RBI Drafts AI Model Risk Governance Guidance
India's Reserve Bank published draft model-risk guidance on June 24 that would require covered financial institutions to apply a board-approved framework to every model, including AI, machine-learning and third-party systems. Comments are due July 24; the proposal adds independent validation, model inventories, human override and kill-switch controls, and safeguards for customer-facing generative AI.
The Reserve Bank of India released draft Guidance on Regulatory Principles for Model Risk Management on June 24, 2026, proposing a common governance framework for every model used by a covered regulated entity. The consultation remains open until July 24, so these are proposed expectations rather than final rules.
What RBI is proposing
The draft says each regulated entity should maintain a board-approved Model Risk Management Framework covering internally developed, third-party, AI and machine-learning models. That framework would define ownership, risk tiers, validation, approval, monitoring, change management, continuity and decommissioning. It would also require an up-to-date inventory of active, inactive and retired models; no model should be used unless it appears in that inventory.
All models, including vendor-supplied systems, would be independently validated by the institution before and after deployment, after material changes, when internal or external triggers arise, and at intervals set by the framework. High-risk models would receive board risk-committee oversight, while institutions would remain accountable for third-party model outcomes and would need sufficient vendor documentation and audit rights.
AI systems get additional controls
For AI and machine-learning models, the RBI draft adds controls tied to autonomy, customer impact and operational risk. Institutions would need to test behavior under stressed and adversarial conditions, manage hallucination, bias, drift and unexplained output variability, and apply stronger safeguards when a provider does not disclose enough information for effective oversight. Customer-facing generative AI would require protection against prompt injection and adversarial inputs, clear disclosure that users are interacting with AI, and an option to switch to human assistance.
The proposal also calls for human-in-command arrangements for automated decisions, including the ability to override, suspend or deactivate a model. Those kill-switch provisions sit alongside periodic human review, not in place of validation and ongoing monitoring.
What practitioners should prepare
The immediate engineering implication is inventory and evidence. Model owners would need traceable versions, documented dependencies, validation results, monitoring signals, incident records and defensible approval paths. Procurement teams would also need contracts that preserve technical access, audit rights and exit arrangements for externally supplied models.
The RBI has invited comments through July 24. The draft says the eventual final guidance would replace the 2002 credit-risk-model chapter, but it does not set a final implementation timetable in the text reviewed here.
Key Points
- 1RBI's June 24 draft would extend a board-approved model-risk framework to all models, including AI, machine-learning and third-party systems.
- 2The proposal calls for independent validation, complete model inventories, adversarial testing, customer disclosures and human override or kill-switch controls.
- 3Comments are due July 24; the document is still a consultation draft and does not establish a final implementation timetable.
Scoring Rationale
A central-bank consultation that would impose lifecycle controls across conventional, third-party and AI models has direct consequences for model-risk, MLOps, security and procurement teams. Its impact is high for Indian financial institutions, while the draft status and absence of a final implementation timetable limit the score.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

