Document management
AI document management for legal and compliance teams: OCR, semantic search and retention in India
AI document management turns files into searchable text: OCR reads scans, an index finds passages by meaning, and answers cite the page they came from. It is weakest on poor scans, handwriting and some Indic-script documents. In India, law sets retention: eight years for books of account, erasure under the DPDP Act, and intermediary retention under the IT Act.
What do OCR and semantic indexing actually do?
A PDF either has a text layer or it is a picture of a page. Documents exported from Word have text; scanned agreements, stamped and signed copies and faxed letters usually do not. Optical character recognition (OCR) reads the image and produces text, ideally with the page number and position of each line, so that a search hit can be traced back to where it appears.
Indexing then makes the text findable. Lexical search matches words and their stems, and is good at exact things: a section number, a defined term, a party name. Semantic search represents passages as vectors so that a query finds text with a similar meaning even when the words differ, such as "limitation of liability" finding a clause headed "Cap on damages". Most serious systems combine the two, because each misses what the other finds.
An answer layer on top reads the best passages and drafts a reply. Its quality depends almost entirely on which passages it was given. Policy documents commonly open with a cover page, distribution list and summary table that mention every common term; a system that quotes the first matching page will quote the letterhead and correctly report that the passage does not answer the question. Ranking passages by how densely they address the query matters more than the language model.
Where does OCR fail?
OCR is good on clean, typed, single-language pages. Legal archives are rarely that. The common failures are:
- Poor scans: low resolution, skewed or curled pages, photocopies of photocopies, and stamps, seals or signatures printed over the text.
- Handwriting: handwritten amendments, initials against changes and filled-in blanks on printed forms are read unreliably, and those are often the parts that matter.
- Indic scripts: accuracy varies by script and by model, conjuncts and vowel signs are easily misread, and documents that mix English with Hindi or a regional language on one page, as stamp papers and government letters often do, are harder still.
- Legacy fonts: many older Hindi and regional-language documents were typed in non-Unicode fonts. Their PDFs have a text layer, but it extracts as meaningless Latin characters, so the file looks searchable and is not.
- Tables and schedules: rate cards, payment schedules and annexures lose their row and column structure, so a number is found but not what it belongs to.
How should a legal team check that search is reliable?
Measure coverage before trusting results. A repository should be able to say how many documents have extracted text, how many pages had none, and which documents need re-scanning. A search that returns nothing is only meaningful if the document it should have found was actually indexed.
Keep the original image as the record and treat OCR text as an index to it, never as a substitute. Show the page reference with every hit and every answer, so a reviewer can check the source in seconds. And design the answer layer to be allowed to say "the repository does not address this", with the passages it read shown alongside, so that a missing answer can be told apart from a retrieval failure.
Which Indian retention rules shape a document system?
Retention is not a preference. Several statutes set a minimum period, and the DPDP Act sets a duty to erase, so the same repository has to keep some records and delete others on schedule.
- Books of account: section 128(5) of the Companies Act, 2013 requires books of account for not less than eight financial years immediately preceding a financial year, with the vouchers relevant to any entry, to be kept in good order. The Central Government may direct a longer period where an investigation has been ordered under Chapter XIV. Section 128(1) allows electronic books in the manner prescribed, which is set out in the Companies (Accounts) Rules, 2014.
- Personal data: section 8(7) of the Digital Personal Data Protection Act, 2023 requires a data fiduciary, unless retention is necessary for compliance with law, to erase personal data when consent is withdrawn or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever is earlier, and to cause its data processors to erase it too.
- DPDP Rules, 2025: rule 6(1)(e) requires logs and personal data needed to detect and investigate unauthorised access to be retained for one year; rule 8(3) requires personal data, traffic data and processing logs to be kept for at least one year from processing for the purposes in the Seventh Schedule; and rule 8(1) with the Third Schedule sets a three-year inactivity period for large e-commerce, online gaming and social media platforms, with 48 hours' notice before erasure under rule 8(2). These rules come into force eighteen months after the Rules were published on 13 November 2025.
- Intermediaries: section 67C of the Information Technology Act, 2000 requires an intermediary to preserve and retain information as the Central Government prescribes, and makes intentional or knowing contravention punishable with imprisonment of up to three years and a fine. Rule 3(1)(g) of the Intermediary Guidelines Rules, 2021 requires removed or disabled information and associated records to be preserved for 180 days for investigation, or longer if a court or authorised agency requires; rule 3(1)(h) requires a user's registration information to be kept for 180 days after the registration is cancelled or withdrawn.
- System logs: the CERT-In directions of 28 April 2022 require service providers, intermediaries, data centres, body corporates and government organisations to keep logs of all ICT systems for a rolling 180 days within India.
How should retention be modelled in the system?
As schedules, not folders. Each record class needs a retention period, the event that starts the clock (end of the financial year, contract expiry, account closure, last contact with the data principal), the legal basis, and what happens at the end: review, archive or destroy. Where two rules apply, the longer minimum wins over the erasure duty only for as long as the law requires retention, which is the exception section 8(7) itself makes.
Destruction needs its own controls. A disposition should be proposed by one person and approved by another, blocked automatically by any legal hold, and evidenced by a record of exactly what was removed. Deleting a document from the application does not by itself purge backups or object storage, and the deletion record should say so rather than imply otherwise.
What access controls and audit trails do auditors expect?
Need-to-know access by default for sensitive classes such as board papers, investigation files and HR records, with department or matter scoping so that access follows responsibility. Rule 6 of the DPDP Rules expects measures to control access to computer resources and visibility of access to personal data through logs, monitoring and review.
Every view, download, share, edit, approval and deletion should be logged with the user and time, and the log should be exportable. Approvals are stronger when bound to a hash of the exact file approved, so that any later change to that version is detectable. External auditors and regulators should get scoped, time-limited, read-only access to a defined set of documents rather than a shared login.
Where does IntelloVault fit?
IntelloVault, IntelloSync's document management system, extracts text from each document version page by page, including scanned PDFs, and reports index coverage. Search results and answers cite the pages they came from and show the passages used, so "the repository does not say" is distinguishable from a retrieval miss. AI classification proposes tags and departments for a person to accept; nothing is applied until someone does.
Retention schedules carry a period, a trigger and a disposition action, and destruction without approval is refused. Disposition is maker-checker, and the certificate of destruction records the SHA-256 hash of every file removed and states that object-storage purge is separate. A legal hold blocks deletion, archiving and disposition of the documents it covers, and if the hold check cannot run the action is refused. Inspection mode gives an auditor a token-gated, read-only, time-boxed, watermarked and fully logged view of a document set fixed when the link is created, and approvals are bound to the SHA-256 hash of the approved version.
The Intermediary Guidelines text cited is MeitY's consolidated version updated to 6 April 2023; the Rules were amended again in October 2025 and February 2026, and MeitY's FAQ on those amendments does not indicate a change to rule 3(1)(g) or (h), but confirm against the current Gazette text. The Companies (Accounts) Rules, 2014 set further conditions for electronic books, including where backups are kept; read rule 3 as currently amended.
Aakash Chaudhary is the founder and CEO of IntelloSync, which builds IntelloVault, a document management system for legal and compliance teams. This article describes the technology in general terms and the statutory framework as published, and is not legal advice. The views expressed are his own.
Sources
Check the law yourself
- Companies Act, 2013 (India Code) — section 128
- Digital Personal Data Protection Act, 2023 (MeitY) — section 8
- MeitY — Digital Personal Data Protection Rules, 2025 — rules 1, 6, 8 and Third and Seventh Schedules
- Information Technology Act, 2000 (India Code) — section 67C
- MeitY — IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as updated 6 April 2023 — rule 3(1)(g) and (h)
- MeitY — FAQs on the Intermediary Guidelines Amendment Rules, 2026
- CERT-In Directions of 28 April 2022
FAQ
Frequently asked questions
How long must a company keep its books of account in India?
At least eight financial years immediately preceding the current financial year, with the vouchers for each entry, under section 128(5) of the Companies Act, 2013. A company in existence for less than eight years keeps all preceding years. The Central Government may direct a longer period if an investigation has been ordered.
Does the DPDP Act require companies to delete documents?
It requires erasure of personal data once consent is withdrawn or the purpose is no longer served, unless retention is necessary for compliance with law (section 8(7)). Documents containing personal data therefore need a retention schedule with a legal basis. The detailed retention and erasure rules apply from May 2027.
What does section 67C of the IT Act require?
It requires intermediaries to preserve and retain information for the duration and in the manner the Central Government prescribes, with knowing contravention punishable by up to three years' imprisonment and a fine. The Intermediary Guidelines Rules, 2021 set 180 days for removed content and for registration information after an account is closed.
Can OCR read Hindi and other Indic scripts?
Often, but accuracy varies by script, scan quality and model, and mixed-language pages are harder. Documents typed in legacy non-Unicode fonts are a separate trap: they have a text layer that extracts as gibberish. Test on a sample of your own archive and check coverage before relying on search.
Should OCR text replace the scanned original?
No. Keep the original file as the record and use the OCR text as an index to it. Every search hit and answer should point to the page in the original, so a reviewer can confirm the wording before relying on it.
How long should access logs be kept?
The CERT-In directions of 28 April 2022 require ICT system logs to be kept for a rolling 180 days within India. From May 2027, the DPDP Rules add a one-year minimum for logs of personal-data processing. Sector regulators and contracts may require more.