For over a decade, financial regulators worldwide have progressively strengthened expectations around enterprise data governance. Yet, one lesson has emerged consistently. That defining sound governance principles is considerably easier than embedding them into institutional practice.
The Basel Committee’s 2023 review on implementation of the Principles for Effective Risk Data Aggregation and Risk Reporting (BCBS 239) found that almost a decade after their issuance, no Global Systemically Important Bank had demonstrated full and sustained compliance across all principles. This finding reinforces an important reality: the fundamental constraint in enterprise data governance today is ‘implementation’, rather than conceptual understanding.
The Reserve Bank of India's Draft Guidance on Data Governance, issued for comments on July 15, 2026, should be viewed against this backdrop. The draft represents the culmination of RBI's steadily evolving governance expectations across information technology, cybersecurity, outsourcing, digital lending, operational resilience, supervisory reporting and, more recently, artificial intelligence and model risk management. Collectively, these frameworks have transformed data from an operational resource into a strategic institutional asset, mirroring the transformation of banking itself. This marks an important inflection point where enterprise data becomes the object of governance, rather than just remaining an input.
The core disciplines underlying effective governance, however, have remained remarkably constant irrespective of the subject being governed. Corporate governance, operational risk, information security and ED governance, all ultimately depend upon the same principles, viz., board oversight, clear accountability, transparent ownership, effective controls, independent assurance and continuous monitoring. However, the challenge confronting regulators is ensuring that they reliably translate into organisational capability.
This has important policy implications. Principles establish intent, but do not necessarily ensure consistent implementation. Equally, detailed prescriptions often encourage mechanical compliance constraining innovation. The next stage of regulatory evolution has to lie between these two extremes. The emerging requirement, therefore, is an implementation architecture that enables institutions to operationalise principles fully while retaining proportional flexibility.
‘Implementation architecture’ differs fundamentally from regulation. It provides a common implementation language through shared taxonomies, indicative governance artefacts, reference architectures, ‘critical data’ methodologies, metadata standards, lineage expectations, maturity models, supervisory assessment criteria, and so on. While institutions remain free to determine how these capabilities are implemented, supervisors gain greater consistency in governance outcomes across diverse business models. Such an approach preserves the spirit of principles-based regulation without fragmenting implementation standards across institutions.
This is most evident in enterprise data quality, which has evolved into a strategic capability determining whether information can be trusted for regulatory reporting, risk management, customer service, AI model training or strategic decision-making. The objective of governance is no longer just accurate data, but data whose provenance, integrity and fitness for purpose, remain demonstrable throughout its lifecycle. In this context, reference may also be made to my article, Why Data must become the Strategic Core of Modern Banking, published by BasisPoint Insight on July 14, 2025.
This distinction also highlights the difference between measuring and assuring data quality. Measurement determines whether data satisfies predefined standards at a given point in time. Assurance determines whether processes can consistently preserve those standards as business models, technologies and data ecosystems evolve. Increasingly, the supervisory question will become, "Can the institution demonstrate that its governance framework will keep the data trustworthy tomorrow?" rather than simply, "Is the data accurate today?"
Accordingly, without compromising the principles-based philosophy, the final guidance could be complemented by illustrative implementation approaches, more granular supervisory expectations and indicative assessment parameters that help institutions distinguish between foundational, adequate and mature governance practices. This would enable the regulated entities to prioritise investments more effectively. Similarly, stated common minimum expectations will enhance regulatory effectiveness and allow governance capabilities to scale according to institutional complexity, systemic importance and data intensity.
Questions relating to metadata adequacy, sufficient lineage, data quality acceptability and control effectiveness, remain open to institutional interpretation resulting in varying levels of implementation maturity. Smaller institutions also lack specialised resources for sophisticated repositories and governance platforms. A useful addition, thus, would be an indicative Data Governance Maturity Framework which enables institutions to progress through successive stages, from foundational to mature managed capabilities, and provides structured implementation roadmaps without compromising optionality.
Equally important is aligning enterprise data governance with the DPDP Act. While the draft exhorts compliance with the Act, it must strengthen this objective by recognising enterprise data governance as the operational foundation for meeting obligations on lawful processing, consent, privacy, retention and deletion of personal data. This integration would reduce duplication, strengthen accountability, customer trust and regulatory compliance. Future iterations of the guidance may also elaborate governance expectations on training datasets, derivation, representativeness, and synthetic and unstructured data for governance to evolve in real-time.
Objective indicators such as data quality scorecards, governance effectiveness metrics, data risk indicators, and Board-level reporting criteria that demonstrate whether governance is functioning as intended, can serve as tangible evidence of operational capability. Further, a survey of prevailing practices would provide valuable insights into the current state of implementation and enable more efficient utilisation of resources by both the REs and supervisors by allowing institutional efforts and supervisory focus to be directed toward areas requiring the greatest attention.
Good governance establishes robust architecture which enables reliable and accountable execution. Good supervision creates confidence in the trustworthiness of enterprise data. Sustainable enterprise data governance emerges only when all these elements operate as integrated institutional capability. The future of enterprise data governance will, therefore, not be determined by the sophistication of technology or the volume of data that institutions possess. It will be decided by confidence that the Boards, customers, regulators and markets are able to place in that data.
*Views expressed are personal