TL;DR
- RBI’s June 2026 draft guidance does not set one fixed revalidation number for NBFCs.
- It requires validation at four points: before deployment, after deployment, after any modification, and on defined internal or external triggers.
- The one hard number in the draft is that model risk tier must be reassessed at least annually.
- Everything else, including exact validation frequency, is left to each NBFC’s own board-approved Model Risk Management Framework.
- An earlier 2024 draft on credit models had set a flat “at least yearly” validation floor, a simpler standard than the 2026 draft’s risk-tiered approach.
- Validation reports must reach the Risk Management Committee of the Board within three months of completion.
RBI Has Not Set One Number for Model Revalidation Frequency
If you searched for this because a risk committee member asked “how often does RBI actually require us to revalidate,” the honest answer is that RBI has not published a single number.
The Reserve Bank of India released draft guidance on model risk management on June 24, 2026 (prid=63006). The comment period closed July 24, 2026. The draft has not been finalized into a Master Direction, and NBFCs should treat it as directional rather than binding for now.
What the draft does specify is a structure: validation must happen at four defined points, and model risk tiers must be reassessed at least once a year. Beyond that floor, the draft hands responsibility for setting exact revalidation cadence to each NBFC’s own board-approved Model Risk Management Framework, or MRMF. RBI is prescribing a governance discipline and asking each entity to build the calendar itself, then defend it.
This matters for how you plan. If you are looking for a table that says “Tier 1 models: quarterly, Tier 2 models: semi-annual,” that table does not exist in the draft. What exists is an expectation that your framework produces one, and that you can show your work.
The Four Points at Which RBI’s Draft Requires Validation
The draft is specific about when validation is mandatory, even where it is silent on frequency. Four triggers appear:
- Prior to deployment. Before a model goes live, it must be validated against its intended use, data lineage, and performance expectations.
- After deployment. A post-implementation check confirms the model behaves in production as it did in testing.
- Following any modification. Any change to a model’s logic, features, scoring thresholds, or underlying data pipeline requires revalidation before that change is considered complete.
- On defined internal or external triggers. This covers events such as performance degradation, a shift in the population the model scores, a regulatory change, or a new risk factor emerging in the portfolio.
A fifth layer sits alongside these four: periodic revalidation as defined in the entity’s own board-approved MRMF. The draft treats this as the mechanism that ties the other four together into an ongoing schedule.

Model Risk Tiers Must Be Reassessed at Least Annually
Here is the one number in the draft that is fixed: model risk tiers must be reassessed at least annually.
Risk tiering is the mechanism the draft uses to scale validation intensity. A model classified as high risk, because of its materiality to lending decisions, its portfolio exposure, or its complexity, should reasonably be validated more often and more rigorously than a low-risk model used for a narrow, low-stakes purpose. The draft does not publish a numeric table mapping tier to cadence. It leaves that mapping to the entity’s MRMF.
What it does fix is the reassessment clock on the tier itself. An NBFC cannot set a model’s risk tier once and leave it there. At least once a year, the tier itself has to be reassessed and, if warranted, changed, which would then change how often that model gets revalidated going forward.
This is a subtle but important distinction. The annual requirement in the 2026 draft governs how often the tier gets reassessed. It says nothing about validating every model itself on a fixed yearly schedule. A high-tier model might require validation more than once a year under your own MRMF. A low-tier model might validate on a longer cycle. The tier itself gets checked annually regardless.
Trigger-Based Revalidation Covers Material Changes and Performance Drift
Two categories of triggers deserve closer attention because they are the ones most likely to catch a model risk team off guard.
Material changes. Any material change to a model, whether that is a retrained scoring algorithm, a new data source feeding the model, or a change in the population it scores, requires a documented impact assessment and revalidation before that change is treated as production-ready. The draft does not define a numeric threshold for what counts as “material.” That determination is left to the entity, which means your MRMF needs its own working definition of materiality, documented and defensible, rather than a judgment call made informally each time a change comes up.
Performance drift. Degradation in model performance or a detectable shift in the behavior the model is scoring should trigger a review. Again, no specific drift threshold, such as a defined drop in AUC or a specific PSI value, is quantified in the draft. The entity sets its own bar.
What is fixed is the reporting clock once a validation is complete. Validation reports must reach the Risk Management Committee of the Board within three months of completion. This is a real deadline, and it means the underlying documentation, the impact assessment, the validation methodology, and the sign-off trail all need to exist in a form the Board can review inside that window, ready ahead of time rather than reconstructed under pressure.
How the 2024 Credit Risk Draft Compared to the 2026 MRM Draft
This is not RBI’s first attempt at addressing model validation frequency, and the comparison is instructive.
