Where do you stand against RBI's 2026 model-risk draft?
A 10-question self-benchmark for NBFCs, fintech lenders, and banks — each question line-mapped to RBI's June 2026 draft model-risk guidance. You get a readiness score, a dimension breakdown, and a genuinely useful finding for every dimension. It is readiness guidance, not a compliance certificate: your validators, auditors, and board remain the authority.
Answer for what your team can evidence today — a policy intention or planned remediation is a "Partly" or a "No". Your score is shown on screen; nothing is stored.
Which best describes your organisation?
Have you identified every decisioning asset that could qualify as a model, including scorecards, BRE rules, calculators, spreadsheets, AI/ML systems, prompts, APIs, vendor tools, and co-lending decision flows?
The draft applies to all internally developed, third-party, or combined models and defines model broadly enough to include decision rules and other computational tools that materially influence decisions.
Is each asset recorded in a live inventory with intended use, lifecycle status, owner, developer or provider, validator, approver, risk tier, dependencies, and key validation, monitoring, and audit observations?
The draft expects an accurate, comprehensive, up-to-date inventory of active, inactive, under-development, and decommissioned models, with no model used unless it is in inventory.
Do you apply a documented risk-tiering method that considers materiality, complexity, consumer impact, explainability, third-party dependency, and for AI, reliance and autonomy in decision-making?
The draft expects risk-based tiering for all models, with the tier driving validation priority, approval structure, controls, monitoring, reporting, documentation, and continuity planning.
Can you show accountable model owner, developer or provider, independent validator, approver, senior-management responsibility, and three-lines-of-defence coverage for material assets?
The regulated entity remains accountable for model outcomes, and the draft assigns oversight to the Board, Risk Management Committee, senior management, model owners, independent validation, and internal audit.
Can you evidence independent validation before deployment, after deployment, after material change or trigger events, and periodically as specified in the MRMF, including for third-party models?
The draft expects independent validation by the regulated entity, including for third-party models, with outcomes documented and reports placed before the relevant committee or delegated authority.
Can you evidence approval or exception approval, including authority, threshold, rationale, conditions, remediation timeline, and committee review for high-risk or equivalent-risk assets?
The draft expects an approval and exception-approval structure with documented decision rationale, and high-risk model validation reports and deployment approvals routed to the Risk Management Committee.
Can you explain what changed in the last quarter and show ongoing monitoring, performance testing, version logs, impact assessments, material-change criteria, revalidation triggers, and fallback plans?
The draft expects ongoing performance testing and monitoring, controlled deployment, structured change management, version records, material-change thresholds, and continuity arrangements.
Have you mapped third-party model, LSP, bureau, data, AI provider, API, and co-lending dependencies with due diligence, minimum technical documentation, audit rights, continuity, exit, and provider-update risk evidence?
The draft says accountability stays with the regulated entity, third-party models remain subject to the MRMF, and contracts should support documentation access, audit rights, continuity, and exit.
For AI/ML or automated decisions, can you show scope, explainability thresholds, bias/fairness/drift controls, red-team or challenge testing, deployment safeguards, customer interface controls, human-in-command, overrides, suspension, or kill-switch records?
The AI/ML section adds controls for scope, autonomy, explainability, hallucination, bias, drift, dynamic updates, deployment security, customer interfaces, human oversight, overrides, incidents, and near misses.
Could you produce this week a Board or Risk Committee pack showing inventory, high-risk models, validations, approvals, exceptions, changes, third-party exposure, AI exposure, open gaps, breaches, and decisions needed?
The draft gives the Board and Risk Management Committee recurring oversight duties and expects committee visibility into validation reports, tiering, exceptions, third-party models, AI models, breaches, and material concerns.
Where you land on the maturity curve
Five readiness bands, from a first asset inventory to continuous governance. Your score sets your position — the bands below it are climbed, the bands above it are the road ahead.
Dimension recommendations
Priority actions
Get your board-ready evidence pack
Add your details to unlock two downloads on this page: your own benchmark results — score, dimension breakdown, and prioritised action list — and the board-ready evidence-pack template, with working templates for inventory, tiering, ownership, validation, third-party dependencies, AI controls, and Board/Risk Committee reporting. Nothing is emailed; both download right here.
Every question is line-mapped to the June 2026 draft
Each of the ten questions cites the relevant paragraph of RBI's June 2026 draft Guidance on Regulatory Principles for Model Risk Management. The full question-to-paragraph map, scoring rubric, and dimension model are published openly so a risk officer, auditor, or board can review and challenge the benchmark.
See the full methodology & source map → The product behind the benchmarkLokta RBI Model Risk Management
The benchmark shows where you stand. Lokta is building the evidence control plane that maintains it — inventory, tiering, validation records, approvals, third-party and co-lending dependencies, and a board-ready evidence pack.
Learn about Lokta RBI Model Risk Management →Your evidence system of record — not another judge of your models
Lokta RBI Model Risk Management is being built as the lender's own evidence system of record: it organises inventory, tiering, validation records, approvals, exceptions, change logs, third-party dependencies, AI oversight, and board packs into one place. Your validators, internal audit, and board remain the authority — Lokta makes the evidence ready, not the judgement.
Built right: an append-only evidence ledger, four-eyes governance on every change, and agents that propose — never act without a human.