We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

CERT-In empanelled · AI governance

AI governance for RBI-regulated entities

As banks, NBFCs and payment firms deploy AI and machine-learning models — for credit, fraud, collections and customer service — RBI’s emphasis on model risk management, data governance, explainability and accountability makes AI governance a board-level obligation. CyberSigma helps RBI-regulated entities build a defensible AI-governance programme: a model inventory and risk classification, data-governance and bias controls, human-oversight and explainability, third-party/GenAI vendor risk, and audit-ready evidence aligned to RBI expectations and the DPDP Act.

Get a free AI-governance snapshot →Book a 20-minute call
Who needs it

Who this is for

RBI-regulated entities — banks, NBFCs, payment aggregators and lenders — deploying AI/ML for credit decisioning, fraud, collections, KYC or customer service, and their model-risk, compliance and technology functions.

Scope

What an AI-governance programme covers

Model inventory & risk classification
A living register of every AI/ML model, its purpose, data and risk tier.
Data governance & bias
Training-data lineage, quality, fairness and bias controls.
Oversight & explainability
Human-in-the-loop, challenge, monitoring and model explainability.
Third-party & GenAI risk
Vendor and GenAI/API risk, data-leakage controls and contractual safeguards.
Regulation

What it aligns to

RBI’s model risk management and data-governance expectations for regulated entities, the DPDP Act 2023 for personal data used in models, and emerging AI-governance good practice — mapped to how you actually build and buy models.

Deliverables

What you receive

AI-governance framework
Policy, roles, model-lifecycle controls and a risk-classified model inventory.
Assessment & roadmap
Gap assessment of current models with a prioritised remediation plan.
Common gaps

Common gaps we find

  • No model inventory — nobody can list the models in production
  • Training-data lineage and bias controls undocumented
  • No human-oversight or challenge process for high-impact decisions
  • GenAI/third-party model data-leakage risk unaddressed
Proof

See how we’ve done it before

Relevant case study
How a lender built a risk-classified model inventory and oversight controls. Read case studies →
Redacted sample deliverable
Inspect a redacted AI-governance assessment first. Request a redacted sample →

Worried about a supplier becoming your breach?

Get a free third-party risk scoping call — share your work email and we frame your vendor tiers, gaps and next steps.

Verified facts

Drawn from the CyberSigma Compliance Registry (updated 11 August 2026). Every statement below is checked against the issuing body’s own publication, with the date it was last verified.

  • Payment system data storage in IndiaEffective 6 October 2018

    RBI circular DPSS.CO.OD No.2785/06.08.005/2017-2018 (6 April 2018) requires payment system providers to store the entire data relating to their payment systems only in India, with compliance within six months (by October 2018). End-to-end transaction data is covered.

    Circular number cited for retrieval via RBI's notification search; we deliberately avoid deep-linking RBI's session-bound URLs.

  • IT Governance Master DirectionEffective 1 April 2024

    Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/DoS/2023-24/107) issued 7 November 2023; effective 1 April 2024. Requires an IT governance framework, information/cyber security policies and periodic IT risk assurance for regulated entities.

    Direction number cited for retrieval via RBI notification search; RBI deep links are session-bound.

  • IT Outsourcing Master DirectionEffective 1 October 2023

    Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102) issued 10 April 2023; effective 1 October 2023. Governs material IT outsourcing by regulated entities, including vendor risk, audit rights and concentration risk.

    Direction number cited for retrieval via RBI notification search.

  • Digital Payment Security Controls Master DirectionEffective 18 February 2021

    Issued 18 February 2021: minimum security standards for digital payment channels — internet banking, mobile payments and card payments — binding scheduled commercial banks, small finance banks, payments banks and card-issuing NBFCs.

    Direction cited by title and date for retrieval via RBI notification search.

  • Cyber Security Framework in BanksEffective 2 June 2016

    RBI’s Cyber Security Framework in Banks (2 June 2016) requires scheduled commercial banks to report cyber incidents to RBI within 2 to 6 hours of detection, alongside board-approved cyber security policy, SOC capability and cyber crisis management plans.

Related in this cluster

AI governance for RBI entities — FAQs

Does RBI require AI governance?

RBI emphasises model risk management, data governance, explainability and accountability for regulated entities using models. AI governance operationalises those expectations, alongside the DPDP Act for personal data used in AI.

Where do we start?

With a model inventory and risk classification — you cannot govern models you have not listed. From there we prioritise controls for the highest-impact models.

Talk to an AI-governance specialist

We inventory and risk-classify your models and build a defensible governance programme aligned to RBI and DPDP. Reply within four business hours.

Book a 20-minute call →

Ready to discuss your AI governance for RBI-regulated entities requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.