RBI’s FREE-AI Framework: What It Actually Requires From KYC & Fraud Systems
RBI’s FREE-AI framework sets governance expectations for AI in Indian financial services. What its 7 Sutras actually require from AI-powered KYC and fraud-detection systems.

On 13 August 2025, the Reserve Bank of India released a report titled “Framework for Responsible and Ethical Enablement of Artificial Intelligence” (FREE-AI). It sets out 7 guiding principles and 26 recommendations across 6 pillars for how RBI-regulated entities should govern AI use, a framework not yet a binding regulation but one that reaches AI used for KYC/onboarding and fraud detection the same way it reaches every other AI use case a bank, NBFC, insurer, or fintech deploys. Nothing in it is KYC- or fraud-specific; the governance expectations (board policy, liability posture, audit trail, disclosure) apply across the board, and KYC and fraud detection show up mainly as two of the use cases RBI’s own survey work tracked.
RBI’s own FREE-AI report PDF and its 13 August 2025 press release both sit behind a CAPTCHA wall. Recommendation-level claims below are corroborated against a KPMG India summary reproducing the report’s own numbering and survey data, cross-checked against law-firm and industry coverage. As of September 2026, FREE-AI remains a committee report with recommendations awaiting binding regulatory effect.
The Committee Behind FREE-AI
Constituted on 26 December 2024 and chaired by Prof. Pushpak Bhattacharyya of IIT Bombay.
RBI constituted the FREE-AI committee on 26 December 2024as an eight-member expert panel chaired by Prof. Pushpak Bhattacharyya of IIT Bombay’s Department of Computer Science and Engineering. Its brief: assess AI adoption in financial services, review how other regulators approach AI, identify AI-related risks, and recommend a governance and monitoring framework suited to India’s financial sector. The other seven members were drawn from academia, industry, and government.
The 7 Sutras: Guiding Governance Principles
The philosophical bedrock of responsible and ethical AI adoption in Indian BFSI.
The report frames its governance philosophy as seven guiding principles, called “Sutras”:
| # | Sutra | What It Means |
|---|---|---|
| 1 | Trust is the Foundation | Trust is non-negotiable and should remain uncompromised |
| 2 | People First | AI should augment human decision-making but defer to human judgment and citizen interest |
| 3 | Innovation over Restraint | Foster responsible innovation with purpose |
| 4 | Fairness and Equity | AI outcomes should be fair and non-discriminatory |
| 5 | Accountability | Accountability rests with the entities deploying AI |
| 6 | Understandable by Design | Ensure explainability for trust |
| 7 | Safety, Resilience & Sustainability | AI systems should be secure, resilient, and energy efficient |
These seven names and their order are corroborated identically across multiple sources summarizing the report.
The 26 Recommendations, Organized Across 6 Pillars
Dual tracks: Innovation Enablement vs Risk Mitigation.
The report organizes its 26 recommendations under six pillars, split into two tracks:
| Track | Pillar | What It Covers |
|---|---|---|
| Innovation Enablement | Infrastructure | Shared AI infrastructure for the sector |
| Innovation Enablement | Policy | Rules and institutional support for AI adoption |
| Innovation Enablement | Capacity | Building sector-wide AI skills and readiness |
| Risk Mitigation | Governance | Board-level accountability for AI use |
| Risk Mitigation | Protection | Consumer, cybersecurity, and continuity safeguards |
| Risk Mitigation | Assurance | Audit, inventory, and disclosure of AI systems |
Three of these pillars carry the most weight for anyone running AI-powered KYC or fraud detection:
- Governance: Recommendation 14 calls for every RBI-regulated entity to adopt a formal Board-Approved AI Policy covering governance, risk, and accountability. Recommendation 15 mandates strong Data Lifecycle Governance, and Recommendation 16 establishes AI System Governance and pre-launch Product Approval risk checks.
- Policy: Recommendation 8 proposes a flexible AI Liability Framework using a graded-liability approach: the regulated entity stays liable for customer losses caused by AI errors, but RBI would apply an accommodative supervisory response for isolated, good-faith incidents where safeguards were followed.
