RBI FREE-AI · NIST AI RMF · EU AI Act · ISO/IEC 42001

Governance you can read like a schematic.

SentRAI is a self-hosted AI governance console for financial services. It finds the models hiding in your code, scores each one against India's RBI FREE-AI framework, the US NIST AI Risk Management Framework, the EU AI Act, and ISO/IEC 42001, monitors them for drift, and maintains the evidence trail your next audit will ask for.

ORG ESTATE REPOSITORIES MODELS + DATASETS PRODUCTION STAGED
FIG 1.0Governance Graph
STYLEBlueprint plate
SOURCELive scan
REV1.0
Estate → repositories → AI artifacts → deployments. Emphasis is carried by stroke weight (white = production); state by pattern (dashed = staged) — never by extra colour.
4
Frameworks, one scan
FREE-AI · NIST · EU AI Act · ISO 42001
3
Jurisdictions covered
India · United States · European Union
7
Principles enforced
from ownership to human oversight
100%
Actions audit-logged
every mutating action, PII-masked
Regulatory coverage

Four frameworks, one model inventory, zero duplicate work.

Wherever you operate — or plan to — the rules differ, but the questions are the same: what AI are you running, who owns it, is it fair, can you explain it, and can you prove all of that? SentRAI answers once and maps the answer to each regulator's language. Exact control counts are published on the coverage disclosure.

IN

India

RBI FREE-AI + DPDP Act

The Reserve Bank of India's 2025 Framework for Responsible and Ethical Enablement of AI: seven guiding principles (Sutras), six pillars, and 26 recommendations for banks, NBFCs, and fintechs. India's DPDP Act adds strict personal-data rules.

SentRAI validates all seven Sutras on every model plus the Governance, Protection, and Assurance recommendations (14, 16, 20, 24), with DPDP-aligned PII masking across the entire console — the deepest of the four frameworks.

US

United States

NIST AI RMF 1.0

The de-facto US standard for AI risk management, organised into four functions — Govern, Map, Measure, Manage — and referenced by US regulators and enterprise procurement alike.

SentRAI validates fourteen controls across all four functions — ownership, board policy and audit cadence; documented purpose, context and provenance; red-team recency and live drift measurement; oversight gates, fallback plans, resourced owners, ledger-tracked risks, and incident hygiene.

EU

European Union

EU AI Act

The world's first comprehensive AI law. Obligations scale with risk tier, and financial-sector uses like credit scoring sit squarely in the high-risk category — with duties for documentation, oversight, and robustness.

SentRAI validates each model's risk classification plus fourteen articles: the core high-risk obligations (Articles 9–15, 17), value-chain and deployer duties (25, 26, 27), post-market monitoring (72), and the Article 50 transparency duty.

INT

International

ISO/IEC 42001

The management-system standard for AI — think ISO 27001, but for how your organisation governs models. Increasingly requested in vendor due-diligence and cross-border deals.

SentRAI validates eight management-system checks spanning clauses 6, 7, 8, 9 and 10 plus Annex A documentation — a living inventory, accountable ownership, risk treatment, incident records, and continuous monitoring.

How it works

Governance that starts where your AI actually lives: the code.

Most governance tools begin with a spreadsheet someone forgot to update. SentRAI begins with a scan of your repositories and infrastructure, so the model inventory reflects reality — then keeps it honest for the model's entire life.

01 · DISCOVER

Find every model

Regex + AST scanning over local code, GitHub repos, and Kubernetes/Triton infrastructure surfaces AI systems you didn't know you were running.

02 · REGISTER

Build the inventory

Every model gets an owner, a risk tier, a purpose, and a ledger entry — scoped per project, with lineage tracked across systems.

03 · VALIDATE

Close the gaps

Automated validators score each model against all four frameworks in one pass — and tell you exactly which artifact or control is missing.

04 · MONITOR

Catch drift early

Your serving layer pushes score windows to the API; an hourly job runs PSI + Wasserstein checks, trips a persistent circuit breaker, and fires a human-review webhook.

