There is a quiet assumption embedded in most conversations about AI and Indian business: that AI is primarily an efficiency tool, and that its governance implications sit mostly in data security and IT policy.
The BRSR framework does not see it that way. Neither do the buyers, investors, and assessors who are increasingly asking mid-sized Indian companies to show not just what their social policies say, but what their operational systems actually do.
Companies using AI for hiring, workforce monitoring, productivity tracking, or performance management have social governance obligations most have not yet thought through. Those obligations sit directly inside BRSR’s human rights and workforce principles. They affect what an assessor will look for. And they create a category of risk that the policy document on the company’s intranet is almost certainly not addressing.
This post is for HR heads, sustainability leads, and company secretaries at mid-sized listed companies who are starting to use AI tools in workforce management and have not yet mapped those tools to their BRSR obligations.
What AI in the Workplace Actually Looks Like in Indian Companies Today
Before connecting to BRSR, it is worth being specific about what “AI in the workplace” means in practice, because the term is broad enough to obscure the actual governance questions. Indian mid-sized companies are using AI-driven tools across four main categories:
Recruitment and hiring.
AI-powered applicant tracking systems that screen resumes, rank candidates, filter on keywords, and in some cases score video interview responses. These tools filter applicants before any human reviewer sees them. A candidate can be eliminated from consideration by an algorithm without any human ever evaluating their profile.
Workforce monitoring.
Productivity tracking tools that log keystrokes, capture periodic screenshots, track application usage, monitor login and logout times, and in some remote work contexts use webcam-based presence detection. These tools are more common than most sustainability teams realise, particularly in IT services, BPO, and manufacturing support functions.
Performance management.
Algorithmic performance scoring systems that aggregate data from multiple sources, sales figures, response times, error rates, output volumes, and use these to generate performance scores that influence appraisals, promotion decisions, and termination recommendations.
Workforce planning and deployment.
AI tools that assign shifts, allocate work, or schedule workers based on operational demand, often without direct human review of individual assignments.
Each of these categories produces a social governance question that maps directly to BRSR. The question is not whether companies should use these tools. The question is whether they have the governance architecture to use them in a way that is defensible under BRSR Principles 3 and 5, and increasingly under India’s Digital Personal Data Protection Act.
What BRSR Actually Requires on This
BRSR is built on the nine principles of the National Guidelines on Responsible Business Conduct. Three of those principles are directly engaged by AI in the workplace.
BRSR Principle 3 requires companies to respect and promote the wellbeing of all employees, whether permanent, contractual, or part-time. BRSR Core’s social and workforce attributes specifically cover workforce size and composition, use of contract labour, diversity, health and safety performance, training, wages, and access to social security benefits. (Source: ESG Market Advisory)
When an AI hiring system screens out candidates based on algorithmic criteria, and that system has not been audited for discriminatory outcomes, the company’s ability to demonstrate compliance with its diversity and inclusion commitments under Principle 3 becomes harder to establish. The number may be disclosed. The system that produced it may be producing biased outputs. That combination is a governance gap.
BRSR Principle 5 requires companies to respect and promote human rights. BRSR’s Principle 5 focus covers human rights due diligence, policies against discrimination and harassment, forced labour, and providing access to remedy for affected individuals. BRSR requires disclosures on human rights policies, training, and any reported instances of human rights violations. (Source: POLARIS Market Research)
Human rights due diligence under BRSR Principle 5 is not limited to supply chain relationships. It includes the company’s own workforce. A worker who is subject to algorithmic performance management that results in a warning, a demotion, or a termination recommendation, and who has no mechanism to understand or challenge that decision, is in a situation that implicates Principle 5 directly. The question is not theoretical. It is whether the company’s grievance mechanism, which BRSR also requires, is accessible and functional for workers who want to contest AI-driven decisions affecting their employment.
BRSR Principle 3 Essential Indicators specifically require disclosure of: number of complaints related to working conditions; access to and details of complaints mechanisms for workers; and details of any corrective actions taken. BRSR Principle 4 requires disclosure of human rights due diligence conducted and its scope, premises accessible to differently abled visitors, percentage of value chain partners assessed for rights issues, and actions taken to address rights risks. (Source: Research and Markets)
When AI systems are making or influencing consequential decisions about workers, human rights due diligence has to include those systems. A company that discloses it has conducted human rights due diligence but has not reviewed the AI tools that affect its workforce’s employment status is making a disclosure that an assessor will find difficult to verify.
The DPDP Act Adds Another Layer
India’s Digital Personal Data Protection Act, enacted in August 2023, adds a parallel set of obligations that interact directly with AI in the workplace.
