Listen to this post

Summary: SEBI has recently proposed an overhaul of the Portfolio Managers Regulations, opening doors that have stayed shut until now. Discretionary portfolio managers may soon be allowed to invest in pre-IPO securities and unlisted debt, while portfolio managers more broadly may be permitted to invest in overseas markets. A new, low-entry “MF-PMS” category is proposed for mutual-fund-only portfolios, alongside looser derivative limits for discretionary portfolio management and a fresh route for independent fund managers to operate under registered PMS players. But it’s not just about new investment avenues, Principal Officer qualifications, net worth requirements, and even the definition of “related party” are all set to change too. If implemented, these reforms could reshape how discretionary and non-discretionary portfolio management services operate in India, making the industry more innovative and investor-friendly.

Continue Reading SEBI’s Proposed Overhaul of the PMS Regulatory Framework
Listen to this post
Research Rejuvenated: ANI v. Open AI and the DPDPA

Summary: This article examines the Delhi High Court’s judgement in ANI v. Open AI as more than a copyright ruling, arguing that its reasoning on what constitutes “research” offers a persuasive analytical framework for one of the central uncertainties under the DPDPA: whether commercial AI model training can qualify for the Act’s research exemption. It contends that the Court’s purpose, fairness and public interest test, while developed under Section 52(1)(a) of the Copyright Act, translates naturally to Section 17(2)(b) of the DPDPA, and removes a significant conceptual obstacle to treating AI training as research under data protection law. It will be relevant to readers tracking the evolving Indian jurisprudence on AI and its intersection with copyright and data protection law.

Continue Reading Research Rejuvenated: ANI v. Open AI and the DPDPA
Listen to this post
Securities Markets Code, 2025: Simplifying the fault line

Summary: The Securities Markets Code Bill, 2025, introduced Clause 92 and Clause 93 as parallel provisions to govern fraudulent and unfair practices and market abuse, respectively. The Parliamentary Standing Committee, in its recently released report on the Bill, found that the distinction between the two clauses was unclear, and allowing the Securities and Exchange Board of India to expand the definition of criminal market abuse through delegated legislation raised serious constitutional concerns. The Committee has recommended a series of targeted amendments to Clause 93 to confine criminal liability to conduct that is grave, willful, and systemic in nature, to delete the residuary rule-making power under Clause 93(g), and to ensure that these changes are carried through into the Prevention of Money-Laundering Act, 2002, schedule. This blog examines each of these recommendations and their practical significance for market participants, intermediaries, and their advisors.

Continue Reading Securities Markets Code, 2025: Simplifying the fault line
Listen to this post
ANI v. Open AI: Delhi High Court Refuses Interim Injunction in Landmark AI Copyright Dispute

Summary: The Delhi High Court has refused ANI Media’s interim injunction application against OpenAI holding on a prima facie basis that the scraping and storage of copyrighted content to train LLMs constitutes fair dealing under Section 52(1)(a) of the Copyright Act, 1957. The ruling, India’s first major judicial decision on AI training and copyright, signals a broad pro-AI path, though substantive questions remain open for trial.

Continue Reading ANI v. Open AI: Delhi High Court Refuses Interim Injunction in Landmark AI Copyright Dispute
Listen to this post
An Insolvency Regulator as Valuation Authority? Rethinking Clause 73 of Corporate Laws (Amendment) Bill, 2026

Summary: Clause 73 would make the Insolvency and Bankruptcy Board of India the country’s statutory Valuation Authority. The profession needs a regulator, but the insolvency regulator may be the wrong home for it, as India’s own expert committee and the practice of comparable jurisdictions suggest.

Continue Reading An Insolvency Regulator as Valuation Authority? Rethinking Clause 73 of Corporate Laws (Amendment) Bill, 2026
Listen to this post
NFRA Reimagined: What the 2026 Amendment Bill means for Boards, Audit Committees, and Auditors

Summary: NFRA is fast becoming the new benchmark of governance for audit quality, financial reporting and audit committee oversight. This blog examines how the Corporate Laws (Amendment) Bill, 2026 proposes to strengthen NFRA’s framework, why this matters for boards, audit committees, in-house counsel and auditors, and what companies should do to prepare.

