How to Track Compliance With RBI's New AI Governance Rules
Two RBI documents now define what AI governance means for regulated entities in India, and neither one is satisfied by a policy PDF sitting in a shared drive.
The draft Model Risk Management Framework, released 24 June 2026, applies to every Commercial, Small Finance, Payment, and Co-operative Bank, plus NBFCs, AIFIs, ARCs, and Credit Information Companies. It broadens the definition of "model" deliberately wide: AI/ML systems, scoring algorithms, rule engines, and even a spreadsheet, if it materially influences a lending rate or a customer's pricing.
The earlier FREE-AI Committee report (August 2025) sets the direction those rules point in: seven sutras, six pillars, and 26 recommendations built around one core idea. Accountability doesn't transfer. An entity deploying an AI system stays accountable for what it decides, regardless of how autonomous the system is, and outsourcing the model to a vendor doesn't outsource that accountability with it.
What "tracking" is required to prove
Put together, the two documents ask for four things that a policy document alone cannot demonstrate:
| Requirement | What it actually means | What a policy PDF can't show |
|---|---|---|
| Board-approved governance | A Model Risk Management Framework with a real owner, not just a signed cover page | Whether the framework is followed after the signature |
| Three Lines of Defense | Someone runs the model, someone independently validates it, someone audits both | Who actually did which line, and when |
| Explainability on live decisions | Loan approvals and fraud calls need a documented rationale a human can read | Whether that rationale exists for a specific decision, on a specific date |
| Vendor accountability | Outsourcing contracts must cover AI-specific risk, audit rights, and liability | Whether the vendor was actually screened against those terms |
Every row in that table is the same shape: a written commitment on one side, a dated, attributable record of it actually happening on the other. Regulators ask for the second one.
Where this breaks down in practice
Most Indian NBFCs and lenders we've spoken with have the first column. Almost none have a working system for the second, because it was never one team's job. Model owners sit in one function, vendor contracts get negotiated by procurement, and the audit trail, if it exists at all, is an email thread someone would have to reconstruct under time pressure.
That reconstruction problem is the actual risk. Not that the governance doesn't exist, but that nobody can produce it fast enough when a regulator or an internal audit actually asks.
What a real tracking system looks like
Four things need to be true at once, continuously, not assembled after the fact:
- Every model has a named owner and a governance trail. Not a policy that says models should have owners, an actual record of who owns this specific model and what decisions they've signed off on. This is what Decision Records are built for: every governance call logged against the evidence that justified it, permanently, the same audit-trail discipline India's Companies Act already requires for financial transactions.
- Model documentation is evidence, not a claim. "We validated this model" is a sentence. A dated validation report, linked to the model it validated, is evidence. See Evidence-Based Scoring for how that distinction gets enforced rather than just stated.
- Vendor risk is screened against the same dimensions you're held to, before onboarding. Not a generic vendor questionnaire. A structured check against the specific governance gaps RBI has flagged, so a new AI vendor doesn't quietly reopen a risk you already closed. Vendor AI Risk runs exactly this screen.
- A human stays accountable for every AI-proposed action, by name. RBI's guidance is explicit that autonomy doesn't dilute accountability. That means every AI-flagged risk or recommendation needs a person who reviewed it, not just a system log saying it happened. AI Command Center is where that human-in-the-loop review actually happens.
The part that's easy to miss
RBI's stakeholder consultation on the draft framework runs through 24 July 2026, but the direction of travel is already set by the FREE-AI report a year earlier: continuous assurance, not a point-in-time audit. A governance framework assessed once a year and left alone until the next audit cycle is already behind what regulators are asking for. The requirement is closer to: can you show, on any given day, that governance is currently operating, not that it operated once.
That's a different tool than a compliance checklist. It's a live, evidence-linked record of models, owners, vendors, and decisions that stays current because it's used every week, not opened once before an audit.
Was this article helpful?
Community Questions (0)
No questions yet. Be the first to ask!
Still have questions?
Contact support
