Does the AI agent comply with RBI outsourcing and cybersecurity guidelines?
Yes. We design agents against the RBI Cybersecurity Framework for Banks and the RBI Master Directions on outsourcing of IT services. That means documented service description, sub-contracting disclosure, right-to-audit clauses, data residency inside India, log retention as per regulator norms and a defined exit plan. For NBFCs we also cover the RBI IT Governance direction issued for NBFCs.
Where is customer data stored and processed?
By default all customer PII and financial data stays inside India. Deployment options are (1) your own VPC on AWS Mumbai, Azure India or GCP Mumbai, (2) on-prem inside your data centre for tier-1 banks, (3) hybrid where retrieval and PII stay on-prem and only redacted prompts hit a zero-data-retention LLM endpoint. We help you map this to your DPDP Act 2023 record of processing.
Can regulators audit how the AI made a decision?
Yes. Every agent action writes an immutable audit record with the input, the retrieved context, the prompt, the model version, the model output, the human reviewer (if any) and the final action. Auditors and internal risk teams get a read-only console. For RBI or SEBI inspections you can replay any decision from the last 7 years, matching your existing record retention policy.
When is a human reviewer mandatory in the loop?
For anything the regulator treats as a decision that affects a customer's rights or money, a human approves before the action goes out. That covers loan approval or rejection, KYC rejection, claim repudiation, SAR filing, and any customer communication that carries a regulatory consequence. The agent drafts, scores and routes. A licensed officer signs. This is not just good practice, it is how we keep you defensible under RBI Fair Practices Code and IRDAI grievance rules.
How do you handle model hallucinations in a regulated setting?
Three layers. First, retrieval is grounded on your own policies, circulars and product terms, and every response carries citations back to the source clause. Second, we run continuous regression tests on a golden set of scenarios that must produce the same answer across model versions. Third, output goes through a rules layer that hard-blocks known unsafe patterns (fabricated interest rates, invented policy numbers, unsupported claim decisions). If confidence drops below threshold, the agent hands off to a human.
Does it work with Account Aggregator and DEPA consent flows?
Yes. For lending and wealth workflows we integrate with the RBI Account Aggregator ecosystem (Setu, Finvu, OneMoney) and honour the DEPA consent artefact. Data pull is scope-bound and time-bound per the consent. The agent cannot request data beyond what the consent allows. Audit records store the consent handle alongside every downstream action.
How much does an AI agent project cost for a BFSI client?
Pilot ₹2 to 4 lakh for one agent, one workflow, one integration, 3 to 4 weeks. Full multi-agent build ₹8 to 25 lakh depending on integrations, compliance scope and audit console requirements, 6 to 10 weeks. Managed operations from ₹60,000 per month covering model API costs, prompt regression, circular monitoring feed and audit retention. BFSI runs slightly higher than SaaS because of compliance review, penetration testing and audit trail work.
Which LLMs do you use for BFSI workloads?
We are model-agnostic. In practice we use Anthropic Claude and OpenAI GPT via zero-data-retention endpoints for most drafting and reasoning, and open weights (Llama, Mistral, Sarvam for Indic languages) when the client needs full on-prem. For OCR heavy KYC we combine AWS Textract or Azure Document Intelligence with an LLM verification pass. Choice is a compliance and cost decision, not a religious one.