If you’re responsible for security at a bank, NBFC, or payments company in India, June 2026 marked an important compliance milestone. The RBI AI Risk Mandate required all regulated entities to conduct an AI risk gap assessment by June 30 and submit a time-bound action plan to address the identified gaps. While that deadline has passed, attention has turned to implementing those plans and demonstrating measurable progress.
Here’s what the mandate entails, how it is interpreted in practice, and how Threatcop can help with compliance.
Table of Contents
ToggleWhat is the aim of the RBI AI Risk Mandate?
The RBI AI Risk Mandate is the Reserve Bank of India’s effort to ensure regulated entities can manage AI-related risks, both in their use of AI for credit, fraud detection, and customer service, and in defending against attackers who use AI. The most visible requirement was for banks and other regulated entities to submit a board-approved AI risk gap assessment and a time-bound action plan to the RBI by June 30, 2026. Part of the motivation for this was the growing potential of frontier AI models, particularly their ability to uncover software vulnerabilities that even the software’s creators were unaware of.
Book a Free
Demo Call
with Our Expert
Discover how Threatcop protects your workforce from modern cyber threats.
The actual meaning of the mandate
Three documents back the mandate: the Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI framework), which establishes responsible AI principles and workforce capacity expectations; the June 2026 AI-accelerated cyber threats advisory, which sets compliance actions and a deadline; and the draft model risk management guidance, which requires a board-approved framework for AI/ML models.
1. The FREE-AI framework (August 2025)
The principles for responsible AI in finance were established in the FREE-AI report, which contains 7 sutras, 6 pillars, and 26 recommendations. Two specific ones are important here. The People First sutra emphasizes the importance of human factors in AI adoption. At the same time, the Capacity pillar highlights the need for institutions to build their workforce’s capacity to operate in an AI context. That is, the capability of the workforce is not simply a ‘best practice’ item in FREE-AI; it is an integral part of the FREE-AI framework.
2. The June 2026 advisory – five actions, one deadline
The AI-accelerated cyber threats advisory outlined compliance expectations and a clearly defined timeframe. It applies to all entities regulated by the RBI, including commercial banks, cooperative banks, NBFCs, payment banks, small finance banks, credit information companies, and payment system operators. It recommended five actions:
- Complete an AI risk gap assessment and obtain Board approval.
- Upgrade AI-related cybersecurity frameworks.
- Execute AI-driven tests on their own systems.
- Identify existing vulnerabilities before attackers do.
- Provide a time-bound, board-approved action plan by June 30, 2026.
3. The draft model risk management guidance (June 24, 2026)
This guidance will compel banks to create a board-approved framework for any internally developed or vendor-purchased AI/ML models. At the time of writing, the guidance remains in draft form.
The requirement most teams miss
The advisory isn’t limited to the AI you deploy. It states that protection is needed against the use of AI in social engineering and impersonation, such as deepfakes, cloned voices, and spoofed identities. Compliance evidence must cover people, not just models.
How can Threatcop assist you in complying with the RBI AI Risk Mandate?
While technology can help mitigate many AI-enabled attacks, it is not a cure-all. A firewall will not block a phone call, and no EDR agent will recognize a WhatsApp message from someone posing as your MD. This is the issue Threatcop, an Indian human risk management company, is meant to fix, and its AAPE (Assess, Aware, Protect, Empower) solution closely aligns with what the RBI now expects a Board to demonstrate.
Simulation: evidence for the gap assessment
The first step in an effective gap assessment is to measure current exposure. Simulations provide measurable evidence of that exposure.
Begin with the assessment. AI can now easily create the attacks that TSAT, Threatcop’s simulation platform, tests employees against: deepfake voice calls cloning a CFO, AI-powered vishing with real two-way conversations, WhatsApp impersonation, smishing, and QR code phishing. Each employee is assigned a vulnerability score that factors in their department, role, and location, providing your board with measurable data rather than assumptions about employee preparedness.
The simulations are AI-driven and replicate the same attack methods mentioned in the advisory, testing them through the human layer—something many traditional assessments overlook.
Closing the gaps by training
TLMS provides over 2,000 training modules that are aligned with the RBI Cyber Security Framework, the DPDP Act, and SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF). It’s not just in English; the content is also available in local languages like Hindi, Tamil, Telugu, Marathi, Bengali, and Kannada, catering to branch networks outside English-speaking metros. When an employee fails a simulation, they will automatically be assigned the corresponding training module and remain locked out until they complete it.
Domain protection, reporting, and audit trails
TDMARC helps prevent domain spoofing, and TPIR gives employees a simple way to report suspicious emails to the security team, which can then be quarantined in minutes. All of it maps to the audit requirements of RBI, SEBI, and the DPDP Act, with an option for data residency in India. This provides an audit trail that aids regulatory reviews and follow-up evaluations.
What is the first step a CISO should take?
Begin where most attacks begin: people. Conduct a baseline simulation through email, voice, and WhatsApp. In scenarios where employees fail, train them, retest them after 90 days, and share the trend line with the Board. Measurable improvements in employee risk scores provide stronger evidence of progress than policy documentation alone.
The mandate’s first deadline has passed. The scrutiny isn’t. If your action plan promises the RBI a stronger human layer, book a Threatcop demo and see how your employees hold up against a deepfake before a real attacker does.
FAQs
What is the RBI AI Risk Mandate?
The RBI AI Risk Mandate is a directive requiring regulated entities to complete a board-approved AI risk gap assessment and submit a time-bound action plan by June 30, 2026. It builds on the FREE-AI framework and the draft model risk management guidance.
Who has to comply with the RBI AI Risk Mandate?
Every entity supervised by the RBI: commercial and cooperative banks, NBFCs, payment and small finance banks, payment system operators, and credit information companies. Fintechs that serve them are also affected by third-party risk requirements.
Does the mandate only cover AI models that banks deploy?
No. It also covers AI used to attack banks. The advisory specifically mentions AI-driven phishing, vishing, and deepfake impersonation, so employee readiness is part of compliance.
How does Threatcop help with RBI AI Risk Mandate compliance?
Threatcop simulates deepfake, vishing, WhatsApp, and phishing attacks, scores each employee's vulnerability, and trains them using content mapped to the RBI Cyber Security Framework. Its reports provide the Board with evidence that the action plan is delivering measurable results.

Purva is a Technical Content Strategist at Threatcop with an MBA in Business Analytics, specializing in SEO-driven content and technical editing across IT and digital domains, and is the author of the book From a Daughter’s Eye.
