New Guidelines Explained | How Can Banks Implement Data Classification and Grading?
2026-08-03

In June 2026, six Chinese authorities jointly issued the Guidelines for the Classification and Grading of Financial Information Services Data (the “Guidelines”), further clarifying the methodology and management requirements for classifying and grading financial information services data. The official release is available from the Cyberspace Administration of China.

What are the key requirements under the Guidelines? How can banks translate them into effective implementation? Drawing on the key provisions of the Guidelines, RIKING provides the following overview.

Key Requirements under the Guidelines

1. Data Classification — Defining What the Data Is

Financial information services data may be classified according to its business attributes.

At the top level, data is divided into three categories: business data, user data and enterprise data. These are further broken down into nine second-level categories and 67 third-level categories.This framework provides financial institutions with a common language for data management and a standardised foundation for data sharing, data governance and security management.


2. Data Grading — Defining How the Data Should Be Managed

The Guidelines divide financial information services data into four grades, from highest to lowest: core data, important data, sensitive general data and ordinary general data.

The appropriate data grade should be determined through a comprehensive assessment of three dimensions:

  • Grading factors: Data coverage, time span, granularity, public availability, geographic scope and other relevant factors.
  • Affected interests: The parties or interests that may be affected by a data security incident, including national security, economic operations, social order, public interests, organisational rights and interests, and individual rights and interests.
  • Severity of impact: The potential harm caused by data leakage, tampering, destruction, unlawful acquisition, unlawful use or unlawful sharing. The severity of impact is classified as particularly severe harm, severe harm or general harm.


3. Data Classification and Grading Process

Data resource inventory and mapping → Data classification → Data grading → Preparation of the data classification and grading register → Submission of the important data catalogue → Ongoing updates and management

How Can Banks Put Data Classification and Grading into Practice?

The Guidelines provide financial institutions with a relatively comprehensive implementation path. For banks, however, the real priority is not to complete a one-off classification and grading exercise, but to translate the Guidelines into sustainable data governance capabilities.

Based on the implementation process set out in the Guidelines, banks should focus on the following four areas.

1. Build a Comprehensive Data Inventory

A comprehensive data inventory is the starting point for classification and grading.

Banks should systematically map data assets across business systems, databases, data tables and data elements. They should also identify data sources, business attributes, accountable departments and data flows.

The results should be consolidated into an enterprise-wide data asset catalogue, providing a reliable foundation for subsequent classification and grading.

2. Establish Consistent Classification and Grading Rules

Banks should establish enterprise-wide rules and standards for data classification and grading.

This helps prevent inconsistent classification standards and grading criteria across business units and systems, ensuring that the results remain consistent and reusable throughout the organisation.

3. Establish Lifecycle Management for Dynamic Governance

Once classification and grading have been completed, banks should establish a data classification and grading register and an important data catalogue.

The relevant requirements should also be embedded into data standards, data quality management, metadata management, regulatory reporting and other data governance processes.

At the same time, banks should establish a dynamic update mechanism to continuously maintain classification and grading results as business operations, systems and data assets evolve, ensuring ongoing alignment with the Guidelines.

4. Explore AI-Enabled Data Governance

With the rapid development of large language models, banks can explore building AI-powered data governance assistants.

AI can support classification recommendations, regulatory and policy interpretation, data standard queries and rule validation, helping improve both the efficiency and consistency of classification and grading.

Building on the unified framework established by the Guidelines, AI can further advance data governance towards greater intelligence and automation, providing a more trusted data foundation for regulatory compliance and data applications.

RIKING Solution for Financial Data Security Classification and Grading

Drawing on years of experience in financial data governance, RIKING provides an integrated data classification and grading solution covering consulting and planning, data asset governance, rule development, AI-powered identification, workflow management, security integration and continuous operations.

The solution helps financial institutions implement the entire process—from framework design and data inventory mapping to platform development, data classification and identification, workflow management and ongoing operations.

Supported by unified data asset management, a consistent classification and grading framework, and AI-powered identification capabilities, RIKING enables full-lifecycle management of data classification and grading.

It also connects classification and grading results with data masking, database encryption, access control, risk monitoring, regulatory reporting, data sharing and AI applications, helping financial institutions build a unified, trusted and sustainable data security governance framework.