Model built or bought, the risk is still yours

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Phasellus pharetra tortor eget lacus ullamcorper, posuere fringilla justo convallis.

Early Impressions

Model built or bought, the risk is still yours

Model risk management under the RBI Draft Guidance on Regulatory Principles for Model Risk Management, 2026

22, July 2026

Executive Summary

Model failures are no longer technical shortcomings; they carry significant financial, operational, regulatory, and reputational consequences. The challenge is not just developing better models, but building governance that keeps them transparent, reliable, explainable, and fit for purpose throughout their lifecycle.

There is an uncomfortable edge to this. Lenders run a mix of in-house and third-party models for credit scoring, fraud engines, off-the-shelf AI services. This leads to part of their exposure sitting in models they did not design or cannot fully see. Built or bought, the risk and accountability stay with the institution.

That is why Model Risk Management can no longer remain a back-office compliance function. In a lending market being reshaped by AI, it has become a strategic capability and the license to scale. Institutions that can demonstrate their models are robust, transparent, and well governed will be able to innovate and grow with confidence.

Those that cannot will increasingly face constraints from regulators, boards, and risks that remain hidden until they materialize. When implemented effectively, Model Risk Management not only safeguards the institution but also enables responsible innovation, strengthens governance, and builds enduring trust in AI- and model-driven decision-making.

Recognizing these evolving risks, the Reserve Bank of India (RBI) has issued the Draft Guidance on Regulatory Principles for Model Risk Management (2026), introducing an enterprise-wide governance framework applicable across Regulated Entities. The Draft Guidance represents an important evolution in supervisory expectations, extending Model Risk Management beyond traditional credit risk models to encompass all material models, including AI and ML models, vendor solutions, and models embedded within business processes.

The Draft Guidance sets out what institutions must achieve. The harder question is “How?” How do Regulated Entities implement model risk management in a way that is proportionate, scalable, and aligned with business strategy while still enabling innovation.

The implementation strategy and approach will increasingly separate the winners from the rest. The impact will be the sharpest for NBFCs, housing finance companies, small finance banks and digital lenders, many of whom are facing an enterprise-wide model-risk rule for the first time and for whom the step-up is steepest.

This publication sets out a practical implementation perspective, combining the RBI’s expectations with leading global practices and our experience supporting financial institutions in model development, validation, IFRS 9, stress testing, capital management, and risk transformation initiatives.


Chapter 1: Why Model Risk Matters More Than Ever

Across the sector, banks, NBFCs, housing finance companies, small finance banks and digital-first lenders now rely on models to drive a large share of their decisions on capital allocation, risk pricing, and customer engagement. The dependence deepens each year as data volumes grow, and analytical techniques mature. Although still in draft, the RBI has signaled its stance clearly: the speed and scale of AI and models can be unlocked only if they are properly governed and independently challenged, not by leaving them to run unchecked.

One change that matters more than the rest is the fact that AI and machine-learning models behave in ways traditional model governance was never designed for. They retrain and shift behavior continuously, resist a single clean explanation and continue carrying bias by developing proxy variables even after the discriminating variable is removed. A framework built for slow, stable models is now being asked to govern fast, self-updating ones. That mismatch is why model governance can no longer stay as it is.

1.1 What put model risk on the regulator’s desk

Model use is no longer concentrated in a few quantitative teams. It now spans the full range of risks a bank manages, as well as an expanding set of technologies and providers.

  • Regulated entities are using models more widely and more intensively, driven by the growing scale and complexity of financial activity, digitalization, advances in analytics, and the arrival of AI and machine learning.
  • Models sit behind decisions across all major risk types: rating and provisioning, market risk valuation and value-at-risk, counterparty credit risk, liquidity and funding, interest rate risk in the banking book, and operational risk such as fraud and AML monitoring.
  • Internal-model approaches have long spanned risk types under the Basel framework, from the internal ratings-based approach for credit risk to the internal models approach for market risk. In contrast, behavioral models underpin interest rate risk in the banking book.
  • A rising share of models is built on AI or machine learning, or sourced from third parties, which widens the risk surface well beyond a bank’s own development teams.

