RBI-Model-Risk-Management

RBI’s AI Model Risk Management – AI Security Compliance Mandate for Banks

 |  Edited : August 07, 2026

On 24 June 2026 the Reserve Bank of India issued its Guidance on Regulatory Principles for Model Risk Management, open for comment until 24 July 2026. Call it the RBI MRM guidance. It reaches almost everyone the RBI supervises: commercial and co-operative banks, NBFCs across all four layers, payments and small finance banks, all-India institutions […]

Reading Time: 7 minutes

TL;DR

  • RBI’s June 2026 MRM guidance covers every AI/ML model that shapes a business decision across banks, NBFCs, payments banks, and all-India financial institutions. If a model touches a decision, it needs to be governed.
  • Shadow models are your biggest compliance gap. RBI requires a complete, live inventory. Automated discovery surfaces the EC2-hosted model, the unapproved notebook, and the inference container nobody registered.
  • Vendor certification is not your validation. RBI holds you accountable for third-party models even when the provider certifies them. You need to red-team hosted models like Bedrock and vLLM on your own terms.
  • Customer-facing generative AI needs a stateful firewall, not a single-prompt filter. Multi-turn jailbreaks don’t announce themselves in one message. Scoring the full conversation is what catches them.
  • The comment window closes 24 July 2026. Banks that map controls to requirements now won’t be scrambling against a hard compliance deadline.

On 24 June 2026 the Reserve Bank of India issued its Guidance on Regulatory Principles for Model Risk Management, open for comment until 24 July 2026. Call it the RBI MRM guidance. It reaches almost everyone the RBI supervises: commercial and co-operative banks, NBFCs across all four layers, payments and small finance banks, all-India institutions like NABARD and EXIM Bank, and credit information companies. If a model shapes a business decision, you now have to govern it.

Most of the guidance is technology-neutral. The chapter on AI and ML is not, and that is where the security work lives. Here is what RBI asks for, and what AccuKnox delivers against it.

A boundary first. This is a security map, not a governance manual. Your board-approved framework, risk appetite, and approval committees stay with you. The controls below are the part you deploy, and the evidence you hand to the committee.

Model Risk Management 1a

Incoming RBI Mandates for AI Model Governance – Banks and Finance Firms Have a Compliance Deadline

RBI asks for a complete, current inventory of every model, built in-house or bought from a vendor, with its dependencies, and says nothing should run unless it is on that list.

AccuKnox delivers automatic discovery of your AI estate: models, datasets, compute, and the pipelines that connect them, across cloud and on-prem. It surfaces the shadow models nobody registered, an EC2-hosted model, an unapproved notebook, an inference container off the books. Because discovery runs continuously, the inventory matches reality between audits instead of drifting.

Model Risk Management 2
Model Risk Management 3

AccuKnox discovers AI across managed services like Bedrock, SageMaker, Vertex, and Azure, and on-prem stacks like Ollama, vLLM, and Triton, including the ones nobody registered.

Validation Can’t Be a Once-a-Year Exercise

RBI asks you to validate every model independently, before and after it goes live and on every material change, and to run structured challenge, red-teaming above all, on anything that talks to customers or generates content.

AccuKnox delivers automated red teaming against your models for prompt injection, jailbreaks, hallucination, toxic output, and unsafe code, before launch and again on every update. Each run is documented, so the test becomes evidence instead of a slide. The statistical soundness of the model stays with your quants; this is the security and behavior half of validation.

Model Risk Management 4

Red teaming scores each model for prompt injection, hallucination, unsafe code, and toxic output, on every update.

A Vendor’s Assurance Is Not Your Validation

RBI asks you to stay accountable for a third-party model even when the vendor certifies it, and to account for supply-chain risk and silent provider updates.

AccuKnox delivers red teaming against hosted models like AWS Bedrock, NVIDIA Triton, and vLLM on your terms, and scans model artifacts for tampering such as pickle-deserialization payloads and poisoned weights. When a provider shares little, the prompt firewall enforces the usage limits RBI asks for, by restricting topics, capping tokens, and filtering both directions.

Model Risk Management 5

When You Can’t Explain a Model, Control It

RBI asks, where full explainability is not achievable, for compensating controls: corroborate the output before it is used, validate more often, monitor continuously, and restrict usage.

AccuKnox delivers exactly that layer. You set the threshold, and when a model falls short AccuKnox supplies the controls: response checks that verify output before a customer sees it, scheduled re-tests, continuous monitoring, and hard limits at the prompt boundary.

Model Risk Management 6

Stop Harmful Output Before the Customer Sees It

RBI asks you to fence generative models against hallucination and bias, and never to deploy a model that harms a customer.

AccuKnox delivers hallucination and toxicity measurement during red teaming, and a stateful prompt firewall that inspects responses in production, blocking toxic content, leaked PII, and off-policy answers on the way out. Fairness statistics on protected groups stay with you; the firewall stops the bad output at the edge.

