Understanding RBI’s Draft Guidance on Regulatory Principles for Model Risk Management

Artificial intelligence has entered a fundamentally different phase in financial services. Banks and financial institutions are increasingly deploying Artificial Intelligence (AI) and Machine Learning (ML) across credit underwriting, treasury operations, fraud management, dynamic pricing and customer service. AI is no longer simply supporting human decision-making; it is increasingly influencing—and in many cases autonomously executing—business decisions that directly affect financial performance, regulatory compliance and customer outcomes.

While these technologies deliver significant gains in operational efficiency and decision-making, they also introduce new dimensions of model risk. Unlike traditional statistical models, modern AI systems continuously evolve as data changes, interact with external foundation models and increasingly operate as interconnected decision systems

As a consequence, model risk has evolved. Historically, institutions focused primarily on statistical accuracy, model calibration, and prediction error. While these remain important, they no longer represent the full spectrum of risk introduced by enterprise AI. Organisations must now govern explainability, hallucinations, prompt injection, concept drift, provider-driven model updates, algorithmic bias, cybersecurity vulnerabilities, concentration risk among AI vendors, human oversight mechanisms, and operational resilience across increasingly interconnected decision ecosystems.

Gaps in model oversight can cause algorithmic anomalies, cascading financial losses, compliance breaches, and severe reputational damage.

Against this backdrop, the Reserve Bank of India (RBI) released its Draft Guidance on Regulatory Principles for Model Risk Management on 24 June 2026 for public consultation. The proposed framework has broad applicability across the Indian financial ecosystem. It covers all Regulated Entities (REs) supervised by the RBI, including:

  • Banking Sector: Commercial Banks, Small Finance Banks, Payment Banks, Co-operative Banks and Regional Rural Banks (RRBs).
  • Non-Banking Sector: Non-Banking Financial Companies (NBFCs) and Housing Finance Companies (HFCs).
  • Specialised Institutions: All-India Financial Institutions (AIFIs), Asset Reconstruction Companies (ARCs) and Credit Information Companies (CICs).

While implementation is expected to be proportionate to an institution’s size, complexity and risk profile, the underlying principle remains consistent: organisations deploying models that materially influence business decisions should establish governance that is proportionate to the risks those models create

Key Regulatory Principles

Expanding the Definition of an AI Model

The RBI has significantly widened the scope of model classification. A system falls under the scope of this guidance if it takes inputs, applies processing logic, and produces outputs that materially affect business decisions, regardless of what the RE calls it.

Simple tools are not exempt. A basic spreadsheet-based pricing calculator or rules engine will face the same governance expectations as an advanced deep-learning model if its output materially impacts consumers, financial performance, or compliance.

Concurrently, model risk is defined as the potential for adverse outcomes—including financial loss, strategic missteps, operational disruptions, or consumer harm—stemming from decisions based on incorrect, biased, or fundamentally misused model outputs.

As AI becomes increasingly embedded across business processes, regulated entities may need to reassess whether business-owned tools, embedded analytical applications, rule engines and spreadsheet-based decision tools fall within the scope of the framework and ensure that they are appropriately classified, documented, validated and monitored. A comprehensive enterprise model inventory can also provide visibility across AI models and autonomous agents, strengthening governance  and helping manage the increasing complexity of AI deployments while eliminating the risk of unmonitored “shadow models.”

 Governance is an Enterprise-Wide Mandate

The RBI’s draft guidance proposes an enterprise-wide governance framework for Model Risk Management, with clearly defined responsibilities spanning the Board, senior management, business teams and independent validation functions. Regulated entities are expected to establish a Board-approved Model Risk Management Framework (MRMF) that defines governance structures, risk appetite and oversight across the entire model lifecycle.

The proposed framework reinforces that model risk should be managed as an enterprise risk rather than a specialist quantitative discipline. As AI becomes increasingly embedded across business processes, governance extends beyond model development and validation to encompass business ownership, technology, cybersecurity, compliance and audit.

The framework is anchored in the Three Lines of Defence model, establishing clear accountability across independent organisational functions:

  • First Line – Model Owners and Business Teams: Responsible for model development, implementation, day-to-day operation and ongoing performance monitoring.
  • Second Line – Independent Validation and Model Risk Management: Responsible for independent validation, model risk assessment, risk tiering and ensuring models remain fit for purpose.
  • Third Line – Internal Audit: Responsible for providing independent assurance on the effectiveness of the Model Risk Management Framework and compliance with approved policies.

The draft guidance also proposes an expanded oversight role for the Risk Management Committee of the Board (RMCB), particularly for high-risk, AI and third-party models. Boards are expected to define risk appetite, approve the Model Risk Management Framework and develop sufficient model literacy to challenge assumptions, understand model limitations and provide effective oversight. Senior management, in turn, is responsible for operationalising the framework by establishing governance processes, allocating resources and ensuring ongoing compliance across the organisation.

