RBI Mandates AI ‘Kill Switch’ & Broadens Model Risk Framework

RBI MANDATES

The Reserve Bank of India (RBI) has released a draft Guidance on Regulatory Principles for Model Risk Management, 2026 for public consultation. This framework marks a major leap forward in AI governance for India’s financial sector, significantly broadening regulatory oversight over analytical, artificial intelligence (AI), and machine learning (ML) models.   

The current draft dramatically scales up the scope of previous guidelines—such as the August 2024 draft credit model risk principles and the August 2025 FREE-AI Committee report. It transitions from focusing solely on credit scoring to regulating every model that influences a business or operational decision across an institution’s lifecycle.  

Who is Impacted?

The proposed guidelines apply universally across the financial ecosystem, covering 11 distinct categories of Regulated Entities (REs):  

  • Commercial Banks, Small Finance Banks, and Payments Banks  

  • Local Area Banks, Regional Rural Banks, and Co-operative Banks (Urban & Rural)  

  • All India Financial Institutions (e.g., NABARD, EXIM Bank)  

  • Non-Banking Financial Companies (NBFCs) across all layers  

  • Asset Reconstruction Companies (ARCs)  

  • Credit Information Companies (CICs)  

Core Pillars of the Framework

1. The AI ‘Kill Switch’ & Human in the Loop

In a bid to curb algorithmic anomalies and flash failures, the RBI mandates that financial firms must maintain an immediate override, suspension, or deactivation mechanism (a ‘kill switch’) for all active AI models.  

  • Human Oversight: Staff managing automated decisions must possess the technical expertise to challenge and override AI outputs.  

  • Customer Autonomy: Whenever a customer interacts directly with a generative or automated AI system, the RE must explicitly disclose this fact, clarify its limitations, and provide a clear choice to seamlessly switch to a human representative.  

2. The Three Lines of Defense

To ensure institutional accountability, the draft introduces a formalized structured governance hierarchy:  

  • First Line (Model Owners): Business units developing or operating the model.  

  • Second Line (Independent Validation): A distinct Model Risk Management and Validation function that independently verifies accuracy, bias, and technical safety.  

  • Third Line (Internal Audit): Independent internal audit units reviewing the systemic health of the entire governance mechanism.   

3. Risk Based Tiering and Comprehensive Inventory

Rather than treating all algorithms equally, models must be categorized into tiers based on their complexity, business impact, and level of autonomy. High-risk models will face tighter validation constraints. Additionally, the RBI has banned the use of “shadow models.” No model can be deployed unless it is logged in a centralized live inventory, and even decommissioned models must be securely archived in the repository for a minimum of 10 years.  

4. Direct Accountability for Sourced & Third Party Models

In a crucial move targeting modern software procurement, the RBI clarifies that outsourcing a model does not outsource the risk. Financial firms remain completely accountable for the decisions made by third-party vendor systems (such as hosted LLMs or cloud APIs). Regulated entities must secure audit rights, construct viable exit arrangements, and demand detailed technical design documentation from tech vendors.  

Tackling Technical Vulnerabilities

The guidance highlights 7 specific AI risk dimensions, including model hallucinations, data overfitting, bias, and lack of explainability. When a model operates as a “black box” where absolute explainability is impossible, the RBI mandates that banks implement compensating controls—such as restricted usage scope, intensive continuous monitoring, and more frequent empirical validations.  

Public Feedback and Next Steps

The RBI has opened the floor for industry feedback to ensure the final circular balances safety with operational viability.  

Important Compliance Note: Regulated entities, tech partners, and members of the public have until July 24, 2026, to submit comments, feedback, or suggestions. Submissions can be processed digitally via the ‘Connect 2 Regulate’ section on the official RBI website, or directed via email/post to the Chief General Manager, Operational Risk Group (Department of Regulation, Central Office, RBI).  

Source: Reserve Bank of India press release

author avatar
RMA INDIA

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.