MODULE 1 — ACADEMIC NOTES
WEEK 4: REGULATORY INNOVATION TOOLS — SANDBOXES,
SELF-REGULATION, AND AI GOVERNANCE
How RBI enables, structures, and governs innovation in FinTech and AI
Primary Sources: RBI Enabling Framework for Regulatory Sandbox (2024) | RBI Framework for Self-Regulatory
Organisation(s) in the FinTech Sector (SRO-FT, May 2024) | RBI FREE-AI Committee Report (2025)
QUICK ORIENTATION: What Week 4 Is About
Week 4 completes Module 1 by zooming in on three concrete regulatory tools RBI has actually
built to address the tensions identified in Weeks 1–3. Where earlier weeks diagnosed the
problems (regulatory lag, arbitrage, consumer harm, AI risk), Week 4 is about the institutional
solutions: what regulatory instruments does RBI deploy, how exactly do they work, and what are
their design choices and trade-offs?
READING CORE QUESTION IT LINK TO EARLIER WEEKS
ANSWERS
RBI Enabling Framework for How does RBI allow innovation Responds to Omarova's
Regulatory Sandbox (Updated to be tested before full "Experimentation" category (Wk
Feb 2024) regulation? What are the 1); operationalises Malhotra's
eligibility criteria, process, innovation-stability trade-off (Wk
exclusions, and safeguards? 2); and Sankar's "encouraging
innovation" principle (Wk 3)
SRO-FT Framework (May 2024) How does RBI address the Operationalises Sankar's SRO
knowledge gap between prescription from GFF 2023 (Wk
regulator and industry? What is 3 Part D); extends Malhotra's
an SRO, how does it get consultation principle (Wk 2);
recognised, what does it do? addresses the knowledge-
asymmetry problem
FREE-AI Committee Report How should AI be responsibly Addresses the AI-specific risks
(2025) adopted in Indian financial from RBI 2024 Report Ch. V
services? What are the (Wk 3 Part E.5); responds to
principles, structure, and 26 algorithmic bias, explainability,
concrete recommendations? and cyber risk concerns; DPI+AI
integration
PART A: THE RBI REGULATORY SANDBOX —
ENABLING FRAMEWORK (Updated February 2024)
A.1 Background and Evolution
The RBI first announced its Enabling Framework for Regulatory Sandbox in August 2019 —
making India one of the earlier major economies to establish a formal FinTech sandbox. The
framework has been updated three times: December 2020, October 2021, and most recently
February 28, 2024. The current framework reflects lessons learned from four completed cohorts
and the interoperable sandbox launched in October 2022.
📌 WHAT IS A REGULATORY SANDBOX?
Under the RBI framework: "Eligible domestic entities can live-test their innovative
products or services in a controlled environment with or without specified regulatory
relaxations for the limited purpose of testing." (RBI Report on Currency and Finance,
2024) The key phrase is "live-test" — this is not paper-based simulation or lab testing.
Real customers are involved, real transactions occur, and real data is generated. This is
what makes the sandbox valuable (real-world evidence) and also what makes the
regulatory safeguards essential (real consumers are at risk).
A.2 Principles and Objectives of the RBI Sandbox
The RBI sandbox rests on three core principles that define its purpose:
• Responsible Innovation: The sandbox is not a free pass. Every entity in the sandbox must
satisfy fit and proper criteria, define clear test scenarios, and maintain mandatory
consumer protections even when other regulations are relaxed.
• Efficiency: The sandbox accelerates the innovation-to-regulation pipeline — generating
empirical evidence about a product faster than waiting for harm to occur and then
regulating.
• Consumer Benefit: The ultimate test of whether a product graduates from the sandbox is
whether it demonstrably benefits consumers or the industry, delivers financial services
more efficiently, or addresses a gap in the financial ecosystem.
The learning-by-doing rationale: "Through this learning-by-doing approach, regulators gather
empirical evidence on the benefits and risks of emerging technologies and their implications,
enabling them to take a holistic view on the regulatory changes or new regulations that may be
needed to support useful innovation, while containing the attendant risks." — RBI Report on
Currency and Finance, 2024.
A.3 Benefits of the Regulatory Sandbox
BENEFIT TO FINTECH ENTITIES BENEFIT TO RBI / REGULATORY SYSTEM
Regulatory certainty during testing — clear rules Empirical evidence: real data on how a product
for the test period reduce uncertainty about actually behaves (not just theoretical risk
legality assessment)
Faster market entry: sandbox graduation can Regulatory learning: deeper understanding of new
enable quicker post-sandbox approval technologies and business models
Regulatory guidance: direct engagement with RBI Risk containment: risks are tested in a limited,
on how to design a compliant product controlled environment before full-scale
deployment
Potential for regulatory relaxations: temporarily Financial inclusion: sandbox specifically designed
eased rules allow testing of products that would to encourage innovations for financial inclusion
otherwise be blocked use cases
Signal to investors: sandbox participation signals Taxonomy development: experience with
regulatory legitimacy sandbox entities helps RBI develop appropriate
regulatory categories
A.4 Risks and Limitations — Why the Sandbox is Not a Free Pass
• Bespoke authorisations involve discretion: Case-by-case decisions on regulatory
relaxations involve judgement calls, which creates potential for inconsistency or regulatory
capture. The framework addresses this by requiring transparency and well-defined
principles in decision-making.
• No legal waivers: RBI explicitly states that "the RBI or its RS cannot provide any legal
waivers." If a product violates a law (as opposed to a regulation), the sandbox cannot
shield the entity from legal liability.
• Post-sandbox approvals still required: Successful completion of sandbox testing does
NOT automatically authorise the product for full-scale commercial deployment. The entity
must still obtain all required regulatory approvals before scaling.
• Liability stays with the entity: "Upfront clarity that liability for customer or business risks
shall devolve on the entity entering the RS will be important." Consumers who are harmed
during sandbox testing cannot rely on RBI to compensate them — the sandbox entity
bears full responsibility.
• Limited scale: By design, the sandbox is narrow in focus and limited in intake. It cannot
test products at the scale needed to detect systemic risks — it is inherently a small-scale,
short-term experiment.
A.5 Focus Areas — When is a Product Eligible for the Sandbox?
The sandbox is not open to all FinTech innovations — it focuses on three specific situations
where regulatory space is genuinely needed:
• Absence of governing regulations: The product operates in a domain where no regulation
currently exists — a true regulatory gap. This is the clearest case: there is nothing to relax,
and testing helps determine what regulation should look like.
• Need to temporarily ease regulations: An existing regulation would block deployment, but
there is a genuine case that the product's benefits justify temporary relaxation for testing.
Example: a payment innovation that requires brief testing with a slightly different KYC
process.
