RBI data governance

Compliance to accountability: RBI’s data governance expectations

RBI's proposed framework requires banks and NBFCs to strengthen governance, data ownership, quality controls and board oversight.




In brief

  • RBI’s draft guidance requires a board-approved, enterprise-wide data governance framework covering the full data lifecycle.
  • The guidance introduces expectations around data quality, lineage, metadata, SSOT, classification and third-party data governance.
  • Banks and NBFCs should begin readiness assessments, strengthen governance models and prepare for future supervisory reviews.

The Reserve Bank of India’s Draft Guidance on Regulatory Expectations for Data Governance marks a significant shift in how financial institutions are expected to manage, govern and demonstrate accountability for data. Released on 15 July 2026 and applicable across a wide range of regulated entities, including banks, NBFCs, asset reconstruction companies and credit information companies, the guidance elevates data governance from an operational concern to a board-level responsibility.

At the centre of the proposal is a board-approved data governance framework that spans the entire data lifecycle, from creation and collection to storage, sharing, archiving and disposal. The draft draws heavily on BCBS 239 principles and aligns with the Digital Personal Data Protection Act (DPDP Act), signalling a more integrated approach to governance, privacy and regulatory oversight.

What is RBI's draft data governance guidance?

The guidance represents the first consolidated articulation of RBI's regulatory expectations for data governance across the financial sector. Unlike previous technology, cybersecurity or reporting-related requirements, the draft establishes an enterprise-wide data governance approach covering all organizational data, rather than focusing solely on regulatory reporting or risk data.

A key theme is data governance accountability. The RBI expects boards to approve, oversee and annually review the framework, making data governance a recurring governance agenda item rather than a responsibility delegated entirely to technology teams. The message is clear: data is no longer just an IT issue but a strategic and supervisory priority.

For institutions seeking clarity on what does the RBI expects from regulated entities on data governance, the draft provides a structured framework covering governance, organizational roles, data lifecycle controls, architecture, data quality, metadata, lineage and third-party data-sharing practices.

Building an enterprise-wide data governance model

A defining aspect of the proposed RBI data governance framework is its emphasis on clearly defined ownership and accountability. Institutions are expected to establish a dedicated data function and formalize responsibilities across ownership, stewardship and custodianship.

This focus on data ownership and stewardship is likely to drive organizational change across many banks and NBFCs. While governance structures may already exist in parts of the organization, the RBI's approach requires a coordinated data governance operating model that applies consistently across business units and functions.

For many organizations, this may require strengthening enterprise data management capabilities, formalizing governance councils, and creating stronger reporting mechanisms for senior leadership and boards.

Why data quality, lineage and SSOT matter

The guidance introduces a strong focus on data quality management, requiring institutions to define standards, establish monitoring mechanisms and implement remediation processes. Supervisors are expected to seek evidence of measurement and controls, increasing the importance of data quality monitoring and governance metrics.

The RBI also highlights data lineage and metadata as foundational capabilities. Regulated entities are expected to document data flows and maintain traceability from origination through reporting. These data lineage requirements for RBI-regulated entities are likely to accelerate investment in metadata repositories and governance tooling.

Equally important is the requirement for a Single Source of Truth (SSOT) for critical data elements. The RBI recognizes that fragmented systems and multiple versions of business-critical data can undermine reliability and decision-making. For institutions wondering how to implement a single source of truth in banking, the answer lies in a phased transformation effort involving architecture modernization, governance controls and consistent data definitions across the enterprise.

Aligning governance with DPDP and third-party risk

Another notable aspect of the draft guidance is its alignment with privacy obligations. The RBI expects institutions to implement a robust data classification framework based on sensitivity and criticality. The report notes that classification serves as an important link between governance requirements and privacy obligations under the DPDP Act compliance framework.

Organizations should therefore view data classification and DPDP compliance as interconnected initiatives rather than separate workstreams. This creates an opportunity to strengthen data privacy governance, streamline compliance efforts and establish stronger control frameworks around sensitive information.

The guidance also extends governance expectations beyond internal datasets. Requirements around third-party data governance and vendor data risk management mean institutions will need greater visibility into data exchanged with fintech partners, outsourcing providers and other third parties. According to the draft, governance obligations apply across the wider data ecosystem, not just within the regulated entity itself.

How banks can prepare for data governance regulations

A phased approach is recommended for institutions preparing for the final guidance. Before finalization, organizations should conduct a readiness review, secure executive sponsorship and inventory third-party data-sharing arrangements.

Over the following months, institutions should strengthen their data governance for banks programs by formalizing governance structures, approving policies at the board level and defining critical data elements and quality metrics. Longer term, organizations should execute a broader data governance transformation agenda focused on architecture modernization, lineage capabilities and scalable quality monitoring.

The guidance may still evolve, but its direction is clear. The emergence of a board-led, enterprise-wide data governance model signals a new regulatory era where governance, accountability and demonstrable controls become central to supervisory expectations.

Download the full pdf

Learn more about RBI data governance and compliance readiness

Summary

Institutions that invest in strengthening data governance capabilities today will be better equipped to build trust in data, meet regulatory expectations and establish a resilient, future-ready operating model.

Related articles

Why customer experience is the new battleground in Indian banking

Indian banking CX is at a turning point, where empathetic and predictive, phygital experiences now define customer loyalty and growth.

How agentic automation is shaping the future of financial services

Financial services are shifting from RPA to agentic automation, using AI agents to drive smarter operations, enhance risk management and improve customer experiences.

How India GCCs are powering core industry processes in Retail and CPG sector

India’s GCCs are powering global Retail and CPG brands through AI, analytics, merchandizing, marketing, customer service and store operations transformation.

About this article