RBI July 2026 Draft Data Governance, operationalised in one module.
The Reserve Bank of India's Draft Guidance on Regulatory Expectations for Data Governance (July 2026, comments to RBI open until 17 August 2026) makes data governance a Board-level obligation for every bank, NBFC and cooperative bank. dcomply ships the operating tool: policy generator, Board and Executive committee registers, Data Owner / Steward / Custodian RACI, Single Source of Truth register, third-party arrangements with CERT-In audit tracking, and a live readiness scorecard exportable as a Board-ready PDF.
If any of this sounds familiar, you're in the right place.
These are the exact sentences we hear on first calls. If two or three of them ring true, dcomply is the workspace you have been trying to build in a spreadsheet.
You read the draft and realised your existing IT Governance framework does not fit the new asks — SSOT, lineage, tagging-at-origination.
Your Board is asking whether you need a new committee or whether the IT Strategy Committee can absorb Data Governance.
Four new roles (Owner, Steward, Custodian, Function head) need naming per domain. You have never done a Data RACI at this granularity.
The 17 August 2026 consultation window is short. Your compliance team is not sure whether to comment on the draft, or just build against it.
Related: the RBI Compliance door covers the RBI Cybersecurity Framework, outsourcing register, and STR / CTR filings. The two modules share the same tenant and evidence store.
Here's what sits above the foundation.
The RBI Draft Guidance sits on top of DPDP and alongside the RBI Cybersecurity Framework. dcomply ships modules for each layer, so evidence produced once is reused across all three.
The Draft Is Directional. Building Against It Is Not.
Most BFSI compliance teams are still reading the draft. The teams that start now will have a defensible programme by the time the final Guidance lands.
Data RACI at scale
Four formal roles across every data domain (customer, transaction, KYC, HR, marketing). No template. No prior discipline.
SSOT with parallel systems
Customer master lives in three systems, KYC lives in two. Designating one authoritative source needs reconciliation, not a decision memo.
Third-party accountability
Every vendor arrangement needs CERT-In empanelled audit, cascading accountability language, and auto-deletion attestation. Your contracts do not have it today.
Everything You Need for RBI Data Governance
Board-approved DGF policy
Applicability picker for your RE type (SCB, SFB, PB, RRB, cooperative, all NBFC layers, AIFI, ARC, CIC). Board-approval workflow with dates and status. Scope statement.
Board + Executive Committees
Committee register with type (Board / Executive), charter summary, chair, secretary, members list, cadence, last meeting, next meeting. Quarterly PDF board pack.
Data Owner / Steward / Custodian RACI
Per-domain assignment of the four RBI-defined roles. Data Function head (CGM-equivalent) named at framework level. Named individuals, not titles.
Single Source of Truth register
Domain → data element → authoritative system → reconciliation notes. One row per domain. No parallel SSOTs.
Classification + consent basis
Four-tier classification (public / internal / confidential / restricted) per domain, aligned with your DPDP Rule 6 security posture. Consent basis per domain (Section 6 or Section 7 limb).
Third-party CERT-In tracker
Vendor register with need-to-know scope, CERT-In audit status and certificate upload, encryption in transit and at rest, auto-deletion attestation, cascading accountability sign-off, NDA in place.
Readiness scorecard, live
Seven weighted checks totalling 100, mapped 1:1 to the draft. Ready / In Progress / Early / Not Started band. Refreshes automatically as you populate the registers.
Board-ready PDF pack
One-click export. Cover, readiness scorecard, framework summary, domain register, committee register, third-party register. Take to the next Board Data Governance Committee meeting.
Starter templates for BFSI
One command loads a framework, four canonical BFSI data domains (Customer Master, Loan & Transaction, KYC & AML, Marketing & Analytics), and Board and Executive committees. Edit, don't start from scratch.
Academy Lesson 8.7 — free with DPDP course
A 12-minute deep dive on the RBI DGF, mapped clause-by-clause to DPDPA. Includes a mid-sized NBFC worked example. Included in the DPDP Act 2023 course, no extra charge.
Questions BFSI compliance leads are asking
Comments to RBI close 17 August 2026.
Start the gap assessment now. Ship the framework before the final Guidance lands.