Build your future with us.

Enable continuous compliance with a unified, intelligent platform

Let's Discuss

RBI’s Draft Model Risk Management Guidance 2026: What Regulated Entities Need to Do Now

The Reserve Bank of India (RBI) has released the draft Guidance on Regulatory Principles for Model Risk Management, 2026, marking a significant shift in how regulated entities (REs) govern, validate, and monitor models used across their operations.

Unlike earlier guidance that primarily focused on credit risk models, the new draft introduces a comprehensive enterprise-wide framework covering all models including statistical models, business rule engines, algorithms, AI/ML models, Generative AI, and third-party models. It reflects RBI’s growing emphasis on responsible AI adoption, robust governance, and continuous model oversight. (Reuters)

Who Does This Apply To?

The guidance applies to a broad range of RBI-regulated entities, including:

  • Commercial Banks
  • Small Finance Banks
  • Payment Banks
  • Regional Rural Banks
  • Urban and Rural Cooperative Banks
  • NBFCs (Base, Middle, Upper and Top Layer)
  • All India Financial Institutions
  • Asset Reconstruction Companies
  • Credit Information Companies

What Has Changed?

The RBI now expects regulated entities to establish an enterprise-wide Model Risk Management Framework (MRMF) that governs the complete lifecycle of every model used within the organization.

The framework should include:

  • Board approved governance
  • Model inventory and documentation
  • Risk based model tiering
  • Independent model validation
  • Model approval and deployment
  • Continuous monitoring
  • Change management
  • Business continuity
  • Model decommissioning

AI and Machine Learning Under Greater Scrutiny

One of the most significant aspects of the draft guidance is its dedicated section on AI and Machine Learning.

For AI models, regulated entities are expected to implement additional controls including:

  • Explainability and transparency
  • Bias and fairness testing
  • Hallucination controls for Generative AI
  • Human oversight
  • Red teaming and adversarial testing
  • Cybersecurity controls
  • Customer disclosures when interacting with AI
  • Override and “kill switch” mechanisms
  • Continuous monitoring for model drift and performance degradation (The Economic Times)

Third-Party Models Are Not Exempt

The guidance makes it clear that outsourcing model development does not transfer accountability.

Regulated entities remain fully responsible for:

  • Independent validation of third-party models
  • Vendor due diligence
  • Technical documentation
  • Contractual audit rights
  • Ongoing monitoring and governance

Key Actions Required for Regulated Entities

To comply with the proposed guidance, organizations should begin preparing by:

  • Developing a Board-approved Model Risk Management Framework.
  • Creating a comprehensive inventory of all models, including AI and third-party models.
  • Classifying models based on risk and business criticality.
  • Establishing independent model validation processes.
  • Strengthening governance, documentation, and audit trails.
  • Implementing continuous monitoring and lifecycle management.
  • Introducing responsible AI controls for AI/ML deployments.

What Is the Timeline?

At present, this is draft guidance released for public consultation.

  • Public comments are invited until 24 July 2026.
  • The RBI will review stakeholder feedback before issuing the final guidance.
  • The implementation timeline has not yet been announced and is expected to be specified when the final guidance is issued. (Reuters)

Given the breadth of the requirements, regulated entities should not wait for the final circular. Building governance structures, model inventories, validation processes, and AI controls will require considerable planning and cross-functional collaboration.

How CyRAACS Can Help

CyRAACS helps regulated entities establish a robust Model Risk Management program aligned with RBI expectations through:

  • Model Risk Management Framework (MRMF) development
  • Model inventory creation and risk tiering
  • Independent model validation and assurance
  • AI governance and Responsible AI assessments
  • Third-party model and vendor risk assessments
  • Gap assessments against RBI guidance
  • Policy and procedure development
  • Internal audit and regulatory readiness assessments

In addition, CyRAACS offers Compliance Management Services (CMS) powered by the COMPASS platform. Through this managed service, our GRC experts continuously monitor compliance obligations, track remediation activities, manage evidence, and provide real-time dashboards and executive reporting. This enables regulated entities to maintain ongoing compliance with evolving RBI requirements while remaining audit-ready throughout the year.

Final Thoughts

The RBI’s draft guidance represents a significant evolution in regulatory expectations around model governance. It moves beyond traditional validation to emphasise enterprise-wide governance, continuous monitoring, independent oversight, and responsible AI.

Organizations that begin their readiness journey now will be better positioned to comply with the final framework while strengthening governance, improving model reliability, and building trust in AI-driven decision-making.

Let us help you

By clicking on this button, you can connect with us. Let’s make your brand secure.

you may also like