If you run a business in Nepal that touches a bank, a microfinance institution, a payment app, or a digital wallet, a new rulebook now shapes how that institution can use artificial intelligence when it deals with you. In December 2025, Nepal Rastra Bank's Banks and Financial Institutions Regulation Department issued the country's first dedicated Artificial Intelligence Guidelines, following up on a commitment made in the Monetary Policy for fiscal year 2024/25 and a public consultation with banks, fintech firms and technology experts.
This is not a footnote. It changes how loan approvals, fraud alerts, chatbot conversations and credit decisions involving AI must be governed, explained and reported inside every NRB-licensed institution. This guide breaks down what the guidelines actually require, in plain language, and what it means for the businesses and customers who interact with these institutions every day.
In this article
Quick answer: NRB's AI Guidelines (issued December 2025) apply to all NRB-licensed institutions — commercial banks, development banks, finance companies, microfinance institutions, Nepal Infrastructure Bank, and payment system operators/providers. They do not ban AI. They require board-approved AI governance, risk classification of every AI system, customer disclosure whenever AI affects a decision about them, bias testing, data-privacy compliance under the Privacy Act 2075, and incident reporting to NRB.
What NRB actually published
Nepal Rastra Bank first circulated a draft of the Artificial Intelligence Guidelines in early December 2025 for public comment, inviting feedback from banks, researchers, technologists and the general public. After the comment window closed, NRB's Banks and Financial Institutions Regulation Department issued the guidelines as formal regulatory guidance. The document sets out how AI should be governed, tested, monitored and disclosed across Nepal's financial sector, and it explicitly references the Cyber Resilience Guidelines 2023, the IT Guidelines 2012, and the Privacy Act 2075 as guidelines that AI use must continue to comply with.
The guidelines were shaped by looking at how neighbouring regulators are approaching the same problem: the Reserve Bank of India's Framework for Responsible and Ethical Enablement of AI, the State Bank of Pakistan's AI Guidelines for Financial Services, and Bangladesh Bank's AI Oversight Framework all informed the drafting process, giving Nepal's version a distinctly South Asian, risk-based flavor rather than a heavier, EU-style rulebook.
Why it matters beyond banking: Even if your business is not a licensed financial institution, if you provide chatbots, credit-scoring tools, fraud-detection software or AI vendor services to a bank or payment company, that institution's compliance obligations flow through to how it can use your product. Vendors should expect new due-diligence questions.
The five operational pillars of NRB's Artificial Intelligence Guidelines, all ultimately reporting into ongoing NRB monitoring and compliance.
Who the guidelines cover
The scope is broad by design. The guidelines apply to every institution NRB licenses, and to a wide range of AI use cases within them:
Institutions covered
Commercial banks (Class A), development banks (Class B), finance companies (Class C), microfinance institutions (Class D), Nepal Infrastructure Bank Limited, and all payment system operators and payment service providers.
Use cases covered
Credit scoring, fraud detection, customer service (including chatbots), risk management, and compliance monitoring — plus "including but not limited to," meaning the list is illustrative, not exhaustive.
Two nuances matter for anyone building or selling AI tools into this market. First, using a third-party AI tool purely for internal work — drafting documents, summarising reports, analysing data — is treated differently from outsourcing an AI-powered customer-facing service. Second, the guidelines draw a hard line around "high-risk" systems, which face materially stricter expectations than everyday internal tools.
The five pillars of the framework
Rather than a single blanket rule, NRB structured its guidance around five connected obligations that licensed institutions must build into how they design, deploy and monitor AI.
1. Governance and accountability
The board of directors and senior management are explicitly named as ultimately accountable for AI outcomes — not the IT department, not the vendor. Institutions must set up a cross-disciplinary AI steering committee covering business, risk, IT, legal, audit and HR, and the resulting AI strategy and governance framework must be approved by the board.
2. Risk management
Every AI system must be assessed before launch to decide whether it is "high-risk." High-risk systems need dedicated resources, more frequent monitoring, and — where appropriate — independent third-party validation. The guidelines also specifically call out AI-generated synthetic media (deepfakes), requiring institutions to deploy detection tools and educate both staff and customers.
3. Transparency and explainability
AI-generated content must be clearly labeled. Customers must be told whenever an AI system is used in a decision that affects them, and institutions must be able to explain — in plain terms — the factors behind that decision. Audit trails of AI decisions must be kept, ideally aligned to the international ISO/IEC 42001 AI management standard.
4. Data privacy and protection
AI use must comply with Nepal's Privacy Act 2075 (2018). The guidelines require data minimization (collecting only what's needed), explicit customer consent before personal data feeds an AI system, and a genuine opt-out that does not cut a customer off from essential services.
5. Fairness and non-discrimination
Institutions must proactively test AI systems for bias and take steps to keep AI from excluding or disadvantaging any group — including efforts to make sure AI actually expands access to financial services for underserved populations rather than narrowing it.