• Significant promise for financial services delivery: The product shows clear promise for
improving how financial services are delivered — even if not in a regulatory gap — and
live testing is the only way to generate the evidence needed.
A.6 The Negative List — What is Excluded from the Sandbox
The framework explicitly excludes certain categories from sandbox testing. This is one of the
most exam-relevant and analytically important parts of the framework:
📌 THE NEGATIVE LIST (Indicative)
Products/services NOT accepted for sandbox testing: • Credit registry and credit
information services • Cryptocurrency / crypto assets services • Trading, investing, or
settling in crypto assets • Initial Coin Offerings (ICOs) • Chain marketing services • Any
product/service banned by regulators or the Government of India The logic: The
exclusions are not arbitrary. Crypto assets and ICOs are excluded because RBI's position
is that these could threaten monetary stability and financial integrity — risks too serious
for even a controlled sandbox. Credit registry exclusion reflects that experimenting with
credit information infrastructure could create systemic risks far beyond the sandbox
boundary. Banned products are excluded because the sandbox cannot override a legal
prohibition.
A.7 Eligibility Criteria — Who Can Enter the Sandbox?
The target applicants are: FinTech companies including start-ups, banks, financial institutions,
any other company, LLPs, and partnership firms partnering with or providing support to financial
services businesses. The eligibility criteria have two layers:
BASIC ELIGIBILITY (ALL APPLICANTS) ADDITIONAL PRODUCT/INNOVATION
CRITERIA
Must be incorporated/registered in India (or a The FinTech solution should highlight an existing
bank licensed in India, or an LLP/Partnership firm gap in the financial ecosystem and demonstrate
registered in India, or a financial institution how it would address the problem and bring
constituted under an Indian statute) benefits to consumers or the industry
Minimum net worth of Rs. 10 lakh as per latest If the proposed product is similar to one already
audited balance sheet tested in the RS with no new innovation, it may
not be considered eligible
All promoters/directors/partners must be "fit and Test scenarios and expected outcomes must be
proper" — no convictions, satisfactory bank clearly defined; entity must agree to report
conduct and credit history progress on an agreed schedule
Entity must demonstrate the product is Boundary conditions (limits on scale, geography,
technologically ready for deployment. RBI will customer profile) must be clearly defined
NOT provide technology testbed or data for
testing
Entity must demonstrate arrangements for An acceptable exit and transition strategy must be
compliance with consumer data protection laws defined — what happens if the product fails or
succeeds
Entity should have robust IT infrastructure and Results of any prior Proof of Concept (PoC)
managerial resources testing must be shared before entry
6-month mandatory cooling period if application Significant risks and mitigation plan must be
rejected — cannot reapply with same/similar submitted upfront
product within this period
A.8 Mandatory Requirements That Cannot Be Relaxed
Even within the sandbox, with whatever regulatory relaxations are granted, the following
requirements apply without exception. These are non-negotiable floors:
• Customer privacy and data protection — all applicable data protection laws must be
complied with
• Secure storage of and access to payment data of all stakeholders
• Local data storage — payment data must be stored within India (India's data localisation
requirement)
• Security of transactions — all transactions must meet security standards
• KYC/AML/CFT requirements — Know Your Customer, Anti-Money Laundering,
Countering the Financing of Terrorism compliance cannot be waived
• Statutory requirements — any legal (as opposed to regulatory) requirement applies in full
⚠️ IMPORTANT FOR EXAMS
EXAM ESSENTIAL: The non-negotiable list is frequently tested. The logic is that these
requirements protect the fundamental integrity of the financial system and consumer trust
— they are not regulatory inconveniences to be balanced against innovation, but
foundational protections. The sandbox can experiment with how credit is assessed, how
payments flow, how data is used — but it cannot experiment with whether consumers are
protected or whether transactions are secure.
A.9 The Five-Stage Sandbox Process
Each cohort of the sandbox proceeds through a well-defined five-stage process, overseen by
RBI's FinTech Department (FTD) under an Inter-Departmental Group (IDG):
STAGE WHAT HAPPENS TIMELINE KEY DECISION
Stage 1: Applications received by ~1 month Is the applicant eligible? Does the
Prelimina FTD and evaluated for basic (outside the 9- product meet focus area requirements?
ry eligibility criteria. Non- month cohort
Screenin compliant or clearly ineligible timeline)
g applications weeded out.
Stage 2: FTD vets applications in ~1.5 months Should this entity be shortlisted for the
Applicatio depth: innovation Testing Phase? What regulatory
n assessment, technology, relaxations (if any) will be granted?
Assessm security evaluation.
ent and Regulatory relaxations (if
Shortlistin any) considered on case-by-
g case basis with relevant
regulatory department.
Shortlisted applicants
present to IDG.
Stage 3: FTD finalises test design ~1.5 months What specifically will be tested? What
Test with each applicant through metrics will determine success or
Design iterative engagement. failure? Are partners and systems
and Outcome metrics defined — ready?
Integratio what evidence of
n benefits/risks will the test
generate? Entities integrate
with partners and prepare for
live testing.
Stage 4: Live testing with real Maximum 5 Is the product performing as expected?
Testing customers and transactions. months Are risks being contained? Are
Phase Entity reports test results consumers being protected?
fortnightly to FTD. FTD
monitors closely.
Stage 5: FTD assesses outcome Following Should the product graduate to full-
Evaluatio reports both quantitatively testing scale deployment? What regulatory
n Phase and qualitatively. Overall changes (if any) are needed?
assessment of whether
product should be
recommended for wider
deployment.
Total cohort timeline: Ordinarily completed within 9 months from receipt of complete and eligible
applications (excluding the preliminary screening period). So the full process from initial
application to evaluation is approximately 9 + 1 = 10 months.
A.10 Sandbox Cohorts — What Has Been Tested?
The RBI sandbox has operated through thematic cohorts — each focused on a specific domain.
As of 2024, four theme-based cohorts have been completed, and a fifth theme-neutral cohort is
ongoing:
COHORT THEME AND SIGNIFICANCE
Cohort 1 Retail Payments — Testing innovations in domestic retail payment products and
services
Cohort 2 Cross-Border Payments — Testing innovations in cross-border payment efficiency,
which is a notoriously expensive and slow part of the financial system globally
Cohort 3 MSME Lending — Testing innovations specifically for credit delivery to Micro, Small
and Medium Enterprises — a financial inclusion priority
Cohort 4 Prevention and Mitigation of Financial Frauds — Testing tools and technologies to
detect, prevent, and mitigate financial fraud — highly relevant given the surge in digital
fraud
Cohort 5 Theme-neutral — Open to innovative products/services/technologies cutting across
(ongoing) any function within RBI's regulatory domain. Shortlisted entities commenced testing in
2024.
