RBIGuidancemedium

Unknown Sponsor Bank

The Reserve Bank of India (RBI) published draft guidance redefining the scope of third-party risk for banks operating in India. Under the proposed framework, banks would be held accountable for all AI models used in their operations, including those licensed from third-party vendors. Rather than relying on vendor certifications, banks would need to independently validate third-party models. The guidance also requires that contracts with technology vendors provide technical documentation, audit rights, and exit/continuity terms. This has significant implications for fintech partnerships and BaaS-style arrangements in the Indian market, where banks increasingly rely on vendor-supplied AI for lending, risk, and compliance functions.

Verified from source: RBI's draft Guidance on Regulatory Principles for Model Risk Management, 2026 makes banks accountable for all AI models used, including vendor-licensed systems. Banks must validate third-party models independently, as vendors cannot certify compliance, and existing contracts often lack necessary documentation and audit rights.

Implications
  1. Banks using third-party fintech or AI vendors must build independent model validation capabilities
  2. BaaS and embedded finance providers may face stricter contractual requirements from Indian bank partners
  3. Sets a potential precedent for other regulators considering similar third-party AI accountability frameworks
Source
Related
Share