An AI agent is software that decides and acts on its own. It is not the same as software that only answers a question. Use this page to see where your bank, NBFC or fintech stands before an agent starts touching customers or money.
What this page is, and what it is not. It is a self-check. It is not legal advice and it is not a compliance opinion. RBI has not issued one rulebook for AI agents. So each check names the document behind it. Each check also says if that document is a rule in force, a draft, or a report. Read the status before you act on a check.
We do not claim this is the first or the only tool of its kind.
20checks, in seven groups
8must-have checks. Miss one and you are not ready
4of the 6 source documents are rules in force
0bytes sent to BankPulse
How this works
1. Answer four questions about your setup. They decide which checks apply to you.
2. Work through the twenty checks. Yes, partly, no, or not applicable.
3. Read your gap list. The worst gaps come first.
4. Print the report. One page for your Board, risk committee or auditor.
Your answers are saved in this browser only, on this device. Use "Save a file" to keep a copy or move it to another computer. Clearing your browser data will remove it.
Step 1. Your setup
Answer these four questions first. The checks that do not apply to you will then be greyed out and left out of your score.
Step 2. The twenty checks
Who is in chargeSomebody must own each agent by name. A team is not a name.
Check 1 of 20MUST HAVE
A written policy covers AI agents
Has your Board approved a written policy that names AI agents and says how they are run?
What good looks like, and the evidence to keep
Good looks like: One policy, approved by the Board. It says which AI uses are allowed and which are not. It also says who decides.
Evidence to keep: The policy document and the Board minute that approved it.
Committee report, not a ruleFREE-AI Committee Report, 2025. The committee asked every regulated entity to have a Board-approved AI policy.
These are our own words. We do not print RBI wording.
Check 2 of 20
One named person owns each agent
For every AI agent you run, is there one person by name who answers for it?
What good looks like, and the evidence to keep
Good looks like: A name, a role and a date. The person knows how the agent works well enough to question it and stop it.
Evidence to keep: The agent register with the owner's name against each agent.
Draft, not a ruleDraft Model Risk Management Guidance, 2026, paragraph 62. The draft says the people who watch a model should know enough about it. They should be able to challenge it, override it, or raise a concern higher.
Committee report, not a ruleFREE-AI Committee Report, 2025. The committee asked for clear lines of accountability for AI.
These are our own words. We do not print RBI wording.
Check 3 of 20MUST HAVE
A live list of every AI agent in use
Do you have one up to date list of every AI agent running in your institution? Count the ones a business team started on its own.
What good looks like, and the evidence to keep
Good looks like: A list that says what each agent does and which systems it can touch. It also names the owner and the risk grade. It is updated when something changes, not once a year.
Evidence to keep: The register itself, with the date it was last updated.
Rule in forceCybersecurity and Technology Directions, 2026, paragraph 47. You must keep an up to date list of your information assets. Business applications count. Mark how important each one is.
Draft, not a ruleDraft Model Risk Management Guidance, 2026, paragraphs 49 and 52. The draft says to set the scope of AI models and grade their risk. How much the model is relied on, and how freely it acts, both count.
These are our own words. We do not print RBI wording.
What the agent may do on its ownThe limits must be written down before the agent starts work, not after.
Check 4 of 20MUST HAVE
Written limits on what the agent may do alone
Is there a written limit on what each agent may do without a person saying yes first? It should cover money, customer records and messages sent outside.
What good looks like, and the evidence to keep
Good looks like: A short written list. For example: may draft a letter, may not send it. May read an account, may not change a limit. May not move money at all.
Evidence to keep: The limits document, and the system setting that enforces it.
Draft, not a ruleDraft Model Risk Management Guidance, 2026, paragraphs 50 and 52. The draft says a model should be used only where its risk can be managed. How freely a model acts should count in its risk grade.
These are our own words. We do not print RBI wording.
Check 5 of 20
A check before the agent goes live
Does a written check and a named approval come before any new agent touches real customers or real money?
What good looks like, and the evidence to keep
Good looks like: A short note on what could go wrong and who could be harmed. It also says what would be done about it. Signed off by a committee, not by one project team alone.
Evidence to keep: The assessment and the approval note for the last agent you launched.