Model Risk Management 7

A response-side policy strips code from model output when the application has no business returning it.

Customer-Facing AI Needs a Firewall, Not a Filter

RBI asks, for models that face customers, for defenses against prompt injection and adversarial input, limits on how much session and context persists, and detection of odd usage.

Model Risk Management 8

AccuKnox delivers a stateful prompt firewall that scores the whole conversation, not one prompt in isolation, which is what catches the multi-turn jailbreaks a single-prompt filter misses. It blocks injection and adversarial input, caps tokens and context, and AI-DR flags anomalous usage. Telling customers they are talking to an AI and offering a human handoff are your application’s job, not ours.

Model Risk Management 9

The stateful firewall runs every message through five stages, normalize, classify, contextualize, score, enforce, scoring the whole conversation so a multi-turn jailbreak does not slip through.

Guardrails Get Bypassed; the OS Layer Doesn’t

RBI asks that deploying a model not open a hole, naming access controls, cyber safeguards, and the risks from APIs and integration pipelines.

AccuKnox delivers least-privilege enforcement at the operating-system layer. A model might refuse to print credentials when asked directly, then comply when asked to print “a file starting with the letter C” in the .aws directory. A runtime policy blocks that file access no matter what the prompt says.

Model Risk Management 10

Runtime enforcement blocks the model’s attempt to read the .aws directory at the OS level, so a bypassed guardrail still fails.

Keep a Kill-Switch a Human Can Reach

RBI asks for human oversight with override, suspension, and kill-switch arrangements, plus periodic human review of model-driven decisions.

AccuKnox delivers that kill-switch through runtime enforcement: it blocks or deactivates model behavior at the OS layer, independent of the model’s own guardrails, and flagged outputs surface for human review. Who reviews, and how often, is yours to set.

A Silent Model Update Shouldn’t Slip Past You

RBI asks for ongoing monitoring of every deployed model, with extra care for models that update automatically.

AccuKnox delivers AI-DR that watches models in production, flags behavior change after a provider-driven or automatic update, and triggers a fresh red-team run so a quiet update does not bypass validation. Drift on your training data stays in your MLOps pipeline; this is the runtime signal.

Model Risk Management 11

Where AccuKnox Stops and You Start

AccuKnox is not your Model Risk Management Framework. The framework, the risk-tier decision, the approval committee, model soundness and fairness math, customer disclosures, and contractual audit rights stay with you. What AccuKnox gives you is the inventory, the test results, the runtime controls, and the audit trail the framework runs on.

The comment window closes on 24 July 2026, and the AI chapter is the part most banks are least ready for. AccuKnox already helps regulated entities meet RBI and SEBI expectations and the RBI SBOM mandate. Model risk is the next one, and mapping it to controls now beats mapping it against a deadline. 

Book a demo for the AccuKnox AI Security Platform Tour and kickstart your compliance journey today.

Model Risk Management 1 1

The AccuKnox AI Security Suite Includes:

  • AI-SPM
  • AI-DR
  • AI Guardrails and Prompt Firewall
  • Agentic AI Security
  • AI Red Teaming and Pen Testing
  • AI Identity Security
  • AI Model and Dataset Security

FAQs

What is RBI’s Model Risk Management guidance?

It’s a draft circular issued on 24 June 2026 that sets regulatory principles for how supervised entities must identify, validate, monitor, and govern every model that influences a business decision. The AI and ML chapter carries the sharpest technical requirements.

Who does it apply to?

Nearly every entity the RBI supervises: commercial and co-operative banks, NBFCs across all four layers, payments and small finance banks, and all-India financial institutions like NABARD and EXIM Bank, plus credit information companies.

What counts as a “model” under the guidance?

Any statistical, mathematical, or AI/ML tool that processes inputs to produce outputs used in business decisions, including credit scoring, fraud detection, customer-facing chatbots, and generative AI applications.

What’s the riskiest gap most banks have right now?

Shadow models: AI workloads deployed outside the formal approval process. RBI explicitly requires that nothing run unless it appears in the model inventory. Most banks cannot produce that inventory accurately today.

Does deploying AccuKnox make you compliant with the MRM guidance?

No. AccuKnox covers the technical controls layer: discovery, red teaming, runtime enforcement, and audit trail. The governance framework, risk-tier decisions, model soundness validation, fairness testing, and board approval structures remain your responsibility.

Ready For A Personalized Security Assessment?

“Choosing AccuKnox was driven by opensource KubeArmor’s novel use of eBPF and LSM technologies, delivering runtime security”

idt

Golan Ben-Oni

Chief Information Officer

“At Prudent, we advocate for a comprehensive end-to-end methodology in application and cloud security. AccuKnox excelled in all areas in our in depth evaluation.”

prudent

Manoj Kern

CIO

“Tible is committed to delivering comprehensive security, compliance, and governance for all of its stakeholders.”

tible

Merijn Boom

Managing Director

×