RBI Issues Draft Data Governance Rules for Financial Firms

RBI
Whalesbook Logo
AuthorAnanya Iyer|Published at:
RBI Issues Draft Data Governance Rules for Financial Firms

The Reserve Bank of India has released a new draft framework to improve data management and security across banks and financial institutions. The proposal requires firms to adopt a clear three-lines-of-defence model, ensuring board-level accountability. This move aims to fix data inconsistencies and prepare entities for upcoming regulatory requirements, including the transition to expected credit loss accounting by 2027.

Detailed Coverage

The Reserve Bank of India (RBI) has introduced a draft framework aimed at strengthening data governance standards for all regulated financial entities. The move comes as financial institutions face growing operational complexities and cybersecurity risks. By formalizing how data is managed, stored, and reported, the central bank intends to shift the industry toward a more disciplined, unified approach to information management.

Accountability and the Three-Lines-of-Defence Model

Central to the new proposal is the adoption of a three-lines-of-defence model. This system seeks to eliminate fragmented data responsibility, where oversight is often split between IT, risk management, and business teams. Under the new guidance, accountability will be pushed to the board level, which must establish a dedicated committee to supervise data practices. Senior executives will be tasked with direct oversight, while clear chains of responsibility will be assigned to data owners and stewards throughout each organization. This structure is designed to ensure that data quality is treated as a strategic priority rather than a purely technical function.

Implementing a Single Source of Truth

One of the most significant challenges identified by the RBI is the inconsistency of data across different banking systems. To address this, the draft promotes the creation of a 'Single Source of Truth' (SSOT). By moving away from disparate systems that often provide conflicting reports, financial institutions will be better positioned to meet upcoming regulatory deadlines. This is especially relevant as banks prepare for the transition to 'expected credit loss' accounting, which is mandated for April 2027. Accurate and reliable data infrastructure will be essential for the accurate calculation of credit losses under these new accounting standards.

Implementation Challenges and Next Steps

The framework is calibrated to account for the size and complexity of different entities, which is intended to reduce the compliance burden for smaller non-banking financial companies and cooperative banks. However, many institutions, particularly those still relying on legacy core banking systems, may find the transition to a centralized data model technically demanding and costly.

Another area requiring clarity is the lack of specific, quantifiable metrics. While the draft sets expectations for data to be 'fit for purpose,' it currently offers limited detail on how auditors should measure compliance. Furthermore, financial conglomerates may face operational difficulties due to the lack of similar harmonized guidelines from the Securities and Exchange Board of India (SEBI) and the Insurance Regulatory and Development Authority of India (IRDAI). Investors should monitor the consultation process in the coming months, as the final version of these rules will likely clarify transition timelines, penalty structures for non-compliance, and the specific standards required to satisfy supervisory audits.

Disclaimer: This article is published for informational purposes only. This is not a buy sell recommendation.