{"id":12890,"date":"2026-08-14T00:16:57","date_gmt":"2026-08-14T05:46:57","guid":{"rendered":"https:\/\/melento.ai\/en-in\/blog\/?p=12890"},"modified":"2026-08-14T06:54:16","modified_gmt":"2026-08-14T12:24:16","slug":"rbis-new-model-for-risk-guidance","status":"publish","type":"post","link":"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance","title":{"rendered":"RBI&#8217;s New Model Risk Guidance: Why AI Governance Is Becoming an Enterprise Responsibility"},"content":{"rendered":"<p><strong><i>A practitioner&#8217;s read on what the Draft Guidance is really regulating, how it measures up against the EU, the US, and Singapore, and the frontier it now has a chance to lead on.<\/i><\/strong><\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">On the surface, the Reserve Bank of India&#8217;s Draft Guidance on Regulatory Principles for Model Risk Management, 2026 reads like a model risk update, the kind of document that lands with risk teams and gradually reshapes an internal policy manual. Look a little closer, though, and it is doing something broader than that title suggests. What RBI has put out is one of India&#8217;s first substantive attempts at AI governance and security regulation for the financial sector, covering not just how models are validated but how they can be attacked, manipulated, and misused.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">That distinction is the eye-opener. A model risk document asks whether a system performs accurately. A governance and security document asks whether that system can be hallucinated into giving wrong advice, prompt-injected into leaking data, drifted into bias, or manipulated by an adversary who understands exactly how it makes decisions. RBI&#8217;s Draft Guidance asks all of these questions in the same breath as accuracy and validation, and that is the part of the document that deserves far more attention than it has received.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">We know this territory because we work in it. <a href=\"https:\/\/melento.ai\/en-in\/\">Melento<\/a> builds the compliance automation, contract lifecycle, and AI-enabled workflow systems that regulated financial institutions run on, and we made a formal submission to RBI on this Draft Guidance. What follows is not a summary of that submission. It is our read on what the Guidance is actually aimed at, how it stacks up against what regulators elsewhere have already done, and where we think India has an opening to lead rather than follow.<\/p>\n<h2><span style=\"color: #2c5363;\"><b>What the Guidance Is Actually Targeting<\/b><\/span><\/h2>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">Strip the Draft Guidance down to its mechanics, and it is targeting three things at once, not one.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">The first is scope, defined deliberately wide. RBI has defined \u201cmodel\u201d broadly enough to catch machine learning systems, generative AI, rule-based engines, algorithms, and even spreadsheets and decision-support tools, provided they materially influence a business decision. This is a regulator closing a loophole before institutions find it: consequential decisions quietly running through tools that were never built, tested, or documented like a model, precisely because nobody called them one.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">The second is the accountability chain, not the technology. Whether a system was built in-house or licensed from a vendor, the Guidance places responsibility with the regulated entity. That includes foundation models and proprietary AI services where the institution has no access to architecture, training data, or weights. RBI is not asking institutions to understand every layer of a vendor&#8217;s model. It is asking them to own the consequences of using it anyway, through contractual controls, integration testing and ongoing monitoring.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">The third, and the one most easily missed, is the security perimeter around the model rather than the model itself. Explainability, fairness, hallucinations, prompt injection, adversarial manipulation, and model drift sit in the same clause as validation and monitoring. That is a regulator treating an AI system the way a security team would: as something with an attack surface, not just an error rate. Very few model risk frameworks anywhere have historically done that. This one does, and it does it early.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">Put together, the target is not \u201cmodels\u201d. It is any point where an automated system touches a customer, a decision, or a regulator&#8217;s ability to reconstruct what happened afterward. And the evidence an institution can produce to prove it was governed the whole way through.<\/p>\n<h2><span style=\"color: #2c5363;\"><b>Where India Sits Against What the Rest of the World Has Already Done<\/b><\/span><\/h2>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">RBI is not writing on a blank page, and seeing where it sits against three live 2026 approaches is what makes this genuinely interesting rather than another compliance memo.