We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Knowledge Center / RBI FREE-AI
Reserve Bank of India · India

RBI FREE-AI & AI Model Risk Management

RBI’s AI governance regime for banks, NBFCs and regulated entities — the FREE-AI framework (Aug 2025) plus the draft Model Risk Management guidance (2026).

RBI’s AI regulatory approach has two components. The FREE-AI Framework (released 13 August 2025) sets the strategic and ethical direction for AI adoption in financial services — seven guiding "Sutras" and 26 recommendations across six pillars (Infrastructure, Policy, Capacity, Governance, Protection, Assurance). The Draft Guidance on Regulatory Principles for Model Risk Management (2026) adds the detailed control layer: board-approved frameworks, model inventories, risk-based classification, independent validation, AI-specific controls and vendor accountability for every AI, machine-learning and decision-making model in a regulated entity.

Status: the 2026 Model Risk Management guidance is a DRAFT under public consultation (comments reportedly due 24 July 2026); final guidance follows consultation. FREE-AI is already released. The core expectations are clear enough to begin implementation now — institutions that wait for the final circular will be compressing 12 months of work into an implementation window.

Who is covered

Directly coveredIndirectly covered
Commercial & foreign banks; Small Finance, Payments & Local Area BanksFinTechs whose models are used by regulated entities
Regional Rural Banks; urban & rural cooperative banksLending Service Providers (LSPs)
NBFCs — Base, Middle, Upper and Top LayersCloud AI vendors and technology providers
All-India Financial Institutions; ARCs; Credit Information CompaniesThe regulated entity always remains accountable for model outcomes

Core requirements of the draft MRM guidance

PillarWhat RBI expects
Board-approved MRMFFramework covering all models (internal, third-party, AI/ML, GenAI, embedded); Board sets risk appetite, approves tiering; Risk Committee approves high-risk models
Model inventoryNo model used unless inventoried; owner/developer/validator/approver named; decommissioned models retained ≥10 years
Risk-based classificationTiering by financial/customer/regulatory impact, complexity, sensitive data, explainability, autonomy, third-party dependency; reviewed annually
Independent validationPre- and post-deployment, on change/drift/incident, periodic by tier; vendor certification alone is NOT sufficient; reports to Board Risk Committee within 3 months
AI-specific controlsExplainability thresholds (highest for credit, pricing, fraud, AML, collections); bias & proxy-discrimination testing; hallucination controls for GenAI; robustness vs drift and adversarial inputs
GenAI securityPrompt-injection, data-leakage, API-abuse and model-manipulation defences; structured red-teaming for customer-facing and generative models
Human oversightHuman-in-the-loop/on-the-loop/in-command, manual override, kill switch; oversight staff with authority to challenge and stop models
Customer protectionDisclose AI interaction, provide human assistance on request, appeal of AI-driven decisions, fair treatment, explanations for material decisions
Third-party AIDue diligence + contracts with documentation access, audit rights (entity AND RBI), incident notification, exit/continuity terms
Monitoring & changeContinuous monitoring (drift, bias, hallucinations, overrides); change control with rollback; stricter rules for self-updating models
Three lines of defenceOwners/developers → independent model-risk & validation → internal audit over the whole framework
Continuity & decommissioningFallbacks (manual, rule-based, backup models); formal decommissioning with audit-trail preservation

FREE-AI: the seven Sutras

Trust is the Foundation · People First · Innovation over Restraint · Fairness and Equity · Accountability · Understandable by Design · Safety, Resilience and Sustainability. The 26 recommendations under six pillars translate these into supervisory expectations for infrastructure, policy, capacity, governance, protection and assurance.

Minimum documentation pack

A defensible RBI AI compliance file includes ~25 artefacts: Board-approved AI & MRM policy, AI acceptable-use policy, model inventory, risk-classification methodology, use-case approval form, AI + data/privacy impact assessments, bias/fairness and explainability assessments, independent validation report, security & red-team report, third-party due-diligence and contract-control checklists, model/system cards, incident-response procedure, change register, human-oversight procedure, customer disclosure notice, grievance/appeal procedure, monitoring dashboard, drift report, business-continuity plan, decommissioning procedure, internal-audit checklist and the Board reporting pack.

How CyberSigma helps: RBI AI-readiness assessment (model discovery + gap analysis vs FREE-AI and the draft MRM guidance), Board policy drafting, independent model validation, GenAI red-teaming, vendor contract remediation and the full documentation pack — delivered by CERT-In empanelled senior auditors who sit in RBI examination rooms with clients.
Free 1-minute check
Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.
Try it free →

Need help with RBI FREE-AI?

CERT-In empanelled, PCI QSA senior auditors can take you from reading about it to compliant — with a scoped, guided programme.