Models are embedded across the enterprise

Historically, model risk management was primarily associated with regulatory capital models or credit risk estimation techniques. Today, the use of models extends across nearly every business and control function. Illustrative examples include:

Business Function Typical Models
Credit Risk Credit scoring, Probability of Default (PD), Loss Given Default (LGD), Exposure at Default (EAD), IFRS 9 Expected Credit Loss (ECL), behavioral scorecards
Treasury and Market Risk Interest rate risk, liquidity forecasting, Value-at-Risk (VaR), Funds Transfer Pricing (FTP), Asset-Liability Management (ALM)
Finance Forecasting, budgeting, profitability, capital planning, stress testing
Customer and Business Pricing optimization, customer segmentation, cross-sell propensity, collections, and recovery strategies
Financial Crime Fraud detection, Anti-Money Laundering (AML), transaction monitoring, sanctions screening
Customer Support Customer service chatbots, document processing, underwriting assistants, predictive analytics, and Generative AI applications

This widespread adoption means that model outcomes increasingly influence customer interactions, financial reporting, regulatory compliance, and strategic business decisions. As a result, weaknesses in governance can have consequences far beyond model accuracy.

1.2 Powerful by design, dangerous when ungoverned

Models create real value, but the same features that make them powerful also create failure modes that can cascade when oversight is weak.

  • Used well, models improve efficiency, sharpen decisions, enhance customer service, and strengthen risk management, including defense against cyber-attacks.
  • Used poorly, models can do real damage, whether through fundamental errors in their design or through incorrect or inappropriate use of their outputs.
  • AI and machine-learning models add newer failure modes, including bias and discriminatory outputs, hallucination in generative models, data, and concept drift, and limited explainability. Left ungoverned, these failures can produce inaccurate outcomes, flawed decisions, financial losses, operational disruptions, compliance failures, and consumer harm.
  • Heavy reliance on a small number of model or AI providers introduces supply-chain and concentration risk at a system level.

Increasingly, the model most likely to hurt a firm is one it did not build. Buying a model outsources the work, not the accountability. Built or bought, the risk stays with the institution.

1.3 Expanding definition of a ‘model’

A central move in the Draft Guidance is a deliberately broad definition of a model, which pulls tools into scope that firms may not currently manage as such.

  • A model is any system that takes inputs, applies quantitative or judgment-based techniques, including AI and machine learning, and produces outputs used in decisions, regardless of whether the entity itself labels it a model.
  • The Draft Guidance illustrates this with a spreadsheet: a basic pricing calculator becomes a model once its outputs drive lending rates, margins, or terms.
  • This breadth mirrors global practice, where supervisory guidance defines models widely across quantitative and statistical methods rather than by portfolio.

1.4 Real-world model-failure examples

The following cases span market, credit, and trading-book risk. In each case, mathematics was not the primary failure. The real failures were assumptions left unchallenged and validation too weak to catch them.

1

Long-Term Capital Management (1998)

A highly leveraged fund built on convergence-trading models that assumed historical volatility and correlation relationships would hold. When Russia defaulted in August 1998, correlations converged towards one and liquidity evaporated, a scenario the models treated as impossible. The fund lost roughly $4.6 billion and required a $3.65 billion recapitalization by 14 institutions, coordinated by the Federal Reserve Bank of New York.

2

Credit rating agency models, global financial crisis (2007–08)

Agencies rated mortgage-backed securities and CDOs on assumptions of low default rates and low correlation across regional housing markets, reinforced by an issuer-pays conflict and limited validation. When national house prices fell, those assumptions failed simultaneously across every pool. Of the roughly $869 billion in securities Moody’s rated AAA in 2006, 83% were later downgraded.

3

JPMorgan “London Whale” (2012)

A newly approved Value-at-Risk model for the Chief Investment Office roughly halved the desk’s reported risk, letting a synthetic-credit book grow without breaching limits. The model ran on manually maintained spreadsheets, one of which was divided by a sum rather than an average, thereby understating volatility. Losses reached at least $6.2 billion.

Key Takeaway

Model risk has outgrown its origins in credit modeling. It is now an enterprise-wide, board-level risk that runs across credit, market, liquidity, interest rate, and operational risk, wherever a model shapes a decision.


Chapter 2: The Global Origins of India’s Regulatory Framework

Model Risk Management did not emerge overnight. It has evolved over more than a decade through successive financial crises, technological advances, and increasingly rigorous supervisory expectations. Understanding this evolution provides important context for India’s Draft Guidance, explaining both the foundations on which it is built and the areas where it extends beyond existing global regulatory frameworks.

2.1 Where it began

The discipline took shape after the global financial crisis, when supervisors concluded that the models themselves were a source of risk.

