# The director's ledger: ten questions, and the record each answer must cite

**The Operator's Map · GFF 2026 Special · 11 September 2026 · The AI Boardroom**
Companion artifact to *"The model said so" is not an answer* — https://vikramjha.work/writing/the-model-said-so-is-not-an-answer

One page for a meeting, not a framework. Each question names the record that answers it, the instrument that asks for that record, and what a non-answer sounds like. A non-answer is almost never silence; it is a sentence that sounds like an answer and cites no record.

Every anchor below is a document fetched from its issuer on 11 September 2026 and listed in the chapter's Sources block. "Draft" means the RBI's draft Guidance on Regulatory Principles for Model Risk Management (rbi.org.in, Id 5089), a draft on that date. "Committee" means the RBI's FREE-AI Committee report of 13 August 2025 (rbi.org.in, ID 1306), a set of recommendations, never a rule. "16C" means Regulation 16C of the SEBI (Intermediaries) Regulations, in force since 10 February 2025. "IRDAI ToR" means the terms of reference in IRDAI office order IRDAI/GA&HR/ORD/MISC/90/06/2026 of 17 June 2026. "DG" means the RBI Deputy Governor's address of 9 September 2026 (Id 1577); "Governor" means the RBI Governor's keynote of 10 September 2026 (Id 1578). One anchor is marked "as reported": it is an outlet's account of a panel remark and carries no instrument's weight.

| # | The question | The record that answers it | The instrument that asks for that record | What a non-answer sounds like |
|---|---|---|---|---|
| 1 | Which of our systems can *act* (pay, file, send, close, approve) rather than recommend, and is every one of them on the inventory? | The model inventory, with an "acts / recommends" column | Draft para 21 ("no model is used, relied upon, or deployed unless it is part of inventory"); draft para 52 ("the level of autonomy placed on the model outputs"); IRDAI ToR III (inventory of AI systems); Committee Rec 23 ("all models, use cases, target groups, dependencies, risks and grievances") and 4.4.49 ("clearly define the tasks AI can perform autonomously") | "Everything customer-facing goes through the model risk process." |
| 2 | For each acting system, who approved its deployment, on what date, and where is the rationale written? | The approval record, with rationale | Draft para 35 ("the rationale for decision / approval"); draft para 12(1) (the board risk committee reviews validation reports of high-tier models "and approve their deployment") | "It went through the architecture review board." |
| 3 | What is the largest action it can take unaided, and where is that limit enforced: in the model, or outside it? | The permission and limit record (the Ship AI chapter's slot — https://vikramjha.work/writing/the-agent-gets-a-slot-not-a-button) | Draft para 60(ii) ("override, suspension, or deactivation mechanisms"); DG para 29 (the proportionality sentence, quoted in the Ship AI chapter) | "There are guardrails in the prompt." |
| 4 | When it acted last quarter, which record shows the authority for each action and the consequence that followed? | The authority-and-consequence record (artifact B) | DG para 21 ("An institution may outsource the computation, but it cannot outsource the consequence"); draft para 63 ("decisions, interventions, overrides, incidents and near misses"); Committee 4.4.48 ("formally recorded and reported") | "We have full logging." |
| 5 | Who can stop it, how fast, and when was that last tried? | The kill-switch record, with a measured time | Draft para 60(ii) ("kill-switch arrangements"); Committee 4.4.74 ("mechanisms exist to stop, pause or unwind AI-driven processes in a controlled manner"); as reported, MediaNama: the SEBI Chairman on "a stop mechanism" | "Ops can disable the integration." |
| 6 | For every vendor component, what can the vendor change without our approval, and what did we not receive? | The third-party scope record | Draft para 53 ("provider-driven updates"; "limitations in independent validation"); draft para 56 ("a clear scope of what can be updated automatically"); DG para 28 ("responsibility for managing risk does not disappear because a model or technology is supplied by a third party"); 16C(1) ("procured from third-party technology service providers"); Committee 4.4.68 "Dependencies:" | "It's covered in the MSA." |
| 7 | When was it last independently validated, and on what date did the validation report reach the board's risk committee? | The validation report and the committee date | Draft para 29 (independent validation of all models, including third-party); draft para 33 ("within three months of completion of the validation") | "Validation is continuous." |
| 8 | What explainability threshold did we set for it, and is it higher because the decision is material? | The explainability-threshold record | Draft para 54(1)(i) ("higher thresholds for explainability to models which are relied upon for material decision-making"); Governor para 17 ("opacity") | "The vendor provides explanations." |
| 9 | Does the customer know they are dealing with a system, and can they reach a person? | The disclosure and hand-off record | Draft para 59(ii) (disclosure that they are interacting with an AI system) and 59(iii) ("option should be provided to the customer to switch to human assistance"); DG para 36 ("They will, however, experience the outcome.") | "It's in the terms of service." |
| 10 | Which of the answers to 1–9 would we hand to a supervisor unedited, and which instrument, today, tells us the format? | The answers themselves | 16C(1)(b) (liability, no format); Governor para 32 ("the draft framework on Model Risk Management"); the RBI drafts listing, 11 September 2026 (still a draft); Committee Sutra 5 ("Accountability cannot be delegated to the model and underlying algorithm" — a principle, not a format); US interagency guidance, footnote 3, sentence 3 (the institution's own practices "should guide the determination") | "We're waiting for the final guidance." |

**Question 10 is the hinge.** In every register the obligation is in force and the *format* is not, so the institution's own record is, for now, the specification the examiner will read.

## How to use it

1. Put the ten questions on the agenda as written. Do not paraphrase them into a survey.
2. For each, ask for the record in column three, not a description of it.
3. Any answer that matches column five is the finding. Record it as such.
4. Re-run after the RBI draft finalizes, after IRDAI's working group reports (due about 17 September 2026), and after any Q-SAFE report, and update the anchors to the final text before relying on a paragraph number.

## Discipline

- No firm, product, client or incident is named. The ledger names records.
- Every day count and every "draft" status is as of 11 September 2026 and is wrong for any other date.
- The FREE-AI report is a committee's recommendations; where it is cited the word is "recommended", never "required".
- SR 11-7 is superseded (17 April 2026) and is not an anchor anywhere in this artifact.
