Most AI governance rules for banks ask a question: can you explain what the model did? India’s central bank is asking a different one: who pays when it is wrong? The Reserve Bank of India’s Draft Guidance on Regulatory Principles for Model Risk Management, 2026, issued 24 June 2026 and open for public comment until 24 July, answers that with a liability shift. The vendor’s certificate stops being a shield. The regulated entity owns the outcome.
That is a narrower and harder claim than most of the AI-in-finance rulebook circulating this year. The Bank of England has treated AI as a financial-stability workstream. Germany’s BSI has turned model use into an audit question. The RBI is doing something more direct: it is reassigning legal accountability.
The problem it targets
Banks and non-bank lenders have spent three years buying AI they did not build. Credit-scoring engines, pricing models, fraud filters, and onboarding tools increasingly arrive from third-party providers, wrapped in vendor assurances that the system was validated, tested, and fit for regulated use. When one of those systems denies a loan on a flawed inference or misprices risk across a customer segment, the current instinct is to point at the supplier’s paperwork.
The RBI draft closes that exit. Under the guidance, a regulated entity remains fully responsible for outcomes generated by vendor-supplied systems, in the RBI’s own framing, “irrespective of certifications, assurances or validations provided by external service providers.” A model bought off the shelf is treated, for accountability purposes, as if the bank built it. The certificate becomes a procurement document, not a legal defence.
What the draft actually requires
The scope is wide. The framework applies to commercial banks, small finance banks, payment banks, co-operative banks, NBFCs, all-India financial institutions, asset reconstruction companies, and credit information companies. It reaches any model that materially influences decisions on credit approval, pricing, risk assessment, or customer classification, whether that model is built in-house, sourced from a third party, or assembled from both.
Three requirements do the work.
First, a board-approved Model Risk Management Framework. Not a compliance sign-off buried in a risk committee, but a framework the board owns, covering the full model lifecycle from development through validation, deployment, monitoring, and decommissioning. The accountability sits at the top of the house.
Second, a three lines of defence structure. Model owners and developers build and run the system. An independent model-risk and validation function checks it. Internal audit sits behind both. The point is separation: the people who benefit from a model going live are not the people who certify it is safe.
Third, and most striking, a deactivation trigger. Every in-scope AI model must carry an arrangement to suspend or switch it off, with human oversight preserved over automated decisions. If a model starts producing harmful or unexplained output, the bank must be able to pull it, and must have decided in advance how.
The certificate becomes a procurement document, not a legal defence.
Why this one is different
Read alongside the European moves, the RBI draft is not another transparency rule. The BSI and ECB interventions ask banks to document, audit, and explain. Those are process obligations. The RBI is doing accountability engineering: it fixes where the liability lands before anything goes wrong, and it fixes it on the regulated entity regardless of how the model got there.
That matters for the vendor market. A bank that cannot outsource its liability will not outsource its due diligence either. Independent validation of third-party models, continuous monitoring across their operational life, and a documented ability to deactivate them become the cost of deployment. Providers that sold a certificate and a support line now have to sell auditability, model documentation, and an off switch the customer controls. The ones that treated the compliance stack as someone else’s problem have the weakest hand.
It also sets a marker for other emerging markets. India is the first major emerging-market central bank to put board-level liability on third-party AI in regulated finance. Central banks across Asia, Africa, and Latin America watch the RBI’s supervisory approach closely, and much of the region runs on the same imported model stack. If the liability-shift reading holds through the comment period, the vendor-certificate defence weakens well beyond India.
The near-term read
The draft is not final. The comment window closes 24 July, and the industry response, particularly from smaller NBFCs that lean hardest on third-party AI and have the least in-house validation capacity, will shape the final text. Expect pushback on the deactivation-trigger mandate and on how much independent validation a payment bank can realistically run against a black-box vendor model.
But the direction is set, and it is the part that will not soften: the bank owns the outcome. For a chief risk officer, the operative sentence is not in the technical annexes. It is the one that says a vendor’s assurance no longer counts as a defence. Everything else in the framework, the board framework, the three lines, the deactivation trigger, follows from that single reallocation of who is on the hook.
Discussion
Sign in to join the discussion.
No comments yet. Be the first to share your thoughts.