The DPDP Act remains applicable to any processing of personal data through AI systems, if the other conditions of the law are met, given the broad definitions of processing and personal data. (Source: Mordor Intelligence)
With the recent uptick in employers using AI tools for recruitment, such as automatically screening job applicant resumes and matching applicants to new job opportunities, employers must ensure that the underlying data is accurate. (Source: Fortune Business Insights)
The DPDP Act’s requirements on notice, consent, and data accuracy apply to employee data processed through AI systems. Where AI makes a consequential decision using personal data, the data must be accurate, and employees have rights of correction. Correction, completion, and updating of personal data can be requested by the employee, but must also occur automatically when the personal data is likely to be used to make a decision that affects the principal. (Source: Mordor Intelligence)
One significant gap in the current framework is worth being honest about. Under Sections 11-12 of the DPDP Act, a worker can access or correct their data only if they previously provided consent. However, most workplace data processing occurs under the non-consent clause of Section 7(i). This effectively denies workers access to their data and recourse against algorithmic decisions, marking a significant gap in data governance for the Indian workforce. (Source: UnivDatos)
This gap does not eliminate the governance obligation. It makes it more important that companies build internal grievance mechanisms that give workers a meaningful channel to raise concerns about AI-driven decisions, because the regulatory framework alone does not guarantee that channel.
The Five Governance Questions AI in the Workplace Creates Under BRSR
These are not hypothetical. They are the questions a diligent BRSR Core assessor, a buyer ESG auditor, or a PE due diligence team will ask when they discover that a company uses AI in workforce decisions.
1. Has the company conducted human rights due diligence on its AI hiring tools?
BRSR Principle 5 requires disclosure of human rights due diligence conducted and its scope. If a company uses an AI-powered applicant tracking system, that system is part of the company’s human rights risk landscape. Vendors cap liability in standard agreements. An employer’s platform may scrape data from unknown sources, score candidates using opaque logic, and filter applicants before any human review, yet vendor agreements typically cap liability, disclaim compliance warranties, and restrict algorithmic audits. (Source: White & Case LLP)
A company that discloses it has conducted human rights due diligence but cannot show it has reviewed the AI tools making pre-screen hiring decisions is making an incomplete disclosure.
2. Can workers access a functioning grievance mechanism for decisions made by or influenced by AI?
BRSR requires companies to have a grievance mechanism accessible to workers, with documented intake, timelines, and closure records. If an AI performance system flags a worker for termination and that worker wants to understand or challenge the basis for that recommendation, the grievance mechanism must be able to receive, process, and resolve that challenge. Most grievance mechanisms at mid-sized companies were not designed with AI-driven decisions in mind. They were built for interpersonal disputes and safety complaints.
3. Are workforce diversity and inclusion disclosures accurate when AI hiring tools are in use?
AI that automatically filters out candidates with gaps in employment or specific keywords may inadvertently discriminate against protected groups or those with disabilities. (Source: CSDDD | Updates, Compliance) If a company’s AI hiring tool is systematically filtering out certain demographic groups, the diversity metrics the company discloses under BRSR Principle 3 may be accurate as stated but misleading in context. An assessor who understands the hiring process will identify this as a governance gap.
4. Is workforce monitoring proportionate, disclosed, and subject to a grievance pathway?
Productivity monitoring tools that track keystrokes, screen activity, or camera-based presence have implications for worker dignity and privacy. BRSR’s worker wellbeing disclosures and the DPDP Act’s data processing requirements both apply. Companies using these tools without a clear internal policy, worker notice, and a grievance pathway for concerns about monitoring have an exposure that their BRSR filing does not currently capture.
5. Does the company’s board receive visibility on AI workforce risks?
BRSR Principle 3 and the broader BRSR governance framework require board-level oversight of social matters. If AI tools are making or influencing decisions about hundreds or thousands of workers, those tools are a social governance risk that should appear somewhere in the company’s board reporting. In most mid-sized companies, they do not. The AI tools are implemented by IT or HR, used operationally, and never reach the sustainability committee or the board.
What Good Governance Looks Like Here
None of this argues against using AI in workforce management. The tools can be genuinely useful. The argument is about governance architecture: what needs to be in place for a company to use these tools in a way that is defensible under BRSR, honest in its disclosures, and fair to workers.
Four things every company using AI in workforce decisions should have in place:
An AI use register for workforce decisions. A documented inventory of which AI tools are used, what decisions they influence, what data they process, and who is responsible for their oversight. This does not need to be complex. It needs to exist.
Human rights due diligence that explicitly covers AI tools. The BRSR Principle 5 disclosure on human rights due diligence should name the AI tools used in workforce decisions as within scope. The due diligence should include at minimum: a review of how the vendor handles bias testing, what data sources the tool uses, and what appeal or override mechanism exists.