  • The US Federal Reserve and the Office of the Comptroller of the Currency (OCC) set the template in 2011 with SR 11-7, which defined model risk and made it a firm-wide concern rather than a modeling-team issue.
  • SR 11-7 introduced the principle of effective challenge: credible, independent review with the standing and incentive to question a model and, where needed, reject it.
  • It established the building blocks still used today, namely a broad model definition, model risk as its own risk type, independent validation, and controls across the model lifecycle.

2.2 RBI journey

India’s path mirrors the global arc but compresses it, moving from a narrow credit-model rule to an enterprise-wide framework in a single step.

  • The starting point was the 2002 Guidance Note on Credit Risk Management, which addressed credit risk models specifically.
  • While the August 2024 iteration modernized governance across the model lifecycle, it confined it to credit risk models.
  • The Draft Guidance replaces that narrow foundation with principles that apply to all models, whatever the risk type or technology.
  • The population that must comply has widened too, reaching the full range of regulated entities rather than large banks alone.

2.3 One direction, many regulators

Around the world, regulators have converged on the same answer, and the scope has only widened: from capital models to all models, to the whole enterprise, to AI and third parties. The Draft Guidance is the latest entry, not the first.

Europe:

  • ECB’s Targeted Review of Internal Models tightened supervision after banks’ own models were found to be inconsistent and too favorable.
  • The AI Act classifies credit scoring and creditworthiness as high-risk, triggering obligations on human oversight, data governance, transparency, and robustness for lending AI.

UK:

  • PRA SS1/23 made model risk a discipline in its own right, covering every model that informs a decision, in-house or vendor, and requiring a named Senior Management Function holder accountable for it.

Canada:

  • OSFI E-23 extended it enterprise-wide to all models regardless of source or purpose – explicitly including third-party and AI and ML – governed across the full lifecycle.

US:

  • SR 26-2 replaced SR 11-7 for the first time in 15 years, swapping fixed annual revalidation for validation scaled to materiality and change velocity.

The same four themes recur: board accountability, third-party risk, AI-specific failure modes, and dynamic validation.

2.4 India versus the world

Around the world, regulators have converged on the same answer, and the scope has only widened: from capital models to all models, to the whole enterprise, to AI and third parties. The Draft Guidance is the latest entry, not the first.

Where the Draft Guidance aligns with global practice

  • A three-line-of-defense governance model, with clear ownership, an independent validation function, and an internal audit.
  • Independent validation of models before and after deployment, and periodically thereafter.
  • Risk-based tiering, so the intensity of oversight scales with a model’s materiality and complexity.

Where the Draft Guidance goes further

  • A wider entity scope, extending beyond large banks to NBFCs across all layers, co-operative banks, and other regulated entities.
  • A dedicated chapter on AI and machine-learning models, covering explainability, bias, hallucination, and behavioral risks.
  • Explicit consumer-protection and grievance-redressal expectations tied to the use of models.
  • Board-level and human-oversight requirements, including override and kill-switch arrangements for automated decisions.

Key Takeaway

India is not arriving late to model risk management; it is arriving in step with a global shift and, in places, ahead of it. The Draft Guidance adopts the core disciplines established since 2011 while extending them to a wider set of entities, to AI and machine-learning models, and to consumer protection.


Chapter 3: The RBI’s Vision for Enterprise MRM

Having established why model risk matters, let us now understand what RBI’s vision for Model Risk Management is. The Draft Guidance extends the rigour of model risk management beyond the individual model or function to a single, enterprise-wide discipline.

3.1 Scope and applicability

The framework is deliberately wide in both who it covers and what counts as a model.

  • It applies across the regulated universe, from banks (be it large, foreign, payment bank, small finance bank, etc.) to NBFCs across all layers, co-operative banks, All-India Financial Institutions, Asset Reconstruction Companies, and Credit Information Companies.
  • It covers every model the entity uses, whether developed in-house, sourced from a third party, or a combination of the two.
  • The definition of a model is drawn just as widely: any system that takes inputs, applies quantitative or judgment-based techniques (including AI and machine learning), and produces outputs used in decisions, whether or not the entity itself labels it a model.

3.2 Who does what

Board, Risk Management Committee of the Board (RMCB), Senior Management

Accountability under the Draft Guidance is layered rather than shared loosely. The board owns the framework, the risk committee oversees its operation, and senior management runs it day-to-day. Keeping the three distinct is what makes governance defensible under supervision.

