← All posts

Global regulation of AI risk in financial services: Convergent guidance from EIOPA & RBI

Anubhav Chattoraj, Founder & Director · 16 July 2026 · 13 min read

Background

With AI making inroads into every sector of the economy, regulators across the world find themselves considering how best to mitigate the risks emerging from AI adoption.

At present, their answers show a degree of convergence.

In this article, we demonstrate these similarities by comparing how two financial-sector regulators from different parts of the world approach this issue:

Overview

As demonstrated by a comparison of the EIOPA and RBI guidance, the global framework for regulation of AI risk in financial services is converging on the following principles:

  1. Risk tiering: AI systems should be classified by levels of risk, and controls should be proportionate to the level of risk.
  2. Governance framework: An organization-wide governance and risk management framework should be established by regulated entities to govern the use of AI models.
  3. Accountability for third-party systems: Entities are accountable for their use of third-party systems
  4. Documentation and explainability: Entities need to maintain comprehensive documentation regarding AI models deployed and how they were trained. These models need to be explainable. Where full explainability is not possible, stronger guardrails, enhanced testing and validation, increased human oversight etc. can serve as compensating controls.
  5. Fairness: The risk of unfair and discriminatory outcomes being produced by AI systems should be identified and mitigated.
  6. Customer protection: Customers should be able to seek redress when harmed by an AI system.
  7. Human oversight: Humans must provide effective oversight and remain responsible for AI decisions.

The following sections provide further details.

Definition of an AI system

This is the clearest area of divergence between the EIOPA and RBI guidance. EIOPA, following the EU AI Act, specifically excludes a large subset of ML systems from its definition of AI. This subset includes algorithms that accelerate the solution to well-understood optimization problems.1

To quote EIOPA:

Paragraph 42 of the Commission Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act) states that “systems used to improve mathematical optimisation or to accelerate and approximate traditional, well established optimisation methods, such as linear or logistic regression methods, fall outside the scope of the AI system definition. This is because, while those models have the capacity to infer, they do not transcend ‘basic data processing’. An indication that a system does not transcend basic data processing could be that it has been used in consolidated manner for many years. This includes, for example, machine learning-based models that approximate functions or parameters in optimization problems while maintaining performance. The systems aim to improve the efficiency of optimisation algorithms used in computational problems. For example, they help to speed up optimisation tasks by providing learned approximations, heuristics, or search strategies.”

Thus, conventional statistical models such as linear and logistic regression, and likely some well-understood pricing algorithms such as Generalised Linear Models (GLMs), would fall outside the EU’s definition of AI.

On the other hand, RBI largely treats Artificial Intelligence and Machine Learning together,2 focusing more on impact than on the underlying technology. (Some parts of RBI’s draft Guidance do deal specifically with AI rather than ML; however, the draft Guidance does not include a precise definition of “AI”.)

Risk tiering

Both RBI and EIOPA require controls to be proportionate to risk. RBI uses formal model tiering based on materiality, complexity, consumer impact, explainability, autonomy and reliance on outputs. EIOPA uses an AI impact assessment based on customer impact, autonomy, data sensitivity, scale, financial impact and business continuity.3

The EU AI Act itself classifies AI into prohibited, high-risk, limited-risk, and minimal-risk systems. The EIOPA guidance, however, goes further:

As a first step, for those AI systems that are within the scope of this Opinion, undertakings should assess the risk of the different AI systems used; it is acknowledged that there are varying levels of risks amongst those AI systems that are not prohibited or considered as high-risk under the AI Act. Therefore, undertakings should assess their risks and develop governance and risk management measures adequate and proportionate to the characteristics and risks of the specific use of AI systems at hand.

Governance framework

EIOPA and RBI both require an organisation-wide governance and risk management framework, with documented roles, responsibilities and lifecycle controls.4

EIOPA:

Undertakings need to define and document the approach to the use of AI systems across the organisation, including the governance and risk management measures that should be applied throughout the entire lifecycle of an AI system. Undertakings may leverage in this regard on existing or updated Enterprise Risk Management (ERM), model risk management, Product Oversight and Governance (POG) frameworks, or other policy or strategy approaches (e.g. through specific IT, Data, or AI frameworks etc.), insofar as these reflect the key principles outlined in this Opinion. The undertaking’s approach to AI systems should be regularly reviewed, in particular if the number, type and materiality of AI systems used within the organisation changes. The approach to AI systems should also include frameworks where the roles and responsibilities of different staff and the interplay between them are clearly defined.