05 · AUDIT

Prove it

Immutable audit trails, incident SLAs, and one-click PDF compliance reports — regulator-ready evidence, not screenshots of dashboards.

Responsible AI, operationalised

Seven principles every framework agrees on — enforced, not framed.

Strip away the acronyms and every serious AI regulation asks for the same seven things. India's FREE-AI calls them Sutras; NIST spreads them across four functions; the EU AI Act writes them into articles. SentRAI enforces each one with a concrete mechanism.

1Accountability & clear ownership

IN · Sutra 5US · GovernEU · Art. 16INT · ISO 42001
Enforced by: no model can be promoted to a live stage without a named owner, a board policy reference, and a risk tier — the API refuses the promotion and lists exactly what's missing. Incidents carry SLA clocks tracked to closure.

2Human oversight

IN · Sutra 2US · ManageEU · Art. 14INT · ISO 42001
Enforced by: when drift crosses the alert threshold, a circuit breaker trips and persists (a restart can't reset it), a mandatory human-review ticket is issued, and your serving layer is notified by webhook to engage the rules fallback.

3Fairness & non-discrimination

IN · Sutra 4US · MeasureEU · Art. 10INT · ISO 42001
Enforced by: MEDIUM/HIGH-risk models must carry an attached bias-test report as an evidence artifact — a self-declared checkbox does not pass. Validators score exactly which evidence you still owe.

4Transparency & explainability

IN · Sutra 6US · MapEU · Art. 13INT · ISO 42001
Enforced by: every inventory entry records the model's purpose, training data, and explainability evidence — so anyone can answer "what does this model do and why?"

5Safety, security & robustness

IN · Sutra 7US · Measure + ManageEU · Art. 15INT · ISO 42001
Enforced by: hourly PSI + Wasserstein drift evaluation over ingested score windows, configurable warning/alert thresholds, and a persistent business-continuity breaker for hard failures.

6Privacy & data protection

IN · DPDP 2023US · privacy-enhancedEU · GDPR-alignedINT · ISO 42001
Enforced by: automatic PII masking (India DPDP + GDPR patterns, credentials included) on every audit event, ledger entry, and notification — plus a fully self-hosted architecture, so model metadata never leaves your jurisdiction.

7Auditability & documented trust

IN · Sutra 1US · GovernEU · Art. 12INT · ISO 42001
Enforced by: an append-only ledger plus a global audit-event stream covering every mutating action — even an admin purge leaves the model's full history and a tombstone behind. Exportable as one-click PDF evidence packs.
Under the hood

Serious machinery for a serious mandate.

SentRAI is a self-hostable console — your model metadata never has to leave your infrastructure.

Discovery

Code-level discovery

Regex plus tree-sitter AST analysis finds model definitions in real source, not self-reported forms. Scans local paths, GitHub, and k8s/Triton serving infra.

Validators

Pluggable validators

Framework checks are plugins with a shared registry — run FREE-AI, NIST AI RMF, EU AI Act, and ISO 42001 in one pass, or add your own internal policy as a fifth.

Monitoring

Statistical drift detection

Push score windows to /monitoring/scores; an hourly job computes Population Stability Index and 1-D Wasserstein distance against the reference window, with configurable thresholds.

Privacy

Privacy-preserving by default

PII masking with India DPDP and GDPR patterns (PAN, Aadhaar, emails, IBANs, credentials) automatically applied to audit events, ledger entries, and outbound notifications.

Evidence

Regulator-ready exports

One-click PDF compliance reports per model, immutable audit trails, and incident histories with SLA status — evidence in the format audits actually want.

Integration

Fits your stack

JWT auth with role-based access, Prometheus /metrics, outbound webhooks for breaker trips and overdue incidents, optional Neo4j lineage, daily re-scans, and a full REST API.

Responsible AI is a practice, not a promise.

Scan your first repository and see your real model inventory in under ten minutes.