Outcome: Some products that exited successfully from these cohorts have been deployed in the
market. The sandbox has thus served its intended function — generating real-world evidence
that enabled products to receive post-sandbox regulatory approval and reach the market.
A.11 Interoperable Regulatory Sandbox — Cross-Regulator Testing
One of the most innovative features of India's sandbox framework is the Interoperable
Regulatory Sandbox (IRS) — which addresses the multi-regulator problem identified in Week 3.
Hybrid FinTech products often fall under the regulatory ambit of more than one financial
regulator simultaneously, creating a problem: which regulator's sandbox should be used?
📌 THE INTEROPERABLE REGULATORY SANDBOX (IRS)
The Inter-Regulatory Technical Group on FinTech (IRTG on FinTech), constituted under
the FSDC Sub-Committee, developed a Standard Operating Procedure for a cross-
regulator sandbox. The IRS has been operational since October 2022. Participating
regulators: RBI, SEBI, IRDAI, IFSCA (International Financial Services Centres Authority),
and PFRDA. How it works: For a product that spans multiple regulatory domains (e.g., a
platform combining insurance and lending), the relevant regulators coordinate through the
IRTG to design and oversee a single unified sandbox test — rather than requiring the
entity to navigate separate sandboxes with each regulator. This significantly reduces the
compliance burden and addresses the "regulatory mosaic" problem.
PART B: THE SRO-FT FRAMEWORK — SELF-
REGULATORY ORGANISATIONS FOR FINTECH (May
2024)
B.1 Why Self-Regulation? The Conceptual Foundation
The SRO-FT Framework is RBI's most structurally sophisticated response to the knowledge
asymmetry problem in FinTech regulation. Its intellectual foundation is elegantly simple: the
people who know the FinTech industry best are the FinTechs themselves. Industry-led self-
regulation can harness this expertise in the service of regulatory objectives.
"Self-regulation necessitates a well-defined structure based on consensus and
cooperation amongst the entities. Appropriately designed, self-regulation can usher in
self-discipline, imbibe high levels of internal governance and foster an environment
conducive to an organised and orderly development of the FinTech sector." — RBI
SRO-FT Framework, May 2024
RBI's definition: "SRO is an industry-led entity responsible for establishing and enforcing
regulatory standards, promoting ethical conduct, ensuring market integrity, resolving disputes,
and fostering transparency and accountability among its members."
B.2 The Six Characteristics of an SRO-FT
Chapter II of the framework specifies six characteristics that define what an SRO-FT must be.
These are both descriptive (what it should look like) and normative (what it is expected to
achieve):
SUTRA 1: TRUE REPRESENTATION OF THE FINTECH SECTOR
"Strength from inclusive membership"
The SRO-FT must be genuinely representative — encompassing FinTechs of diverse sizes,
stages, and activities, including both regulated FinTechs (NBFC-AAs, NBFC-P2P etc.) and
unregulated ones, but excluding banks. It must be the body the industry looks up to and
accepts as the legitimate standard-setter. Note: FinTechs may be members of more than
one SRO; FinTechs are encouraged by RBI to join at least one SRO.
SUTRA 2: DEVELOPMENT-ORIENTED
"Growth partner, not just compliance gatekeeper"
The SRO-FT must actively contribute to industry growth — prescribing minimum eligibility
criteria, providing specialised knowledge, offering guidance, contributing to capacity-
building. Crucially, it should help early-stage FinTechs with "handholding, guiding, and
keeping them abreast with the dynamic nature of financial technology and the regulatory
environment." This is forward-looking, not reactive.
SUTRA 3: INDEPENDENCE FROM INFLUENCE
"Impartiality as the source of credibility"
The SRO-FT must operate independently — free from influence of any single member or
group of members. No entity may hold 10% or more of its paid-up share capital (singly or
acting in concert). Independence prevents capture by dominant players and ensures the
SRO can credibly regulate even its most powerful members. Independence is what makes it
trustworthy to both industry and regulator.
SUTRA 4: LEGITIMATE ARBITER OF DISPUTES
"Transparent, fair, and trusted dispute resolution"
Members must perceive the SRO-FT as the appropriate forum for resolving disputes arising
among them. This requires transparent, fair, and efficient dispute resolution mechanisms.
The SRO-FT cannot be the judge-in-your-own-cause — it must be truly impartial. This is
what distinguishes an SRO from an industry lobbying body.
SUTRA 5: ENCOURAGING MEMBERS TO SUBSCRIBE TO REGULATORY
EXPECTATIONS
"Communication bridge between industry and RBI"
The SRO-FT must motivate its members to align with RBI's regulatory priorities — not just
its own self-imposed standards. Key qualification: "The codes/standards/rules set for
adoption by its members shall not be a substitute to the direct prescribed regulatory
framework for FinTechs, if any." SRO rules are in addition to, not in place of, RBI regulation.
The SRO has powers to investigate and take disciplinary action for non-adherence.
SUTRA 6: REPOSITORY OF INFORMATION
"Knowledge hub for the entire FinTech sector"
The SRO-FT must collect, analyse, and disseminate relevant data on its members'
activities. This information hub serves as a resource for industry research, trend analysis,
and policy-making. The SRO is encouraged to set up a repository containing all information
relating to its member FinTechs — making it a valuable intelligence source for both the
industry and RBI.
B.3 Eligibility Criteria for the SRO-FT — Who Can Become One?
• Legal form: Must be a not-for-profit company registered under Section 8 of the Companies
Act, 2013. This ensures the SRO is mission-driven, not profit-driven.
• Ownership structure: No entity may hold 10% or more of paid-up share capital — singly or
acting in concert. This structural dispersal of ownership prevents capture by any dominant
member.
• Primary object: The Memorandum of Association (MoA) must explicitly state operation as
an SRO-FT as its primary objective.
• Minimum net worth: Rs. 2 crore — to be achieved within 1 year of recognition by RBI, or
before commencement of operations as SRO-FT, whichever is earlier. This ensures the
SRO has adequate financial resources to function.
• IT infrastructure: Must demonstrate capability to establish necessary infrastructure
effectively and consistently. Must have robust IT infrastructure and ability to deploy
technological solutions within a reasonable timeframe.
• User harm management: Must have systems for managing "user harm" instances —
fraud, mis-selling, unfair practices, unauthorised transactions, or any misconduct harming
consumers.
• India domicile: The SRO-FT must be domiciled/registered in India. Cannot set up overseas
offices without prior RBI approval.
📌 FIT AND PROPER — BOARD AND KMP
The Board of Directors and Key Managerial Personnel (KMP) must: (1) Possess
professional competence and a reputation for fairness and integrity. (2) Declare any legal
proceedings against themselves. (3) Have no convictions for any offence including moral
turpitude or economic offences. RBI's views on fit and proper status are final.
