A note on scope: this is a practical readiness aid, not legal advice, and it refers to the RBI guidance as a draft. Confirm the current text of any regulation with your own risk and legal teams. Where an item says a system "supports" an obligation, that means the architecture makes the obligation easier to meet, never that any product makes you compliant on its own.
Human oversight
Consequential decisions should have a human in the loop, and the human should have what they need to decide well.
Explainability, not a black box
You should be able to say why an answer was given, and check it at the source.
Kill switch and decommission
You must be able to suspend, restrict or retire the system on your own, quickly.
Third-party accountability
Outsourcing the technology does not outsource the responsibility.
Audit trail and records
If you cannot show what the system did, you cannot govern it.
Model risk governance
Models change; your controls should not depend on the model of the month.
Data protection (DPDP Act, 2023)
Customer and employee records are personal data, and you are the one accountable for them.
Every row above is a design decision. A rented, cloud-hosted AI service struggles to answer yes to the ownership, residency and switch-off rows. A private deployment on your own infrastructure is built to answer yes to all of them. That is the difference the RBI draft is really pointing at. Read the full analysis in RBI's 2026 AI rules for banks, and see how ZenithAI supports each control in security and governance and the Intelligence Framework.