RBI is more prescriptive about the roles of various parts of the organization. Under RBI’s draft Guidance:

  • The Board approves and periodically reviews the entity’s Model Risk Management Framework (MRMF) and risk appetite.
  • The Risk Management Committee of the Board (RMCB) oversees the implementation of the MRMF. It should review validation reports of models with ‘high’ or equivalent risk and approve their deployment, review model risk tiering at least annually, and review reports of breaches and other material concerns.
  • The senior management should allocate resources to operationalize the MRMF, implement risk-based tiering, and ensure that the model inventory and documentation are maintained and updated.

Accountability for third-party models

RBI and EIOPA both state that the regulated entity remains responsible even where the model or AI system is supplied by a third party. Both require due diligence, information access, contractual protections and compensating controls where transparency is limited due to third-party IP.5

EIOPA on compensating controls:

Where it is challenging to implement certain AI governance and risk management measures (e.g. data governance or explainability) due to the intellectual property rights of third-party service providers, undertakings should mitigate consequent risks by implementing complementary governance measures and by adopting other measures such as including appropriate clauses in contracts and service level agreements, conducting external audits, or performing due diligence testing and monitoring.

RBI on compensating controls:

All provisions of the MRMF (Model Risk Management Framework) should apply mutatis mutandis to third-party models. These should additionally be subject to:

(i) independent validation by the RE (Regulated Entity) in accordance with paragraphs 29 to 33 [of the draft Guidance] notwithstanding any validation, certification, or assurance provided by the third-party provider; and

(ii) enhanced oversight by the RMCB, irrespective of their risk tier.

Prior to acquisition or use of a third-party model, an RE should undertake due diligence which should, inter alia, include credibility of the service provider, methodological soundness of the model and its limitations, and the suitability and quality of data used.

Documentation and explainability

Both EIOPA and RBI require documentation sufficient for traceability, reproducibility and auditability.6 Where models are supplied by third parties, the regulated entity may not possess all underlying development records, but remains responsible for obtaining sufficient information, documentation and assurance to govern, test and oversee the model.5

RBI and EIOPA require a level of explainability proportionate to the model’s impact and accept compensating controls where full explanation is not possible.

EIOPA on explainability:

Following a risk-based and proportionate approach, undertakings should ensure that the outcomes of AI systems can be meaningfully explained. Different approaches can be used to this extent, such as using explainable AI algorithms instead of more opaque (“black box”) ones, or using complex AI systems only for the purpose of challenging and fine-tuning traditional mathematical models. Local and global model-agnostic explanatory tools [such as LIME and SHAP] may also be used to explain the inner functioning of complex AI systems, but the assumptions and limitations of these tools should be duly documented and addressed. Statistical or stochastic explanations may also be used instead of deterministic ones when duly justified and documented.

Undertakings should adapt the explanations to specific uses of AI systems. For certain uses where there are no suitable alternatives, if the complexity of the AI system hinders the full transparency and explainability, the undertaking should put in place, where necessary, complementary risk management measures such as stronger guardrails and increased human oversight. Undertakings should comprehensively secure and test - before release as well as on an ongoing basis - those uses of AI systems that could have a high impact on customers or the solvency of the undertaking.

RBI has more granular requirements on explainability. To summarise, RBI expects regulated entities to:

  • Test model behaviour under atypical or stressed scenarios to ensure absence of vulnerabilities
  • Define explainability and transparency thresholds for all AI models, applying higher explainability thresholds to models that are relied on for material decision-making
  • Subject models to enhanced risk management measures and controls where full explainability is not achievable. Such measures include:
    • enhanced validation and testing
    • mechanisms to verify and corroborate model outputs prior to their use
    • frequent validation and continuous monitoring
    • usage restrictions
    • other necessary compensating controls
  • Put in place appropriate control boundaries to mitigate the risk of hallucination
  • Conduct fairness assessments and identify and mitigate the risk of bias and discriminatory outputs

Fairness

EIOPA and RBI both require the risk of unfair or discriminatory outcomes to be identified and mitigated.7 The EIOPA opinion treats this matter in more depth, discussing, among other aspects, the use of prohibited rating factors in insurance. (Gender is a prohibited rating factor in the EU; insurance companies cannot vary prices based on the insured’s gender, even where claims statistics may have justified it.)

Per EIOPA:

Undertakings should also adopt sound data governance policies (see the data governance section [in the Opinion]), including by making reasonable efforts to remove biases in the data, including potential unlawful proxy discriminatory variables. The outputs of AI systems should also be meaningfully explainable to identify and mitigate potential bias (see the explainability section [in the Opinion]).

