The Malta Independent 23 July 2026, Thursday
View E-Paper

Data accountability in banks: Is it a risk that can be ignored?

Sunday, 8 March 2026, 08:00 Last update: about 6 months ago

Silvio Chetcuti

When people hear the term "bank risk," they may think of interest rates, cyberattacks, or the next economic shock. But there's a quieter risk that sits underneath: whether a bank can trust its own numbers. If customer, account, and transaction data don't match across units, leaders don't get one version of the truth. They get competing stories.

That is why "good data and strong governance" are not back-office hygiene. They are the foundation of effective risk management. Regulations may come in many forms: privacy, prudential reporting, financial crime controls, operational resilience, but their message converges: data must be consistent, traceable, and accountable.

The banks that treat each rule as a separate compliance project will keep reconciling contradictions at reporting stage. The banks that build a single, reliable data foundation will earn something harder to buy - credibility.

 

One version of the truth isn't a luxury.

Banks manage data across all lines of defence, including retail, corporate banking, risk, and finance functions. Every domain consumes and produces information for different purposes. Meanwhile, regulators increasingly expect banks to demonstrate that underlying data is consistent, traceable, and of good quality, not only at reporting stage but also as a sustained capability. Good data and strong governance are the foundations of effective risk management.

 

Data Discipline

The banking regulatory environment combines broad frameworks such as GDPR with function-specific regimes including BCBS 239, CRR 3, FINREP, and AML/CFT requirements. While these frameworks address different risks, they converge on expectations around data quality, integrity, availability, and accountability.

The temptation is to treat each regulation as its own project, but that approach often creates a predictable failure mode in contradictions that surface only at the end of the pipeline, when reports are being produced, and when someone discovers that two parts of the organisation are counting the same thing differently.

A better model is a unified approach to data governance, one that supports multiple regulatory "views" of the same underlying information, without changing the foundation. As Weill and Ross argue, governance is about decision rights and accountability for information-related processes, and fragmented implementation can signal governance weaknesses rather than technical gaps.

 

A single, reliable data foundation

A fundamental principle that each bank must consistently apply is maintaining a single, reliable data foundation from which different regulatory and management representations are derived. That principle sounds simple, but it is demanding. It requires that critical data elements such as customer profile, account data, limits and transactions are defined, owned, and controlled consistently across domains. It also requires discipline about what may differ and what must not. Regulatory reports, risk calculations, and management information can differ in interpretation and aggregation, but they should not differ in the underlying data sources.

When banks lack that discipline, the symptoms show up everywhere: inconsistent reporting outcomes, weakened control environments, and reduced confidence in the risk management framework. Research also links fragmented governance structures with inconsistent reporting outcomes.

 

Data ownership

Regulatory bodies anticipate a clearer definition of data ownership coupled with stewardship, while emphasising that senior management holds overall accountability for ensuring data quality and meeting regulatory standards.

That accountability is expected to extend across organizational and legal-entity boundaries, especially in group and cross-border arrangements. In other words: "we didn't own that system" or "that sits in another entity" is no longer a persuasive explanation when the outputs must still be consistent, secure, and reliable.

Banks are also expected to remain accountable for the integrity, security, and availability of data under DORA and EBA ICT guidelines. This is governance in its most practical form: who owns which data, who stewards it day-to-day, and who answers when it fails quality thresholds or becomes untraceable.

 

When rules collide: GDPR vs the need for history

Modern banking compliance also requires banks to handle conflicts across regulatory requirements.  One of the most difficult is the tension between GDPR's principles of data minimisation and purpose limitation and the need for thorough historical data for regulatory purposes.

This is not a theoretical dilemma. It's a design challenge that demands defensible architecture and rigorous documentation. The piece argues that this can be addressed through purpose-driven data layers, robust access controls, and methods like anonymisation, supported by clear documentation of the legal rationale for retaining data for regulatory needs.

The banks manage data across all lines of defence, including retail, corporate banking, risk and finance functions. Each domain consumes and produces data which is used for different purposes, on the other hand regulators increasingly expect that banks must demonstrate that the underlying data is always consistent, traceable, and finally of good quality. Therefore, data management has become a very important element of regulatory compliance, risk management, and operational resilience. This aligns with information quality theory, which defines high-quality data as accurate, complete, consistent, and timely (Wang & Strong, 1996).

In other words: retain what is needed, protect it properly, and be able to explain clearly why it is needed. That is how trust is built internally, and externally, with supervisors assessing whether a Bank's risk management framework is real or just well-presented.


Silvio Chetcuti is a seasoned and accomplished professional in the dynamic realm of banking, Silvio Chetcuti brings over 34 years of dedicated experience in finance, management, risk management, and client relations.


Sponsored Content by Bank of Valletta
  • don't miss