RBI Model Risk Management

RBI model-risk readiness for every lending decision system

An evidence-ready control plane for the models, BRE rules, scorecards, AI use cases, third-party dependencies, and co-lending workflows behind your lending decisions — so when the board or the regulator asks, the answer and the evidence are already in one place.

Built by the team behind Apache Fineract · Append-only evidence ledger · Four-eyes governance · Human-authoritative by design

Lokta RBI Model Risk Management — board-readiness, the command bar, and a 'needs your decision' inbox.
Why now

The expectations just widened. The evidence work didn't get easier.

RBI's June 2026 draft Guidance on Model Risk Management, with the FREE-AI framework, widens what lenders must govern — a board-approved framework, a complete model inventory, risk tiering, independent validation, AI/ML controls, and accountability for third-party and co-lending models. The hard part was never the policy; it is proving, on demand, what exists, who owns it, what's validated, and what's ready for the board.

Most lenders can answer only by stitching spreadsheets together the week before a Risk Committee. Lokta replaces the stitching with a system of record.
What Lokta does

One control plane, from scattered evidence to a board-ready pack

  1. 01

    Inventory every decisioning asset

    Models, rules, scorecards, AI use cases, vendor APIs, and co-lending — one catalogue.

  2. 02

    Score your readiness

    Against the draft, dimension by dimension, with the gaps ranked.

  3. 03

    Track and close evidence gaps

    A live queue of what's missing, who owns it, and what “ready” means.

  4. 04

    Govern the record

    Approvals, exceptions, and changes with four-eyes sign-off and an immutable trail.

  5. 05

    Generate the board pack

    A Risk-Committee-ready evidence pack in minutes.

Inside the control plane

See where your model-risk evidence actually stands

From one inventory to a board-ready pack — built so the evidence is examination-ready, and a human stays the authority on every assertion.

Inventory

One inventory of every decisioning asset

Models, BRE rules, scorecards, pricing calculators, AI use cases, bureau and vendor APIs, and co-lending dependencies — each with an owner, a risk tier, an evidence score, and a status. The whole decisioning surface in one catalogue, not a dozen spreadsheets.

Lokta RBI MRM inventory — decisioning assets listed with owner, risk tier, evidence score, and status.
Readiness

Readiness scored against the draft, worst gaps first

A live board-readiness score across the twelve RBI model-risk themes, each one ranked, with the agent summarising which gaps to close first to lift the number before the Risk Committee meets.

RBI readiness dashboard showing 64% board-readiness with themes ranked worst-first.
The agent

A cited agent that proposes — a human decides

Ask about your estate and get an answer with citations to the exact record behind every claim. The agent drafts and surfaces; it never approves evidence or activates a control. Nothing moves without a person.

Lokta model-risk agent answering a question with section citations and a human-approval disclaimer.
Board pack

A board-ready pack, assembled from current evidence

Eleven sections — executive summary, readiness heatmap, high-risk assets, validation status, exceptions, third-party exposure — drafted from what is on record, with citations throughout. The agent never finalises; you review and snapshot it.

Board pack with 86 citations across 11 sections, drafted by the board-pack agent.
Provenance

Every claim traces back to a record

Open Sources on any pack and each line links to the evidence behind it — the validation, the approval, the gap finding, the snapshot. Read-only references, so the pack holds up to the question no one prepared for.

Board-pack Sources panel — every claim traces to a source record you can jump to.
Governance

Four-eyes on every action — acceptance is not execution

The agent's toolbox is read and create-draft only. Every action is logged as Proposed, then Accepted or Rejected by a named reviewer under two-person sign-off. Accepting a draft is never the same as activating a control.

Agent activity log — proposed, accepted, and rejected actions with named reviewers and statuses.
Not just your AI models

Built for how RBI defines "model" — the whole decisioning surface

The draft's definition is deliberately broad: AI/ML, algorithms, decision rules, calculators — even the spreadsheets that materially shape a lending decision — plus the vendor and co-lending models you are now accountable for.

Most governance tools were built to watch AI models. Lokta was built for lending decisioning: deterministic BRE rules, scorecards, pricing logic, and third-party dependencies sit in the same catalogue as your AI use cases, governed the same way — because that is the surface a supervisor will examine.

