AIS-189 vs UN R155/R156: What India OEMs Need to Know

How India's mandate lines up with UN R155/R156, and where it doesn't.

AIS-189 is India's automotive cybersecurity standard. It is closely modelled on UN R155/R156, so most of a manufacturer's work carries over, but the approval route and a few details are India-specific, and that is where OEMs get caught out.

If you already sell into UNECE markets, the good news is that the underlying discipline is the same. Both regulations expect you to run an approved Cybersecurity Management System (CSMS) that manages risk across the whole vehicle lifecycle, not just at launch. Build that capability once and it satisfies both.

Where AIS-189 aligns with UN R155/R156

The core is shared: a documented CSMS, threat analysis and risk assessment (TARA) behind your design decisions, monitoring for new threats after the vehicle is on the road, and evidence that you manage cybersecurity across your supply chain. Type approval in both regimes is gated on that CSMS being audited and approved.

Where it differs

What to do now

If you hold an R155/R156 CSMS, map your existing processes to the AIS-189 clauses and close the India-specific gaps rather than starting again. If you are early, build the CSMS to the shared model first, it is the long pole, then handle the national approval steps.

The fastest way to see the overlap and the gaps side by side is a compliance gap assessment mapped to the markets you actually sell in.

From Reading About Compliance to Achieving It

When you're ready to go from understanding AIS-189 to actually meeting it, start with a gap assessment mapped to your product and markets.