Critical Data Asset Identification: Protect Core Data
A Bank Faces an Unexpected Exam Finding
Mid‑size lender Riverbank Trust, with $45 billion in assets, was preparing for its annual OCC examination when examiners flagged a glaring omission. The exam team cited OCC Bulletin 2024‑57, released on September 12, 2024, which demands that banks formally classify data and identify critical data asset identification for certification. Riverbank’s internal data inventory listed over 12,000 data sets but lacked any formal classification taxonomy.
The examiners noted that without a clear view of which data sets are mission‑critical, the bank could not demonstrate effective risk controls, exposing it to potential enforcement under the OCC’s heightened standards for data governance. Riverbank’s CDO was left with a single sentence thesis: Without a systematic approach to data classification and critical asset identification, the bank cannot meet the OCC’s new expectations for continuous compliance.
Why This Matters
The failure to perform critical data asset identification not only jeopardizes regulatory compliance but also amplifies operational risk. Unclassified data can be inadvertently exposed in a breach, leading to costly penalties and reputational damage. Moreover, regulators now expect real‑time evidence of classification, making manual spreadsheets untenable.
The Problem
Banks today store petabytes of information across legacy mainframes, cloud warehouses, and third‑party data platforms. Yet most institutions still rely on spreadsheets or ad‑hoc tagging to track data lineage. This fragmented approach creates three intertwined failures.
- Inconsistent Classification – Without a uniform taxonomy (public, confidential, restricted, regulated), risk owners cannot prioritize controls, leading to over‑protecting low‑risk data and under‑protecting high‑risk data.
- Missing Critical Asset Identification – The process of singling out data that directly supports key banking functions or regulatory reporting is rarely automated, leaving examiners with blind spots.
- Inability to Provide Real‑Time Evidence – OCC 2024‑57 explicitly requires banks to maintain real‑time evidence of data classification and asset status, a demand that legacy tools and manual processes simply cannot satisfy.
Consequently, banks miss the very data that regulators will scrutinize during examinations. The bulletin cites recent enforcement actions where banks were fined for not being able to produce a qualified data lineage map within a 30‑day window, underscoring that regulators are moving from advisory guidance to enforceable expectations.
The Cost of Inaction
Beyond fines, failure to adopt robust critical data asset identification erodes stakeholder trust. Investors increasingly demand transparency around data risk, and board members are scrutinizing data‑governance maturity as a proxy for overall operational resilience.
The CoComply Approach
Critical Data Asset Identification
CoComply addresses each of these gaps with a continuous, AI‑driven certification layer.
- Automated Classification – Our platform ingests metadata from all data sources, on‑premise databases, cloud data lakes, and third‑party APIs, and automatically applies a regulator‑aligned classification taxonomy. The taxonomy mirrors the OCC’s four‑tier model and is continuously updated as new data types appear. * Critical Asset Engine – Using transaction‑flow analysis and risk scoring, CoComply surfaces the data sets that directly support core banking functions such as loan underwriting, AML monitoring, and liquidity reporting. These assets are flagged for continuous certification.
- Evidence Generation – Every classification decision, lineage update, and policy enforcement is logged with immutable timestamps and can be exported as a regulator‑ready audit package. This eliminates the manual collection of spreadsheets and ensures that the bank can answer any examiner request with a single click, turning a previously reactive compliance exercise into a proactive governance program.
Workflow Detail
When a new data source is onboarded, CoComply first extracts schema and access‑control metadata. The engine then maps each column to the OCC’s taxonomy (e.g., PII, financial transaction data, regulatory reporting fields). A risk‑scoring model evaluates the data’s impact on core processes such as loan underwriting, liquidity reporting, and anti‑money‑laundering (AML) monitoring. Data that scores above the preset threshold is automatically designated as a critical data asset. The system creates a lineage graph, attaches policy tags, and publishes an immutable proof‑of‑classification record to an enterprise‑grade ledger.
Auditors can retrieve the record via a secure API or a one‑click export that conforms to the format required by OCC Bulletin 2024‑57 (OCC Bulletin 2024‑57).
Expanded Capabilities for Depth and Coverage
To further strengthen compliance posture, CoComply layers additional analytics on top of the core engine. First, it cross‑references external threat‑intelligence feeds to flag data sets that contain personally identifiable information (PII) of high‑risk customers, automatically tightening encryption and access controls. Second, it runs periodic “data‑staleness” checks, identifying assets that have not been accessed or updated in over twelve months, prompting custodians to either archive or re‑validate their relevance. Third, the platform generates a risk‑heat map visualizing concentrations of critical assets across business units, enabling senior leadership to allocate resources strategically.
These supplemental features not only satisfy the OCC’s requirement for continuous evidence but also provide actionable insights that improve overall data‑risk governance.
Continuous Monitoring and Remediation
Our platform monitors changes in content, schema, or access patterns and triggers re‑validation automatically. When a new data source is added, the system automatically classifies it, updates the critical asset list, and records the change for audit.
Integration with Existing Toolchains
CoComply integrates with popular data‑catalog tools, SIEMs, and DLP solutions, ensuring that classification and critical asset status are reflected across the entire technology stack. This unified view reduces the likelihood of policy drift and supports rapid incident response.
Closing Insight
When regulators move from guidance to enforceable standards, banks must evolve from siloed data inventories to a unified, continuously certified data fabric. The Riverbank Trust scenario illustrates that without a systematic critical data asset identification strategy, even well‑funded banks can stumble over basic compliance checkpoints.
By embedding CoComply’s AI‑verified certification into everyday data workflows, banks not only meet the OCC’s new expectations but also create a living assurance layer that reduces operational risk, streamlines examinations, and frees staff to focus on strategic initiatives rather than endless paperwork. In a regulatory landscape that rewards agility, the ability to instantly prove that your most important data is properly classified and protected becomes a decisive competitive advantage.
Tags: Data Governance, Critical Asset Identification, Regulatory Compliance