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">The European Union has gone furthest toward binding law. Under the EU AI Act, AI systems used to evaluate the creditworthiness of natural persons are explicitly classified as high-risk, triggering documented risk management, data governance, automatic logging, transparency, and human-oversight obligations, backed by a conformity assessment before deployment. New high-risk systems had to be compliant by August 2026, with legacy systems given until February 2027, backed by penalties denominated in real numbers. It is a regime built for enforcement first. The United States has just made a very different choice, and it is the most telling data point of the three.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">In April 2026, the Federal Reserve, the OCC and the FDIC replaced their fifteen-year-old model risk guidance with SR 26-2 and deliberately placed generative AI and agentic AI outside its formal scope, describing them as too novel and fast-moving to regulate through a fixed rulebook.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">American banks are now governing their fastest-growing AI systems without a shared supervisory template, at exactly the moment those systems are scaling the most. Singapore has taken a third path: principles first, tooling second.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">The Monetary Authority of Singapore built its Fairness, Ethics, Accountability and Transparency principles back in 2018, then spent years turning them into the Veritas initiative, an open-source toolkit with shared fairness metrics and assessment methodologies.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">Its newer AI Risk Management Guidelines extend that proportional, full-lifecycle approach to generative and agentic AI directly. Set against these three, here is the eye-opener: RBI&#8217;s Draft Guidance chose to bring generative AI, RAG systems and autonomous agents inside the perimeter from the outset, rather than carving them out the way the world&#8217;s largest banking regulator did four months earlier.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">India is not playing catch-up here. On this specific point, it is ahead of the United States, and closer in spirit to Singapore&#8217;s inclusive, full-lifecycle stance than most coverage of the Draft Guidance has given it credit for.<\/p>\n<h2><span style=\"color: #2c5363;\"><b>The Frontier RBI Now Has a Chance to Lead<\/b><\/span><\/h2>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">Being broader in scope than the US and more inclusive than most peer frameworks puts India in a genuinely strong starting position. What happens next is where the real opportunity sits, and it is the same opportunity every regulator in this space is currently racing to seize, not a shortcoming unique to this draft.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">The first frontier is turning principle into a shared operating rhythm. Every framework we looked at, including RBI&#8217;s, eventually has to answer the same practical question: what does \u201cgoverned\u201d look like on a Tuesday afternoon, when a supervisor asks for evidence rather than intent? Singapore answered this by building a shared toolkit alongside its principles.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">RBI has the chance to do something similar for the Indian market, and given how many institutions across the sector would benefit from a common measurement layer for explanability and fairness rather than each building its own, this is a genuine opening rather than a gap to be filled defensively.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">The second frontier is workflow-level risk, and this is the newest and most interesting problem in AI governance globally, not a flaw in any one country&#8217;s drafting. A generative model drafting a credit memo that a human then approves inside a separate, older scoring model creates a risk pathway that belongs to neither system on its own.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">Researchers studying the US&#8217;s own SR 26-2 are actively building control frameworks to address exactly this, months after that guidance was finalised. RBI is drafting at a moment when this problem is already visible elsewhere, which means India has the rare advantage of designing for it directly rather than discovering it after the fact, the way other markets currently are.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">The third is timing and consequence, and here the opportunity is simply sequencing. The EU&#8217;s deadlines and enforcement structure show what the mature end state can look like once an ecosystem is ready for it. RBI has chosen, wisely in our view, to start from principles and proportionality rather than immediately importing that machinery.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">It is worth flagging now, while the draft is open for comment, that institutions will move faster and more confidently once a clear runway with defined milestones exists. That is a natural next step for the Guidance to build toward, not a missing piece today.<\/p>\n<h2><span style=\"color: #2c5363;\"><b>Key Takeaways for CXOs and Decision-Makers<\/b><\/span><\/h2>\n<ul>\n<li style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">Treat this as an enterprise governance issue, not a technology project. AI <span style=\"font-weight: 400;\">risk now touches legal, compliance, information security, operations, and customer experience. Assign ownership accordingly and distribute it well.