RBI wants a register of every model you run. Where is your model inventory?
On 24 June, a draft from Mint Road asked for exactly that. A peer note on the distance between using AI — and being able to account for it.
Most AI programmes in Indian banking run the same script. A GenAI centre of excellence gets named. Copilots go to relationship managers. A chatbot takes tier-one queries. A vendor demo becomes a pilot. The pilot becomes a dashboard. The dashboard reports adoption to the board.
By the second quarter, it looks like progress.
Then.
On 24 June 2026, the RBI released its draft guidance on model risk management. A short document with long consequences. It covers every model a regulated entity uses. Third-party models included. AI and machine learning included, by name. It expects a central register: a model not on the register is not to be used. Retired models stay on it for ten years. Validation must be independent of the people who built the model. And every AI system needs a tested way to shut it off — the draft’s own words include “kill-switch arrangements”. Comments close on 24 July.
The draft doesn’t stand alone. FREE-AI arrived in August 2025: board-approved AI policies, AI disclosures in annual reports, human authority over AI decisions. The Digital Lending Directions made your collections bot legally you. SEBI and IRDAI are moving the same way.
RBI draft guidance · 24 Jun 2026 · FREE-AI · Aug 2025
The board question changed. Not what can AI do? — where is the list?
Walk the floor of most institutions and count what is actually live. A dozen pilots. A chatbot. Perhaps one system in production. That gap looks like an adoption problem. It isn’t. A pilot needs a sponsor and a sandbox. A production system needs an owner, a data lineage, a validation cycle, an audit trail and a rollback path. That list is exactly what the draft now asks you to show.
India’s banks don’t have an AI adoption gap. They have an AI governance gap. And the regulator is writing the audit script for it.
One line in the draft deserves a slow read. A model is anything that turns inputs into a business decision. Read strictly, that includes the credit spreadsheet your team has trusted for a decade. Most institutions have never made that list. Now it has a deadline.
Two engagements taught us what survives a regulated environment.
A consumer-lending NBFC.
Credit, fraud and collections decided continuously, on a live book. We were hired for models. The real work was the foundation. Twenty integrations became five. The data layer was rebuilt live, without stopping the book. Then the models went on top. Three years in production. About 30% cheaper to run. And every decision routes through one engine — which is what makes the book auditable. The register isn’t a project there. It’s an export.
A large private-sector bank.
GenAI unit testing across a core-banking SDLC — about 4,500 engineers. Week one: senior developers rejected twelve of our first fifteen generated tests. Technically valid, functionally useless. The model knew code. It didn’t know banking. We fixed that by capturing the bank’s own domain rules into oracle packs. And the CISO’s office sat in from week one. Governance as design — not a gate at the end.
Different problems. Same finding: what made AI production-grade wasn’t the model. It was the substrate — data, lineage, validation, ownership — built before scale, not after.
Governance isn’t the brake. It’s the substrate.
The standard objection says regulation will slow AI down. The evidence runs the other way. FREE-AI carries an enabling half most commentary skips: a sectoral sandbox, shared data infrastructure, tolerance for good-faith failures. And watch the leaders. HDFC built Neev — its own GenAI platform, governance inside — and reported its first workforce reduction in nine years, framed as AI redeployment. Axis runs AXIOM, aiming AI at 40–50% of operational journeys within eighteen months. SBI’s technology head said it plainly: the challenge is execution, not experimentation.
A kill-switch you can’t locate is a policy. A kill-switch you can test is a control.
Most institutions bought governance as a document. The draft describes something else: a living register, tiered validation, override paths that actually work. A document can’t produce that. Only a working system can.
The playbook that closes the gap runs four steps, in order. Each proven in the field.
01
Inventory before intelligence.
One register of every model and agent — owner, risk tier, override path. The RBI’s list becomes an export, not a project.
Proven at a regulated services company
02
The data layer is the product.
Decisions are only as auditable as the pipes that feed them. Foundation first. Models second.
Proven in a regulated lending book
03
Measure the workflow, not the task.
Real journeys, timed before and after, quality scored blind. Task wins that never reach the cost-income line keep programmes stuck.
Proven across sectors
04
Capability as compliance.
FREE-AI makes board and workforce capacity a pillar. Short, timed reps on your own cases — until the governed way is the default way.
Proven across sectors
The first ninety days are concrete. Weeks one to three: surface every model — including the ones inside SaaS tools nobody bought as AI. Weeks four to eight: stand up the register. Give the top-tier models tested override paths. Instrument one workflow end to end. Weeks nine to twelve: ship one governed use case, and print the board pack from the register. None of this waits for the final circular.
After that, the register question takes minutes. New use cases inherit controls instead of negotiating them. Vendor models carry the same accountability as home-built ones.
The leaders aren’t piloting more. They’re rewiring.
If the copilots are live and an inspection sits somewhere on the calendar, one question is worth an hour this week. Could you produce your model register in 48 hours — and show the override path on any entry in it?
That’s a design decision. The next inspection will grade it.
Happy to compare notes — no agenda beyond it. The people I learn most from are running the same problem on their own book.