
RBI Draft Guidelines on Data Governance Framework for Banks
#GS-2 #GS-3 #Governance & Social Justice #E-Governance #Science & Technology #ICT #Cyber Security #Economy #Banking #Current Events #National
Why in News
- The **Reserve Bank of India (RBI)** has released draft guidance on data governance expectations for financial institutions.
- This guidance directs all **Regulated Entities (REs)** to build a strong **Data Governance Framework (DGF)** with a **two-tier** organizational setup.
- The new framework aims to boost data security, enforce accountability, and ensure compliance with the **Digital Personal Data Protection (DPDP) Act, 2023**.
Key Provisions of the Data Governance Framework
- The main goal is to lower financial, operational, and cyber risks by linking the **Data Governance Framework (DGF)** with each institution's **Enterprise Risk Management (ERM)** across the full data lifecycle.
- Financial institutions must set up a **Board-level Data Governance Committee** to supervise policy execution, review security breaches, and check framework performance.
- Institutions must also form an **Executive Data Governance Committee** and a dedicated **Data Management Function** led by an officer ranked **Chief General Manager (CGM)** or higher.
- The framework assigns explicit duties to **Data Owners** for quality and governance, **Data Stewards** for daily execution, and **Data Custodians** for technical storage, backups, and safe data disposal.
- Institutions must handle data responsibly through purpose-based collection, consent checks, encryption, tokenisation, anonymisation, and secure archiving.
- Banks must establish a **Single Source of Truth (SSOT)** for key data while keeping metadata and data lineage logs to maintain accuracy and enable audits.
- The framework combines data quality, privacy, ownership, cross-border data transfer, and vendor risks into the main **Enterprise Risk Management (ERM)** system.
- Banks stay fully responsible for data shared with third-party vendors and group companies, requiring strict access controls, encryption, contracts, and regular audits.
- This step will strengthen operational resilience, enhance data-based decisions, safeguard customer information, and build a safer digital banking system in India.