
The Reserve Bank of India (RBI) has proposed a stricter data governance framework for banks and non-banking financial companies (NBFCs). The move is aimed at improving data quality, security, and accountability across the financial sector.
The central bank released a draft circular on Thursday, seeking public feedback by August 17. The proposal comes amid rising concerns over data breaches and the need for robust data management practices.
Under the proposed framework, banks and NBFCs will have to establish a comprehensive data governance policy. This includes appointing a chief data officer (CDO) who will be responsible for data management and compliance.
Firms will also need to maintain a data dictionary, document data lineage, and implement controls for data quality. The RBI wants lenders to ensure that data is accurate, complete, and consistent across all systems.
The draft mandates that financial institutions conduct regular audits of their data governance practices. They must also report any data breaches or issues to the RBI promptly.
The proposed rules place a strong emphasis on protecting customer data. Banks and NBFCs will have to implement stricter access controls and encryption standards for sensitive personal information.
Firms will be required to anonymise or pseudonymise customer data when used for analytics or sharing with third parties. The RBI has also called for clear guidelines on data retention and deletion.
The central bank noted that many lenders currently lack a unified data governance framework. This has led to inconsistencies in data reporting and increased vulnerability to cyber threats.
The RBI's proposal has drawn mixed reactions from the banking sector. Some experts have welcomed the move, saying it will bring much-needed discipline to data management. Others have expressed concerns about the compliance burden, especially for smaller NBFCs.
The deadline for public feedback is August 17. The RBI will review the comments before finalising the framework. The exact timeline for implementation of the new rules has not been disclosed yet.
The central bank has indicated that it may provide a transition period for firms to comply with the new requirements. The final circular will likely include provisions for phased implementation.
The RBI's move aligns with global trends, where regulators are increasingly focusing on data governance. India's financial sector is expected to see greater scrutiny on how lenders handle and protect data.
The central bank will now analyse the feedback received from banks, NBFCs, and other stakeholders. The final rules are expected to be notified later this year, after which firms will have to start aligning their operations with the new framework.