RBI’s Draft Data Governance Framework 2026: What Every Bank and NBFC Needs to Know

Share:

Table of Contents

For years, data governance at most banks followed an informal approach: a few owners here, some documentation there, and no one really checking if it held together. On 15 July, the RBI said that's no longer good enough.

On 15 July 2026, the RBI released its Draft Guidance on Regulatory Expectations for Data Governance for public comment. It’s not a brand-new rulebook, it raises the bar on what’s already expected. The message is simple: all kinds of data is an asset the Board is accountable for, not a byproduct of running the business.

Who This Touches

This applies to almost everyone. Commercial and foreign banks, small finance banks, payments banks, local area banks, every kind of co-operative bank, all NBFCs, and the big institutions like NABARD, SIDBI and NaBFID. Asset reconstruction companies and credit information companies are covered too, eleven types of entity in all. Smaller players get a lighter version to work with, but no one is exempt. If you hold a licence and you hold data, this applies to you.

11

Classes of regulated entity in scope

4

New data jobs every entity must name

CGM+

Seniority required to run the Data Function

Where It Comes From

This isn’t a new idea. The RBI is building on BCBS 239, a Basel rule written after the 2008 crisis. Regulators back then found that some of the world’s biggest banks couldn’t even total up their own risk exposures fast enough as markets fell apart. The lesson was simple: if you can’t trust your data, you can’t manage your risk. India is now applying that same logic to data governance and risk reporting as well.

Who's Actually on the Hook

Ask a bank who owns a particular customer field today, and you’ll usually get a shrug or a meeting. This draft ends the shrug. It requires creating a new department named the Data Function, and new data-mapped responsibilities every entity must name, four roles in all, each written down and accountable. At the top sits someone at Chief General Manager level or above, with enough seniority to bring business, tech and risk into one room. Below that, every set of data gets three named roles solving three very different problems.

THE ONE IN CHARGE

Head of the Data Function : CGM or above

Leads the Data Function, the department that has to make governance actually happen across business, technology and risk, and carries the framework to the Board.

OWNS THE MEANING

Data Owner

Decides what a field means, who may use it and how it is classified. Accountable and responsible for ensuring data within the domain is defined, classified and used consistent with the DGF. Their name is on it when it is wrong.

RUNS IT DAILY

Data Steward

Turns the Owner’s rules into everyday practice and catches the gaps before they spread across systems.

GUARDS THE SYSTEMS

Data Custodian

Controls access, storage, backups and secure deletion. The one holding the keys to where it all sits.

THE DATA LIFECYCLE GOVERNED AT EVERY STAGE

You stop building point-to-point pipes every time something new is required. You start running an institution where information is already in motion, and new products are ways of listening to it.

Join Our Newsletter

Get exclusive insights on banking, fintech, regulatory updates and industry trends delivered to your inbox.

The DPDP Connection

This is where it all connects. The draft doesn’t treat privacy as a separate topic, it builds DPDP directly into the pipes. The framework has to comply with the DPDP Act 2023 and the DPDP Rules 2025, using the same definition of “personal data” as the Act. Consent lives inside the data lifecycle, and nothing goes to a third party without a check first. So if privacy has been a side project for your legal team, that’s changing: consent, classification and ownership now need to be built into the same system that moves the data.

DPDPA CONNECTION

The Bottom Line

The consultation is still open, so details may change. The direction won’t. The RBI is moving data governance out of the IT department and into the boardroom, and building privacy into it along the way. For a large bank with clean architecture, much of this just means writing down what already happens. For a mid-sized NBFC held together by integrations and a lean tech team, it’s real work: new roles, new committees, and a single source of truth that doesn’t exist yet. The safe move is to start now, because whatever version lands will expect it.

Getting Your Data House in Order?

The Digital Fifth works with banks and NBFCs on data governance strategy and DPDP readiness. If this draft changes how your data function needs to be structured, we’re happy to think it through with you.

Contact Us

Recent Posts

Zero MDR Under PressureIs UPI’s Free Payments Era Changing?

Event-Driven Banking: Why Real-Time Banks Still Run on Batch Rails

Credit for the Creditless Designing Lending Products for Thin-File Borrowers

AI-Assisted Relationship Managers: Augmentation or Replacement?

Third-Party Risk in Indian Banking: Why LSP Governance Matters More Than Vendor Management

Latest Reports

Embedded Supply Chain Finance Report
Embedded Supply Chain Finance in India MSME Report 2026
Indian Fintech Funding Report Q1 2026
Indian Fintech Funding Report – Q1 2026
India funding report jan to dec 2025
Indian Fintech Funding Report – Jan-Dec 2025
Indian Fintech Funding Report nov 2025
Indian Fintech Funding Report November 2025
September-October 2025 funding report
Indian Fintech Funding Report September & October 2025

Join Our Newsletter

Get exclusive insights on banking, fintech, regulatory updates and industry trends delivered to your inbox.

Join WhatsApp community

Scan the QR code to join our WhatsApp community for instant updates and discussions.

Thank you for reaching out!

Your form has been successfully submitted. Our team will get back to you shortly.

In the meantime, don’t miss out on our latest insights, industry reports, and leadership conversations: