RBI’s AI regulatory approach has two components. The FREE-AI Framework (released 13 August 2025) sets the strategic and ethical direction for AI adoption in financial services — seven guiding "Sutras" and 26 recommendations across six pillars (Infrastructure, Policy, Capacity, Governance, Protection, Assurance). The Draft Guidance on Regulatory Principles for Model Risk Management (2026) adds the detailed control layer: board-approved frameworks, model inventories, risk-based classification, independent validation, AI-specific controls and vendor accountability for every AI, machine-learning and decision-making model in a regulated entity.
Who is covered
| Directly covered | Indirectly covered |
|---|---|
| Commercial & foreign banks; Small Finance, Payments & Local Area Banks | FinTechs whose models are used by regulated entities |
| Regional Rural Banks; urban & rural cooperative banks | Lending Service Providers (LSPs) |
| NBFCs — Base, Middle, Upper and Top Layers | Cloud AI vendors and technology providers |
| All-India Financial Institutions; ARCs; Credit Information Companies | The regulated entity always remains accountable for model outcomes |
Core requirements of the draft MRM guidance
| Pillar | What RBI expects |
|---|---|
| Board-approved MRMF | Framework covering all models (internal, third-party, AI/ML, GenAI, embedded); Board sets risk appetite, approves tiering; Risk Committee approves high-risk models |
| Model inventory | No model used unless inventoried; owner/developer/validator/approver named; decommissioned models retained ≥10 years |
| Risk-based classification | Tiering by financial/customer/regulatory impact, complexity, sensitive data, explainability, autonomy, third-party dependency; reviewed annually |
| Independent validation | Pre- and post-deployment, on change/drift/incident, periodic by tier; vendor certification alone is NOT sufficient; reports to Board Risk Committee within 3 months |
| AI-specific controls | Explainability thresholds (highest for credit, pricing, fraud, AML, collections); bias & proxy-discrimination testing; hallucination controls for GenAI; robustness vs drift and adversarial inputs |
| GenAI security | Prompt-injection, data-leakage, API-abuse and model-manipulation defences; structured red-teaming for customer-facing and generative models |
| Human oversight | Human-in-the-loop/on-the-loop/in-command, manual override, kill switch; oversight staff with authority to challenge and stop models |
| Customer protection | Disclose AI interaction, provide human assistance on request, appeal of AI-driven decisions, fair treatment, explanations for material decisions |
| Third-party AI | Due diligence + contracts with documentation access, audit rights (entity AND RBI), incident notification, exit/continuity terms |
| Monitoring & change | Continuous monitoring (drift, bias, hallucinations, overrides); change control with rollback; stricter rules for self-updating models |
| Three lines of defence | Owners/developers → independent model-risk & validation → internal audit over the whole framework |
| Continuity & decommissioning | Fallbacks (manual, rule-based, backup models); formal decommissioning with audit-trail preservation |
FREE-AI: the seven Sutras
Trust is the Foundation · People First · Innovation over Restraint · Fairness and Equity · Accountability · Understandable by Design · Safety, Resilience and Sustainability. The 26 recommendations under six pillars translate these into supervisory expectations for infrastructure, policy, capacity, governance, protection and assurance.
Minimum documentation pack
A defensible RBI AI compliance file includes ~25 artefacts: Board-approved AI & MRM policy, AI acceptable-use policy, model inventory, risk-classification methodology, use-case approval form, AI + data/privacy impact assessments, bias/fairness and explainability assessments, independent validation report, security & red-team report, third-party due-diligence and contract-control checklists, model/system cards, incident-response procedure, change register, human-oversight procedure, customer disclosure notice, grievance/appeal procedure, monitoring dashboard, drift report, business-continuity plan, decommissioning procedure, internal-audit checklist and the Board reporting pack.
Need help with RBI FREE-AI?
CERT-In empanelled, PCI QSA senior auditors can take you from reading about it to compliant — with a scoped, guided programme.