\u00a0<\/span><\/li>\n<li style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\"><span style=\"font-weight: 400;\">Treat this as an enterprise governance issue, not a technology project. AI risk now touches legal, compliance, information security, operations, and customer experience. Assign ownership accordingly and distribute it well.<\/span><\/li>\n<li style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\"><span style=\"font-weight: 400;\">Build a risk-tiering exercise into your model inventory now. Not every AI use case warrants the same level of scrutiny. A defensible framework classifies systems by the consequence of failure, not by whether the word &#8220;AI&#8221; applies.<\/span><\/li>\n<li style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\"><span style=\"font-weight: 400;\">Read this as security regulation, not a compliance memo. Prompt injection, adversarial manipulation, and hallucination sit alongside validation and monitoring in this Guidance. Assign ownership to security and risk jointly, not to a model validation team alone.<\/span><\/li>\n<li style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\"><span style=\"font-weight: 400;\">Recognise the head start you are working with. India&#8217;s inclusive scope, covering generative and agentic AI from day one, puts institutions ahead of peers in markets like the US that are still governing these systems without a shared template.<\/span><\/li>\n<li style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\"><span style=\"font-weight: 400;\">Map workflow-level risk while it is still a frontier problem, not a catch-up exercise. Trace every point where an AI output feeds into another model or decision. This is the newest governance challenge globally, and getting ahead of it is a genuine differentiator.<\/span><\/li>\n<li style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\"><span style=\"font-weight: 400;\">Start building your own measurement methodology for fairness and explainability. Institutions that define rigorous internal standards now will be the ones setting the benchmark if and when a shared toolkit emerges.<\/span><\/li>\n<li style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\"><span style=\"font-weight: 400;\">Track obligations beyond RBI if you operate internationally. Institutions with EU exposure may already be bound by Annex III high-risk obligations and an August 2026 or February 2027 deadline, regardless of where RBI&#8217;s own timeline lands.<\/span><\/li>\n<li style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\"><span style=\"font-weight: 400;\">Audit whether your documentation could survive a regulator&#8217;s question today. If you cannot produce a current record of a model&#8217;s purpose, owner, validation history, known limitations, and monitoring status on short notice, your governance exists on paper more than in practice.<\/span><\/li>\n<li style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\"><span style=\"font-weight: 400;\">Invest in documentation and workflow infrastructure before the Guidance is finalized. Institutions that wait for the final text to build model inventories, approval workflows, and <a href=\"https:\/\/melento.ai\/en-in\/blog\/audit-trail-secures-edocuments\">audit trails<\/a> will be building under supervisory pressure rather than on their own timeline.<\/span><\/li>\n<li style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\"><span style=\"font-weight: 400;\">Make human oversight and escalation paths explicit. The Guidance expects defined boundaries for AI decision-making and a clear route for escalated issues and retired models. This should be a designed process, not an informal understanding.<\/span><\/li>\n<\/ul>\n<h2><span style=\"color: #2c5363;\"><b>Responsible AI Requires a System of Control<\/b><\/span><\/h2>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">The next phase of AI adoption in Indian financial services will not be defined by how quickly institutions deploy AI. It will be defined by how well they can govern it and by whether they can prove that governance to a regulator, an auditor, or a customer, on demand.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">RBI&#8217;s Draft Guidance is a strong first step toward that standard, and one built on a principle worth taking seriously well beyond the letter of any final regulation. AI governance cannot live in a policy document. It has to be embedded into the operational fabric of the institution, into the workflows, the documentation, the approvals and the oversight that surround every model, at every stage of its life cycle. That is the conversation Melento intends to keep having, with regulators and institutions alike, as this framework moves from draft to reality.<\/p>\n<h2><span style=\"color: #2c5363;\"><b>The Conclusion Worth Drawing<\/b><\/span><\/h2>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">The real story here is not RBI versus the EU versus the US, as though regulators are competing on strictness. It is that the world&#8217;s major financial regulators are each running a different real-world experiment on the same open question: where does AI risk actually live?