Navigating through RBI's draft guidance on Data Governance
- Kenvin Pillai
- Aug 11
- 3 min read
Organizations dealing in financial matters understand that data is the lifeline of today's financial ecosystem. To protect and govern this critical asset, the Reserve Bank of India (RBI) has proposed guidelines for the Regulated Entities (REs) which emphasize on accuracy, availability, confidentiality, consistency, integrity, and traceability of data.
Let's explore the requirements of the draft guidance and impact on the financial industry. RBI has set August 17, 2026 as the deadline for public feedback.

Who does it apply to?
As expected, the RBI's draft guidance applies to a wide range of entities operating in the financial services space, including:
Commercial Banks, Small Finance Banks, Payments Banks, and Local Area Banks.
Regional Rural Banks, Urban Co-operative Banks, and Rural Co-operative Banks.
NBFCs, including all NBFCs in the Base Layer.
All India Financial Institutions, Asset Reconstruction Companies, and Credit Information Companies.
What does it say about governance?
The RBI's draft guidance requires that every RE must implement a robust Data Governance Framework (DGF) that complies with the Digital Personal Data Protection (DPDP) Act, 2023. There is a strong emphasis on top-down approach to data governance.
For instance:
The Board of each RE must constitute a Data Governance Committee (DGC) that will be responsible for overseeing the implementation of the DGF, developing appropriate policies, and reviewing relevant Key Performance Indicators (KPIs) and Material Issues.
An Executive-level committee is required to be established that will ensure the necessary resources are in place and any breaches are remediated promptly upon detection during audit or otherwise.
Defining the Roles: Who is Responsible?
To ensure accountability, the RBI mandates a clear division of data-related responsibilities within the organization.
Role | Key Responsibility |
Data Function Head | A senior officer (not below the rank of Chief General Manager or equivalent) leading the central coordination of the framework. |
Data Owner | Accountable for the business logic, definitions, classification, and designation of the authoritative source for their specific data domain. |
Data Steward | Positioned within business units to manage day-to-day operations, document data flows, and prepare data metrics. |
Data Custodian | Manages the technical environment, including access controls, backups, disaster recovery, and secure data disposal. |
What about technical architecture and operations?
The technical requirements are aimed at reducing the data governance complexities by removing silos and establishing the single source of truth (SSOT) for all data elements.
Every RE is required to establish the SSOT for all data elements (i.e., there must not be multiple sources for the same data element). All downstream systems, derivations, analytics, and business intelligence must be built upon this defined SSOT.
The metadata about the data elements (including relevant fields such as source, purpose, owner, classification, retention period, etc.) must be captured and documented at the time of capture/inception and this information must flow down to all downstream systems unless these fields are irrelevant for downstream uses.
Regarding data sharing with third parties, the REs are responsible for ensuring appropriate confidentiality, integrity, and availability of the data. In other words, any sharing of data with third parties must be limited to a "need-to-know" basis and protected by appropriate encryption and other safeguards. Additionally, REs are expected to conduct third-party audits of such vendors to ensure compliance with the above requirements.

Industry Perspective: Proposed Review Comments
While the RBI's guidance provides a necessary framework for a secure financial future, certain clauses present significant operational challenges. As the industry prepares public submissions, a few key areas require constructive dialogue.
1. Proportionality in Leadership Mandates
The Mandate: The Data Function must be headed by an officer not below the rank of Chief General Manager or equivalent.
The Industry View: While ensuring executive accountability is crucial, mandating a CGM-level officer is disproportionately burdensome for smaller entities like Base Layer NBFCs or Local Area Banks.
Proposed Solution: Allow smaller REs the flexibility to designate the head of the Data Function based on their internal hierarchy, provided the officer reports directly to the Executive Committee or the Board.
2. Implementation Timeline for the SSOT
The Mandate: Establish an SSOT for all data elements, ensuring no parallel sources exist.
The Industry View: Transitioning legacy, fragmented IT architectures to a strict SSOT for every single data element is a massive technological undertaking with exceptionally high execution risk.
Proposed Solution: Limit the immediate SSOT mandate to "Critical Data Elements" (CDEs) rather than all data, providing a phased, multi-year implementation roadmap.
3. Direct Audits of Third-Party Systems
The Mandate: REs must conduct periodic audits of third-party systems, either internally or through external auditors.
The Industry View: Many REs rely on global cloud hyperscalers (e.g., AWS, Azure, Google Cloud), which typically do not permit direct, individualized client audits of their physical environments.
Proposed Solution: Amend the clause to explicitly permit REs to rely on internationally recognized, independent third-party assurance reports (such as SOC 2 Type II or ISO 27001 certifications) in lieu of direct audits.



Comments