Home All services
Start a project → Call Now

AI risk management services for banks, NBFCs and insurers

Put every AI model under your model risk framework — with dated evidence to prove it.

SR 11-7, the US Federal Reserve's model risk guidance issued in 2011, is still the reference text. The RBI's draft guidance, out for comment in June 2026 and not yet notified, extends the same discipline to systems nobody calls a model. We list them, tier them, validate what matters and design monitoring that your team runs.

  • Every document has a named owner
  • Pass marks fixed before any test runs
  • We reply within one working day.
  • SR 11-7 / OCC 2011-12
  • RBI draft model risk guidance, 2026
  • ISO/IEC 42001 Annex A
  • NIST AI RMF
Illustration: a balance scale holding an AI core against a small bank building and a stack of coins, resting steady beside a gauge with a calm low reading

In brief

What it is
Model risk management for AI. Every system that turns data into a business decision gets an owner, a tier, independent validation and monitoring.
Why it matters
The RBI's draft counts a system as a model by what it does, so vendor AI features and pricing spreadsheets count too. Your board answers for all of them.
What you get
A tiered model inventory, a framework your board approves, validation against pass marks set in advance, and a monitoring design your team runs, so dated evidence builds up.

What you get

Seven documents, each with a name on it.

One evidence set, mapped to ISO/IEC 42001 Annex A and the NIST AI RMF, so it gets written once.

SecWiz issues no certificates, and nothing in this table is one.
DocumentWhat it has to showWho produces it, who signs it
Model risk management frameworkScope, tiering rules, validation cadence, escalation, and the reporting line to the boardWe draft it. Your board approves and owns it.
Tiered model inventoryEvery system that turns data into a decision, rated on materiality, complexity and autonomyWe build the first pass. Your model owners keep it current.
Independent validation reportConceptual soundness, data, testing, outcomes analysis, and the questions the validator actually raisedWe do the work. Your validation function accepts it, and accountability stays with you.
AI system impact assessmentThe effect on the customer who gets declined, not only on the balance sheet. ISO/IEC 42001 clause 6.1.4 and control A.5, method per ISO/IEC 42005:2025We produce it. Your business owner signs it.
Statement of ApplicabilityAll 38 ISO/IEC 42001 Annex A controls, each included or excluded with a reasonWe draft, you approve. The certificate comes only from a body accredited under ISO/IEC 42006:2025.
Evaluation packThresholds fixed before the run, then accuracy, stability, bias and robustness results against themWe run the tests and sign our own report.
Monitoring design and running evidenceDrift (results moving away from what was validated), performance decay, output sampling, incidents and near misses, all dated. NIST AI RMF MEASURE 2.4 and MANAGE 4.1We design it. Your team runs it. Nobody can backdate it.

Validating a bought model? See AI vendor risk. Listing every AI system first? Start with AI governance, or see all GRC and compliance work.

Where this comes from

AI didn't create model risk. It spread it across the business.

In April 2011 the US Federal Reserve and the Office of the Comptroller of the Currency (OCC) issued SR 11-7 and OCC Bulletin 2011-12, setting out three things a bank owes every model it relies on. AI risk frameworks have since adopted the second one, independent validation.

  • Sound development and use.
  • Effective challenge, through independent validation.
  • Governance, with the board accountable.

What changed is where models live. A behavior scorecard used to be built by four people, documented once and revalidated on a cycle. Today the system making the decision is often bought, sits inside a collections dialer or a KYC queue, changes when the vendor ships, and can answer the same input differently on Tuesday than on Monday.

How we work

Inventory first. Then tier, validate and design monitoring.

Model risk programs break in the same few places; each step closes one.

  1. Find every model, named or not

    The RBI draft defines a model by what it does: data in, a statistical or AI technique applied, an output that moves a business decision. That catches scoring rule engines, the pricing spreadsheet three people maintain and the vendor feature switched on inside your core system.

  2. Tier on three separate scores

    Low complexity can't pull a high-materiality model down a tier. A plain logistic regression declining retail loans at volume is a top-tier model, however simple the math.

  3. Validate with the pass mark set first

    We validate before deployment, after any change and on a fixed cycle. Set the pass mark after seeing the numbers and you have recorded an opinion, not a test. Generative models get LLM security testing for prompt injection, jailbreaks (tricks that talk a model out of its rules) and data leakage. Findings map to the OWASP Top 10 for LLM Applications and MITRE ATLAS, a public catalog of attacks on AI systems. Our AI security team does both, so the validator knows where the controls give way.

  4. Design monitoring that your team runs

    Reviews fail here most: a signed framework, but no dated monitoring evidence. The NIST AI RMF expects behavior to be watched in production and a written post-deployment monitoring plan. We design the drift and decay checks and the incident log; your team runs them.

