TL;DR
- What it is: Model risk management is the framework of governance, inventory, independent validation, and monitoring that keeps a bank’s decision-making models sound across their whole life.
- The core mechanic: Every model is owned, listed, independently checked, and watched for decay, so a failing model is caught by the institution before a regulator or a loss finds it.
- Who it applies to: The RBI’s draft guidance covers commercial banks, small finance and payments banks, cooperative banks, RRBs, all-India financial institutions, and NBFCs across every layer.
- Key dates: The RBI released its Draft Guidance on Regulatory Principles for Model Risk Management on 24 June 2026 (Press Release 2026-2027/528); public comments closed 24 July 2026.
- One caveat: This RBI guidance is a draft, with public comments closed 24 July 2026 and not yet finalized. Requirements below are what the draft proposes and could change before it is issued.
A credit scoring model approves loans every hour of every working day. It was validated once, at launch, eighteen months ago. Since then the borrower mix has shifted, a new product line has fed it data it never saw in training, and its accuracy has slipped by a few points a quarter. Nobody flagged it, because nobody owned the job of watching it. The approvals kept flowing. That gap between when a model starts making bad decisions and when someone notices is exactly what model risk management exists to close.
For Indian banks and NBFCs, that discipline is about to move from good practice to a supervisory expectation. The Reserve Bank of India released its Draft Guidance on Regulatory Principles for Model Risk Management in June 2026. This article explains what a model risk framework covers, what the RBI draft would add, and why AI and machine-learning models raise the stakes.
What model risk management controls before a lending decision goes out
Model risk management is the set of controls a financial institution uses to make sure the models behind its decisions are sound, documented, independently checked, and monitored over their whole life. It covers how a model is built, who approves it, how its outputs are validated, and how the institution catches the model when it starts to fail.
The reason it matters is that a model is not a fixed asset. It is an assumption about the world, encoded in math, and the world keeps changing. A collections model that ranked risk perfectly in 2024 can quietly misrank it in 2026 because incomes, product mixes, and repayment behavior have moved underneath it. Model risk management is the practice that treats every model as something to be governed, not something to be trusted and forgotten.
The RBI’s draft guidance treats more of your systems as models than you do
Most banks think of “models” as their credit scorecards and their fraud engines. The RBI draft defines the term far more widely. Under the draft, a model is any system that uses data and statistical, mathematical, economic, or AI and machine-learning techniques to produce results used in business decisions, and it applies “irrespective of whether the RE recognises them as models.”
That definition pulls in a lot of tools a bank runs today without calling them models: pricing spreadsheets, early-warning triggers, provisioning calculators, propensity scores bought from a vendor. The draft’s scope is equally broad on who it covers. It applies to eleven categories of regulated entities, including commercial banks, small finance banks, payments banks, regional rural banks, cooperative banks, all-India financial institutions, and NBFCs across every layer from Base to Upper.
So the first job for a risk team reading the draft is not to build new controls. It is to find every system that now counts as a model. Most institutions discover they have several times more than their inventory shows.
Three ways model risk turns into losses a regulator can see
The RBI draft names three sources of model risk, and each one shows up as a real loss in a lending book. What model risk actually is, and the specific points where it enters a lending book, is covered in depth in its own article.

Model error. The model is wrong on its own terms: flawed assumptions, a coding mistake, or incomplete data feeding it. A default-probability model trained on a benign credit cycle underprices risk when the cycle turns, and the book takes losses the pricing never accounted for.
Misapplication. The model is used for something it was never built to do. A scorecard designed for salaried borrowers gets pointed at self-employed applicants, and the decisions it produces are confident and wrong.
Time-suitability. The model was right and has gone stale. This is model drift, and it is the most common failure because it happens silently. Nothing breaks. The model keeps returning scores. They are just less accurate every month until someone measures them against outcomes.
A regulator reviewing a portfolio can see the results of all three in the numbers, even when the institution running the models cannot. That asymmetry is the case for taking model risk seriously before an examiner does.
The three controls every model risk framework rests on
A model risk framework, whether it follows the RBI draft or any other national supervisor’s rules, comes down to three controls working together.