B.4 Membership Criteria
• Primary members: Primarily FinTechs that are currently NOT regulated by any financial
sector regulator — i.e., the unregulated FinTech universe that is the hardest for RBI to
directly supervise.
• Secondary membership: May also be open to Regulated Entities (other than banks).
Banks are explicitly excluded.
• Voluntary membership: Participation is voluntary — though RBI strongly encourages
FinTechs to join at least one SRO.
• Diversity requirement: Membership must be diverse across size, stage, and activity. If
membership is inadequate at application stage, a roadmap to achieve comprehensive
membership must be included.
• Fee structure: Must be reasonable and non-discriminatory. Fees may vary by
size/capability, but all members irrespective of fees must enjoy equal rights and
representation.
• Cross-membership permitted: Given FinTechs can operate across domains, they can be
members of more than one SRO.
• RBI encouragement: "FinTechs would be encouraged by the RBI to become members of a
recognised SRO-FT." — not mandatory, but strongly promoted.
B.5 Functions of the SRO-FT (Chapter IV) — What Does It Actually
Do?
The SRO-FT's functions fall into four main clusters:
B.5.1 Standard-Setting
• Code of conduct: Frame a code of conduct for members, customised to the nature of
various activities undertaken by them.
• Industry benchmarks: Set baseline technology standards for transparency, disclosure,
data privacy, etc.
• Standardised documents: Frame standard agreements (e.g., agreements between LSPs
and regulated entities) to ensure compliance with statutory and regulatory requirements.
Members encouraged to use these as baseline.
• Accreditation mechanism: Set up accreditation for FinTechs — to improve compliance
culture, foster professionalism, create healthy market behaviour. Requires prior RBI
approval.
• Responsible advertising standards: Develop code of conduct for responsible
advertisements and market standards.
• Governance standards: Develop baseline governance standards for the FinTech sector.
• Consequences for violation: Specify and enforce consequences for misconduct —
counselling, cautioning, reprimanding, and expulsion. Monetary penalties must be
reasonable, not prohibitive. SRO-FT can bar/remove a member for a specified period or
permanently if circumstances require.
B.5.2 Oversight and Enforcement (Surveillance)
• Structured framework: Maintain a formal framework for oversight and enforcement
functions meeting regulatory expectations.
• Surveillance mechanisms: Deploy tools and techniques to assess activities of industry
participants proactively — detecting exceptions and violations before they become crises.
• Confidentiality obligation: Surveillance data must be strictly confidential. Data collection
restricted to essential information disclosed to FinTechs for specified purposes only. This
prevents the SRO from becoming a surveillance tool that members fear.
• Reporting by members: FinTechs encouraged (not merely permitted) to report their
activities to the SRO-FT proactively.
B.5.3 Developmental Functions
• Promote compliance culture: Actively promote understanding of statutory and regulatory
requirements; facilitate exchange of expertise; organise training programmes.
• Information dissemination: Share sector-specific information through periodicals, bulletins,
pamphlets, etc. — keeping members aware of developments, trends, and best practices.
• Research and development: Encourage research culture; conduct studies, surveys,
research papers, think tank discussions.
• Support for smaller entities: Extend guidance and support to smaller FinTechs agnostic of
membership — even non-members can benefit from SRO developmental activities.
B.5.4 Grievance Redressal and Dispute Resolution
• Member-level grievance redressal framework: Establish efficient, fair, and transparent
mechanisms for resolving disputes among members.
• Consumer education: Work towards customer education focused on products and services
offered by FinTech members.
• Periodic assessment: Regularly assess customer service standards and review the
grievance redressal framework.
B.6 Responsibilities Towards RBI — The SRO as a Regulatory Bridge
Beyond its member-facing functions, the SRO-FT has a defined set of responsibilities to RBI
itself. This is what makes it more than an industry association — it is a quasi-regulatory body
operating under RBI oversight:
• Collective voice: Act as the collective voice of its members in engagements with RBI —
but functioning beyond the self-interest of specific members and addressing larger
concerns of the FinTech sector.
• Notification of violations: Regularly update RBI on sector developments. Notify RBI of any
major violation by members regarding statutory/regulatory requirements or systemic
issues — enabling RBI to take timely action.
• Market intelligence: Collect relevant sectoral information and share with RBI for policy-
making. Develop a scalable technology solution for this purpose — enabling RBI to
understand details about specific products, services, and scale of activities.
• Taxonomy development: Consult RBI in developing and updating the taxonomy for
FinTechs.
• Assigned tasks: Carry out tasks assigned by RBI; review referred proposals; supply
requested data.
• Annual report submission: Submit Annual Report and periodic returns as prescribed by
RBI.
• Book inspection: RBI reserves the right to inspect or audit the SRO-FT's books. Expenses
of inspection borne by the SRO-FT.
• Guide regulation: Guide/facilitate RBI on the extent, scope, and manner of regulation of
entities in the FinTech sector — providing bottom-up intelligence for top-down regulation.
B.7 Recognition Process and Current Status
• Application: Any representative FinTech organisation can apply for recognition. Application
must be accompanied by MoA, Board details, roadmap for comprehensive membership,
and detailed justification of how it satisfies the six characteristics and proposed functions.
• Letter of Recognition: If deemed suitable, RBI issues a "Letter of Recognition" — subject
to conditions including continuing compliance with membership requirements.
• Multiple SROs possible: The number of SRO-FTs to be recognised will be based on the
number and nature of applications received. The framework explicitly contemplates that
there may be more than one SRO-FT.
📌 CURRENT STATUS (as of GFF 2024 — Das speech, optional reading Week 2)
3 applications received. 1 recognised (granted Letter of Recognition). 1 returned for
resubmission (did not meet requirements). 1 under examination.
PART C: THE FREE-AI FRAMEWORK —
RESPONSIBLE AND ETHICAL ENABLEMENT OF AI IN
INDIAN FINANCE (2025)
C.1 Background and Constitution of the Committee
FREE-AI stands for Framework for Responsible and Ethical Enablement of Artificial Intelligence.
The FREE-AI Committee was constituted by RBI in 2024 and published its report in 2025. The
Committee conducted: two RBI surveys (understanding current AI adoption and challenges in
the financial sector); extensive stakeholder consultations with regulated entities, FinTechs,
technology companies, and AI experts.