A grievance mechanism that explicitly covers AI-influenced decisions. Workers should be able to raise a concern about an AI-driven decision through the company’s existing grievance mechanism. The intake form, the workflow, and the escalation path should all be capable of handling this category of complaint. If they are not, the mechanism needs to be updated.
Board visibility on AI workforce risk. Twice a year at minimum, the sustainability committee or board should receive a summary of the AI tools used in workforce decisions, any concerns raised through the grievance mechanism about those tools, and any bias or accuracy issues identified through internal review.
Why This Will Become More Visible, Not Less
The regulatory direction globally is toward more scrutiny of AI in employment, not less. 83% of companies had planned to use AI to screen resumes in 2025, according to a survey by Resume Builder, yet state rules in the US demand audits, notices, and bias tests that vary widely. (Source: Normative)
India’s regulatory framework does not yet have dedicated AI employment law. But BRSR’s human rights due diligence requirements, the DPDP Act’s data processing obligations, and the direction of international investor scrutiny all point in the same direction. Companies that build the governance architecture now will be in a materially better position when assessors, buyers, and investors start asking these questions specifically.
The companies that will struggle are the ones that have implemented AI workforce tools operationally without connecting them to their social governance framework. When the BRSR disclosure says “human rights due diligence conducted” and the AI hiring tool has never been reviewed for discriminatory outcomes, that gap will eventually be visible.
Frequently Asked Questions about AI in the Workplace and BRSR
Does BRSR specifically mention AI or automated decision-making?
The current BRSR framework does not use the words “AI” or “automated decision-making” explicitly. However, BRSR Principles 3 and 5 require human rights due diligence, worker grievance mechanisms, and workforce wellbeing disclosures that apply to any organisational process affecting workers, including automated ones. The scope of these obligations does not change because a decision is made by an algorithm rather than a manager.
Is the DPDP Act in force for employee data in India?
The Digital Personal Data Protection Act was enacted in August 2023. Its rules were notified by the Indian government in November 2025 via G.S.R. 846(E). The Act applies to processing of digital personal data including employee data, with processing under employment-related purposes covered under Section 7(i) of the Act.
What is the governance risk if our AI hiring tool has not been audited for bias?
A company using an AI hiring tool that has not been reviewed for discriminatory outcomes has a gap in its human rights due diligence under BRSR Principle 5. If the tool’s outputs are producing demographic disparities in who gets screened through to interview, the company’s diversity disclosures under BRSR Principle 3 may be accurate as stated but misleading in context. An assessor who understands the hiring process may identify this. A buyer due diligence team almost certainly will.
Does a worker have a legal right to challenge an AI-driven employment decision in India?
Under the current DPDP Act framework, workers can request correction of personal data used in decisions affecting them, but this right is limited when processing occurs under the non-consent employment clause. There is currently no explicit statutory right to contest a solely automated employment decision in India, unlike under the EU GDPR. This makes internal grievance mechanisms that cover AI-driven decisions more important, not less.
What should a BRSR Principle 5 disclosure say about AI in the workplace?
At minimum, a complete BRSR Principle 5 human rights due diligence disclosure for a company using AI in workforce decisions should acknowledge that automated tools are within scope of the due diligence, identify the categories of decisions AI tools influence, describe how the company monitors for discriminatory or inaccurate outcomes, and note the grievance pathway available to affected workers. A disclosure that says human rights due diligence was conducted without any reference to AI tools is incomplete if those tools are in use.
Where does this fit in the SVEGA Framework?
AI workplace governance sits across two pillars of the SVEGA Framework. Pillar 2, Workforce Governance Architecture, covers the KPI ownership, monitoring, and evidence infrastructure that must extend to AI-influenced workforce decisions. Pillar 4, Grievance and Escalation Infrastructure, covers the mechanism design that must be capable of receiving and resolving worker concerns about automated decisions. A SVEGA Diagnostic will assess whether your current governance architecture covers AI workforce tools or has left them outside its scope.
What to Do Next
If your company uses AI tools in hiring, performance management, monitoring, or workforce planning, start with an honest internal audit of three things.
First, which tools are in use and what decisions do they influence. Second, whether those tools have been reviewed for accuracy and discriminatory outcomes, and what the vendor contractually provides in terms of transparency and auditability. Third, whether the company’s grievance mechanism can receive and process a worker complaint about an AI-driven decision.
If any of those three audits produces a gap, that gap is a BRSR governance exposure. It is also the kind of exposure that surfaces first in a buyer due diligence conversation or a BRSR Core assessment, not in an internal review.