The outcomes of AI systems should also be regularly monitored and, where appropriate, audited, including with the use of fairness and non-discrimination metrics (see examples of metrics for higher risk uses of AI systems in Annex I [of the Opinion]).

Proxy discrimination is further defined in a footnote:

Proxy discrimination arises when sensitive customer characteristics (e.g. ethnicity), whose use is not permitted, are indirectly inferred from other customer characteristics (e.g. location) that are considered legitimate. As noted by the Commission Guidelines on the application of Council Directive 2004/113/EC to insurance in the light of the judgment of the Court of Justice of the European Union in Case C-236/09 (Test-Achats) (link), proxies should be removed unless their use is objectively justified by a legitimate aim, and it is appropriate and necessary. The Commission explains this situation with the following examples: price differentiation based on the size of a car engine in the field of motor insurance should remain possible, even if statistically men drive cars with more powerful engines. On the contrary, it is not possible to price differentiation based on the size or weight of a person in relation to motor insurance (men are commonly taller and heavier than women).

Annex I section 3 gives examples of fairness metrics, such as:

  • “Demographic Parity”, which assigns favourable decisions at proportionately equal rates to each subgroup of a protected class. For instance, in a recruitment scenario, demographic parity could mean that male and female candidates are invited to job interviews in proportion to their representation among applicants.
  • “Equalized Odds”, which requires equal true positive and true negative rates across all subgroups. For instance, in a recruitment process, this metric would ensure that qualified men and women have an equal chance to be invited to a job interview.
  • “Individual fairness”, which aims to ensure that similar individuals are treated similarly. For instance, all individuals with the same risk profile should pay the same insurance premium.

EIOPA emphasizes that “undertakings should ultimately adopt the fairness metrics that best suit their business model and uses of AI systems, taking into account risk based and proportionality considerations.”

RBI, by contrast, takes a broad-brush approach, specifying only that entities should identify the risk of bias and discriminatory outputs, carry out fairness assessments, and implement appropriate mitigants.

Customer protection

RBI and EIOPA both require that entities’ complaints handling mechanisms to address grievances arising from AI models.8

RBI expressly requires that customers be informed that they are interacting with an AI system and be given an option to switch to human assistance.9

By contrast, EIOPA does not grant a right to human assistance. It does, however, impose the following requirement:10

For customers, in addition to being informed that they are interacting with an AI system, upon the customer’s request, the influence of the AI system on the decision that has a material impact on them should be clarified using simple, clear and non-technical language to allow them to make informed decisions.

Human oversight

RBI and EIOPA both require effective human oversight of AI models.

The EIOPA opinion emphasizes that the relevant functions within regulated entities remain responsible for the functioning of AI systems within their respective domains.11

RBI is more specific about the nature of human oversight, requiring regulated entities to ensure the following12:

  • AI models have robust human oversight, including appropriate risk mitigants, including human-in-command arrangements, override/suspension/deactivation mechanisms, and periodic human review of model outputs and model-driven decisions
  • The oversight mechanism considers risks arising from automation bias, over-reliance on model outputs, and decision fatigue
  • The personnel involved in oversight possess an adequate understanding of model functioning and are able to effectively challenge, override, or escalate issues in model outputs
  • Human oversight arrangements are periodically reviewed and strengthened based on experience

Footnotes

  1. EIOPA Opinion, para 2.10 footnote 11

  2. RBI draft Guidance paras 7(3), 49

  3. EIOPA Opinion paras 3.1-3.6, RBI draft Guidance paras 17-20 and 49-53

  4. EIOPA Opinion paras 3.7-3.10, RBI draft Guidance paras 8-13, 49-50

  5. EIOPA Opinion paras 3.11 and 3.21, RBI draft Guidance paras 8-9, 45-48, 51, 53 2

  6. EIOPA Opinion paras 3.22-3.28 and Annex I Section 2, RBI draft Guidance paras 19, 21-24, 29-33, 41, 54(1), 57

  7. EIOPA Opinion paras 3.12-3.16, Annex I Section 3, RBI draft Guidance para 54(3)

  8. EIOPA Opinion para 3.16, RBI draft Guidance para 25

  9. RBI draft Guidance paras 59(ii)–(iii)

  10. EIOPA Opinion para 3.28

  11. EIOPA Opinion paras 3.29–3.33

  12. RBI draft Guidance paras 60–63