Blogs and News

Stay updated with the latest insights, news, and best practices on data governance, regulatory compliance, and AI-powered solutions.

Your Perimeter Is Wherever Your Data Sits
Data GovernanceRegulatory Compliance
Jul 23, 2026

Your Perimeter Is Wherever Your Data Sits

A bank can pass every internal security review and still end up defending a class action because a vendor got breached. When customer data moves through a third party, the liability doesn't move with it.

by CoComply Team

Read More
Every Exception You Approved Is Now Your Policy
Risk Data AggregationData Observability
Jul 17, 2026

Every Exception You Approved Is Now Your Policy

A $60 billion commercial bank went into its annual internal audit confident. Its data governance policy was mature, board-approved, and well documented. Every control had an owner. Every standard had a threshold. Then the auditors pulled the exception log.

by CoComply Team

Read More
The Audit Trail Is Not a Compliance Artifact. It Is a Competitive Weapon.
Data LineageData Observability
Jul 14, 2026

The Audit Trail Is Not a Compliance Artifact. It Is a Competitive Weapon.

Wells Fargo's 2022 consent order for data governance deficiencies included a specific citation that most banks overlooked: the bank could not demonstrate, through auditable records, that its risk data aggregation met BCBS 239 standards during stress events. The fine made headlines. The specific failure did not. But that specific failure is the one that should concern every Tier 2 bank right now, because it signals what regulators are actually testing for.

by CoComply Team

Read More
Data Stewardship Programs Die for One Reason: They Confuse Ownership with Volunteering
Risk Data AggregationData Management
Jul 13, 2026

Data Stewardship Programs Die for One Reason: They Confuse Ownership with Volunteering

In 2022, a $35 billion-asset Midwest bank launched a data stewardship program with great fanfare. Forty-five stewards were appointed across business lines. Training was delivered. A stewardship council was formed. Eighteen months later, 31 of the 45 stewards had either left the role or stopped participating. The council had not met in six months. The program was functionally dead, and the bank's CDO was back at square one explaining to the board why governance was still "maturing."

by CoComply Team

Read More
Two Regulators, One Data Set, Zero Agreement: Cross-Border Governance at the Breaking Point
Data GovernanceCorporate Governance
Jul 10, 2026

Two Regulators, One Data Set, Zero Agreement: Cross-Border Governance at the Breaking Point

In September 2024, a $68 billion-asset bank with operations in the US, UK, and EU received simultaneous examination requests. The OCC wanted proof that its US consumer lending data met BCBS 239 accuracy standards. The FCA wanted evidence that the same data, processed through its UK entity, complied with Consumer Duty reporting requirements. The EBA wanted assurance that the data flowing into its European stress test models had complete lineage documentation back to source systems.

by CoComply Team

Read More
Governance Debt: The Problem That Does Not Show Up on Any Dashboard
Jul 9, 2026

Governance Debt: The Problem That Does Not Show Up on Any Dashboard

Technical debt has a seat at the table now. CIOs track it. CFOs budget for it. Boards ask about it. Governance debt does not have a seat anywhere. It accumulates in the spaces between audits, in the gaps between policy and practice, in the decisions that were made once and never revisited. And it is compounding inside Tier 2 banks at a rate that would terrify any CFO who actually measured it.

by CoComply Team

Read More
The Reorg Tax: Every Time You Restructure, Your Certifications Reset to Zero
Data GovernanceData Certification
Jul 8, 2026

The Reorg Tax: Every Time You Restructure, Your Certifications Reset to Zero

First Republic was acquired by JPMorgan in May 2023. Within weeks, the OCC issued guidance about governance continuity during absorption. What got less attention: the acquired bank's data governance certifications, some less than six months old, became instantly invalid. New ownership structures meant new data domain owners. New system integrations meant new lineage paths. New risk tolerances meant new thresholds. Every certification the bank had earned was void, not because the content was wrong, but because the context had changed.

by CoComply Team

Read More
The AI Dashboard Said We Were Fine. The Examiner Disagreed.
Regulatory ComplianceData Observability
Jul 6, 2026

The AI Dashboard Said We Were Fine. The Examiner Disagreed.

