On 24 June 2026 the Reserve Bank of India released a draft "Guidance on Regulatory Principles for Model Risk Management, 2026" and invited comments until 24 July 2026. It covers all models used by regulated entities, including third-party models and models employing AI/ML, and requires a Board-approved model risk management framework, risk-based model tiering, a complete model inventory, independent validation and ongoing monitoring. Chapter V adds specific principles for AI/ML models: explainability thresholds, controls against hallucination, bias and fairness assessment, red-teaming, human oversight with override and kill-switch arrangements, and disclosure to customers that they are dealing with AI. It is a draft: the instrument number and date are placeholders, and no final version had been published on rbi.org.in as of 5 October 2026. On finalisation it would supersede Chapter 3 of the 2002 Guidance Note on Credit Risk Management.
OFFICIAL TEXT: rbi.org.in ↗ · PROPOSED · COMMENT PERIOD CLOSED · RBI
| Document | RBI draft Guidance on Regulatory Principles for Model Risk Management — Guidance on Regulatory Principles for Model Risk Management, 2026 (draft released for public comments) |
| Issued by | Reserve Bank of India — India's central bank and regulator of banks, non-banking financial companies and other regulated entities (REs) |
| Type | Consultation |
| Status | Proposed · comment period closed |
| Published | Jun 24, 2026 |
| Comment deadline | Jul 24, 2026 |
| Applies to | If finalised: commercial banks (including foreign banks), small finance banks, payments banks, local area banks, regional rural banks, urban and rural co-operative banks, NBFCs in the Base, Middle, Upper and Top layers, all-India financial institutions, asset reconstruction companies and credit information companies. It applies to all models, internally developed, third-party or both, including models employing AI/ML. |
| Official source | rbi.org.in ↗ |
| Use cases | Model risk management · Credit scoring & underwriting · Generative & agentic AI · Third-party & vendor AI · AI governance (general) · Customer-facing chatbots · Fair lending & discrimination |
What are the key points of RBI draft Guidance on Regulatory Principles for Model Risk Management?
- Scope (paragraphs 4 and 6): applies to the listed regulated entities and to all models, whether developed internally, sourced from third parties or both; the draft defines a model to include algorithms and decision-based rules that materially affect decisions even if the RE does not call them models, with a spreadsheet loan-pricing calculator as an illustration.
- Accountability and governance (paragraphs 8 to 13): the RE is accountable for outcomes of all models; a Board-approved Model Risk Management Framework (MRMF) applies to all models including AI/ML; the Risk Management Committee of the Board (RMCB) reviews validation reports of high-risk models and approves their deployment.
- Tiering and inventory (paragraphs 17 to 24): risk-based tiering reviewed at least annually, using materiality and complexity without one factor diluting another; a complete inventory with no model used unless inventoried; decommissioned models kept in the inventory for at least ten years.
- Consumer protection (paragraph 25): an RE should not use any model that harms consumers, and grievance redressal must cover grievances from consumer-facing models.
- Validation (paragraphs 29 to 33): independent validation of all models, including third-party models, before and after deployment, after modification and periodically; reports go to the RMCB within three months of completion.
- Third-party models (paragraphs 45 to 48): the RE is accountable; independent validation notwithstanding provider certification; enhanced RMCB oversight irrespective of tier; contracts must give access to technical documentation, audit rights for the RE and the supervisor, and exit arrangements.
- AI/ML models (paragraphs 49 to 57): additional controls commensurate with impact, including for foundation and frontier AI models; explainability and transparency thresholds; control boundaries against hallucination; fairness assessment; out-of-sample testing; red-teaming; enhanced controls for automatic updates; enhanced documentation.
- Deployment and human oversight (paragraphs 58 to 63): cyber controls against prompt injection and adversarial inputs for customer-facing models, disclosure that users are interacting with an AI/ML system and an option to switch to human assistance, human-in-command arrangements, override, suspension or kill-switch mechanisms, and periodic human review of outputs.
What did RBI draft Guidance on Regulatory Principles for Model Risk Management change for banks?
The draft turns the RBI's 2024 credit-model proposals into a whole-institution model risk standard and, following the FREE-AI report, writes AI/ML-specific principles into it. For banks, if finalised as drafted, it would introduce AI-specific explainability thresholds, red-teaming, kill switches and AI disclosure to customers.
What would the RBI's draft Guidance on Regulatory Principles for Model Risk Management require of banks?
