Follow us on Facebook → fresh APAC stories, daily

Capital

India’s central bank makes AI accountability non-negotiable for lenders

Reserve Bank of India Governor Sanjay Malhotra told banks on August 12, 2026 that they cannot hide behind algorithms, requiring complete AI inventories, explainability, and board-approved governance before deploying credit models.

Reserve Bank of India Governor Sanjay Malhotra told banks on August 12, 2026 that they must take full responsibility for AI-driven lending decisions, declaring that “the model decided” can never be an acceptable answer. The speech at the FIBAC conference in Mumbai outlined governance requirements including explainability, human oversight, and board accountability, while endorsing AI as a tool to bring unbanked Indians into formal credit.

The framework is principles-based, not a final circular, leaving banks to build governance before the regulator turns expectations into enforceable rules. The endorsement of alternative data for credit scoring could reshape lending to millions of gig workers and small businesses.

India’s central bank wants lenders to use artificial intelligence to reach borrowers who have never had a formal loan. But it will not let them hide behind the algorithm. On August 12, 2026, at the FIBAC conference in Mumbai, Governor Sanjay Malhotra told the industry that AI could pull millions of first-time borrowers, gig workers, and small enterprises into the credit system by reading signals traditional underwriters miss — cash flows, tax filings, digital payments, the alternative data that builds a financial identity without a pay stub. Then he drew a line.

“The model decided,” he said, “can never be an acceptable answer to a customer, an auditor, or the Reserve Bank.” The governor’s prescription was specific. Banks must maintain complete AI inventories, adopt board-approved policies with clear accountability, and prove they can explain lending and fraud decisions. They must stress-test models before and after deployment. And wherever an AI failure could hurt a customer or the financial system, a human must be able to step in. The message was clear: adopt AI, but do not outsource responsibility.

Get the latest APAC news as it happens — follow Indoneo on Facebook

The governance framework that comes with the endorsement

India’s banks currently operate with a cost-to-income ratio of 47 to 49 per cent, according to coverage citing a BCG-linked figure. That is the benchmark Malhotra identified as the efficiency gain that AI promises to help reduce, and the governance cost it demands. The same models that can cut per-loan costs can also embed bias, concentrate risk, and resist explanation.

For a gig worker in Mumbai with no pay stub but a steady stream of digital payments, the RBI’s endorsement of alternative data is not a policy abstraction. It is the difference between a bank loan and a moneylender at 40 per cent. Malhotra framed AI as a capability to be harnessed responsibly, not a risk to be contained. He pointed to early-warning models that could identify borrowers approaching default and trigger preventive counseling rather than debt recovery — a pathway to financial inclusion, not just collection.

The governor then laid out the governance demands. Banks must keep a complete inventory of all AI systems, including those embedded in vendor software. They must be able to explain material AI decisions in lending and fraud detection. They must red-team and stress-test models before and after deployment. And they must ensure human oversight at every point where an AI failure could harm a customer or financial stability. The governor also identified concentration among a few AI vendors as a key risk, warning that model flaws could spread across institutions if a small number of shared vendors supplied multiple banks. The framework the governor outlined is easier seen than read.

The speech is not a circular. The RBI has not yet issued a formal AI rulebook, and the date of the address — August 12, 2026 — underscores that the details are still being absorbed. What exists is a principles-based posture, described in coverage as proportionate rather than one-size-fits-all. The question now is whether banks will treat the speech as a checklist or a genuine shift in how they govern AI.

A central bank setting rules for a data-rich market

The speech is less about whether banks should use AI than about who sets the operating rules for a credit market that is becoming more data-rich and less relationship-driven. The RBI is trying to prevent a technology shift from turning into a hidden governance failure inside lenders that are otherwise competing to automate faster.

India’s account ownership rate reached 77.6 per cent in 2021, up from 53.7 per cent in 2014, according to the World Bank Global Findex 2021. Yet the RBI’s consumer confidence survey showed current income sentiment at just 95.5 in July 2026 — a signal of still-cautious household balance sheets. The gap between having an account and accessing affordable credit remains wide. Malhotra’s endorsement of alternative data is designed to close it, but only if banks build the governance to match.

Western banks and vendors selling credit, fraud, or customer-service AI into India now face a procurement standard built around explainability and human override, not just model accuracy. That could become a compliance export as other emerging markets watch. The next RBI communication on AI supervision, expected within one to three quarters, will reveal whether the speech becomes operational policy. If it does, banks that built governance early will have a head start. If it does not, the framework remains a speech — and the risk of uneven implementation grows.

Beyond the headline

The Bigger Picture

The central bank is setting the operating rules for a credit market that is becoming more data-rich and less relationship-driven. The speech is an attempt to prevent a technology shift from turning into a hidden governance failure inside lenders that are otherwise competing to automate faster.

The Power Behind It

By making accountability non-delegable, the RBI shifts power away from procurement teams and technology suppliers toward bank boards and risk functions. The real control point is not the model vendor, but the institution that can document why a decision was made and who can stop it.

