
Introduction
India's financial sector is no longer defined solely by traditional banking institutions. Over the last decade, lending, payments, customer onboarding, fraud detection, and regulatory reporting have become increasingly digital, with almost every function relying on the continuous collection and processing of data. As financial institutions become more data-driven, high-quality and reliable data aside from being an operational requirement, has also become essential for customer protection and effective regulatory oversight.
Based on this shift, the Reserve Bank of India (RBI) has released its Draft Guidance on Regulatory Expectations for Data Governance. The Draft Guidance treats data itself as a governance concern. Rather than asking whether data is merely secure, the framework asks whether it is accurate, consistent, traceable, and fit for use throughout its lifecycle. In doing so, it shifts data governance from an IT function to an enterprise-wide responsibility. This article explains the draft and what banks and fintechs need to do next.
Where Does the Draft Guidance Fit?
At the centre of this framework is the Digital Personal Data Protection Act, 2023 (DPDP Act), which regulates the processing of personal data by establishing obligations relating to consent, lawful processing, security safeguards, and the rights of data principals.
The draft guidelines address a different concern. While older frameworks largely regulate how data should be protected, the new guidance focuses on how data should be governed. A financial institution may have robust cybersecurity controls and still make unreliable regulatory decisions if the underlying data is inaccurate, fragmented, or not accounted for.
Accordingly, the RBI requires every regulated entity to establish a comprehensive Data Governance Framework (DGF) aligned with its enterprise risk management framework and compliant with the DPDP Act and other applicable laws.
The guidance applies to a wide range of regulated entities (REs) supervised by the RBI, including commercial banks, small finance banks, payment banks, regional rural banks, urban and rural cooperative banks, Non-Banking Financial Companies (NBFCs) across all regulatory layers, All India Financial Institutions such as NABARD, SIDBI, NHB and EXIM Bank, Asset Reconstruction Companies (ARCs), and Credit Information Companies (CICs). Although fintech companies are not directly covered unless they themselves qualify as regulated entities, those partnering with banks and NBFCs are likely to experience the practical impact of these standards through outsourcing arrangements, vendor contracts, and supervisory expectations.
The Five Pillars of the Draft Guidance
At its core, the Draft Guidance rests on five broad principles.
Governance and Accountability: Boards are responsible for overseeing the Data Governance Framework, while Board-level and Executive Data Governance Committees supervise implementation, monitor risks, and review compliance. Responsibility for data is further distributed through clearly defined organisational roles such as Data Owners, Data Stewards, and Data Custodians.
Lifecycle based Governance: Data governance begins when data is first collected and continues through processing, sharing, transformation, storage, archival, and eventual disposal. Institutions are expected to maintain ownership, metadata, traceability, validation mechanisms, and appropriate consent throughout this lifecycle.
Robust Data Architecture: The framework introduces concepts such as the Single Source of Truth (SSOT), which means a single designated authoritative source for a specific data element within the regulated entity. Metadata management, data lineage, and structured data classification. Together, these measures seek to ensure that every important data element can be traced back to one authoritative source and remains consistent across systems and reports. consistent across systems and reports.
Data Risk Management: The guidance incorporates data governance into enterprise risk management by requiring institutions to identify, assess, monitor, and periodically review risks relating to data quality, architecture, privacy, security, cross-border operations, and third-party arrangements. Regular audits and Board reporting reinforce this governance structure.
Third-party Governance: Recognising that financial institutions increasingly rely on cloud providers, outsourcing partners, and technology vendors, the RBI makes it clear that accountability does not end when data is shared. Regulated entities remain responsible for ensuring that third parties process data only for authorised purposes, maintain adequate safeguards, and remain subject to continuous oversight.
What Banks Should Do Now
Conduct an enterprise-wide data inventory: Banks should identify what data they hold, where it originates, who owns it, how it flows across systems, and whether multiple versions of the same data exist. Without this exercise, implementing concepts such as a Single Source of Truth or data lineage will be difficult.
Embed governance beyond IT departments: Data governance committees should be established with representation from business, compliance, risk management, legal, and technology teams. Data Owners and Data Stewards should be formally designated, with clearly documented responsibilities and reporting structures.
Review data quality management practices: The RBI expects institutions to measure data quality through indicators such as accuracy, completeness, consistency, timeliness, and reliability. Rather than treating these as regulatory metrics alone, institutions should integrate them into internal performance and risk management frameworks. This becomes particularly important as AI-driven credit assessment, fraud detection, and predictive analytics become increasingly dependent on high-quality data.
Align data governance with existing DPDP compliance programmes: Many institutions currently treat privacy compliance and information governance as separate initiatives. The Draft Guidance provides an opportunity to consolidate consent management, retention schedules, metadata, classification frameworks, and governance documentation under a single enterprise-wide framework.
Revisit vendor governance: Outsourcing arrangements should no longer be assessed solely from a cybersecurity perspective. Contracts with cloud providers, payment service providers, fintech partners, and technology vendors should clearly define ownership of data, access controls, confidentiality obligations, deletion requirements, audit rights, and responsibilities in the event of security incidents or regulatory investigations.
What Fintechs Should Do Now
Banks and NBFCs increasingly expect their technology partners to demonstrate governance standards comparable to their own. Fintech companies involved in digital lending, embedded finance, payment infrastructure, account aggregation, or Banking-as-a-Service should therefore anticipate more rigorous due diligence during vendor onboarding and periodic audits. They should:
Incorporate privacy and governance by design: Metadata, audit trails, data lineage, access controls, and retention policies should be built into systems from the outset rather than introduced later as compliance requirements.
Review how data is used to train AI models and automatic decision-making systems: The Draft Guidance's emphasis on accuracy, traceability, and data quality reflects a broader recognition that unreliable data produces unreliable outcomes. Organisations relying heavily on AI for underwriting, fraud detection, or customer profiling should therefore establish internal governance mechanisms capable of validating training data, documenting transformations, and monitoring quality over time.
Prepare comprehensive contracts: Banks are likely to seek assurances regarding governance policies, data quality controls, audit mechanisms, secure sharing practices, and compliance with the DPDP Act before entering or renewing commercial partnerships.
Conclusion
The RBI's Draft Guidance marks an important evolution in India's regulatory approach to data. Earlier frameworks strengthened cybersecurity and operational resilience, while the DPDP Act established the legal framework for protecting personal data. This guidance complements both by focusing on the quality, accountability, and governance of the data that underpins financial decision-making.
For banks, compliance will require stronger governance structures, clearly defined ownership, improved data architecture, and continuous monitoring of data quality and for fintechs, it signals the governance standards that regulated entities will increasingly expect across the financial ecosystem.
Want to Stay Ahead?
Reach out to the experts at Gotrust today.








