TL;DR

  • RBI released draft guidance on model risk management on June 24, 2026, open for public comment until July 24, 2026. It is not yet final. Its scope, covering all models across ten categories of regulated entities including NBFCs, signals where enforcement is headed.
  • The draft asks for a model inventory with risk tiering, independent validation that a regulated entity cannot outsource to a vendor certificate, board-level sign-off on high-risk models, and compensating controls for black-box models used in material decisions.
  • No effective date is specified in the draft. That is not a reason to wait. The underlying capability, inventory, validation workflow, audit trail, takes months to build regardless of when the rule lands.
  • iTuring’s Model Governance module, built around an immutable audit trail and maker-checker approval, maps directly to the inventory, validation-trail, and board-oversight elements the draft describes.

An NBFC’s model inventory usually lives in three places at once: a spreadsheet the risk team maintains, a vendor scorecard from whichever bureau or fintech partner supplied a scoring model, and someone’s memory of what is actually running in production this quarter. Ask that team to produce a validation trail for one specific model, on a specific date, and watch how long it takes to answer. This is not a hypothetical compliance exercise. It is the exact gap RBI’s latest draft guidance is aimed at.

RBI’s June 2026 Draft Guidance, and What Actually Changed From the 2024 Circular

In August 2024, RBI circulated a draft titled Regulatory Principles for Management of Model Risks in Credit. It covered credit models specifically and was never finalized. On June 24, 2026, RBI released a broader successor, the Guidance on Regulatory Principles for Model Risk Management, confirmed through RBI’s own press release. This version drops the credit-only limitation. It covers all models, and it extends across ten categories of regulated entities, with NBFCs confirmed as one of them.

This is a draft. It is open for public comment until July 24, 2026. It has not been issued as a Master Direction, and RBI has not attached a compliance effective date to it. Treat both of those facts as true and treat the direction of travel as the signal that matters more. Regulators rarely narrow scope between a draft and a final version. The scope in June 2026 is wider than the scope in August 2024, and that pattern is the one to plan around, not the absence of a deadline.

The Five Requirements NBFC Model Risk Teams Need to Solve For

Secondary legal and advisory summaries of the draft converge on five capability areas. None of the following should be read as a verbatim quote from RBI. It is a practitioner’s translation of what the draft is asking regulated entities to be able to do.

  1. Model inventory and risk-tiering. Every model in production, tiered by risk, and this includes spreadsheet-based scoring tools, not only AI and machine learning models.
  2. Independent model validation. A vendor’s own certification of its model does not discharge the entity’s obligation to validate it independently.
  3. Board-approved MRM framework. High-risk models are expected to get sign-off from the Risk Management Committee of the Board, not just a risk team’s internal review.
  4. Explainability and compensating controls. Black-box models driving material decisions, credit underwriting being the clearest example, are expected to carry compensating controls such as restriction or enhanced monitoring, along with bias and fairness testing on credit outcomes.
  5. Human-in-the-loop and escalation. Kill-switch mechanisms, periodic review, and for customer-facing AI such as chatbots and voice bots, disclosure, red-teaming, and hallucination controls.

What RBI Model Risk Management Framework Software Actually Has to Do

Reading the draft as an operational spec rather than a legal text, RBI model risk management framework software needs to do four things well.

  • Model inventory that reconciles itself. Every model in production, captured and tiered by risk, without a quarterly manual reconciliation across spreadsheets and vendor portals.
  • Maker-checker approval workflow. No model reaches production without a second, independent sign-off. This is the operational form the draft’s independent-validation principle takes in practice.
  • Immutable audit trail per model, per decision. A validation history that can be produced on demand, rather than reconstructed after the fact from emails and meeting notes. This is iTuring’s own operationalization of the explainability principle in the draft. It is not a quoted RBI requirement.
  • Structured escalation to the Risk Management Committee. High-risk models route to a defined committee review, not an email thread that may or may not reach the board.

This is exactly what iTuring’s Model Governance module is built to do: an immutable audit trail, maker-checker approval built into the workflow rather than bolted on, and risk-tiered visibility that gives a Risk Management Committee something concrete to review rather than a status update.

Why Vendor Certification Alone Doesn’t Satisfy the Draft’s Validation Bar

iTuring.ai holds SOC 2 Type II and ISO 27001 certification. Neither of those certifications, on their own, satisfies an NBFC’s own independent validation obligation under the draft, and it would be wrong to imply otherwise. They are evidence of platform-level control: how data is handled, how access is governed, how the infrastructure is secured. The regulated entity still owns the obligation to independently validate the models it deploys on top of that infrastructure. Treat certifications as supporting evidence inside a validation program the NBFC’s own risk function runs. Certification does not substitute for running that program.

What Operating This at Scale Looks Like

Sixteen banks and insurers currently run live on iTuring, across 200-plus use cases in production. That is a working answer to the question of whether a governed model inventory can operate at scale rather than only on a whiteboard. Models on the platform reach production 97% faster than legacy deployment cycles, and that speed comes from the governance workflow being built into deployment. Skipping that workflow isn’t what makes a maker-checker gate fast, structure is.

A Practical Starting Checklist Before the Comment Period Closes

  • Inventory every model in production, including spreadsheet-based scoring tools, not just AI and machine learning models.
  • Tier that inventory by risk, with a defined method for what makes a model high-risk.
  • Document validation independently of any vendor sign-off already on file.
  • Give the Risk Management Committee of the Board visibility into high-risk models specifically, not a general model-portfolio summary.
  • Start building the audit trail now, so a validation history exists before anyone asks for one.

The Calendar Is Unsettled. The Capability Gap Isn’t.

The draft may still change before it is finalized. The comment period runs until July 24, 2026, and RBI could adjust scope, thresholds, or timelines in response. What is unlikely to change is the underlying gap the draft is naming: NBFCs that cannot produce a model inventory, an independent validation trail, and board-level visibility into high-risk models on demand. Building that capability now is a lower-risk bet than waiting for a final date that is not on the calendar yet.