Body Core duties under the Draft Guidance
Board Approve and periodically review the Model Risk Management Framework (MRMF); set a forward-looking, stress-informed model-risk appetite; approve the model-risk-tiering policy
RMCB Oversee MRMF implementation; approve deployment of high-risk models; review tiering at least annually; oversee exceptions, third-party, and AI models; review breaches
Senior Management Operationalize the MRMF (people and technology); implement tiering; maintain inventory and documentation; run periodic policy reviews and report to the RMCB

The three lines of defense

Ownership of model risk is assigned across three lines of defense, so that those who run models are not the only ones responsible for checking them.

1L

First line

Who it comprises Model owners, developers, and the business functions that deploy and rely on the model
Core responsibilities under the Draft Guidance Build or select the model on a sound business case, with fairness and bias checked; ensure data quality; document it and keep its inventory entry current; use it within approved limits; monitor performance and remediate issues; own the outcomes.
2L

Second line

Who it comprises The independent model validation / model-risk management function is kept separate from the developers
Core responsibilities under the Draft Guidance Validate models before and after deployment, on triggers and periodically; provide effective challenge; set validation and tiering standards; assess model risk both per model and enterprise-wide against appetite; report to the RMCB.
3L

Third line

Who it comprises Internal audit
Core responsibilities under the Draft Guidance Provide independent assurance that the MRMF is well-designed and operating effectively, and that the first and second lines are doing their jobs; report to the board/audit committee.

3.3 From siloed validation to enterprise-wide model risk

The central shift is to treat model risk as an enterprise risk, assessed continuously, rather than a set of one-off validations.

  • Entities are expected to assess model risk at both the individual-model and enterprise-wide levels, on an ongoing basis.
  • Where a model’s assessed risk exceeds the stated risk appetite, timely action is expected, such as enhanced controls, restrictions on use, remediation, or decommissioning, with escalation to the board’s risk committee.
  • The board sets a forward-looking risk appetite for model risk, informed by scenario analysis and stress testing.
  • A three-line-of-defense structure assigns ownership to the first line, independent validation to the second, and assurance to internal audit as the third.

3.4 Consumer protection as a first-order objective

The Draft Guidance treats consumer protection as an explicit objective, not a by-product of good modeling.

  • An entity should not use any model that harms consumers.
  • Grievance-redressal mechanisms must cover complaints arising from consumer-facing models.

This raises the bar for models used in pricing, underwriting, collections, and customer interaction, where outcomes reach customers directly.

3.5 How it fits with the rest of the rulebook

The Draft Guidance is written as an overlay, not a standalone code. The Draft Guidance is to be read together with RBI’s other Directions, and where they conflict, the specific Direction prevails. The practical question is not which rule applies, but how the model-risk lens stacks on top of the rules that an RE already follows.

Data protection – DPDP Act, 2023

Every model that touches personal data inherits the Act’s obligations. Data-governance expectations are discharged through DPDP in practice: a lawful consent or legitimate-use basis for the data a model trains and runs on, purpose limitation and minimization constraining which features are permissible, and data-principal rights.

Digital lending – RBI (Digital Lending) Directions, 2025

For a digitally originated loan, the two regimes govern different layers of the same decision: the Draft Guidance governs the credit model; the Digital Lending Directions govern the borrower-facing journey. They meet at three points: the explainability of an automated decline, the limits of permissible data, and consumer grievance redressal.

Outsourcing and IT governance – RBI Outsourcing of IT Services Directions, 2023 and IT Governance Directions, 2023

A bought model is simultaneously an outsourcing event and a model event. Read together, the vendor contract must deliver not just service continuity but enough of the model’s design to let the RE validate it. Further, the Draft Guidance’s deployment controls map onto the IT Governance Directions’ access, cyber, and change-control expectations.

Financial reporting and capital – Ind AS 109 ECL and Basel Regulations

These regimes already validate specific model families for a specific purpose, and the Draft Guidance adds an enterprise overlay. The real work here is reconciliation and recognition of existing Basel/ECL validations, so the model-risk framework adds enterprise visibility without duplicating them.

Key Takeaway

The RBI’s vision is enterprise-wide and accountability-driven. Model risk is owned at the board level, assessed continuously across all models and risk types, and judged not only by accuracy but also by fairness, explainability, and impact on consumers.


