RBI Sets Out Responsible AI Guardrails for Banks: Human Accountability, Explainability and Resilience in Focus
Read Time:
The Reserve Bank of India has sharpened its message on artificial intelligence in banking: banks should adopt AI rapidly, but they must not outsource accountability to algorithms.
In a keynote address on 19 August 2026, RBI Deputy Governor Shri Shirish Chandra Murmu outlined a governance-oriented vision for AI in Indian banking built around inclusion, human judgement, operational resilience, fair conduct and explainability. The speech, delivered at the CNBC-TV18 Banking Transformation Summit in Mumbai, provides one of the clearest recent statements of RBI's expectations as banks expand the use of AI in credit, servicing, fraud detection and decision-making.
RBI's starting point: the banking system is strong enough to innovate
The Deputy Governor said India's banking system is well capitalised and profitable, with a capital-to-risk-weighted-assets ratio of 17.7%, profit after tax exceeding ₹4 lakh crore and gross non-performing assets at 1.8%. RBI stress tests, he said, suggest that the system is positioned to absorb adverse shocks.
That strength creates room for banks to scale technology and reach, but RBI's message is that growth should not be measured only by balance-sheet expansion or aggregate credit. It should also be judged by who receives finance, whether consumer needs are met and whether banks build sufficient technology, process and governance capacity as their operations become more complex.
AI should help banks reach borrowers the system does not yet understand
RBI highlighted a structural concern in commercial credit. According to data cited in the speech, the share of fresh businesses entering the formal credit system fell from 52% in 2022-23 to 42% in 2025-26, even as outstanding commercial credit grew by 14% over the year.
The Deputy Governor argued that more data and better analytical tools should not merely make banks faster at serving borrowers they already understand. Instead, AI should help lenders assess borrowers who may not have traditional collateral, long financial histories or conventional documentation.
He pointed to alternative data such as cash flows, GST filings, utility payments, e-commerce records, mobile usage, agricultural information and geospatial data. Such inputs, when collected with consent, tested for reliability and bias and used responsibly, can strengthen human credit judgement and potentially bring more 'credit invisible' borrowers into the formal system.
Human judgement cannot become ceremonial
A major theme of the speech is that human oversight must remain meaningful. RBI cautioned that AI models can fail when used for new customer segments, new activities or changed economic conditions. A model that performs well on average can still produce poor outcomes for a smaller or vulnerable group.
For that reason, the people responsible for reviewing automated decisions must understand the basis of the model and have the authority to intervene. The Deputy Governor warned against systems in which human review happens only after material choices have already been made.
For boards and senior management, this means accountability remains at the top. AI can help assemble information across an institution, but governance cannot be delegated to a model. RBI also warned about the possibility of 'centralised algorithmic risk' if too much institutional judgement is concentrated in common automated systems.
Shared models and vendors can create concentration risk
RBI also drew attention to system-wide risks. If multiple institutions depend on the same data sources, models, technology providers or infrastructure, a common failure can affect many banks at once.
The speech therefore calls for effective challenge, limits on undue concentration and credible alternatives. This is particularly relevant for banks using common cloud providers, third-party scoring systems, outsourced AI models or shared technology infrastructure.
AI should improve fraud detection and operational resilience
The Deputy Governor said AI can connect structured indicators with audit observations, incident narratives, complaints and system logs to identify emerging fraud, conduct, operational or cyber risks earlier.
He cited initiatives such as MuleHunter.ai and the Digital Payments Intelligence Platform as examples of pooling signals across the financial system to improve detection and coordinated response.
RBI's expectation is not simply that AI systems work under normal conditions. Banks should retain alternative arrangements and the human capability needed to act when automated systems fail or behave unexpectedly. The speech specifically calls for adverse testing before deployment and repeated testing thereafter.
Customer-impacting decisions must be explainable and challengeable
The strongest customer-protection message is that materially adverse decisions should not become opaque simply because they are automated. The Deputy Governor said that where a decision affects a customer — for example, a loan decline, lower limit, account restriction or claim denial — there should be a route to a person who can reconsider it.
He summarised the principle in practical terms: a machine may reach a decision, but a person must own it. Banks should also disclose when customers are dealing with automated systems, because that knowledge affects how customers interpret the information they receive and whether they seek further review.
The speech also tied AI governance to existing conduct expectations such as the Key Facts Statement and the Internal Ombudsman mechanism. Formal consent alone is not enough if terms are difficult to understand or the practical consequences become visible only later.
RBI wants banks to maintain an inventory of AI systems
Among the most actionable governance points is the call for banks to understand exactly what technology they are using. The Deputy Governor said institutions should maintain a current inventory of every model and AI system in use, including systems embedded in vendor products.
This has direct implications for internal audit, risk management, compliance, outsourcing governance and model-risk functions. Banks will need visibility not just over in-house models, but also over third-party systems that influence credit, fraud, customer service, KYC or other decisions.
Why this matters for CAs, auditors and finance professionals
- Internal audit: AI governance will increasingly require testing of model controls, vendor dependence, override mechanisms, data quality and operational resilience.
- Risk and compliance: Institutions need processes for bias testing, explainability, customer escalation and concentration-risk monitoring.
- Finance and credit: Alternative data can expand underwriting capability, but decision ownership cannot be transferred to a model.
- Boards and senior management: Ultimate accountability for AI-enabled decisions remains with the institution's leadership.
- Customer conduct: Banks should be able to explain adverse automated decisions and provide meaningful human review.
RBI is not signalling resistance to AI. It is signalling that scale and speed must be matched by governance capability. Banks adopting AI should be able to identify every material model in use, understand its limitations, test it under adverse conditions, preserve human authority, manage vendor and concentration risk, and explain customer-impacting outcomes. For audit and compliance teams, those themes are likely to become increasingly important benchmarks for evaluating responsible AI deployment in financial institutions.
Useful official links
A Vision for Responsible AI, Resilient Banking
Key takeaway
The August 19 RBI speech provides detailed, practical governance principles for AI use by banks and is highly relevant to banking, risk, audit, compliance and finance professionals.