📌 THE STRUCTURE OF THE FREE-AI FRAMEWORK
7 Sutras: The foundational principles — the "living spirit" of the framework, to be woven
through the entire AI lifecycle. 6 Pillars (in 2 groups): Innovation Enablement
(Infrastructure + Policy + Capacity) and Risk Mitigation (Governance + Protection +
Assurance). 26 Recommendations: Specific, implementable steps with assigned actors
(Regulators, REs, Industry) and timelines (Short-term, Medium-term). "At the heart of the
FREE-AI framework are the 7 Sutras, the foundational principles which are the living spirit
of the framework. The 6 Pillars provide structural balance by enabling innovation as well
as mitigating risks. Finally, the 26 Recommendations bring it all to life with specific,
implementable steps that translate aspiration into action." — FREE-AI Report,
Conclusion.
C.2 AI in Finance — Opportunities and Risks (Chapter 2)
Before developing the framework, the report maps the landscape of AI adoption in Indian
finance:
AI OPPORTUNITIES IN FINANCE AI RISKS AND CHALLENGES IN FINANCE
Credit assessment: AI can process alternative Model risk (bias and opacity): AI models may
data sources (GST, utility bills, social footprint) to encode historical biases in training data; the
assess creditworthiness for thin-file borrowers "black box" problem makes decisions hard to
who lack formal credit history — expanding explain, audit, or challenge — especially serious
financial inclusion in credit decisions affecting people's lives
Fraud detection: AI can identify patterns in Hallucinations (GenAI): Generative AI can
transaction data that human analysts cannot produce inaccurate, non-sensical outputs
detect — detecting fraudulent transactions in real confidently — creating risks in customer
time across millions of transactions communications, compliance documentation, and
simultaneously financial advice
Customer service: AI-powered chatbots and Operational risk under stress: AI amplifies faults
virtual assistants provide 24/7 service, handle across high-volume transactions. A fraud
routine queries, resolve issues without human detection model that incorrectly flags legitimate
intervention — reducing costs and improving transactions — or misses actual fraud due to
experience model drift — creates losses at scale
Risk monitoring: AI can monitor portfolios, Third-party/concentration risk: AI often depends
counterparty risks, and market conditions on a small number of cloud providers and AI
continuously — generating early warning signals vendors. Failure of one vendor can cascade
faster than traditional monitoring across multiple financial institutions
simultaneously
Regulatory compliance (RegTech): AI can Liability gaps: AI blurs lines of responsibility. If an
automate compliance monitoring, flag potential AI credit model causes harm — is the deploying
violations in real time, reduce reporting burden bank, the model developer, or the data provider
responsible? Non-deterministic AI makes
accountability legally complex
Financial inclusion: Multi-modal, multi-lingual AI AI-driven collusion: Without human oversight,
can deliver financial services to millions currently goal-directed AI agents could theoretically collude
excluded — voice interfaces in local languages, in high-frequency trading or dynamic pricing —
simplified products for low-literacy users raising market conduct concerns
GenAI investments: Projected AI investment in Financial stability amplification: AI models
financial services to exceed Rs. 8 lakh crore ($97 learning from historical patterns can reinforce
billion) by 2027 globally. GenAI segment forecast market trends (procyclicality); herding when
to cross Rs. 1.02 lakh crore ($12 billion) by 2033 multiple institutions use similar models can
(CAGR 28-34%) intensify volatility
C.3 The 7 Sutras — Foundational Principles (THE HEART OF THE
FRAMEWORK)
The word "sutra" means "thread" in Sanskrit. The 7 Sutras are the threads to be woven through
the entire lifecycle of every AI system in the Indian financial sector. They are not abstract —
they must be integrated into policies, governance frameworks, operational protocols, and risk
management systems.
SUTRA 1: TRUST IS THE FOUNDATION
"Trust is non-negotiable and should remain uncompromised"
In a sector that safeguards people's money, there can be no compromise on trust. AI
systems should enhance — and not erode — public trust in the financial system. When
embedded into AI systems' essence (not treated as a by-product of compliance), trust
becomes a powerful catalyst for innovation itself. It is essential to build trust IN AI systems
and build trust THROUGH AI systems.
SUTRA 2: PEOPLE FIRST
"AI should augment human decision-making but defer to human judgment and citizen interest"
AI can improve efficiency and outcomes, but final authority should rest with humans, who
must be able to override AI — especially for societal benefit and human safety. Citizens
should be made aware of AI-generated content and informed when interacting with AI
systems. Human safety and interest at the core makes AI trusted. This directly addresses
the liability and autonomy concerns in the risks chapter.
SUTRA 3: INNOVATION OVER RESTRAINT
"Foster responsible innovation with purpose"
AI should serve as a catalyst for augmentation and impactful innovation. Responsible AI
innovation, aligned with societal values and maximising overall benefit while reducing harm,
should be actively encouraged. All other things being equal, responsible innovation should
be PRIORITISED over cautionary restraint. This is a deliberately pro-innovation stance —
recognising that excessive caution itself is a regulatory risk.
SUTRA 4: FAIRNESS AND EQUITY
"AI outcomes should be fair and non-discriminatory"
AI systems must be designed and tested to ensure outcomes are unbiased and do not
discriminate against individuals or groups. AI should uphold fairness and not accentuate
exclusion and inequity. Critically: AI should be LEVERAGED to address financial inclusion
and expand access to financial services for all — not just not-harm, but actively help.
SUTRA 5: ACCOUNTABILITY
"Accountability rests with the entities deploying AI"
Entities that deploy AI should be responsible and remain FULLY accountable for the
decisions and outcomes that arise from the use of these systems — regardless of their level
of automation or autonomous functioning. Accountability must be clearly assigned.
Accountability CANNOT be delegated to the model and underlying algorithm. This directly
closes the liability gap created by AI's non-deterministic nature.
SUTRA 6: UNDERSTANDABLE BY DESIGN
"Ensure explainability for trust"
Understandability is fundamental to building trust and should be a core design feature —
not an afterthought. AI systems must have disclosures, and outcomes should be
understood by the entities deploying them. This addresses the "black box" problem by
demanding that explainability be built in from the beginning, not retrofitted after deployment.
SUTRA 7: SAFETY, RESILIENCE, AND SUSTAINABILITY
"AI systems should be secure, resilient, and energy efficient"
AI systems should operate safely and be resilient to physical, infrastructural, and cyber
risks. They should have capabilities to detect anomalies and provide early warnings to limit
harmful outcomes. AI systems should prioritise energy efficiency and frugality to enable
sustainable adoption — acknowledging the significant compute resources AI consumes and
their environmental footprint.
⚠️ IMPORTANT FOR EXAMS
EXAM ESSENTIAL: The 7 Sutras (Trust, People First, Innovation over Restraint, Fairness
and Equity, Accountability, Understandable by Design, Safety/Resilience/Sustainability)
must be known in sequence with a one-sentence explanation of each. They are the
conceptual core of the entire FREE-AI framework and will be the first thing examiners look
for in any question about the framework.
