Source: Business Standard
Context
The Reserve Bank of India (RBI) on Wednesday, 24 June 2026, released the Draft Guidance on Regulatory Principles for Model Risk Management, 2026 under Press Release No. 2026-2027/528, setting comprehensive governance, validation, monitoring, and oversight requirements for all models used by regulated entities (REs) — including Artificial Intelligence (AI) and Machine Learning (ML) models. Regulated entities will be required to put in place a board-approved Model Risk Management Framework (MRMF) covering all models, irrespective of whether they are developed internally, sourced from third parties, or built using a combination of both. The draft applies to 11 categories of RBI-regulated entities — commercial banks, cooperative banks, small finance banks, payment banks, NBFCs, asset reconstruction companies (ARCs), credit information companies (CICs), all-India financial institutions, etc. Feedback is invited via RBI’s “Connect 2 Regulate” portal or by post/email to the Chief General Manager, Operational Risk Group, Department of Regulation, RBI, Mumbai until 24 July 2026. Key provisions include: mandatory kill switches for AI systems to halt them instantly if they produce harmful outputs; mandatory human oversight for AI-driven decision-making; three lines of defence (3LoD) structure — model owners (1st), independent validation (2nd), internal audit (3rd); risk-tiered model classification; comprehensive model inventory (active, inactive, decommissioned); explainability and transparency thresholds; customer disclosure when interacting with AI; option to speak with a human for customer-facing AI; red-teaming under edge cases, abnormal inputs, manipulation attempts, and adversarial conditions; and mandatory accountability of REs for outcomes, regardless of vendor origin.
11 Categories of RBI-Regulated Entities Covered
- Commercial Banks.
- Cooperative Banks.
- Small Finance Banks (SFBs).
- Payment Banks.
- Local Area Banks.
- NBFCs (all layers).
- Asset Reconstruction Companies (ARCs).
- Credit Information Companies (CICs).
- All-India Financial Institutions (AIFIs).
- Primary Dealers (PDs).
- Other RBI-regulated entities.
Core Pillars of the MRMF Framework
| Pillar | Requirement |
|---|---|
| 1. Board Accountability | Board-approved MRMF; periodic review; approve risk appetite and tolerance for model risk; scenario analysis and stress testing |
| 2. Three Lines of Defence (3LoD) | 1st: Model owners; 2nd: Independent validation function; 3rd: Internal audit |
| 3. Model Inventory | Maintain comprehensive inventories (active, inactive, decommissioned); no model deployed without formal documentation |
| 4. Risk-Tiered Classification | Every model assigned a risk level (high, medium, low) |
| 5. Independent Validation | High-risk models validated before deployment |
| 6. Ongoing Monitoring | Regular performance review, drift detection, recalibration |
| 7. Audit Trail | Complete documentation of model development, validation, and deployment |
Role of Risk Management Committee of the Board (RMCB)
- Review validation reports of models classified as high risk before deployment.
- Oversee monitoring of third-party and AI-based models.
- Review model-risk classification reports at least annually.
- Examine material breaches and other major concerns.
- Approve material exceptions to MRMF policies.
AI/ML-Specific Mandates
| Mandate | Description |
|---|---|
| Kill Switches | Mandatory override, suspension, deactivation mechanisms to halt AI systems instantly |
| Human Oversight | Mandatory review mechanisms addressing automation bias, over-reliance, decision fatigue |
| Explainability | Define explainability and transparency thresholds for AI models |
| Customer Disclosure | Customers must be informed when interacting with AI |
| Human Option | Customer-facing AI must offer option to speak with a human |
| Pre-Deployment Risk Assessment | Assess if risks can be identified, measured, monitored, managed |
| Red-Teaming | Test under edge cases, abnormal inputs, manipulation attempts, adversarial conditions |
| GenAI Cybersecurity | Additional cybersecurity requirements for generative AI interacting with customers/external users |
| Supply Chain Concentration | Address dependence on few global AI providers |
| No Consumer Harm | REs must not use models that harm consumers |
| Grievance Redress | Mechanisms must address complaints arising from customer-facing AI |
7 AI Risk Dimensions
- Hallucinations (false outputs presented as facts).
- Bias (discriminatory outputs).
- Drift (model performance degradation over time).
- Adversarial attacks (manipulation by bad actors).
- Explainability gaps.
- Data privacy and leakage.
- Concentration risk (dependence on few vendors).
Third-Party Model Risk Provisions
- Vendor disclosure: If vendors don’t disclose adequate information, REs must identify risks and put safeguards in place.
- Restriction: REs may restrict use of such models where necessary.
- Accountability: RE is accountable for outcomes of all models, irrespective of source.
- No “vendor blame” for AI-driven decisions gone wrong.
FREE-AI Committee (Framework for Responsible and Ethical Enablement of AI)
- What: An RBI-constituted committee that submitted its report in August 2025 on responsible AI deployment in India’s financial sector; proposed AI governance principles, explainability standards, human oversight mechanisms, and AI ethics norms; chaired by an external expert.
- Where: Constituted by RBI from Mumbai; report applicable to India’s financial sector.