Chapter 4: The RBI’s Enterprise MRM Requirements in Depth

What each requirement means, what it asks for, and where compliance gets hard.

Governance and accountability

Impact: Critical
Readiness Gap: High (especially for smaller entities)

What it means

  • The board is answerable for every model, whether built or bought.
  • This responsibility cannot be delegated to a vendor or the model team.

What it requires

  • One board-approved framework covering all models.
  • A board-set model-risk appetite that looks ahead.
  • A risk committee that signs off on high-risk, AI, and vendor models.
  • Enough people and budget to run it.

Implementation challenges

  • Boards often lack the depth to challenge models.
  • No starting point for what ‘acceptable’ model risk means.
  • Model practices are scattered across teams.
  • Too few skilled validators to hire.

Enterprise view, tiering, and inventory

Impact: Critical
Readiness Gap: High

What it means

  • Model risk is to be managed across the whole firm, not model by model.
  • Each model needs to be ranked by how much harm it can cause.

What it requires

  • Tracking risk per model and firm-wide, continuously.
  • Three lines of defense: owner, independent check, audit.
  • Rating every model by importance and complexity.
  • A live list of all models – none runs unless listed (keeping the retired ones for 10 years).
  • Never use a model that harms customers.

Implementation challenges

  • Enterprise-wide picture of model risk is missing.
  • Hidden models and spreadsheets that are not on the list.
  • Links between models are not mapped.
  • Teams push for lower ratings.
  • ‘No customer harm’ is hard to test.

Model lifecycle

Impact: Critical
Readiness Gap: Very High

What it means

Model needs to be governed from idea to retirement – not just at launch.

What it requires

  • A clear business case; checking for fairness and bias before building.
  • Good data and a proper build process.
  • Independent checks before and after launch; reporting on the same within 3 months.
  • Clear approval rules, including those for exceptions.
  • Stable and continuous monitoring of models in production.
  • Logging all changes; big changes trigger a re-check.
  • A backup plan and a proper retirement process.

Implementation challenges

  • Fairness checks happen too late in the build.
  • Few validators to meet the 3-month deadline.
  • Hard to define a ‘big change’ for models that retrain often.
  • Manual backups are unrealistic at high volumes.

Vendor (third-party) models

Impact: High
Readiness Gap: Very High (especially fintech-dependent NBFCs)

What it means

  • Buying a model does not transfer the risk.
  • The entity is responsible for a model it buys as for one it builds in-house.

What it requires

  • Applying the full framework to vendor models.
  • The entity should validate whatever the vendor claims.
  • Extra risk-committee oversight, whatever the rating.
  • Performing due diligence before buying.
  • Contracts giving documentation, audit rights, and an exit.

Implementation challenges

  • Vendors may not be willing to share enough to validate the model.
  • Old contracts lack audit and exit rights.
  • Hard to validate a ‘black box’ with little information.
  • Everyone leaning on the same few vendors builds hidden risk.

AI and machine-learning models

Impact: Very High
Readiness Gap: Critical

What it means

  • AI and ML get the toughest rules.
  • AI fails in new ways – bias, hallucination, drift, ‘black box’.

What it requires

  • Using AI only where risks are manageable.
  • Decisions should be explainable – more so for customers.
  • Testing for bias, hallucination, drift, and unstable outputs.
  • Challenging models (e.g., red-teaming); controlled auto-updates.
  • Informing customers when a decision is AI-driven, offering a human alternative.
  • Keeping real human oversight, with an override and a kill-switch.

Implementation challenges

  • Hard to make opaque models explainable enough.
  • Bias/drift testing must be ongoing, not one-off.
  • Real (not tick-box) human oversight is hard at scale.
  • Vendor AI keeps changing with each update.
  • Serious shortage of AI-risk skills.

Chapter 5: Are Regulated Entities Ready?

Modeling capability has advanced quickly across the industry, but governance has often grown up function by function rather than as a single enterprise discipline. The readiness question is therefore whether they can govern them consistently across the enterprise. This chapter offers a way to gauge readiness and identify where the largest gaps typically lie.

5.1 Where institutions stand today

Most entities have strong modeling teams, yet governance capabilities have not always kept pace. A few patterns recur across the industry.

