RBI Introduces Comprehensive Model Risk Management Framework to Transform India’s Financial Sector, ETCISO
The Reserve Bank of India’s consultative paper on Model Risk Management, released in June 2026, is an important moment for the Indian financial sector. It signals that model risk is no longer being seen as a narrow credit risk issue, but as a broader governance question that cuts across business, risk, technology and customer outcomes. That makes the paper both significant and timely.
Its direction is clearly positive. It moves India closer to global thinking on model risk, including frameworks such as PRA SS 1/23 and the principles associated with SR 11-7 and SR 26-2. At the same time, the draft does leave a few areas open to interpretation. If these are not clarified, banks and other regulated entities may implement the same principle in very different ways.
From Credit Model Controls to Responsible AI Architecture
RBI’s earlier approach to model risk was sound, but it was relatively narrow. It focused mainly on credit risk models used for areas such as borrower selection, pricing and credit loss estimation. It expected board-approved policies, model inventories, independent validation, documentation, monitoring and oversight through the Risk Management Committee of the Board. These were important safeguards, but model risk was still largely viewed through a credit lens.
The new draft should also be read alongside RBI’s FREE-AI framework, which sets expectations for fair, transparent, accountable, explainable, safe, inclusive and contestable AI adoption. In that sense, the MRM paper provides the operating architecture. It translates responsible AI principles into the practical disciplines of governance, inventory, validation, monitoring, accountability and third-party oversight.
The New Paradigm: Enterprise-Wide Model Risk Management
The biggest change is scope. A model is no longer only a credit risk tool. It may include statistical techniques, AI and machine learning models, rules engines and even spreadsheet-based tools if they materially influence business, risk or operational decisions. This is the right direction, but it is also where the draft needs greater precision. At present, the definition appears to bring together models, applications, interfaces and decision rules. Unless the boundary is clearer, institutions may find it difficult to decide what should enter the model inventory and what should go through validation. The draft also raises the bar on accountability. It expects stronger board ownership, clearer risk appetite, defined roles for model owners, developers, validators and approvers, and a more formal use of the three lines of defence. The message is simple: models are enterprise assets, and they need to be governed with the same care as other important risk-taking or risk-management capabilities.
Materiality is another area where the final guidance could be clearer. The draft rightly asks institutions to classify models based on materiality, complexity and impact. However, it does not yet explain what makes a “decision” material. A practical way forward would be to focus on decision criticality. If a model directly determines, or materially influences, a significant customer outcome, prudential position, regulatory report or financial decision, it should be treated as material even if the model itself is not technically complex.
The AI-related expectations are among the most important parts of the paper. The draft refers to explainability, compensating controls, stress and edge-case testing, bias and fairness, human oversight, intervention mechanisms, and risks such as hallucinations or stochastic outputs. This is a useful move from technology-neutral regulation to AI-aware regulation. Even so, some terms need sharper treatment. Foundation models and frontier models are mentioned but not defined. Explainability thresholds appear to be left to institutions without clear reference points. Red teaming is required, but the paper does not say enough about scope, frequency or minimum coverage. These are exactly the kinds of issues that the consultation process should help clarify.
Third-party models are also treated more seriously. The draft is clear that institutions cannot shift accountability to vendors. Validation, auditability, explainability, supervisory access and concentration risk management remain the responsibility of the regulated entity. That is the right principle. But in practice, proprietary vendor models may not always allow traditional validation. The final guidance should recognise outcome-based approaches such as benchmarking, back-testing, challenger models and compensating controls. It should also explain how enhanced oversight for third-party models fits with risk-based tiering, possibly through portfolio-level reporting and model-level escalation for higher-risk cases.
What This Means for Financial Institutions
For financial institutions, this is more than a regulatory expansion. It changes how models are identified, owned, governed, validated and monitored across the enterprise. Banks will need central model inventories, risk-based governance, stronger AI validation capability and a common lifecycle that brings business, risk, technology and compliance teams together. The final paper should also address proportionality. Regulated entities vary widely in size, complexity and model maturity, and implementation expectations should reflect that reality. A phased approach for legacy models would make the transition more practical.
From Compliance Burden to Strategic Lever
Some drafting choices may also need recalibration. For example, a statement that institutions should not use any model that harms consumers sounds right in principle, but its application could be subjective. All models have error rates, and occasional adverse outcomes can occur even in well-governed systems. A more workable standard would focus on systematic, foreseeable or unmanaged consumer harm, along with clear expectations for identification, mitigation and remediation. The treatment of dynamic or retrained AI models also needs more detail. Changes within a pre-approved operating envelope should not automatically require full re-validation if monitoring remains within approved limits.
A Maturing Regulatory Framework
Overall, RBI’s move from credit model guidance to an enterprise-wide MRM framework shows a maturing regulatory approach. By widening the scope, strengthening governance, addressing AI-specific risks and building on FREE-AI, the draft places India closer to leading global practice. But because this is a consultative paper, its final strength will depend on how well it resolves the open questions around model boundaries, materiality, AI definitions, third-party validation, consumer harm, dynamic models and proportional implementation.
The author is Karthik Pasupathy, Partner, Financial Services Risk Management, EY India.
Disclaimer: The views expressed are solely of the author and ETCISO does not necessarily subscribe to it. ETCISO shall not be responsible for any damage caused to any person/organization directly or indirectly.
Firewall Security Company India Complete Firewall Security Solutions Provider Company in India