A $26 billion-asset bank deployed an AI-powered data governance monitoring tool in mid-2023. The tool ingested metadata from across the bank's data estate and produced a daily governance health score. For six months, the score showed green. Then an OCC examination found that 12 critical data elements had quality scores below threshold, three key lineage paths were undocumented, and five certification cycles had lapsed without renewal.

by CoComply Team

Read More
FDIC Consent Orders in 2024 Had a Data Governance Signature. Did You Catch It?
Data CertificationRisk Data Aggregation
Jul 3, 2026

FDIC Consent Orders in 2024 Had a Data Governance Signature. Did You Catch It?

Through the first three quarters of 2024, the FDIC issued 14 consent orders against banks with assets between $20 billion and $250 billion. Eleven of those orders included specific language about data governance deficiencies: incomplete data lineage, insufficient quality monitoring, inadequate governance of third-party data, and failure to demonstrate risk data aggregation capabilities. The pattern is unmistakable. Data governance is no longer a secondary concern in enforcement actions. It is a primary finding.

by CoComply Team

Read More
In M&A Due Diligence, Governance Certifications Are the Asset Nobody Is Valuing
Data LineageData Management
Jul 2, 2026

In M&A Due Diligence, Governance Certifications Are the Asset Nobody Is Valuing

When PacWest Bancorp was acquired by Banc of California in 2023, the deal documents included extensive analysis of credit risk, deposit stability, and capital adequacy. What they did not include was any assessment of the target's data governance maturity. Eighteen months post-merger, the combined entity was still untangling data lineage gaps, recertifying data domains, and reconciling governance frameworks. The integration cost attributed to data governance restructuring exceeded $4 million, a number that never appeared in any pre-deal analysis.

by CoComply Team

Read More
The Regulator Who Saw Through the Dashboard: When Governance Theater Meets Examination Reality
Regulatory ComplianceRisk Data Aggregation
Jul 1, 2026

The Regulator Who Saw Through the Dashboard: When Governance Theater Meets Examination Reality

In 2023, the FDIC issued a consent order against a $31 billion-asset bank that included a finding most governance leaders missed: the bank's data governance dashboard showed green across all domains, but underneath, three critical data elements had quality scores below threshold for over six months. The dashboard was not lying. It was averaging. Aggregated metrics hid domain-level failures. The examiner saw the detail that the aggregation concealed.

by CoComply Team

Read More
Your Best Data Person Resigned. Can Your Exam Still Pass Tomorrow?
Regulatory ComplianceRisk Management
Jun 30, 2026

Your Best Data Person Resigned. Can Your Exam Still Pass Tomorrow?

In Q1 2024, a $44 billion-asset regional bank lost its VP of Data Governance to a competitor. Within 30 days, the bank received an examination notice. The VP had been the sole owner of 23 critical data domain certifications, the only person who understood the lineage mapping for the bank's stress testing data, and the keeper of the informal escalation paths that actually made the governance program function.

by CoComply Team

Read More
When the Examiner Asks for Your Incident Log, Will It Tell a Story or Stay Silent?
Regulatory ComplianceRisk Data Aggregation
Jun 29, 2026

When the Examiner Asks for Your Incident Log, Will It Tell a Story or Stay Silent?

In March 2024, the OCC cited a $42 billion-asset regional bank not for having an incident, but for having no auditable record of how it responded. The bank had suffered a data feed corruption that inflated commercial lending exposures for 11 days. Operations fixed it. Risk was notified. But the governance trail, the who-decided-what-when, simply did not exist in any system. The examiner's write-up was blunt: the bank could not demonstrate that its incident response followed its own policy.

by CoComply Team

Read More
When Certification Becomes the Problem It Was Supposed to Solve
Data LineageData Observability
Jun 29, 2026

When Certification Becomes the Problem It Was Supposed to Solve

A $52 billion-asset bank on the East Coast completed 2,400 data governance certifications last year. By its own metrics, the program was a success. By its examiners' assessment, it was a liability. The OCC's 2024 findings noted that certifications were being produced mechanically, with renewal rates above 98 percent, a statistical impossibility if any genuinely critical review was occurring. The bank was certifying motion, not mastery.

by CoComply Team

Read More
Self-Service Analytics Gave Everyone a Dashboard. Governance Did Not Get the Memo.
Data LineageRegulatory Compliance
Jun 26, 2026

Self-Service Analytics Gave Everyone a Dashboard. Governance Did Not Get the Memo.