Utkarsh 2029
- What: RBI’s medium-term strategic framework (2024–2029) that outlines regulatory and supervisory priorities, including digital innovation, AI governance, financial inclusion, cybersecurity, monetary policy modernisation.
- Where: Issued by RBI, Mumbai; applies to all RBI-regulated entities in India.
Practice MCQs
Q1. With reference to the RBI’s Draft Guidance on Regulatory Principles for Model Risk Management, 2026, consider the following statements:
- The Draft was released on 24 June 2026 under RBI Press Release No. 2026-2027/528.
- Regulated entities will be required to put in place a board-approved Model Risk Management Framework (MRMF) covering all models, including AI/ML.
- Feedback can be submitted until 24 July 2026 via the “Connect 2 Regulate” portal.
- The Guidance applies only to commercial banks and excludes NBFCs and other entities.
How many of the above statements are correct?
(a) Only one (b) Only two (c) Only three (d) All four (e) None
(Statement 4 is wrong; the Guidance applies to 11 categories of RBI-regulated entities including NBFCs, ARCs, CICs, SFBs, payment banks, cooperative banks, and others — NOT just commercial banks.)
Q2. With reference to the AI/ML-specific mandates in the draft, consider the following statements:
- Regulated entities must implement mandatory kill switches for AI systems to halt them instantly if they produce harmful outputs.
- Mandatory human oversight is required for AI-driven decision-making to address automation bias and over-reliance.
- Customers must be informed when they are interacting with an AI model and given the option to speak with a human.
- Regulated entities can shift accountability for AI-driven decisions to third-party vendors who developed the models.
How many of the above statements are correct?
(a) Only one (b) Only two (c) Only three (d) All four (e) None
(Statement 4 is wrong; REs remain fully accountable for outcomes of all models, irrespective of whether they are developed internally or sourced from third parties — accountability cannot be shifted to vendors.)
Q3. With reference to the three lines of defence (3LoD) structure under the MRMF, consider the following statements:
- The first line of defence comprises model owners.
- The second line of defence is independent validation functions.
- The third line of defence is provided by internal audit.
- The Risk Management Committee of the Board (RMCB) is part of the first line of defence.
How many of the above statements are correct?
(a) Only one (b) Only two (c) Only three (d) All four (e) None
(Statement 4 is wrong; the RMCB is part of board-level oversight (above the three lines) — NOT part of the first line of defence, which comprises model owners.)
Q4. With reference to the AI risk dimensions identified in the draft, consider the following statements:
- Hallucinations (AI generating false outputs presented as facts) are identified as a key AI risk.
- Algorithmic bias is identified as a key AI risk dimension.
- Concentration risk arising from dependence on a few global AI providers is identified.
- The draft excludes adversarial attacks from AI risk considerations.
How many of the above statements are correct?
(a) Only one (b) Only two (c) Only three (d) All four (e) None
(Statement 4 is wrong; the draft explicitly includes adversarial attacks as one of the 7 AI risk dimensions and requires red-teaming to test models under adversarial conditions.)
Q5. With reference to the predecessor documents and context, consider the following statements:
- The draft follows RBI’s August 2024 draft on Regulatory Principles for Management of Model Risks (in credit).
- It also follows the August 2025 report of the Committee on FREE-AI (Framework for Responsible and Ethical Enablement of AI).
- On finalisation, the new Guidance will supersede Chapter-3 (Credit Risk Models) of RBI’s Guidance Note on Credit Risk Management dated 12 October 2002.
- The draft is aligned with the European Union’s AI Act and has been jointly drafted with the EU.
How many of the above statements are correct?
(a) Only one (b) Only two (c) Only three (d) All four (e) None
(Statement 4 is wrong; while the draft aligns with global AI governance trends, it was drafted independently by RBI, NOT jointly with the EU.)
Q6. With reference to consumer protection provisions in the draft, consider the following statements:
- The RBI states that regulated entities should not use any model that harms consumers.
- Grievance-redress mechanisms must specifically address complaints arising from customer-facing AI.
- Customer-facing AI systems must provide an option for customers to speak with a human at any point.
- Customer-facing generative AI systems are exempted from additional cybersecurity requirements.
How many of the above statements are correct?
(a) Only one (b) Only two (c) Only three (d) All four (e) None
(Statement 4 is wrong; generative AI systems interacting with customers or external users face ADDITIONAL cybersecurity requirements, NOT exemption.)
Answer Key
- (c), Statements 1, 2, 3 are correct; Statement 4 is wrong because it applies to 11 RE categories.
- (c), Statements 1, 2, 3 are correct; Statement 4 is wrong because accountability cannot be shifted to vendors.
- (c), Statements 1, 2, 3 are correct; Statement 4 is wrong because RMCB is board-level, not first line.
- (c), Statements 1, 2, 3 are correct; Statement 4 is wrong because adversarial attacks are included.
- (c), Statements 1, 2, 3 are correct; Statement 4 is wrong because the draft is independent of the EU AI Act.
- (c), Statements 1, 2, 3 are correct; Statement 4 is wrong because GenAI faces additional cybersecurity requirements.