C.4 The 6 Pillars and 26 Recommendations
The 6 pillars are organised into two complementary sub-frameworks. The key insight is that
innovation enablement and risk mitigation are NOT competing objectives — they are
complementary forces that must be pursued in tandem.
PILLAR CORE PURPOSE KEY RECOMMENDATIONS
(SELECTED)
INNOVATION ENABLEMENT Build the foundational Rec 1: Financial Sector Data
1. Infrastructure infrastructure needed to support Infrastructure as DPI (short-
AI innovation in finance term, Regulators+Govt)
Rec 2: AI Innovation Sandbox
for financial sector (short-term,
RBI/MeitY/FSRs)
Rec 3: Incentives and funding
support for smaller entities
(medium-term)
Rec 4: Indigenous Financial
Sector AI Models as public good
(medium-term)
Rec 5: Integrate AI with DPI
INNOVATION ENABLEMENT Agile, adaptive policy and Rec 6: Principle-based AI
2. Policy regulatory architecture for regulatory framework (short-
responsible AI adoption term)
Rec 7: Regulatory clarity and
compliance tolerance for low-
risk AI (medium-term)
Rec 8: Shared AI risk taxonomy
across regulators
Rec 9: AI Regulatory Committee
(short-term)
Rec 10 (under Capacity Pillar):
Capacity building within REs
INNOVATION ENABLEMENT Human skill development and Rec 10: Capacity building within
3. Capacity institutional capacity to harness REs — Board/C-suite and
AI safely workforce training (medium-
term)
Rec 11: Capacity building for
Regulators and Supervisors
(medium-term)
Rec 12: Framework for sharing
best practices via IBA/SROs
(medium-term)
Rec 13: Recognise and reward
responsible AI innovation
RISK MITIGATION Robust governance structures Rec 14: Board-Approved AI
4. Governance for AI-based decisions and Policy at each RE (medium-
actions term)
Rec 15: Data Lifecycle
Governance — robust data
governance for AI (medium-
term)
Rec 16: AI System Governance
Framework covering full model
lifecycle (medium-term)
Rec 17: AI-Specific Evaluations
in Product Approval Processes
Rec 18: Third-party AI risk
management framework
RISK MITIGATION Strong safeguards for Rec 19: Consumer protection
5. Protection consumers and the financial for AI-driven services —
system disclosure of AI interaction
Rec 20: Cybersecurity
enhancements specific to AI
threats (model poisoning,
adversarial attacks)
Rec 21: Business Continuity
Plan (BCP) for AI systems
including model-specific fallback
mechanisms (medium-term)
Rec 22: AI Incident Reporting
and Sectoral Risk Intelligence
Framework (medium-term)
RISK MITIGATION Continuous validation and Rec 23: AI Audit Framework —
6. Assurance oversight of AI systems comprehensive AI-specific
audits of high-risk models
Rec 24: AI Model Risk
Management (MRM)
Framework
Rec 25: AI Disclosures — REs
include AI disclosures in annual
reports and websites (short-
term, REs+Regulators)
Rec 26: AI Compliance Toolkit
— developed and maintained by
SRO or industry body (medium-
term)
C.5 Key Recommendations in Depth — The Most Exam-Relevant
C.5.1 Recommendation 1 — Financial Sector Data Infrastructure as DPI
A high-quality financial sector data infrastructure should be established as a Digital Public
Infrastructure — to help build trustworthy AI models for the financial sector. This infrastructure
may be integrated with the AI Kosh - India Datasets Platform, established under the IndiaAI
Mission. [Short-term, Regulators and Government]
Why it matters: AI quality is bounded by data quality. The Indian financial sector has massive
amounts of data — but it is fragmented, inconsistently formatted, and held by different entities.
A shared, high-quality financial sector dataset would democratise AI development — allowing
smaller FinTechs and even RBI itself to build better AI models. Making it a DPI (public good) is
significant: it prevents large incumbents from monopolising data advantages.
C.5.2 Recommendation 2 — AI Innovation Sandbox
An AI innovation sandbox for the financial sector should be established to enable REs,
FinTechs, and other innovators to develop AI-driven solutions, algorithms, and models in a
secure and controlled environment. Other FSRs should also collaborate to contribute to and
benefit from this initiative. [Short-term, RBI/MeitY/FSRs]
Connection to Sandbox Framework (Part A): This is a NEW, AI-specific sandbox — distinct from
the existing FinTech Regulatory Sandbox. The existing sandbox tests products with real
customers. The AI Innovation Sandbox is for developing and testing AI models and algorithms
before they are even embedded in products — an earlier stage of the innovation pipeline. Both
sandboxes serve the same philosophical purpose (evidence-based regulation) but at different
stages.
C.5.3 Recommendation 4 — Indigenous Financial Sector AI Models
Indigenous AI models (including LLMs, SLMs, or non-LLM models) tailored specifically for the
Indian financial sector should be developed and offered as a public good. [Regulators, SROs
and Industry, Medium-term]
Why this matters: General-purpose LLMs (GPT-4, Gemini, Claude etc.) are trained on diverse,
largely English-language global datasets. They may produce outputs that do not align with
Indian regulatory requirements, financial laws, and linguistic diversity. Domain-specific models
trained on RBI, SEBI, IRDAI regulatory documents, Indian financial laws, and real-world Indian
financial cases would be more precise, reliable, legally grounded, and actionable. One
implementation pathway: RBI subsidiaries or industry bodies like IBA or SRO-FT could develop
indigenous base models and make them available as a public utility.
C.5.4 Recommendation 14 — Board-Approved AI Policy
Every Regulated Entity (RE) should establish a board-approved AI policy — covering key areas
including: governance structure; accountability; risk appetite; operational safeguards;
auditability; consumer protection measures; AI disclosures; model lifecycle framework; and
liability framework. Industry bodies should support smaller entities with an indicative policy
template. [REs and Industry, Medium-term]
Significance: Just as financial institutions have board-approved policies on credit risk,
cybersecurity, and outsourcing, they must now have a formal, board-level stance on AI. This
prevents fragmented, ad-hoc AI adoption where different teams interpret "acceptable AI risk"
differently. The board-level approval ensures accountability flows to the highest level of
governance.
C.5.5 Recommendation 25 — AI Disclosures
Regulated Entities should include AI-related disclosures in their annual reports and websites.
Regulators should specify an AI-specific disclosure framework to ensure consistency and
adequacy of information across institutions. [Short-term, REs and Regulators]
This is the transparency mechanism — making AI use visible to investors, regulators,
consumers, and researchers. Disclosures enable external scrutiny and create reputational
incentives for responsible AI deployment. The short-term timeline signals urgency.
