News

RBI Issues Draft Data Governance Framework for Banks and NBFCs

The Reserve Bank of India (“RBI”) has invited public comment on its draft “Guidance on Regulatory Expectations for Data Governance” (the “Draft”) until August 17, 2026. The Draft provides a Data Governance framework for banks and non-banking financial institutions (“NBFCs”) and other regulated institutions.

The Draft recognises the importance of data as an organisational asset and draws on evolving international practices, including the Basel Committee on Banking Supervision’s Principles for effective risk data aggregation and risk reporting (BCBS 239). The Draft provides a uniform regulatory framework for the entire data lifecycle that includes data creation, collection, storage, processing, sharing, and archiving and disposal. The RBI has required that a regulated institution’s board-approved Data Governance Framework be proportionate to the institution’s size, complexity, business model, and IT and information-security set-up and be reviewed at least annually.

The Draft focuses on the framework’s governance and accountability. Each regulated institution would establish a Data Function, headed by a senior officer not below the rank of Chief General Manager (or equivalent), to serve as the central point of coordination and would designate a Data Owner, Data Steward and Data Custodian for each data domain. The Draft further provides that the Data Governance framework and policies would be monitored and that the framework’s implementation would be overseen through a two-tier structure comprising a board-level Data Governance Committee (DGC) and an executive-level Data Governance Executive Committee, with the board retaining overall oversight.

The Draft particularly focuses on data quality and data traceability. The RBI has required that the regulated institutions’ data be accurate and complete and that the data be of sufficient quality to be useful. The RBI also expects that regulated institutions address data quality issues in a timely manner and implement frameworks for the management of metadata and data lineage. The RBI has required that data governance frameworks be aligned with the regulated institutions’ risk management frameworks. On data architecture, the Draft requires each regulated entity to maintain a Single Source of Truth (SSOT) for its data, avoiding parallel or competing sources, and to adopt a data classification framework based on the criticality, sensitivity and regulatory relevance of data.

The draft establishes stricter standards for data shared with third-party service providers. Regulated entities will be required to maintain data governance for outsourced functions, and if third parties are granted data access, it should be on a need-to-know basis, and third-party contracts must include confidentiality provisions. The Draft also requires regulated entities to assess and manage data risks arising from cross-border operations, including processing, storage, transfer and usage, and to ensure such arrangements do not impair their ability to access, retrieve and manage their data.

The proposed framework will require regulated entities to meet legal and regulatory standards, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and will require regulated entities to integrate data governance with the organisation’s risk management and compliance frameworks. The Draft also expects the framework, policies and processes to be subject to periodic internal and external audits, including through CERT-In empanelled auditors, as applicable, with audit reports placed before the Audit Committee of the Board.

The Guidance will apply to a wide range of RBI-regulated entities, including commercial banks (including foreign banks), small finance banks, payments banks, local area banks, regional rural banks, urban and rural co-operative banks, NBFCs (across the Base, Middle, Upper and Top Layers), all-India financial institutions, asset reconstruction companies and credit information companies. The framework, once finalised, is expected to set a minimum governance standard across all covered regulated entities for the management, quality, and security of data. It is to be read together with existing RBI directions, which will prevail in the event of any inconsistency.

For banks and larger NBFCs, the Draft marks a meaningful step-up in compliance burden, effectively elevating data governance to a board-supervised, independently audited function with dedicated senior ownership at the chief general manager level. From a practical standpoint, the “Single Source of Truth” requirement is likely to be the most difficult to implement, as many large institutions run fragmented legacy and siloed systems across core banking, treasury, cards and group entities that cannot readily be consolidated into a single authoritative source, and enterprise-wide metadata and data-lineage management pose a similar challenge. Several aspects would benefit from clarification, including the implementation timeline and any transition period, how the proportionality standard applies in practice to smaller entities, and how the framework will interact with existing RBI Directions and the DPDP regime so as to avoid overlapping or duplicative obligations.