RBI — Draft Guidance on Regulatory Principles for Model Risk Management, 2026

Tag: S-2026-06-30-rbi-model-risk-management Type: report (regulator consultation draft, captured during the daily scan) Author(s): Reserve Bank of India (RBI) Date of source: 2026-06 (June 2026 draft; consultation open until 24 July 2026) Date ingested: 2026-07-01 Authority weight: medium — a primary regulator draft, but captured via a secondary newsletter summary; primary RBI draft not directly fetched. India is outside Paul’s core EU/UK jurisdictions, so recorded as a cross-jurisdictional convergence signal rather than a directly-applicable regime. Raw file: S-2026-06-30-rbi-model-risk-management.md. External source: riskinfo.ai Regulatory Updates Newsletter, 30 June 2026.

What it claims

The RBI released a draft “Guidance on Regulatory Principles for Model Risk Management, 2026” (consultation open until 24 July 2026) establishing a comprehensive governance framework for analytical models used by regulated financial institutions — banks, NBFCs, cooperative banks, financial institutions, ARCs and credit information companies — explicitly including AI and ML models, and covering both internally developed and third-party models.

The draft would require every regulated entity to establish a Board-approved Model Risk Management Framework governing the entire model lifecycle (development, validation, monitoring, modification, retirement). It introduces a risk-based classification of models, mandates independent validation before deployment, requires a comprehensive model inventory, and formalises governance through the three-lines-of-defence model.

For AI/ML systems it proposes additional safeguards: assessing explainability, bias, hallucinations, data drift, third-party dependencies and IP risks; conducting stress testing, adversarial testing and red-teaming; implementing robust human oversight, override / kill-switch mechanisms; and clearly informing customers when they are interacting with AI systems. Firms relying on third-party AI vendors remain fully accountable for model outcomes.

Notable quotes

“The draft requires every regulated entity to establish a Board-approved Model Risk Management Framework governing the entire model lifecycle, from development and validation to monitoring, modification and retirement.” — riskinfo.ai newsletter, 30 June 2026 (secondary)

“These include assessing explainability, bias, hallucinations, data drift, third-party dependencies and intellectual property risks. Financial institutions would be expected to conduct stress testing, adversarial testing and red-teaming of AI models, implement robust human oversight, maintain override and kill-switch mechanisms, and clearly inform customers whenever they are interacting with AI systems.” — riskinfo.ai newsletter, 30 June 2026 (secondary)

What’s speculative vs. asserted

  • Asserted by the secondary source: existence and title of the RBI draft; the 24 July 2026 consultation close; Board-approved MRM framework; risk-based classification; independent validation; model inventory; 3LoD; the AI/ML-specific safeguards listed.
  • Speculative / commentary: the newsletter’s reading that “AI governance is becoming a core prudential expectation”.
  • Not confirmed: exact scope thresholds and the precise text — ⚠️ pending primary retrieval from rbi.org.in.

Topics this feeds

Open questions raised

  • Does the RBI draft’s decision to bring AI/ML explicitly inside MRM (with red-teaming and kill-switches) diverge from the US SR 26-2 carve-out — i.e. is global practice splitting on whether GenAI/agentic sits inside or outside prescribed MRM?
  • What are the exact model-classification tiers and validation-independence requirements in the primary text?