How "high-risk" AI is classified
This is the part of the guidelines with the most day-to-day teeth. Before deployment, every AI-enabled system must be screened against five criteria. If it matches enough of these, it is classified high-risk and subject to tighter controls, more frequent monitoring, and possible third-party validation.
| Criterion | What NRB is asking |
|---|---|
| Serious harm | Could the system cause significant financial loss, legal liability, or denial of an essential service? |
| Broad impact | Is it deployed at large scale, raising the chance of a systemic problem across institutions? |
| Minimal human oversight | Does it operate with limited human supervision, raising the risk of unchecked errors? |
| Rights risk | Could it affect privacy, fairness, non-discrimination or equality? |
| Sensitive data use | Does it process biometric data or large volumes of personal/financial data? |
Self-check: is your AI system high-risk?
This quick, private checklist mirrors NRB's own five criteria. It is a screening aid, not a compliance certificate — final classification decisions and documentation must follow your institution's own risk-assessment process.
High-Risk AI Self-Check
Tick every statement that applies to the AI system you are evaluating.
What this means if you are a business, not a bank
Most readers of a business or fintech-focused blog are not NRB-licensed institutions themselves, but they interact with the guidelines indirectly in three common ways.
You use bank or wallet-linked AI tools
If a bank or payment app declines your loan, flags a transaction, or routes you to a chatbot, the guidelines now require the institution to disclose that AI was involved and to be able to explain the reasoning if you ask. You have a stronger basis to request an explanation and to raise a grievance than before.
You sell software or AI services to a financial institution
Expect new vendor due-diligence steps: audit-rights clauses, data-usage limits, board approval before outsourcing, and a notification to NRB's relevant supervision department. Institutions are now required to treat this as a formal outsourcing decision rather than a routine procurement.
You are a fintech applying for a license or partnership
An AI governance framework, a documented risk classification process, and evidence of bias testing are increasingly likely to appear in due-diligence checklists for partnerships, investment, and licensing conversations with banks and payment operators.
Common mistake to avoid: Treating "we use an off-the-shelf AI chatbot, so the rules don't apply to us" as a safe assumption. The guidelines classify internal use of third-party AI tools differently from outsourced AI services — but both still require documented governance, and outsourced customer-facing AI services need board approval and an NRB notification before launch.
Common misconceptions
- "NRB has banned AI in banking." No — the stated objective is to promote responsible AI adoption, not to restrict it. The guidelines exist to make adoption safer, not to prevent it.
- "Only large banks need to comply." The scope covers Class A, B, C and D institutions plus payment operators of every size. A small microfinance institution using a basic scoring tool is still in scope.
- "This is just a recommendation, not a rule." The document uses "required" and "must" language throughout its governance, risk, transparency, privacy and reporting sections — this is regulatory guidance issued by NRB's regulation department, not a voluntary code.
- "AI incident reporting only covers major breaches." Institutions must report both critical incidents and non-critical issues (minor model errors, small technical glitches) — non-critical items go to NRB on a quarterly basis rather than immediately.
Expert tip: If you are advising or working with an NRB-licensed institution, ask specifically whether a given AI use case has been through the five-criteria high-risk screening and whether that classification is documented. This single question tends to reveal how far along an institution's AI governance actually is.
Frequently asked questions
When did NRB's AI Guidelines take effect?
NRB circulated a public draft in early December 2025 and issued the guidelines through its Banks and Financial Institutions Regulation Department after the consultation period. Because implementation timelines and any further updates can evolve, licensed institutions and their vendors should check NRB's official website for the current circular and any transitional deadlines.
Do the guidelines apply to fintech startups that are not yet licensed?
The guidelines directly bind NRB-licensed institutions. An unlicensed fintech is not directly regulated by this document, but if it partners with, is acquired by, or seeks a license from a covered institution, it will likely be expected to demonstrate compatible AI governance during due diligence.
Can a customer opt out of AI-driven decisions?
The guidelines require institutions to obtain explicit consent before using customer data in AI systems and to provide a clear opt-out that does not result in denial of essential services. In practice, how a specific opt-out works will vary by institution and product.
What happens if an institution does not comply?
The guidelines are issued as regulatory guidance by NRB and list compliance with related regulations (Cyber Resilience Guidelines 2023, IT Guidelines 2012, Privacy Act 2075) as a requirement. The document itself focuses on governance, reporting, and risk-management obligations rather than spelling out a specific penalty schedule; enforcement follows NRB's general supervisory powers over licensed institutions.
Does this cover AI chatbots used only for FAQs, not decisions?
Yes — customer service is explicitly listed as a covered use case. Even a simple FAQ chatbot needs to be catalogued, and AI-generated content it produces must be clearly labeled as such.
Want the fintech-specific breakdown — outsourcing rules, sandbox interplay, and what payment providers should do first?
Read: How NRB's AI Guidelines Affect Banks and Fintech Firms →This article summarizes NRB's published Artificial Intelligence Guidelines (Banks and Financial Institutions Regulation Department, December 2025) for general awareness. It is not legal or regulatory advice. Licensed institutions should refer to the official document on nrb.org.np and consult their compliance and legal teams for implementation decisions.
Discussion