TL;DR

  • RBI’s June 2026 MRM draft guidance applies the same requirements across NBFC layers, per legal-commentary analysis of the draft. It does not create a separate track for NBFC-UL.
  • The added complexity for NBFC-UL comes from stacking that uniform draft on top of obligations NBFC-UL already carries under Scale-Based Regulation: capital adequacy, mandatory listing, enhanced governance, differential provisioning.
  • A model governance platform for NBFC-UL needs to configure for more stakeholders and more granular reporting, not for a different rulebook.
  • Practical configuration points covered: board and RMCB reporting granularity, post-listing SEBI LODR disclosure, asset-class-level segmentation for provisioning, and the capital-adequacy link for credit models feeding RWA.
  • The MRM draft is still a draft. The comment period closed July 24, 2026. It has not been finalized as a Master Direction.

NBFC-UL Compliance Teams Assume the MRM Draft Gets Stricter at Their Layer

Most NBFC-UL risk and compliance teams reading RBI’s June 2026 model risk management draft guidance make a reasonable assumption: because their entity carries the highest regulatory burden under Scale-Based Regulation, the new MRM requirements must scale up with it. Somewhere in the draft, they expect, there’s a heavier standard reserved for the Upper Layer.

There isn’t. At least not in the draft text itself.

That assumption matters because it shapes how compliance and technology teams plan for the new guidance. If NBFC-UL is expected to face a materially different MRM standard, the natural response is to wait for a layer-specific rulebook before configuring systems. That’s the wrong read of what’s actually in front of them, and it’s worth correcting before budgets and roadmaps get built around it.

RBI’s Draft Guidance Reads the Same Across Every NBFC Layer

RBI released its draft guidance on model risk management on June 24, 2026 (prid=63006). The comment period closed July 24, 2026. It remains a draft. It has not been issued as a Master Direction.

Per legal-commentary analysis of the draft, the text applies uniformly across all four NBFC layers: Base, Middle, Upper, and Top. No section of the draft calls out NBFC-UL specifically, and none of the commentary reviewed references Scale-Based Regulation within the draft’s own text. We have not independently verified this against RBI’s primary source document, and no specific section number is cited here because none has been confirmed.

The practical reading: if the draft is finalized as currently understood, an NBFC-UL entity and a Middle Layer NBFC would face the same model risk management expectations on paper. The difference in real-world compliance load comes from somewhere else entirely.

NBFC-UL Entities Already Carry Obligations Smaller NBFCs Don’t

iTuring.ai has covered the four-layer Scale-Based Regulation framework and its collections implications in a separate piece, so this section is a quick orientation rather than a full rebuild.

NBFC-UL classification is based on a standalone-assets threshold, reported by a single legal-commentary source as approximately ₹1,00,000 crore. We have not independently verified this figure against RBI’s own circular. The list is reviewed roughly every three years, and RBI publishes it annually. A secondary source from August 2026 puts the current list at roughly 17 entities; treat that count as directional rather than confirmed.

What’s stable and already in force, independent of the MRM draft:

  • Minimum 9% CET-1 capital ratio
  • Single-party and group exposure caps
  • Mandatory stock exchange listing within three years of classification
  • Differential, more conservative provisioning by asset class
  • Enhanced board composition and disclosure requirements
  • A minimum five-year retention period once classified into the layer

None of this comes from the MRM draft. All of it predates it.

The Real Complexity Is Stacking, Not a Separate Rulebook

Put those two facts together and the actual source of NBFC-UL’s added compliance load becomes clear. The MRM draft itself is uniform. The obligations an NBFC-UL entity already carries are not.

A Middle Layer NBFC implementing the same draft guidance answers to its own board and its regulator. An NBFC-UL entity implementing the identical guidance answers to its board, its Risk Management Committee, its capital-adequacy reporting chain, and, once listed, its stock exchange disclosure obligations, all reading off the same model governance trail.

The configuration challenge for NBFC-UL is real. It just isn’t the challenge most compliance teams are bracing for. It’s a stakeholder and reporting-granularity problem sitting on top of a uniform standard.

