A practitioner’s read on what the Draft Guidance is really regulating, how it measures up against the EU, the US, and Singapore, and the frontier it now has a chance to lead on.

On the surface, the Reserve Bank of India’s Draft Guidance on Regulatory Principles for Model Risk Management, 2026 reads like a model risk update, the kind of document that lands with risk teams and gradually reshapes an internal policy manual. Look a little closer, though, and it is doing something broader than that title suggests. What RBI has put out is one of India’s first substantive attempts at AI governance and security regulation for the financial sector, covering not just how models are validated but how they can be attacked, manipulated, and misused.

That distinction is the eye-opener. A model risk document asks whether a system performs accurately. A governance and security document asks whether that system can be hallucinated into giving wrong advice, prompt-injected into leaking data, drifted into bias, or manipulated by an adversary who understands exactly how it makes decisions. RBI’s Draft Guidance asks all of these questions in the same breath as accuracy and validation, and that is the part of the document that deserves far more attention than it has received.

We know this territory because we work in it. Melento builds the compliance automation, contract lifecycle, and AI-enabled workflow systems that regulated financial institutions run on, and we made a formal submission to RBI on this Draft Guidance. What follows is not a summary of that submission. It is our read on what the Guidance is actually aimed at, how it stacks up against what regulators elsewhere have already done, and where we think India has an opening to lead rather than follow.

What the Guidance Is Actually Targeting

Strip the Draft Guidance down to its mechanics, and it is targeting three things at once, not one.

The first is scope, defined deliberately wide. RBI has defined “model” broadly enough to catch machine learning systems, generative AI, rule-based engines, algorithms, and even spreadsheets and decision-support tools, provided they materially influence a business decision. This is a regulator closing a loophole before institutions find it: consequential decisions quietly running through tools that were never built, tested, or documented like a model, precisely because nobody called them one.

The second is the accountability chain, not the technology. Whether a system was built in-house or licensed from a vendor, the Guidance places responsibility with the regulated entity. That includes foundation models and proprietary AI services where the institution has no access to architecture, training data, or weights. RBI is not asking institutions to understand every layer of a vendor’s model. It is asking them to own the consequences of using it anyway, through contractual controls, integration testing and ongoing monitoring.

The third, and the one most easily missed, is the security perimeter around the model rather than the model itself. Explainability, fairness, hallucinations, prompt injection, adversarial manipulation, and model drift sit in the same clause as validation and monitoring. That is a regulator treating an AI system the way a security team would: as something with an attack surface, not just an error rate. Very few model risk frameworks anywhere have historically done that. This one does, and it does it early.

Put together, the target is not “models”. It is any point where an automated system touches a customer, a decision, or a regulator’s ability to reconstruct what happened afterward. And the evidence an institution can produce to prove it was governed the whole way through.

Where India Sits Against What the Rest of the World Has Already Done

RBI is not writing on a blank page, and seeing where it sits against three live 2026 approaches is what makes this genuinely interesting rather than another compliance memo.

The European Union has gone furthest toward binding law. Under the EU AI Act, AI systems used to evaluate the creditworthiness of natural persons are explicitly classified as high-risk, triggering documented risk management, data governance, automatic logging, transparency, and human-oversight obligations, backed by a conformity assessment before deployment. New high-risk systems had to be compliant by August 2026, with legacy systems given until February 2027, backed by penalties denominated in real numbers. It is a regime built for enforcement first. The United States has just made a very different choice, and it is the most telling data point of the three.

In April 2026, the Federal Reserve, the OCC and the FDIC replaced their fifteen-year-old model risk guidance with SR 26-2 and deliberately placed generative AI and agentic AI outside its formal scope, describing them as too novel and fast-moving to regulate through a fixed rulebook.

American banks are now governing their fastest-growing AI systems without a shared supervisory template, at exactly the moment those systems are scaling the most. Singapore has taken a third path: principles first, tooling second.

The Monetary Authority of Singapore built its Fairness, Ethics, Accountability and Transparency principles back in 2018, then spent years turning them into the Veritas initiative, an open-source toolkit with shared fairness metrics and assessment methodologies.

Its newer AI Risk Management Guidelines extend that proportional, full-lifecycle approach to generative and agentic AI directly. Set against these three, here is the eye-opener: RBI’s Draft Guidance chose to bring generative AI, RAG systems and autonomous agents inside the perimeter from the outset, rather than carving them out the way the world’s largest banking regulator did four months earlier.

India is not playing catch-up here. On this specific point, it is ahead of the United States, and closer in spirit to Singapore’s inclusive, full-lifecycle stance than most coverage of the Draft Guidance has given it credit for.

The Frontier RBI Now Has a Chance to Lead

Being broader in scope than the US and more inclusive than most peer frameworks puts India in a genuinely strong starting position. What happens next is where the real opportunity sits, and it is the same opportunity every regulator in this space is currently racing to seize, not a shortcoming unique to this draft.

The first frontier is turning principle into a shared operating rhythm. Every framework we looked at, including RBI’s, eventually has to answer the same practical question: what does “governed” look like on a Tuesday afternoon, when a supervisor asks for evidence rather than intent? Singapore answered this by building a shared toolkit alongside its principles.

RBI has the chance to do something similar for the Indian market, and given how many institutions across the sector would benefit from a common measurement layer for explanability and fairness rather than each building its own, this is a genuine opening rather than a gap to be filled defensively.

