Why now
The regulatory clock is already running
Three regulators, one direction: prove what your AI did. The dates below are not projections — they are published frameworks, draft directions and enacted law.
-
August 2025 · India · RBI
01 / 04
RBI FREE-AI
The RBI committee’s Framework for Responsible and Ethical AI sets the direction for AI adoption in Indian financial institutions.
What it asks
- · Board-level accountability for AI adoption and its outcomes
- · An inventory of AI systems in use across the institution
- · Auditability: records of what AI systems decided, and why
- · The survey behind it found only 18% of AI adopters keep audit logs
Where Truint answers
The AI Inventory answers the “what do you have” questions; the Evidence Engine answers “what did it do.” The FREE-AI Gap Report shows where you stand, control by control.
-
June 2026 · India · RBI
02 / 04
RBI Draft Model Risk Management
The draft MRM guidance turns direction into obligation for models and AI systems used in decisioning.
What it asks
- · “No Record, No Deployment” — undocumented systems don’t go live
- · 10-year retention of model decision records
- · Kill switches: demonstrable ability to halt a model
- · Override files: who overrode the model, when, and why
Where Truint answers
The sealed record is the deployment prerequisite; retention certificates prove the 10 years; override files generate from evidence already on the chain.
-
2027 · India · data
03 / 04
DPDP Act — rules in force
India’s Digital Personal Data Protection regime reaches full enforcement, covering the personal data that AI systems consume and produce.
What it asks
- · Lawful purpose and consent for personal data used in automated processing
- · Obligations on significant data fiduciaries — most banks will qualify
- · Demonstrable accountability: showing, not asserting, compliance
Where Truint answers
Evidence of what data a system touched, under which policy gate, is the same sealed trail — one record serves both the RBI and DPDP conversations.
-
2027 · Global
04 / 04
MAS AIRG · EU AI Act
Singapore’s MAS AI Risk Guidelines and the EU AI Act’s high-risk obligations reach institutions with international footprints.
What it asks
- · MAS: AI risk management proportionate to materiality, with oversight evidence
- · EU AI Act: logging, traceability and human oversight for high-risk systems — credit scoring among them
Where Truint answers
The same evidence layer, exported in the shape each supervisor expects. Three regulators, one direction: prove what your AI did.
This page is the site’s single source for regulatory wording. It summarises published material for orientation — it is not legal advice, and your compliance team’s reading governs.
Map your gaps in one call.
Bring the two people who own this problem. We'll walk your estate against FREE-AI and the draft MRM — and show you what an inspection-ready answer looks like on screen.