The Exposure That Read Too Low
A commercial bank ran a routine exposure check on a corporate borrower and got an answer that felt too low. A closer look revealed why: the same company existed in its systems six times — as "ACME Corp," "ACME Corporation," "Acme Corp Ltd," a misspelling, a legacy code, and a subsidiary booked as if unrelated.
Each record was internally tidy. Together they fractured one customer into six, and the bank's view of its own exposure was wrong by a wide margin. Nobody had made a mistake in the ordinary sense — every system did exactly what it was built to do. The failure was that no authoritative version of "this customer" existed anywhere.
Identity Fragmented by Design
Most organizations let each system own its own version of core entities. A CRM, a lending platform, and a payments system each maintain their own customer records, and no layer above them establishes which version is authoritative.
This is not a technology problem. It is a governance design problem. Identity is fragmented because nothing was ever made responsible for resolving it, so the same entity multiplies quietly across the estate. The consequences reach the regulator: BCBS 239 assumes an institution can aggregate exposure to a single counterparty across the whole group. Fragmented identity makes that impossible to do reliably, and understated exposure — the most dangerous direction for a risk number to be wrong — is a supervisory finding waiting to happen.
The CoComply Approach
CoComply treats core entity identity as governed master data — a single authoritative version — rather than a problem analysts re-solve at report time. The specific gap — one customer fractured into six records — is closed by resolving incoming records against a managed identity, reconciling variant names, codes, and misspellings into one governed version, and maintaining the legal hierarchy that ties subsidiaries to their parent.
That means aggregation runs on a customer counted once, not six times. Instead of analysts stitching identities together each cycle through heroic manual reconciliation, CoComply's governance model keeps the master identity current as new records arrive, so a single trustworthy answer to "who is this?" is available whenever a number is built on it.
You Cannot Aggregate What You Cannot Identify
Fix identity at the core, and every exposure figure, concentration report, and customer decision downstream inherits a view that finally matches reality.
The organizations that hold up under scrutiny aren't the ones with the cleanest individual systems. They're the ones where a customer is a single, governed identity no matter how many systems touch it.