Continue Reading NFRA Reimagined: What the 2026 Amendment Bill means for Boards, Audit Committees, and Auditors
Listen to this post
FIG Paper No. 61: RBI’s Draft Data Governance Guidance: An Overview

Summary: The RBI has released the Draft Guidance on Regulatory Expectations for Data Governance, proposing a comprehensive enterprise-wide framework applicable across banks, NBFCs, payment banks, co-operative banks, CICs, and other regulated entities. The Draft Guidance emphasises board oversight, defined data governance roles, lifecycle-based controls, SSOT architecture, metadata and lineage management, data classification, data quality processes, and governance of third-party data sharing. The proposal reflects increasing regulatory focus on data as a core prudential and operational asset and aligns with international frameworks such as BCBS 239. Comments on the draft can be submitted until August 17, 2026.

  1. On July 15, 2026, the Reserve Bank of India (“RBI”) published the Draft Guidance on Regulatory Expectations for Data Governance (“Draft Guidance”).[1] The framework seeks to strengthen the reliability, consistency, availability, traceability, and security of data across regulated entities (“REs”).[2] It is intended to be read alongside existing RBI directions, which will continue to prevail in the event of any inconsistency. The Draft Guidance draws upon supervisory observations, stakeholder engagement, and international standards, including the Basel Committee on Banking Supervision’s “Principles for Effective Risk Data Aggregation and Risk Reporting” (BCBS 239).[3]
  2. At the governance level, the Draft Guidance requires every RE to establish a Data Governance Framework (“DGF”) covering all organisational data. The DGF must be proportionate to the size, complexity, and business model of the institution and aligned with applicable legal and regulatory requirements.
    • The Draft Guidance envisages a three-tier governance structure. The Board is required to oversee the DGF, while a dedicated Data Governance Committee (“DGC”), or an existing board committee, is tasked with policy oversight and review of governance metrics.
    • At the management level, a Data Governance Executive Committee (“DGEC”) must operationalise the framework, address data governance gaps and oversee implementation across functions.
    • Data risk management is expected to form part of an RE’s broader risk management framework. RBI identifies seven foundational principles for effective data governance: accountability, integrity, auditability, transparency, traceability, proportionality, and standardisation.
  3. At the organizational structure level, the Draft Guidance requires REs to establish a dedicated ‘data function’ headed by a sufficiently senior officer. In addition, each data domain must have clearly identified ‘data owners’, ‘data stewards’, and ‘data custodians’. Data owners are responsible for data governance outcomes within their domain, including classification, quality and oversight of data usage; data stewards support day-to-day implementation and monitoring of governance requirements; and data custodians are responsible for the technical management of data systems and controls, including access management, security, retention and business continuity measures. Together, these roles are intended to create end-to-end accountability covering business ownership, operational implementation, and technical management of data assets.
  4. The RBI has also proposed a lifecycle-based approach to data governance. Data must be created or collected only for legitimate and defined purposes, with key attributes such as ownership, classification, usage intent, and customer consent recorded at the point of collection where relevant. Appropriate controls are expected to apply through subsequent stages of processing, sharing, transformation, retention, and disposal.
  5. The Draft Guidance places particular emphasis on data architecture, with the following expectations:
    • It requires REs to establish and maintain a single source of truth (SSOT) for data elements, supported by reconciliation mechanisms to identify inconsistencies. It permits centralised, federated, or hybrid implementation models, provided the REs ensure a clearly identifiable authoritative source and traceability across downstream systems and reporting layers.
    • It requires comprehensive metadata management and data lineage capabilities. The REs must ensure foundational metadata is captured at source, preserved through downstream processing, and updated when data is transformed or derived. They must establish data classification frameworks to account for criticality, sensitivity, confidentiality, and regulatory relevance, enabling risk-based controls across the data lifecycle.
    • Data quality management forms another key element of the proposal. It expects REs to maintain data quality metrics, establish remediation processes, and ensure that deficiencies do not adversely affect decision-making, risk management, or regulatory reporting. The REs must report persistent quality issues periodically to the board-level governance structure.
  6. The Draft Guidance also addresses third-party data sharing. It requires REs to remain accountable for data shared with external service providers and group entities and must implement controls governing access, usage, retention, deletion, and monitoring. The REs should ensure shared data remains traceable to the designated SSOT and is subject to appropriate contractual, technical, and audit safeguards.

