Skip to content
BankPulseBETARegulatory intelligence for Indian banking
Tool · Draft RBI guidance · Self-check

RBI Model Risk Readiness Check

RBI has put out a draft on how banks and NBFCs should manage the risk in their models. It covers every model, including AI models and models bought from outside. Use this page to see where your institution stands before the final version arrives.

This is a draft, not a final rule. RBI issued it on 24 June 2026 and took comments until 24 July 2026. RBI has not issued the final version as of 3 September 2026. The final wording may differ. Every check below is BankPulse's own reading of the draft, in our own words. It is not legal or compliance advice.

Source: RBI press release 2026-2027/528, which links to the draft.

40checks, each tied to a paragraph of the draft
64paragraphs in the draft, all read
11kinds of regulated entity it applies to
0bytes sent to BankPulse. Your answers stay in your browser

How this works

1. Tell us about your institution. Three questions decide which checks apply to you.
2. Answer the 40 checks. Yes, partly, no, or not applicable. Add where the evidence sits.
3. Read your gap list. The biggest gaps come first, with the evidence you will need.
4. Build your model inventory. Then tier each model and check each vendor contract.
5. Print the report. One document for your Board, risk committee or auditor.

Your work is saved in this browser only, on this device. Use "Save a file" to keep a copy or move it to another computer. Clearing your browser data will remove it.

Who the draft applies to

The draft names eleven kinds of regulated entity:

It applies to every model they use, built in-house or bought, including AI and machine learning models.

Step 1. Your institution

Do you use models bought or licensed from outside?
Do you use AI or machine learning models?
Does any model face your customers?

Answer the three questions. Checks that do not apply to you are greyed out and left out of the score.

Step 2. The 40 checks

Answer each one as it stands today, not as you plan it to be. Open "What good looks like" if you are unsure.

Governance (draft paragraphs 8 to 13)

Check 1 of 40Core

A Board-approved model risk management framework exists

Has the Board approved one written framework that covers every model, including AI models and models bought from outside?

What good looks like, and the evidence to keep

Good looks like: One document, approved by the Board, that applies to every model the entity uses.

Evidence to keep: The framework document and the Board minute that approved it.

Comes from paragraphs 9 and 10 of the draft on RBI's site. Our words, not RBI's.

Check 2 of 40Important

The framework covers all the required parts

Does the framework set out a model taxonomy, governance structure, scope of use, tiering method, inventory standards and lifecycle policies?

What good looks like, and the evidence to keep

Good looks like: Each of the six parts has its own section or policy under the framework.

Evidence to keep: A table mapping each required part to a section or policy.

Comes from paragraph 10 of the draft on RBI's site. Our words, not RBI's.

Check 3 of 40Important

The Board has set a risk appetite for model risk

Has the Board approved a risk appetite and tolerance for model risk? Does it look forward and use scenario analysis or stress testing?

What good looks like, and the evidence to keep

Good looks like: A risk appetite statement with limits for model risk, informed by stress scenarios.

Evidence to keep: The risk appetite statement and the stress-test or scenario papers behind it.

Comes from paragraph 11 of the draft on RBI's site. Our words, not RBI's.

Check 4 of 40Important

The Board approves the tiering policy and reviews the framework

Does the Board approve the model tiering policy and review the whole framework at a fixed interval?

What good looks like, and the evidence to keep

Good looks like: A review cycle is written down and the last review is on record.

Evidence to keep: Board minutes showing approval of the tiering policy and the last framework review.

Comes from paragraph 11 of the draft on RBI's site. Our words, not RBI's.

Check 5 of 40Core

The Risk Management Committee approves high-risk models

Does the Risk Management Committee of the Board read validation reports of high-risk models and approve their deployment?

What good looks like, and the evidence to keep

Good looks like: No high-risk model goes live without the committee's approval on record.

Evidence to keep: Committee minutes for each high-risk model approval.

Comes from paragraph 12 of the draft on RBI's site. Our words, not RBI's.

Check 6 of 40Important

The committee reviews tiering reports at least once a year

Does the Risk Management Committee review model tiering reports at least once every year?

What good looks like, and the evidence to keep

Good looks like: A yearly tiering report with the committee's review recorded.

Evidence to keep: The latest tiering report and the minute of its review.