<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">The EU is betting it lives in the model, and that binding classification and penalties will force it into the open. The US just bet that it lives partly outside the model risk framework altogether, in judgement calls institutions have to make on their own.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">Singapore is betting it lives in the gap between principle and practice, and is building shared tooling to close that gap. RBI, by choosing the broadest scope of any major regulator so far, is making the boldest and, in our view, the most forward-looking bet of the four.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">What turns a bold scope into changed behaviour is infrastructure, and that is the part we know from the inside, not from reading the draft. Melento builds the systems that this kind of regulation quietly assumes already exist inside every regulated institution. The workflows, approvals, documentation, and audit trails that let someone actually answer a regulator&#8217;s question about a model, on the day the question is asked.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">What we have learned building that infrastructure for banks and NBFCs is that governance succeeds or fails long after a model is approved, in how confidently an institution can trace a vendor&#8217;s silent update, or explain the moment two low-risk AI components were wired together into something new.<\/p>\n<p style=\"text-align: justify; font-size: 17px; font-family: 'open sans';\">India does not need to copy the EU&#8217;s rulebook or import Singapore&#8217;s toolkit wholesale. It has already made the boldest opening move of the four. The genuinely exciting question, and the one we think institutions and regulators should be asking together while this draft is still open, is what India builds next on top of that head start: a shared measurement layer, a clear runway toward consequence, and an explicit answer to workflow-level risk before it becomes the industry&#8217;s next hard lesson rather than its next competitive advantage.<\/p>\n<p style=\"text-align: center;\"><button class=\"navigate-to-form\"><strong>Book a Demo Now!<\/strong><\/button><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A practitioner&#8217;s read on what the Draft Guidance is really regulating, how it measures up against the EU, the US, and Singapore, and the frontier it now has a chance to lead on. On the surface, the Reserve Bank of India&#8217;s Draft Guidance on Regulatory Principles for Model Risk Management, 2026 reads like a model [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":12895,"comment_status":"closed","ping_status":"open","sticky":false,"template":"page_templates\/blog-new-3.php","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[20],"tags":[1936,1944],"class_list":["post-12890","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-regulations","tag-rbi-digital-lending-guidelines","tag-rbi-guidelines"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.1.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>RBI AI Governance &amp; Model Risk Guidance Explained<\/title>\n<meta name=\"description\" content=\"Discover how the RBI&#039;s model risk guidance shifts AI governance to enterprise responsibility, transparency, and accountability.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"RBI AI Governance &amp; Model Risk Guidance Explained\" \/>\n<meta property=\"og:description\" content=\"Discover how the RBI&#039;s model risk guidance shifts AI governance to enterprise responsibility, transparency, and accountability.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance\" \/>\n<meta property=\"og:site_name\" content=\"Melento (Formerly SignDesk)\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-14T05:46:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-14T12:24:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/melento.ai\/en-in\/blog\/wp-content\/uploads\/2026\/08\/RBI-model-risk-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1338\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Neela\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Neela\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance\",\"url\":\"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance\",\"name\":\"RBI AI Governance & Model Risk Guidance Explained\",\"isPartOf\":{\"@id\":\"https:\/\/melento.ai\/en-in\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance#primaryimage\"},\"image\":{\"@id\":\"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance#primaryimage\"},\"thumbnailUrl\":\"https:\/\/melento.ai\/en-in\/blog\/wp-content\/uploads\/2026\/08\/RBI-model-risk-scaled.jpg\",\"datePublished\":\"2026-08-14T05:46:57+00:00\",\"dateModified\":\"2026-08-14T12:24:16+00:00\",\"author\":{\"@id\":\"https:\/\/melento.ai\/en-in\/blog\/#\/schema\/person\/6e57a3c3c265c628ef90b958e2bfe781\"},\"description\":\"Discover how the RBI's model risk guidance shifts AI governance to enterprise responsibility, transparency, and accountability.