Data Management
RBI proposes data governance norms for banks to manage data better, securely
This story was originally published at 18:25 IST on 15 July 2026
Register to read our real-time news.Informist, Wednesday, Jul. 15, 2026
--RBI issues draft regulatory guidance for data governance
--RBI seeks comments on draft data governance regulatory norms by Aug 17
NEW DELHI – The Reserve Bank of India Wednesday proposed a stricter data governance framework for banks and other regulated financial institutions to promote sound practices relating to data management across the data lifecycle. The proposed norms set out broad regulatory expectations regarding data governance, architecture, metadata, quality, and third-party arrangements for data sharing, the central bank said.
"As the volume, variety and velocity of data continue to increase, effective data governance has become essential to ensure that data remains accurate, consistent, secure and fit for purpose across functions and systems," the RBI said in a notification. "Weaknesses in data governance and its management can lead to broader financial, operational, compliance and reputational risk for the REs (regulated entities)," it added.
Under the proposed norms, banks must put in place a 'data governance framework' applicable to all data and align it with their risk management framework. The data governance framework must be proportionate to the entity's size, complexity, business model, and information technology security. The framework must also cover all material aspects of data governance, including its lifecycle, quality, classification, single source of truth arrangements, metadata, lineage, and third-party arrangements, RBI said.
Regarding third-party arrangements, the RBI said that a regulated entity must be responsible for the governance of data shared with third parties, including group entities. Banks and other institutions must ensure that access to data by third parties is on a 'need to know' basis and that sharing of data does not result in unauthorised reuse, sharing, or duplication. They must implement standards for data sharing, such as encryption, authentication controls, access controls, auto-deletion, and deduplication controls.
The central bank proposed that regulated entities establish processes to manage data risk as a part of their overall risk management framework. It should include identification of data attributes, structure, sources, quality, including accuracy and timeliness for identification, assessment, monitoring, and managing risks pertaining to data. This system should assess and implement controls to mitigate data-related risks arising from third-party arrangements. "It should assess and manage data-related risks in respect of cross-border operations, including processing, storage, transfer and usage, and ensure that such cross-border operations do not impair the RE's (regulated entity's) ability to access, retrieve, and manage its data," the RBI said.
Banks and other financial institutions must also establish a board-level data governance committee to oversee the implementation of the framework and help formulate appropriate policies. The RBI also proposed either establishing an executive-level data governance committee or delegating the responsibility to an existing executive committee with representation from the data team, IT, relevant business verticals, risk management, compliance, and other relevant functions, as required. The committee will "periodically review data-related metrics, breaches and exceptions, major audit observations, and ensure timely remediation," the RBI said.
The central bank also proposed delegating various data-related responsibilities to a host of executives to ensure protection and quality management. The RBI sought stakeholder views on the proposed norms by Aug. 17. End
Reported by Priyasmita Dutta
Edited by Saji George Titus
For users of real-time market data terminals, Informist news is available exclusively on the NSE Cogencis WorkStation.
Cogencis news is now Informist news. This follows the acquisition of Cogencis Information Services Ltd. by NSE Data & Analytics Ltd., a 100% subsidiary of the National Stock Exchange of India Ltd. As a part of the transaction, the news department of Cogencis has been sold to Informist Media Pvt. Ltd.
Informist Media Tel +91 (11) 4220-1000
Send comments to feedback@informistmedia.com
© Informist Media Pvt. Ltd. 2026. All rights reserved.
To read more please subscribe