A $28 billion-asset regional bank discovered in late 2023 that its commercial lending team had built 340 separate dashboards in its self-service analytics platform. Each dashboard pulled from slightly different data cuts, applied different filters, and used different definitions of "exposure." When the CRO asked for the bank's total commercial exposure across three risk categories, she got six different answers from six different dashboards, all built by smart analysts who trusted the data they were working with.

by CoComply Team

Read More
Who Actually Owns the Data? Really.
Data GovernanceRisk Data Aggregation
Jun 25, 2026

Who Actually Owns the Data? Really.

Data ownership is one of the most discussed and least resolved topics in data governance. Every framework calls for it. Every policy document references it. Every organization says they've defined it.

by CoComply Team

Read More
The 72-Hour Regulatory Exam Stress Test
Regulatory ComplianceData Management
Jun 24, 2026

The 72-Hour Regulatory Exam Stress Test

If you want to know whether your data governance works, don't wait for the examination. Run the 72-hour stress test. Here's the scenario: you receive a notification that examiners will arrive in three days. They've asked for complete data lineage documentation for your top 20 critical data elements, current certification status for data feeding regulatory reports, and evidence of ownership and attestation for the past 12 months.

by CoComply Team

Read More
Metadata Is the Backbone of Data Trust
Regulatory ComplianceCorporate Governance
Jun 21, 2026

Metadata Is the Backbone of Data Trust

Metadata has a branding problem. It sounds technical and optional, like something database administrators care about but executives don't. It's the kind of word that makes eyes glaze over in boardrooms.

by CoComply Team

Read More
Model Risk Is a Data Governance Problem
Data LineageRisk Data Aggregation
Jun 20, 2026

Model Risk Is a Data Governance Problem

Banks have gotten serious about model risk management. SR 11-7 gave them no choice. Model validation is now a mature discipline. Model inventory is a standard practice. Model risk committees meet regularly and challenge assumptions.

by CoComply Team

Read More
Your Vendors' Data Gaps Are Your Gaps
Data LineageData Management
Jun 18, 2026

Your Vendors' Data Gaps Are Your Gaps

Banks outsource. That's not a surprise. What is a surprise to examiners, to risk committees, and sometimes to the banks themselves, is how many governance obligations travel with that outsourcing and never arrive at the destination.

by CoComply Team

Read More
Data Quality Is a Balance-Sheet Risk
Data GovernanceData Observability
Jun 17, 2026

Data Quality Is a Balance-Sheet Risk

Every CFO trusts their numbers. That's the problem. Not because CFOs are gullible; it is because the systems feeding them numbers are quietly decaying, and nobody owns the decay. A data quality issue in a trading book doesn't show up as a data problem. It shows up as a P&L variance. A stale reference rate in a loan portfolio doesn't flag itself as "bad data." It registers as an unexpected margin compression. By the time the numbers look wrong, the data has been wrong for weeks.

by CoComply Team

Read More
The Uncomfortable Truth About Governance Theater
Data GovernanceRisk Management
Jun 16, 2026

The Uncomfortable Truth About Governance Theater

The Uncomfortable Truth About Governance Theater Most governance programs aren't failing. They're performing. If you sat through your last data governance committee meeting and walked away thinking "that went well," you might be the problem. Not because you're doing something wrong, but because "going well" is exactly what governance theater feels like. The slides were polished. The stakeholders nodded. Someone even used the phrase "mature data culture" without irony. Andnothing will change.

by CoComply Team

Read More
The Uncomfortable Truth About Attestation
Data GovernanceData Management
Jun 15, 2026

The Uncomfortable Truth About Attestation

The Uncomfortable Truth About Attestation Most governance programs have an attestation process. Few have an attestation problem they are willing to admit. Here is how it typically works. Once a quarter, or maybe once a year, an email goes out. It asks someone, usually a vice president or a director, to affirm that the data under their domain is accurate, complete, fit for purpose, and compliant with policy.

by CoComply Team

Read More
You Can't Protect Everything. So What Are You Actually Protecting?
Data GovernanceRisk & Compliance
Jun 12, 2026

You Can't Protect Everything. So What Are You Actually Protecting?