The second frontier is workflow-level risk, and this is the newest and most interesting problem in AI governance globally, not a flaw in any one country’s drafting. A generative model drafting a credit memo that a human then approves inside a separate, older scoring model creates a risk pathway that belongs to neither system on its own.

Researchers studying the US’s own SR 26-2 are actively building control frameworks to address exactly this, months after that guidance was finalised. RBI is drafting at a moment when this problem is already visible elsewhere, which means India has the rare advantage of designing for it directly rather than discovering it after the fact, the way other markets currently are.

The third is timing and consequence, and here the opportunity is simply sequencing. The EU’s deadlines and enforcement structure show what the mature end state can look like once an ecosystem is ready for it. RBI has chosen, wisely in our view, to start from principles and proportionality rather than immediately importing that machinery.

It is worth flagging now, while the draft is open for comment, that institutions will move faster and more confidently once a clear runway with defined milestones exists. That is a natural next step for the Guidance to build toward, not a missing piece today.

Key Takeaways for CXOs and Decision-Makers

  • Treat this as an enterprise governance issue, not a technology project. AI risk now touches legal, compliance, information security, operations, and customer experience. Assign ownership accordingly and distribute it well. 
  • Treat this as an enterprise governance issue, not a technology project. AI risk now touches legal, compliance, information security, operations, and customer experience. Assign ownership accordingly and distribute it well.
  • Build a risk-tiering exercise into your model inventory now. Not every AI use case warrants the same level of scrutiny. A defensible framework classifies systems by the consequence of failure, not by whether the word “AI” applies.
  • Read this as security regulation, not a compliance memo. Prompt injection, adversarial manipulation, and hallucination sit alongside validation and monitoring in this Guidance. Assign ownership to security and risk jointly, not to a model validation team alone.
  • Recognise the head start you are working with. India’s inclusive scope, covering generative and agentic AI from day one, puts institutions ahead of peers in markets like the US that are still governing these systems without a shared template.
  • Map workflow-level risk while it is still a frontier problem, not a catch-up exercise. Trace every point where an AI output feeds into another model or decision. This is the newest governance challenge globally, and getting ahead of it is a genuine differentiator.
  • Start building your own measurement methodology for fairness and explainability. Institutions that define rigorous internal standards now will be the ones setting the benchmark if and when a shared toolkit emerges.
  • Track obligations beyond RBI if you operate internationally. Institutions with EU exposure may already be bound by Annex III high-risk obligations and an August 2026 or February 2027 deadline, regardless of where RBI’s own timeline lands.
  • Audit whether your documentation could survive a regulator’s question today. If you cannot produce a current record of a model’s purpose, owner, validation history, known limitations, and monitoring status on short notice, your governance exists on paper more than in practice.
  • Invest in documentation and workflow infrastructure before the Guidance is finalized. Institutions that wait for the final text to build model inventories, approval workflows, and audit trails will be building under supervisory pressure rather than on their own timeline.
  • Make human oversight and escalation paths explicit. The Guidance expects defined boundaries for AI decision-making and a clear route for escalated issues and retired models. This should be a designed process, not an informal understanding.

Responsible AI Requires a System of Control

The next phase of AI adoption in Indian financial services will not be defined by how quickly institutions deploy AI. It will be defined by how well they can govern it and by whether they can prove that governance to a regulator, an auditor, or a customer, on demand.

RBI’s Draft Guidance is a strong first step toward that standard, and one built on a principle worth taking seriously well beyond the letter of any final regulation. AI governance cannot live in a policy document. It has to be embedded into the operational fabric of the institution, into the workflows, the documentation, the approvals and the oversight that surround every model, at every stage of its life cycle. That is the conversation Melento intends to keep having, with regulators and institutions alike, as this framework moves from draft to reality.

The Conclusion Worth Drawing

The real story here is not RBI versus the EU versus the US, as though regulators are competing on strictness. It is that the world’s major financial regulators are each running a different real-world experiment on the same open question: where does AI risk actually live?

The EU is betting it lives in the model, and that binding classification and penalties will force it into the open. The US just bet that it lives partly outside the model risk framework altogether, in judgement calls institutions have to make on their own.

Singapore is betting it lives in the gap between principle and practice, and is building shared tooling to close that gap. RBI, by choosing the broadest scope of any major regulator so far, is making the boldest and, in our view, the most forward-looking bet of the four.

What turns a bold scope into changed behaviour is infrastructure, and that is the part we know from the inside, not from reading the draft. Melento builds the systems that this kind of regulation quietly assumes already exist inside every regulated institution. The workflows, approvals, documentation, and audit trails that let someone actually answer a regulator’s question about a model, on the day the question is asked.

What we have learned building that infrastructure for banks and NBFCs is that governance succeeds or fails long after a model is approved, in how confidently an institution can trace a vendor’s silent update, or explain the moment two low-risk AI components were wired together into something new.

India does not need to copy the EU’s rulebook or import Singapore’s toolkit wholesale. It has already made the boldest opening move of the four. The genuinely exciting question, and the one we think institutions and regulators should be asking together while this draft is still open, is what India builds next on top of that head start: a shared measurement layer, a clear runway toward consequence, and an explicit answer to workflow-level risk before it becomes the industry’s next hard lesson rather than its next competitive advantage.