Skip to content

Governing data risks in the age of AI

Sep 2026 · Journal of financial compliance · 0 citations

TL;DR

This paper proposes a practical, audit-ready approach to governing data risks in the AI era, and introduces the concept of critical data elements (CDEs): data elements whose inaccuracy, unavailability, or misuse can produce material regulatory, financial, or customer-facing impact.

Abstract

Artificial intelligence (AI) and in particular generative AI (GenAI) has accelerated data risk in financial services by changing how data is accessed, transformed, and used to drive decisions that regulators closely scrutinise. The pace of AI adoption has outrun many organisations’ data control foundations: AI tools frequently require broad access to data systems, deepen reliance on third-party vendors, and create new pathways through which sensitive data can leak, via prompts, model outputs, automated retrieval processes, and AI-driven actions. At the same time, regulatory expectations for data accuracy, completeness, timeliness, and traceability remain uncompromising, particularly for high-stakes use cases such as capital and liquidity management, regulatory and financial reporting, and financial crime detection. This paper proposes a practical, audit-ready approach to governing data risks in the AI era. The central idea is to add a second lens to traditional data classification, one focused on business consequence rather than confidentiality alone. Specifically, it introduces the concept of critical data elements (CDEs): data elements whose inaccuracy, unavailability, or misuse can produce material regulatory, financial, or customer-facing impact. Pairing CDE designation with conventional confidentiality classifications creates a dual-axis model that directs the strongest controls to the highest-consequence data, even when that data may not appear sensitive on the surface. Drawing on established regulatory frameworks including BCBS 239 (risk data aggregation and reporting), SR 26-2 (model risk management, the interagency guidance issued jointly by the Federal Reserve, Office of the Comptroller of the Currency (OCC), and Federal Deposit Insurance Corporation (FDIC) in April 2026, superseding SR 11-7), and US interagency third-party risk guidance, the paper explains why AI amplifies data risk across four dimensions (privacy, security, integrity, and accountability), and presents an eight-domain data governance framework with concrete audit evidence examples. The goal is to equip compliance, risk, and audit leaders with a repeatable structure for demonstrating that AI innovation rests on controlled, auditable data foundations. This article is also included in The Business & Management Collection which can be accessed at http://hstalks.com.business/.

View source

Similar papers

Review Aug 2026

Artificial Intelligence in Financial Decision-Making: Opportunities, Risks, and Challenges

The dual nature of AI adoption in finance is examined, with AI materially improves predictive accuracy, operational efficiency, and access to financial services, with adoption accelerating sharply since the introduction of generative and agentic AI tools.

Abhishek Rajan · 0 citations
Conference Aug 2026

A Data-Driven AI Framework for Governance and Decision Intelligence in Financial Services

Financial services companies are swiftly utilizing artificial intelligence (AI) for essential functions such as risk assessment, fraud detection, credit scoring, and regulatory compliance. Many current AI-driven financial systems lack regulation, transparency, and real-time decision-making capabilities, hence undermini...

Vishnu Kiran Bollu, Vigneshwar Rangini · 0 citations
Review Sep 2026

The role of AI in sourcing and mining data to identify, secure and manage relevant evidence: Is it really the panacea it claims to be?

The rapid expansion of digital data has transformed the demands of modern legal practice, particularly in investigations, regulatory enquiries, and disputes. This paper examines the evolving role of artificial intelligence (AI) — especially generative AI (GenAI) — in sourcing, analysing, and managing evidence within th...

Catherine Bellsham-Revell, Karie Twinem · 0 citations
Sep 2026

AI risk management for insurers

Artificial intelligence (AI) is rapidly reshaping the UK insurance sector, offering significant opportunities for efficiency, innovation, and improved customer outcomes. At the same time, AI introduces complex and fast-moving risks relating to model opacity, bias, data protection, consumer fairness, operational resilie...

Martha Phillips, Michelle Gabay · 0 citations
#explainable ai Review Open access Sep 2026

The Role of AI in Enhancing Financial Decision-Making in Commerce

Financial decisions in commerce—whom to lend to, what to stock and at what price, when to hedge, which transactions to flag—have always been made under uncertainty, time pressure and cognitive limitation. Artificial intelligence (AI) alters this situation by sharply reducing the cost of prediction and by extracting sig...

Prof. (Dr.) Smruti Ranjan Rath, Dr. Madhabi Mehta, Ejim Kenneth Ejimne³, Ram Prakash Yadav · 0 citations
Sep 2026

The hidden barrier to AI success: Trusted data foundations

Artificial intelligence (AI) has reached a critical inflection point in financial services. Despite its extraordinary promise, most AI initiatives in post-trade operations struggle to move beyond experimentation. This paper sets out to address that gap within post-trade operations, where accuracy, predictability, and c...

Andy Grayland · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.