The Reserve Bank of India (RBI) proposed on Wednesday that banks and non-banking financial companies (NBFCs) implement a data governance framework (DGF) aligned with their risk management policies. This framework should be proportionate to the size, complexity, and business model of each regulated entity, according to the RBI draft guidelines.
Key Details
The RBI stated that the DGF must cover all critical aspects of data governance, including data lifecycle, quality, classification, metadata, lineage, and third-party arrangements. It should comply with the Digital Personal Data Protection (DPDP) Act, 2023, and other applicable laws. The regulator emphasized the importance of data as a vital organizational asset for regulated entities, which supports business operations, customer service, financial reporting, regulatory compliance, risk management, and strategic decision-making.
To ensure effective oversight, the RBI recommended that each regulated entity establish a data function led by a senior officer, not below the rank of chief general manager. Furthermore, a board-level Data Governance Committee (DGC) should be formed to oversee the implementation of the DGF and develop related policies. The RBI noted that the rapid growth of digital financial services and advanced analytics has increased the volume and complexity of data handled by these entities.
Background
The draft guidelines also stipulate that the DGF should be reviewed annually or more frequently as needed, with the board responsible for reviewing reports and metrics related to data governance.
This proposal could lead to increased compliance costs for banks and NBFCs as they implement the new data governance frameworks. Investors may see shifts in investment strategies within the financial sector, particularly among firms that adapt quickly to these regulatory changes.
Watch for further details on the implementation timeline and specific compliance requirements from the RBI in the coming months.