Comes from paragraph 12 of the draft on RBI's site. Our words, not RBI's.

Check 7 of 40Important

The committee watches exception, third-party and AI models

Does the committee oversee models approved with exceptions, third-party models and AI models, and read reports of breaches?

What good looks like, and the evidence to keep

Good looks like: A standing agenda item covers these models and any breach reports.

Evidence to keep: Committee agendas and breach reports from the last year.

Comes from paragraph 12 of the draft on RBI's site. Our words, not RBI's.

Check 8 of 40Important

Senior management runs the framework day to day

Has senior management set procedures, given people and systems, put tiering in place, kept the inventory current and reviewed policies?

What good looks like, and the evidence to keep

Good looks like: Named owners, a budget, and a yearly policy review reported to the committee.

Evidence to keep: Procedure documents, staffing plan and the policy review report.

Comes from paragraph 13 of the draft on RBI's site. Our words, not RBI's.

Check 9 of 40Core

The entity owns the results of every model

Is it written down that the entity answers for the results of every model, even models bought from outside?

What good looks like, and the evidence to keep

Good looks like: The framework says the entity is answerable for all model outcomes, without exception.

Evidence to keep: The clause in the framework and vendor contracts that reflect it.

Comes from paragraphs 8 and 45 of the draft on RBI's site. Our words, not RBI's.

Model risk management (draft paragraphs 14 to 25)

Check 10 of 40Important

Model risk is assessed for each model and for the whole entity

Is model risk assessed on an ongoing basis, model by model and across the entity? Is action taken when a model exceeds the risk appetite?

What good looks like, and the evidence to keep

Good looks like: A report that adds up model risk, flags models over the limit, and records what was done.

Evidence to keep: The latest model risk report and any committee paper on models over the limit.

Comes from paragraph 14 of the draft on RBI's site. Our words, not RBI's.

Check 11 of 40Core

Three lines of defence are in place

Are model owners the first line, an independent model risk and validation function the second, and internal audit the third?

What good looks like, and the evidence to keep

Good looks like: An organisation chart that shows the three lines and their independence.

Evidence to keep: The organisation chart and the charter of the validation function.

Comes from paragraph 15 of the draft on RBI's site. Our words, not RBI's.

Check 12 of 40Important

Model performance is tested on an ongoing basis

Are models tested regularly using past data and forward-looking methods, with AI-specific tests where needed and benchmarking?

What good looks like, and the evidence to keep

Good looks like: A testing calendar and results for each model, including back-tests.

Evidence to keep: The testing calendar and the latest test results.

Comes from paragraph 16 of the draft on RBI's site. Our words, not RBI's.

Check 13 of 40Core

Every model has a risk tier that is reviewed yearly

Is every model in the inventory given a risk tier? Is the tier reviewed at least once a year, or sooner on set triggers?

What good looks like, and the evidence to keep

Good looks like: Each inventory row shows a tier and the date it was last reviewed.

Evidence to keep: The inventory with tier and review date columns filled in.

Comes from paragraph 17 of the draft on RBI's site. Our words, not RBI's.

Check 14 of 40Important

The risk tier drives how the model is treated

Does the tier decide validation depth and frequency, who approves, and what controls apply? Does it also set monitoring, documentation and continuity plans?

What good looks like, and the evidence to keep

Good looks like: A table that says what each tier means for validation, approval, monitoring and documentation.

Evidence to keep: The tier-to-treatment table in the framework.

Comes from paragraph 18 of the draft on RBI's site. Our words, not RBI's.

Check 15 of 40Important

Tiering uses materiality and complexity without one hiding the other

Does the tiering method weigh how much the model matters, how complex it is, and other factors? Does a simple but important model still get a high tier?

What good looks like, and the evidence to keep

Good looks like: A scoring method where a low complexity score cannot pull down a highly material model.

Evidence to keep: The tiering method and a worked example.

Comes from paragraphs 19 and 20 of the draft on RBI's site. Our words, not RBI's.

Check 16 of 40Core

One complete model inventory exists

Is there one inventory of all models: active, inactive, under development and retired? Is it a rule that no model is used unless it is in it?

What good looks like, and the evidence to keep

Good looks like: A single register that every business unit feeds, with a rule that nothing runs outside it.

