Governing data risks in the age of AI
Abstract
Artificial intelligence (AI) and in particular generative AI (GenAI) has accelerated data risk in financial services by changing how data is accessed, transformed, and used to drive decisions that regulators closely scrutinise. The pace of AI adoption has outrun many organisations’ data control foundations: AI tools frequently require broad access to data systems, deepen reliance on third-party vendors, and create new pathways through which sensitive data can leak, via prompts, model outputs, automated retrieval processes, and AI-driven actions. At the same time, regulatory expectations for data accuracy, completeness, timeliness, and traceability remain uncompromising, particularly for high-stakes use cases such as capital and liquidity management, regulatory and financial reporting, and financial crime detection. This paper proposes a practical, audit-ready approach to governing data risks in the AI era. The central idea is to add a second lens to traditional data classification, one focused on business consequence rather than confidentiality alone. Specifically, it introduces the concept of critical data elements (CDEs): data elements whose inaccuracy, unavailability, or misuse can produce material regulatory, financial, or customer-facing impact. Pairing CDE designation with conventional confidentiality classifications creates a dual-axis model that directs the strongest controls to the highest-consequence data, even when that data may not appear sensitive on the surface. Drawing on established regulatory frameworks including BCBS 239 (risk data aggregation and reporting), SR 26-2 (model risk management, the interagency guidance issued jointly by the Federal Reserve, Office of the Comptroller of the Currency (OCC), and Federal Deposit Insurance Corporation (FDIC) in April 2026, superseding SR 11-7), and US interagency third-party risk guidance, the paper explains why AI amplifies data risk across four dimensions (privacy, security, integrity, and accountability), and presents an eight-domain data governance framework with concrete audit evidence examples. The goal is to equip compliance, risk, and audit leaders with a repeatable structure for demonstrating that AI innovation rests on controlled, auditable data foundations. This article is also included in The Business & Management Collection which can be accessed at http://hstalks.com.business/.
The full article is available to subscribers to the journal.
Author's Biography
Xin ‘Cindy’ Tu CPA, CISA, CISSP, CDMC is an executive with over 19 years of experience in artificial intelligence (AI), data, IT, and cyber risks. Cindy has spent the last 11 years building AI, data, IT, and cyber risk frameworks for top financial services companies. Most recently, she has been with Capital One, Discover Financial Services, and Fannie Mae. Additionally, Cindy serves on the Editorial Board of CDO Magazine, AI Advisory Board of HotTopics, and Executive Advisory Board of FIMA Events. Given her specialty, Cindy helps shape the Data Governance and AI Governance Frameworks working with the EDM Council and American Bankers Association.