Common gaps What it typically looks like
Fragmented governance Separate policies, approvals, and reporting across credit, treasury, finance, and analytics, rather than one framework.
Inconsistent committee structures Some institutions have model risk committees; many do not. Where they exist, terms of reference, membership, and decision authority vary widely.
Incomplete inventory Business spreadsheets, end-user tools, vendor models, and AI solutions operating outside formal governance.
Inconsistent classification Risk-based tiering is either absent or uneven, so scrutiny does not align with model materiality or impact.
Validation skewed to regulatory models Stronger independent review for IRB and ECL, lighter review for business, operational, and AI models.
Limited lifecycle governance Focus on development and validation, with less attention to monitoring, change, and retirement.
Emerging AI governance gaps Explainability, fairness, bias testing, and oversight of external AI are still maturing.

5.2 Why AI breaks the old MRM playbook

Traditional model risk practice assumes slow-moving models and a single technical audience. AI and machine learning strain both, and each strained assumption maps to a failure mode, which the Draft Guidance now names.

  • Speed outruns the review cycle: A model that retrains weekly can change behavior a dozen times before an annual validation looks at it once, which is the reason the Draft Guidance ties validation to change and materiality, not the calendar.
  • One explanation no longer fits every audience: The account a data scientist accepts will not satisfy a declined customer, or an ombudsman, which is why explainability must be built for the hardest audience, not the easiest.
  • Dropping the input does not drop the bias: Even though attributes that could drive discrimination are excluded from the model’s inputs, the model can reconstruct it from correlated data points, proxy variables (spending patterns or device data), and continue to carry the same bias through to its outputs. Fairness, therefore, has to be tested on outcomes, not on inputs alone.
  • Decay is silent: Performance rarely breaks loudly; it drifts as customer behavior and data shift, which is why the guidance expects continuous monitoring, not a point-in-time sign-off.

The paradox is sharpest for the very ambition the industry is chasing. Agentic and self-learning systems are designed to continuously change their own behavior, which is precisely what a once-a-year validation cannot detect. The more autonomous the model, the less an annual review can be trusted to catch it.

5.3 Cost of compliance: the same baseline, an uneven burden

Most of the cost is a fixed baseline that every entity must build regardless of size.

  • Large and complex banks already have foundations to extend. The task is to integrate and bring consistency rather than start from scratch.
  • Smaller and mid-sized organizations start further back. Many have no documented governance at all, and where it is documented, it is often not practiced. They are building capability from scratch, not formalizing what already runs.

5.4 Build versus buy

A sector-wide scarcity of model validators, AI auditors, and explainable AI specialists makes talent itself a cost pressure. That is precisely why the proportionate posture and the build-versus-buy choice matter most at the smaller end: for many base- and middle-layer entities, buying validation, tooling, and monitoring will be more practical than building them in-house.

Whichever way the build-or-buy decision goes, it only changes who does the work, not who carries the risk. A bought model, a bought validation, a bought monitoring stack, each still answers to a board that remains accountable for the outcome.

5.5 What supervisors will look for

Supervisory engagement will test whether governance is real and evidenced, not merely documented. Entities should be able to show, on request:

  • Governance: a board-approved framework, defined roles, and minutes showing the risk committee reviews model risk.
  • Inventory: a complete, current inventory spanning internal, vendor, and AI models, with owners and risk tiers.
  • Tiering: a documented, risk-based tiering methodology applied consistently across the estate.
  • Validation: independent validation records, findings, and timely reporting to the committee.
  • Monitoring: ongoing performance monitoring, drift detection, and evidence of action on breaches.
  • AI and third-party: explainability, fairness, and human-oversight controls, and validation of vendor models despite supplier assurances.
  • Documentation: an audit trail sufficient to reconstruct decisions, changes, and approvals.

5.6 The cost of non-compliance

The case for moving early is not only regulatory. Weak model governance carries costs across several dimensions, and these costs tend to compound rather than remain contained.

Dimension What it looks like Illustrative trigger
Supervisory/regulatory Business restrictions, heightened scrutiny, and remediation mandates Inventory or validation gaps found on inspection
Financial Losses, provisions, capital add-ons Model error or mispricing at scale
Consumer/conduct Grievances, unfair-treatment findings, redress Biased or opaque consumer-facing model
Reputational Public and board exposure A model failure that reaches customers or the press
Systemic Concentration risk Heavy reliance on a few model / AI vendors
Opportunity cost Inability to scale AI safely Governance is too weak to deploy AI with confidence

Key Takeaway

For many entities, meeting the Draft Guidance will not mean building governance from scratch. It will mean integrating existing practices into a single coherent enterprise framework that delivers consistency, transparency, and accountability across all material models. Those that start early will be better placed to meet future expectations and to enable innovation through stronger governance rather than more controls.


