You are here:

How Indian Banks Can Meet RBI’s AI Vendor Security Due Diligence Requirements: A 2026 Action Plan

Business professionals reviewing charts and reports, illustrating AI vendor security due diligence for Indian banks under RBI requirements.

Key Takeaways

  • Indian banks now sit under three layered RBI regimes touching AI vendors at once: the binding 2023 IT Outsourcing Master Direction, the newly binding July 2026 Cybersecurity, Technology: Risk, Resilience and Assurance Directions, and the not-yet-final June 2026 draft Model Risk Management Guidance. None of them let a bank point to a vendor’s certificate as a defense.
  • The RBI’s message across every one of these instruments, going back to 2023, is identical: outsourcing a system does not outsource accountability. A bank remains liable for customer data and model outcomes even when an AI vendor built and operates the system.
  • The July 31, 2026 Directions replaced the 2016 cybersecurity framework outright, with no transition period, and specifically tightened concentration-risk monitoring, exit clauses, and mandatory audits of critical vendors — obligations that apply the moment a bank connects an AI vendor to its systems.
  • RBI’s draft Model Risk Management Guidance, still in consultation as this is written, would require independent validation of every third-party AI model a bank uses — not contractual assurance from the vendor — plus kill-switch capability and human override for customer-facing AI.
  • 70% of surveyed Indian banks and NBFCs already use AI selectively or at scale in live operations, per a 2026 industry survey. Most institutions are retrofitting vendor governance onto AI relationships that already exist, not designing it from a blank page.
  • Global standards — NIST’s AI RMF and ISO 27036-2 for supplier relationships — give Indian banks a ready-made structure to operationalize what RBI is asking for, rather than building a due-diligence process from first principles.

Ask a bank’s compliance team whether their AI vendors have been through security due diligence, and most will point to a signed contract and a vendor-supplied certification. RBI’s current regulatory direction says that’s not enough, and hasn’t been enough since at least 2023. What’s changed in 2026 is the density of the requirement: a binding cybersecurity framework that came into force with zero transition period, and a draft model-risk framework that would make a bank independently validate a vendor’s AI model rather than take the vendor’s word for it.

None of this is theoretical anymore. A July 2026 industry survey found seven in ten Indian banks and NBFCs already running AI selectively or at scale — fraud detection, customer service, credit assessment, document processing. Every one of those deployments likely touches a third-party vendor somewhere in the stack: the model provider, the cloud host, the data-labeling firm, the API layer. RBI’s stance is that the bank owns the risk at every one of those points, regardless of who wrote the code.

This guide lays out what RBI actually requires of banks managing AI vendor risk today, what’s changing as draft guidance moves toward finalization, and a concrete sequence for closing the gap — built on RBI’s own instruments, supplemented with recommendations from the standards and practitioner community already working this problem globally.

Key Definitions

  • TPSP (Third-Party Service Provider): RBI’s term, from the 2023 IT Outsourcing Master Direction, for any external party a regulated entity engages to provide IT or IT-enabled services — including AI vendors, cloud hosts, and model providers.
  • MRMF (Model Risk Management Framework): The board-approved framework RBI’s draft 2026 guidance would require every regulated entity to maintain, covering the full lifecycle of every model — internally built, third-party, or a mix — including AI and machine learning systems.
  • FREE-AI Sutras: The seven guiding principles from RBI’s August 2025 Framework for Responsible and Ethical Enablement of AI committee report — trust, people-first, innovation, fairness, accountability, explainability, and resilience — underpinning the committee’s 26 recommendations.
  • Kill-switch: An emergency capability, specified in RBI’s draft Model Risk Management Guidance, to take a malfunctioning AI model offline immediately, paired with mandatory human override for customer-facing AI decisions.
  • Concentration risk: The exposure created when a bank, or multiple banks across the sector, depend heavily on a single AI vendor, cloud provider, or model — a named focus area in both the 2023 Outsourcing Master Direction and the 2026 Cybersecurity Directions.
  • Human-in-the-loop (HITL): A control requiring a human decision point in an AI-driven process rather than fully automated action, specified in RBI’s draft model-risk guidance as a safeguard against automation bias.

What Does RBI Actually Require for AI Vendor Due Diligence Right Now?

RBI requires banks to treat every AI vendor relationship as a regulated outsourcing arrangement, subject to risk-based due diligence, audit rights, and full accountability for outcomes — a standard set in 2023 and tightened twice since. The foundation is the RBI Master Direction on Outsourcing of Information Technology Services, binding since October 2023, which requires a board-approved outsourcing policy, due diligence on service providers weighing qualitative, quantitative, legal, reputational, and operational factors, and contracts that guarantee both the bank’s and RBI’s right to audit and inspect. It applies whether the “IT service” in question is a core banking platform or a fraud-detection model bought from an AI vendor — RBI drew no distinction.

