As banks deepen their technology connectivity, operational risks tend to escalate
| Photo Credit:
Orientfootage
The RBI recently released a draft Data Governance Framework (DGF) for 11 categories of regulated entities, including commercial banks, small finance banks, payments banks, regional rural banks, urban cooperative banks, non-banking finance companies, asset reconstruction companies, and credit information companies.As banks deepen their technology connectivity, operational risks tend to escalate. Increasingly, banks have adopted interoperable technology, making data management critical for sustainability and operational efficiency. Data integrity, accuracy, traceability, storage, protection, and retrievability, with low-latency standards, have become critical for every bank in the digital age.The point is, when the banks work hard to deepen financial inclusion based on the National Strategy for Financial Inclusion – 2025-30, and with the uptick expected in business levels, the data size will go up to challenge the data management system, needing upgraded data architecture.It is estimated that the total accumulated data stored across all BFSI intermediaries in India is estimated in the Exabyte (EB) range — roughly 1.5 to 2.5 Exabytes. One Exabyte (1000 petabytes) is equal to one million Terabytes. The total operational and historical data footprint is projected to expand 3.5x to 5x, reaching upwards of 8 to 10 Exabytes by 2030. Banks will need to increase data management capacity accordingly with adequate buffers.Data consumptionOut of the data centre capacity of 1.8 Gigawatts (GW), the BFSI sector consumes 25-30 per cent of commercial data centre capacity due to regulations requiring dedicated server racks and private clouds. Data centre capacity is on track to quadruple to 6.5 to 7 GW with an incremental investment of $20-25 billion. Hence, banks are setting up expanded sites in Tier II and Tier III cities to park their data for fallback.The new DGF, where banks are already building unified data hubs, will ensure that risk, reporting, and customer data originate from a single designated system rather than from conflicting departmental databases. The combined push from the DPDP Act, 2023, and RBI’s data localisation rules strictly require personal data, payment records, and customer profiles to be processed and stored exclusively within Indian geographical boundaries.The primary objective of DGF is to: (i) promote sound data practices; (ii) mitigate operational and systemic risks; (iii) align with privacy laws; (iv) protect data to comply with the DPDP Act, 2023.A two-tier governance and leadership structure will be enforced, where a board-level data governance committee will be supported by an executive committee dedicated to data management. There will be clear delineation between data owners (defining quality, classification, and usage), data stewards (day-to-day management), and data custodians (technical controls and storage).When data quality and integrity standards improve, risk assessment systems and risk management strategies will be effective. Before the final guidelines are issued by the RBI, banks should use the window to reform the data management architecture to ensure that the new DGF is implemented in both letter and spirit, going beyond compliance to turn it into a multi-pronged tool to ring-fence against risks.The writer is an Adjunct Professor, Institute of Insurance and Risk Management. The views are personalPublished on July 31, 2026