Chapter 6: Enterprise Transformation Roadmap

The Draft Guidance sets a clear destination, but the journey differs by size, business model, model landscape, and technology maturity. Implementation is best treated not as a one-off compliance project but as a phased transformation that strengthens governance while minimizing disruption. The aim is a sustainable capability that evolves with business and with technology. Because the Draft Guidance is out for consultation, the period before finalization is the natural moment to begin.

6.1 A four-phase transformation journey

Most institutions implement enterprise MRM in phases, each building on the last.

1

Assess and Mobilize

Understand the current state — 1-3 months

2

Design the Target Operating Model

Build the enterprise framework — 2-4 months

3

Implement and Operationalize

Embed governance into the business — 6-12 months

4

Monitor and Continuously Improve

Keep the framework living — Ongoing

Phase Focus Illustrative activities Owner (lead)
Phase 1: Assess and Mobilize Understand the current state Baseline current MRM against the Draft Guidance and leading practice, inventory material models, assess maturity, and produce a prioritized roadmap. CRO / model-risk function
Phase 2: Design the Target Operating Model Build the enterprise framework Design the MRM policy, governance, and three lines, the inventory and tiering methodology, lifecycle and validation standards, AI governance, and technology architecture. Model-risk function, with CDO (data) and CIO (IT)
Phase 3: Implement and Operationalize Embed governance into the business Stand up committees, register and classify models, validate high-risk models first, deploy the platform and dashboards, and train owners and validators. Board / RMCB, with model owners
Phase 4: Monitor and Continuously Improve Keep the framework living Run periodic maturity and validation-quality reviews, monitor performance indicators, refresh policies, and update AI governance as the estate and rules evolve. Internal audit and the model-risk function

Durations are indicative and scale with size and complexity; a first pass typically takes 12 to 18 months, after which the framework operates continuously. Ownership is shared across the board and its risk committee, the model risk function, model owners, IT and data, and internal audit.

6.2 Transformation priorities

Priorities differ by institution, but certain initiatives consistently deliver the greatest early value.

Horizon Priority initiatives
Immediate A board-approved enterprise MRM policy, an enterprise governance structure, clear ownership, an enterprise model inventory, identification of material AI and third-party models, and a tiering methodology.
Medium-term Standardized lifecycle documentation, an independent validation capability, continuous monitoring, management dashboards, governance workflows, and stronger issue management.
Long-term An enterprise MRM technology platform, integrated AI governance, advanced monitoring analytics, automated reporting, alignment with enterprise risk management, and predictive model-risk indicators.

6.3 Measuring what matters

Boards cannot oversee what they cannot see. A concise set of enterprise model-risk indicators turns governance into something the board can actually monitor.

Horizon Priority initiatives
Inventory completeness Share of known models captured and tiered, and any operating outside governance.
Validation coverage Proportion of high-risk models validated and up to date.
Overdue validations Number and tier of models past their validation due date.
Models live without approval Exceptions running in production, and their remediation status.
Performance and drift alerts Models breaching performance or drift thresholds.
AI and vendor exposure Count and materiality of AI and third-party models, and concentration on key providers.
Issue and remediation status Open model-risk issues by severity and aging.

A board or risk-committee pack should summarize the tier distribution, validation coverage, overdue items, material findings, and the status of AI and vendor models, showing trends over time rather than point-in-time counts.

6.4 Critical path

Across the journey, four items sit on the critical path, where slippage delays everything downstream:

  • Board-approved MRMF: gates everything downstream.
  • Enterprise model inventory and tiering: nothing can be prioritized until models are known and ranked.
  • Independent validation capacity: the scarcest resource; the build-or-buy decision sits here.
  • Vendor contract remediation: long lead time; audit, documentation, and exit rights must be renegotiated.

Key Takeaway

Enterprise model risk management is a transformation journey, not a compliance destination. A phased roadmap that integrates governance, people, processes, and technology builds a scalable, future-ready capability that meets regulatory expectations, strengthens resilience, supports responsible innovation, and builds enduring trust in model-driven decisions.


Chapter 7: Closing Thoughts

Institutions are no longer managing isolated tools but interconnected ecosystems of models that drive financial performance, customer outcomes, and compliance. The Draft Guidance marks a shift in supervisory philosophy, from regulating individual models to strengthening enterprise-wide governance, and that shift is both a challenge and an opportunity.

