THE POLICY EDGE
Expert Commentary

18 September 2026

From XBRL to AI: Rethinking India's Financial Supervision

As SEBI and RBI move towards data-driven supervision, India needs to build accountability into systems that determine what regulators see and where they focus

Prem Vaswani is an Assistant Professor at the Institute of Rural Management Anand (IRMA), “Tribhuvan” Sahkari University. 

Listen to the article

Views are personal.

Expert Commentary image

For decades, investors and regulators have relied on quarterly or annual disclosures to assess financial health, often using information that was already months old. Digitisation is changing this model by turning static financial documents into structured, machine-readable data that can be systematically extracted, compared and analysed. Frameworks such as Inline eXtensible Business Reporting Language (iXBRL), which embeds machine-readable information within financial statements, allow individual data points to be classified and processed consistently.

India's regulatory architecture is already responding to this shift. In February 2026, the Securities and Exchange Board of India (SEBI) outlined measures including XBRL filings for financial and non-financial disclosures by listed companies, standardised data definitions and formats across market infrastructure institutions, Unified Distilled File Formats (UDiFF) to improve interoperability, and data-sharing policies for market infrastructure institutions. Together, these measures are creating a more structured and connected base for regulatory analysis.

The significance of this infrastructure extends beyond more efficient filing. It allows supervision to move from reading disclosures largely as individual documents towards analysing financial information systematically across entities, reporting periods and datasets. As this transition advances, regulatory accountability must extend beyond the final supervisory decision to the data, models and analytical signals that increasingly inform it.

From Machine-Readable Data to Supervisory Intelligence

In February 2025, SEBI proposed a framework for digital assurance based on information obtained from external data repositories, extending the sources available for verification beyond conventional financial statements.

Artificial intelligence (AI) and machine learning (ML) can extend these capabilities by analysing large volumes of structured financial information for patterns, anomalies and inconsistencies across datasets.

For supervision, the important change is not simply that more information can be analysed, but that analytical systems can influence what receives regulatory attention. AI need not make the final regulatory decision to affect regulatory judgement. By determining which transactions, entities or risks are flagged and prioritised, such systems can shape where supervisors look and what they investigate.

This distinction matters. Automation of regulatory attention can be consequential even without automation of regulatory decisions.

When Algorithms Shape Regulatory Judgement

Opacity becomes particularly consequential when an algorithmic signal contributes to regulatory scrutiny or enforcement. Deep-learning systems can function as "black boxes", making it difficult for a human reviewer to trace how a particular conclusion or risk flag was generated. Regulators must therefore be able to establish what information informed an assessment, how the signal was generated and how it contributed to subsequent supervisory action.

Automated analysis is also only as reliable as the data on which it operates. Errors, biases or gaps in historical data can influence the patterns identified by AI systems, potentially producing false alarms or distorted assessments. Where such outputs influence scrutiny or enforcement, responsibility for assessing their reliability must remain institutionally clear.

On 8 January 2026, SEBI constituted a working group to develop five-year and ten-year technology roadmaps for market infrastructure institutions, covering technologies including AI/ML, Supervisory Technology (SupTech) and Regulatory Technology (RegTech). SEBI has also described its oversight as increasingly continuous and technology-led, supported by more than 300 SupTech alerts for real-time compliance monitoring.

The Reserve Bank of India (RBI) is pursuing a related approach in banking supervision. Its May 2025 Annual Report notes that its Advanced Supervisory Analytics Group had developed AI/ML-based models for microdata analytics, governance assessment, social-media monitoring, fraud vulnerability, borrower vulnerability and asset-quality prediction.

These developments make model governance a present institutional question rather than one to be addressed only after AI becomes deeply embedded in supervision. Rules governing the validation, use and accountability of these systems therefore need to develop alongside their adoption.

Building Accountability into Regulatory Architecture

Accountability needs to operate across three connected layers: the data used for supervision, the models that analyse them and the regulatory decisions informed by their outputs.

At the data layer, interoperability should move beyond standardising individual datasets towards an architecture that allows relevant supervisory information across regulatory systems to be linked, compared and analysed without creating duplicative reporting requirements. Regulators will also need clear requirements for data provenance, validation and lineage so that significant findings can be traced to their underlying evidence.

At the model layer, AI systems used for supervision should be subject to documented validation, performance monitoring and periodic independent review, particularly where their outputs influence consequential regulatory decisions. Validation cannot be confined to the point when a model is introduced: performance can change as underlying data, market behaviour and the contexts in which models are applied evolve.

At the decision layer, clear thresholds should determine when model-generated alerts require human review, when they can trigger further investigation and when regulatory action requires independent judgement. Supervisors should also be able to override model outputs, with the reasons recorded where those outputs materially influence regulatory decisions.

The three layers cannot be governed independently. Reliable models cannot compensate for poor or incomplete underlying data, while technically robust models cannot substitute for clear institutional responsibility over regulatory decisions.

The question is therefore no longer whether technology will become part of financial supervision; SEBI and RBI are already building that architecture. The question is whether the governance of supervisory data and models will develop as deliberately as the technology itself. As algorithms acquire greater influence over what regulators investigate, accountability must extend upstream – from regulatory action to the data, models and signals that helped direct it.


Rethinking Public Policy Through Insight | Inquiry | Impact

Opinion • Grassroots Voices • Policymakers Perspectives • Expert Analysis • Policy Briefs