PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Industry3 min readReviewed September 20269 sources

AIBOM for banks and financial services

Banks have managed model inventories for years. AI brings models they did not build, data they did not collect and services they do not host. An AIBOM extends the existing inventory to cover them.

Key takeaways
  • RBI's FREE-AI committee report (13 August 2025) recommends AI inventories covering models, use cases, dependencies and risks.
  • US model risk guidance was revised in April 2026 (SR 26-2), and it explicitly excludes generative and agentic AI, which regulators plan to address separately.
  • Under the EU AI Act, creditworthiness assessment and life and health insurance pricing are high-risk uses (Annex III).
  • An AIBOM links each model to data, vendors and business decisions, which supervisors and auditors ask about.

Why banks need more than a model inventory

Model inventories are established practice in banking. What has changed is the kind of model. A bank may now use a vendor's fraud model, an open-weight language model fine-tuned on internal documents, and a hosted AI service in a customer chatbot. Each brings third-party components, training data of uncertain provenance and versions that change outside the bank's release process. An AIBOM records these dependencies in a standard form.

India: RBI FREE-AI

The RBI's committee report on a Framework for Responsible and Ethical Enablement of AI (FREE-AI) was released on 13 August 2025. Its recommendations include board-approved AI policies covering governance, lifecycle management, risk controls and third-party vendor liabilities; the creation of AI inventories and sector-wide repositories covering models, use cases, dependencies and risks; and AI incident reporting with audit processes [1]. The report sets out seven sutras, six pillars and 26 recommendations [2]. These are committee recommendations; check current RBI directions for binding requirements.

Group entities that are SEBI-regulated, such as broking or depository subsidiaries, also fall under SEBI's Cybersecurity and Cyber Resilience Framework (August 2024) [3].

United States: revised model risk guidance

On 17 April 2026 the Federal Reserve, OCC and FDIC issued revised model risk management guidance (SR 26-2), superseding SR 11-7 [4]. Legal commentary notes that the revision raises the primary scope to institutions above USD 30 billion in assets, narrows the definition of a model, and explicitly excludes generative and agentic AI models, which regulators plan to address in separate guidance [5]. Banks using those models therefore cannot rely on model risk guidance alone for them, and an AIBOM gives them a documented inventory in the meantime.

European Union: high-risk uses in finance

Annex III of the EU AI Act lists AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score (excluding fraud detection) and AI for risk assessment and pricing in life and health insurance as high-risk [6]. Following the AI Omnibus, Annex III obligations apply from 2 December 2027 [7]. Providers must maintain Annex IV technical documentation, which covers third-party pre-trained components and training-data provenance [8].

What a bank's AIBOM should add

FieldWhy it matters in banking
Business decision supportedLinks the model to credit, fraud, pricing or customer-service outcomes
Vendor and contract referenceSupports third-party risk reviews and vendor liability
Training data categoriesShows whether customer personal data was used
Validation and approval recordEvidence for model governance committees
Hosted model identifier and versionDetects provider-side changes
Monitoring metricsSupports drift and performance review

These sit on top of the CERT-In minimum elements, which include model developer, licensing, performance metrics and data source [9].

Getting started

  1. Extend the existing model inventory to include vendor models, hosted AI services and AI features in SaaS products.
  2. Generate an AIBOM for each, starting with customer-facing and credit-related systems (AIBOM generation).
  3. Add AIBOM requirements to vendor contracts (AI procurement requirements).
  4. Route new models through an approval gate that checks AIBOM completeness (AIBOM management).

How IntelliXBOM helps

IntelliXBOM helps banks keep AIBOMs for in-house and vendor models, validate them against required-field policies, and correlate models and frameworks with vulnerabilities, licences and the business services they support. It maps the inventory to framework controls with timestamped evidence and can run on-premise or air-gapped.

This article summarises public guidance and is not legal advice.

Frequently asked questions

Does RBI require an AI inventory?

The RBI FREE-AI committee report of August 2025 recommends AI inventories and sector-wide repositories covering models, use cases, dependencies and risks, along with board-approved AI policies. These are committee recommendations, so check current RBI directions for what is binding.

Does US model risk guidance cover generative AI?

According to legal commentary on SR 26-2, issued in April 2026, the revised guidance explicitly excludes generative and agentic AI models. Regulators plan to issue separate guidance on them.

Is credit scoring high-risk under the EU AI Act?

Yes. Annex III lists AI systems used to evaluate the creditworthiness of natural persons or establish their credit score as high-risk, excluding systems used to detect financial fraud.

Sources

  1. ERGO: RBI's FREE-AI Framework (28 August 2025)Khaitan & Cowww.khaitanco.com/sites/default/files/2025-08/Ergo%20-%20FREE%20AI%20Framework%20-%2028%20Augusut%202025.pdf
  2. RBI FREE-AI Committee Report on Framework for Responsible and Ethical Enablement of Artificial IntelligenceKPMG Indiakpmg.com/in/en/insights/2025/08/rbi-free-ai-committee-report-on-framework-for-responsible-and-ethical-enablement-of-artificial-intelligence.html
  3. Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (August 2024)SEBIwww.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html
  4. SR 26-2: Revised Guidance on Model Risk Management (17 April 2026)Board of Governors of the Federal Reserve Systemwww.federalreserve.gov/supervisionreg/srletters/SR2602.htm
  5. Agencies Overhaul Model Risk Management Guidance for Banks: Here's What ChangedOrrickwww.orrick.com/en/Insights/2026/04/Agencies-Overhaul-Model-Risk-Management-Guidance-for-Banks-Heres-What-Changed
  6. AI Act Annex III: High-Risk AI SystemsEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/annex/3/
  7. AI Omnibus enters into force (27 July 2026)European Commissiondigital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force
  8. AI Act Annex IV: Technical DocumentationEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/annex/4/
  9. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related AIBOM guides

Across the BOM Suite

Put your AIBOM under governance.AI supply-chain transparency with continuous correlation and timestamped evidence.