RBI Releases Draft Guidance on Data Governance: What Regulated Entities Must Know
The Reserve Bank of India has taken a significant step toward formalising data governance standards across India's financial sector by releasing a comprehensive draft guidance document titled 'Guidance on Regulatory Expectations for Data Governance'. Published on July 15, 2026, this draft invites comments from all stakeholders until August 17, 2026, and lays down an extensive set of expectations for how regulated entities (REs) should govern their data assets, structures, and processes.
Background and Policy Context
Why Data Governance Has Become a Regulatory Priority
The financial sector has undergone a dramatic transformation over the past decade. With the proliferation of digital banking, fintech partnerships, cloud-based infrastructures, and automated decision-making platforms, the sheer scale of data being generated, consumed, and transmitted by financial institutions has grown exponentially. Data is no longer merely a byproduct of business operations — it has become a core strategic and operational asset.
The RBI has drawn upon international best practices, including the Basel Committee on Banking Supervision's Principles for effective risk data aggregation and risk reporting (BCBS 239), as well as supervisory observations gathered through engagements with regulated entities, to frame this guidance. Internal supervisory assessments have revealed that while many REs have made progress in building data management capabilities, persistent weaknesses remain — particularly in the areas of data integrity, accountability structures, and third-party data sharing — that could give rise to financial, operational, compliance, and reputational risks.
This draft guidance is designed to bridge those gaps by providing a structured regulatory framework that REs are expected to embed within their broader governance and risk management systems.
Applicability of the Draft Guidance
Entities Covered Under the Framework
The draft guidance applies broadly across the Indian financial ecosystem. The following categories of regulated entities are within its scope:
- Commercial Banks — including all banking companies, corresponding new banks, and the State Bank of India as defined under subsections (c), (da), and (nc) of
Section 5of the Banking Regulation Act, 1949, including Foreign Banks - Small Finance Banks
- Payments Banks
- Local Area Banks
- Regional Rural Banks — as defined under Clause (ja) of
Section 5of the Banking Regulation Act, 1949 - Urban Co-operative Banks — meaning Primary Co-operative Banks under
Section 5(ccv)read withSection 56of the Banking Regulation Act, 1949 - Rural Co-operative Banks — meaning State Co-operative Banks and Central Co-operative Banks as defined under the National Bank for Agriculture and Rural Development Act, 1981
- Non-Banking Financial Companies across all regulatory layers — Base Layer (NBFC-BL), Middle Layer (NBFC-ML), Upper Layer (NBFC-UL), and Top Layer (NBFC-TL)
- All-India Financial Institutions, specifically: Export Import Bank of India (EXIM Bank), National Bank for Agriculture and Rural Development (NABARD), National Bank for Financing Infrastructure and Development (NaBFID), National Housing Bank (NHB), and Small Industries Development Bank of India (SIDBI)
- Asset Reconstruction Companies registered with the RBI under
Section 3of the Securitisation and Reconstruction of Financial Assets and Enforcement of Security Interest Act, 2002 - Credit Information Companies as defined under clause (e) of
Section 2of the Credit Information Companies (Regulation) Act, 2005
Important: Where any inconsistency arises between this Guidance and applicable Directions issued by the RBI, the Directions shall prevail.
Key Definitions Under the Framework
The guidance establishes a precise definitional vocabulary to ensure consistent application across all REs. Key terms include: