The Reserve Bank of India (RBI) has released a draft Guidance on Regulatory Expectations for Data Governance, proposing a comprehensive framework for how banks, NBFCs and other regulated entities (REs) should manage data across their entire lifecycle. The draft builds on supervisory findings and international standards, including the Basel Committee’s BCBS 239 principles, after the RBI found persistent weaknesses in how financial institutions govern data. 

How data should be governed through its lifecycle: The RBI wants REs to adopt a lifecycle-based approach so that governance applies consistently from data collection to disposal.

At the point of collection, REs must:

  • Collect or create data only for defined business, legal, or regulatory purposes.
  • Establish ownership, classification, intended usage, and customer consent, wherever applicable, when data is first captured.
  • Ensure systems validate data for completeness and consistency.
  • Apply the same governance standards to data obtained from third parties as to internally generated data.

When processing or sharing data, REs must:

  • Use only approved rules and standards for processing, transformation, or sharing.
  • Protect data through encryption, tokenisation, anonymisation, and other security controls.
  • Clearly assign accountability for transformed or derived datasets.
  • Conduct impact assessments before implementing transformation logic.
  • Ensure transformed data remains traceable to its source and retains the appropriate classification.

For retention and disposal, REs must:

  • Establish a Data Retention and Archival Policy.
  • Retain data only for justified business, legal, audit, or regulatory purposes.
  • Preserve metadata, classification, and lineage during archival.
  • Ensure archived data remains easily retrievable for supervisors, auditors, and investigations.
  • Dispose of data through secure, controlled, and verifiable processes based on its sensitivity and criticality.

Organisational structure and governance:

Boards and committees:

  • The Board will oversee the Data Governance Framework (DGF).
  • REs must either establish a Board-level Data Governance Committee or assign the role to an existing Board committee.
  • The committee must approve data governance policies covering architecture, ownership, quality, classification, lifecycle management, and third-party arrangements.
  • It must periodically review policies and escalate major breaches or conflicts to the Board.

Executive governance: Above this, an executive-level Data Governance Committee should:

  • Include representatives from data, IT, information security, business, compliance, and risk functions.
  • Implement and operationalise the DGF.
  • Ensure sufficient staffing, authority, and budget.
  • Review breaches, audit findings, and policy exceptions.
  • Monitor data classification, critical data elements, and remediation measures.

Dedicated data roles: The RBI also…


Source link

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We blogs.grocliq.com want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It’s possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.

Website Upgradation is going on for any glitch kindly connect at [email protected]

 

 

Categorized in:

Blog,

Last Update: July 16, 2026