Evidence to keep: The inventory and the rule in the framework.

Comes from paragraph 21 of the draft on RBI's site. Our words, not RBI's.

Check 17 of 40Important

The inventory holds the minimum details

Does each inventory entry name the owner, developer, validator and approver? Does it also show the tier, intended use, upstream and downstream links, and key findings?

What good looks like, and the evidence to keep

Good looks like: Every column filled for every model. Use the inventory builder below to check.

Evidence to keep: An export of the inventory with no blank required columns.

Comes from paragraph 22 of the draft on RBI's site. Our words, not RBI's.

Check 18 of 40Supporting

Retired models stay in the inventory for ten years

Are retired models kept in the inventory for at least ten years from retirement, or longer if the law asks?

What good looks like, and the evidence to keep

Good looks like: A retention rule of ten years or more, and retired models still visible in the register.

Evidence to keep: The retention policy and a filter of retired models in the inventory.

Comes from paragraph 23 of the draft on RBI's site. Our words, not RBI's.

Check 19 of 40Important

Every model, including bought ones, is documented

Is there full documentation for every model, including third-party models, kept as long as the model stays in the inventory?

What good looks like, and the evidence to keep

Good looks like: A documentation standard and a file for each model that meets it.

Evidence to keep: The documentation standard and a sample of model files.

Comes from paragraph 24 of the draft on RBI's site. Our words, not RBI's.

Check 20 of 40ImportantCustomer-facing only

Customer complaints about models are handled

Does the complaint process cover complaints that arise from customer-facing models? Is there a check that no model harms customers?

What good looks like, and the evidence to keep

Good looks like: The grievance policy names model-related complaints, and a harm check runs before launch.

Evidence to keep: The grievance policy and the pre-launch harm check.

Comes from paragraph 25 of the draft on RBI's site. Our words, not RBI's.

Model lifecycle (draft paragraphs 26 to 44)

Check 21 of 40Important

Purpose and scope are written before a model is built

Before development starts, are the reason, goals and scope written down? Are costs like fairness and bias weighed against benefits?

What good looks like, and the evidence to keep

Good looks like: A short business case for each model with a fairness and bias note.

Evidence to keep: Business case documents for recent models.

Comes from paragraph 26 of the draft on RBI's site. Our words, not RBI's.

Check 22 of 40Important

Development follows a set process with governed data

Does development follow a structured process, from data collection to design and refinement? Does the data meet the data governance rules?

What good looks like, and the evidence to keep

Good looks like: A development standard and sign-off that data governance rules were followed.

Evidence to keep: The development standard and a data governance sign-off.

Comes from paragraphs 27 and 28 of the draft on RBI's site. Our words, not RBI's.

Check 23 of 40Core

Every model is validated independently

Is every model, including third-party models, validated by someone independent of those who built, own or use it?

What good looks like, and the evidence to keep

Good looks like: A validation record for every model, signed by the independent function.

Evidence to keep: Validation reports and the independence rule in the charter.

Comes from paragraph 29 of the draft on RBI's site. Our words, not RBI's.

Check 24 of 40Important

Validation happens at the right times

Is validation done before and after deployment, after any change, on set triggers, and at a fixed interval?

What good looks like, and the evidence to keep

Good looks like: A validation calendar that shows each trigger and the last date for each model.

Evidence to keep: The validation calendar.

Comes from paragraph 30 of the draft on RBI's site. Our words, not RBI's.

Check 25 of 40Important

Validation checks inputs, design, performance and fit

Does each validation assess the data and assumptions, the soundness of the design, the performance, and fit with intended use? Is it documented?

What good looks like, and the evidence to keep

Good looks like: A validation template with these four parts, filled for each model.

Evidence to keep: The validation template and completed reports.

Comes from paragraphs 31 and 32 of the draft on RBI's site. Our words, not RBI's.

Check 26 of 40Important

Validation reports reach the committee within three months

Do validation reports, with findings and recommendations, reach the Risk Management Committee or its delegate within three months of completion?

What good looks like, and the evidence to keep

Good looks like: A log of validation completion dates and committee dates, all within three months.

Evidence to keep: The validation log with both dates.

Comes from paragraph 33 of the draft on RBI's site. Our words, not RBI's.

