RBI Draft Guidelines on Data Governance Framework for Banks

RBI Draft Guidelines on Data Governance Framework for Banks

#GS-2 #GS-3 #Governance & Social Justice #E-Governance #Science & Technology #ICT #Cyber Security #Economy #Banking #Current Events #National

Why in News

  • The **Reserve Bank of India (RBI)** has released draft guidance on data governance expectations for financial institutions.
  • This guidance directs all **Regulated Entities (REs)** to build a strong **Data Governance Framework (DGF)** with a **two-tier** organizational setup.
  • The new framework aims to boost data security, enforce accountability, and ensure compliance with the **Digital Personal Data Protection (DPDP) Act, 2023**.

Key Provisions of the Data Governance Framework

  • The main goal is to lower financial, operational, and cyber risks by linking the **Data Governance Framework (DGF)** with each institution's **Enterprise Risk Management (ERM)** across the full data lifecycle.
  • Financial institutions must set up a **Board-level Data Governance Committee** to supervise policy execution, review security breaches, and check framework performance.
  • Institutions must also form an **Executive Data Governance Committee** and a dedicated **Data Management Function** led by an officer ranked **Chief General Manager (CGM)** or higher.
  • The framework assigns explicit duties to **Data Owners** for quality and governance, **Data Stewards** for daily execution, and **Data Custodians** for technical storage, backups, and safe data disposal.
  • Institutions must handle data responsibly through purpose-based collection, consent checks, encryption, tokenisation, anonymisation, and secure archiving.
  • Banks must establish a **Single Source of Truth (SSOT)** for key data while keeping metadata and data lineage logs to maintain accuracy and enable audits.
  • The framework combines data quality, privacy, ownership, cross-border data transfer, and vendor risks into the main **Enterprise Risk Management (ERM)** system.
  • Banks stay fully responsible for data shared with third-party vendors and group companies, requiring strict access controls, encryption, contracts, and regular audits.
  • This step will strengthen operational resilience, enhance data-based decisions, safeguard customer information, and build a safer digital banking system in India.