Briefing · Regulation
SEBI Regulation 16C: what “solely responsible” means in practice
The liability for your AI outputs sits with you, whoever built the system. Here is what that actually requires on a Tuesday morning.
- Author
- Meera Krishnan, Director, Assurance
- Published
- 12 August 2026
- Reading time
- 9 min read
What the regulation actually says
SEBI Regulation 16C makes a regulated entity solely responsible for the outputs of the AI systems it uses, regardless of whether the system was built in-house, bought from a fintech, or embedded in a platform it rents. Responsibility for outcomes cannot be contracted away, delegated to a vendor, or disclaimed in a terms-of-service document.
The instinct in most organisations is to treat this as a legal problem. It is an operational one. Legal can tell you that you are liable; only operations can tell you what you are liable for.
Four things “solely responsible” means on a Tuesday
First, an inventory. You cannot be responsible for systems you cannot list. In our assurance work, organisations typically declare three or four AI systems and turn out to run between twenty and forty, once departmental SaaS, browser extensions and personal LLM accounts are counted.
Second, documentation. Every decision-affecting system needs a documented feature list, a known data lineage, and a record of who approved it for production. If the vendor holds the model and you hold the liability, the documentation clause in that contract is now the most important page in it.
Third, monitoring. A credit or scoring model in production needs performance measured against a baseline, on a cadence, with drift thresholds that trigger review. “The vendor monitors it” is not monitoring; it is an assumption about monitoring.
Fourth, auditability. If a regulator asks why a specific customer received a specific decision, you need to be able to reconstruct it. That means logging inputs, outputs and model versions, which most vendor contracts never obliged anyone to keep.
Where the exposure actually sits
The pattern we see most often in financial services: a scoring or collections system built by a fintech partner, where the partner holds the model, you hold the regulatory exposure, and the contract contains no feature documentation, no audit right, and no exit-data clause. The second most common: a customer-facing assistant in production that has never been measured against the human baseline it replaced, and has never been adversarially tested at all.
The next thirty days
Build the inventory, including shadow AI. Pull every AI-touching vendor contract and mark the ones missing documentation, audit and exit clauses. Measure your customer-facing systems against the human baseline. Name an owner for each system. That is not compliance complete, but it is the difference between answering a regulator's letter and receiving it in silence.
Sources
- SEBI circulars and master circulars
- RBI FREE-AI framework report, 2025
- 72 Networks Assurance engagement records, 2025-26