\",\"breadcrumb\":{\"@id\":\"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance#primaryimage\",\"url\":\"https:\/\/melento.ai\/en-in\/blog\/wp-content\/uploads\/2026\/08\/RBI-model-risk-scaled.jpg\",\"contentUrl\":\"https:\/\/melento.ai\/en-in\/blog\/wp-content\/uploads\/2026\/08\/RBI-model-risk-scaled.jpg\",\"width\":2560,\"height\":1338,\"caption\":\"RBI's New Model For Risk Mitigation\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/melento.ai\/en-in\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"RBI&#8217;s New Model Risk Guidance: Why AI Governance Is Becoming an Enterprise Responsibility\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/melento.ai\/en-in\/blog\/#website\",\"url\":\"https:\/\/melento.ai\/en-in\/blog\/\",\"name\":\"Melento\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/melento.ai\/en-in\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/melento.ai\/en-in\/blog\/#\/schema\/person\/6e57a3c3c265c628ef90b958e2bfe781\",\"name\":\"Neela\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/melento.ai\/en-in\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/22b94f6f04adbc71de9adc48c3794f2fc644283c178eb0e18d345ae718b5684f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/22b94f6f04adbc71de9adc48c3794f2fc644283c178eb0e18d345ae718b5684f?s=96&d=mm&r=g\",\"caption\":\"Neela\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"RBI AI Governance & Model Risk Guidance Explained","description":"Discover how the RBI's model risk guidance shifts AI governance to enterprise responsibility, transparency, and accountability.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance","og_locale":"en_US","og_type":"article","og_title":"RBI AI Governance & Model Risk Guidance Explained","og_description":"Discover how the RBI's model risk guidance shifts AI governance to enterprise responsibility, transparency, and accountability.","og_url":"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance","og_site_name":"Melento (Formerly SignDesk)","article_published_time":"2026-08-14T05:46:57+00:00","article_modified_time":"2026-08-14T12:24:16+00:00","og_image":[{"width":2560,"height":1338,"url":"https:\/\/melento.ai\/en-in\/blog\/wp-content\/uploads\/2026\/08\/RBI-model-risk-scaled.jpg","type":"image\/jpeg"}],"author":"Neela","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Neela","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance","url":"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance","name":"RBI AI Governance & Model Risk Guidance Explained","isPartOf":{"@id":"https:\/\/melento.ai\/en-in\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance#primaryimage"},"image":{"@id":"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance#primaryimage"},"thumbnailUrl":"https:\/\/melento.ai\/en-in\/blog\/wp-content\/uploads\/2026\/08\/RBI-model-risk-scaled.jpg","datePublished":"2026-08-14T05:46:57+00:00","dateModified":"2026-08-14T12:24:16+00:00","author":{"@id":"https:\/\/melento.ai\/en-in\/blog\/#\/schema\/person\/6e57a3c3c265c628ef90b958e2bfe781"},"description":"Discover how the RBI's model risk guidance shifts AI governance to enterprise responsibility, transparency, and accountability.","breadcrumb":{"@id":"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance#primaryimage","url":"https:\/\/melento.ai\/en-in\/blog\/wp-content\/uploads\/2026\/08\/RBI-model-risk-scaled.jpg","contentUrl":"https:\/\/melento.ai\/en-in\/blog\/wp-content\/uploads\/2026\/08\/RBI-model-risk-scaled.jpg","width":2560,"height":1338,"caption":"RBI's New Model For Risk Mitigation"},{"@type":"BreadcrumbList","@id":"https:\/\/melento.ai\/en-in\/blog\/rbis-new-model-for-risk-guidance#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/melento.ai\/en-in\/blog\/"},{"@type":"ListItem","position":2,"name":"RBI&#8217;s New Model Risk Guidance: Why AI Governance Is Becoming an Enterprise Responsibility"}]},{"@type":"WebSite","@id":"https:\/\/melento.ai\/en-in\/blog\/#website","url":"https:\/\/melento.ai\/en-in\/blog\/","name":"Melento","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/melento.ai\/en-in\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/melento.ai\/en-in\/blog\/#\/schema\/person\/6e57a3c3c265c628ef90b958e2bfe781","name":"Neela","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/melento.ai\/en-in\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/22b94f6f04adbc71de9adc48c3794f2fc644283c178eb0e18d345ae718b5684f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/22b94f6f04adbc71de9adc48c3794f2fc644283c178eb0e18d345ae718b5684f?s=96&d=mm&r=g","caption":"Neela"}}]}},"_links":{"self":[{"href":"https:\/\/melento.ai\/en-in\/blog\/wp-json\/wp\/v2\/posts\/12890","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/melento.ai\/en-in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/melento.ai\/en-in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/melento.ai\/en-in\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/melento.ai\/en-in\/blog\/wp-json\/wp\/v2\/comments?post=12890"}],"version-history":[{"count":11,"href":"https:\/\/melento.ai\/en-in\/blog\/wp-json\/wp\/v2\/posts\/12890\/revisions"}],"predecessor-version":[{"id":12904,"href":"https:\/\/melento.ai\/en-in\/blog\/wp-json\/wp\/v2\/posts\/12890\/revisions\/12904"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/melento.ai\/en-in\/blog\/wp-json\/wp\/v2\/media\/12895"}],"wp:attachment":[{"href":"https:\/\/melento.ai\/en-in\/blog\/wp-json\/wp\/v2\/media?parent=12890"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/melento.ai\/en-in\/blog\/wp-json\/wp\/v2\/categories?post=12890"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/melento.ai\/en-in\/blog\/wp-json\/wp\/v2\/tags?post=12890"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}