The processes an OEM has to show, and how suppliers fit in.
AIS-189 is India's automotive cybersecurity standard. It is closely modelled on UN R155/R156, so most of a manufacturer's work carries over, but the approval route and a few details are India-specific, and that is where OEMs get caught out.
If you already sell into UNECE markets, the good news is that the underlying discipline is the same. Both regulations expect you to run an approved Cybersecurity Management System (CSMS) that manages risk across the whole vehicle lifecycle, not just at launch. Build that capability once and it satisfies both.
Where AIS-189 aligns with UN R155/R156
The core is shared: a documented CSMS, threat analysis and risk assessment (TARA) behind your design decisions, monitoring for new threats after the vehicle is on the road, and evidence that you manage cybersecurity across your supply chain. Type approval in both regimes is gated on that CSMS being audited and approved.
Where it differs
- Approval authority and route. AIS-189 is administered under India's own approval framework, so the paperwork, the assessing body and the timelines are national, not UNECE.
- Its software-update counterpart. AIS-189 pairs with AIS-190 for software-update security (a SUMS), which aligns with UN R156 the way AIS-189 aligns with R155/R156.
- Scope and phase-in. Applicability and effective dates are set nationally, so confirm which of your vehicle categories fall in scope and when.
What to do now
If you hold an R155/R156 CSMS, map your existing processes to the AIS-189 clauses and close the India-specific gaps rather than starting again. If you are early, build the CSMS to the shared model first, it is the long pole, then handle the national approval steps.
The fastest way to see the overlap and the gaps side by side is a compliance gap assessment mapped to the markets you actually sell in.