RBI: AI Compliance Must Go Beyond DPDP
As artificial intelligence moves deeper into Indian banking, DPDP compliance alone cannot become the definition of responsible AI. RBI Governor Sanjay Malhotra has urged banks to build broader governance and accountability around AI, identifying six major risks that could emerge as adoption accelerates.
The first is the “black box” problem. When AI influences lending, fraud detection, customer onboarding or other consequential decisions, banks must be able to explain the outcome. If a loan is rejected, customers, auditors and regulators should be able to understand why. Explainability therefore needs to become part of AI architecture rather than an afterthought.
The second challenge is bias and exclusion. AI trained on incomplete or historically biased datasets could unintentionally disadvantage particular customers. Banks consequently need continuous model testing, human oversight and mechanisms to challenge automated decisions.
RBI has also highlighted concentration and herding risk. If multiple institutions depend on similar models, datasets or AI infrastructure, they could potentially reach similar decisions simultaneously. What appears efficient at an individual-bank level could create systemic vulnerabilities across the financial sector.
A fourth concern is third-party and vendor dependence. Banks increasingly consume AI through cloud providers, foundation models, fintech platforms and external applications. Institutions cannot outsource accountability simply because the underlying model belongs to another company. Vendor AI therefore requires rigorous due diligence, monitoring, contractual controls and exit strategies.
Data privacy represents the fifth challenge. The DPDP framework establishes important obligations, but banks hold exceptionally sensitive financial and identity information. Privacy-by-design, data minimization, purpose limitation, controlled model access and strong data governance must extend beyond minimum statutory compliance.
Finally, cyber and adversarial AI risks could become one of banking's most significant emerging threats. Deepfakes, synthetic identities, prompt manipulation, model attacks, AI-powered social engineering and autonomous cyberattacks are changing the fraud landscape.
The RBI's message signals an important shift: AI governance cannot become another compliance checklist. Banks need an integrated framework combining explainability, fairness, privacy, cybersecurity, third-party governance, continuous monitoring and human accountability.
AI can transform credit, customer experience, operational efficiency and fraud prevention—but banking ultimately runs on trust. The institutions that lead the AI era will not simply deploy AI faster; they will prove that their AI can be trusted.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




