Nepal Rastra Bank has put artificial intelligence on the regulatory map. In December 2025, the central bank's Banks and Financial Institutions Regulation Department released the country's first Artificial Intelligence Guidelines, a document that reaches into every commercial bank, development bank, finance company, microfinance institution and payment firm it licenses. If your institution is already using AI for credit scoring, fraud detection, or customer chat support - or is planning to - this is the framework you now have to work inside.
- Background: why NRB acted now
- Who the guidelines apply to
- The four core objectives
- Governance and board accountability
- Risk management and high-risk classification
- Transparency, explainability and disclosure
- Data privacy and consent
- Fairness and non-discrimination
- Monitoring, incidents and annual reporting
- Common mistakes to avoid
- Readiness self-assessment tool
- FAQs
Quick answer
NRB's Artificial Intelligence Guidelines (December 2025) apply to every NRB-licensed institution - Class A, B, C and D banks and financial institutions, Nepal Infrastructure Bank, and all payment system operators and payment service providers. They do not ban AI. Instead, they require board-approved AI governance, risk classification of AI systems as "high-risk" or "not high-risk," customer disclosure when AI affects a decision, explicit consent and opt-out rights, incident reporting to NRB, and an annual AI activity report using a standard template. The guidelines were first circulated in draft form for stakeholder feedback, so institutions should confirm the current, in-force version and any compliance deadline directly on NRB's official guidelines page before finalising internal policy.
Why NRB introduced an AI guideline
Nepali banks and payment companies were already using AI before any rule existed for it - automated credit scoring, fraud-detection engines running quietly behind card transactions, and chatbots handling customer queries had all crept into daily operations. What was missing was a shared rulebook: nobody had defined what "high-risk" AI use looked like in a Nepali bank, who was accountable when an algorithm made a bad call, or what a customer was owed by way of explanation.
NRB's own background note to the guideline frames the intent plainly: enable financial institutions to use AI for efficiency and better customer experience, while protecting fairness, accountability and financial stability. The guideline follows the announcement made in the Monetary Policy for fiscal year 2024/25 and draws on international frameworks - the EU's risk-tiered approach, the Reserve Bank of India's FREE-AI framework, and Bangladesh Bank's AI Oversight Framework are among the regional precedents cited around the same period.
Who actually has to comply
The scope is broad by design. It is not limited to the large commercial banks - it reaches every tier of NRB-licensed institution, plus the companies that move digital payments.
| Category | Examples | AI use cases typically in scope |
|---|---|---|
| Class A - Commercial Banks | NIC Asia, NABIL, Global IME, and other "A" class banks | Credit scoring, fraud detection, chatbots, AML monitoring |
| Class B - Development Banks | Regional and national development banks | Loan underwriting support, customer service automation |
| Class C - Finance Companies | Licensed finance companies | Risk scoring, collections prioritisation |
| Class D - Microfinance Institutions | Microfinance and rural credit institutions | Alternative credit scoring, field agent tools |
| Nepal Infrastructure Bank Limited | Infrastructure financing | Project risk analytics |
| Payment System Operators (PSOs) | Switches and clearing/settlement operators | Transaction monitoring, anomaly detection |
| Payment Service Providers (PSPs) | Digital wallets and payment apps, e.g. eSewa, Khalti | Fraud detection, onboarding/KYC checks, chat support, personalised offers |
If you run a digital wallet rather than a bank, the obligations look somewhat different in practice - we cover that in detail in our companion article, how NRB's AI rules affect digital wallets like eSewa and Khalti.
The four objectives behind the guideline
1. Enable, don't block
Promote AI adoption that improves efficiency, innovation and customer experience, without compromising financial stability.
2. Protect customers
Ensure AI applications are transparent, explainable, fair and accountable, and that customer rights and data privacy are upheld.
3. Manage risk
Address operational, ethical, systemic, model and cyber risks with adequate governance structures.
4. Widen access
Foster a competitive, inclusive financial sector where AI helps deliver affordable services to underserved segments.
Governance: the board is on the hook
This is the section that changes the most for institutions that have treated AI as an IT project rather than a board-level risk item. NRB is explicit: the board of directors and senior management remain ultimately accountable for the outcomes of an institution's AI systems - not the vendor, not the data science team, not the branch that deployed the tool.
What the board must do
- Define the institution's AI-related risk tolerance within its overall risk management framework.
- Set the strategic direction for AI adoption and approve the AI strategy and governance framework.
- Establish governance structures with clear roles and responsibilities for AI oversight.
What senior management must do
- Keep AI usage aligned with risk appetite, regulatory requirements and strategic goals.
- Continuously monitor how dependent the institution has become on AI systems.
- Oversee day-to-day AI operations, including human oversight, auditability and remediation mechanisms.
Institutions are expected to form a cross-disciplinary AI steering committee - drawing on business, risk, IT, legal, audit and HR - or formally hand this mandate to an existing committee. The resulting AI strategy and governance framework needs board sign-off, and at least one senior manager should carry enough technical grounding to oversee AI-specific risk.
Outsourcing versus internal use
NRB draws a useful line here. Using a third-party AI tool internally - say, to draft documents or summarise reports - is not treated as outsourcing; the institution's own governance and compliance policies simply apply. But when a third party uses AI to deliver a service to the institution's customers - a vendor-run fraud engine or a white-labelled AI chatbot, for instance - that is outsourcing. It requires due diligence, contract terms covering data security and auditability, board approval before signing, and notification to NRB's relevant supervision department.