Model Risk-Based Tiering

Recognising that not all models present the same level of risk, the RBI’s draft guidance proposes that every regulated entity establish a structured, risk-based model tiering framework covering all models within its enterprise inventory. The assigned risk tier becomes the foundation for model governance, determining the intensity of validation, approval requirements, monitoring, documentation, reporting, risk controls and business continuity planning throughout the model lifecycle.

Accordingly, higher-risk models would be subject to the highest level of governance, including enhanced validation, continuous monitoring, robust business continuity planning and approval by the Risk Management Committee of the Board (RMCB). Lower-risk models may follow proportionate governance processes, including delegated approval mechanisms. The draft further proposes that model risk classifications be reviewed at least annually, or earlier where material changes or predefined trigger events occur.

The proposed tiering framework requires regulated entities to assess model risk across three broad dimensions:

  • Materiality: The significance of the model to critical business processes, its impact on financial and operational outcomes, and its potential implications for customers.
  • Complexity: The technical complexity of the model, including the use of advanced AI techniques, unstructured data and the challenges associated with explainability and effective oversight.
  • Regulatory and Supervisory Considerations: Circumstances where regulatory expectations or supervisory priorities warrant enhanced governance and oversight.

An important implication of the proposed framework anti-dilution principle: an institution cannot dilute a model’s business criticality simply because its underlying math or code is simple. A relatively simple rules engine or spreadsheet-based pricing model may require the same level of governance as an advanced AI model if it materially influences customer outcomes, financial performance or regulatory compliance. Conversely, a technically sophisticated model with limited business impact may not warrant the highest governance tier.

  • The draft guidance also strengthens expectations around model validation and ongoing oversight, recognising that model governance extends well beyond initial deployment.
  • Pre-Deployment and Post-Modification Validation: Independent validation by the Second Line of Defence is proposed before a model is deployed, following any material modification, and at predefined periodic intervals thereafter.
  • Continuous Performance Monitoring: Regulated entities are expected to implement ongoing monitoring using both backward-looking performance assessments and forward-looking indicators to evaluate model effectiveness throughout its lifecycle.
  • Proactive Risk Detection: Monitoring frameworks should incorporate benchmarking and AI-specific evaluations to identify model drift, deteriorating performance and emerging anomalies before they materially affect business outcomes.

As AI adoption accelerates, maintaining this level of continuous oversight across increasingly large model portfolios is likely to require greater automation of Model Risk Management processes. Institutions may therefore need to strengthen capabilities for real-time monitoring, model lifecycle management and automated validation to support effective governance at scale.

Enterprise Model Inventory and Documentation

The RBI’s draft guidance places the enterprise model inventory at the centre of Model Risk Management, serving as the institution’s single source of truth. Every regulated entity is required to maintain an accurate, comprehensive and up-to-date inventory of all models across the enterprise, including active models, models under development, inactive models and decommissioned models.

Core Inventory Requirements

  • No Record, No Deployment:  Models should not be developed, deployed or relied upon unless they are formally recorded in the enterprise model inventory.
  • Comprehensive Coverage: The ledger must capture all active, under-development, inactive, and decommissioned models.
  • Required Metadata: Each model record should include key information such as the model owner, developer, validator, approver, assigned risk tier, upstream and downstream data dependencies, validation status and significant audit observations.
  • Upstream/Downstream Visibility: The inventory should maintain visibility over upstream and downstream model dependencies to help assess the potential impact of changes across interconnected model ecosystems.
  • 10-Year Record Retention: Decommissioned models and their associated lifecycle documentation should be retained for at least ten years to support regulatory reviews, audit requirements and future investigations

Beyond supporting regulatory compliance, a comprehensive enterprise model inventory strengthens governance by improving visibility and accountability across the model lifecycle. It also helps institutions manage model sprawl as the number of AI models and analytical assets continues to grow.

Model Lifecycle Management

The draft guidance extends Model Risk Management across the entire model lifecycle, proposing governance requirements from model selection and development through to retirement and decommissioning. Rather than focusing solely on model validation before deployment, the framework sets out governance expectations for every stage of a model’s lifecycle, ensuring that changes, performance, approvals and operational risks remain subject to ongoing oversight.

