Operating models built around agent-executed, human-supervised decisions.
Policy enforced at the point of decision, not after the fact.
Every category in this guide depends on one underlying question: who is accountable when an agent makes a decision? Governance & Next-Gen Operating Models is the EASE 9.0 category that measures whether a bank has answered this deliberately, rather than by default.
A traditional operating model assigns accountability to a named individual at each step: a credit officer signs an approval, a compliance officer signs a policy exception, a committee signs a large sanction. When an agent makes those decisions, the operating model has to define, explicitly, what a human is now accountable for.
A bank that automates without answering who is accountable has not reduced risk. It has relocated that risk to a system no one owns.
This is not an abstract governance philosophy a bank has to invent from scratch. In August 2025, an RBI-appointed committee chaired by Prof. Pushpak Bhattacharyya of IIT Bombay published the Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI), setting out seven guiding principles ("Sutras") and 26 specific recommendations across six strategic pillars, applying to every RBI-regulated entity: banks, NBFCs, payment operators, and fintechs alike. The committee's own survey found roughly one in five regulated entities already deploying AI in customer support, sales, underwriting, or cybersecurity at the time of the report. That means the framework was written to govern capability that was already live, not to pre-empt a future rollout. A PSU bank building its accountability matrix and escalation ladder against FREE-AI's actual recommendations, rather than a generic governance template, is answering the specific question its own regulator has already posed.
Source: Reserve Bank of India, Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI), August 2025; independent summaries by Dvara Research and KPMG.
This category does not have a revenue figure attached, and manufacturing one would misrepresent what it actually delivers: regulatory and examiner confidence, and a materially lower tail-risk profile when something does go wrong. What that risk costs in practice is not hypothetical. In an order dated March 23, 2026, following supervisory inspection of financial position as of March 31, 2025, RBI fined three PSU banks for lapses that continuous, agent-enforced governance is built to close. Union Bank of India was fined ₹95.40 lakh, partly for manual intervention in system-based asset classification on certain Kisan Credit Card accounts — a human overriding what should have been an automated, policy-bound decision, the precise failure mode this category exists to remove. Central Bank of India was fined ₹63.60 lakh for KYC and financial-inclusion-norm lapses. Bank of India was fined ₹58.50 lakh for priority-sector-lending and deposit-interest non-compliance. All three penalties trace back to the same root cause: a manual process running without the continuous, sampled audit trail a Compliance Agent is built to generate. That is what this category actually buys — not a guarantee against every failure, but a standing, continuously checked record that catches this shared failure mode before an examiner has to reconstruct it months later.
Source: RBI order dated March 23, 2026, as reported by Angel One, “RBI Imposes Monetary Penalties on Union Bank, Bank of India, and Central Bank of India” (30 Mar 2026).
This category has its own dedicated agent, rather than a policy layered on top of the others: the Compliance Agent runs continuous monitoring, generates regulatory reporting, and verifies consent status; it perceives every decision every other agent makes, checks it against policy, and either clears it or escalates it. Consent verification and in-country data residency are enforced by the same Inform layer that logs every other agent's decisions, not a separate compliance system reconciled against decisioning records after the fact.
So this is not the meta-category that "doesn't run agents of its own" — it runs the one agent whose entire job is watching the others.
In practice, this means a governance committee that reviews agent-decision audit samples on a regular cadence rather than relying solely on an annual policy document; a named data-and-model owner accountable for agent drift, distinct from the business owner accountable for the decisions the agent makes; and an escalation matrix that specifies, for every category of exception, exactly which role reviews it and within what timeframe.
Putting a Compliance Agent in charge of watching every other agent invites an old question in a new form. Who watches the watcher, and if the agent responsible for catching drift has its own blind spot, hasn't the bank simply concentrated risk in one place instead of distributing it across desks the way the old model did?
The Compliance Agent is not designed to be the final word; it is designed to make the human final word tractable. FREE-AI's own recommendations require a named data-and-model owner accountable for agent drift, distinct from the business owner accountable for outcomes; a human, not the agent, still owns the answer when something goes wrong. What the Compliance Agent changes is what that human reviews: a continuous, sampled audit trail generated as decisions happen, instead of a forensic reconstruction weeks after a problem surfaces. The watcher does not replace the human accountable for watching it; it is what makes that human's oversight actually keep pace with decisions made in milliseconds.
Every operating model in this category is ultimately answering one question: does a bank find out about a governance gap from its own continuous audit trail, or does it find out the way three PSU banks did in March 2026, from an RBI order issued months after the inspection that caught it. A Compliance Agent is built to produce that answer in real time, for the decisions running through it, rather than months later in an enforcement order. The harder test for this category, over the next examination cycle, is not whether agents make good decisions; it is how many of a bank's remaining processes still cannot answer the question at all.