Risk management: classifying "high-risk" AI
Before any AI system goes live, institutions must assess it against five criteria to decide whether it counts as high-risk. High-risk systems get more resources, more monitoring and more scrutiny.
| Requirement | Not high-risk | High-risk |
|---|---|---|
| Monitoring frequency | Regular reviews | Dedicated monitoring plan, more frequent checks |
| Independent validation | Not required | Recommended third-party validation of outcomes |
| Documentation | Written justification for the classification kept on file | Full documentation of data sources, algorithms and decision logic |
| Resourcing | Standard risk-management process | Institution must allocate sufficient dedicated resources |
Beyond classification, the guideline folds AI risk into existing risk registers - every AI-related risk needs a named owner, a mitigation plan and a monitoring mechanism. Model risk management (development, validation, monitoring, decommissioning), data quality and retention policies, cybersecurity controls aligned with NRB's Cyber Resilience Guidelines, and detection tools for AI-generated synthetic media such as deepfakes are all explicitly called out.
Transparency, explainability and disclosure
Two obligations sit at the centre of this section, and both are directly customer-facing:
- Explainability: AI decision-making must be explainable in terms customers, regulators and auditors can actually understand - not just accurate on paper. AI-generated content must be clearly labelled as such.
- Disclosure: Customers must be told whenever an AI system is used in a decision that affects them, with accessible explanations of how the decision was reached and what factors influenced it.
Institutions are also expected to keep audit trails of AI decision-making, ideally aligned with international benchmarks such as ISO/IEC 42001 for AI management systems, and to retain those records for whatever period NRB specifies.
Data privacy and consent
AI systems must comply with Nepal's Privacy Act, 2075 (2018) alongside the guideline itself. Three practical requirements stand out for compliance teams:
- Data minimisation - collect only what the specific AI application needs, and retain it only as long as required.
- Explicit consent - customer data cannot go into an AI system without their consent.
- Opt-out without penalty - customers must be able to opt out at any time, and doing so cannot result in denial of essential services.
Fairness and non-discrimination
Institutions must proactively test AI systems for bias rather than waiting for complaints to surface it. For high-risk systems, independent third-party validation of outcomes is recommended to confirm decisions are fair, accurate and compliant. The guideline also frames inclusion as a design requirement: AI should not be allowed to widen financial exclusion for marginalised or underserved groups - a meaningful point in a market where alternative-data credit scoring is expanding fast.
Monitoring, incidents and annual reporting
| Incident type | Examples | Reporting requirement |
|---|---|---|
| Critical | Major system failure, data breach, significant algorithmic bias harming customers | Report to NRB's supervision department as it happens, per IT Guidelines 2012 and Cyber Resilience Guidelines 2023 |
| Non-critical | Minor model errors, low-impact technical issues | Document internally; report to NRB on a quarterly basis |
On top of incident reporting, every licensed institution must submit an annual AI activity report using NRB's standardised template, covering the AI systems in use, their applications, risk-management measures and customer outcomes. High-risk systems need comprehensive documentation on file; non-high-risk systems need a clear, retrievable justification for why they were classified that way.
Capacity building and customer grievance handling
Two lighter-touch but easy-to-overlook obligations round out the guideline. Institutions must run training programmes so board members, senior management and relevant staff understand AI risks and evolving regulation - not a one-off session, but an ongoing programme covering everyone involved in overseeing, building, deploying or managing AI systems. And institutions must adapt their grievance-handling processes so customers have a clear route to challenge an AI-driven decision they believe harmed them.
Compliance: the secondary regulations that still apply
The AI Guidelines don't replace existing regulation - they sit on top of it. Institutions must continue complying with:
- Cyber Resilience Guidelines, 2023
- IT Guidelines, 2012
- The Privacy Act, 2075 (2018)
- Any other relevant law or regulation issued by NRB or another regulatory body
Common mistakes banks and financial institutions should avoid
Treating it as an IT-only policy
Without board approval and a named governance structure, the framework doesn't meet NRB's bar - even if the technical controls are solid.
Skipping the risk classification step
Deploying a system before assessing it against the five high-risk criteria leaves no documented basis for its risk tier if NRB asks.
Confusing internal use with outsourcing
Using a vendor's AI to deliver a customer-facing service (not just internal drafting) requires board approval and NRB notification before go-live.
Silent AI use
Not disclosing AI involvement in a customer-affecting decision undermines the transparency requirement, even if the outcome itself was correct.
AI Governance Readiness Self-Assessment
Check the items your institution already has in place. This is an informal planning aid based on the guideline's core requirements - it is not a substitute for a formal compliance review.
Expert tips for getting ahead of enforcement
- Start with an inventory, not a policy document. You cannot classify risk on systems you haven't listed. Catalogue every AI system in production or pilot before drafting governance language.
- Write the customer disclosure first. If you can't explain a decision in plain language to a customer, the underlying model likely isn't explainable enough for NRB either.
- Revisit vendor contracts now. Outsourcing clauses on data security, audit rights and termination are cheaper to renegotiate before an incident than after one.
- Align, don't duplicate. Fold AI risk into your existing risk register and cyber resilience programme rather than building a parallel compliance track.
Frequently asked questions
Conclusion
NRB's AI Guidelines mark Nepal's shift from informal, unregulated AI adoption in finance to a structured, board-accountable framework built around risk classification, transparency and customer protection. For banks and financial institutions, the practical work starts with an honest inventory of every AI system already running, followed by governance, documentation and disclosure built to match. None of this needs to slow AI adoption down - it just needs to be visible, explainable and owned at the board level.
Curious how the same rules play out for digital wallets rather than banks? Read our companion guide: How NRB's AI rules will affect digital wallets like eSewa and Khalti.
Discussion