The Reserve Bank of India [“RBI”] has released the draft ‘Guidance on Regulatory Principles for Model Risk Management, 2026’ [“the Guidance”] that sets out a comprehensive model risk management framework that covers the application and adoption of models and their uses across Regulated Entities [“REs”] including commercial banks, co-operative banks, NBFCs, All-India Financial Institutions, Asset Reconstruction Companies and Credit Information Companies. The Guidance has been put out as a response to increased complexity in models used by REs, stemming from digitalisation of financial services, growth in analytical capabilities, increased adoption of artificial intelligence [“AI”] and machine learning [“ML”], and dependence on third-party model providers.
Acknowledging the increased use of models by REs to improve efficiency and decision-making, RBI has issued this model risk governance guidance to aid model risk management by REs. The draft is predicated on the fact that poorly controlled model risk could lead to erroneous outputs, poor decision-making, financial loss, operational disruption, regulatory non-compliance, and reputational damage and therefore requires enhanced governance, risk management, and continued scrutiny. It also notes that additional regulatory requirements pertaining specifically to AI models could be considered, as per paragraph I.10 of the Utkarsh 2029 and that this Guidance provides the foundational framework for model risk governance.
The Guidance, once finalised, will supersede Chapter 3 [Credit Risk Models] of the RBI’s ‘Guidance Note on Credit Risk Management’ , dated October 12, 2002, and thus the scope of applicability of model risk management would then also extend to models used by REs for other purposes as well. This note sets out a summary of the Guidance, and provides an analysis of the same.
APPLICABILITY AND SCOPE
The Guidance applies to all entities regulated by the RBI, including banks [including Regional Rural Banks], co-operative banks, NBFCs [across all regulatory categories], All India Financial Institutions, Asset Reconstruction Companies and Credit Information Companies [“Credit Information Companies”]. It is to be read in conjunction with the other applicable regulatory directions, and, in case of conflict, the specific directions shall prevail.
The Guidance applies to all models used by an RE, whether developed internally, procured from, or acquired through a hybrid arrangement with, a third-party provider. Thus, REs will be required to treat models procured or acquired from third-party providers as equivalent to internally developed models for all purposes, including risk governance, regulation, and supervision.
The Guidance adopts a very wide definition of ‘Model’ , encompassing any internally generated, third-party, or hybrid system that processes data and assumptions as inputs using statistical, mathematical, financial, economic, or AI/ML-driven models, or algorithms or applications to produce, as output, decisions or decision-support information for business or operational purposes. Thus, any algorithm or decision rules applied by an RE, including those in the form of spreadsheets used for calculations, that have a material influence on a business decision qualify as a model.
The Guidance also defines ‘Model Risk’ as a risk that an RE faces due to the possibility of errors in model design, flawed assumptions, incomplete data, misapplication or time-suitability issues. ‘Explainability’ of a model is broadly defined as the ability of a model to explain the factors influencing its outputs understandably.
ANALYSING ISSUES
A. Deliberately expansive, outcome-based definition of ‘Model’
The Guidance’s definition of ‘Model’, and illustrative example of a spreadsheet-based loan pricing calculator, make it abundantly clear that the RBI expects the Guidance to apply to a much wider set of tools that go beyond traditional quantitative/statistical models used in credit underwriting and market risk. Rule-based engines or algorithms and even spreadsheet-based tools that have a material input into a business decision could be covered by the Guidance. This will require REs to undertake a significant inventory exercise to identify ‘shadow models’ that have not been formally incorporated into the RE’s model governance framework.
B. Accountability cannot be transferred to vendors
A common refrain throughout the Guidance is that the RE’s responsibility for a model and its outcomes cannot be transferred to a vendor, even where a model is procured from a vendor. This is evident in requirements for independent RE validation of third-party models despite potential vendor validations, enhanced RMCB oversight of third-party models, and contractual requirements for audit rights and technical documentation. This has significant implications for REs, especially those that use fintech/vendors for scoring, fraud detection, and other decisioning, since confidentiality/IP clauses in vendor contracts may need to be revisited to permit model validation by the RE.
C. Elevated Board and RMCB involvement, particularly for high-risk and AI models
As reflected in specific requirements for the RMCB to approve “high” tier models, enhanced monitoring of all third party models irrespective of tier and additional oversight for AI/ML models, the Guidance requires increased Board and RMCB-level involvement in model risk governance. This will necessitate enhanced Board-level education on models, as well as potentially more dedicated resources for the RMCB for model reviews, including perhaps independent model risk advisors who can keep the RMCB abreast of model risk trends and developments.
D. Detailed, prescriptive AI/ML risk-management expectations
While the Guidance is largely principles-based, expectations for risk management around AI/ML are more detailed and prescriptive, covering explainability, hallucination, bias/fairness, robustness against adversarial inputs and model drift, as well as human oversight and kill-switch arrangements. These expectations are broadly aligned with emerging global trends [e.g. EU AI Act risk-based requirements and the US federal banking agencies’ SR 11-7 model risk management guidance , which have been extended to include AI/ML models], but provide certain safeguards, notably around explainability requirements for consumer-facing generative AI [e.g. customer access to human option] and defence against prompt injection
E. Documentation, inventory and retention as a control backbone
The Guidance’s requirement that decommissioned models be retained in inventory for a minimum of 10 years [or more as applicable] as well as retention of documentation for at least as long as the inventory, indicates that RBI expects a long look-back capability for model risk management which is critical for supervisory and regulatory review as well as model-related consumer protection [e.g. mis-selling or discriminatory credit practices that may emerge much later in a model’s life-cycle].
F. Broader scope beyond credit risk models
While the Guidance does not explicitly mention credit risk, its clear indication that the final Guidance will supercede only the credit risk model chapter of the 2002 Guidance Note, means that model risk management at REs will be evolving from a predominantly credit risk-centric regime to a truly enterprise-wide model risk governance framework covering pricing, fraud detection, AML/KYC, collections, service operations [including AI chatbots] and other areas besides credit.
LOOKING FORWARD
The draft marks a step forward in the RBI’s model risk management regulatory agenda. While the previous RM circular only covered credit risk models in a fairly limited way, the new draft adopts a comprehensive approach, addressing all model classes and all banks and NBFCs subject to RBI regulation.
At the same time, the principle-based nature of the draft allows REs to determine their internal approach based on their risk profile and organisational complexity. However, the detailed guidance on AI/ML, as well as mandatory escalation to the Board/RMCB, suggests that the RBI will raise overall model governance expectations, particularly for complex third-party and AI/ML models.




![Digital Personal Data Protection Toolkit [Part 2]: Data Processing Agreements](https://metaboard-assets.s3.ap-south-1.amazonaws.com/articles/article-1777306369699.webp)
