Home / Resources / Frameworks / RBI FREE-AI
RBI FREE-AI: India's AI governance blueprint for the financial sector
The Reserve Bank of India's Framework for Responsible and Ethical Enablement of AI sets governance expectations for every AI system operating within India's regulated financial sector. Seven sutras, six pillars, twenty-six recommendations, and a clear accountability principle: the regulated entity always remains responsible for model outcomes.
What is FREE-AI?
FREE-AI (Framework for Responsible and Ethical Enablement of Artificial Intelligence) is a comprehensive AI governance framework issued by the Reserve Bank of India. The eight-member expert committee, chaired by Dr. Pushpak Bhattacharyya of IIT Bombay and constituted in December 2024, released its report on August 13, 2025 after consulting over 100 stakeholders including banks, NBFCs, fintechs, academics, and global regulators.
612
RBI-regulated entities surveyed by the committee, of which 20.8% were deploying AI systems
RBI FREE-AI Committee Report, Aug 2025
18%
of AI-using regulated entities maintained audit logs for their AI systems
RBI FREE-AI Committee Survey
85%
of surveyed entities requested a formal regulatory framework for AI governance
RBI FREE-AI Committee Survey
Who must comply
Scheduled Commercial Banks
All SCBs including foreign banks operating in India. The framework requires board-approved AI policies, model inventories, and risk classification across all AI deployments.
RBI FREE-AI · Banking Regulation Act, 1949
NBFCs and Fintechs
Non-Banking Financial Companies across all tiers and fintech entities providing financial services under RBI's regulatory ambit. Accountability for AI outcomes cannot be outsourced to algorithms or vendors.
RBI FREE-AI · RBI Act, 1934
Payment System Operators
PSOs, cooperative banks, regional rural banks, and all-India financial institutions. AI governance obligations apply regardless of the institution's size or current level of AI adoption.
RBI FREE-AI · Payment and Settlement Systems Act, 2007
Third-party AI vendors
Cloud AI vendors, technology providers, and offshore service providers are indirectly covered. Indian institutions must "flow down" RBI obligations through contracts, giving the framework indirect extraterritorial reach.
RBI FREE-AI · Vendor governance provisions
What you must do
Board-approved AI policy and governance structure
Sutra 5: Accountability. The board must approve an AI policy (annually reviewed), define governance structures, risk appetite, oversight protocols, and clear accountability lines. A named executive, such as a Chief AI Ethics Officer or designated CRO/CDO, must be accountable. Quarterly board reviews of AI risk are required for serious deployments.
Nexovern's continuous inventory feeds the governance data the board needs, covering every agent, its owner, risk class, and runtime behavior, updated live rather than assembled manually each quarter.
Comprehensive AI model inventory
Pillar 6: Assurance. Maintain a registry of all AI systems in production and pilot, each classified by function, data sensitivity, customer impact, degree of automation, and third-party dependency. Named owner, developer, validator, and approver for every model. Decommissioned models must be retained for at least 10 years. Anonymized summaries feed RBI's planned National Repository.
Nexovern discovers and inventories every AI agent, copilot, and MCP across your endpoints automatically, classified by risk tier, with full lifecycle tracking from deployment through decommissioning.
Audit trails and incident reporting
Pillar 5: Protection. Tamper-evident audit logs, standardized incident reporting templates, and proportionate escalation mechanisms. Pre-deployment validation, post-deployment drift detection, and continuous fairness monitoring. Independent validation reports must reach the Board Risk Committee within 3 months.
Nexovern captures prompt-level execution records and OS-layer telemetry for every AI session, correlated under one identity. When an incident occurs, the evidence for root cause analysis and reporting is already captured.
Consumer protection and explainability
Sutra 2: People First. Plain-English disclosure when AI is involved in a decision. Right to challenge AI-driven decisions, especially for high-stakes decisions like credit, pricing, fraud, and AML. Grievance redressal mechanisms for AI-influenced decisions. Human assistance must be available on request.
Nexovern's decision-path records reconstruct why a specific AI action was taken, giving compliance teams the evidence they need to respond to customer challenges and regulatory inquiries.
Third-party vendor governance
Pillar 4: Governance. Explicit AI-specific contract language, audit rights for both the entity and RBI, incident notification obligations, data confidentiality requirements, and geo-sovereignty constraints. Vendor certification alone is insufficient; the entity must independently validate.
Nexovern's discovery layer identifies AI systems and MCP integrations operating through third-party services, ensuring vendor-deployed AI is visible and governed under the same framework as internal deployments.
Penalties for non-compliance
Supervisory scrutiny
Heightened scrutiny during on-site and off-site supervision. The committee recommends that supervisory tools be updated to incorporate AI considerations, enabling RBI to assess compliance during routine inspections.
RBI supervisory framework
Enforcement actions
Monetary penalties under the RBI Act 1934 and Banking Regulation Act 1949. Restrictions on business activities, Prompt Corrective Action frameworks, and potential impact on licensing and approval processes.
RBI Act · Banking Regulation Act · PSSA 2007
Deployment restrictions
Regulatory restrictions on AI deployments or new AI-related product launches for entities that fail to demonstrate adequate governance, audit, and accountability structures.
RBI Master Directions (anticipated)
Advisory today, mandatory tomorrow
The framework is currently advisory, but it is expressly designed for conversion into binding requirements via Master Directions and circulars. Institutions delaying until final mandatory guidance will be compressing 12 months of work into an implementation window.
Expected operationalization: 12 to 24 months from Aug 2025
Key dates
01
Dec 2024: Committee constituted
RBI formally constitutes the eight-member FREE-AI Committee under Dr. Pushpak Bhattacharyya to recommend a comprehensive AI governance framework for India's financial sector.
02
Aug 13, 2025: Report released
The FREE-AI Committee Report is officially published, establishing seven sutras, six pillars, and twenty-six recommendations spanning infrastructure, policy, capacity, governance, protection, and assurance.
03
FY 2025-26: Awareness and capacity building
Phase 1 focuses on board-approved AI policies, institutional AI inventories, baseline risk classification, and data governance initiation. The industry's recommended six-month urgent action window.
04
FY 2026-27: Governance institutionalization
Operational AI governance frameworks, audit frameworks, fairness testing, sector-wide coordination, and annual public disclosures in annual reports begin. Draft MRM guidance consultation expected.
05
FY 2027-28: Full implementation
Mandatory audits for high-risk systems, National Repository operational, sector-wide incident reporting active, and cross-regulatory coordination fully established.
How Nexovern helps
- AI model inventory (Rec. 23): Automated discovery and classification of every AI agent, copilot, and MCP tool across your endpoints, maintained live rather than assembled manually for each review cycle.
- Risk classification (Rec. 16): AI systems classified by function, data sensitivity, customer impact, and autonomy level, aligned to the high, medium, and low risk tiers the framework prescribes.
- Audit trail and incident evidence (Rec. 22, 24): Prompt-level execution records correlated with OS-layer telemetry and identity, producing the tamper-evident audit trail the Three Lines of Defense model expects.
- Board reporting (Rec. 25): Governance dashboards that surface the adoption, risk posture, and compliance status data boards need for quarterly reviews and annual report disclosures.
- Third-party visibility (Rec. 14): Discovery of vendor-deployed AI systems and MCP integrations operating within your environment, ensuring no AI runs outside governance, regardless of where it was built.
- Continuous monitoring (Sutra 7): Drift detection, adherence scoring, and real-time alerts for policy violations, replacing periodic spot-checks with continuous assurance.
- Consumer protection evidence (Rec. 18): Decision-path reconstruction for AI-influenced outcomes, supporting the explainability, challenge rights, and grievance redressal the framework mandates.
- Kill switch and containment (Rec. 21): Runtime controls to quarantine or disable specific agents and sessions when they exceed policy boundaries, supporting the business continuity and fallback mechanisms the framework requires.
Build your FREE-AI compliance posture before the window closes
The framework is advisory today, but the compliance architecture it demands takes months to build. A Nexovern demo maps your current AI estate against the 26 recommendations and shows where the gaps are.