FinBox Research

The RBI just made "source of truth" a regulatory requirement

Ask your credit team what a borrower owes today. Then ask your collections team. If the answers don't match, this week's RBI proposals are about you.

The RBI just made "source of truth" a regulatory requirement


Hello everyone, 

Welcome to the 212th edition of The Pattern. 

Before we get into this week's topic, try something. 

Ask your credit team what a specific borrower owes today. Then ask your collections team the same question. 

If you've ever asked around, you've probably heard two different answers. It's rarely because someone made a mistake. More often, it's because each team is working from its own version of the data. 

Pick one number and stick to it 

The Reserve Bank of India has proposed a governance framework for how banks, NBFCs and other regulated entities manage data across its lifecycle. The draft norms, open for public comments until August 17, require entities to establish Board-approved Data Governance Frameworks, designate data owners and custodians, create Board and executive-level data governance committees, and maintain a 'Single Source of Truth' (SSOT) to ensure consistency, traceability and quality of data used for business, regulatory reporting and decision-making. 

Read between the lines and it's easy to see why this matters. The same customer's income can look different in the LOS and the core banking system. A loan might appear current in one dashboard and overdue in another. That doesn't necessarily mean anyone's doing anything wrong. Different systems are updated at different times, serve different purposes or maintain their own copies of the data. The problem starts when different teams begin making decisions using different numbers. 

The draft also puts names to responsibilities. 

  • Data Owner is responsible for defining a data domain, maintaining its quality and deciding which system serves as its single source of truth. 
  • Data Steward keeps those standards working in practice, maintaining definitions, monitoring data flows and resolving issues across teams. 
  • Data Custodian looks after the technical side, securing the data, managing access and maintaining the metadata and lineage needed to trace it back to its source. 

The responsibility doesn't stop when the data leaves your systems. Share customer data with a bureau, a collections partner or a TSP, and you're still expected to know who has it, why they have it and how it traces back to your own records. 

It's the same ownership question CROs are already asking about their credit decisioning stack, not just raw data. Who owns the policy logic, who owns the pipeline, who can walk an NPA cohort back to the exact rule that let it through. I wrote about that split in Who Owns the Credit Decisioning Platform — Risk or IT — and How CROs Use It to Cut NPA, and this draft is asking lenders to build the same muscle for data as a whole. If someone asked you right now which system holds the real number for a specific borrower's income, would you know who to call? 

A house you're never allowed to sell back 

When a borrower defaults, the bank may have to take possession of the house, shop, or land pledged as collateral. But banks aren't in the business of owning property. They sell the asset to recover the money they're owed. 

The RBI has now drawn a clear line around who those assets can be sold to.  

Under the finalised Resolution of Stressed Assets Directions, 2025, banks and NBFCs can no longer sell a seized property back to the defaulting borrower or anyone related to them. Not after a cooling-off period. Not once the loan is no longer classified as stressed. Simply not at all. 

The rule comes into effect on October 1, 2026. 

The directions also tighten how lenders manage these assets from the moment they're acquired until they're eventually sold. 

That means: 

  • A board-approved policy for acquiring and disposing of these assets. 
  • A cap on how much of the balance sheet they can occupy. 
  • A fresh valuation every two years using a distress-sale basis. 
  • A maximum holding period of seven years before they're disposed of. 

Assets already sitting on lenders' books have until September 2027 to comply. 

Answer before you're asked 

Seen together, these aren't two separate stories anymore. A single source of truth is really an admission that banks have been sitting on two versions of reality and letting whichever one was more convenient pass for official. The seized-asset ban comes from the same place. Once collateral leaves the official books, there was nothing stopping it from finding its way back into the wrong hands. Either way, the RBI wants the same thing: proof, not an explanation after the fact. 

This goes beyond compliance. It's about being able to explain your decisions when it matters. 
 
FinBox's own early-warning work on transaction pattern clustering, for instance, is built around the same idea: catching signs of distress in a borrower's account weeks before they miss an EMI, rather than reconstructing what happened once they already have. 

Expect to see more regulations that ask the same question in different ways: can you prove what happened, or can you only explain it after the fact? 
 

Reading list 

 

Thank you for reading. If you liked this edition, forward it to your friends, peers, and colleagues. You can also connect with me on X here and follow FinBox on LinkedIn to get the latest updates. 

Cheers,  
Mayank 

All opinions expressed are my own and do not necessarily reflect the views of FinBox or its promoters. 

Share
Still exploring this topic?
Get instant, cited answers from the FinBox lending knowledge base

Stay current

Get research like this in your inbox.

Join 5,000+ lending professionals who read FinBox's research on credit infrastructure, underwriting, and embedded finance.

Subscribe free
Mayank Jain
Mayank Jain

Head - Marketing and Content