Draft, not a ruleDraft Model Risk Management Guidance, 2026, paragraph 58. The draft says that putting an AI model into use must not open holes in the live systems. It lists the safeguards to apply.
Committee report, not a ruleFREE-AI Committee Report, 2025. The committee asked for an AI impact check before a new AI use goes live.
These are our own words. We do not print RBI wording.
Check 6 of 20AI bought from outside
Updates that happen by themselves are controlled
Does your agent or its model update itself? If yes, have you written down what may change on its own?
What good looks like, and the evidence to keep
Good looks like: A written scope for automatic updates, a reason for allowing them, and tighter checking after each one. An agent that quietly became a different agent last Tuesday is a real risk.
Evidence to keep: The update policy and the log of the last few model changes.
Draft, not a ruleDraft Model Risk Management Guidance, 2026, paragraph 56. The draft asks for stronger controls where a model updates automatically. That includes a clear scope of what may change, and closer watching.
These are our own words. We do not print RBI wording.
Check 7 of 20
Data passed between systems is not edited by hand
When an agent moves data from one system to another, does it go straight through? Is there a login check, a record, and no hand editing?
What good looks like, and the evidence to keep
Good looks like: The path is tested, automatic, and leaves a record. Nobody opens a file in between and corrects it.
Evidence to keep: The design note for the data path and the test result.
Rule in forceCybersecurity and Technology Directions, 2026, paragraphs 141 and 142. For important applications there must be no hand changes to data moving between systems. The transfer must be tested, automatic, and leave a record.
These are our own words. We do not print RBI wording.
The person in the loopA person must be able to see the decision, stop it, and answer for it.
Check 8 of 20MUST HAVEAgents that deal with customers
A person makes the final call on a customer decision
For any decision that affects a customer, does a person make the final call? Can that person disagree with the agent?
What good looks like, and the evidence to keep
Good looks like: The person can see why the agent said what it said. They have time to think. They are not scored on how fast they click yes.
Evidence to keep: The process note, plus a sample of cases where a person went against the agent.
Draft, not a ruleDraft Model Risk Management Guidance, 2026, paragraphs 60 and 61. The draft asks for firm human oversight of AI, including where decisions are automatic. It also says to allow for the habit of trusting the machine too much.
Committee report, not a ruleFREE-AI Committee Report, 2025. The committee said the final decision should rest with people, not with the model.
These are our own words. We do not print RBI wording.
Check 9 of 20MUST HAVEAgents that act on their own
A stop switch that has been tested
Can you stop an agent within minutes, and have you actually tested it?
What good looks like, and the evidence to keep
Good looks like: One switch, one owner, one tested drill with a date. Work carries on by hand while the agent is off.
Evidence to keep: The drill record with the date and how long the stop took.
Draft, not a ruleDraft Model Risk Management Guidance, 2026, paragraph 60. The draft asks for ways to override, suspend or shut down an AI model, including a kill switch.
These are our own words. We do not print RBI wording.
Check 10 of 20Agents that deal with customers
The customer is told, and can ask for a person
Is the customer told plainly that they are dealing with AI? Can they move to a person when they ask?
What good looks like, and the evidence to keep
Good looks like: A plain line at the start, not a line in the terms and conditions. The move to a person works on the first ask.
Evidence to keep: A screen shot of the message, and the route to a human agent.
Draft, not a ruleDraft Model Risk Management Guidance, 2026, paragraph 59. The draft says customers should be told they are dealing with an AI system, and told its limits. They should be able to move to a person.
Committee report, not a ruleFREE-AI Committee Report, 2025. The committee asked for the same, plus a way to complain about an AI decision.
These are our own words. We do not print RBI wording.
Proof of what the agent didIf you cannot rebuild the decision later, you cannot defend it.
Check 11 of 20MUST HAVE
Every agent action is recorded
Does every agent action leave a record? It should show what went in, what came out, when, and who approved it.
What good looks like, and the evidence to keep
Good looks like: The record carries the date, the time, the source and enough detail to identify the exact action. A summary count is not a record.
Evidence to keep: A sample of the log for one real day.
Rule in forceCybersecurity and Technology Directions, 2026, paragraphs 93 and 94. Every application that can reach important or sensitive information must be able to log and leave a trail. The settings must be checked from time to time. That is how the minimum details get captured.
