RBI Master Direction on IT Governance
The Reserve Bank of India's master directive on IT governance for regulated entities — specifies that AI/ML model lifecycle artefacts must be hosted under the regulated entity's exclusive control.
What RBI Master Direction on IT Governance means in practice
The Reserve Bank of India's Master Direction on IT Governance, Risk, Controls and Assurance Practices specifies the technology controls expected of Indian banks, NBFCs and payment-system operators. The AI provisions: model lifecycle artefacts (training data, weights, evaluation sets, inference logs) must be hosted on infrastructure under the regulated entity's exclusive control. Combined with the 2024 data-localisation circulars, the effect is a sovereign-first deployment posture for any GenAI workload touching Indian customer data. MindMap's Indian BFSI deployments — including the West African Tier-1 Bank Sovereign LLM Platform and similar reference engagements — are architected to this standard from day one.
Related terms
Sovereign AI →
An architecture where customer data never leaves the network perimeter, model weights run on customer-controlled hardware, inference logs stay in the customer's SIEM, and the entire stack can operate air-gapped.
SAMA Cyber Resilience Framework →
The Saudi Central Bank's cyber-resilience framework — sets the technology and data-residency expectations for regulated financial institutions, with explicit AI provisions in the 2025 update.
DPDP Act (India) →
India's Digital Personal Data Protection Act 2023, the country's first comprehensive data-protection law, with explicit treatment of health and financial data as a special category.
More in this category
All 62 terms, in plain language
Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.