India Regulatory Hub
Cross-regulator · India Deep Dive

AI in BFSI — Regulatory Map

No single Indian 'AI Act' exists yet — AI obligations arrive through sectoral rules. This map consolidates every AI-relevant requirement a BFSI entity faces in 2026.

Last verified: 2026-06-17
RegulatorAI-Relevant Rule / InitiativeWhat It RequiresStatus
RBIFREE-AI Committee framework (2025)Framework for Responsible and Ethical Enablement of AI in financial services — governance, explainability and accountability expectations for AI in lending and operationsRecommendations published; supervisory expectations forming
RBIDigital Lending Guidelines 2022Algorithmic credit underwriting must remain explainable; lending service providers' models fall within the RE's accountability; no automated decisioning without grievance pathIn force
RBIMD-ITGRC model risk expectationsAI/ML systems are 'critical IT assets' — change management, audit trails and validation apply to models in productionIn force (Apr 2024)
SEBIAlgo trading framework (retail algo rules, 2025)Exchange approval for retail algos; broker accountability for API-based algo orders; audit trail for every algo orderIn force
SEBIAI/ML disclosure circular (2019, updated)Quarterly reporting by intermediaries of AI/ML systems used in products, surveillance and complianceIn force
SEBICSCRF coverage of AI systemsAI systems in scope of asset inventory, VAPT and incident reporting under CSCRFIn force (Aug 2024)
IRDAIAI/ML in underwriting & claimsFairness and non-discrimination expectations for AI-based underwriting, pricing and claims triage; board accountability for model outcomesSupervisory expectations; guidelines evolving
DPDPSDF algorithm audits (§10)Significant Data Fiduciaries must audit algorithms for risk to data principals' rights — first statutory algorithm-audit duty in IndiaEnforceable ~May 2027
DPDPAutomated decision-making + childrenNo tracking/behavioural monitoring or targeted ads to children; verifiable parental consent gates AI personalisation for minorsEnforceable ~May 2027
CERT-InAI system incidents reportableAttacks or malicious/suspicious activity affecting AI/ML systems are a reportable incident category — 6-hour clock appliesIn force (Jun 2022)

Made with Emergent