Publications

Emerging Architecture of Accountability for AI in India’s Financial Sector: Examining RBI’s Draft Guidance on Model Risk Management

An article titled “Emerging Architecture of Accountability for AI in India’s Financial Sector: Examining RBI’s Draft Guidance on Model Risk Management” co-authored by Senior Partner, Vaibhav Kakkar, and Principal Associate, Gangesh Varma has been published by BW Legal.

Whether a bank uses a cutting-edge neural network or a twenty-year-old Excel spreadsheet to reject your loan, the outcome for you as the consumer is identical. The important regulatory question is whether the bank understands the system, can test its assumptions, can intervene when it fails and remains accountable for the resulting decision. Irrespective of the underlying technology being cutting-edge AI or a simple spreadsheet, the Reserve Bank of India (RBI) wants to ensure accountability. Towards this goal and adapting regulatory frameworks to rapid technological developments, the RBI’s draft Guidance on Regulatory Principles for Model Risk Management, 2026 (Draft Guidance) was released for public consultation last month. The Draft Guidance is expected to be finalised after considering stakeholder feedback and will eventually be incorporated into the RBI’s regulatory framework on credit risk management.

An Expansive Scope

The Draft Guidance applies to a wide range of Regulated Entities (REs) across commercial and co-operative banks, non-banking financial companies, payments banks, asset reconstruction companies and credit information companies. It covers models developed internally as well as those obtained from third parties, including systems employing artificial intelligence and machine learning. 

It deliberately adopts an expansive and technology-agnostic understanding of a “model.” Rather than relying on specific nomenclature like “agentic AI,” the definition focuses on the outcomes and material impact of the tools. It extends beyond sophisticated credit-scoring algorithms or generative AI to include algorithms, analytics, interfaces, applications, decision rules and other computational tools that materially affect decisions even when the institution itself does not describe them as models. Once its inputs and formulas determine lending rates or credit terms, it becomes a model requiring governance. This is an important regulatory choice. By focusing on material impact rather than technological novelty or complexity, the RBI avoids endless definitional disputes that frequently distract AI regulation.

Locating Accountability and Responsibility

REs remain accountable for every model it uses, regardless of whether the model was built internally, purchased from a vendor or incorporated into a third-party service. Outsourcing the technology does not outsource responsibility for its consequences.

This principle is translated into an extensive institutional architecture in the Draft Guidance. Regulated entities would need a board-approved Model Risk Management Framework, a model inventory, risk-based classification, independent validation, continuous monitoring, change-management procedures, business-continuity arrangements and formal decommissioning processes. High-risk models would receive board-level scrutiny. Models would be assessed both individually and at the enterprise level, including their interdependencies and aggregate risks.

Operationalizing AI Governance

In effect, the RBI is turning AI governance from an ethics statement into an operating system. Explainability, fairness and human control are not left as aspirations. They must be reflected in organisational responsibilities, technical testing, documentation, escalation mechanisms and audit trails.

The provisions relating specifically to AI are particularly wide-ranging. Institutions would have to address hallucinations, discriminatory outputs, overfitting, data and concept drift, spurious correlations and unexplained variability. They would be expected to test systems under abnormal and adversarial conditions, conduct red-teaming where appropriate, guard against prompt injection, disclose when customers are interacting with AI and provide mechanisms to override, suspend or deactivate models including kill-switches. The draft also recognises foundation and frontier models, provider-driven updates and concentration risks arising from dependence on a limited number of technology suppliers.

Missing Pieces in the Regulatory Jigsaw

The Draft Guidance marks an important, though still incomplete, step in recalibrating the regulatory framework to keep pace with technological change and growth in the sector. Its institutional risk-management architecture is detailed, while its consumer-protection provisions remain limited. The draft states that regulated institutions should not deploy models that cause harm to consumers and that grievance-redress mechanisms should extend to grievances arising from consumer-facing models. These principles form a small but valuable part, of further regulatory developments needed to build a more comprehensive framework for protecting individuals affected by automated financial decisions.

A borrower is not adequately protected merely because a bank’s board understands the model or because an independent validator has tested it. Explainability to a risk committee is not the same as an intelligible explanation to the person whose loan has been refused. Human oversight within the institution is not the same as an individual right to have an automated decision reconsidered by a competent human being. Separate laws and regulations ranging from RBI’s own regulations to India’s personal data protection laws may each address these concerns individually. Both REs and consumers will need to navigate this interplay to chalk out how responsibility should be divided where a problem simultaneously concerns data quality, privacy, model bias, validation and consumer harm – and what remedies will be available.

The final guidance may not be the place for prescriptive consumer grievance redressal. However, given the brief yet explicit reference in the draft, there should be more specific integration of explicit consumer rights regulations. Building on the RBI’s Framework for Responsible and Ethical Enablement of Artificial Intelligence Committee (FREE-AI Committee) Report from last year, greater transparency measures in consumer-facing AI needs to be operationalised. Where a model materially influences access to credit or another significant financial service, the affected person should be informed of that fact, given the principal reasons for the decision, permitted to correct inaccurate information and provided a meaningful route to contest the outcome before a human decision-maker. The framework should also clarify responsibility and compensation where model failures cause consumer harm. These protections can be calibrated according to the RBI’s own risk-tiering system rather than imposed indiscriminately on every model. Similar additions such as contestability, compensation and clearer liability have also been recommended in stakeholder comments on the draft.

The treatment of third-party models in the Draft Guidance also warrants close scrutiny. While the draft requires institutions to validate vendor models independently and obtain technical documentation and audit rights, smaller banks and NBFCs may lack leverage with large AI providers. Standardised assurance reports, regulatory access mechanisms and common audit documentation may therefore be necessary to ensure accountability workable.

The RBI is essentially building a sectoral AI-governance framework without adopting a standalone AI-specific rulebook. This reflects India’s approach to AI governance in practice, even as rhetoric in public intermittently swings towards dedicated omnibus AI laws. The RBI’s FREE-AI Committee Report articulated foundational principles, the draft guidance on data governance addresses the information layer, and the Draft Guidance on Model Risk strengthens oversight of the decision layer. As the regulatory framework takes shape, it should avoid becoming asymmetrical: institutional obligations should not become increasingly detailed while innovation support, public transparency, and the rights of individuals affected by automated decisions remain underdeveloped.

Published On:

  • August 13, 2026

Counsel Involved:

DISCLAIMER AND CONFIRMATION

Current rules of the Bar Council of India impose restrictions on maintaining a web page and do not permit lawyers to provide information concerning their areas of practice. Saraf and Partners is, therefore, constrained from providing any further information on this web page.

The rules of the Bar Council of India prohibit law firms from soliciting work or advertising in any manner. By clicking on ‘I AGREE’, the user acknowledges that The user wishes to gain more information about Saraf and Partners, its practice areas and its attorneys, for his/her own information and use;

The information is made available/provided to the user only on his/her specific request and any information obtained or material downloaded from this website is completely at the user’s volition and any transmission, receipt or use of this site is not intended to, and will not, create any lawyer-client relationship; and None of the information contained on the website is in the nature of a legal opinion or otherwise amounts to any legal advice.

Saraf and Partners, is not liable for any consequence of any action taken by the user relying on material/information provided under this website. In cases where the user has any legal issues, he/she in all cases must seek independent legal advice.

Please Read & Accept our website's Privacy Policy & Terms of Use.

Scroll to Top