If finalised as drafted, the RBI's Guidance would require each regulated entity to put in place a Board-approved model risk management framework for all models, including AI/ML and third-party models, tier models by materiality and complexity and review the tiers at least annually, keep a complete model inventory, and subject every model to independent validation before and after deployment, with high-risk models approved by the Risk Management Committee of the Board. For AI/ML models it adds explainability thresholds, hallucination and bias controls, red-teaming, enhanced controls for automatically updating models, customer disclosure that they are dealing with AI with an option to reach a human, and human-in-command arrangements including override and kill-switch mechanisms. It is a draft released on 24 June 2026, comments closed on 24 July 2026, and it is not yet in force.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Paragraphs 8 to 10 — Accountability and Board-approved MRMF | RBI | The RE is accountable for outcomes of all models and must have a Board-approved model risk management framework covering the whole lifecycle for all models, including AI/ML. | Draft; not yet in force |
| Paragraphs 17 to 20 — Risk-based tiering | RBI | Classify all inventoried models by materiality and complexity, review tiers at least annually, and use the tier to drive validation, approval, monitoring and continuity planning. | Draft; not yet in force |
| Paragraphs 21 to 24 — Inventory and documentation | RBI | Keep a complete inventory of active, inactive and decommissioned models, use no model that is not inventoried, and keep decommissioned models in the inventory for at least ten years. | Draft; not yet in force |
| Paragraphs 29 to 33 — Independent validation | RBI | Independently validate all models, including third-party models, before and after deployment, after modification and periodically; place validation reports before the RMCB within three months of completion. | Draft; not yet in force |
| Paragraphs 45 to 48 — Third-party models | RBI | Remain accountable for third-party models, validate them independently despite provider assurance, give enhanced RMCB oversight, and secure documentation access, audit rights and exit arrangements by contract. | Draft; not yet in force |
| Paragraphs 49 to 57 — AI/ML model risk | RBI | Apply additional controls to AI/ML models: explainability and transparency thresholds, hallucination control boundaries, fairness assessment, out-of-sample testing, red-teaming, enhanced controls for automatic updates and enhanced documentation. | Draft; not yet in force |
| Paragraph 59 — Customer-facing AI | RBI | For models that interface with customers: controls against prompt injection and adversarial inputs, disclosure that the user is interacting with an AI/ML system and its limitations, and an option to switch to human assistance. | Draft; not yet in force |
| Paragraphs 60 to 63 — Human oversight | RBI | Establish human-in-command arrangements, override, suspension or kill-switch mechanisms and periodic human review of AI-driven decisions, with oversight staff able to challenge and escalate. | Draft; not yet in force |
The draft says the final Guidance, following public consultation, would supersede Chapter 3 on Credit Risk Models of the Guidance Note on Credit Risk Management of 12 October 2002, and that it is to be read with other RBI Directions, which prevail in case of inconsistency (paragraph 5). It also notes, citing paragraph I.10 of Utkarsh 2029, that further requirements applicable to AI models may be issued later.
It builds on the RBI's draft circular "Regulatory Principles for Management of Model Risks in Credit" of 5 August 2024 and on the FREE-AI Committee report of 13 August 2025. Separately, the Reserve Bank (Commercial Banks - Asset Classification, Provisioning and Income Recognition) Directions, 2026 dated 27 April 2026 include Chapter V on principles for model risk management under expected credit loss, in force from 1 April 2027.
WHAT THIS MEANS IN PRACTICE
- Compare the existing model inventory and tiering against paragraphs 17 to 24, including spreadsheet-based tools that meet the draft's definition of a model.
- Map AI/ML and third-party models to the Chapter V principles and identify where explainability thresholds, red-teaming and kill-switch arrangements are missing.
- Review vendor contracts for documentation access, audit rights for the bank and supervisor, and exit arrangements.
- Plan Board and RMCB reporting on high-risk model validations and exceptions.
- Watch for the final text and any changes after the consultation that closed on 24 July 2026 before committing build effort.
What is the RBI's draft Guidance on Regulatory Principles for Model Risk Management?
A draft released on 24 June 2026 that sets broad regulatory expectations for model risk management across the model lifecycle, applicable to all models of regulated entities including third-party and AI/ML models. Comments were invited until 24 July 2026, and the draft says the final guidance would supersede Chapter 3 on Credit Risk Models of the Guidance Note on Credit Risk Management of 12 October 2002.
Is the RBI model risk management guidance in force?
No. It is a draft; the instrument number and date are placeholders and the RBI had not published a final version as of 5 October 2026. The RBI's ECL Directions for commercial banks, in force from 1 April 2027, separately contain a chapter on model risk management under ECL.
Does the RBI draft cover AI and generative AI models?
Yes. The definition of a model includes AI/ML, and Chapter V sets principles for AI/ML models, covering foundation and frontier AI models, hallucination controls for generative AI, bias and fairness assessment, red-teaming and human oversight including override and kill-switch mechanisms.
How does the RBI draft compare with SR 26-2 and PRA SS1/23?
Like SR 26-2 and SS1/23 it is principles-based model risk guidance built on governance, tiering, validation and monitoring. Unlike the US and UK texts it names AI/ML explicitly, with a dedicated chapter, and it applies to NBFCs, co-operative banks and credit information companies as well as commercial banks.
| Date | Document | Status |
|---|---|---|
| Aug 13, 2025 | RBI FREE-AI framework — Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) Committee Report | Final |
| Aug 5, 2024 | RBI draft circular on Regulatory Principles for Management of Model Risks in Credit — Regulatory Principles for Management of Model Risks in Credit (draft circular for comments) | Proposed |
| Jul 24, 2026 | Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) | In force |
| Jun 10, 2026 | FSB AI sound practices consultation (June 2026) — Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report | Proposed |
| Jun 5, 2026 | 2026 BoE/FCA AI survey — The Bank of England and FCA's 2026 AI Survey | Final |
| Jun 4, 2026 | Hill House oversight testimony (Jun 2026) — Statement of Chairman Travis Hill: Oversight of Prudential Regulators | Final |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning