Blog
“The algorithm did it” won’t satisfy RBI: what this means for AI in Indian lending
RBI’s Governor and Deputy Governor have both said banks can’t blame AI or vendors for decisions. What meaningful human oversight and explainability require in practice — starting with the documents.
In the space of a month, RBI’s two most senior voices on this topic said the same thing.
At FIBAC in August, Governor Sanjay Malhotra told banks that meaningful human oversight of AI must be built in as “a design principle and not an afterthought.” He described that oversight as the ability to explain decisions, to step in, and to override them when needed. He was blunt that RBI won’t accept banks blaming the technology or the vendor for a bad decision. The responsibility stays with the bank.
In September, at the Global FinTech Fest, Deputy Governor S.C. Murmu made the same point. When an algorithm makes a financial decision or heavily shapes one, the algorithm can’t be the one accountable. Boards and senior management are expected to understand the models they deploy. Customers should be able to understand how a decision about them was made and how to challenge it.
These speeches build on two documents that set out RBI’s approach to AI in financial services:
- The FREE-AI Committee Report (August 2025). It set out seven principles for responsible AI in finance, including explainability, accountability and fairness, plus 26 recommendations on governance, audit and consumer protection.
- The Draft Guidance on Regulatory Principles for Model Risk Management (June 2026). It turns those principles into expectations: explainability for decisions that affect customers, real human oversight, telling customers when AI influenced an outcome, and clear accountability when a model comes from a third-party vendor.
The model risk guidance is still in draft, but the direction is clear. For any decision that matters to a customer, “the model said so” won’t be accepted, whether it’s said to the customer, the auditor or RBI.
Explainability starts with the documents, not the model
Most discussion of AI explainability is about the model: feature importance, SHAP values, interpretable versus black-box algorithms. That matters. But in Indian lending, a lot of the risk sits one step earlier, where the model’s inputs are built.
Before any scorecard or ML model runs, someone or something has to read:
- bank statements and GST returns
- ITRs, audited financials and CMA data
- KYC documents, property papers, sanction letters and legal opinions
Those documents get turned into numbers: monthly average balance, EBITDA, DSCR, leverage, bounced-cheque count. The model then works on those numbers.
If that extraction step is opaque, the model’s explanation doesn’t mean much. You can say a loan was declined because the DSCR fell below 1.2x. You can’t defend that if you can’t show where the DSCR came from: which figures, from which page of which document, and whether they were extracted correctly.
A decision is only as explainable as the data that fed it. You also can’t meaningfully override a decision if you can’t see what went into it.
What “meaningful human oversight” requires in practice
The Governor named three abilities: to explain, to step in, and to override. Put together with FREE-AI and the draft guidance, they mean a customer-affecting decision needs answers to five questions:
- Where did this number come from? Every value used in a decision should trace back to the document, the page and the exact location it came from.
- How confident was the system? Extraction and classification should carry confidence scores. Low-confidence values should go to a person, not be used silently.
- Can a person step in before the decision is final? Adverse or high-impact outcomes, such as rejections and limit cuts, need a real review point where a person can change the result. A rubber stamp after the fact doesn’t count.
- Is the system fair? The Governor warned about models that favour or disfavour particular regions, occupations or communities. That kind of bias can only be caught if decisions and their inputs can be examined in aggregate, not just one file at a time.
- Can you show it later? Six months on, an auditor, ombudsman or RBI inspector may ask to rebuild the decision. You need a record that shows what the system did, what a person changed, and why.
Both the Governor and the draft guidance also make a point many institutions haven’t absorbed yet: buying AI from a vendor doesn’t move accountability to the vendor. If a third-party tool helped decide a customer’s outcome, the lender still has to explain it. That changes what banks and NBFCs should ask of every AI vendor, including us.
How we build for this at Botminds
Botminds has worked on document intelligence for financial services for years. We’ve always believed that in regulated industries, an answer you can’t trace is only a guess. In the Governor’s words, oversight is a design principle for us, not an afterthought.
- Every extracted value links to its source. Each figure in a spread, checklist or case file links back to the exact place in the document it came from. A credit analyst, auditor or customer-grievance officer can click through and check.
- Derived values show their working. Ratios and computed fields show the formula and the inputs used, so a DSCR or leverage figure can be traced down to the line items behind it.
- Confidence drives routing. Uncertain extractions go to human review queues instead of flowing silently into decisions.
- People can step in and override. Configurable review stages, maker-checker controls and policy rules keep a person responsible for outcomes that affect customers.
- The audit trail can’t be quietly altered. Every automated step and every manual override is logged, with who changed what and why, so a decision can be rebuilt long after it was made.
In practice: One of our customers is a large government-backed development finance institution in North America that finances and invests in businesses across many sectors. Its credit teams handle a large and varied flow of financial statements, business plans and supporting documents for every application. With Botminds, each figure that goes into their credit analysis links back to the page it came from. Uncertain values go to analysts for review before they’re used. Every override is logged. The result is a 60% reduction in review time. When a credit committee member or auditor asks “where does this number come from?”, the answer is one click away.
The regulator and country are different, but the expectation is the same one RBI is now setting out. Whether the money is public or private, if a decision affects a borrower, you have to be able to explain it. That customer’s result also shows that oversight done well speeds work up rather than slowing it down.
What to do now
The guidance isn’t final, but after two senior speeches in two months, the direction won’t change. Institutions that act now will spend far less than those that retrofit later.
- List every model. The draft defines “model” broadly: AI/ML systems, scoring algorithms, rule engines and even key spreadsheets. Include the document extraction and classification tools that feed them.
- Map your lineage. For your highest-impact decisions, check whether you can trace each input back to its source document today.
- Design where people step in. Decide which decisions need human review, at what confidence level, and who has authority to override. Write it down.
- Test for bias. Check outcomes across regions, occupations and customer segments, and keep enough data to explain any differences you find.
- Question your vendors. Ask every AI vendor how they support explainability, audit trails and human oversight. If they can’t show you, the gap becomes yours.
- Get the board involved. RBI expects boards to understand the models the institution uses. Give them plain-language summaries, not technical appendices.
Conclusion
AI can expand credit to people traditional underwriting has missed, and it can speed up and improve operations. RBI isn’t trying to slow that down. Its message is that those gains last only if a person can still explain each decision, step in, and take responsibility for it. At Botminds, we think the institutions that do well in India’s next phase of digital lending will build that in from the start.
References: RBI, Report of the Committee on the Framework for Responsible and Ethical Enablement of AI (FREE-AI), August 2025; RBI, Draft Guidance on Regulatory Principles for Model Risk Management, June 2026 (draft); Governor Sanjay Malhotra, address at FIBAC 2026, 11 August 2026; Deputy Governor S.C. Murmu, remarks at Global FinTech Fest 2026.