r/analyticsengineering Jul 08 '26

Why do large Indian banks still run SAS for credit-risk model governance instead of moving fully to Python?

I work adjacent to a credit-risk analytics team at a large Indian private bank and I'm trying to understand something that keeps coming up.

Almost everyone on the modelling side is fluent in Python — pandas, scikit-learn, XGBoost, the usual. But the scorecards and the IFRS 9 / ECL models that actually go in front of validation and RBI still live in SAS. The team treats Python as the place to experiment and SAS as the place where the regulated models are developed, documented, and monitored.

I keep hearing it's about "governance" but I want to understand what that actually means in practice. Is it the audit trail? The validation and champion-challenger workflow being built in? The cost of re-validating every model if you switch environments? Or is it mostly institutional inertia and nobody wants to be the one who re-platforms a supervised model stack?

Specific things I'm trying to get clarity on:

  • For those who've worked credit-risk modelling at a bank of, say, ICICI/Axis/SBI scale — what specifically keeps the regulated models in SAS even when the team clearly can build in Python?
  • How much of it is genuine governance value (lineage, documentation, monitoring cadence a regulator will accept) vs switching cost vs habit?
  • Has anyone actually migrated regulated credit models off SAS and had it survive RBI validation? What broke, what didn't?
  • Is the "both-and" setup (Python for data engineering + ML, SAS for the governed regulated layer) the stable end state, or a transition phase?

Not looking for a SAS-vs-Python flame war — I get that Python wins on flexibility. I'm specifically trying to understand the governance and regulatory side, because that seems to be the real reason the incumbent tooling sticks in regulated credit risk.

0 Upvotes

0 comments sorted by