RBI's AI Draft Rules Put Liability Squarely On Banks, NBFCs; Third-Party Models No Defence

The RBI proposed a liability-focused framework requiring banks and NBFCs to remain accountable for AI-driven decisions, third-party models and customer-facing algorithms

Update: 2026-06-25 06:21 GMT

RBI released draft Model Risk Management Guidelines proposing stricter accountability, human oversight and governance standards for AI and machine learning systems used by banks and NBFCs

The Reserve Bank of India (RBI) has proposed a sweeping model risk management framework that places ultimate accountability for artificial intelligence (AI), machine learning (ML) and automated decision-making systems squarely on banks, NBFCs and other regulated entities, regardless of whether the models are developed in-house or procured from third-party vendors.

In its draft Guidance on Regulatory Principles for Model Risk Management, 2026, released on Wednesday, the RBI has made it clear that financial institutions cannot escape responsibility for flawed decisions, customer harm or regulatory breaches by attributing failures to external technology providers or AI systems.

The proposed framework comes amid the rapidly growing use of AI-driven tools across lending, customer onboarding, risk management, fraud detection, customer service and cybersecurity functions. According to the central bank, weaknesses in governance, oversight and controls over such models can expose institutions to financial, operational, compliance and reputational risks.

Board-Approved Framework Mandatory

At the heart of the draft guidance is a principle of institutional accountability. The RBI has proposed that every regulated entity adopt a Board-approved Model Risk Management Framework (MRMF) covering the entire lifecycle of models, including their development, validation, deployment, monitoring, modification and eventual decommissioning.

The framework will apply to commercial banks, small finance banks, payment banks, co-operative banks, non-banking financial companies (NBFCs), all-India financial institutions, asset reconstruction companies (ARCs) and credit information companies.

Importantly, the RBI has adopted an expansive definition of a "model". The term covers not only sophisticated AI and machine learning systems but also algorithms, analytics tools, decision-based rules, applications and even spreadsheet-based tools where they materially influence business decisions such as credit approval, pricing or risk assessment.

One of the most significant features of the draft guidance is its treatment of third-party models. The RBI has proposed that regulated entities remain fully responsible for the outcomes generated by vendor-supplied systems, irrespective of certifications, assurances or validations provided by external service providers.

Banks and NBFCs would therefore be required to independently validate third-party models before deployment and continuously monitor their performance throughout their operational life. The draft also requires entities to conduct due diligence before acquiring such systems and identify risks arising from limited transparency in vendor-developed AI models.

Enhanced Scruitry for AI and Machine learning systems

Recognising the unique risks associated with AI and ML systems, the draft guidance proposes additional safeguards for such models.

Regulated entities will be required to assess risks arising from:

-AI hallucinations and inaccurate outputs.

-Bias and discriminatory outcomes.

-Data drift and model degradation.

-Manipulation attempts and adversarial attacks.

-Cybersecurity vulnerabilities.

Institutions must also test AI systems under stressed and abnormal scenarios to identify weaknesses that may not emerge during routine operations.

Human oversight and kill switches

One of the most significant proposals relates to human supervision of AI-driven decision-making.

The RBI has proposed mandatory human oversight mechanisms, including:

-Human-in-the-loop review systems.

-Override capabilities.

-Suspension and deactivation controls.

-Emergency "kill switch" mechanisms.

The central bank also warned against automation bias and over-reliance on machine-generated outputs, emphasising that final accountability must remain with regulated entities.

Customer-Facing AI Systems

The draft guidance imposes additional obligations on banks and NBFCs deploying AI-based customer interfaces, including generative AI applications.

Financial institutions will be required to clearly disclose when customers are interacting with AI systems, explain the limitations of such technologies and provide an option to switch to human assistance upon request.

The RBI has also proposed cybersecurity safeguards to protect customer-facing AI systems from prompt injection attacks, adversarial inputs and other emerging threats.

Model Inventory and Risk Classification

The draft framework further requires institutions to maintain a comprehensive inventory of all active, inactive and retired models. No model may be deployed unless it is formally recorded in the inventory.

Each model must be classified according to its risk profile, based on factors such as materiality, complexity and business impact. High-risk models will require approval from the Risk Management Committee of the Board before deployment.

The RBI has invited comments on the draft guidance until July 24, 2026, after which the framework may form the basis of a comprehensive regulatory regime governing AI and model risk management across India's financial sector.

Tags:    

Similar News