Check 27 of 40Important

Approvals and exceptions follow a written structure

Is there an approval structure with authorities, thresholds, extra conditions for exception approvals and repair timelines, with reasons recorded?

What good looks like, and the evidence to keep

Good looks like: An approval matrix and a decision record for every model and exception.

Evidence to keep: The approval matrix and recent decision records.

Comes from paragraphs 34 and 35 of the draft on RBI's site. Our words, not RBI's.

Check 28 of 40Important

Deployment is planned with IT and outputs are stable

Is deployment done with IT and data teams? Is it checked that production outputs match test outputs and stay stable?

What good looks like, and the evidence to keep

Good looks like: A deployment checklist with a production-match test signed off.

Evidence to keep: The deployment checklist and the match test result.

Comes from paragraph 36 of the draft on RBI's site. Our words, not RBI's.

Check 29 of 40Core

Every live model is monitored

Is every deployed model, including third-party ones, monitored against its intended results, with closer watch on exception-approved models?

What good looks like, and the evidence to keep

Good looks like: Monitoring dashboards or reports for each live model, with the committee watching exception models.

Evidence to keep: Monitoring reports and the committee's review of exception models.

Comes from paragraph 37 of the draft on RBI's site. Our words, not RBI's.

Check 30 of 40Important

Changes to models are controlled and logged

Is there a change process with roles, an impact assessment before change, and a way to undo failed changes? Is there a version log and a rule for what counts as a material change?

What good looks like, and the evidence to keep

Good looks like: A change log per model, and a material-change rule that restarts validation and approval.

Evidence to keep: The change policy, a sample change log and the material-change rule.

Comes from paragraphs 38, 39, 40, 41 and 42 of the draft on RBI's site. Our words, not RBI's.

Check 31 of 40Important

Models have a fallback and a retirement process

Does the business continuity plan cover model failure with fallbacks? Are people told in time when a model is retired?

What good looks like, and the evidence to keep

Good looks like: A continuity section for models with manual or backup options, and a retirement notice process.

Evidence to keep: The continuity plan section and a recent retirement notice.

Comes from paragraphs 43 and 44 of the draft on RBI's site. Our words, not RBI's.

Third-party models (draft paragraphs 45 to 48)

Check 32 of 40ImportantOutside models only

Vendors and their models are checked before purchase

Before buying or using an outside model, is the vendor's standing checked? Are the model's method, limits and data quality checked too?

What good looks like, and the evidence to keep

Good looks like: A due diligence report for each outside model, done before the contract.

Evidence to keep: Due diligence reports.

Comes from paragraph 47 of the draft on RBI's site. Our words, not RBI's.

Check 33 of 40CoreOutside models only

Vendor contracts give documentation, audit rights and an exit

Do vendor contracts give enough technical documentation to validate the model? Do they give audit rights for the entity and for RBI, and continuity and exit terms?

What good looks like, and the evidence to keep

Good looks like: A contract checklist with these three items ticked for every outside model.

Evidence to keep: Contract clauses or a contract review table.

Comes from paragraph 48 of the draft on RBI's site. Our words, not RBI's.

Check 34 of 40CoreOutside models only

Outside models are validated in-house and watched by the committee

Is every outside model validated by the entity itself, even when the vendor certifies it? Is it watched by the committee whatever its tier?

What good looks like, and the evidence to keep

Good looks like: In-house validation reports for outside models, and the committee's oversight record.

Evidence to keep: Validation reports and committee minutes.

Comes from paragraph 46 of the draft on RBI's site. Our words, not RBI's.

AI and machine learning models (draft paragraphs 49 to 63)

Check 35 of 40CoreAI models only

AI use is scoped and limited to where risk can be managed

Is the scope of AI models, including large foundation models, defined? Are they used only where risk can be managed, with use limited when a vendor shares little?

What good looks like, and the evidence to keep

Good looks like: An AI use policy that lists allowed use cases and the extra controls for each.

Evidence to keep: The AI use policy and the list of approved use cases.

Comes from paragraphs 49, 50 and 51 of the draft on RBI's site. Our words, not RBI's.

Check 36 of 40ImportantAI models only

AI tiering counts reliance, autonomy and vendor dependence

Does tiering for AI models also weigh how much decisions rely on them and how autonomous they are? Is the risk of depending on few vendors assessed?

