RBI has put out a draft on how banks and NBFCs should manage the risk in their models. It covers every model, including AI models and models bought from outside. Use this page to see where your institution stands before the final version arrives.
This is a draft, not a final rule. RBI issued it on 24 June 2026 and took comments until 24 July 2026. RBI has not issued the final version as of 3 September 2026. The final wording may differ. Every check below is BankPulse's own reading of the draft, in our own words. It is not legal or compliance advice.
0bytes sent to BankPulse. Your answers stay in your browser
How this works
1. Tell us about your institution. Three questions decide which checks apply to you.
2. Answer the 40 checks. Yes, partly, no, or not applicable. Add where the evidence sits.
3. Read your gap list. The biggest gaps come first, with the evidence you will need.
4. Build your model inventory. Then tier each model and check each vendor contract.
5. Print the report. One document for your Board, risk committee or auditor.
Your work is saved in this browser only, on this device. Use "Save a file" to keep a copy or move it to another computer. Clearing your browser data will remove it.
Who the draft applies to
The draft names eleven kinds of regulated entity:
Commercial banks, including foreign banks
Small finance banks
Payments banks
Local area banks
Regional rural banks
Urban co-operative banks
Rural co-operative banks
NBFCs in every layer
All India financial institutions
Asset reconstruction companies
Credit information companies
It applies to every model they use, built in-house or bought, including AI and machine learning models.
Step 1. Your institution
Do you use models bought or licensed from outside?
Do you use AI or machine learning models?
Does any model face your customers?
Answer the three questions. Checks that do not apply to you are greyed out and left out of the score.
Step 2. The 40 checks
Answer each one as it stands today, not as you plan it to be. Open "What good looks like" if you are unsure.
Governance (draft paragraphs 8 to 13)
Check 1 of 40Core
A Board-approved model risk management framework exists
Has the Board approved one written framework that covers every model, including AI models and models bought from outside?
What good looks like, and the evidence to keep
Good looks like: One document, approved by the Board, that applies to every model the entity uses.
Evidence to keep: The framework document and the Board minute that approved it.
Does the tier decide validation depth and frequency, who approves, and what controls apply? Does it also set monitoring, documentation and continuity plans?
What good looks like, and the evidence to keep
Good looks like: A table that says what each tier means for validation, approval, monitoring and documentation.
Evidence to keep: The tier-to-treatment table in the framework.
Tiering uses materiality and complexity without one hiding the other
Does the tiering method weigh how much the model matters, how complex it is, and other factors? Does a simple but important model still get a high tier?
What good looks like, and the evidence to keep
Good looks like: A scoring method where a low complexity score cannot pull down a highly material model.
Evidence to keep: The tiering method and a worked example.
Does each inventory entry name the owner, developer, validator and approver? Does it also show the tier, intended use, upstream and downstream links, and key findings?
What good looks like, and the evidence to keep
Good looks like: Every column filled for every model. Use the inventory builder below to check.
Evidence to keep: An export of the inventory with no blank required columns.
Is there a change process with roles, an impact assessment before change, and a way to undo failed changes? Is there a version log and a rule for what counts as a material change?
What good looks like, and the evidence to keep
Good looks like: A change log per model, and a material-change rule that restarts validation and approval.
Evidence to keep: The change policy, a sample change log and the material-change rule.
Comes from paragraphs 38, 39, 40, 41 and 42 of the draft on RBI's site. Our words, not RBI's.
Check 31 of 40Important
Models have a fallback and a retirement process
Does the business continuity plan cover model failure with fallbacks? Are people told in time when a model is retired?
What good looks like, and the evidence to keep
Good looks like: A continuity section for models with manual or backup options, and a retirement notice process.
Evidence to keep: The continuity plan section and a recent retirement notice.
Vendor contracts give documentation, audit rights and an exit
Do vendor contracts give enough technical documentation to validate the model? Do they give audit rights for the entity and for RBI, and continuity and exit terms?
What good looks like, and the evidence to keep
Good looks like: A contract checklist with these three items ticked for every outside model.
Evidence to keep: Contract clauses or a contract review table.
AI and machine learning models (draft paragraphs 49 to 63)
Check 35 of 40CoreAI models only
AI use is scoped and limited to where risk can be managed
Is the scope of AI models, including large foundation models, defined? Are they used only where risk can be managed, with use limited when a vendor shares little?
What good looks like, and the evidence to keep
Good looks like: An AI use policy that lists allowed use cases and the extra controls for each.
Evidence to keep: The AI use policy and the list of approved use cases.
Are explainability limits set, hallucinations bounded, and bias tested for fairness? Are overfitting, false patterns, output swings and data drift checked?
What good looks like, and the evidence to keep
Good looks like: A test report for each AI model covering all seven behaviour risks.
Evidence to keep: The AI test report and the drift monitoring dashboard.
AI models face adversarial tests and extra documentation
Are AI models tested under stress and attack, and red-teamed where they generate content or talk to customers? Are self-updating models tightly controlled and fully documented?
What good looks like, and the evidence to keep
Good looks like: Red-team results, an auto-update rule, and documentation that lets a third party reproduce the model.
Evidence to keep: Red-team reports, the auto-update policy and the model documentation.
Are access, cyber and integration controls in place for each AI deployment? For customer-facing AI, are there prompt injection defences, a clear AI notice, and a switch to a human?
What good looks like, and the evidence to keep
Good looks like: A security sign-off for each AI deployment. An AI notice and a human hand-off in every customer channel.
Evidence to keep: The security sign-off and screenshots of the notice and hand-off.
Is there human oversight, with a way to override, pause or switch off each AI model? Are outputs reviewed by trained staff, and overrides and incidents reviewed too?
What good looks like, and the evidence to keep
Good looks like: A named human owner, a tested kill switch, and a quarterly review of overrides and incidents.
Evidence to keep: The oversight procedure, the kill-switch test record and the override log.
Every check you answered "No" or "Partly", biggest first. Core checks come before important ones.
No gaps yet. Answer the checks above and they will appear here.
Step 4. Model inventory builder
Paragraph 22 of the draft lists what an inventory should hold at the least. These columns follow that list. Add each model, including spreadsheets that drive decisions. The draft counts those as models too.
No models yet.
Model
Built where
AI
Status
Tier
Owner
Developer
Validator
Approver
Intended use
Upstream
Downstream
Last validated
Key findings
Edit
A red cell is a required column left blank. The draft says no model should be used unless it is in the inventory (paragraph 21).
Step 4a. Model tiering calculator
A model's tier rests on how much it matters, how complex it is, and other factors (paragraph 19). A simple model that matters a lot must still get a high tier (paragraph 20). For AI models, reliance on the output and how much it acts alone also count (paragraph 52).
This is BankPulse's own method built on those three paragraphs. It suggests a tier. Your Board-approved tiering policy decides.
How much the model matters
How complex the model is
Other factors
Suggested tier
Answer the questions
Step 4b. Vendor and AI vendor contract checklist
The draft says you stay answerable for a model you buy (paragraph 45). It asks for due diligence before you buy (paragraph 47) and for set terms in the contract (paragraph 48). AI models bought from outside carry extra points (paragraphs 51, 53 and 56).
One checklist per vendor. Tick what is in place and note where the clause sits.
Type a vendor name to start.
Step 5. Report, save and export
"Print the report" opens your browser's print window. Choose "Save as PDF" there to get a PDF. The saved file is plain JSON. Load it on any computer to carry on.
When RBI issues the final guidance, BankPulse will update this page and mark what changed. The Daily Brief will carry it the same morning. Subscribe free to be told.