RBI Guidelines on Outsourcing of Financial Services: AI Vendor Checklist
The Reserve Bank of India (RBI) guidelines on outsourcing of financial services require banks and Non-Banking Financial Companies (NBFCs) to keep full responsibility for any activity they outsource — including to Artificial Intelligence (AI) vendors. Regulated entities must run due diligence, protect customer data, retain audit and inspection rights, and never outsource core management functions.
This is an explainer, not legal advice. For any outsourcing decision, refer to the official RBI circular and your compliance and legal teams.
Outsourcing to an AI vendor — a voice bot provider, a document-processing engine, or a credit-scoring model — is still outsourcing in the eyes of the regulator. The rules that govern a recovery agency or a data-processing firm apply equally to your AI stack. This explainer turns the RBI framework into a practical due-diligence checklist you can use before signing an AI vendor.
Which RBI Rules Govern Outsourcing of Financial Services?
Two core instructions frame outsourcing for regulated entities:
- Banks: The Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services by banks — RBI/2006/167, DBOD.NO.BP. 40/21.04.158/2006-07, dated November 3, 2006 — apply to all Scheduled Commercial Banks (excluding Regional Rural Banks).
- NBFCs: The Directions on Managing Risks and Code of Conduct in Outsourcing of Financial Services by NBFCs — RBI/2017-18/87, DNBR.PD.CC.No.090/03.10.001/2017-18, dated November 9, 2017 — extend a near-identical framework to all NBFCs.
Technology-specific arrangements — cloud hosting, IT services, and much of what an AI vendor provides — are additionally covered by the Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102, DoS.CO.CSITEG/SEC.1/31.01.015/2023-24, dated April 10, 2023). Read the two together when the vendor is an AI or software provider.
A foundational principle runs through all of them: the RBI states that outsourcing "does not diminish" the obligations of the regulated entity, its Board and its senior management, who retain "ultimate responsibility for the outsourced activity."
What Counts as "Material Outsourcing" Under RBI Rules?
The 2006 banks guidelines define material outsourcing as arrangements that, "if disrupted, have the potential to significantly impact the business operations, reputation or profitability." Materiality is judged on the importance of the activity, its potential impact on earnings and risk profile, reputational impact, cost as a proportion of operating costs, and concentration with a single service provider.
For an AI vendor, ask: if this system failed tomorrow — the collections voice bot, the underwriting model, the Video KYC engine — would customer service, credit decisions, or regulatory reporting break? If yes, treat it as material outsourcing, with Board-approved policy, tighter contracts, and central record-keeping. The RBI requires a central record of all material outsourcing to be maintained and placed before the Board for half-yearly review.
Which Functions Can a Bank or NBFC Never Outsource?
The RBI prohibits outsourcing of core management functions. This is one of the clearest lines in the framework.
Function | Can it be outsourced? |
|---|---|
Internal audit | Prohibited |
Compliance function | Prohibited |
Strategic and decision-making functions | Prohibited |
Determining compliance with Know Your Customer (KYC) norms for account opening | Prohibited |
According sanction for loans (including retail loans) | Prohibited |
Management of the investment portfolio | Prohibited |
Loan origination support, document processing, data processing, marketing | Permitted, with safeguards |
An AI vendor may assist these functions — flagging KYC mismatches, drafting a credit memo, scoring an application — but the final decision and accountability must stay inside the regulated entity. AI as a decision-support tool is within the framework; AI as the decision-maker for a loan sanction or a KYC determination is not.
How Do You Run Due Diligence on an AI Vendor?
The 2006 guidelines call for due diligence covering "qualitative and quantitative, financial, operational and reputational factors," including past experience, financial soundness, business reputation, security and internal controls, audit coverage, and business continuity. Here is that framework mapped to questions you should put to an AI vendor.
