In Episode 1 we mapped DPDP against RBI, SEBI, PMLA and CERT-In, and set the rule: DPDP layers on top, and where regimes touch the same control, the stricter one binds.
Continuous governance is not a philosophy for BFSI. RBI mandates continuous auditing. SEBI mandates continuous monitoring and a measurable maturity score. CERT-In mandates 180 days of logs in India. DPDP extends the same evidentiary discipline to personal data. This is the baseline your supervisor already expects.
Why manual compliance collapses in regulated finance
Every company outgrows spreadsheets. Financial entities outgrow them faster, for structural reasons.
The failure mode is not missing controls. It is unprovable controls. SEBI asked you to prove security on a schedule examiners can read. DPDP does the same for personal data.
What your regulators already mandate
Four regulators already told you to run continuously. The work is unifying mandates that overlap by about 70%, not inventing a new model.
A mid-sized NBFC with a broking arm is being told to do the same thing four times. Continuous governance is how you stop.
Collect evidence once. Map it many times.
SEBI's 28 August 2025 CSCRF clarifications added Equivalence: where similar controls are already mandated by another regulator, that compliance can count under CSCRF. Exclusivity narrows CSCRF to systems used exclusively for SEBI-regulated activities. The control is the unit of compliance, not the framework.
Design one control library, one evidence pipeline, many framework mappings. Contradictory policies across regimes are themselves an enforcement exposure.
Data discovery in a real BFSI estate
Classify each dataset on four axes: category and sensitivity, purpose, system location and owner, processor involvement.
Cores predate consent granularity. Realistic answer: a consent management layer between customer apps and the core, enforcing purpose at the boundary the core cannot.
Fraud data later feeding collections breaches RBI conduct and DPDP purpose limitation. Purpose mapping catches drift before a regulator does.
Consent as a machine-readable artefact
BFSI already has the blueprint. Account Aggregator (DEPA) runs on a consent artefact with purpose, categories, validity, recipients, signature, notification, and revocation. DPDP Rules 3 and 4 generalise that pattern. Stop designing consent as a boolean. Design it as an artefact.
Near-term forcing function: NBFC Responsible Business Conduct consent rules from 1 July 2026. Build to the artefact standard once.
Wire rights into RBI machinery. Do not rebuild it.
You already run nodal officers, Internal Ombudsman, and RBI CMS. Integrate DPDP into that stack: dual categorisation at intake, stricter timeline (DPDP caps at 90 days), and automated fulfilment with evidence.
Nomination has no GDPR analogue. It needs a real product surface. Easy to forget, trivially auditable.
Retention orchestration (preview of Episode 3)
Field-level reconciliation, not a policy paragraph. Legal obligation lets you refuse erasure for regulated fields only if you erase non-essential fields, document the basis, and prove both.
Continuous detection: the clock starts whether you are watching
Your detection capability, not your policy library, determines whether you can comply. One trigger, one runbook, four channels with pre-drafted templates.
Vendor, LSP and processor governance
ITGRCA requires vendor risk including concentration and SPOF. Outsourcing never diminishes your obligations. CSCRF adds SBOM for critical apps. DPDP Rule 6 makes processor contracts mandatory. Contract processors to notify you within one hour. Your six-hour clock does not wait for theirs.
Measure with metrics regulators already ask for
Do not invent a scorecard. SEBI published the Cyber Capability Index. A maturity score you cannot evidence is worse than no score at all.
The continuous governance operating model
Source systems feed a framework-agnostic control library and continuous evidence pipeline, then map out to RBI, SEBI, DPDP, CERT-In, and ISO / SOC 2.
| Function | Board | CISO | DPO | Eng | Compliance |
|---|---|---|---|---|---|
| IT & cyber policy (ITGRCA) | A | R | C | C | R |
| Consent artefact & ledger | I | C | A | R | C |
| Retention matrix & erasure | I | C | A | R | R |
| SOC / detection & CCI | A | R | C | C | C |
| Breach fan-out (4 clocks) | I | R | R | C | A |
| Vendor / LSP risk | A | R | C | C | R |
If you are an SDF, the DPO's Board reporting line hard-wires privacy into governance.
The first 90 days
See it, unify it, automate it. Then use the runway to July 2026, November 2026, and May 2027 to harden, not scramble.
Explicit, per-product, affirmative consent with withdrawable audit trail.
Interoperable give, review, manage, withdraw consent.
Harden on the runway. Do not scramble.
Compliance as a commercial asset
Bank partners and co-lenders run the same questionnaires. An evidenced maturity score answers in days, not quarters.
Evidence collected continuously is evidence you do not reconstruct under deadline.
Privacy and security review becomes a gate the pipeline already satisfies.
Demonstrable, evidenced maturity beats attestations alone.
Next: Episode 3 on data retention and deletion, the field-level reconciliation of DPDP erasure against RBI KYC, PMLA and SEBI retention. This episode reflects DPDP Rules 2025, RBI ITGRCA Directions 2023, Digital Lending Directions 2025, SEBI CSCRF (as amended through Aug 2025), NBFC-AA / ReBIT specs, and CERT-In 2022 Directions. General information only, not legal advice.