These are our own words. We do not print RBI wording.
Check 12 of 20
Somebody reads the records
Does anyone look at the agent records regularly to spot something odd? Or are they opened only after a problem?
What good looks like, and the evidence to keep
Good looks like: A named team, a set frequency, and a note of what they found last time.
Evidence to keep: The monitoring report for the last quarter.
Rule in forceFraud Risk Management Directions, 2026, paragraph 20. A bank must set up a Data Analytics and Market Intelligence Unit. Its job is to help catch a fraud early.
These are our own words. We do not print RBI wording.
Check 13 of 20
You can rebuild a decision months later
A customer or RBI asks in a year why the agent did what it did. Can you show the version, the data and the reason?
What good looks like, and the evidence to keep
Good looks like: You keep the model version, the settings, the input and the output together. You can run it again and get the same answer.
Evidence to keep: One worked example, rebuilt end to end.
Draft, not a ruleDraft Model Risk Management Guidance, 2026, paragraph 57. The draft asks for fuller records for AI models so a decision can be traced, repeated and audited.
These are our own words. We do not print RBI wording.
Data the agent can reachAn agent with wide access is a wide risk.
Check 14 of 20MUST HAVE
The agent sees only the data it needs
Does each agent have the smallest access that lets it do its job, and is that access reviewed?
What good looks like, and the evidence to keep
Good looks like: Least access, and separate duties. Strong login for any account with high access. An agent should not hold a general staff login.
Evidence to keep: The access list for each agent and the date of the last review.
Rule in forceCybersecurity and Technology Directions, 2026, paragraphs 109 and 110. Access must run through one central system. It must follow least access and separation of duties. Users with high access to important systems need two or more login steps.
These are our own words. We do not print RBI wording.
Check 15 of 20
Personal data has a lawful reason and a purpose
For every piece of personal data an agent reads, is there a lawful reason and a stated purpose? Is there a time after which it is deleted?
What good looks like, and the evidence to keep
Good looks like: You can name the reason for each field. Customer data does not travel into an outside model without a decision on record.
Evidence to keep: The data map for the agent and the retention rule.
Rule in forceDigital Personal Data Protection Act, 2023. The Act sets out notice, consent and purpose limits for personal data. The rules under it were notified on 14 November 2025.
Committee report, not a ruleFREE-AI Committee Report, 2025. The committee asked for an internal framework covering how data is collected, used, kept, shared and deleted.
These are our own words. We do not print RBI wording.
Check 16 of 20
Cloud and hosted systems follow the same rules
Do the same controls apply when the agent runs in the cloud or on somebody else's platform?
What good looks like, and the evidence to keep
Good looks like: No lighter treatment because it is hosted. The provider reaches your data only on a need to know basis.
Evidence to keep: The cloud control note and the access rule for the provider's staff.
These are our own words. We do not print RBI wording.
Outside models and vendorsMost agents are bought, not built. The contract is the control.
Check 17 of 20AI bought from outside
The contract covers the AI risks
Does the contract give you and RBI the right to audit? Does it set out how you leave, and require notice before the model changes?
What good looks like, and the evidence to keep
Good looks like: Audit rights for you and for RBI. Access to the provider's premises and data. An exit plan. The provider must not destroy data during the handover.
Evidence to keep: The clause numbers in the signed contract.
Rule in forceManaging Risks in Outsourcing Directions, 2025, paragraphs 76, 81 and 82. The provider must give real access to data and premises for you, your auditors and RBI. The exit plan must name other arrangements. The contract must cover safe removal of data and must stop the provider erasing data during the changeover.
Draft, not a ruleDraft Model Risk Management Guidance, 2026, paragraph 51. Where an outside provider will not share enough about an AI model, the draft says to list the risks. It also says to consider limiting the model's use.
These are our own words. We do not print RBI wording.
Check 18 of 20AI bought from outside
You know what happens if the vendor goes
Have you worked out what breaks if this one provider or one model stops, changes or raises its price?
What good looks like, and the evidence to keep
Good looks like: You have counted how much sits with one provider. You have named the single points of failure. You have written what you would do instead.
Evidence to keep: The concentration note and the exit plan.
