On 24 June 2026, the Reserve Bank of India (RBI) released the “Draft Guidance on Regulatory Principles for Model Risk Management, 2026” (hereafter “Draft Guidance”). The Draft Guidance proposes broad regulatory expectations for model risk management across the model lifecycle. It intends to strengthen governance, oversight, risk management and controls of Regulated Entities (REs) using models (including AI / ML models). In this response we present our comments to the Draft Guidance, through six recommendations:
- Include a formal cross-functional governance and escalation mechanism could further strengthen the governance framework. Specifically, we recommend the Draft Guidance:
a) establish a cross-team committee or similar forum where different teams jointly determine model fitness, effectiveness of the proposed mitigants, escalation mechanisms for resolution, and other aspects of model deployment and behaviour;
b) offer indicative principles for ensuring the independence of validators, which account for expertise, organisational standing and incentives for independent validators and
c) In line with the recommendations of the FREE-AI Committee, ground the Model Risk Management Framework (MRMF) in a distinct Board-approved AI policy that establishes a common institutional position on responsible AI adoption before individual models enter the development and validation pipeline. - Strengthen customer protection rights, specifically by complementing explainability requirements with rights such as the right to information, contestability, grievance redressal, right of compensation founded on a clear delineation of liability.
- Establish an AI incident management framework comprising standardized taxonomies of potential model harms and risks, reporting and resolution protocols, and mechanisms to systematically identify, respond to model-related harms.
- Acknowledge the practical limitations in independently validating proprietary third-party models and provide guidance on complementary governance measures that REs could adopt. Specifically, we recommend the Draft Guidance to consider alternative assurance mechanisms from third-party model providers and enhanced post-deployment controls.
- Consider providing more granular details on identification of concentration risk, documentation of concentration risk using AI inventory and exit preparedness.
- Institutionalise a feedback mechanism for the Draft Guidance to remain current and responsive to
Read the full response here.