Infographic illustrating how the uniform Model Risk Management draft applies to all NBFCs, with additional obligations for NBFC-UL, including capital adequacy, mandatory listing, differential provisioning, and enhanced governance.

What Changes in Board and Risk Committee Reporting at This Layer

Enhanced board composition and disclosure requirements at NBFC-UL stack directly with RMCB reporting duties covered elsewhere in this series, so this section flags the change rather than re-teaching the underlying obligation.

The model governance trail itself doesn’t need to be different at NBFC-UL. What changes is who reads it and how often. A larger, more specialized board and a formally constituted Risk Management Committee expect model performance, drift, and override data presented at a level of granularity that a smaller NBFC’s leadership team may not require. The audit trail is the same artifact. The reporting views built on top of it need to serve more stakeholders, more frequently, at finer detail.

Listing Brings a Second Disclosure Audience Into the Same Model Governance Trail

Mandatory stock exchange listing within three years introduces an audience that has nothing to do with RBI at all. Once listed, an NBFC-UL entity falls under SEBI’s Listing Obligations and Disclosure Requirements, which carry their own materiality and disclosure standards for governance-related events, including model failures or overrides significant enough to matter to investors.

This is a genuine configuration consideration for a model governance platform. RBI’s MRM guidance itself doesn’t require it. A model inventory and audit trail built to satisfy a bank regulator wasn’t necessarily built to also satisfy a securities regulator’s disclosure timelines. NBFC-UL entities need both audiences served from the same underlying record.

Differential Provisioning Means Reporting Needs Asset-Class Segmentation

NBFC-UL’s more conservative, asset-class-differentiated provisioning requirements have a direct downstream effect on model reporting. A credit or collections model feeding into provisioning decisions needs to report performance, drift, and override rates broken out by asset class, rather than as a single aggregate figure.

A Base or Middle Layer NBFC without differential provisioning obligations may reasonably report at a portfolio level. An NBFC-UL entity needs the same underlying model governance data cut finer, because the provisioning consequence downstream is itself asset-class-specific.

Capital-Adequacy Exposure Changes What a Model Failure Costs at This Layer

This is a reasoned inference connecting two confirmed facts. RBI has not stated this as a requirement.

NBFC-UL entities must maintain a minimum 9% CET-1 capital ratio. Credit-risk models directly influence how exposures are classified and weighted, which in turn feeds risk-weighted asset calculations. Put those two facts together, and a credit model error at an NBFC-UL entity carries a capital-adequacy consequence that a smaller-layer NBFC, without the same capital ratio obligation, doesn’t face with the same intensity. A drifting or miscalibrated model isn’t just a model problem at this layer. It has a line back to the capital ratio the board is required to maintain.

Configuring Model Governance for the Layers That Actually Apply to You

A model risk management platform for NBFC-UL needs the same governance framework as any other layer, configured for more stakeholders and finer-grained reporting.

iTuring’s Model Governance module is built around three components: a full model inventory, an immutable audit trail, and maker-checker approval workflows. The design intent behind all three is configurability, not a fixed reporting template. For an NBFC-UL entity, that means:

  • Board and RMCB reporting configured for the enhanced governance structure covered above, with drill-down views for committees that need more than a summary.
  • SEBI LODR-aligned disclosure views available once listing obligations apply, drawing from the same underlying audit trail rather than a separate system.
  • Asset-class segmentation built into reporting so provisioning teams get the breakdown differential provisioning actually requires.

This same governance layer already runs across 16 banks and insurers, with more than 200 use cases in production, which is the relevant proof point for configurability at this scale. It’s an existing, audited system, already proven at scale, being tuned to a specific layer’s stakeholder set. The platform is SOC 2 Type II and ISO 27001 certified, which matters directly here: an immutable audit trail is only as credible as the controls environment it sits inside.

Infographic showing NBFC-UL configuration changes, including audit trail granularity, maker-checker approval routing, and stakeholder reporting views triggered by board disclosure, SEBI LODR, and asset-class segmentation.