The Reserve Bank of India (RBI) has proposed a new governance framework that would require lenders to keep tighter control over every AI model they deploy.
The framework comes as artificial intelligence (AI) becomes a bigger part of banking operations.
The draft rules aim to make AI systems more transparent, accountable and easier to monitor, thereby reducing the risks associated with automated decision-making across the financial sector.
Also Read: Nirmala Sitharaman Flags AI-Led Cybersecurity Risks in Banking
Board-level oversight and stronger AI accountability
The proposed framework requires every regulated entity to adopt a Board-approved Model Risk Management Framework (MRMF) covering all models, including Artificial Intelligence (AI) and Machine Learning (ML) systems. The rules will apply whether the models are developed in-house, purchased from third-party vendors or built using a combination of both.
Under the proposal, banks must maintain a complete inventory of AI models and continuously assess risks at both the individual model level and across the organisation. If an AI system is found to pose excessive risk, institutions must take corrective action, including restricting its use, strengthening controls or removing the model altogether. Such decisions must also be reported to the Board’s Risk Management Committee.
Also Read: RBI Tightens Digital Payment Security Norms, Signals Shift Beyond OTP-Authentication
No room for ‘black-box’ AI in banking
One of the biggest changes is the RBI’s push against opaque, or “black-box,” AI systems that cannot adequately explain how they arrive at decisions.
The regulator has proposed mandatory human oversight for AI models used in automated decision-making, ensuring that critical banking decisions are not left entirely to machines. Every model, including those supplied by external vendors, must undergo independent validation before deployment and regular reviews throughout its lifecycle.
The draft framework also proposes a “kill switch” capability that allows banks to immediately suspend or deactivate any AI model if it behaves unexpectedly or poses operational risks.
Also Read: RBI Just Made UPI Smarter — AI, IoT, and Credit Features Unveiled at GFF 2025
Extra safeguards for Generative AI
Recognising the growing use of Generative AI in customer service, the RBI has proposed additional cybersecurity safeguards for AI systems that directly interact with customers or external users.
Banks would also be expected to manage risks posed by third-party AI providers while ensuring that AI deployments do not introduce new security vulnerabilities into production systems. The regulator has invited public comments on the draft framework until 24 July 2026 before finalising the rules.
The Indian financial system is expanding the use of AI across lending, fraud detection, customer support and compliance. RBI’s proposal outlines a shift towards responsible AI governance, prioritising transparency, human oversight and operational resilience without slowing innovation.
The proposed framework could be India’s most significant AI governance measure for the banking sector. If adopted rightly, it will reshape how banks procure, deploy and monitor AI systems, while setting a stronger benchmark for responsible AI adoption across the country’s fintech ecosystem.

Samarjit Kaur is a journalist and communications professional covering technology & emerging digital trends. With a focus on clarity and context, she reports on developments shaping industries and governance. When not reporting, she chooses to plug-in and relax on her playlists and plan her next bucket-list trips!
