RBI Releases Draft Guidance on Data Governance: What Regulated Entities Must Know

The Reserve Bank of India has taken a significant step toward formalising data governance standards across India's financial sector by releasing a comprehensive draft guidance document titled 'Guidance on Regulatory Expectations for Data Governance'. Published on July 15, 2026, this draft invites comments from all stakeholders until August 17, 2026, and lays down an extensive set of expectations for how regulated entities (REs) should govern their data assets, structures, and processes.


Background and Policy Context

Why Data Governance Has Become a Regulatory Priority

The financial sector has undergone a dramatic transformation over the past decade. With the proliferation of digital banking, fintech partnerships, cloud-based infrastructures, and automated decision-making platforms, the sheer scale of data being generated, consumed, and transmitted by financial institutions has grown exponentially. Data is no longer merely a byproduct of business operations — it has become a core strategic and operational asset.

The RBI has drawn upon international best practices, including the Basel Committee on Banking Supervision's Principles for effective risk data aggregation and risk reporting (BCBS 239), as well as supervisory observations gathered through engagements with regulated entities, to frame this guidance. Internal supervisory assessments have revealed that while many REs have made progress in building data management capabilities, persistent weaknesses remain — particularly in the areas of data integrity, accountability structures, and third-party data sharing — that could give rise to financial, operational, compliance, and reputational risks.

This draft guidance is designed to bridge those gaps by providing a structured regulatory framework that REs are expected to embed within their broader governance and risk management systems.


Applicability of the Draft Guidance

Entities Covered Under the Framework

The draft guidance applies broadly across the Indian financial ecosystem. The following categories of regulated entities are within its scope:

  1. Commercial Banks — including all banking companies, corresponding new banks, and the State Bank of India as defined under subsections (c), (da), and (nc) of Section 5 of the Banking Regulation Act, 1949, including Foreign Banks
  2. Small Finance Banks
  3. Payments Banks
  4. Local Area Banks
  5. Regional Rural Banks — as defined under Clause (ja) of Section 5 of the Banking Regulation Act, 1949
  6. Urban Co-operative Banks — meaning Primary Co-operative Banks under Section 5(ccv) read with Section 56 of the Banking Regulation Act, 1949
  7. Rural Co-operative Banks — meaning State Co-operative Banks and Central Co-operative Banks as defined under the National Bank for Agriculture and Rural Development Act, 1981
  8. Non-Banking Financial Companies across all regulatory layers — Base Layer (NBFC-BL), Middle Layer (NBFC-ML), Upper Layer (NBFC-UL), and Top Layer (NBFC-TL)
  9. All-India Financial Institutions, specifically: Export Import Bank of India (EXIM Bank), National Bank for Agriculture and Rural Development (NABARD), National Bank for Financing Infrastructure and Development (NaBFID), National Housing Bank (NHB), and Small Industries Development Bank of India (SIDBI)
  10. Asset Reconstruction Companies registered with the RBI under Section 3 of the Securitisation and Reconstruction of Financial Assets and Enforcement of Security Interest Act, 2002
  11. Credit Information Companies as defined under clause (e) of Section 2 of the Credit Information Companies (Regulation) Act, 2005

Important: Where any inconsistency arises between this Guidance and applicable Directions issued by the RBI, the Directions shall prevail.


Key Definitions Under the Framework

The guidance establishes a precise definitional vocabulary to ensure consistent application across all REs. Key terms include: