
India’s central bank has proposed sweeping new rules requiring banks to independently validate, continuously monitor and govern artificial intelligence and machine-learning models, a move that could significantly expand the role of software testing and quality engineering across the country’s financial sector.
The Reserve Bank of India (RBI) published this week guidelines that will require banks and other regulated entities to establish board-approved model risk management frameworks covering all of its software infrastructure, including artificial intelligence and machine-learning systems.
Firms would also be required to maintain comprehensive model inventories, assess risk at both model and enterprise level, and ensure independent testing and validation of internally developed as well as third-party models.

The proposals represent far more than another AI governance initiative, because the draft framework effectively treats AI software infrastructure and machine-learning systems as controlled technology assets that require continuous validation, testing, monitoring and governance throughout their lifecycle rather than simply being approved before deployment.
The RBI said banks must assess, test and monitor risk “at both the individual model level and across the enterprise on an ongoing basis.”
The central bank also said that, where risks are found to be excessive, lenders should take timely corrective action, including “enhanced testing, controls, restrictions on use, remediation or decommissioning of the model.”
That language will have significant implications for quality engineering efforts within the sub-continent’s banking space.
Banks will increasingly need to demonstrate not only that AI models have been approved, but that they have been independently validated against their intended use, continuously monitored once deployed and supported by clear governance processes when behaviour moves outside agreed risk thresholds.

The emphasis on independent validation is particularly noteworthy because the proposals extend beyond internally developed systems.
The RBI said all models and related software, including those supplied by third parties, should be subject to independent validation. That could have important consequences for banks deploying vendor-developed AI platforms, embedded machine-learning models or generative AI capabilities delivered through cloud providers and technology partners.
For software testing teams, that means assurance responsibilities are likely to extend beyond internally written code. Banks may increasingly need evidence around the behaviour, assumptions, resilience, outputs and failure modes of models they neither built nor directly control.
The draft guidelines also require human oversight for AI models used in automated decision-making, while generative AI systems interacting with customers or external users must incorporate additional cybersecurity controls.
Taken together, those requirements move AI governance firmly into the territory of software assurance and operational resilience.
Customer-facing generative AI systems will require far more than traditional functional testing or model accuracy assessments. Financial institutions will increasingly need evidence around guardrail validation, prompt evaluation, misuse scenarios, cybersecurity resilience, data leakage, escalation mechanisms and the ability for humans to intervene when necessary.
Case study
While the RBI’s proposals focus specifically on AI models, they also reflect a broader regulatory direction already emerging across India’s banking sector, where technology controls, automation and quality assurance have become increasingly important in meeting regulatory obligations.
Federal Bank offers a useful example of that wider shift. The private sector lender turned to robotic process automation (RPA) after facing mounting compliance requirements following a decade of rapid expansion.
One of its most pressing challenges involved a regulatory mandate requiring the management and merging of unique customer identification codes (UCIC) to ensure consistent customer identification across the organisation.
The bank concluded that completing the exercise manually would have required up to a year, introduced significant operational risk and demanded substantial additional staffing. Instead, it partnered with UiPath to automate the highly repetitive, rules-based compliance process.

Federal Bank has long viewed technology as a strategic enabler of growth, guided by an internal digital transformation strategy focused on balancing automation with customer-centric service delivery.
“We always look for new, better, and smarter ways to manage our entire business,” explained Shalini Warrier, executive director at Federal Bank.
“These new situations led us to consider robotic process automation, and we were confident automating many critical processes would help users reduce costs, improve data accuracy, and gain a scalable solution for future efficiencies for the entire company.”
According to Roshni Majeed, assistant vice president and the bank’s first RPA champion, time pressure made automation essential.

“It quickly became clear that we didn’t have a lot of time to hit the compliance date,” explained Majeed. “Yet we also realized that if we attempted to perform all the necessary work manually, we were at risk of not hitting the deadline.”
The results underline why quality engineering increasingly sits alongside compliance and operational resilience.
Where employees had previously merged between 200 and 300 customer records during a full working day, the software robot processed around 250 records every hour while operating continuously.
Just as importantly from a quality assurance perspective, the automated UCIC process achieved a zero percent error rate while reducing turnaround times by around 50 percent compared with the bank’s original estimates.
Federal Bank has since expanded automation across multiple business functions, automating 15 processes with plans to increase that figure to 53, while establishing an internal centre of excellence to oversee the development, testing and governance of future automation initiatives.
Automation has also been extended into customer-facing services.
“The UiPath Robot has brought this time down to just one minute per transfer,” disclosed Warrier, referring to merchant onboarding for BharatQR. “That would have been unimaginable in a manual environment.”
Looking ahead, the bank plans to combine robotic process automation with artificial intelligence to further expand automation across IT and operational functions.
“We continue to evaluate new automation opportunities to become even more agile,” Majeed concluded.
Against that backdrop, the RBI’s draft model risk framework appears to represent the next phase of an evolving regulatory agenda rather than a standalone AI initiative.
Where previous compliance programmes focused on improving process quality, operational consistency and data integrity, the latest proposals extend similar expectations to AI systems, requiring financial institutions to demonstrate that models can be independently validated, continuously monitored and governed throughout their operational lifecycle.
16 SEPTEMBER IN LONDON

REGISTER TODAY – SIMPLY CLICK HERE
Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- Inside Rabobank: Engineering resilience by design
- Can AI agents finally automate data testing?
- Continuous testing drives DORA compliance
- Why software testing may face a major rethink
- Buy or build? AI rewrites software testing for banks
WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS



