RBI MRM draft · methodology

How the self-benchmark is built, and mapped to the draft

Every question, the scoring, and the maturity bands behind the RBI MRM draft self-benchmark — published openly so a risk officer, auditor, or board can review and challenge it. Each question is line-mapped to RBI's June 2026 draft Guidance on Regulatory Principles for Model Risk Management.

Take the self-benchmark →

Scoring

Each question is scored 0, 1, or 2 — score only what you can evidence today, not what is intended or planned. The ten scores sum to a 0–20 raw score, shown as a 0–100 readiness percentage. The result is a directional readiness signal, not a regulatory grade.

  • 0Not demonstrable today
  • 1Partly documented, fragmented, or not consistently evidenced
  • 2Current, owned, evidence-backed, and repeatable

Maturity bands

Deliberately neutral language. The bands describe readiness, not exposure — a vendor tool recording a risk grade against a named regulated entity would be a discoverable artifact.

  1. 0–30% FoundationalThe foundation is still forming. The priority is visibility — one inventory of decisioning assets and clear ownership — before tiering, validation, or board reporting can rest on anything solid.
  2. 31–55% DevelopingA framework is taking shape, but the evidence is fragmented. The work now is turning policy into proof: tiering, validation records, approvals, change logs, and third-party evidence.
  3. 56–75% ManagedModel risk is managed in most places. What remains is consistency and traceability — closing the evidence gaps a reviewer would probe first, and making the trail reproducible.
  4. 76–90% Board-ReadyYou could put a credible model-risk pack in front of the board. Tighten the edges — validation ageing, exception rationale, material-change revalidation, and AI oversight records — so nothing surfaces in a review you did not run.
  5. 91–100% Continuous GovernanceA strong, defensible position. The goal now is keeping it live — re-tiering, revalidating on material change, and keeping the board pack current so readiness does not decay between cycles.
Source map

The ten questions, mapped to the June 2026 draft

Grouped by the four readiness dimensions. Each question shows the draft paragraphs it cites, why it matters, and the first action it implies.

Scope & Inventory

Q1 Draft paras 6, 7(3), 10 Risk + Technology

Have you identified every decisioning asset that could qualify as a model, including scorecards, BRE rules, calculators, spreadsheets, AI/ML systems, prompts, APIs, vendor tools, and co-lending decision flows?

The draft applies to all internally developed, third-party, or combined models and defines model broadly enough to include decision rules and other computational tools that materially influence decisions.

First action: Build one decisioning-asset inventory across LOS, BRE, LMS, data, AI, vendor, and partner systems. Use the broadest definition first, then tier down.

Q2 Draft paras 13(3), 21-24 Compliance + Model owners

Is each asset recorded in a live inventory with intended use, lifecycle status, owner, developer or provider, validator, approver, risk tier, dependencies, and key validation, monitoring, and audit observations?

The draft expects an accurate, comprehensive, up-to-date inventory of active, inactive, under-development, and decommissioned models, with no model used unless it is in inventory.

First action: Create the minimum inventory schema and reconcile it against source systems, vendor lists, rule catalogues, spreadsheets, and committee packs.

Governance & Tiering

Q3 Draft paras 17-20, 52 CRO + Model risk

Do you apply a documented risk-tiering method that considers materiality, complexity, consumer impact, explainability, third-party dependency, and for AI, reliance and autonomy in decision-making?

The draft expects risk-based tiering for all models, with the tier driving validation priority, approval structure, controls, monitoring, reporting, documentation, and continuity planning.

First action: Define tiering criteria, score each asset, record the rationale, and require annual or trigger-based tier review.

Q4 Draft paras 8-15, 22 Board + Senior management

Can you show accountable model owner, developer or provider, independent validator, approver, senior-management responsibility, and three-lines-of-defence coverage for material assets?

The regulated entity remains accountable for model outcomes, and the draft assigns oversight to the Board, Risk Management Committee, senior management, model owners, independent validation, and internal audit.

First action: Create an ownership and authority matrix. Separate owner, validator, and approver roles, and make high-risk ownership visible to senior management and the Risk Management Committee.