The Draft Guidance represents a comprehensive data governance framework. While larger institutions may already maintain elements of such a framework, the proposed requirements will necessitate enhancements to data governance processes, documentation standards, metadata and lineage capabilities, data quality monitoring mechanisms, and technology infrastructure. The consultation process is, therefore, likely to focus on proportional implementation, operational feasibility, and phased adoption timelines across different categories of REs.


[1] ‘Draft Guidance on Regulatory Expectations for Data Governance’ published by RBI on July 15, 2026, accessible here.

[2] This Guidance is applicable to following REs of the Reserve Bank of India: (i) Commercial Banks (including Foreign Banks); (ii) Small Finance Banks; (iii) Payments Banks; (iv) Local Area Banks; (v) Regional Rural Banks; (vi) Urban Co-operative Banks; (vii) Rural Co-operative Banks; (viii) Non-Banking Financial Companies in Base Layer, Middle Layer, Upper Layer, and Top Layer; (ix) All-India Financial Institutions, viz., EXIM Bank, NABARD, NaBFID, National Housing Bank and SIDBI; (x) Asset Reconstruction Companies registered with the RBI; and (xi) Credit Information Companies.

[3] Basel Committee on Banking Supervision’s ‘Principles for Effective Risk Data Aggregation and Risk Reporting’ (BCBS 239), January 2013, accessible here.

Listen to this post

Device Locking in Digital Lending: Welcoming the New Recovery Agent in Town

Summary: The Reserve Bank of India has proposed a formal framework for deployment of device-based restrictions in smartphone financing. This tool has been in operation for a while now and regulation is only just catching up. The Draft Amendments may have gotten the architecture right: controlled permission, not prohibition. However, does the proposal strike the right balance between borrower protection and lending viability?

Continue Reading Device Locking in Digital Lending: Welcoming the New Recovery Agent in Town
Listen to this post
Rethinking Open-Offer Financing: The Impact Of RBI’s Acquisition Financing Liberalisation

Summary: Indian banks are now permitted to finance acquisitions of ‘control’ over target companies, marking the most significant liberalisation of acquisition financing in India in decades. However, where the target is a listed company, the mandatory open offer obligations under the SAST Regulations introduce a series of interpretive questions regarding the interplay between the CF Directions 2026 and the open offer financing obligations.

Continue Reading Rethinking Open-Offer Financing: The Impact Of RBI’s Acquisition Financing Liberalisation
Listen to this post
Gujarat Data Center Policy 2026-2029: A Push For Large-Scale Data Center Infrastructure

Summary: The Gujarat Government has unveiled the Viksit Gujarat Data Center Policy 2026-2029 (“Policy”), to promote hyperscale and colocation data centers in the state, marking a significant shift from its earlier incentive regime for data center projects under the IT/ITES Policy 2022-2027. While the previous framework supported relatively smaller projects through a limited capital and power subsidy model, the new Policy is designed for hyperscale/ large data center developments with a minimum installed IT load capacity of 150 MW. It introduces a substantially enhanced incentive package comprising long-term power-related benefits, interest subsidies, GST reimbursements, support for allied infrastructure such as battery energy storage systems and desalination plants, and various regulatory relaxations. With this Policy, Gujarat aims to attract hyperscale/ large, capital-intensive data center projects and compete with other leading data center hubs in the country.

Continue Reading Gujarat Data Center Policy 2026-2029: A Push For Large-Scale Data Center Infrastructure