RBI Data Governance Framework

|

RBI Data Governance Framework

Economy
RBI Data Governance Framework

The Reserve Bank of India (RBI) issues a comprehensive draft framework titled “Guidance on Regulatory Expectations for Data Governance.” The draft mandates upgraded data risk management, security, and accountability across all Regulated Entities (REs), including commercial banks and NBFCs.

RBI Draft: 

Dimension Key Details
Issuing authority The framework is issued by the Reserve Bank of India (RBI).
Framework title The draft is titled “Guidance on Regulatory Expectations for Data Governance.”
Coverage The framework applies to all Regulated Entities (REs), including commercial banks and NBFCs.
Mandated oversight structure The RBI mandates a two-tier organisational framework to oversee data governance.
Board-level committee REs must establish a dedicated board-level Data Governance Committee, or assign the role to an existing committee, to formulate governance frameworks, periodically review them, and analyse reports on data governance and material breaches.
Executive-level committee An executive-level cross-functional Data Governance Committee comprises representatives from Data Management, IT, Information Security, Risk Management, Compliance, and Business teams.
Proportionality principle The framework must be designed proportionate to the size, operational complexity, business model, and existing technological infrastructure of the respective financial institution.
Core pillars The framework mandates data architectures anchored on accountability, integrity, transparency, auditability, traceability, proportionality, and standardization.
Single Source of Truth (SSOT) REs are required to identify and establish a Single Source of Truth for all critical data elements, ensuring internal business verticals rely on a uniform, authoritative source of information.
Auditing protocols Institutions must continuously assess their data systems and subject data governance mechanisms to periodic internal and external audits.
Third-party liability Banks and NBFCs bear full responsibility for institutional and customer data shared with outsourced service providers or group entities.
Dedicated data function leadership The guidelines require a dedicated data function led by a senior executive not below the rank of Chief General Manager (CGM) or its equivalent.
Data roles and responsibilities Data Owners are accountable for data definitions, quality classification, metadata management, and governance; Data Stewards supervise day-to-day implementation of prescribed standards; Data Custodians handle technical controls including data storage, user access, backups, business continuity, disaster recovery, and secure disposal of stale data.
Did you find this informative?

Attempt Possible Qs

Q 1 / 2

With reference to the RBI draft on data governance, consider the following statements:

1. It mandates a two-tier organisational framework to oversee data governance.
2. It requires establishment of a board-level Data Governance Committee or assignment to an existing committee.
3. It prescribes that only the executive-level committee will review reports on material breaches.

Which of the statements given above are correct?