RBI — Draft Guidance on Regulatory Principles for Model Risk Management, 2026
Tag: S-2026-06-30-rbi-model-risk-management Type: report (regulator consultation draft, captured during the daily scan) Author(s): Reserve Bank of India (RBI) Date of source: 2026-06 (June 2026 draft; consultation open until 24 July 2026) Date ingested: 2026-07-01 Authority weight: medium — a primary regulator draft, but captured via a secondary newsletter summary; primary RBI draft not directly fetched. India is outside Paul’s core EU/UK jurisdictions, so recorded as a cross-jurisdictional convergence signal rather than a directly-applicable regime. Raw file: S-2026-06-30-rbi-model-risk-management.md. External source: riskinfo.ai Regulatory Updates Newsletter, 30 June 2026.
What it claims
The RBI released a draft “Guidance on Regulatory Principles for Model Risk Management, 2026” (consultation open until 24 July 2026) establishing a comprehensive governance framework for analytical models used by regulated financial institutions — banks, NBFCs, cooperative banks, financial institutions, ARCs and credit information companies — explicitly including AI and ML models, and covering both internally developed and third-party models.
The draft would require every regulated entity to establish a Board-approved Model Risk Management Framework governing the entire model lifecycle (development, validation, monitoring, modification, retirement). It introduces a risk-based classification of models, mandates independent validation before deployment, requires a comprehensive model inventory, and formalises governance through the three-lines-of-defence model.
For AI/ML systems it proposes additional safeguards: assessing explainability, bias, hallucinations, data drift, third-party dependencies and IP risks; conducting stress testing, adversarial testing and red-teaming; implementing robust human oversight, override / kill-switch mechanisms; and clearly informing customers when they are interacting with AI systems. Firms relying on third-party AI vendors remain fully accountable for model outcomes.
Notable quotes
“The draft requires every regulated entity to establish a Board-approved Model Risk Management Framework governing the entire model lifecycle, from development and validation to monitoring, modification and retirement.” — riskinfo.ai newsletter, 30 June 2026 (secondary)
“These include assessing explainability, bias, hallucinations, data drift, third-party dependencies and intellectual property risks. Financial institutions would be expected to conduct stress testing, adversarial testing and red-teaming of AI models, implement robust human oversight, maintain override and kill-switch mechanisms, and clearly inform customers whenever they are interacting with AI systems.” — riskinfo.ai newsletter, 30 June 2026 (secondary)
What’s speculative vs. asserted
- Asserted by the secondary source: existence and title of the RBI draft; the 24 July 2026 consultation close; Board-approved MRM framework; risk-based classification; independent validation; model inventory; 3LoD; the AI/ML-specific safeguards listed.
- Speculative / commentary: the newsletter’s reading that “AI governance is becoming a core prudential expectation”.
- Not confirmed: exact scope thresholds and the precise text — ⚠️ pending primary retrieval from rbi.org.in.
Topics this feeds
- Model Risk Management and Agentic AI — a third-jurisdiction data point that, unlike US SR 26-2, brings AI/ML explicitly INSIDE the prescribed MRM perimeter (with kill-switches, red-teaming, human oversight).
- Three Lines of Defence for AI — mandates 3LoD for model governance including AI/ML.
Open questions raised
- Does the RBI draft’s decision to bring AI/ML explicitly inside MRM (with red-teaming and kill-switches) diverge from the US SR 26-2 carve-out — i.e. is global practice splitting on whether GenAI/agentic sits inside or outside prescribed MRM?
- What are the exact model-classification tiers and validation-independence requirements in the primary text?