Why Nexovern
Support Request a demo

Home  /  Resources  /  Frameworks  /  RBI FREE-AI

RBI FREE-AI: India's AI governance blueprint for the financial sector

The Reserve Bank of India's Framework for Responsible and Ethical Enablement of AI sets governance expectations for every AI system operating within India's regulated financial sector. Seven sutras, six pillars, twenty-six recommendations, and a clear accountability principle: the regulated entity always remains responsible for model outcomes.

What is FREE-AI?

FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) is a comprehensive AI governance framework issued by the Reserve Bank of India. The eight-member expert committee, chaired by Dr. Pushpak Bhattacharyya of IIT Bombay and constituted in December 2024, released its report on August 13, 2025 after consulting over 100 stakeholders including banks, NBFCs, fintechs, academics, and global regulators.

612

RBI-regulated entities surveyed by the committee, of which 20.8% were deploying AI systems

RBI FREE-AI Committee Report, Aug 2025

18%

of AI-using regulated entities maintained audit logs for their AI systems

RBI FREE-AI Committee Survey

85%

of surveyed entities requested a formal regulatory framework for AI governance

RBI FREE-AI Committee Survey

Who must comply

Scheduled Commercial Banks

All SCBs including foreign banks operating in India. The framework requires board-approved AI policies, model inventories, and risk classification across all AI deployments.

RBI FREE-AI · Banking Regulation Act, 1949

NBFCs and Fintechs

Non-Banking Financial Companies across all tiers and fintech entities providing financial services under RBI's regulatory ambit. Accountability for AI outcomes cannot be outsourced to algorithms or vendors.

RBI FREE-AI · RBI Act, 1934

Payment System Operators

PSOs, cooperative banks, regional rural banks, and all-India financial institutions. AI governance obligations apply regardless of the institution's size or current level of AI adoption.

RBI FREE-AI · Payment and Settlement Systems Act, 2007

Third-party AI vendors

Cloud AI vendors, technology providers, and offshore service providers are indirectly covered. Indian institutions must "flow down" RBI obligations through contracts, giving the framework indirect extraterritorial reach.

RBI FREE-AI · Vendor governance provisions

What you must do

Board-approved AI policy and governance structure

Sutra 5: Accountability. The board must approve an AI policy (annually reviewed), define governance structures, risk appetite, oversight protocols, and clear accountability lines. A named executive, such as a Chief AI Ethics Officer or designated CRO/CDO, must be accountable. Quarterly board reviews of AI risk are required for serious deployments.

Nexovern's continuous inventory feeds the governance data the board needs, covering every agent, its owner, risk class, and runtime behavior, updated live rather than assembled manually each quarter.

Comprehensive AI model inventory

Pillar 6: Assurance. Maintain a registry of all AI systems in production and pilot, each classified by function, data sensitivity, customer impact, degree of automation, and third-party dependency. Named owner, developer, validator, and approver for every model. Decommissioned models must be retained for at least 10 years. Anonymized summaries feed RBI's planned National Repository.

Nexovern discovers and inventories every AI agent, copilot, and MCP across your endpoints automatically, classified by risk tier, with full lifecycle tracking from deployment through decommissioning.

Audit trails and incident reporting

Pillar 5: Protection. Tamper-evident audit logs, standardized incident reporting templates, and proportionate escalation mechanisms. Pre-deployment validation, post-deployment drift detection, and continuous fairness monitoring. Independent validation reports must reach the Board Risk Committee within 3 months.

Nexovern captures prompt-level execution records and OS-layer telemetry for every AI session, correlated under one identity. When an incident occurs, the evidence for root cause analysis and reporting is already captured.

Consumer protection and explainability

Sutra 2: People First. Plain-English disclosure when AI is involved in a decision. Right to challenge AI-driven decisions, especially for high-stakes decisions like credit, pricing, fraud, and AML. Grievance redressal mechanisms for AI-influenced decisions. Human assistance must be available on request.

Nexovern's decision-path records reconstruct why a specific AI action was taken, giving compliance teams the evidence they need to respond to customer challenges and regulatory inquiries.

Third-party vendor governance

Pillar 4: Governance. Explicit AI-specific contract language, audit rights for both the entity and RBI, incident notification obligations, data confidentiality requirements, and geo-sovereignty constraints. Vendor certification alone is insufficient; the entity must independently validate.

Nexovern's discovery layer identifies AI systems and MCP integrations operating through third-party services, ensuring vendor-deployed AI is visible and governed under the same framework as internal deployments.

Penalties for non-compliance

Supervisory scrutiny

Heightened scrutiny during on-site and off-site supervision. The committee recommends that supervisory tools be updated to incorporate AI considerations, enabling RBI to assess compliance during routine inspections.

RBI supervisory framework

Enforcement actions

Monetary penalties under the RBI Act 1934 and Banking Regulation Act 1949. Restrictions on business activities, Prompt Corrective Action frameworks, and potential impact on licensing and approval processes.

RBI Act · Banking Regulation Act · PSSA 2007

Deployment restrictions

Regulatory restrictions on AI deployments or new AI-related product launches for entities that fail to demonstrate adequate governance, audit, and accountability structures.

RBI Master Directions (anticipated)

Advisory today, mandatory tomorrow

The framework is currently advisory, but it is expressly designed for conversion into binding requirements via Master Directions and circulars. Institutions delaying until final mandatory guidance will be compressing 12 months of work into an implementation window.

Expected operationalization: 12 to 24 months from Aug 2025

Key dates

01

Dec 2024: Committee constituted

RBI formally constitutes the eight-member FREE-AI Committee under Dr. Pushpak Bhattacharyya to recommend a comprehensive AI governance framework for India's financial sector.

02

Aug 13, 2025: Report released

The FREE-AI Committee Report is officially published, establishing seven sutras, six pillars, and twenty-six recommendations spanning infrastructure, policy, capacity, governance, protection, and assurance.

03

FY 2025-26: Awareness and capacity building

Phase 1 focuses on board-approved AI policies, institutional AI inventories, baseline risk classification, and data governance initiation. The industry's recommended six-month urgent action window.

04

FY 2026-27: Governance institutionalization

Operational AI governance frameworks, audit frameworks, fairness testing, sector-wide coordination, and annual public disclosures in annual reports begin. Draft MRM guidance consultation expected.

05

FY 2027-28: Full implementation

Mandatory audits for high-risk systems, National Repository operational, sector-wide incident reporting active, and cross-regulatory coordination fully established.

How Nexovern helps

Build your FREE-AI compliance posture before the window closes

The framework is advisory today, but the compliance architecture it demands takes months to build. A Nexovern demo maps your current AI estate against the 26 recommendations and shows where the gaps are.