
Only 21% of Indian financial institutions are implementing AI, and the RBI's draft MRM guidance leaves key questions unanswered. The consultation closes July 24.
The Reserve Bank of India will close the public consultation window on July 24 for its draft guidance on model risk management. The framework, part of the central bank's Free-AI report, sets out how banks and other regulated entities should govern artificial intelligence. The question for financial institutions has shifted from whether to adopt AI governance to how to meet specific requirements with limited operational clarity.
RBI's own survey of about 600 regulated entities, covering 90% of the sector's asset base, found that only 21% of institutions are implementing or developing AI. Where AI is used, it is largely for low-stake applications such as customer-facing chatbots and internal process automation. Use in high-stake functions like credit decisions and fraud detection remains limited, the survey showed.
A gap between principle and practice is now the central challenge, according to a Mint article by two policy researchers. Industry executives have raised a series of practical questions that the draft guidance does not fully answer. Who owns an AI system once it goes live? Which committee approves its deployment? How should AI risk be incorporated into the enterprise risk management system? What constitutes an 'AI incident'? What documentation should be maintained for supervisory review?
The MRM framework requires every regulated entity to maintain a model inventory. No model can be used unless it appears in that inventory. It requires risk-based model-tiering so that governance intensity is calibrated to the potential impact of each system. It requires independent validation of all models, including those sourced from third-party vendors, regardless of assurances from vendors. It also requires specific controls for AI systems, covering explainability thresholds, hallucination mitigation, bias assessment and red-teaming to catch failures.
A financial institution that does not currently maintain a model inventory or classify its AI systems by risk is already behind the governance architecture outlined by the RBI's guidance document, the article noted. Such institutions also lack AI-specific provisions in their vendor contracts.
A second unresolved issue is the graded liability framework. The Free-AI report recommended a graded liability approach to allow entities to experiment with AI technologies in financial-sector use cases. Boards and product heads have no clear answer on what the exposure would be if a product goes live and something goes wrong even after good-faith compliance, the article noted. Financial innovation will be a downstream exercise that follows once the principle of graded liability is defined clearly, the authors wrote.
The RBI's final requirements, once published, will shape the technology spending trajectory of the sector. Institutions that begin building governance capability now will be in a significantly stronger position when the final rules arrive, the article said. The consultation period is the right time for institutions to assess gaps and work on closing them.
Work is underway to produce practical tools that operationalize the requirements, including a maturity assessment, model inventory template, risk-scoring instrument and a vendor governance checklist designed for governance, risk and compliance teams. The eventual framework should be grounded in a comparative analysis of global and Indian governance frameworks and tested with practitioners across banks, fintech, legal and policy firms and technology organizations, the article's authors wrote.
July 24 is the last day for public comments. No date has been set for the release of the final guidance.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.