Summary: The RBI has released the Draft Guidance on Regulatory Expectations for Data Governance, proposing a comprehensive enterprise-wide framework applicable across banks, NBFCs, payment banks, co-operative banks, CICs, and other regulated entities. The Draft Guidance emphasises board oversight, defined data governance roles, lifecycle-based controls, SSOT architecture, metadata and lineage management, data classification, data quality processes, and governance of third-party data sharing. The proposal reflects increasing regulatory focus on data as a core prudential and operational asset and aligns with international frameworks such as BCBS 239. Comments on the draft can be submitted until August 17, 2026.
- On July 15, 2026, the Reserve Bank of India (“RBI”) published the Draft Guidance on Regulatory Expectations for Data Governance (“Draft Guidance”).[1] The framework seeks to strengthen the reliability, consistency, availability, traceability, and security of data across regulated entities (“REs”).[2] It is intended to be read alongside existing RBI directions, which will continue to prevail in the event of any inconsistency. The Draft Guidance draws upon supervisory observations, stakeholder engagement, and international standards, including the Basel Committee on Banking Supervision’s “Principles for Effective Risk Data Aggregation and Risk Reporting” (BCBS 239).[3]
- At the governance level, the Draft Guidance requires every RE to establish a Data Governance Framework (“DGF”) covering all organisational data. The DGF must be proportionate to the size, complexity, and business model of the institution and aligned with applicable legal and regulatory requirements.
- The Draft Guidance envisages a three-tier governance structure. The Board is required to oversee the DGF, while a dedicated Data Governance Committee (“DGC”), or an existing board committee, is tasked with policy oversight and review of governance metrics.
- At the management level, a Data Governance Executive Committee (“DGEC”) must operationalise the framework, address data governance gaps and oversee implementation across functions.
- Data risk management is expected to form part of an RE’s broader risk management framework. RBI identifies seven foundational principles for effective data governance: accountability, integrity, auditability, transparency, traceability, proportionality, and standardisation.
- At the organizational structure level, the Draft Guidance requires REs to establish a dedicated ‘data function’ headed by a sufficiently senior officer. In addition, each data domain must have clearly identified ‘data owners’, ‘data stewards’, and ‘data custodians’. Data owners are responsible for data governance outcomes within their domain, including classification, quality and oversight of data usage; data stewards support day-to-day implementation and monitoring of governance requirements; and data custodians are responsible for the technical management of data systems and controls, including access management, security, retention and business continuity measures. Together, these roles are intended to create end-to-end accountability covering business ownership, operational implementation, and technical management of data assets.
- The RBI has also proposed a lifecycle-based approach to data governance. Data must be created or collected only for legitimate and defined purposes, with key attributes such as ownership, classification, usage intent, and customer consent recorded at the point of collection where relevant. Appropriate controls are expected to apply through subsequent stages of processing, sharing, transformation, retention, and disposal.
- The Draft Guidance places particular emphasis on data architecture, with the following expectations:
- It requires REs to establish and maintain a single source of truth (SSOT) for data elements, supported by reconciliation mechanisms to identify inconsistencies. It permits centralised, federated, or hybrid implementation models, provided the REs ensure a clearly identifiable authoritative source and traceability across downstream systems and reporting layers.
- It requires comprehensive metadata management and data lineage capabilities. The REs must ensure foundational metadata is captured at source, preserved through downstream processing, and updated when data is transformed or derived. They must establish data classification frameworks to account for criticality, sensitivity, confidentiality, and regulatory relevance, enabling risk-based controls across the data lifecycle.
- Data quality management forms another key element of the proposal. It expects REs to maintain data quality metrics, establish remediation processes, and ensure that deficiencies do not adversely affect decision-making, risk management, or regulatory reporting. The REs must report persistent quality issues periodically to the board-level governance structure.
- The Draft Guidance also addresses third-party data sharing. It requires REs to remain accountable for data shared with external service providers and group entities and must implement controls governing access, usage, retention, deletion, and monitoring. The REs should ensure shared data remains traceable to the designated SSOT and is subject to appropriate contractual, technical, and audit safeguards.
The Draft Guidance represents a comprehensive data governance framework. While larger institutions may already maintain elements of such a framework, the proposed requirements will necessitate enhancements to data governance processes, documentation standards, metadata and lineage capabilities, data quality monitoring mechanisms, and technology infrastructure. The consultation process is, therefore, likely to focus on proportional implementation, operational feasibility, and phased adoption timelines across different categories of REs.

[1] ‘Draft Guidance on Regulatory Expectations for Data Governance’ published by RBI on July 15, 2026, accessible here.
[2] This Guidance is applicable to following REs of the Reserve Bank of India: (i) Commercial Banks (including Foreign Banks); (ii) Small Finance Banks; (iii) Payments Banks; (iv) Local Area Banks; (v) Regional Rural Banks; (vi) Urban Co-operative Banks; (vii) Rural Co-operative Banks; (viii) Non-Banking Financial Companies in Base Layer, Middle Layer, Upper Layer, and Top Layer; (ix) All-India Financial Institutions, viz., EXIM Bank, NABARD, NaBFID, National Housing Bank and SIDBI; (x) Asset Reconstruction Companies registered with the RBI; and (xi) Credit Information Companies.
[3] Basel Committee on Banking Supervision’s ‘Principles for Effective Risk Data Aggregation and Risk Reporting’ (BCBS 239), January 2013, accessible here.