C.5.6 Recommendation 26 — AI Compliance Toolkit
An AI Compliance Toolkit will help REs validate, benchmark, and demonstrate compliance
against key responsible AI principles such as fairness, transparency, accountability, and
robustness. The toolkit should be developed and maintained by a recognised SRO or industry
body. [Regulators and Industry, Medium-term]
Significance: This directly connects the FREE-AI framework to the SRO-FT — the SRO is the
designated builder of this toolkit. This is a concrete function assigned to the SRO-FT under the
FREE-AI framework. The toolkit is voluntary but strongly encouraged — particularly for smaller
and mid-sized REs that lack internal AI risk management capabilities.
PART D: SYNTHESIS — HOW THE THREE
FRAMEWORKS CONNECT AND COMPLETE MODULE
1
D.1 The Three Frameworks as a Coherent System
The three Week 4 frameworks are not independent documents — they form a coordinated
system of regulatory innovation tools:
FRAMEWORK REGULATORY PROBLEM HOW IT CONNECTS TO
IT SOLVES THE OTHERS
Regulatory Sandbox Regulation cannot sensibly The FREE-AI framework
precede innovation that is not recommends a separate AI
yet understood. The sandbox Innovation Sandbox (Rec 2) —
enables informed, evidence- extending the sandbox concept
based regulation by generating to the AI domain. SROs can
real-world data before full-scale help design sandbox tests and
deployment. receive insights about member
firms that went through the
sandbox.
SRO-FT Framework RBI cannot directly supervise The SRO is assigned specific
thousands of FinTechs with the FREE-AI functions: developing
depth of expertise the industry the AI Compliance Toolkit (Rec
itself has. The SRO bridges the 26), sharing best practices (Rec
knowledge and supervision gap 12), developing indigenous AI
— industry-led standards, RBI models (Rec 4). The sandbox
oversight. generates intelligence that flows
to the SRO for standard-setting.
FREE-AI Framework AI creates a new class of risks FREE-AI relies on the SRO-FT
(opacity, bias, hallucinations, for implementation (toolkit, best
autonomous agency) that practices, model development).
existing regulatory frameworks The AI Sandbox (Rec 2) is a
were not designed to address. new sandbox-like mechanism.
FREE-AI builds a principles + The board-approved AI policy
recommendations architecture (Rec 14) parallels the
for responsible AI adoption. governance standards SRO-FT
sets for its members.
D.2 Module 1 in One View — The Narrative Arc
Module 1 tells a coherent story from diagnosis to prescription:
• Week 1: What is FinTech? The products, categories, and market context. India's unique
opportunity. The regulatory perimeter problem (Omarova).
• Week 2: How does RBI think about regulation? The 5 principles, 5 challenges, and DPI
strategy (Malhotra). The WG Chapter 5 Indian regulatory issues.
• Week 3: What specific tensions does FinTech create? Regulatory arbitrage, innovation-
stability, consumer protection. Three empirical examples from RBI 2024 Report: dark
patterns, BNPL, social contagion. The HKU multi-regulator map and crypto journey.
• Week 4: What are the concrete regulatory tools RBI has built in response? Sandbox
(enabling innovation + evidence), SRO (bridging knowledge gap), FREE-AI (governing AI
responsibly). Each tool directly addresses a specific regulatory challenge identified in
earlier weeks.
PART E: EXAMINATION PREPARATION
E.1 Key Definitions
• Regulatory Sandbox (RS): A framework allowing eligible entities to live-test innovative
financial products or services in a controlled environment, with or without specified
regulatory relaxations, for the limited purpose of testing. Learning-by-doing approach
generating empirical evidence for regulators.
• Cohort: An end-to-end sandbox process for a group of entities testing their products during
a stipulated period, typically themed around a specific domain. Ordinarily completed within
9 months from receipt of complete applications.
• SRO-FT: Self-Regulatory Organisation for the FinTech Sector. An industry-led entity
responsible for establishing and enforcing regulatory standards, promoting ethical conduct,
ensuring market integrity, resolving disputes, and fostering transparency and
accountability among its FinTech members.
• FREE-AI: Framework for Responsible and Ethical Enablement of Artificial Intelligence.
RBI's 2025 framework containing 7 Sutras, 6 Pillars, and 26 Recommendations for
responsible AI adoption in Indian financial services.
• 7 Sutras (FREE-AI): Trust is the Foundation | People First | Innovation over Restraint |
Fairness and Equity | Accountability | Understandable by Design | Safety, Resilience, and
Sustainability.
• Sutra (Sanskrit): "Thread" — the principles are to be woven through the entire lifecycle of
AI systems.
• Model Risk: Risk arising when AI model outputs deviate from expected outcomes, due to
bias in training data, design flaws, calibration errors, or implementation failures — leading
to financial losses or reputational harm.
• Hallucination (GenAI): A phenomenon where Generative AI produces outputs that are
inaccurate, non-sensical, or confidently wrong — creating risks in customer
communications and financial decisions.
• Board-Approved AI Policy: A formal organisational stance on AI governance, ethics, and
accountability — covering governance structure, accountability, risk appetite, operational
safeguards, auditability, consumer protection, AI disclosures, model lifecycle, and liability
framework. Required of all REs under FREE-AI Rec 14.
• Interoperable Regulatory Sandbox: A cross-regulator sandbox for hybrid FinTech products
falling under more than one financial regulator's ambit. Operated since October 2022 by
IRTG on FinTech under FSDC Sub-Committee. Participating: RBI, SEBI, IRDAI, IFSCA,
PFRDA.
• Section 8 Company: A not-for-profit company registered under Section 8 of the
Companies Act, 2013. The required legal form for the SRO-FT.
E.2 Likely Exam Questions and Approaches
Q1: "Explain the RBI's Regulatory Sandbox framework. What are its objectives, eligibility
criteria, and the five-stage process?"
Approach: Define RS and its three principles (responsible innovation, efficiency, consumer
benefit). Explain focus areas (regulatory gap, temporary relaxation need, significant promise).
Five stages with approximate timelines. Eligibility — basic (incorporated in India, min net worth
Rs. 10 lakh, fit and proper, technology-ready) and product criteria. The negative list with
reasons (crypto, ICOs excluded because of monetary stability risks). Non-negotiable
requirements (KYC/AML, data protection, security). Four completed cohorts + fifth theme-
neutral cohort. Interoperable sandbox for multi-regulator products.
Q2: "What is a Self-Regulatory Organisation? Explain the SRO-FT framework with
reference to its characteristics, eligibility criteria, functions, and responsibilities towards
RBI."