Rule in forceManaging Risks in Outsourcing Directions, 2025, paragraphs 62 and 79. You must judge the risk of putting too much with one provider. The outsourcing policy must carry a clear exit plan.
Draft, not a ruleDraft Model Risk Management Guidance, 2026, paragraph 53. The draft flags the risk of depending on a small number of model providers. That includes supply chain risk, and changes the provider makes.
These are our own words. We do not print RBI wording.
When it goes wrongPlan for the agent that keeps running and keeps being wrong.
Check 19 of 20MUST HAVE
An AI failure counts as an incident, and goes out in time
Is a bad agent decision treated as an incident? Can you report a cyber incident to RBI within six hours of finding it?
What good looks like, and the evidence to keep
Good looks like: Your incident list names AI failures. The six hour clock is understood and the route is known. Your provider must tell you fast enough for you to meet it.
Evidence to keep: The incident policy and one report you actually filed.
Rule in forceCybersecurity and Technology Directions, 2026, paragraphs 175 and 182. You must have an incident policy. It must cover how incidents are defined, graded and reported. A cyber incident must be reported within six hours of finding it, on RBI's DAKSH platform. CERT-In must also be told.
Rule in forceManaging Risks in Outsourcing Directions, 2025, paragraph 56. The provider must report an incident to you without delay. That lets you report it to RBI within six hours of the provider finding it.
These are our own words. We do not print RBI wording.
Check 20 of 20
The agent is attacked on purpose before someone else does it
Has anyone tried to break your agent with odd inputs, hidden instructions and stress cases? Was the result written down?
What good looks like, and the evidence to keep
Good looks like: Testing covers hidden instructions inside documents the agent reads. It covers strange inputs. It also covers the quiet failure, where the agent keeps working and keeps being wrong.
Evidence to keep: The test report, the faults found, and what was fixed.
Draft, not a ruleDraft Model Risk Management Guidance, 2026, paragraphs 54, 55 and 59. The draft says to test how a model behaves under odd, stressed and hostile conditions. It asks for structured challenge, including red teaming. For customer facing models it asks for guards against hidden instructions and hostile inputs.
Rule in forceCybersecurity and Technology Directions, 2026, paragraph 162. The Directions say a bank may run red team exercises to test its defences. This one is a may, not a must.
These are our own words. We do not print RBI wording.
Load a file
Your score
0%
Not started
0 of 20 checks answered.
Your biggest gaps
Answer a few checks and your gaps will appear here.
Where every check comes from
Six documents sit behind these checks. Their status is not the same, and that matters more than the checks themselves.
Rule in forceReserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026
Issued 31 July 2026
A rule in force. It replaced the older cybersecurity framework and the older IT governance directions.
Draft, not a ruleGuidance on Regulatory Principles for Model Risk Management, 2026
Issued 24 June 2026
A draft, not a rule. RBI issued it on 24 June 2026 and took comments until 24 July 2026. The final version has not been issued. The wording may change. It uses the word 'should', not 'shall'.
Committee report, not a ruleReport of the Committee on a Framework for Responsible and Ethical Enablement of Artificial Intelligence in the Financial Sector
Issued 13 August 2025
A committee report, not a rule. RBI released it on 13 August 2025. It carries 26 recommendations. Nothing in it binds a bank by itself.
One thing worth knowing. The Cybersecurity and Technology Directions of 31 July 2026 replaced the older cybersecurity framework and the older IT governance directions. If your AI paperwork still points at the 2023 IT governance master direction, it is pointing at a document that has been repealed.
What this page does not cover
This page checks how an agent is governed. It does not check the model inside it. For that, use our other free tool: the Model Risk Readiness Check. It runs forty checks against RBI's draft model risk guidance of June 2026.
It also does not cover sector rules for your particular product. Lending, payments and insurance distribution are examples.
Built on 8 September 2026. If you find a mistake on this page, tell us and we will answer within three working days.
Tell us what to build next
BankPulse is built for bankers. What you send here goes straight to the founder.
Sign-in opens shortly. The suggestion box opens with it.
Until then you can see what other bankers have asked for on the suggestions board.
You are signed out. Sign in with your Google account below.
Please sign in first. It keeps the board clean and lets us write back to you.