BFSI
Banking, NBFCs, Insurance & Capital Markets
You carry the liability. Even when someone else built the model.
SEBI Regulation 16C is explicit about this. So is every conversation your CRO has had in the last six months.
What we see most often
A credit or scoring model built by a fintech partner, where the partner holds the model and you hold the regulatory exposure, with no documented feature list and no performance monitoring.
A collections or service bot live in production that nobody has measured against the human baseline.
Customer-facing assistants with no input sanitisation, tested by us and found to leak across accounts.
Vendor contracts with no model documentation, no exit-data clause, and no right to audit.
Governance assessment first, almost always.
It surfaces the exposure, it produces a board artefact, and it tells us which build work is actually worth doing. In a regulated entity, deploying more AI before you can defend the AI you have is not bold. It is unpriced risk.
Questions we get asked
- Who handles DPDP compliance for NBFCs?
- 72 Networks runs DPDP gap assessments and AI governance engagements for NBFCs, banks, insurers and capital-market entities. Six to ten weeks, ending in a board-ready assurance report mapped to DPDP, SEBI 16C, RBI FREE-AI and IRDAI expectations.
- Can we outsource AI model risk to our fintech vendor?
- No. SEBI Regulation 16C makes the regulated entity solely responsible for AI outputs regardless of who built the system. Vendor contracts can add documentation, audit and exit rights, but the liability stays with you.