Mapped to the draft

Line-mapped to the June 2026 MRM draft

Every readiness dimension and gap in the self-benchmark traces back to a specific expectation in RBI's June 2026 draft. No generic global checklist retrofitted to India — purpose-built for the RBI examination your board is preparing for.

RBI draft expectation What we map it to Draft paras
A complete, up-to-date model inventory Every decisioning asset in one catalogue 13(3), 21-24
Independent validation on record A validation register — dates, scope, findings 29-33, 46(i)
Accountability for third-party & co-lending models A dependency ledger — audit rights, continuity, exit 45-48, 51, 53

See the full question-to-paragraph map & methodology →

Built right

Governance you can trust, because it's governed itself

Append-only evidence ledger

Every action is preserved — who, what, when, source. Records cannot be quietly altered or deleted.

Four-eyes on every assertion

Validation, approval, exception, tier confirmation, and decommission all route through two-person sign-off.

Human-authoritative by design

Assistive agents propose and surface — they never approve, alter evidence, or activate a control without a person. Every agent action is logged.

You stay the authority

Lokta is your evidence system of record. Your validators, auditors, and board remain the decision-makers — we organise and ready the evidence; we do not sit in judgment of your models.

Built for

The people accountable when the regulator asks

  • CROs
  • Heads of Compliance
  • Model-risk & credit-policy teams
  • Data science leaders
  • Internal audit
  • CTOs
  • Founders of fintech lenders

Designed for Middle Layer NBFCs, co-lending partners, and fintech lenders who carry the same accountability as a large bank — without a large bank's model-risk department.

How it works

Up and running on uploads — not a six-month integration

  1. 01

    Upload

    Your assets and existing records, with guided templates.

  2. 02

    See your readiness

    On a live dashboard, scored against the draft.

  3. 03

    Close the gaps

    From a prioritised queue, with owners and "ready" criteria.

  4. 04

    Generate your board pack

    Evidence-ready, in minutes.

Where does your model-risk evidence stand today?

Take the RBI MRM draft self-benchmark — 10 questions, anchored to the June 2026 draft. Get your readiness score instantly. No email needed to see where you stand.

Take the self-benchmark →
Waitlist

Be among the first lenders to pilot RBI model-risk evidence readiness

We are onboarding a small group of design-partner lenders ahead of general availability. Join the waitlist to get early access and a readiness walkthrough.

Prefer to talk first? Book a 30-minute readiness walkthrough →

We'll only use this to share early access and your readiness report. No spam.

FAQ

Questions a risk officer asks

The sharp ones — compliance, independence, third-party scope, integration, and the draft itself.

  • Does Lokta make us "RBI compliant"?

    No tool can. Lokta helps you build and maintain the evidence and readiness a lender needs to demonstrate its model-risk governance — the inventory, the validations on record, the approvals, the gaps, and the board pack. Compliance is your board's determination; we make it provable.

  • You also build lending technology. Can you be our governance system?

    Lokta RBI MRM is your own system of record — it organises and evidences the controls you run. Your validators, auditors, and board remain the independent authority over your models. We do not validate or certify models; we make the evidence examination-ready. Where required, your data stays walled from any other Lokta product.

  • We use third-party and co-lending models. Are those covered?

    Yes — that is a core reason Lokta exists. Vendor, bureau, and co-lending dependencies sit in the same catalogue as your own assets, with ownership and oversight evidence tracked against the draft's expectation that accountability is not outsourced.

  • Do we need to integrate our systems first?

    No. Start with guided uploads and get a readiness dashboard and board pack from day one. Deeper source-system evidence APIs are available when you are ready.

  • Is the June 2026 guidance final?

    It is a draft, out for public consultation. Lokta is built around evidence and board-readiness that serve your Risk Committee today — and we track the guidance as it finalises so your mapping stays current.

Talk to the team

Adopt the agent-native lending stack.

Lokta is built for enterprise deployment — VPC or single-tenant cloud, with an audit trail in every state change. We work with a select group of institutions through a founder-led model: deep adoption, deliberate scope, a delivery window the team commits to in writing.