Approach: Define SRO and articulate the knowledge-asymmetry rationale. Six characteristics in
order with brief explanation of each. Eligibility: Section 8 company, no entity >10%
shareholding, Rs. 2 crore net worth, robust IT, user harm systems, India-domiciled.
Membership: primarily unregulated FinTechs, voluntary, voluntary but RBI-encouraged. Four
function clusters: standard-setting (code of conduct, benchmarks, documents, accreditation),
oversight (surveillance with confidentiality), developmental (training, research, support for small
entities), grievance redressal. Responsibilities to RBI: collective voice, notification of violations,
market intelligence, taxonomy, annual reports, book inspection. Current status: 1 recognised, 1
returned, 1 under examination.
Q3: "Explain the FREE-AI framework. What are the 7 Sutras and the 6 Pillars? Discuss its
key recommendations."
Approach: Background — why AI needs a specific framework (new risks: bias, opacity,
hallucinations, liability gaps, stability amplification). Structure: 7 Sutras + 6 Pillars + 26 Recs.
Name and briefly explain all 7 Sutras (essential). Explain the dual sub-framework logic
(Innovation Enablement vs. Risk Mitigation as complementary not competing). Name the 6
Pillars (Infrastructure, Policy, Capacity | Governance, Protection, Assurance). Key
recommendations: Rec 1 (data infrastructure as DPI), Rec 2 (AI Innovation Sandbox), Rec 4
(indigenous AI models), Rec 14 (board-approved AI policy), Rec 25 (AI disclosures), Rec 26 (AI
Compliance Toolkit by SRO).
Q4: "How do the Regulatory Sandbox, SRO-FT, and FREE-AI frameworks together
constitute a coherent system for governing FinTech innovation in India?"
Approach: Each framework addresses a distinct regulatory problem: sandbox (evidence gap),
SRO (knowledge gap), FREE-AI (AI-specific risk gap). They connect: SRO is assigned key
FREE-AI implementation roles (Recs 12, 26); FREE-AI recommends an AI-specific sandbox
(Rec 2); sandbox graduates inform SRO standard-setting. Together they reflect the three
Sankar principles: encourage innovation (sandbox, AI sandbox), non-disruptive assimilation
(SRO bridges transition), consumer protection (FREE-AI Sutras 2, 4, 5, 6; SRO grievance
redressal). These tools are also the operationalisation of Malhotra's 5 principles: sandbox =
evidence-based regulation; SRO = consultation; FREE-AI = principle-based and regular review.
E.3 Common Misconceptions to Avoid
• ❌ "Sandbox completion means the product is approved for full deployment" — WRONG.
Post-sandbox, the entity must still obtain all required regulatory approvals before scaling
commercially. The sandbox provides evidence and engagement but not automatic
clearance.
• ❌ "The sandbox provides legal waivers" — WRONG. Explicitly stated: "The RBI or its RS
cannot provide any legal waivers." Regulatory relaxations are possible; legal immunity is
not.
• ❌ "SRO-FT rules replace RBI regulation" — WRONG. "The codes/standards/rules set for
adoption by its members shall not be a substitute to the direct prescribed regulatory
framework for FinTechs, if any." SRO standards are supplementary to RBI regulation, not
a replacement.
• ❌ "Banks can be SRO-FT members" — WRONG. Membership may include Regulated
Entities other than banks. Banks are explicitly excluded. This prevents the SRO from being
dominated by the most powerful incumbents.
• ❌ "FREE-AI says AI should not be used in high-risk decisions" — WRONG. Sutra 3
explicitly says responsible innovation should be prioritised over cautionary restraint. The
framework enables AI use in credit decisions, fraud detection, etc. — but with Sutra 5
accountability and Sutra 6 explainability requirements.
• ❌ "Accountability under FREE-AI can be delegated to the AI model" — WRONG. Sutra 5
explicitly states: "Accountability cannot be delegated to the model and underlying
algorithm." The deploying institution remains fully accountable regardless of how
autonomous the AI is.
• ❌ "Crypto is allowed in the sandbox if it shows sufficient promise" — WRONG. Crypto
assets, trading/settling in crypto assets, and ICOs are on the explicit negative list and are
not eligible for sandbox testing regardless of promise shown.
PART F: QUICK REVISION SUMMARY
WEEK 4 IN ONE VIEW: THREE FRAMEWORKS FOR GOVERNING FINTECH AND AI
INNOVATION
REGULATORY SANDBOX → Live-test innovations in controlled environment, with or
without regulatory relaxations. 3 principles: responsible innovation, efficiency, consumer
benefit. 3 focus areas (no regulation / need to ease regulation / significant promise).
Negative list: crypto/ICOs excluded. Non-negotiable: KYC/AML + data protection +
security + local storage. 5 stages: Screening (1m) → Assessment (1.5m) → Test Design
(1.5m) → Testing (5m) → Evaluation. 4 completed cohorts. Interoperable Sandbox since
Oct 2022. SRO-FT FRAMEWORK (May 2024) → Industry-led entity: 6 Characteristics
(True Representation, Development-Oriented, Independent, Legitimate Arbiter,
Subscribes to Regulatory Expectations, Repository). Eligibility: Section 8 not-for-profit; no
entity >10%; Rs. 2 crore net worth; robust IT; India-domiciled. Functions: Standard-setting
+ Oversight + Developmental + Grievance Redressal. Responsibilities to RBI: collective
voice, violation notifications, market intelligence, annual reports, book inspection. Status:
1 recognised, 1 returned, 1 under examination. FREE-AI FRAMEWORK (2025) → 7
SUTRAS: Trust | People First | Innovation over Restraint | Fairness & Equity |
Accountability | Understandable by Design | Safety, Resilience, Sustainability. 6 PILLARS:
Innovation Enablement (Infrastructure + Policy + Capacity) + Risk Mitigation (Governance
+ Protection + Assurance). 26 RECOMMENDATIONS. Key: Rec1 (data DPI), Rec2 (AI
sandbox), Rec4 (indigenous models), Rec14 (board AI policy), Rec25 (AI disclosures),
Rec26 (AI toolkit by SRO). THE LOGIC: Sandbox = evidence before regulation. SRO =
industry knowledge at service of regulation. FREE-AI = principles + governance for AI.
Together they operationalise Sankar's 3 principles (encourage innovation + non-disruptive
assimilation + consumer protection) and Malhotra's 5 principles (evidence-based,
consultation, principle-based, proportionality, regular review).
Academic Notes | Module 1 — Week 4 | Primary Sources: RBI Enabling Framework for Regulatory Sandbox
(Updated February 28, 2024) | RBI Framework for Self-Regulatory Organisation(s) in the FinTech Sector (SRO-FT,
May 2024) | RBI FREE-AI Committee Report (2025)