Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →Reserve Bank of India Draft AI Governance Framework for Banking
Issued by
Reserve Bank of India
The Reserve Bank of India has released draft norms requiring banks and regulated financial institutions to establish board-approved model risk management frameworks governing AI and algorithmic decision-making. The framework applies to all RBI-regulated entities that use AI systems in credit, risk, compliance, or customer-facing functions. Core obligations include maintaining an inventory of decision-making algorithms, conducting independent model validation, and ensuring human oversight over AI-driven outcomes.
Applies To
Overview
The RBI draft framework establishes governance expectations for AI and machine learning models used across the Indian banking sector, covering the full model lifecycle from development through deployment and retirement. Regulated entities are required to obtain board-level approval for their model risk management frameworks, ensuring senior accountability for AI-related decisions. An independent validation function must assess models before deployment and on a periodic basis thereafter, separate from the teams responsible for model development. Institutions must maintain a comprehensive inventory of all algorithms involved in consequential decisions, including credit scoring, fraud detection, and customer segmentation. The framework adopts a three-lines-of-defense structure, assigning distinct responsibilities to business units, risk functions, and internal audit. As a draft instrument, the final effective date and associated penalty provisions remain subject to public consultation and RBI notification.
Key Requirements
- •Establish a board-approved model risk management framework covering all AI and algorithmic systems used in regulated activities.
- •Maintain a complete, up-to-date inventory of decision-making algorithms, including their purpose, data inputs, and risk classification.
- •Conduct independent model validation prior to deployment and at defined periodic intervals, performed by a function separate from model developers.
- •Implement human oversight mechanisms for all AI-driven decisions affecting customers, credit, or regulatory compliance.
- •Assign clear three-lines-of-defense accountability: first line owns model risk, second line provides oversight, internal audit provides independent assurance.
- •Apply tiered controls calibrated to model risk level, with heightened scrutiny for high-impact or opaque models.
What Your Organization Must Do
- →Audit all AI and algorithmic systems currently in use and classify each by risk tier based on consequence and opacity.
- →Present a board resolution adopting a formal model risk management framework before the consultation period closes.
- →Establish or designate an independent model validation unit with staffing, budget, and reporting lines separate from model development teams.
- →Build and maintain a live model inventory with fields capturing model purpose, data lineage, validation status, owner, and last review date.
- →Embed human review checkpoints into workflows where AI systems generate decisions on credit, fraud flags, or customer eligibility.
- →Update internal audit charters to include explicit coverage of AI model governance as a recurring audit domain.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Which RBI-regulated entities must comply with the AI governance framework for banking?
- The framework applies to all RBI-regulated entities using AI systems in credit, risk, compliance, or customer-facing functions, covering banks, NBFCs, and other supervised financial institutions operating in India. There is no explicit size exemption in the draft, meaning smaller regulated entities deploying algorithmic decision-making are also in scope.
- Does the RBI AI governance framework require board-level approval for model risk management policies?
- Yes, the draft expressly requires a board-approved model risk management framework, placing formal accountability at the highest governance level. Compliance teams should prepare board resolutions and policy documentation in advance of any final notification, since this approval is a foundational prerequisite for all downstream obligations.
- What is the independent model validation requirement under the RBI draft framework?
- Regulated entities must establish a validation function that is organizationally separate from model development teams, with independent staffing, budget, and reporting lines. This function must validate models before deployment and reassess them periodically, with heightened scrutiny required for high-impact or opaque models.
- What penalty provisions apply if a bank fails to comply with the RBI AI governance framework?
- The draft does not yet specify penalty provisions, as enforcement details remain subject to public consultation and a final RBI notification. Compliance officers should monitor the RBI website for the finalized instrument, since penalties will likely align with the RBI's existing supervisory enforcement powers under the Banking Regulation Act.
- How does the RBI AI governance framework compare to the EU AI Act for financial institutions?
- Both frameworks impose risk-tiered controls and require human oversight over consequential AI decisions, but the RBI draft is sector-specific to banking while the EU AI Act applies horizontally across industries. The RBI framework places distinct emphasis on a three-lines-of-defense model and board accountability, reflecting India's existing banking supervisory architecture rather than the EU's broader prohibited-use classification system.
- What must be included in the algorithm inventory required by the RBI draft AI framework?
- The inventory must capture each model's purpose, data inputs, risk classification, validation status, model owner, and last review date for all algorithms involved in consequential decisions such as credit scoring, fraud detection, and customer segmentation. The framework requires this inventory to be comprehensive and kept current throughout the model lifecycle.
