KlaritiQKlaritiQ
Features

How to Track Compliance With RBI's New AI Governance Rules

KlaritiQ Team·August 2026·7 min read

Two RBI documents now define what AI governance means for regulated entities in India, and neither one is satisfied by a policy PDF sitting in a shared drive.

The draft Model Risk Management Framework, released 24 June 2026, applies to every Commercial, Small Finance, Payment, and Co-operative Bank, plus NBFCs, AIFIs, ARCs, and Credit Information Companies. It broadens the definition of "model" deliberately wide: AI/ML systems, scoring algorithms, rule engines, and even a spreadsheet, if it materially influences a lending rate or a customer's pricing.

The earlier FREE-AI Committee report (August 2025) sets the direction those rules point in: seven sutras, six pillars, and 26 recommendations built around one core idea. Accountability doesn't transfer. An entity deploying an AI system stays accountable for what it decides, regardless of how autonomous the system is, and outsourcing the model to a vendor doesn't outsource that accountability with it.

What "tracking" is required to prove

Put together, the two documents ask for four things that a policy document alone cannot demonstrate:

RequirementWhat it actually meansWhat a policy PDF can't show
Board-approved governanceA Model Risk Management Framework with a real owner, not just a signed cover pageWhether the framework is followed after the signature
Three Lines of DefenseSomeone runs the model, someone independently validates it, someone audits bothWho actually did which line, and when
Explainability on live decisionsLoan approvals and fraud calls need a documented rationale a human can readWhether that rationale exists for a specific decision, on a specific date
Vendor accountabilityOutsourcing contracts must cover AI-specific risk, audit rights, and liabilityWhether the vendor was actually screened against those terms

Every row in that table is the same shape: a written commitment on one side, a dated, attributable record of it actually happening on the other. Regulators ask for the second one.

Where this breaks down in practice

Most Indian NBFCs and lenders we've spoken with have the first column. Almost none have a working system for the second, because it was never one team's job. Model owners sit in one function, vendor contracts get negotiated by procurement, and the audit trail, if it exists at all, is an email thread someone would have to reconstruct under time pressure.

That reconstruction problem is the actual risk. Not that the governance doesn't exist, but that nobody can produce it fast enough when a regulator or an internal audit actually asks.

What a real tracking system looks like

Four things need to be true at once, continuously, not assembled after the fact:

  1. Every model has a named owner and a governance trail. Not a policy that says models should have owners, an actual record of who owns this specific model and what decisions they've signed off on. This is what Decision Records are built for: every governance call logged against the evidence that justified it, permanently, the same audit-trail discipline India's Companies Act already requires for financial transactions.
  2. Model documentation is evidence, not a claim. "We validated this model" is a sentence. A dated validation report, linked to the model it validated, is evidence. See Evidence-Based Scoring for how that distinction gets enforced rather than just stated.
  3. Vendor risk is screened against the same dimensions you're held to, before onboarding. Not a generic vendor questionnaire. A structured check against the specific governance gaps RBI has flagged, so a new AI vendor doesn't quietly reopen a risk you already closed. Vendor AI Risk runs exactly this screen.
  4. A human stays accountable for every AI-proposed action, by name. RBI's guidance is explicit that autonomy doesn't dilute accountability. That means every AI-flagged risk or recommendation needs a person who reviewed it, not just a system log saying it happened. AI Command Center is where that human-in-the-loop review actually happens.

The part that's easy to miss

RBI's stakeholder consultation on the draft framework runs through 24 July 2026, but the direction of travel is already set by the FREE-AI report a year earlier: continuous assurance, not a point-in-time audit. A governance framework assessed once a year and left alone until the next audit cycle is already behind what regulators are asking for. The requirement is closer to: can you show, on any given day, that governance is currently operating, not that it operated once.

That's a different tool than a compliance checklist. It's a live, evidence-linked record of models, owners, vendors, and decisions that stays current because it's used every week, not opened once before an audit.

See where your own organization's evidence gaps actually are.See what you can't prove yet

Was this article helpful?

Community Questions (0)

No questions yet. Be the first to ask!

Still have questions?

Contact support