The Reach

Global banking technology vendors now face a new sales hurdle in India: they must prove that their tools can be inventoried, explained, and overridden inside a regulated lender. Explainability and override requirements raise the bar for enterprise AI products sold to Indian financial institutions, especially where the same product is deployed across multiple banks.

A compliance window that will not stay open

With the RBI’s governance expectations now public, banks and vendors face a compliance window that will close when the first supervisory review begins.

  • Western Bank Executive with Indian Operations

    You must review your current AI deployment and procurement strategies in India to ensure compliance with the RBI’s new governance, explainability, and human oversight mandates. Start by mapping every AI system used in Indian lending, including vendor tools. The RBI expects a complete inventory. Next, test whether your models can explain a loan denial in plain language — not just a risk score. The speech made clear that “the model decided” is not an answer. Check the RBI’s speeches page for any follow-up circular within the next quarter.

  • Global Fintech or AI Vendor Targeting Indian Banks

    You need to assess your product roadmap to incorporate features for AI inventory management, explainability, and human override capabilities to remain competitive and compliant in the Indian market. Indian banks will now ask whether your tool can be inventoried, explained, and overridden. If your product cannot produce a human-readable reason for a credit decision, expect procurement to stall. Build override dashboards and audit trails into your next release. The sales hurdle is now governance, not accuracy.

  • Investor in Indian Financial Services or Tech

    You should evaluate the AI governance readiness of your portfolio companies in the Indian banking and fintech sectors, and identify potential investment opportunities in regtech or AI compliance solutions. Look at Indian banks with heavy SME and new-to-credit exposure — they face higher compliance costs and slower AI rollout. Conversely, regtech firms selling model inventory, explainability, and red-teaming tools could see demand rise. HSBC’s India operations and global cloud vendors with banking clients are directly exposed.

  • Global Financial Regulator or Policy Professional

    You should analyze the RBI’s specific requirements for AI explainability, accountability, and human oversight to inform discussions and policy development within your own regulatory body. Compare the RBI’s principles-based approach with the EU’s AI Act, which would likely classify credit-scoring AI as high-risk. The RBI’s emphasis on board accountability and human override, without a prescriptive statute, offers a lighter-touch model that may influence other emerging markets. Review the European Commission’s AI Act implementation pages for contrast.

FAQ

Will banks have to disclose why an AI loan was rejected?

The speech says banks must be able to explain material AI-driven decisions, especially in lending and fraud. That implies internal traceability and customer-facing explanation duties, but it does not yet spell out a statutory disclosure template or appeals process. Whether the RBI turns this into a formal supervisory expectation or leaves it to bank policy remains an open question.

What counts as acceptable alternative data?

Coverage explicitly names cash flows, GST filings, utility payments, digital footprints, digital platforms, and payment records. The unresolved question is not whether those sources can be used, but whether lenders can combine them lawfully and consistently under India’s privacy and data-governance rules, especially when vendors process the scoring logic outside the bank.

How quickly could banks implement the governance stack?

The practical bottleneck is likely to be model inventory, board approval, and stress-testing rather than model purchase. Banks using third-party AI will need to map embedded tools, set override rights, and document responsibility for each use case before deployment, which means implementation timetables will vary sharply between large banks and smaller lenders.

Explainer

FIBAC
FIBAC is an annual banking conference in India, co-hosted by the Federation of Indian Chambers of Commerce and Industry (FICCI) and the Indian Banks’ Association (IBA). The 2026 edition in Mumbai was the first where AI governance was the central theme of the central bank governor’s address. It has become a platform where the RBI often signals its supervisory priorities to the industry.
Alternative data
Alternative data refers to non-traditional information used to assess creditworthiness, such as utility payments, mobile phone usage, and digital transaction records. In India, the Account Aggregator framework enables consent-based sharing of such data between financial institutions. The RBI’s endorsement signals that lenders can use these signals to reach borrowers without formal credit histories.
Explainability
Explainability is the requirement that an AI system’s decisions can be understood and articulated in human terms. The RBI’s draft model risk management framework already calls for human oversight and override mechanisms for material-model risk. The governor’s speech reinforced that banks must be able to explain AI-driven lending and fraud decisions to customers and auditors.
Red-teaming
Red-teaming is a practice borrowed from cybersecurity where a team simulates attacks to find weaknesses. In AI governance, it means stress-testing models with adversarial scenarios to uncover biases or failure modes before deployment. The RBI expects banks to red-team AI systems both before and periodically after they go live.
Principles-based regulation
Principles-based regulation sets high-level outcomes and expectations rather than prescriptive rules. The RBI’s approach to AI governance is described as proportionate and principles-based, meaning banks have flexibility in how they meet standards like explainability and accountability, but must demonstrate compliance to the supervisor. This contrasts with the more rule-based EU AI Act.

Covered in this article: South Asia India

Indoneo APAC Desk

The editorial operation behind Indoneo's breaking news and developing story coverage. The APAC Desk monitors primary sources across 75 countries and territories — governments, regulators, research institutions — and answers the question regional coverage rarely asks: what does this mean for a Western reader's money, travel, safety, or decisions. Indoneo's reporting is produced using AI-assisted drafting within an editorial pipeline built for source verification and originality.