Skip to main content
Regulatory Updates

RBI's Draft Data Governance Guidance: What Banks and NBFCs Must Build

RBI's draft data governance guidance mandates a board-level committee, data tagging, and quarterly reporting for banks and NBFCs. Comments due August 17, 2026.

9 min read
On This Page

On July 15, 2026, the Reserve Bank of India released the draft Guidance on Regulatory Expectations for Data Governance. Comments are due by August 17, 2026. The document is short on ceremony and long on structure: it tells every regulated entity to put data governance in front of its board, tag its data with metadata, trace its lineage, and measure its quality on a reporting cadence.

For banks and NBFCs the significant line is not any single control. It is that the draft writes the DPDP Act 2023 directly into RBI’s supervisory expectations. Data protection compliance and prudential supervision have been separate conversations. This draft merges them.

What the Draft Guidance Is

The draft sets out regulatory expectations across six areas: data governance structure, roles and responsibilities, data architecture, metadata and lineage, data quality, and third-party arrangements involving data sharing.

It is guidance, not directions. The consultation closes on August 17, 2026, and the final instrument will follow. Treat the draft as the blueprint RBI has already committed to in outline, with the details open for comment.

The full draft text is published on the RBI website as Guidance on Regulatory Expectations for Data Governance.

Who Must Comply

The draft applies to eleven categories of regulated entities:

  • Commercial banks
  • Small finance banks
  • Payments banks
  • Local area banks
  • Regional rural banks
  • Urban co-operative banks
  • Rural co-operative banks
  • All India Financial Institutions
  • Non-banking financial companies, across all layers
  • Asset reconstruction companies
  • Credit information companies

There is no size carve-out in the coverage list. A base-layer NBFC and a systemically important bank are addressed by the same document.

The Core Mandate: A Board-Level Data Governance Committee

The draft puts accountability at the top of the organisation.

“An RE should establish a Board level Data Governance Committee (DGC) or assign the responsibility to an existing Committee of the Board.” (Paragraph 9)

The committee owns data governance policy and oversees implementation. For most NBFCs this is a new obligation category: data governance stops being an IT function and becomes a board agenda item with a paper trail.

Data Tagging: Metadata and Lineage Requirements

The draft requires data to carry metadata from capture onward. The minimum attributes named include the source application, the purpose, the data owner, the classification, and retention and usage requirements. When data is transformed or derived, the metadata must be updated to record the relationship between source and derived data, the purpose of the transformation, and any change in classification or accessibility.

Lineage is defined as documented traceability of data from its origin through aggregation, transformation, and usage to its final destination. Third-party sharing is inside the perimeter:

”… data shared with third-parties remains traceable to the designated SSOT, and metadata and lineage capture the extent of such sharing.” (Paragraph 63)

The SSOT is the entity’s designated single source of truth for each data element. Read that against your current state. If your customer records live in spreadsheets and CRM exports, none of this metadata exists. Building it starts with a personal data inventory, because you cannot tag data you have not mapped.

Quarterly Reporting and Annual Review

The draft sets a measurement cadence.

“The data quality metrics report and persistent data quality issues should be placed before the DGC at quarterly or more frequent intervals.” (Paragraph 59)

The governance framework itself must be reviewed annually or more frequently. Quarterly metrics before a board committee means the committee needs something to review. Defined metrics. A pipeline that produces them on schedule. And a record of what was decided when they arrived.

Where the Draft Meets the DPDP Act 2023

This is the section that makes the draft more than an internal-controls document. Paragraph 6 requires a governance framework that “complies with the Digital Personal Data Protection (DPDP) Act, 2023, the DPDP Rules, 2025, and all other applicable laws and rules”. Paragraph 18 repeats the requirement at the data level:

“An RE should ensure that customer-related data is handled in compliance with DPDP Act, 2023, and DPDP Rules, 2025.” (Paragraph 18)

The draft also names consent management for customer data within its scope. The consequence is direct: when RBI supervisors examine data governance, DPDP compliance is part of what they examine. A bank or NBFC that treats the DPDP Act as a standalone legal project, separate from its RBI obligations, will build the same infrastructure twice and defend it twice.

This compounds the dual-compliance position BFSI already occupies. The Responsible Business Conduct Directions have governed consent conduct for banks since July 1, 2026. The Second Amendment Directions for NBFCs take effect on January 1, 2027. The retention conflict between RBI mandates and DPDP erasure rights remains unresolved by either regulator. The draft guidance now adds the governance layer above all of it.

Draft Status: What “Not in Force” Means

The guidance is not enforceable today. Comments close on August 17, 2026, and finalisation follows. Nothing in the draft changes the DPDP enforcement timeline: the DPDP Rules took effect in November 2025, Consent Manager registration closes in November 2026, and penalty enforcement is expected from May 2027.

The preparation logic still runs one way. The DPDP obligations the draft references exist independently of it. A board committee does not materialise in a quarter. Neither does a tagged data estate. Entities that wait for the final guidance will be building governance structure at the same time their supervisors begin asking for it.

What Banks and NBFCs Should Do Now

Four actions fit inside the consultation window.

  1. File comments by August 17, 2026. The tagging and lineage requirements carry real implementation cost. If the draft’s expectations are impractical for your data estate, the comment window is the mechanism to say so.
  2. Map the data estate. Every subsequent obligation assumes you know what personal data you hold, where it came from, and why. Start with the data inventory.
  3. Put data governance on a board agenda. Whether a new committee or an existing one, the designation decision and its mandate belong in board minutes now.
  4. Consolidate the DPDP and RBI workstreams. The draft makes them one examination surface. Data Fiduciary obligations, consent records, and retention documentation should live in one system of record, not in parallel legal and IT projects.

ConsentOS operates this layer for BFSI: consent capture with signed Electronic Consent Artifacts, a Data Inventory portal, and a conflict-of-law documentation register that records where RBI retention mandates and DPDP erasure obligations collide. Run the Gap Assessment to see where your organisation stands, or review what DPDP compliance requires for NBFCs.

Know where you stand on DPDP compliance

Run the free Compliance Vault Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.

Enforcement milestones, rule notifications, and deadline analysis.

One email when it matters, no more.