RBI Data Governance door. BFSI-only. New for July 2026.

RBI July 2026 Draft Data Governance, operationalised in one module.

The Reserve Bank of India's Draft Guidance on Regulatory Expectations for Data Governance (July 2026, comments to RBI open until 17 August 2026) makes data governance a Board-level obligation for every bank, NBFC and cooperative bank. dcomply ships the operating tool: policy generator, Board and Executive committee registers, Data Owner / Steward / Custodian RACI, Single Source of Truth register, third-party arrangements with CERT-In audit tracking, and a live readiness scorecard exportable as a Board-ready PDF.

72%
DGF Readiness Score — In Progress
✓ Board-approved DGF
✓ Board + Executive Committees
✓ Data Function head named
✓ 4 domains with full RACI
⚠ SSOT designated for 2 of 4
⚠ Third-party CERT-In audits: 1 pending
Last assessed: Today
Live RBI DGF readiness scorecard, board-ready PDF export
Sound familiar?

If any of this sounds familiar, you're in the right place.

These are the exact sentences we hear on first calls. If two or three of them ring true, dcomply is the workspace you have been trying to build in a spreadsheet.

You read the draft and realised your existing IT Governance framework does not fit the new asks — SSOT, lineage, tagging-at-origination.

Your Board is asking whether you need a new committee or whether the IT Strategy Committee can absorb Data Governance.

Four new roles (Owner, Steward, Custodian, Function head) need naming per domain. You have never done a Data RACI at this granularity.

The 17 August 2026 consultation window is short. Your compliance team is not sure whether to comment on the draft, or just build against it.

Related: the RBI Compliance door covers the RBI Cybersecurity Framework, outsourcing register, and STR / CTR filings. The two modules share the same tenant and evidence store.

Your regulator stack

Here's what sits above the foundation.

The RBI Draft Guidance sits on top of DPDP and alongside the RBI Cybersecurity Framework. dcomply ships modules for each layer, so evidence produced once is reused across all three.

DPDP Act 2023 + DPDP Rules 2025
The horizontal privacy law. Notice, consent, SDF, DPIA, rights, cross-border transfers, processor obligations. The DGF operationalises these for BFSI.
RBI Cybersecurity Framework
Technical controls, cyber resilience, incident reporting. Separate module in dcomply, integrates via CERT-In audits shared with the DGF third-party register.
RBI Data Governance Framework (this door)
Board-approved DGF, Board + Executive Committees, Data Owner / Steward / Custodian RACI, SSOT, lineage, third-party controls with CERT-In audits and cascading accountability.
The Problem

The Draft Is Directional. Building Against It Is Not.

Most BFSI compliance teams are still reading the draft. The teams that start now will have a defensible programme by the time the final Guidance lands.

Data RACI at scale

Four formal roles across every data domain (customer, transaction, KYC, HR, marketing). No template. No prior discipline.

SSOT with parallel systems

Customer master lives in three systems, KYC lives in two. Designating one authoritative source needs reconciliation, not a decision memo.

Third-party accountability

Every vendor arrangement needs CERT-In empanelled audit, cascading accountability language, and auto-deletion attestation. Your contracts do not have it today.

Capabilities

Everything You Need for RBI Data Governance

Board-approved DGF policy

Applicability picker for your RE type (SCB, SFB, PB, RRB, cooperative, all NBFC layers, AIFI, ARC, CIC). Board-approval workflow with dates and status. Scope statement.

Board + Executive Committees

Committee register with type (Board / Executive), charter summary, chair, secretary, members list, cadence, last meeting, next meeting. Quarterly PDF board pack.

Data Owner / Steward / Custodian RACI

Per-domain assignment of the four RBI-defined roles. Data Function head (CGM-equivalent) named at framework level. Named individuals, not titles.

Single Source of Truth register

Domain → data element → authoritative system → reconciliation notes. One row per domain. No parallel SSOTs.

Classification + consent basis

Four-tier classification (public / internal / confidential / restricted) per domain, aligned with your DPDP Rule 6 security posture. Consent basis per domain (Section 6 or Section 7 limb).

Third-party CERT-In tracker

Vendor register with need-to-know scope, CERT-In audit status and certificate upload, encryption in transit and at rest, auto-deletion attestation, cascading accountability sign-off, NDA in place.

Readiness scorecard, live

Seven weighted checks totalling 100, mapped 1:1 to the draft. Ready / In Progress / Early / Not Started band. Refreshes automatically as you populate the registers.

Board-ready PDF pack

One-click export. Cover, readiness scorecard, framework summary, domain register, committee register, third-party register. Take to the next Board Data Governance Committee meeting.

Starter templates for BFSI

One command loads a framework, four canonical BFSI data domains (Customer Master, Loan & Transaction, KYC & AML, Marketing & Analytics), and Board and Executive committees. Edit, don't start from scratch.

Academy Lesson 8.7 — free with DPDP course

A 12-minute deep dive on the RBI DGF, mapped clause-by-clause to DPDPA. Includes a mid-sized NBFC worked example. Included in the DPDP Act 2023 course, no extra charge.

FAQ

Questions BFSI compliance leads are asking

Yes. The draft applies to all layers of NBFCs (base, middle, upper, top). Mid-layer NBFCs have the same board-level obligation as banks, though the scale of Data Function may be smaller. dcomply's applicability picker adapts the framework to your layer.

Not separately. RBI expects the role to sit at or above CGM equivalent. A CDO reporting to CIO or CRO typically qualifies, provided the CDO chairs the Executive Data Governance Committee and reports to the Board Data Governance Committee. dcomply lets you name the individual and record the designation.

Yes, if the Board expressly delegates the Data Governance mandate to it. The dcomply committee register lets you record either a new standalone committee or an existing committee with a delegated mandate. Charter language matters — the module has a template.

Cleanly. RBI DGF is DPDPA operationalised for BFSI. Existing DPIA outputs become inputs to the Board Data Governance Committee data-risk pack. Existing consent records provide the consent basis attribute per domain. dcomply auto-links where your DPDP evidence already exists in the platform.

The substantive asks (governance structures, RACI, SSOT, classification, lineage, third-party controls) are directional enough that they will not change materially. What may change is applicability thresholds and phased timelines. Build the substance now; adjust the specifics when the final text lands. dcomply will version the framework template.

Yes, through a separate RBI Compliance module that covers the Cybersecurity Framework, outsourcing register, STR / CTR filings and CERT-In incident reporting. Both modules share the same tenant, so a CERT-In empanelled audit uploaded once satisfies both.

Comments to RBI close 17 August 2026.

Start the gap assessment now. Ship the framework before the final Guidance lands.