RBI MRM draft · self-benchmark

Score your readiness for RBI's draft model risk management framework.

An RBI model risk management framework for an NBFC is the set of controls the June 2026 draft guidance expects around every model, rule and scorecard behind a lending decision: an inventory of what is in use, ownership and risk tiering, validation and monitoring through the model's life, and evidence a board or supervisor can inspect. This 10-question self-benchmark, for NBFCs, fintech lenders and banks, scores what your team can evidence today, each question line-mapped to the draft. You get a readiness score, a dimension breakdown and a finding for every dimension. It is readiness guidance, not a compliance certificate: your validators, auditors and board remain the authority.

Answer for what your team can evidence today: a policy intention or planned remediation is a "Partly" or a "No". Scoring runs in your browser, and your answers stay there unless you ask for the evidence pack.

First, who are you?

Choose the description that fits your organisation.

Q1 of 10Scope & InventoryDraft paras 6, 7(3), 10

Have you identified every decisioning asset that could qualify as a model, including scorecards, BRE rules, calculators, spreadsheets, AI/ML systems, prompts, APIs, vendor tools, and co-lending decision flows?

The draft applies to all internally developed, third-party, or combined models and defines model broadly enough to include decision rules and other computational tools that materially influence decisions.

Q2 of 10Scope & InventoryDraft paras 13(3), 21-24

Is each asset recorded in a live inventory with intended use, lifecycle status, owner, developer or provider, validator, approver, risk tier, dependencies, and key validation, monitoring, and audit observations?

The draft expects an accurate, comprehensive, up-to-date inventory of active, inactive, under-development, and decommissioned models, with no model used unless it is in inventory.

Q3 of 10Governance & TieringDraft paras 17-20, 52

Do you apply a documented risk-tiering method that considers materiality, complexity, consumer impact, explainability, third-party dependency, and for AI, reliance and autonomy in decision-making?

The draft expects risk-based tiering for all models, with the tier driving validation priority, approval structure, controls, monitoring, reporting, documentation, and continuity planning.

Q4 of 10Governance & TieringDraft paras 8-15, 22

Can you show accountable model owner, developer or provider, independent validator, approver, senior-management responsibility, and three-lines-of-defence coverage for material assets?

The regulated entity remains accountable for model outcomes, and the draft assigns oversight to the Board, Risk Management Committee, senior management, model owners, independent validation, and internal audit.

Q5 of 10Lifecycle EvidenceDraft paras 29-33, 46(i)

Can you evidence independent validation before deployment, after deployment, after material change or trigger events, and periodically as specified in the MRMF, including for third-party models?

The draft expects independent validation by the regulated entity, including for third-party models, with outcomes documented and reports placed before the relevant committee or delegated authority.

Q6 of 10Lifecycle EvidenceDraft paras 12(1), 18(ii), 34-35

Can you evidence approval or exception approval, including authority, threshold, rationale, conditions, remediation timeline, and committee review for high-risk or equivalent-risk assets?

The draft expects an approval and exception-approval structure with documented decision rationale, and high-risk model validation reports and deployment approvals routed to the Risk Management Committee.

Q7 of 10Lifecycle EvidenceDraft paras 16, 36-43

Can you explain what changed in the last quarter and show ongoing monitoring, performance testing, version logs, impact assessments, material-change criteria, revalidation triggers, and fallback plans?

The draft expects ongoing performance testing and monitoring, controlled deployment, structured change management, version records, material-change thresholds, and continuity arrangements.

Q8 of 10Third-party, AI & Board ReadinessDraft paras 45-48, 51, 53

Have you mapped third-party model, LSP, bureau, data, AI provider, API, and co-lending dependencies with due diligence, minimum technical documentation, audit rights, continuity, exit, and provider-update risk evidence?

The draft says accountability stays with the regulated entity, third-party models remain subject to the MRMF, and contracts should support documentation access, audit rights, continuity, and exit.

Q9 of 10Third-party, AI & Board ReadinessDraft paras 25, 49-63

For AI/ML or automated decisions, can you show scope, explainability thresholds, bias/fairness/drift controls, red-team or challenge testing, deployment safeguards, customer interface controls, human-in-command, overrides, suspension, or kill-switch records?

The AI/ML section adds controls for scope, autonomy, explainability, hallucination, bias, drift, dynamic updates, deployment security, customer interfaces, human oversight, overrides, incidents, and near misses.

Q10 of 10Third-party, AI & Board ReadinessDraft paras 11-14, 33, 37, 46(ii)

Could you produce this week a Board or Risk Committee pack showing inventory, high-risk models, validations, approvals, exceptions, changes, third-party exposure, AI exposure, open gaps, breaches, and decisions needed?

The draft gives the Board and Risk Management Committee recurring oversight duties and expects committee visibility into validation reports, tiering, exceptions, third-party models, AI models, breaches, and material concerns.

Where you land on the maturity curve

Five readiness bands, from a first asset inventory to continuous governance. Your score sets your position: the bands below it are climbed, the bands above it are the road ahead.

  1. You land here
    FoundationalYou land here
    0, 30%Start with scope
  2. You land here
    DevelopingYou land here
    31, 55%Move from policy to proof
  3. You land here
    ManagedYou land here
    56, 75%Close the consistency gaps
  4. You land here
    Board-ReadyYou land here
    76, 90%Tighten the edges
  5. You land here
    Continuous GovernanceYou land here
    91, 100%Keep it live

Dimension recommendations

Priority actions

    Get your board-ready evidence pack

    Add your details and two downloads open on this page: your own benchmark results. Score, dimension breakdown, and prioritised action list, and the board-ready evidence-pack template, with working templates for inventory, tiering, ownership, validation, third-party dependencies, AI controls, and Board/Risk Committee reporting. Nothing is emailed; both download right here.

    Your evidence system of record, not another judge of your models

    Lokta RBI Model Risk Management is available as the lender's own evidence system of record: it organises inventory, tiering, validation records, approvals, exceptions, change logs, third-party dependencies, AI oversight, and board packs into one place. Your validators, internal audit, and board remain the authority: Lokta makes the evidence ready, not the judgement.

    Built right: an append-only evidence ledger, four-eyes governance on every change, and agents that propose, never act without a human.

    Founder-led adoption

    Adopt the agentic loan servicing platform.

    Lokta is built for enterprise deployment, VPC or single-tenant cloud, with an audit trail in every state change. We work with a select group of institutions through a founder-led model: deep adoption, deliberate scope, a delivery window the team commits to in writing.