- Assurance: Recommendation 23 calls for entities to maintain internal AI inventories. Recommendation 24 establishes a risk-based AI Audit Framework (internal and third-party), and Recommendation 25 requires annual report public disclosures of AI governance.
The report also proposes giving these recommendations effect partly through amendments to existing RBI regulatory instruments, including Information Technology Governance and IT Outsourcing directions.
What This Means for AI-Powered KYC and Fraud Tools
Four critical due-diligence questions buyers must ask tech vendors.
FREE-AI treats KYC and fraud detection as two of the AI use cases that fall under the same governance recommendations covering every other AI deployment a regulated entity makes, with no separate KYC-AI or fraud-AI rulebook. Per one legal analysis, KYC shows up as an example of where AI can help a regulated entity meet its own KYC obligations.
That still leaves a practical question for anyone buying AI-powered KYC or fraud detection tools: what should you actually ask a vendor? The recommendations point to four questions:
1. Board-Approved AI Policy Alignment
Can the vendor's AI system support your board-approved AI policy and its risk/accountability documentation, per Recommendation 14?
2. Graded-Liability & Incident Reporting
What liability and incident-reporting posture does the vendor support, given the graded-liability approach the Policy pillar recommends?
3. Audit Trail & Inventory Support
Can the vendor support an audit trail and inventory entry that feeds your own AI inventory and disclosure obligations, per Recommendations 23–25?
4. Explainability & Transparent Design
Are the vendor's models explainable enough to satisfy the 'Understandable by Design' sutra and avoid black-box compliance failures?
The Adoption Gap: Survey Insights Across 688 Entities
Only 20.8% of entities have deployed AI, while 85% seek clear regulatory guidance.
Only 20.8% of surveyed financial entities had actually deployed AI systems, per RBI’s own survey work underlying the FREE-AI report, fielded by RBI’s Department of Supervision (612 supervised entities) and FinTech Department (76 entities) between January and May 2025, covering entities representing close to 90% of the financial sector’s asset size. Within the FinTech Department’s 76-entity sample specifically, 67% were exploring at least one Generative AI use case.
Within that same survey, roughly 20 entities reported implementing or piloting AI for AML/CFT/KYC, and roughly 32 entities reported the same for fraud detection. The barriers cited most often for wider adoption were AI talent gaps, high implementation cost, lack of high-quality training data, limited access to computing power, and legal/regulatory uncertainty. Separately, 85% of respondents said they wanted clearer regulatory guidance on data privacy, algorithmic transparency, bias mitigation, and cross-border data flows.
What This Means for KYCKART and RegTech Vendors
Why waiting for a binding circular is a strategic error for compliance teams.
This piece reads FREE-AI’s governance recommendations as extending, once the framework is given regulatory effect, to any vendor providing AI-powered KYC or fraud tooling to RBI-regulated entities, not only to the banks, NBFCs, insurers, and fintechs buying that tooling.
What the framework’s own recommendations make clear is the direction the questions are heading: whether a vendor’s AI system can support a buyer’s board-approved AI policy, what liability and incident-reporting posture it supports, whether it can feed a buyer’s audit trail and AI inventory, and whether its models are explainable.
The practical implication of reading the adoption numbers and the recommendations together is that governance expectations are already published even though actual deployment is still catching up. A vendor or buyer that waits for a binding circular before addressing board policy, liability posture, audit trail, and explainability is starting that work later than the survey data suggests the market already is.
Frequently Asked Questions
Bhanujeet Choudhary
Head of Compliance, KYCKART
Published September 23, 2026
Disclaimer: This piece describes RBI’s FREE-AI report and its recommendations for general informational purposes. It is not legal or compliance advice, and RBI-regulated entities should confirm current requirements directly with RBI or qualified counsel before making compliance decisions based on it.
Next Steps for BFSI
Build Explainable, Auditable AI into Your Compliance Stack
Talk to KYCKART’s compliance specialists to align your KYC and fraud detection pipelines with RBI’s emerging AI governance, auditability, and model explainability standards.
Explore Fraud Intelligencearrow_forward