Lifecycle StageKey Regulatory Expectations
Model Selection and Development Every model should have a clearly defined business rationale, documented objectives and scope, supported by structured development practices, robust data governance, and assessments of fairness, bias, ethical considerations and potential adverse outcomes.
Independent ValidationAll models, including third-party models, should undergo independent validation before deployment, after material changes, at predefined intervals and in response to trigger events. Validation should assess model inputs, assumptions, conceptual soundness, performance and fitness for purpose.
Model ApprovalRegulated entities should establish a clearly defined approval framework with documented decision-making and exception management processes.  High-risk models must be approved by the Risk Management Committee of the Board (RMCB). Any models approved via the “exception pathway” are automatically subjected to enhanced, high-frequency monitoring.
Deployment and Ongoing MonitoringModels should be deployed through coordinated business, technology and data governance processes and continuously monitored to identify model drift, performance deterioration and changing business suitability.
Change ManagementMaterial model changes should follow documented impact assessments, version control, approval workflows and mandatory revalidation before implementation.
Business Continuity and Decommissioning Business continuity plans should address model failures and performance degradation, supported by fallback mechanisms, controlled retirement processes and long-term retention of model documentation.

Third-Party Models: Accountability Cannot Be Outsourced

As financial institutions increasingly rely on external AI platforms, proprietary fraud engines, credit scoring solutions and Software-as-a-Service (SaaS) providers, the draft guidance reinforces a fundamental principle: outsourcing a model does not outsource accountability. Regulated entities remain responsible for the governance, performance and regulatory compliance of all third-party models.

Key expectations include:

  • Mandatory Independent Validation: Third-party models should undergo independent validation irrespective of vendor certifications, assurances or validation reports.
  • Pre-Onboarding Due Diligence: Institutions should assess the provider’s credibility, model methodology, underlying assumptions, limitations and training data before deployment.
  • Contractual Transparency: Vendor agreements should provide sufficient access to model documentation, assumptions and operating logic to support independent validation and ongoing oversight.
  • Managing Black-Box Models: Where sufficient transparency cannot be obtained, institutions should document the associated risks, implement appropriate mitigation measures and determine whether deployment remains appropriate.

AI and Machine Learning Models:  Additional Governance Expectations

Recognising that AI and machine learning models introduce risks beyond traditional statistical models, the draft guidance proposes additional governance measures proportionate to their business impact.

 Key expectations include:

  • Foundation and Frontier AI Governance: Document the intended use, operational boundaries and behaviour of foundation models and other advanced AI systems.
  • Pre-Deployment AI Risk Assessment: Assess and mitigate AI-specific risks before deployment.
  • Explainability: Establish transparency standards based on business criticality, particularly for customer-facing decisions such as credit underwriting and pricing.
  • Continuous AI Monitoring: Monitor for AI-specific risks including hallucinations, model overfitting, data drift and concept drift.
  • AI Concentration Risk: Assess dependencies on cloud providers, foundation models and external AI platforms, including provider-driven model updates.

Strengthening Deployment Controls & Cybersecurity

The RBI expands model risk governance beyond mathematical algorithms, directly encompassing the physical and digital environments in which the AI models operate.

Key expectations include:

  • Secure Interfaces: Protect APIs, internal interfaces and third-party integrations against unauthorised access and manipulation.
  • AI-Specific Cybersecurity Controls: Implement controls to detect and mitigate prompt injection attacks, adversarial inputs, insecure session persistence and anomalous usage patterns that may indicate attempted model manipulation or unauthorised access.

 Kill Switches and Human Oversight

To mitigate “automation bias”—the cognitive tendency for human operators to blindly defer to machine-generated outputs—the draft guidance proposes a strict human safeguard layer.

Key expectations include:

  • Human Oversight: Implement Human-in-the-Loop (HITL), Human-on-the-Loop or Human-in-Command controls supported by override, suspension and deactivation mechanisms.
  • Emergency Kill Switches: Maintain tested capabilities to suspend or deactivate AI models operating outside approved risk thresholds.
  • Consumer Safeguards: Customer-facing AI applications, including chatbots and generative voice systems, should:
  • Clearly disclose that users are interacting with an AI system and communicate its operational limitations.
  • Provide a seamless option for customers to escalate to a human representative at any stage of the interaction.
  • Maintain complete and immutable audit trails to support dispute resolution, regulatory review and a customer’s right to an explanation.

In Conclusion

The RBI’s draft guidance modernises traditional Model Risk Management (MRM) to address the governance challenges introduced by artificial intelligence.

If adopted in its current form, the guidance will require regulated entities to strengthen governance across the entire model lifecycle—from model development and validation to deployment, continuous monitoring, change management and retirement. It also reinforces enterprise-wide accountability through stronger governance structures, risk-based tiering, independent validation, comprehensive model inventories and enhanced oversight of third-party and AI-enabled models.

While the guidance remains under public consultation, it provides financial institutions with a clear indication of the RBI’s evolving supervisory expectations for AI governance. Institutions that begin assessing the maturity of their existing Model Risk Management frameworks, identifying governance gaps and strengthening oversight capabilities will be better positioned to support responsible AI adoption while maintaining regulatory compliance, operational resilience and customer trust.

Understanding RBI’s Draft Guidance on Regulatory Principles for Model Risk Management