That foundation got substantially reinforced on July 31, 2026, when RBI’s new Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions came into force for commercial banks, replacing the 2016 cybersecurity framework and the 2023 IT governance master direction outright, with no transition period. Third-party risk management is one of the Directions’ named pillars, and the specifics matter: banks must maintain a current inventory of information assets including vendor-processed data, monitor concentration and single-point-of-failure risk across their vendor base, and ensure contracts allow both bank and RBI audit rights. Cyber incidents detected anywhere in that vendor chain — including at an AI provider — have to reach RBI’s DAKSH reporting platform within six hours of detection.

Sitting on top of both is RBI’s draft Guidance on Regulatory Principles for Model Risk Management, released for consultation on June 24, 2026. It’s the instrument written specifically for AI and it goes further than either of the other two: every model — including ones bought from a vendor — needs to sit inside a board-approved Model Risk Management Framework, get classified by risk tier, and undergo independent validation regardless of what the vendor’s own testing showed. The draft is explicit that outsourcing model development does not transfer accountability, and it adds AI-specific expectations — explainability, bias and hallucination testing, red-teaming, kill-switches, and mandatory human oversight — that a standard IT outsourcing due-diligence checklist was never built to cover.

01. Inventory Every AI Vendor Relationship — Including the Ones Nobody Approved

Start with a complete, current list of every third party whose AI touches your systems or your customers’ data, and treat “we don’t think we have shadow AI” as an assumption to test, not a fact. RBI’s asset-inventory requirement under the July 2026 Directions explicitly covers vendor-processed data, and a model risk framework is only as good as the model inventory underneath it. Business units adopting AI tools without procurement or security sign-off is the single most common gap examiners find, and it’s the one that turns a documented governance program into an incomplete one the moment an auditor asks “is this list actually everything.”

02. Apply Risk-Based Due Diligence, Updated for What’s Different About AI

Run every AI vendor through the same risk-based evaluation the 2023 Outsourcing Master Direction already requires — qualitative, quantitative, legal, reputational, operational — and then add the questions a traditional IT vendor questionnaire doesn’t ask: what data trained the model, whether that data included your customers’ information, how the vendor tests for bias and hallucination, and what happens to your data if the vendor uses it to improve models for other clients. A vendor’s general security certifications answer the infrastructure question. They don’t answer the model question, and RBI’s draft guidance is explicit that they’re not expected to.

03. Rewrite Vendor Contracts for Audit Rights, Exit Clauses, and Incident Timelines

Confirm every AI vendor contract explicitly grants your bank and RBI the right to audit and inspect, specifies an exit and transition plan if the relationship ends, and commits the vendor to reporting incidents to you fast enough that you can meet RBI’s six-hour DAKSH reporting window yourself. Contracts negotiated before AI vendors were a meaningful category often don’t cover model-specific failure modes at all — a vendor obligated to report a data breach isn’t necessarily obligated to report a model that started producing biased credit decisions, and that gap needs closing explicitly, not assumed.

04. Independently Validate Vendor AI Models — Don’t Accept the Vendor’s Word

Build the internal capability, or engage a qualified third party, to test a vendor’s AI model yourself before and after deployment — for accuracy, for bias, for stability under adversarial inputs — rather than relying solely on what the vendor’s own documentation claims. This is the clearest line in RBI’s draft model-risk guidance: financial institutions remain fully accountable for third-party AI tools and are expected to validate them independently. A bank that has never tested a vendor’s fraud model against its own data has no real basis for the confidence it’s implicitly extending to that vendor.

05. Map Concentration Risk Across Your Entire AI Vendor Portfolio

Look across your AI vendor relationships as a portfolio, not one contract at a time, and identify where multiple critical functions depend on the same underlying provider — the same cloud host, the same foundation model, the same specialized fintech partner. RBI’s concern here isn’t hypothetical: multiple banks relying on the same AI system means a single flawed model could misfire the same way across several institutions simultaneously, which is exactly the systemic scenario RBI’s financial-stability work has flagged. A concentration map that only exists in one team’s head isn’t a control — it needs to be a living register the board can actually see.