  5. Check that someone has tested the off switch

    Human-in-command (a person can override the system), human-in-the-loop (a person approves each decision) and human-on-the-loop (a person watches and can step in) need different staffing. The draft also expects customer-facing AI to be disclosed, with a route to human help. An untested kill switch is a paragraph, not a control.

The clock

The RBI draft isn't the only date you're running against.

When the RBI guidance is final, it replaces Chapter 3 of the October 2002 credit risk guidance your validation policy probably still cites. If your model's output reaches users in the EU, we also scope your EU AI Act exposure.

13 August 2025: the RBI's FREE-AI report

Seven sutras, 26 recommendations and six pillars spanning infrastructure, policy, capacity, governance, protection and assurance. Direction for the sector, not yet an obligation on any single entity.

5 November 2025: India AI Governance Guidelines

MeitY set seven principles across six pillars and preferred sectoral supervision to a standalone AI statute. That is why the pressure reaches you through your regulator rather than a new law.

24 June 2026: the RBI draft is issued (still a draft on 9 September 2026)

Draft Guidance on Regulatory Principles for Model Risk Management, 2026: six chapters, released for public comment. The window closed on 24 July 2026. It has not been notified.

November 2026: DPDP Consent Manager registration

Consent Manager registration under Rule 4 opens a DPDP tranche. The duties that reach the personal data behind your training sets come in the tranche after it, so model risk and data protection stop being separate files. See DPDP Act compliance.

2 December 2027: EU high-risk duties for Annex III systems

Regulation (EU) 2026/1744 took effect on 27 July 2026 and deferred standalone high-risk obligations by 16 months, to this date. Product-embedded Annex I systems moved 12 months, to 2 August 2028.

What this work does not include. We are not a certification body, hold no accreditation to audit anyone against ISO/IEC 42001, and are not ISO 27001 certified ourselves. As of early August 2026 no India-accredited body for ISO/IEC 42001 had been confirmed, so an Indian entity that wants the certificate goes to a foreign-accredited body operating here. Every engagement runs remotely from India.

FAQ

Questions banks and NBFCs ask about AI risk management.

Anything else? Ask us directly.

Because the inventory takes longest, whatever the notification date. Entities that scope the exercise honestly find several times more models than they expected once rule engines, vendor features and material spreadsheets are counted, and each one still needs an owner, a tier and a validation record. The draft was issued on 24 June 2026 and comments closed on 24 July 2026. No version of the final text will make a missing inventory faster to build.

The function is the same; the scope, the evidence and the failure mode are not. Classical validation tests a fixed specification against outcomes. An AI model brings output variability, spurious correlations, hallucination in the generative case, and behavior that degrades quietly between reviews. The draft names those risk dimensions directly, alongside explainability, bias and overfitting. Your validators need test sets they control, thresholds agreed before the run, and telemetry from production. Most validation teams can absorb this; few have the telemetry today.

Yes. Independent validation by the regulated entity is expected even where the provider has certified its own model, and accountability for the outcome stays with you. Ask what the certificate covers: a management system certificate covers an organization's processes within a stated scope, and says nothing about whether a particular model is accurate or fair. Then get audit rights, a data lineage answer and an exit plan into the contract before you sign.

Not from us, and not for model risk. RBI does not certify anything here: it supervises, and an inspection looks at your framework, your inventory and your validation files. ISO/IEC 42001 is certifiable, but only by a certification body accredited under ISO/IEC 17021-1 and ISO/IEC 42006:2025, and the certificate covers a management system within a declared scope, never a model. There is no NIST AI RMF certification of any kind.

Not on its scope list, which covers banks of several kinds, NBFCs across layers, All-India financial institutions, asset reconstruction companies and credit information companies. That answers jurisdiction, not risk. Underwriting and pricing models carry the same board exposure and reputational risk, and an audit committee will eventually ask for the discipline a bank supervisor expects. We build to the same framework and drop the parts that only make sense for an entity RBI regulates.

No. The Article 40 presumption of conformity attaches only to standards whose references have been published in the Official Journal. EN 18286:2026, the quality management standard written for AI Act purposes, was approved on 12 July 2026 and made available on 22 July 2026, and it still carries no citation in the Official Journal. Until it does, the presumption is available to nobody, and conformity has to be shown requirement by requirement.

Inventory and tiering take a few weeks for a mid-sized entity, longer where the estate has never been mapped. The framework and validation policy run in parallel. The validation backlog then moves at the pace of your model count and materiality, and the monitoring history builds up in real time, which nobody can compress. Plan on evidence that gets stronger each quarter, not a launch date.

Let's talk

Start with the inventory.

Send us your model estate as you understand it, plus the systems you suspect are missing. You get a scope, a tiering approach and a straight view on whether you need this work at all. We reply within one working day.