What good looks like, and the evidence to keep

Good looks like: Extra tiering questions for AI models and a vendor concentration note.

Evidence to keep: The AI tiering questions and the concentration assessment.

Comes from paragraphs 52 and 53 of the draft on RBI's site. Our words, not RBI's.

Check 37 of 40CoreAI models only

AI behaviour risks are tested and controlled

Are explainability limits set, hallucinations bounded, and bias tested for fairness? Are overfitting, false patterns, output swings and data drift checked?

What good looks like, and the evidence to keep

Good looks like: A test report for each AI model covering all seven behaviour risks.

Evidence to keep: The AI test report and the drift monitoring dashboard.

Comes from paragraph 54 of the draft on RBI's site. Our words, not RBI's.

Check 38 of 40ImportantAI models only

AI models face adversarial tests and extra documentation

Are AI models tested under stress and attack, and red-teamed where they generate content or talk to customers? Are self-updating models tightly controlled and fully documented?

What good looks like, and the evidence to keep

Good looks like: Red-team results, an auto-update rule, and documentation that lets a third party reproduce the model.

Evidence to keep: Red-team reports, the auto-update policy and the model documentation.

Comes from paragraphs 54, 55, 56 and 57 of the draft on RBI's site. Our words, not RBI's.

Check 39 of 40CoreAI models only

AI deployment is secured and customers are told

Are access, cyber and integration controls in place for each AI deployment? For customer-facing AI, are there prompt injection defences, a clear AI notice, and a switch to a human?

What good looks like, and the evidence to keep

Good looks like: A security sign-off for each AI deployment. An AI notice and a human hand-off in every customer channel.

Evidence to keep: The security sign-off and screenshots of the notice and hand-off.

Comes from paragraphs 58 and 59 of the draft on RBI's site. Our words, not RBI's.

Check 40 of 40CoreAI models only

Humans stay in command with a kill switch

Is there human oversight, with a way to override, pause or switch off each AI model? Are outputs reviewed by trained staff, and overrides and incidents reviewed too?

What good looks like, and the evidence to keep

Good looks like: A named human owner, a tested kill switch, and a quarterly review of overrides and incidents.

Evidence to keep: The oversight procedure, the kill-switch test record and the override log.

Comes from paragraphs 60, 61, 62 and 63 of the draft on RBI's site. Our words, not RBI's.

Step 3. Your gap list

Every check you answered "No" or "Partly", biggest first. Core checks come before important ones.

No gaps yet. Answer the checks above and they will appear here.

Step 4. Model inventory builder

Paragraph 22 of the draft lists what an inventory should hold at the least. These columns follow that list. Add each model, including spreadsheets that drive decisions. The draft counts those as models too.

* columns the draft asks for at the least (paragraph 22).

No models yet.

ModelBuilt whereAIStatusTierOwnerDeveloperValidatorApproverIntended useUpstreamDownstreamLast validatedKey findingsEdit

A red cell is a required column left blank. The draft says no model should be used unless it is in the inventory (paragraph 21).

Step 4a. Model tiering calculator

A model's tier rests on how much it matters, how complex it is, and other factors (paragraph 19). A simple model that matters a lot must still get a high tier (paragraph 20). For AI models, reliance on the output and how much it acts alone also count (paragraph 52).

This is BankPulse's own method built on those three paragraphs. It suggests a tier. Your Board-approved tiering policy decides.

How much the model matters

How complex the model is

Other factors

Suggested tier
Answer the questions

    Step 4b. Vendor and AI vendor contract checklist

    The draft says you stay answerable for a model you buy (paragraph 45). It asks for due diligence before you buy (paragraph 47) and for set terms in the contract (paragraph 48). AI models bought from outside carry extra points (paragraphs 51, 53 and 56).

    One checklist per vendor. Tick what is in place and note where the clause sits.

    Type a vendor name to start.

    Step 5. Report, save and export

    "Print the report" opens your browser's print window. Choose "Save as PDF" there to get a PDF. The saved file is plain JSON. Load it on any computer to carry on.

    When RBI issues the final guidance, BankPulse will update this page and mark what changed. The Daily Brief will carry it the same morning. Subscribe free to be told.

    Want to review this with us? Write to contactus@bankpulse.ai. We read every mail.