Table of Contents
For years, data governance at most banks followed an informal approach: a few owners here, some documentation there, and no one really checking if it held together. On 15 July, the RBI said that's no longer good enough.
On 15 July 2026, the RBI released its Draft Guidance on Regulatory Expectations for Data Governance for public comment. It’s not a brand-new rulebook, it raises the bar on what’s already expected. The message is simple: all kinds of data is an asset the Board is accountable for, not a byproduct of running the business.
Who This Touches
This applies to almost everyone. Commercial and foreign banks, small finance banks, payments banks, local area banks, every kind of co-operative bank, all NBFCs, and the big institutions like NABARD, SIDBI and NaBFID. Asset reconstruction companies and credit information companies are covered too, eleven types of entity in all. Smaller players get a lighter version to work with, but no one is exempt. If you hold a licence and you hold data, this applies to you.
11
Classes of regulated entity in scope
4
New data jobs every entity must name
CGM+
Seniority required to run the Data Function
Where It Comes From
This isn’t a new idea. The RBI is building on BCBS 239, a Basel rule written after the 2008 crisis. Regulators back then found that some of the world’s biggest banks couldn’t even total up their own risk exposures fast enough as markets fell apart. The lesson was simple: if you can’t trust your data, you can’t manage your risk. India is now applying that same logic to data governance and risk reporting as well.
Who's Actually on the Hook
Ask a bank who owns a particular customer field today, and you’ll usually get a shrug or a meeting. This draft ends the shrug. It requires creating a new department named the Data Function, and new data-mapped responsibilities every entity must name, four roles in all, each written down and accountable. At the top sits someone at Chief General Manager level or above, with enough seniority to bring business, tech and risk into one room. Below that, every set of data gets three named roles solving three very different problems.
THE ONE IN CHARGE
Head of the Data Function : CGM or above
Leads the Data Function, the department that has to make governance actually happen across business, technology and risk, and carries the framework to the Board.
OWNS THE MEANING
Data Owner
Decides what a field means, who may use it and how it is classified. Accountable and responsible for ensuring data within the domain is defined, classified and used consistent with the DGF. Their name is on it when it is wrong.
RUNS IT DAILY
Data Steward
Turns the Owner’s rules into everyday practice and catches the gaps before they spread across systems.
GUARDS THE SYSTEMS
Data Custodian
Controls access, storage, backups and secure deletion. The one holding the keys to where it all sits.
You stop building point-to-point pipes every time something new is required. You start running an institution where information is already in motion, and new products are ways of listening to it.
Join Our Newsletter
Get exclusive insights on banking, fintech, regulatory updates and industry trends delivered to your inbox.
The DPDP Connection
This is where it all connects. The draft doesn’t treat privacy as a separate topic, it builds DPDP directly into the pipes. The framework has to comply with the DPDP Act 2023 and the DPDP Rules 2025, using the same definition of “personal data” as the Act. Consent lives inside the data lifecycle, and nothing goes to a third party without a check first. So if privacy has been a side project for your legal team, that’s changing: consent, classification and ownership now need to be built into the same system that moves the data.
The Bottom Line
The consultation is still open, so details may change. The direction won’t. The RBI is moving data governance out of the IT department and into the boardroom, and building privacy into it along the way. For a large bank with clean architecture, much of this just means writing down what already happens. For a mid-sized NBFC held together by integrations and a lean tech team, it’s real work: new roles, new committees, and a single source of truth that doesn’t exist yet. The safe move is to start now, because whatever version lands will expect it.
Getting Your Data House in Order?
The Digital Fifth works with banks and NBFCs on data governance strategy and DPDP readiness. If this draft changes how your data function needs to be structured, we’re happy to think it through with you.