On July 15, 2026, the Reserve Bank of India put out a draft Guidance on Regulatory Expectations for Data Governance and opened it for public comment until August 17, 2026. The list of regulated entities it covers runs from commercial banks straight through to Non-Banking Financial Companies of every size. Read that way, it is unremarkable: India's financial data rulebook is catching up to how much of that data now moves between institutions, and one rulebook for everyone reads like basic fairness. Consent, localization, breach reporting, all the same words applied to every balance sheet the RBI supervises.
It is worth slowing down on that reading. The draft does not just set rules for how data is handled. It also names the rank of the officer responsible for running the department that handles it, and that rank does not bend for size.
One officer, any size of institution
The draft requires every regulated entity, from the smallest NBFC to the largest bank, to establish a Data Function headed by an officer not below the rank of Chief General Manager or equivalent. A Chief General Manager is a senior banking rank, the kind of title a large public-sector bank hands to an officer several rungs above a branch manager. A large bank already has people at that level with headroom to take on a new mandate. A small NBFC, the sort with a handful of branches and a lean back office, does not have a CGM-equivalent officer sitting idle. It has to create the post, staff it, and give that person real authority over how the company touches data, and the draft's own text does not attach a size threshold to that requirement.
A five-branch NBFC and a nationalised bank get the identical leadership mandate.
The RBI draft's own text describes the mandate in one unqualified sentence, applied to every regulated entity on the list.
The draft is not indifferent to scale everywhere. It separately directs that each entity's data governance framework be proportionate to its own size, complexity and business model, rather than mandating identical infrastructure for a small NBFC and a large bank. That clause genuinely softens how deep the framework has to go, how many systems and controls a small lender must build. But it governs the depth of the framework, not who is required to lead it. The CGM-rank requirement is a fixed organizational cost sitting on top of a scalable one, and fixed costs do not care how big the balance sheet under them is.
The rule that reaches into co-lending
The part of the draft that lands most directly on the smallest lenders is not the leadership clause. It is the section on data shared with outside parties. The draft requires regulated entities to control data shared with third parties through customer consent, need-to-know access, non-disclosure clauses and periodic audits, including by CERT-IN empanelled auditors. That is precisely the arrangement underlying bank and NBFC co-lending, where a bank supplies the balance sheet and an NBFC or fintech partner supplies the borrower relationship and the underlying data, and the two sides pass loan and customer information back and forth continuously.
Co-lending already carries its own compliance layer. RBI's Co-Lending Arrangements Directions, 2025, effective January 1, 2026, require each regulated entity in a co-lending deal to retain a minimum 10 percent of every loan on its own books and to reflect the partner's share within 15 calendar days. The new data governance draft does not replace that layer. It adds a second one on top, specifically aimed at the data pipes the co-lending model runs on.
Small loans, thin margins
To see why that second layer bites harder on one side of the co-lending table, look at what a fintech NBFC's loan book actually looks like. Fintech NBFCs sanctioned 8.3 crore personal loans worth Rs 81,365 crore in the first nine months of FY 2024-25, an average ticket size of Rs 9,758 per loan. That is 76 percent of all personal-loan sanction volume in the market but just 13 percent of its value.

Source: FACE, sanctions through December 2024; FACE, outstanding book as of December 2024. Chart: The Signal.
The same skew shows up in the loans already on the books. Fintech NBFCs' outstanding personal-loan book stood at Rs 72,775 crore as of December 2024, spread across 4.84 crore loans. Those loans are 42 percent of all personal-loan accounts outstanding in India but just 5 percent of the value. December 2024 is the most recent breakdown FACE has published; the underlying build, small-ticket digital lending at scale, is structural rather than seasonal, so the shape of the market is unlikely to have reversed in the months since.
The same FACE report gives the wider market's totals for that nine-month sanction window: 11 crore personal loans worth Rs 6.4 lakh crore across all lenders. Divide one by the other and the market-wide average ticket works out to about Rs 58,182, our calculation from those two figures. Fintech NBFCs' own average of Rs 9,758 is roughly a sixth of that.

Source: FACE, sanctions through December 2024. Market-wide average is The Signal's calculation. Chart: The Signal.
A CGM-equivalent officer and CERT-IN empanelled third-party audits cost roughly the same in absolute rupees no matter the size of the loans on the book behind them. Spread that fixed cost across a book built on fintech NBFCs' Rs 9,758 average ticket rather than the market's roughly Rs 58,182, and it eats a much larger share of the revenue each loan generates. That is the mechanism, not a metaphor: the compliance bill is flat, the ticket size is not.
This is also the model that has been growing the fastest. NBFC co-lending assets under management were nearing Rs 1 lakh crore five years into the model, with medium-term growth momentum of 35 to 40 percent a year, a figure CRISIL published in April 2024, the most recent public estimate. A structurally higher fixed cost lands right at the point where that growth has been concentrated.
The honest objection
The strongest case against reading this as a burden on small NBFCs is the proportionality clause itself. RBI wrote the framework to scale with size, complexity and business model, and regulators do not typically legislate against their own stated intent. On this reading, the CGM-rank requirement is a floor on seniority and independence, not a demand for a large department, and a small NBFC can satisfy it with one experienced, empowered officer wearing multiple hats rather than a standing team. The Co-Lending Arrangements Directions already put skin in the game on both sides of a deal, with the 10 percent minimum retention rule applying equally regardless of which partner is larger, so the data-sharing controls in the new draft are simply extending an existing, already-balanced framework rather than inventing a new asymmetry.
That case holds for the depth of the framework. It does not answer the narrower point: the text establishing the Data Function itself carries no size qualifier, while the text on proportionality is a separate clause governing the framework as a whole. A regulator can mean for a rule to scale and still write the one line that does not. Comments on the draft are open until August 17, 2026, and whether RBI adds an explicit size threshold to the leadership requirement before finalizing it is the detail that will settle which reading holds.
The Signal
RBI's data governance draft is not written as a blow to small lenders. It is written as a uniform floor, and uniform floors are exactly where a size-blind fixed cost hides. The co-lending model those NBFCs and fintechs built their growth on runs on loans a sixth of the market's average ticket size, precisely the segment where a flat compliance bill bites hardest per rupee lent. Watch what RBI does with the comment period: an explicit carve-out or a phased threshold for the Data Function mandate would confirm the proportionality clause was meant to reach that far. Silence on that point, and the smaller lenders in India's fastest-growing lending channel absorb a senior appointment sized for a bank they are not.
Reporting basis: the terms of RBI's draft Guidance on Regulatory Expectations for Data Governance, its Data Function mandate, its proportionality clause and its third-party data-control provisions are all from RBI's own draft text and press release, a single primary origin. The Co-Lending Arrangements Directions, 2025 are separately from RBI's own notification. The personal-loan sanction and outstanding-book figures for fintech NBFCs are from FACE (the Fintech Association for Consumer Empowerment), an RBI-recognised self-regulatory organisation, drawing on Crif High Mark credit bureau data as its named source. The co-lending assets-under-management estimate is from CRISIL Ratings. The market-wide average ticket size and its comparison to the fintech NBFC average are The Signal's calculations from the total sanction count and value stated in the FACE report.



