AIBOM for banks and financial services
Banks have managed model inventories for years. AI brings models they did not build, data they did not collect and services they do not host. An AIBOM extends the existing inventory to cover them.
- RBI's FREE-AI committee report (13 August 2025) recommends AI inventories covering models, use cases, dependencies and risks.
- US model risk guidance was revised in April 2026 (SR 26-2), and it explicitly excludes generative and agentic AI, which regulators plan to address separately.
- Under the EU AI Act, creditworthiness assessment and life and health insurance pricing are high-risk uses (Annex III).
- An AIBOM links each model to data, vendors and business decisions, which supervisors and auditors ask about.
Why banks need more than a model inventory
Model inventories are established practice in banking. What has changed is the kind of model. A bank may now use a vendor's fraud model, an open-weight language model fine-tuned on internal documents, and a hosted AI service in a customer chatbot. Each brings third-party components, training data of uncertain provenance and versions that change outside the bank's release process. An AIBOM records these dependencies in a standard form.
India: RBI FREE-AI
The RBI's committee report on a Framework for Responsible and Ethical Enablement of AI (FREE-AI) was released on 13 August 2025. Its recommendations include board-approved AI policies covering governance, lifecycle management, risk controls and third-party vendor liabilities; the creation of AI inventories and sector-wide repositories covering models, use cases, dependencies and risks; and AI incident reporting with audit processes [1]. The report sets out seven sutras, six pillars and 26 recommendations [2]. These are committee recommendations; check current RBI directions for binding requirements.
Group entities that are SEBI-regulated, such as broking or depository subsidiaries, also fall under SEBI's Cybersecurity and Cyber Resilience Framework (August 2024) [3].
United States: revised model risk guidance
On 17 April 2026 the Federal Reserve, OCC and FDIC issued revised model risk management guidance (SR 26-2), superseding SR 11-7 [4]. Legal commentary notes that the revision raises the primary scope to institutions above USD 30 billion in assets, narrows the definition of a model, and explicitly excludes generative and agentic AI models, which regulators plan to address in separate guidance [5]. Banks using those models therefore cannot rely on model risk guidance alone for them, and an AIBOM gives them a documented inventory in the meantime.
European Union: high-risk uses in finance
Annex III of the EU AI Act lists AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score (excluding fraud detection) and AI for risk assessment and pricing in life and health insurance as high-risk [6]. Following the AI Omnibus, Annex III obligations apply from 2 December 2027 [7]. Providers must maintain Annex IV technical documentation, which covers third-party pre-trained components and training-data provenance [8].
What a bank's AIBOM should add
| Field | Why it matters in banking |
|---|---|
| Business decision supported | Links the model to credit, fraud, pricing or customer-service outcomes |
| Vendor and contract reference | Supports third-party risk reviews and vendor liability |
| Training data categories | Shows whether customer personal data was used |
| Validation and approval record | Evidence for model governance committees |
| Hosted model identifier and version | Detects provider-side changes |
| Monitoring metrics | Supports drift and performance review |
These sit on top of the CERT-In minimum elements, which include model developer, licensing, performance metrics and data source [9].
Getting started
- Extend the existing model inventory to include vendor models, hosted AI services and AI features in SaaS products.
- Generate an AIBOM for each, starting with customer-facing and credit-related systems (AIBOM generation).
- Add AIBOM requirements to vendor contracts (AI procurement requirements).
- Route new models through an approval gate that checks AIBOM completeness (AIBOM management).
How IntelliXBOM helps
IntelliXBOM helps banks keep AIBOMs for in-house and vendor models, validate them against required-field policies, and correlate models and frameworks with vulnerabilities, licences and the business services they support. It maps the inventory to framework controls with timestamped evidence and can run on-premise or air-gapped.
This article summarises public guidance and is not legal advice.
Frequently asked questions
Does RBI require an AI inventory?
The RBI FREE-AI committee report of August 2025 recommends AI inventories and sector-wide repositories covering models, use cases, dependencies and risks, along with board-approved AI policies. These are committee recommendations, so check current RBI directions for what is binding.
Does US model risk guidance cover generative AI?
According to legal commentary on SR 26-2, issued in April 2026, the revised guidance explicitly excludes generative and agentic AI models. Regulators plan to issue separate guidance on them.
Is credit scoring high-risk under the EU AI Act?
Yes. Annex III lists AI systems used to evaluate the creditworthiness of natural persons or establish their credit score as high-risk, excluding systems used to detect financial fraud.
Sources
- ERGO: RBI's FREE-AI Framework (28 August 2025)Khaitan & Cowww.khaitanco.com/sites/default/files/2025-08/Ergo%20-%20FREE%20AI%20Framework%20-%2028%20Augusut%202025.pdf
- RBI FREE-AI Committee Report on Framework for Responsible and Ethical Enablement of Artificial IntelligenceKPMG Indiakpmg.com/in/en/insights/2025/08/rbi-free-ai-committee-report-on-framework-for-responsible-and-ethical-enablement-of-artificial-intelligence.html
- Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (August 2024)SEBIwww.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html
- SR 26-2: Revised Guidance on Model Risk Management (17 April 2026)Board of Governors of the Federal Reserve Systemwww.federalreserve.gov/supervisionreg/srletters/SR2602.htm
- Agencies Overhaul Model Risk Management Guidance for Banks: Here's What ChangedOrrickwww.orrick.com/en/Insights/2026/04/Agencies-Overhaul-Model-Risk-Management-Guidance-for-Banks-Heres-What-Changed
- AI Act Annex III: High-Risk AI SystemsEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/annex/3/
- AI Omnibus enters into force (27 July 2026)European Commissiondigital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force
- AI Act Annex IV: Technical DocumentationEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/annex/4/
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.