
The Reserve Bank of India (RBI) has proposed a stricter data governance framework for banks and non-banking financial companies (NBFCs). The move aims to improve data quality, security, and accountability across the financial sector.
The central bank released a draft circular on Wednesday, inviting public comments. It seeks to address concerns over data integrity and privacy as digital transactions surge.
The framework mandates that each bank and NBFC appoint a Chief Data Officer (CDO) who will be responsible for data governance. The CDO must report directly to the board or a board-level committee.
Institutions will have to maintain a comprehensive data dictionary covering all critical data elements. They must also conduct regular data audits by an external agency at least once a year.
The proposal requires lenders to implement automated data validation checks at the point of entry. This is to prevent errors and inconsistencies in customer and transaction data.
Banks and NBFCs must also deploy encryption and access controls to protect sensitive data. The RBI has emphasised that data should be stored only on servers located within India.
Non-compliance could attract penalties under the Banking Regulation Act and other relevant laws. The RBI has not specified the exact quantum of penalties yet.
India's banking sector has seen a sharp rise in digital payments and online frauds. Data breaches at some lenders have raised concerns about customer information security.
The RBI has also faced challenges in getting accurate data from financial institutions for its own supervisory functions. The new framework seeks to standardise data reporting and reduce discrepancies.
The draft circular will be open for public feedback until August 31, 2026. The final guidelines are expected to be issued later this year.
Bankers have welcomed the move but flagged implementation costs, especially for smaller NBFCs. Training staff and upgrading systems will require significant investment.
The RBI has said it will provide a transition period of at least 12 months once the final rules are notified. Institutions must submit a compliance plan within three months of the final circular.
Experts say this framework could set a benchmark for data governance in emerging economies. The central bank's approach may influence other regulators in Asia and Africa.
The RBI is expected to release a compliance tracker for banks and NBFCs to monitor progress. Industry bodies are likely to seek more clarity on data localisation rules during the consultation period.