RBI Draft Model Risk Management Guidance for AI/ML Models
Why in the news
The RBI put out draft rules asking regulated entities to govern every model they use, including AI and machine-learning systems, through a board-backed framework.
Key facts
- Document: Draft Guidance on Regulatory Principles for Model Risk Management, 2026, Press Release No. 2026-2027/528, dated 24 June 2026.
- Requirement: a board-approved Model Risk Management Framework (MRMF) for all models, whether built in-house, bought from vendors or mixed.
- Scope: 11 categories of regulated entities, including commercial, cooperative, small finance, payment and local area banks, NBFCs, ARCs, CICs, AIFIs and primary dealers.
- Comments: through RBI’s Connect 2 Regulate portal, or post/email to the CGM, Operational Risk Group, Department of Regulation, Mumbai, until 24 July 2026.
Core pillars of the MRMF
| Pillar | What it asks |
|---|---|
| Board accountability | Approve framework and risk appetite; periodic review; stress tests |
| Three lines of defence | Model owners, then independent validation, then internal audit |
| Model inventory | List active, inactive and decommissioned models; nothing deployed without documents |
| Risk tiering | Each model rated high, medium or low |
| Independent validation | High-risk models checked before deployment |
| Ongoing monitoring | Performance review, drift detection, recalibration |
| Audit trail | Full record of development, validation and deployment |
AI and ML specific rules
- Kill switches to override, suspend or deactivate AI instantly.
- Human oversight addressing automation bias, over-reliance and decision fatigue.
- Explainability and transparency thresholds.
- Customers told when they deal with AI, with an option to reach a human; grievance redress for such AI.
- Pre-deployment risk assessment and red-teaming under edge cases, odd inputs, manipulation and adversarial conditions.
- Extra cybersecurity for generative AI; attention to concentration on a few global AI providers; no models that harm consumers.
Role of the board’s Risk Management Committee
- Reviews validation of high-risk models before deployment and monitors third-party and AI models.
- Reviews classification reports at least yearly, examines material breaches and approves major exceptions.
Seven AI risks named
- Hallucinations, bias, drift, adversarial attacks, explainability gaps, data privacy and leakage, concentration risk.
Third-party models
- If a vendor shares too little, the entity must find the risks and add safeguards, or restrict use.
- The regulated entity stays accountable for outcomes; blaming the vendor is not allowed.
Related
- FREE-AI Committee: RBI-formed panel whose August 2025 report proposed AI governance, explainability and ethics norms for finance.
- Utkarsh 2029: RBI’s 2024-2029 medium-term strategic framework.
Exam angle
- Framework acronym: MRMF; oversight model: 3LoD.
- Consultation closes 24 July 2026.
- Entity stays responsible even for vendor-built AI.