- The RBI proposed data risk management processes for banks and NBFCs under a new framework
- Draft guidelines include roles, data architecture, metadata, quality, and third-party data sharing
- Entities must form a Data Governance Committee with representation from key functions and IT
The Reserve Bank of India (RBI) on Wednesday proposed that banks, non-banking financial companies (NBFCs) and other entities regulated by it establish processes to manage data risk as part of their overall risk management framework.
The central bank issued draft guidelines outlining broad regulatory expectations on data governance, including roles and responsibilities, data architecture, metadata and lineage, data quality, and third-party arrangements involving data sharing.
With the financial sector becoming increasingly digital and technology-driven business models gaining traction, data has emerged as a critical asset for regulated entities, the RBI said. As the volume, variety and velocity of data continue to grow, effective governance is essential to ensure data remains accurate, consistent, secure and fit for purpose across functions and systems.
The RBI warned that weaknesses in data governance could expose regulated entities to financial, operational, compliance and reputational risks.
ALSO READ | India Records Current Account Surplus Of $2.8 Billion During April-May 2026: RBI Data
Data Governance Committee, Board Oversight Proposed
Under the proposed framework, regulated entities would be required to identify data attributes, structure, sources, quality and classification to assess, monitor and manage data-related risks.
The RBI has also proposed setting up an executive-level Data Governance Committee, or assigning the responsibility to an existing executive committee, with representation from the data function, information technology, information security, relevant business verticals, risk management and compliance.
The board of each regulated entity would oversee the Data Governance Framework (DGF), review related reports and metrics, and ensure the framework is reviewed at least annually or more frequently, if required.
ALSO READ | RBI Clears Rajiv Kumar For Three-Year Term As HDFC Bank Part-Time Chairman
Lifecycle Approach From Origination To Deletion
The RBI has also proposed a lifecycle-based approach to data governance, requiring regulated entities to manage data consistently from its creation or acquisition through to deletion. The framework aims to ensure risks are identified and mitigated at every stage of the data lifecycle.
The draft guidelines also state that data should be created or acquired only for defined and legitimate purposes aligned with an entity's approved business, risk, legal and regulatory objectives.
The RBI has invited stakeholder comments on the draft guidelines until Aug. 17.
(With PTI inputs.)
Essential Business Intelligence, Sharp Market Insights, Practical Personal Finance Advice, Daily Fuel, Gold and Silver Prices and Latest Stories — On NDTV Profit.