On August 5, 2024, RBI circulated an earlier draft, “Management of Model Risk in Credit,” aimed specifically at credit models. That draft set a much simpler, explicit numeric floor: models had to be validated before deployment, after any material amendment, and on a periodic basis of at least once a year. NBFCs were given six months to bring existing models into compliance with that standard.
The 2026 draft moves away from that flat annual floor and replaces it with a risk-tiered, MRMF-defined approach. The only fixed number carried forward is the annual reassessment of risk tier, a narrower requirement than the 2024 draft’s blanket annual validation standard for every model.
To be clear about what is and is not confirmed: whether the 2026 draft supersedes the 2024 circular, narrows its scope, or is meant to sit alongside it for non-credit models, has not been stated explicitly by RBI. This is an inference based on the structure and timing of the two documents, best treated as a working assumption rather than a confirmed regulatory position. NBFCs that built compliance programs around the 2024 circular’s flat annual standard should treat the 2026 draft as a signal to revisit that approach, while watching for RBI’s final language before making structural changes.

Why the Federal Reserve’s SR 11-7 Standard Is Relevant Context, Not a Rule for Indian NBFCs
Risk teams building out an MRMF often look to established international standards for structure, and the most commonly referenced one is the US Federal Reserve and OCC’s SR 11-7 guidance on model risk management.
SR 11-7 requires periodic review of models at least annually, but more frequently if warranted by the model’s materiality, complexity, or performance history. That “at least annually, scaled to risk” language has clearly influenced how model risk frameworks are written globally, and the structural similarity to RBI’s 2026 draft is worth noting.
SR 11-7 is US Federal Reserve and OCC guidance. It has no legal or regulatory force in India and does not apply to Indian NBFCs. It is useful as comparative precedent when designing an MRMF, particularly for institutions building a framework from scratch, and it should never be cited to a regulator or auditor as the basis for an NBFC’s validation cadence in India.
Building a Revalidation Calendar Inside Your Board-Approved MRMF
Given that RBI has set a structure rather than a schedule, the practical work falls on each NBFC to translate that structure into an actual calendar. A defensible MRMF, at minimum, needs to produce:
- A risk tier assignment for every model in the inventory, with the criteria used to assign that tier documented and reviewable.
- A validation cadence tied to each tier, set by the entity, applied consistently, and revisited whenever the tier changes.
- A documented materiality threshold for what counts as a change requiring revalidation, so this decision does not get made ad hoc each time a model is touched.
- A defined trigger list for performance drift, population shift, and external events, with owners assigned to monitor each one.
- An annual tier reassessment process, scheduled and tracked, not left to informal review.
- A reporting path to the Risk Management Committee of the Board that can produce a complete validation report inside the three-month window.
The common failure point is not designing this structure. It is maintaining it across a growing model inventory without a system tracking which model is due for what, and on what basis.
How Model Governance Tracks Revalidation Schedules and Produces Audit-Ready Evidence
This is precisely the gap iTuring’s Model Governance module is built to close.
Model Governance maintains a full model inventory with each model’s risk tier, deployment date, last validation date, and next scheduled revalidation visible in one place. Revalidation scheduling and tracking is built into the module, so a model due for its annual tier reassessment, or flagged by a performance trigger, surfaces automatically rather than depending on someone remembering to check a spreadsheet.
Every revalidation runs through maker-checker approval, meaning no model is marked revalidated without a second, independent sign-off recorded against it. That sign-off, along with the validation methodology and results, is written into an immutable audit trail, which is the evidence a Risk Management Committee needs to review inside its three-month reporting window without a scramble to reconstruct what happened and when.
Model Governance is in use across 16 banks and insurers running 200 or more live use cases, with revalidation and deployment workflows built around RBI’s MRM expectations from the outset. The module reaches production 97% faster than typical build timelines, and operates under SOC 2 Type II and ISO 27001 certification, which matters directly here: the same audit trail infrastructure that supports those certifications is what produces the evidence trail your Board and your examiners will ask to see.
What This Means for Your Next Board Reporting Cycle
Before your next Risk Management Committee meeting, have three things ready: a current model inventory with risk tiers and last-validation dates attached, a documented rationale for your tier assignments and materiality thresholds, and evidence that any trigger-based revalidation in the past quarter reached the Board within three months of completion.
None of this requires waiting for RBI to finalize the 2026 draft. The structure it describes, tiering, four validation points, an annual reassessment floor, and a three-month reporting clock, is a reasonable standard to build toward now, both because it is likely to resemble the final Master Direction and because it is simply sound model risk practice regardless of how the draft language settles.


