Finance did not wait for the national framework; it wrote the first draft of it. Three months before MeitY published its sutras, the Reserve Bank of India released its committee’s report on a Framework for Responsible and Ethical Enablement of Artificial Intelligence ~ the FREE-AI report, submitted on 13 August 2025 ~ setting out seven guiding sutras, twenty-six recommendations and six pillars: infrastructure, policy, capacity, governance, protection and assurance.
Those seven sutras are, in substance, the seven that MeitY would adopt for the nation in November. The finance regulator drew the thread first, and the country took it up; for the practitioner, that lineage is not trivia but a signal ~ the sutras reach finance already load-bearing, road-tested in the economy’s most regulated corner before being applied to the whole. Begin by mapping each task to the principle it most engages. AI-driven lending answers above all to Fairness and Equity: the danger is not merely a bad loan but a discriminatory one, bias laundered through a training set and reproduced at scale. Algorithmic and AI-assisted trading answers to Understandable by Design: a strategy no one can explain is a strategy no one can supervise.
Advertisement
AI-generated ESG ratings turn on Accountability: when a score moves capital, someone must own the judgement the machine appears to have made. And AI-assisted audit commentary engages Accountability and understandability at once – the auditor who leans on a model still signs the opinion. The cost of getting this wrong is not hypothetical. In an interim order of July 2025, SEBI impounded Rs 4,843.57 crore in alleged unlawful gains from a US-based trading group accused of manipulating the Bank Nifty on derivative-expiry days ~ buying index constituents through the morning to lift the index, then reversing in the afternoon to profit from far larger options positions. The case vindicated the traceability architecture the regulator had already built.
Its circular of 4 February 2025 requires every algorithmic strategy to be registered with the exchange and tagged with a unique Algo ID before it goes live, mandatory across the board from 1 April 2026, and it splits algorithms into disclosed “white box” and opaque “black box” categories, the latter’s providers pushed towards registration and documentation. Explainability, here, is not an ethical nicety; it is the precondition of supervision. In lending, the commentary is being written now.
On 24 June 2026 the Reserve Bank released draft guidance on model risk management (Press Release 2026-2027/528, open for comment until 24 July 2026) that would require every regulated entity to adopt a board-approved framework covering all models ~ built in-house, bought from a vendor, or both ~ with explicit controls for explainability, bias, hallucination and data drift, and a “kill switch” for models that misbehave. Its decisive move is to make accountability non-transferable: outsourcing a model to a fintech vendor does not outsource the liability for what it decides. The same principle already binds the securities markets: SEBI’s Regulation 16C, in force from 10 February 2025, makes the intermediary the single point of accountability for every AI system it deploys, and its consultation paper of 20 June 2025 rests on six pillars ~ ethics, accountability, transparency, auditability, data privacy and fairness. You may deploy the model, but you may not outsource the responsibility.
Two frontiers remain thinly governed. AI-generated ESG ratings carry a double opacity ~ corporate data that is often self-reported and unverified, run through a weighting model that is itself proprietary ~ so that greenwashing can enter at the input layer and again at the scoring layer. SEBI brought ESG-rating providers under a registration framework in 2023 and, in February 2026, constituted a working group to review it. Audit is subtler still. As machine tools move into working papers, and with revised auditing standards set to take effect for Indian audits from April 2026, the profession has not yet fixed the documentation a machineassisted judgement demands.
A model can flag an anomaly; it cannot decide whether the anomaly is fraud or a legitimate change in the business. The signature at the foot of the report is still a human one. None of this is exotic. It is ordinary audit discipline ~ evidence, recalculation, documentation ~ applied to a novel object. The temptation is to imagine that because the tool is new the assurance must be invented from nothing, and so to wait for a standard-setter before acting. That is precisely the misreading the sutra form is meant to forestall. Nor is the risk marginal: the Reserve Bank’s Financial Stability Report of June 2026, surveying thirty-three scheduled commercial banks and ten large non-bank lenders, found AI-enabled cyber threats ranked as the single most significant risk institutions expected over the coming year, ahead of ransomware and phishing.
This is a board-level exposure, not a technologydepartment one, and it lands squarely on the audit committee’s desk. What the profession now lacks is not principle but method ~ the bhāsya that turns a sutra into a working standard. Two are worth proposing concretely. The first is an assurance framework for AI-assisted disclosures under Ind AS, where a model may draft a note to the accounts, an expected-credit-loss estimate under Ind AS 109, an impairment test under Ind AS 36, or a fair-value measurement under Ind AS 113. Before relying on such output, the auditor should independently test three things: the provenance of the training data, documented and evidenced rather than asserted; the monitoring of model drift between reporting dates; and a complete human-override log, showing where a person changed the machine’s output and why.
Where the model is a vendor’s, the same evidence ~ model cards, bias-test results, explainability documentation ~ should be a condition of the contract, not an afterthought. The second is a control framework for machine-learning fraud detection: disclosure of the model’s own false-positive and false-negative rates, revalidation on a fixed cadence rather than at installation alone, and explainability documentation adequate to defend every automated flag that ripens into a Suspicious Transaction Report filed with the Financial Intelligence Unit ~ in language a regulator, and if need be a court, can read.
None of this waits on a new statute; all of it can be built now. For four decades the financial professions have read the terse language of statute and standard and supplied the working meaning that lets others act on it. The AI sutras ask nothing different of them, only sooner and at higher stakes. A sutra, the grammarians knew, is inert without its commentator. India’s financial professionals are now that commentary.
(The writer is a practicing Chartered Accountant and a Vedantic Scholar and can be reached at kannan@cakt.in)