Most enterprises have thousands of data elements across hundreds of systems. Trying to govern all of them equally is how you end up governing none of them well. The concept of Critical Data Elements (CDEs) is supposed to solve this. In theory, you identify the data that drives your most important decisions, feeds your regulatory reports, and underpins your risk calculations. You apply higher standards to that data and accept lower rigor for everything else.

by CoComply Team

Read More
OCC Heightened Standards: From Potential Threshold Relief to Right-Sized Governance
Risk Governance Banking Regulation
Jun 11, 2026

OCC Heightened Standards: From Potential Threshold Relief to Right-Sized Governance

The OCC is proposing a massive threshold jump for Heightened Standards from $50B to $700B. But smart banks aren’t walking off the field. Here is why this shift from prescriptive checklists to supervisory judgment means your evidence trail matters more than ever—and how to right-size your governance to win.

by CoComply Team

Read More
The Real Cost of a Governance Gap Isn't the Fine
Data GovernanceRegulatory Compliance
Jun 10, 2026

The Real Cost of a Governance Gap Isn't the Fine

The Real Cost of a Governance Gap Isn't the Fine Most organizations can tell you what their last regulatory fine was. Fewer can tell you what it actually cost. The fine is the headline. The real damage is everything that comes after: the consent order that constrains strategy for three years, the remediation program that eats your best people, the board conversations that shift from growth to survival, and the quiet erosion of trust that makes your next audit harder before it even begins. Governance gaps are expensive. But not in the way most risk reports capture. The problem isn't that organizations underestimate the cost. The problem is they measure the wrong costs.

by CoComply Team

Read More
The Regulatory Squeeze on Tier 2 Banks: What Happens When Exemptions Expire
Banking RegulationData Governance
Jun 10, 2026

The Regulatory Squeeze on Tier 2 Banks: What Happens When Exemptions Expire

The Regulatory Squeeze on Tier 2 Banks: What Happens When Exemptions Expire Here is what nobody tells you about being a Tier 2 bank right now: the regulatory patience is running out. For years, smaller and mid-sized financial institutions operated under a simple assumption. The big rules, the ones with teeth, were written for the global systemically important banks. BCBS 239, the OCC heightened standards, the FDIC expectations around data risk governance, these were Tier 1 problems. Tier 2 banks watched from a comfortable distance, tweaking their frameworks just enough to stay off the supervisory radar. That distance is gone.

by CoComply Team

Read More
You Can't Hire Your Way Out of a Governance Problem
Data GovernanceRisk Management
Jun 9, 2026

You Can't Hire Your Way Out of a Governance Problem

You Can't Hire Your Way Out of a Governance Problem Most organizations respond to governance failures the same way: they hire more people. Another data steward. Another policy analyst. Another layer of oversight in the middle office. It feels like the right thing to do. The regulator wants to see commitment. The board wants to see action. The audit finding says "insufficient resources," and so resources get added. But here is what nobody tells you about scaling governance through headcount: it works exactly until it doesn't. And the point where it stops working arrives faster than you think.

by CoComply Team

Read More
The Uncomfortable Truth About Certification: Most of It Is Just Documentation
Data GovernanceRegulatory Compliance
Jun 8, 2026

The Uncomfortable Truth About Certification: Most of It Is Just Documentation

The Uncomfortable Truth About Certification: Most of It Is Just Documentation If your compliance team left tomorrow, what would remain of your data governance program? The dashboards? The policy documents? The attestation records signed by people who haven't looked at a data lineage diagram in three quarters? Here is what most organizations get wrong. They think documentation is certification. It is not. The difference between the two is the difference between a photograph of a building and the building itself. One describes. The other stands on its own.

by CoComply Team

Read More
The Difference Between Proving and Describing
Data CertificationActive Governance
Jun 4, 2026

The Difference Between Proving and Describing

The Difference Between Proving and Describing Every bank has documentation. Data dictionaries. Policy manuals. Stewardship matrices. Lineage diagrams that look impressive on a projector. Rows and rows of metadata, neatly organized in governance tools that cost six figures to implement. And when an examiner asks, "How do you know this data is right?" someone opens the documentation and points to the page. That's not certification. That's description. And the difference between the two is where regulatory risk lives.

by CoComply Team

Read More
If Your Data Steward Left Today, Would Anything Change?
Data GovernanceData Management
Jun 3, 2026

If Your Data Steward Left Today, Would Anything Change?

