3
Common high-stakes AI use cases across Indian BFSI
2023
Year the DPDP Act was enacted, governing the personal data these models use
Nov 2025
MeitY's India AI Governance Guidelines released under the IndiaAI Mission
1
Sign-off gate most institutions still handle by email and spreadsheet

Ask most risk teams whether they have an AI governance process, and the answer is usually yes — a policy document, a checklist, maybe a committee that meets quarterly. Ask whether that process actually distinguishes between a document classifier flagging KYC uploads and a model that decides who gets a loan, and the answer is often no. Everything gets the same generic form.

That's a problem, because these use cases are not the same kind of risk. A misclassified PAN card creates rework. A wrongly declined loan application creates a regulatory complaint, a fairness question, and potentially a DPDP grievance. Building one AI impact assessment (AIIA) process that treats both identically either under-scrutinises the second or buries the first in paperwork it doesn't need.

What an AI Impact Assessment Actually Covers A documented, pre-deployment review of an AI system's purpose, the data it consumes, its risk tier, its fairness and explainability posture, and who is accountable for monitoring it once it's live. It is a governance record, not a technical audit — and it should be proportionate to what the model actually decides.

Why This Is No Longer Optional

Three regulatory threads are converging on Indian BFSI institutions at once. The DPDP Act, 2023 governs how personal data feeding any AI system is collected, used, and protected — and how individuals can seek recourse when an automated process affects them. MeitY's India AI Governance Guidelines, released in November 2025 under the IndiaAI Mission, set a national baseline for risk-based, sector-agnostic AI adoption, explicitly encouraging impact assessments proportionate to risk. And sector regulators are layering their own expectations on top: the RBI's long-standing model risk management expectations extend naturally to AI-based credit and lending models, while IRDAI has begun convening industry working groups specifically on AI governance for insurers.

None of this requires a specific product or vendor to comply with. What it requires is a repeatable, documented process — one that can show a regulator, an auditor, or a board committee that every AI system materially affecting a customer was assessed before it went live, and continues to be reviewed after.

Regulatory DriverWhat It Actually RequiresApplies Most To
DPDP Act, 2023Lawful processing of personal data; recourse for individuals affected by automated outcomesAll three use cases
MeitY AI Governance GuidelinesRisk-proportionate assessment before and after deploymentAll three use cases
RBI model risk expectationsModel validation, explainability, and human oversight for credit decisionsCredit scoring
IRDAI AI governance workEmerging sector-specific expectations for insurers using AIInsurance-linked underwriting & claims AI

Use Case 1: KYC & Document Classification AI

Models that read and classify onboarding documents — PAN cards, address proofs, signatures — are usually the first AI a bank or NBFC deploys, because the risk feels contained. It largely is: a misclassification typically routes a document to manual review rather than making a decision that harms a customer.

That doesn't mean no assessment is needed. The data itself is sensitive personal information under the DPDP Act, and document classifiers are frequently the entry point where AI first touches identity documents at scale. A standard-depth assessment — confirming data handling, retention, and a human fallback when confidence is low — is proportionate and keeps the onboarding funnel auditable without slowing it down.

Use Case 2: Transaction Fraud Detection AI

Fraud models sit in a different tier. They act in near-real time, and the cost of getting it wrong runs both ways: a missed fraud pattern is a loss, but a false positive means declining or freezing a legitimate customer's transaction — sometimes their salary credit or a time-sensitive payment.

An enhanced-depth assessment for fraud models should document the false-positive rate the business is willing to accept, how customers are notified and can appeal a block, and how the model's behaviour is monitored for drift as fraud patterns evolve. This is also the use case most likely to intersect with CERT-In and RBI incident-reporting obligations if the model itself is manipulated or gamed — a reason to treat its governance record as seriously as any other production system.

A PROPORTIONATE AIIA LIFECYCLE — FROM INTAKE TO IN-LIFE MONITORING
MODEL INTAKE RISK TIERING PROPORTIONATE ASSESSMENT SIGN-OFF & RECORD IN-LIFE MONITORING Monitoring findings re-open the assessment when model behaviour changes A REPEATABLE PROCESS, NOT A ONE-TIME FORM
The assessment doesn't end at deployment — findings from production monitoring feed back into re-assessment when a model's behaviour drifts

Use Case 3: Credit Risk Scoring AI

Credit scoring is where an AI impact assessment matters most, because the model's output directly decides whether someone gets access to a financial product — and on what terms. This is the use case that most squarely intersects RBI's model risk management expectations, DPDP's provisions on automated decisions affecting individuals, and basic fairness obligations that predate AI entirely.

A full assessment here should go beyond "does the model perform well" to ask who reviews an adverse decision, whether the model's key drivers can be explained to the customer and to a regulator, what data it was trained on and whether that data reflects the population it's now scoring, and how often the model is revalidated as market conditions and applicant behaviour shift. This is also the use case where sign-off should sit above the model-owning team — typically with a risk or model governance function that isn't the one being asked to ship the model quickly.

A Common Failure Pattern The most frequent gap isn't a missing assessment — it's an assessment done once at launch and never revisited. A credit model retrained on six months of new data, or a fraud model retuned after a new attack pattern, is functionally a different model. If the assessment record doesn't reflect that, it isn't protecting anyone by the time it's needed.

"Assessment depth should scale with how directly a model affects a customer's outcome — a document classifier and a credit decision are not the same governance problem."

— CreativeCyber AI Governance Analysis, Sep 2026

What a Practical AIIA Program Looks Like

Institutions that get this right tend to share a few habits, none of which require exotic tooling:

A single inventory, not scattered spreadsheets. Every model in production or under development is listed in one place, with its risk tier and assessment status visible to risk, compliance, and the business owner — not locked in one team's inbox.

Risk tiers that actually change what's required. A three-tier structure (low, medium, high impact) with genuinely different assessment depth per tier keeps the process fast for low-stakes models and rigorous for the ones that matter.

A sign-off that's recorded, not assumed. Whoever approves a model for deployment — business owner, risk function, or both for high-impact cases — should leave an auditable record, not a verbal go-ahead in a meeting.

Monitoring that reopens the assessment. A model's risk profile isn't fixed at launch. Drift, retraining, or a change in the population it serves should trigger a fresh look, not wait for the next annual review cycle.

SIGN-OFF ROUTING BY RISK TIER
WHO SIGNS OFF, BY TIER STANDARD Business owner sign-off ENHANCED Business owner + risk function sign-off FULL Business owner + risk/model governance function + audit-retained record Higher-impact use cases route through more independent reviewers before deployment — never fewer.
Sign-off complexity should increase with a model's customer impact, not stay flat across every use case

The Practical Takeaway

India's AI governance expectations are still forming, but the direction is clear: proportionate, documented, and revisited assessment is becoming the baseline BFSI institutions are expected to meet, whether the pressure comes from DPDP obligations, MeitY's national guidelines, RBI's model risk lens, or a sector regulator's emerging AI framework. Getting there doesn't require treating every model identically — it requires a process that can tell a KYC classifier from a credit decision, and give each the scrutiny it actually needs.

RiskSage AI Capability RiskSage AI includes a structured AI impact assessment workflow, a model inventory with risk tiering, and sign-off tracking — built to help BFSI risk and compliance teams run a proportionate, auditable AIIA process across every AI use case in production.

Open RiskSage AI →

Regulatory references: DPDP Act 2023 (Government of India); MeitY India AI Governance Guidelines, November 2025, under the IndiaAI Mission; RBI model risk management expectations for regulated entities; IRDAI AI governance working-group activity for the insurance sector. Verify current requirements against the regulator's own published material before relying on this summary for compliance purposes.