For years, data governance was largely viewed as an internal matter for financial institutions, centred on operational efficiency, reporting accuracy and technology management. Increasingly, however, regulators are becoming active participants in this conversation.

Recent regulatory actions relating to data inaccuracies and reporting deficiencies have brought this issue into sharper focus. Viewed in isolation, these may appear to be discrete compliance failures. Viewed collectively, they reveal something more significant: data accuracy, completeness and timeliness are increasingly becoming matters of direct regulatory supervision and enforcement. Regulators are no longer focusing solely on what institutions do; they are also scrutinising the quality and reliability of the data that informs those activities.

The Reserve Bank of India's Data Governance Framework, proposed through its draft guidance on data governance, reflects this changing environment. The discussion extends beyond privacy and protection to a more fundamental question: who owns the data, who is accountable for its quality and whether institutions can confidently rely on it when it matters most.

Why is data governance receiving greater regulatory attention?

Recent regulatory actions involving the Central Repository of Information on Large Credits (CRILC) and Credit Information Companies (CICs) have reinforced the importance of data accuracy, completeness and timeliness.

In March 2024, RBI penalised a public sector bank for inaccurate reporting of large borrower data to CRILC and for furnishing inaccurate information to CICs. Similar enforcement actions followed in 2025 and 2026 in relation to CRILC reporting and borrower-level information submitted to CICs.

Governor Sanjay Malhotra has articulated the RBI's aspiration for supervision to become "more off-site than on-site" and "as near real-time as possible rather than periodic." This signals a broader transformation in the supervisory model. We believe RBI is progressively moving towards a future state in which technology-enabled supervision plays a substantially greater role, potentially moving to 95% offsite supervision from the current 70:30 balance between off-site and on-site supervision. 

In such an environment, data becomes the foundation of supervisory processes, risk assessments and regulatory interventions. The quality, reliability and integrity of institutional data therefore assume greater importance in supervisory and regulatory processes.

How are global regulators approaching data governance?

The increasing focus on data governance is not unique to India. Over the past decade, regulators across the globe have elevated data governance from a technology or operational concern to a foundational pillar of financial stability, risk management and effective supervision.

The Basel Committee on Banking Supervision (BCBS) 239 framework established global expectations around risk data aggregation and risk reporting capabilities, with emphasis on data accuracy, completeness and timeliness. Regulators such as the Australian Prudential Regulation Authority, the European Central Bank and the Monetary Authority of Singapore have reinforced similar principles through supervisory frameworks and guidance.

Although the regulatory instruments differ across jurisdictions, the underlying expectation remains consistent. Financial institutions are expected to maintain robust governance frameworks, clearly defined ownership and accountability for data, effective data quality controls and the ability to rely on data for risk management, regulatory reporting and supervisory purposes.

Moving beyond privacy to enterprise-wide governance

While the Digital Personal Data Protection Act, 2023 (and rules issued in 2025) focuses on the protection and processing of personal data, RBI's approach broadens the discussion to enterprise-wide data governance. 

Data accountability is positioned as an enterprise-wide responsibility rather than a technology-led function. Effective data governance cannot be achieved through technology alone. It requires clear ownership, business accountability and governance embedded throughout the organisation.

Why is data ownership and accountability important?

Clear data ownership and accountability are central to data governance. Ownership is expected to be assigned to every significant data domain, with formal accountability established across data owners, data stewards and data custodians. Responsibilities extend across data definitions, business rules, classification, quality, metadata, lineage, authoritative sources and lifecycle management. Documented accountability structures, role mappings and escalation paths are expected to be maintained and periodically reviewed.

How does data lineage management support regulatory reporting accuracy?

Understanding where data originates, how it moves across systems and how it is ultimately used is increasingly important. Metadata and data lineage management are expected to be maintained across the data lifecycle. Metadata captures information such as ownership, source, purpose, classification and usage, while lineage capabilities trace data movement across systems, transformations, reports and business processes. Together, these capabilities support traceability and regulatory reporting accuracy.

Why are critical data elements important?

The framework places significant emphasis on critical data elements and data quality management.

A structured classification framework is expected to reflect:

  • Business criticality
  • Sensitivity
  • Confidentiality
  • Customer impact
  • Regulatory relevance

Data quality standards and metrics are expected to be monitored across dimensions such as accuracy, completeness, consistency and timeliness.

What role does a SSOT play?

Maintaining consistency across systems, processes and reporting activities requires clearly identified authoritative data sources.

An SSOT supports the use of approved and consistent data across the organisation. Institutions are expected to identify authoritative data sources, govern SSOT designations and implement reconciliation mechanisms to identify and resolve inconsistencies.

Depending on the institution's architecture, SSOT models may be centralised, federated or hybrid.

Where are organisations likely to begin implementation?

For many regulated entities, the starting point is likely to be data that already supports high-priority regulatory and supervisory activities, including:

Beginning with these domains helps establish ownership, quality controls, lineage and accountability before extending governance practices across other material data domains.

The road ahead

The draft guidance formalises governance disciplines around clear accountability, defined ownership, authoritative data sources and traceability of data from origin to regulatory use.

Rather than being viewed as a standalone compliance exercise, it forms part of a broader shift towards stronger data stewardship across the financial sector. Institutions that begin with data supporting regulatory reporting, credit risk and provisioning processes will not only be better positioned for eventual compliance but will also strengthen the reliability of the information on which management, boards and supervisors increasingly depend, while strengthening the data governance compliance capabilities.

Institutions must consolidate fragmented efforts around data management to ensure compliance with the final guidelines when issued and support accurate data-enabled decision-making.

RBI’s draft guidance on data governance

RBI’s draft guidance on data governance

October 2026