If Your Data Steward Left Today, Would Anything Change? Most organizations think governance lives in the governance team. They're wrong. Go into any mid-size bank and ask who owns data quality for the trade reporting pipeline. You'll get pointed to a data steward, probably someone in operations who inherited the role three years ago, keeps the rules in a spreadsheet, and answers questions on Slack when someone's unsure about a field mapping. That person is doing important work. But the organization has confused a person with a system.

by CoComply Team

Read More
The Uncomfortable Truth About BCBS 239 Compliance
Regulatory ComplianceRisk Data Aggregation
Jun 2, 2026

The Uncomfortable Truth About BCBS 239 Compliance

The Uncomfortable Truth About BCBS 239 Compliance Most Tier 2 banks think they have their risk data under control. They don't. If you sit in a governance meeting at a mid-size bank, you will hear the same reassuring chorus: "We're BCBS 239 compliant. We passed our last assessment. The regulators signed off." And technically, maybe they did. The checklist was completed. The documentation was filed. The attestation was signed. But here is what nobody tells you about BCBS 239 compliance at Tier 2 banks: the gap between passing an assessment and actually having reliable risk data is wider than anyone wants to admit. And the regulators know it.

by CoComply Team

Read More
The Uncomfortable Truth About Data Lineage: You Can't Certify What You Can't See
Data LineageData Observability
Jun 2, 2026

The Uncomfortable Truth About Data Lineage: You Can't Certify What You Can't See

The Uncomfortable Truth About Data Lineage: You Can't Certify What You Can't See Most organizations think they know where their data comes from. They're wrong. Ask any CDO to sketch the journey of a single critical data element from source system to regulatory report, and you'll get one of three responses: a confident answer that falls apart under follow-up questions, a vague wave toward a wiki page that hasn't been updated since the last reorg, or an honest admission that nobody really knows. The third response is the most dangerous because it's the rarest. The first two are where real risk lives.

by CoComply Team

Read More
Certification Is Not a Badge. It Is Infrastructure.
Data GovernanceRegulatory Compliance
Jun 2, 2026

Certification Is Not a Badge. It Is Infrastructure.

Most organizations treat data certification like a merit badge. You earn it once, pin it to a slide deck, and move on. The certificate sits in a shared drive somewhere, the attester has already rotated to a new role, and six months later nobody can tell you what was actually certified or whether it still holds. That is not certification. That is decoration.

by CoComply Team

Read More
Governance Theater: When the Slide Deck Is the Deliverable
Data GovernanceCorporate Governance
May 31, 2026

Governance Theater: When the Slide Deck Is the Deliverable

Most organizations do not have a governance problem. They have a presentation problem. Walk into any Tier 2 bank's risk committee meeting and you will see it. Beautiful heat maps. Color-coded RACI charts. Dashboards that pulse with green, amber, and red like a functioning traffic system. Data quality scores trending upward. Attestation coverage above 90 percent. Everything looks under control.

by CoComply Team

Read More
CoComply Announces the Appointment of Jane Sorenson Herthel as Strategic Advisor
AnnouncementLeadership
Feb 23, 2026

CoComply Announces the Appointment of Jane Sorenson Herthel as Strategic Advisor

CoComply announces the appointment of Jane Sorenson Herthel as Strategic Advisor, bringing more than 25 years of experience designing and executing scalable enterprise B2B revenue strategies across high-growth startups and Fortune 500 companies, including leadership roles at Oracle, SAP, Salesforce, Microsoft, and Guidewire.

by CoComply

Read More
RegulatoryBanking
Feb 9, 2026

OCC Shake-Up: What Banks Should Watch

The OCC offered buyouts drawing nearly 800 employees, raising pressing questions about how this shake-up will affect banks. From examiner standards under review to MRAs potentially becoming law, here are the key regulatory shifts banks need to watch.

by CoComply

Read More
FinanceLeadership
Nov 7, 2025

Leadership Insights from Fintech Startups: Transforming Big Banks for the Future

In today's rapidly changing financial landscape, fintech startups have emerged as agile and innovative powerhouses, disrupting traditional banking models. Their fresh approaches to customer engagement, technology integration, and problem-solving have caught the attention of consumers and established institutions alike.

by Editorial Team

Read More