TL;DR
- RBI’s June 2026 draft guidance on model risk management names three factors for risk tiering: materiality, complexity, and extent of reliance and autonomy. The draft does not prescribe a scoring method or weighting.
- NBFCs and banks need to build their own tiering methodology using these three inputs. Waiting for a final rule before starting means starting late.
- The same underlying model architecture can land in different risk tiers depending on the use case it drives. Credit decisioning and collections scoring built on the same base model can carry different oversight requirements.
- Model Governance infrastructure (audit trail, maker-checker approval, model inventory) supports whatever tiering methodology an institution builds. It does not auto-assign tiers, because RBI has not published a method to encode.
A model risk officer at an NBFC gets asked by an examiner which of the institution’s forty deployed models get the deepest scrutiny. There is no RBI-published answer yet, only three named inputs and a deadline that keeps moving.
The Three Factors RBI’s Draft Actually Names
RBI’s June 24, 2026 draft guidance (“Guidance on Regulatory Principles for Model Risk Management,” press release prid=63006) names three factors for tiering model risk: materiality (how much the model’s output affects a customer-facing or capital decision), complexity (how opaque the model’s internal logic is to a human reviewer), and extent of reliance and autonomy (how much a human still checks the model’s output before it acts). The draft’s comment period closed July 24, 2026. It has not been finalized and is not a Master Direction, at least not yet. An anti-dilution rule appears in the draft text: an institution cannot lower a model’s tier by splitting a single automated decision across multiple smaller models.

What RBI Names as Inputs, and What It Leaves for NBFCs to Build
The draft names three inputs. It does not name a scoring rubric, a weighting formula, or a minimum number of tiers. The regulation has a gap here, and that gap does not remove the institution’s obligation to answer for it. An examiner will still ask which models get more frequent revalidation and tighter change control, even before the guidance finalizes. Institutions that wait for the final text to start building a methodology will be building it under exam pressure instead of on their own schedule.
Why the Same Model Can Sit in Different Tiers
A single base model architecture, for example a gradient-boosted tree trained on repayment history, can plug into more than one use case. This is a reasoned inference from the three named factors, not RBI guidance: the same architecture used for credit decisioning likely sits in a higher tier than the same architecture used for churn scoring on deposit accounts, because credit decisioning carries higher materiality (it gates access to credit) and often lower human override (approval workflows increasingly run on autonomous thresholds). Collections recovery scoring sits in the middle. Fraud detection models, despite high autonomy, may carry lower materiality per single decision but higher aggregate exposure across a portfolio. RBI has not confirmed this inference. Institutions should treat it as a working hypothesis to test against their own risk committee’s judgment, not a rule to cite in an exam.

How Other Regulators Have Handled This Same Gap
US banking regulators faced a similar gap in 2011. SR 11-7, the Federal Reserve and OCC’s supervisory guidance on model risk management, introduced a materiality and complexity-based tiering approach for US banks. SR 11-7 is US supervisory guidance. It does not apply to Indian NBFCs or banks. It’s referenced here only as an example of how another regulator handled a comparable gap between named risk factors and a prescribed scoring method, more than a decade before RBI’s draft.
How Model Governance Supports a Tiering Methodology You Build
Model Governance does not auto-assign a model to a risk tier. RBI has not published a scoring method to encode, and building a proprietary auto-tiering algorithm ahead of the final guidance risks having to re-tier every model once the rule lands. What Model Governance does provide: an immutable audit trail logging every model version, approval, and retraining event; maker-checker approval workflows that route higher-risk model changes through a second reviewer before deployment; and a model inventory that lets a risk team tag each model with its institution-assigned tier and revalidation cadence, then produce that tagging on demand for an examiner. The institution decides the tiering methodology. Model Governance makes that methodology auditable and enforceable across every model in production.
That’s what a model risk tiering framework needs from software: not the scoring logic, since RBI hasn’t published one, but the infrastructure to run whatever logic the institution designs and prove it held on every model, every time.
iTuring’s Model Governance module is live across 16 banks and insurers today, supporting 200+ use cases already in production, including institutions running multi-tier model inventories ahead of RBI’s guidance finalizing.
What to Document Before an Examiner Asks
Four items worth having ready regardless of when the draft finalizes: a written tiering rubric mapping the three RBI-named factors to your institution’s own scoring scale, a model inventory tagged against that rubric, a record of who approved each model’s current tier assignment, and a revalidation schedule tied to tier rather than a fixed calendar date for every model.
The Methodology Is Yours to Build, Regardless of When the Draft Finalizes
RBI has named the inputs and left the method to the institution. NBFCs and banks that treat this as a reason to wait will end up building a tiering methodology under exam pressure. Those that start now, using the three named factors and infrastructure that makes the resulting methodology auditable, will have already answered the examiner’s question by the time it’s asked.


