 2029, but it is not yet finalised in the gazette. That is a reason to build capability now, not to wait — the work below takes the same time whenever the date lands, and the earliest phase is already close. The full schedule is in India's automotive cybersecurity timeline.

The sequence

Readiness is a sequence, not a pile of parallel tasks. Doing it in order is what keeps the effort proportionate.

# Step What "done" looks like
1 Scope The vehicle types, systems, backends and plant in scope are fixed and written down
2 Gap assessment Current processes mapped against AIS-189/190; gaps listed with owners
3 TARA Threat analysis and risk assessment complete, risks treated, decisions recorded
4 Processes CSMS and SUMS processes defined, owned, and operating — not just drafted
5 Evidence Records showing each process ran on a real programme, assembled into a pack
6 Dry-run An internal assessment against the pack before the agency arrives

1. Scope

Decide what is in. A CSMS assessment does not stop at the vehicle — production OT, flashing stations, backends and the supply chain are part of the surface. Get this wrong and everything downstream is either over- or under-built. Fix the vehicle types, the systems, the backends, and the plant, and write the boundary down.

2. Gap assessment

Map what you already do against what AIS-189 and AIS-190 require, and list the gaps with named owners. Most organisations have more than they think — change management, quality records, existing security work — and less evidence than they need. The output is a punch-list, not an essay.

3. TARA

The threat analysis and risk assessment is the spine. It identifies assets, threat scenarios, attack paths, impact and risk, and records the treatment decision for each risk. Under R155/AIS-189 a TARA is not a one-off — it has to be maintained as the design changes. A TARA that was done once and never updated is a classic finding.

4. Processes

Stand up the CSMS and SUMS processes so they operate: governance, risk management, supplier flow-down, monitoring and incident response for the CSMS; configuration, RxSWIN management and update integrity for the SUMS. A process that exists on paper but has never run produces no evidence, and evidence is what step 5 needs.

5. Evidence

This is where first assessments are won or lost. The assessor reads process descriptions and the records proving those processes were followed on a real programme — TARA and risk treatment, verification results, supplier evidence, monitoring logs, and for the SUMS the update and RxSWIN records. Assemble these into a pack the assessor can open in order. The gap between "we have a process" and "here is the record of it running" is the single most common reason an assessment stalls; our note on the gaps that fail a first assessment walks through the recurring ones.

6. Dry-run

Run the assessment on yourself first. A dry-run against the evidence pack surfaces the missing records while there is still time to produce them, and it calibrates the team to how an assessor actually reads. It is the cheapest risk reduction in the whole sequence.

Two honesty notes on timeline

First, how long this takes depends on your starting maturity, scope and supplier readiness — there is no honest single figure. An organisation with mature ISO/SAE 21434 processes and good records is closing gaps; one starting from documents alone is building the machine that produces records. Those are different jobs on different clocks.

Second, because the RxSWIN, records and integrity work for AIS-190 mirrors R156, an OEM already carrying a UN R156 file has a head start on the SUMS half. For where the assessment itself sits in the Indian approval process, see how an Indian type approval actually gets assessed. For the standard behind the CSMS half, see AIS-189 explained.

The AutoSifu view

AutoSifu works one route: compliance, solutioning, and CoC/VTA support, with the approval body in the room. We run this checklist with an OEM end to end — scope through dry-run — and because we prepare the evidence alongside CIRT, the assessor is not seeing the pack for the first time on assessment day. Readiness built this way is durable: it holds whenever MoRTH notifies the date.

Questions

How do I prepare for an AIS-189 assessment?
Work through it in sequence: fix the scope, run a gap assessment against the standard, complete a TARA, stand up the CSMS processes, build the evidence pack that shows those processes ran, then do a dry-run before the real assessment. AIS-189 is aligned to UN R155, so the assessor is judging whether your management system is real and followed — not whether a document exists. Preparation is mostly about producing records, not prose.
What documents does an AIS-189/190 audit need?
The assessor opens process descriptions plus the records that prove those processes were followed on a real programme: TARA and risk treatment, verification results, supplier evidence, monitoring records, and — for AIS-190/SUMS — configuration, RxSWIN and update records. Describing a process is not enough; the evidence has to show it ran. The gap between the two is the most common reason a first assessment stalls.
How long does readiness take?
It depends on your starting maturity, the scope, and how ready your suppliers are — there is no honest single number. An organisation with existing ISO/SAE 21434-style processes and good records moves far faster than one starting from documents alone. Because AIS-189/190 enforcement in India is still at the draft stage — MoRTH draft G.S.R. 503(E) proposes a phased timeline from October 2026 but has not yet finalised it — the sensible plan is to build the capability now rather than compress it against a date that is still moving.

09 — Start here

Bring us the file you are least sure about.

Most conversations start with a gap assessment, or a type approval submission that is closer than it feels. Either is a good place to begin.

Direct

Jaipur · registered office

Plot No. 8, ABS Plaza, Chanakya PuriJagatpura, Jaipur – 302017, RajasthanAUTOSIFU Pvt Ltd · India

Required