06. Build Kill-Switch and Human-Override Capability Into Every Customer-Facing AI Integration

Don’t wait for the Model Risk Management Guidance to finalize before building the operational capability to take a vendor’s AI model offline and fall back to a human process. Every customer-facing AI system — a chatbot, an automated credit decision, a fraud flag — needs a defined, tested path to disable it and hand the interaction to a person, plus disclosure to the customer that they’re interacting with AI in the first place. This is a genuinely new operational muscle for most banks, closer to incident response planning than to traditional vendor management, and it needs the same testing discipline.

07. Borrow Structure From NIST AI RMF and ISO 27036-2 Instead of Building From Scratch

Use NIST’s AI Risk Management Framework — its Govern, Map, Measure, and Manage functions — to structure how your bank organizes AI vendor risk internally, and use ISO 27036-2 for the supplier-relationship-specific controls spanning procurement through exit. Neither is mandatory in India, but both were built by practitioners solving exactly this problem, and RBI’s own draft guidance covers similar ground without prescribing a specific methodology. A bank that maps its AI vendor program to an established framework has a much easier time demonstrating rigor to an examiner than one presenting a bespoke process invented internally under deadline pressure.

08. Prepare for the Model Risk Management Guidance to Finalize — Don’t Wait for It

Treat the gap between the draft’s July 24, 2026 comment deadline and a final circular as a preparation window. RBI’s pattern with other recent instruments — replacing the entire 2016 cybersecurity framework in a single day, with zero transition period — suggests final model-risk rules won’t come with a generous glide path either. Every recommendation in this guide is buildable against the draft’s stated direction and the binding instruments already in force; waiting for the final text before starting means compressing months of work into whatever window RBI actually grants.

RBI InstrumentStatusWhat It Requires for AI Vendors
Master Direction on Outsourcing of IT Services (2023)Binding since October 2023Board-approved outsourcing policy, risk-based vendor due diligence, audit rights, concentration-risk awareness
Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions (2026)Binding since July 31, 2026Vendor-inclusive asset inventory, concentration and single-point-of-failure monitoring, annual audits of critical vendors, 6-hour incident reporting via DAKSH
Draft Guidance on Regulatory Principles for Model Risk Management (2026)Consultation closed July 24, 2026 — not yet finalBoard-approved MRMF covering third-party models, independent validation, explainability, kill-switches, human oversight, no accountability transfer to vendors

Statistics & Citations

  • RBI’s Master Direction on Outsourcing of Information Technology Services was notified on April 10, 2023, and became binding on October 1, 2023, requiring risk-based due diligence on service providers across qualitative, quantitative, legal, reputational, and operational factors — Lexology / Reserve Bank of India.
  • The RBI (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 took effect immediately on July 31, 2026, replacing the 2016 Cyber Security Framework with no transition period, and require vulnerability assessments every six months and annual penetration testing for critical customer-facing systems — Security Brigade / Medianama.
  • RBI’s FREE-AI Committee, chaired by Dr. Pushpak Bhattacharyya of IIT Bombay, released its report on August 13, 2025, setting out seven guiding “Sutras” and 26 recommendations across six pillars for responsible AI in India’s financial sector — KPMG India / Dvara Research.
  • RBI’s draft Guidance on Regulatory Principles for Model Risk Management was released for public consultation on June 24, 2026 (Press Release 2026-2027/528), applying to 11 categories of RBI-regulated entities, with comments due by July 24, 2026 — CorpLawUpdates / Business Standard.
  • A 2026 survey of executives across 18 Indian banks and NBFCs found 70% already using AI selectively or at scale in live operations, primarily for customer service, fraud detection, risk analysis, and document processing — industry survey cited in The420.in.
  • The 2026 Black Kite Third-Party Breach Report found an average of 5.28 downstream organizations compromised per vendor breach, with a median 117-day gap between breach occurrence and public disclosure — a pattern increasingly involving AI tools with unmonitored access to sensitive systems — Black Kite / Mitratech.

Summary

RBI has not left banks guessing about what AI vendor due diligence is supposed to look like — it’s spelled it out across three instruments in three years, each one closing a gap the last one left open. The 2023 Outsourcing Master Direction set the baseline: due diligence, audit rights, accountability that survives outsourcing. The July 2026 Cybersecurity Directions made the third-party risk piece binding and specific, with real timelines and real audit expectations. The draft Model Risk Management Guidance, once final, will close the remaining gap by forcing banks to validate AI models themselves rather than trust a vendor’s word for it. Banks that build their AI vendor governance now, against the direction all three instruments are already pointing, won’t be scrambling when the draft becomes a circular. The ones that wait for a final published rule before starting are choosing to do this work under a deadline instead of ahead of one.

