The Reserve Bank of India (RBI) on Wednesday proposed that banks and non-banks implement a data governance framework (DGF) aligned with their risk management policies.
It said that this framework should be proportionate to the size of the regulated entity, its complexity, and its business model, among other factors.
It should cover all material aspects of data governance, including its lifecycle, quality, classification, metadata, lineage, and third-party arrangements; and should be in line with the Digital Personal Data Protection (DPDP) Act, 2023, the DPDP Rules, 2025, and all other applicable laws.
“The DGF should be reviewed annually or more frequently as required. The Board should oversee the DGF of the regulated entity and review the reports and metrics placed before it,” said the RBI draft guidelines.
RBI said that a regulated entity should establish a data function headed by a sufficiently senior officer not below the rank of chief general manager or equivalent, having adequate authority and with necessary competence.
RBI said that data has increasingly emerged as a critical organizational asset for regulated entities (REs), underpinning business operations, customer service, financial reporting, regulatory compliance, risk management, and strategic decision-making.
“The rapid growth in digital financial services, interconnected technology ecosystems, third-party arrangements, advanced analytics, and automated decision-making processes has significantly expanded the volume, velocity and complexity of data being generated, processed, shared and stored by REs,” it said.
The regulator said that banks and non-banks should establish a board-level Data Governance Committee (DGC) or assign responsibility to an existing board committee.
The committee responsible should oversee the implementation of the DGF and formulate policies for data governance, including the scope of data governance, data architecture, and management of data risk.
An entity regulated by RBI should be responsible for the governance of data shared with third parties, including group entities.
“It should ensure that data is shared with third parties only for defined and approved purposes and by designated personnel. It should put in place systems and controls for access, usage, and deletion of data shared with third parties…” read RBI draft guidelines.
Shayan leads the coverage for banking and finance in Mint. Based in Mumbai, he has spent 15 years as a journalist, joining the Mint team in 2018. Over the years, he has tracked the Reserve Bank of India (RBI), commercial banks, and the complex world of shadow banking.<br><br>His expertise goes beyond just reporting news, and he specializes in explaining the "why" behind India’s financial shifts. Shayan has covered major milestones in the industry, including the rollout of the Insolvency and Bankruptcy Code (IBC), mergers in the banking and non-banking space, and the many challenges facing the country's credit markets. He has tracked cases of wrongdoings at India’s private sector banks and murky boardroom battles, trying to get behind the scenes.<br><br>Shayan is driven by a commitment to accuracy and clear, honest reporting. He believes in making finance easy to understand, ensuring his readers and investors stay informed about the forces shaping their money. When not at work, he tries to hone his amateurish photography skills, read fiction, and listen to music. You can follow his work and updates on LinkedIn and Twitter/X.
Catch all the Industry News, Banking News and Updates on Live Mint. Download The Mint News App to get Daily Market Updates.
MoreOops! Looks like you have exceeded the limit to bookmark the image. Remove some to bookmark this image.