Lifecycle Evidence

Q5 Draft paras 29-33, 46(i) Independent validation

Can you evidence independent validation before deployment, after deployment, after material change or trigger events, and periodically as specified in the MRMF, including for third-party models?

The draft expects independent validation by the regulated entity, including for third-party models, with outcomes documented and reports placed before the relevant committee or delegated authority.

First action: Stand up a validation register with latest validation date, next due date, scope, findings, recommendations, owner response, committee date, and evidence links.

Q6 Draft paras 12(1), 18(ii), 34-35 Risk + Committee secretariat

Can you evidence approval or exception approval, including authority, threshold, rationale, conditions, remediation timeline, and committee review for high-risk or equivalent-risk assets?

The draft expects an approval and exception-approval structure with documented decision rationale, and high-risk model validation reports and deployment approvals routed to the Risk Management Committee.

First action: Create a decision log for approvals and exceptions. Capture rationale, approver, conditions, expiry, remediation owner, and board or committee reference.

Q7 Draft paras 16, 36-43 Technology + Model owner

Can you explain what changed in the last quarter and show ongoing monitoring, performance testing, version logs, impact assessments, material-change criteria, revalidation triggers, and fallback plans?

The draft expects ongoing performance testing and monitoring, controlled deployment, structured change management, version records, material-change thresholds, and continuity arrangements.

First action: Create a quarterly change and monitoring pack with material-change decisions, versions, approvals, failed-change recovery, monitoring breaches, incidents, near misses, and fallback status.

Third-party, AI & Board Readiness

Q8 Draft paras 45-48, 51, 53 Vendor + Partnerships

Have you mapped third-party model, LSP, bureau, data, AI provider, API, and co-lending dependencies with due diligence, minimum technical documentation, audit rights, continuity, exit, and provider-update risk evidence?

The draft says accountability stays with the regulated entity, third-party models remain subject to the MRMF, and contracts should support documentation access, audit rights, continuity, and exit.

First action: Build a third-party dependency ledger linked to decision impact. Add provider evidence, contract clauses, validation constraints, supply-chain risk, continuity, and exit readiness.

Q9 Draft paras 25, 49-63 AI risk + Operations

For AI/ML or automated decisions, can you show scope, explainability thresholds, bias/fairness/drift controls, red-team or challenge testing, deployment safeguards, customer interface controls, human-in-command, overrides, suspension, or kill-switch records?

The AI/ML section adds controls for scope, autonomy, explainability, hallucination, bias, drift, dynamic updates, deployment security, customer interfaces, human oversight, overrides, incidents, and near misses.

First action: Create an AI use-case register. Attach explainability, fairness, drift, red-team, prompt-injection, human oversight, override, incident, near-miss, and kill-switch evidence by use case.

Q10 Draft paras 11-14, 33, 37, 46(ii) CRO + Compliance

Could you produce this week a Board or Risk Committee pack showing inventory, high-risk models, validations, approvals, exceptions, changes, third-party exposure, AI exposure, open gaps, breaches, and decisions needed?

The draft gives the Board and Risk Management Committee recurring oversight duties and expects committee visibility into validation reports, tiering, exceptions, third-party models, AI models, breaches, and material concerns.

First action: Create a repeatable evidence pack with a readiness heatmap, high-risk asset docket, validation ageing, exceptions, material changes, third-party/AI exposure, incidents, open gaps, and requested decisions.

Source & guardrails

Mapped to RBI's June 2026 draft Guidance on Regulatory Principles for Model Risk Management, which is out for public consultation and may change before it is final. This benchmark is readiness guidance, not legal advice or a compliance certification. Lokta does not validate, certify, or independently assess models — your model validators, internal audit, and board remain the authority.

Read the RBI draft (PDF) →

Run it against your own controls

Two minutes, one question at a time. Your score is shown on screen; nothing is stored.

Take the self-benchmark

Or see the product behind it: Lokta RBI Model Risk Management →

Talk to the team

Adopt the agent-native lending stack.

Lokta is built for enterprise deployment — VPC or single-tenant cloud, with an audit trail in every state change. We work with a select group of institutions through a founder-led model: deep adoption, deliberate scope, a delivery window the team commits to in writing.