Frequently Asked Questions

Is RBI’s draft Model Risk Management Guidance legally binding yet?

No — it’s a draft that closed for public consultation on July 24, 2026, and hasn’t been issued as a final circular. But its direction is consistent with RBI’s binding instruments already in force, and RBI’s recent pattern has been to finalize and enforce quickly, without long transition periods.


Does the 2023 IT Outsourcing Master Direction still apply now that the 2026 Cybersecurity Directions are in force?

Yes. Multiple analyses of the July 2026 Directions note that outsourcing-specific requirements sit in a separate instrument the 2026 Directions deliberately preserved rather than replaced. Banks need to comply with both, not treat the newer instrument as a full substitute.


What counts as an “AI vendor” under RBI’s due diligence expectations?

Any third party providing a model, tool, or service that uses AI or machine learning and touches your systems or customer data — a fraud-detection platform, a customer-service chatbot provider, a credit-scoring model vendor, or a cloud provider hosting a model your bank operates. RBI’s draft guidance defines “model” broadly enough to include scoring algorithms and rule engines, not just modern AI/ML systems.


Can a bank rely on a vendor’s ISO 42001 or SOC 2 certificate instead of doing its own validation?

Not fully. Those certifications are useful evidence of a vendor’s general governance and security maturity, but RBI’s draft model-risk guidance is explicit that regulated entities remain accountable for third-party AI models and are expected to validate them independently — a vendor’s certificate supports due diligence, it doesn’t replace it.


What’s the realistic compliance timeline for a bank starting from scratch?

The binding pieces — outsourcing due diligence and the July 2026 Cybersecurity Directions — apply now, with no grace period. The model-risk-specific requirements are still in draft, but building toward them now, rather than waiting for a final circular, is the only way to avoid a compressed scramble once RBI publishes the final version.


Do NBFCs face the same requirements as commercial banks?

Not identically today — NBFCs currently sit under the 2024 ITGRCA Master Directions rather than the July 2026 Cybersecurity Directions, which apply specifically to commercial banks. RBI’s consistent pattern, though, has been to extend commercial-bank requirements to NBFCs within 12 to 18 months, so treating the commercial bank framework as a preview is a reasonable planning assumption.


What’s the single most common gap banks have in AI vendor due diligence right now?

An incomplete inventory. Most banks can describe their major, procurement-approved AI vendor relationships in detail; far fewer can confidently say they’ve captured every AI tool a business unit has adopted informally. A model risk framework built on top of an incomplete inventory has a hole in it no matter how rigorous the rest of the process is.


How does global guidance like NIST’s AI RMF fit into an RBI-compliant program?

As structure, not substitute. Neither NIST’s AI RMF nor ISO 27036-2 is mandatory in India, but both give a bank a tested way to organize AI vendor governance — inventory, risk assessment, ongoing monitoring — that maps cleanly onto what RBI’s own instruments are asking for, without requiring the bank to invent a methodology from first principles under deadline pressure.

Author

Seecko Das

Seecko Das is an information security, Governance, Risk, and Compliance consultant with a proven record of securing critical infrastructures and enabling regulatory confidence across the MENA, EU, and Asian regions. He specializes in advising fintech, healthcare, cloud, commercial gaming, and high-data-value organizations on aligning technology operations with international security, privacy, and AI governance standards. He holds certifications in ISO 27001/42001 Lead Auditor, CISA, PCI QSA, PCI SSLCA, and CEH, and brings deep expertise across audit, governance, and assurance disciplines. His experience spans PCI DSS/3DS/PIN and SWIFT CSP certification programs, ISO 27001/27701/42001 implementations, EU AI Act and NIST AI RMF adoption, WLA SCS audits, and compliance with UAE IAR, DESC ISR, GDPR, UAE PDPL, and DPDPA requirements. Seecko combines technical rigor with strategic oversight to help organizations manage emerging AI and cyber risks while achieving sustainable compliance and market trust.

Table of Contents

Protect Your Business from Cyber Threats Today!

Safeguard your business with tailored cybersecurity solutions. Contact us now for a free consultation and ensure a secure digital future!

Ready to Secure Your Future?

We partner with ambitious leaders who shape the future, not just react to it. Let’s achieve extraordinary outcomes together.

I want to talk to your experts in:

Related Blogs

Official Reserve Bank of India (RBI) gold seal logo centered over an abstract dark background with flowing golden digital data waves, representing AI risk governance, banking compliance, and the central bank's technology mandate.
Glowing AI lightbulb on a cube surrounded by human figures, symbolizing building a responsible AI culture through data privacy, governance, and risk management practices