A board-approved framework and one model inventory
Governance sits at the top. The board approves a written model risk policy that says who owns models, how they are classified by risk, and who signs off before one goes live. Underneath the policy is a single model inventory: one authoritative list of every model the institution runs, what it does, what data it uses, and who is responsible for it. Without the inventory, there is no way to know what needs validating, and no way to prove to a supervisor that the framework covers everything.
Independent validation that reaches decision-makers
Validation is the check that a model does what it claims, run by people who did not build it. Independence is the point. A team reviewing its own work will forgive its own shortcuts. Validation tests the model’s assumptions, its data, its performance on fresh cases, and its limits, then documents where it can and cannot be trusted. That documentation only earns its keep if the people making deployment decisions actually read it, which is why timely reporting matters as much as the testing itself.
Ongoing monitoring that catches drift first
Validation at launch is a snapshot. Monitoring is the film. It tracks a live model’s accuracy, stability, and inputs against thresholds, so that when performance decays the institution finds out from its own dashboard rather than from a rising default rate or a regulator’s question. Good monitoring turns model drift from a discovery into an alert.
What the RBI’s 2026 draft guidance adds to model risk management
The RBI draft would make several of these expectations explicit and specific for Indian regulated entities. The draft is out for public consultation, with comments closed on 24 July 2026, so it is not yet in force. On finalization it would supersede Chapter 3 of the 2002 Guidance Note on Credit Risk Management. The concrete requirements to plan for include:
- A board-approved MRMF covering all models, including AI and ML models. The framework is a board-level document, not a risk-team memo.
- Inventory or no deployment. “No model may be used, relied upon, or deployed unless it is part of the inventory.” The inventory becomes a gate, not a record.
- Independent validation of every model, including third-party models, with validation reports reaching decision-makers within three months of completion.
- Risk-based tiering that drives how intensely each model is validated and monitored, protected by an “anti-dilution rule” so a low complexity score cannot quietly downgrade a high-materiality model.
- Ten-year retention of decommissioned models and their documentation.
- Third-party accountability that does not transfer. An entity using a vendor model “remains fully accountable for its outcomes,” with contracts that include audit rights and exit arrangements.

For institutions preparing against the RBI’s model risk expectations specifically, our RBI model risk management resources go deeper on how each principle maps to day-to-day controls.
Why AI and ML models make model risk harder to contain
Traditional scorecards are hard enough to govern. AI and machine-learning models add failure modes that older frameworks were never designed to catch, and the RBI draft addresses them head-on. It names seven risk dimensions that AI models must be controlled for: explainability, hallucinations, bias and discriminatory outputs, overfitting, spurious correlations, output variability, and data risks.
Explainability is the one that bites hardest in lending. A regulator, or a rejected borrower, can ask why a decision was made. A model that cannot produce a clear, account-level reason for its output is a compliance problem regardless of how accurate it is on average. Bias is the second: a model can be accurate overall and still treat a protected group unfairly, and “the model said so” is not a defense.
For customer-facing AI, the draft goes further. It would require override, suspension, and deactivation controls, including kill-switch arrangements. It would require that customers are told they are dealing with an AI system, and given the option to switch to a human. It expects human-in-command oversight, whether human-in-the-loop or human-on-the-loop, so that an automated decision is never fully unowned. The theme across all seven dimensions is the same: an AI model has to be governed harder than the statistical model it replaces, not trusted more because it performs better.

Building a model risk framework that stays audit-ready
Meeting these expectations by hand does not scale. An institution with dozens of models cannot keep a spreadsheet inventory current, validate every model independently on schedule, retain a decade of documentation, and produce account-level explanations on demand, all through manual effort. This is where the model risk framework has to be operationalized in the platform that builds and runs the models.
A governed AI platform does this by design: every model lives in an inventory the moment it is created, every prediction carries an audit-grade explanation, every change runs through maker-checker approval, and the full lineage from data to decision is preserved in an immutable audit trail. The controls are enforced by the system rather than remembered by a person.
The payoff shows up in outcomes, not just compliance. A leading NBFC in India used iTuring’s approach to rank borrowers by risk and focus collections on the highest-risk segment. It saw a 116% improvement in collections and 86% predictive accuracy, with the model deployed in two weeks. The governance was not a tax on that result. It was what let the institution trust the model enough to act on it.
If your team is scoping a model risk framework against the RBI draft, book a working session with our data science team to map your model inventory and governance gaps against the draft’s principles.