  • The challenge is strengthening governance across a diverse estate of statistical models, machine learning, generative AI, and third-party platforms.
  • The opportunity is turning model risk management from a compliance obligation into a strategic capability that enables innovation while preserving trust.

7.1 Shape the guidance before it binds

The consultation window closes on 24 July 2026, and the period before the guidance is finalized is an opportunity that organizations should not let pass. It is the moment to engage the RBI directly on practical challenges they anticipate, seek clarity where there is room for interpretation, and put their own views on the record. That engagement should rest on self-assessment where each entity gauge where it stands against the draft, pinpoint the areas where it falls short or where a particular requirement would be difficult to implement.

7.2 Open questions and ambiguities to watch

No draft of this scope is free of ambiguity. Several will matter as the guidance is finalized:

  • What counts as a “material change” for models that retrain continuously.
  • How the rules scale down for smaller entities in practice.
  • Treatment of foundation, frontier, and agentic AI models.
  • Where the framework overlaps or double-counts with Basel IRB and Ind AS 109 validations.
  • Expected timelines for compliance once the guidance is finalized.

7.3 Beyond compliance

Institutions need to move past the question of what is the minimum needed to comply and start asking how stronger governance can improve the quality of their decisions. Done well, model risk management enhances far more than regulatory readiness.

  • Decision quality and organizational transparency.
  • Board oversight and operational resilience.
  • Customer confidence and responsible adoption of AI.
  • Strategic agility, so governance enables performance rather than slowing innovation.

7.4 The choice is now strategic, not procedural

The institutions that treat Draft Guidance as a floor will meet it and gain little. Those who treat it as an operating model will find that the same disciplines (a complete inventory, risk-based tiering, independent challenge, continuous monitoring) are exactly what enable them to deploy AI faster and with more confidence than rivals who cannot.

Good governance improves decision quality, board oversight, and customer trust; its sharpest payoff is strategic agility, the ability to say yes to AI at scale without betting the franchise on a model no one can explain.

The frontier is already visible: continuous AI assurance in place of one-off validation, real oversight of autonomous and agentic systems, and model risk joined up with cyber, data, and operational risk. None of it holds without a culture of transparency, effective challenge, and accountability from the board to the developer, because governance is ultimately practiced, not documented.

7.5 The way forward

The consultation window is the time to move, not wait. The direction is already set, and the institutions that act now will be ready when the guidance is finalized. Four near-term actions matter most:

  • Put ownership on the board’s agenda: name a senior accountable owner and agree on a model-risk appetite before supervisors ask.
  • Build a single source of truth: complete an enterprise model inventory and risk-based tiering that captures AI, spreadsheets, and vendor models, not just regulatory ones.
  • Secure validation capacity early: make the build-versus-buy decision now, because independent validation is the scarcest resource and the longest lead time.
  • Govern AI as a first-class risk: put explainability, bias testing, and human oversight in place before scaling, not after a problem reaches a customer.

Begin during the consultation period, and the framework becomes a head start rather than a scramble.

Key Takeaway

In a market being rebuilt around AI, model governance decides who gets to grow with AI and who gets throttled by it. The models are yours, whether they are built or bought, and so is the race.

Topics in this article

Related

Newsletter

FRM Regulatory Pulse- August 2026

Executive Summary The second edition of the Uniqus "Regulatory Pulse" bulletin covers key regulatory developments and supervisory themes observed across India and the Middle East over the quarter ended June 2026. Consistent with the series, this publication focuses on banking...

Newsletter

Sustainability & Climate Pulse- August 2026

In the News Global Record Climate Finance by Multilateral Development Banks Reaches USD 163 Billion in 2025 In a significant boost for global climate action, multilateral development banks (MDBs) achieved a record climate finance total of USD 163 billion in...

Early Impressions

FASB’s Proposed Accounting Standards Update

Executive Summary On June 10, 2026, the FASB issued a proposed Accounting Standards Update that would clarify the discount rate used to measure the benefit obligation under Subtopic 715-30, Compensation—Retirement Benefits—Defined Benefit Plans—Pension, for certain market-return cash balance plans. The...

Ask Uniqus
Your AI Knowledge Assistant
AI
Hi 👋 How can I help you today?

Download the pdf of this publication


This will close in 0 seconds