Data Governance · RBI Draft Guidance
Every Bank Has Ample Data. The RBI's Draft Guidelines Ask Who's Accountable For It.
A closer look at the new data governance framework — and what it means for banks and NBFCs.
The Digital Fifth · RBI Draft Guidance, 15 July 2026 · 5 min read
For years, data governance at most banks followed an informal approach: a few owners here, some documentation there, and no one really checking if it held together. On 15 July, the RBI said that's no longer good enough.
On 15 July 2026, the RBI released its Draft Guidance on Regulatory Expectations for Data Governance for public comment. It's not a brand-new rulebook — it raises the bar on what's already expected. The message is simple: all kinds of data is an asset the Board is accountable for, not a byproduct of running the business.
This applies to almost everyone. Commercial and foreign banks, small finance banks, payments banks, local area banks, every kind of co-operative bank, all NBFCs, and the big institutions like NABARD, SIDBI and NaBFID. Asset reconstruction companies and credit information companies are covered too — eleven types of entity in all. Smaller players get a lighter version to work with, but no one is exempt. If you hold a licence and you hold data, this applies to you.
This isn't a new idea. The RBI is building on BCBS 239, a Basel rule written after the 2008 crisis. Regulators back then found that some of the world's biggest banks couldn't even total up their own risk exposures fast enough as markets fell apart. The lesson was simple: if you can't trust your data, you can't manage your risk. India is now applying that same logic to data governance and risk reporting as well.
Ask a bank who owns a particular customer field today, and you'll usually get a shrug or a meeting. This draft ends the shrug. It requires creating a new department named the Data Function, and new data-mapped responsibilities every entity must name — four roles in all, each written down and accountable. At the top sits someone at Chief General Manager level or above, with enough seniority to bring business, tech and risk into one room. Below that, every set of data gets three named roles solving three very different problems.
The draft follows data through its whole life — from the moment it's captured to the day it's destroyed. Two things stand out. First, a Single Source of Truth: one authoritative copy of each data element, no conflicting versions. For banks whose customer records live in a dozen systems that quietly disagree with each other, this is the hardest line in the document. Second, the framework has to account for consent across the data lifecycle, so that what a customer has agreed to is respected wherever that data travels.
This is where it all connects. The draft doesn't treat privacy as a separate topic — it builds DPDP directly into the pipes. The framework has to comply with the DPDP Act 2023 and the DPDP Rules 2025, using the same definition of "personal data" as the Act. Consent lives inside the data lifecycle, and nothing goes to a third party without a check first. So if privacy has been a side project for your legal team, that's changing: consent, classification and ownership now need to be built into the same system that moves the data.
| Dimension | Typical today | Under the draft |
|---|---|---|
| Data ownership | Sits loosely with IT | Named owner per domain, answers to Board |
| Customer consent | Captured at sign-up | Tracked across the full lifecycle |
| Source of truth | Many systems, often in conflict | One designated Single Source of Truth |
| Senior accountability | Diffuse | Data Function led by CGM or above |
| Third-party data | Governed by contract | Traceable, audited, need-to-know |
- Clear accountability ends the "not my data" problem
- Cleaner data means faster, safer regulatory reporting
- Consent baked in shrinks DPDP exposure
- One source of truth improves every model downstream
- Building a real SSOT across legacy systems
- New senior roles and two committees to staff
- A heavier lift for smaller NBFCs despite proportionality
- Retro-fitting lineage and consent onto old data
The consultation is still open, so details may change. The direction won't. The RBI is moving data governance out of the IT department and into the boardroom, and building privacy into it along the way. For a large bank with clean architecture, much of this just means writing down what already happens. For a mid-sized NBFC held together by integrations and a lean tech team, it's real work: new roles, new committees, and a single source of truth that doesn't exist yet. The safe move is to start now — because whatever version lands will expect it.