Skip to content

RBI Draft Model Risk Management Guidance for AI/ML Models

25 June 20262 min read
BANKING & FINANCERBI Draft ModelRisk ManagementGuidance forAI/ML Models25 June 2026safalsetu.com

Why in the news

The RBI put out draft rules asking regulated entities to govern every model they use, including AI and machine-learning systems, through a board-backed framework.

Key facts

  • Document: Draft Guidance on Regulatory Principles for Model Risk Management, 2026, Press Release No. 2026-2027/528, dated 24 June 2026.
  • Requirement: a board-approved Model Risk Management Framework (MRMF) for all models, whether built in-house, bought from vendors or mixed.
  • Scope: 11 categories of regulated entities, including commercial, cooperative, small finance, payment and local area banks, NBFCs, ARCs, CICs, AIFIs and primary dealers.
  • Comments: through RBI’s Connect 2 Regulate portal, or post/email to the CGM, Operational Risk Group, Department of Regulation, Mumbai, until 24 July 2026.

Core pillars of the MRMF

PillarWhat it asks
Board accountabilityApprove framework and risk appetite; periodic review; stress tests
Three lines of defenceModel owners, then independent validation, then internal audit
Model inventoryList active, inactive and decommissioned models; nothing deployed without documents
Risk tieringEach model rated high, medium or low
Independent validationHigh-risk models checked before deployment
Ongoing monitoringPerformance review, drift detection, recalibration
Audit trailFull record of development, validation and deployment

AI and ML specific rules

  • Kill switches to override, suspend or deactivate AI instantly.
  • Human oversight addressing automation bias, over-reliance and decision fatigue.
  • Explainability and transparency thresholds.
  • Customers told when they deal with AI, with an option to reach a human; grievance redress for such AI.
  • Pre-deployment risk assessment and red-teaming under edge cases, odd inputs, manipulation and adversarial conditions.
  • Extra cybersecurity for generative AI; attention to concentration on a few global AI providers; no models that harm consumers.

Role of the board’s Risk Management Committee

  • Reviews validation of high-risk models before deployment and monitors third-party and AI models.
  • Reviews classification reports at least yearly, examines material breaches and approves major exceptions.

Seven AI risks named

  • Hallucinations, bias, drift, adversarial attacks, explainability gaps, data privacy and leakage, concentration risk.

Third-party models

  • If a vendor shares too little, the entity must find the risks and add safeguards, or restrict use.
  • The regulated entity stays accountable for outcomes; blaming the vendor is not allowed.

Related

  • FREE-AI Committee: RBI-formed panel whose August 2025 report proposed AI governance, explainability and ethics norms for finance.
  • Utkarsh 2029: RBI’s 2024-2029 medium-term strategic framework.

Exam angle

  • Framework acronym: MRMF; oversight model: 3LoD.
  • Consultation closes 24 July 2026.
  • Entity stays responsible even for vendor-built AI.

Test yourself

1. RBI's draft guidance on model risk management requires which framework at the board level?

Entities need a board-approved Model Risk Management Framework.

2. In the three lines of defence (3LoD), who forms the third line?

Internal audit is the third line.

3. Feedback on the RBI's draft model risk guidance is invited until when?

Comments are open until 24 July 2026.