RBI requirement | Question to ask your AI vendor |
|---|---|
Capability and track record | Can you show BFSI deployments, uptime data, and model accuracy under Indian conditions? |
Financial soundness | Can you service commitments even under adverse conditions? |
Data confidentiality and security | Where is customer data stored and processed? How is access limited to a "need to know" basis? |
Audit and inspection rights | Will the contract let us — and the RBI or persons authorised by it — access records held with you within a reasonable time? |
Sub-contracting | Do you use sub-processors? Is our prior consent required? |
Business continuity | Do you test disaster recovery, and can our data be returned or destroyed on exit? |
Grievance handling | How do complaints tied to your system reach our redressal machinery? |
On data confidentiality, the RBI requires that access to customer information be on a "need to know" basis and that the entity notify the RBI in the event of any breach of security or leakage of confidential customer information. On audit and inspection rights, outsourcing agreements must include clauses allowing the RBI or persons authorised by it to access records held with the service provider, and to inspect the service provider. On business continuity, the service provider must maintain and test recovery plans, and the entity must retain the ability to bring the activity back in-house.
How AI Helps Regulated Entities Stay Compliant
AI does not only sit on the vendor side of this equation — it can strengthen a regulated entity's own oversight. Conversation-intelligence platforms such as YuCI can monitor 100% of outsourced collections and service calls for script adherence, disclosure, and fair-practice compliance, replacing thin manual sampling. That gives compliance teams an audit trail across the outsourced activity — evidence of the "continuous monitoring and assessment" the RBI expects. For more on this, see how to ensure voice AI compliance with RBI guidelines and how AI ensures fair practice compliance in collections calling. The regulated entity still owns accountability — AI simply makes oversight continuous rather than periodic.
For the broader regulatory picture, read Regulatory AI in BFSI: RBI guidelines and what they mean for banks and AI security and data privacy: what Indian businesses need to know.
FAQ
Do banks or NBFCs need RBI approval before outsourcing to an AI vendor? Under the 2006 guidelines, banks do not need prior RBI approval to outsource a permissible financial service, whether the provider is in India or abroad. But the entity must put the required safeguards — policy, due diligence, contract clauses, monitoring — in place itself.
Can an AI model make the final loan or KYC decision? The framework prohibits outsourcing decision-making functions such as sanctioning loans and determining KYC compliance. An AI system can support and recommend, but the final decision and accountability must remain with the regulated entity.
What is material outsourcing? An arrangement whose disruption could significantly affect the entity's operations, reputation or profitability. Material outsourcing needs Board-approved policy, a central record, and half-yearly Board review per the RBI guidelines.
Must our contract give the RBI access to the AI vendor's records? Yes. Outsourcing agreements must include clauses allowing the RBI, or persons authorised by it, to access relevant records held with the service provider and to inspect the provider within a reasonable time.
Who is liable if the AI vendor causes a data breach? The RBI requires the entity to notify it of any breach, and states the entity would be liable to its customers for damage. Responsibility for the outsourced activity stays with the regulated entity.
Does outsourcing reduce our compliance burden? No. The RBI is explicit that outsourcing does not diminish the obligations of the entity, its Board, or senior management. It changes who performs the work, not who is accountable.
Conclusion
RBI's outsourcing framework predates modern AI, but it maps cleanly onto it. Treat every material AI vendor as a regulated outsourcing arrangement: run structured due diligence, hard-wire audit and inspection rights, protect customer data, plan for exit, and keep core decisions in-house. The checklist above is a starting point — always confirm against the current RBI circulars and your legal counsel.
Building an AI-driven, audit-ready BFSI stack? Talk to the YuVerse team to see how our platform supports compliant deployment.
References
- RBI — Guidelines on Managing Risks and Code of Conduct in Outsourcing of Financial Services by banks (RBI/2006/167, DBOD.NO.BP. 40/21.04.158/2006-07, November 3, 2006) — https://www.rbi.org.in/Scripts/BS_ViewMasCirculardetails.aspx?id=3148
- RBI — Directions on Managing Risks and Code of Conduct in Outsourcing of Financial Services by NBFCs (RBI/2017-18/87, DNBR.PD.CC.No.090/03.10.001/2017-18, November 9, 2017) — https://www.rbi.org.in/CommonPerson/english/scripts/Notification.aspx?Id=2646
- RBI — Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102, DoS.CO.CSITEG/SEC.1/31.01.015/2023-24, April 10, 2023) — https://www.rbi.org.in/scripts/BS_ViewMasDirections.aspx?id=12486