Banks and large non-bank financial institutions are being asked to do two things at once: accelerate data-driven decisioning and AI, while maintaining discipline that can withstand regulators, auditors, customers and litigation.
That tension is not transitional; it is the operating environment. Boards should treat this as a governance issue, not a technology initiative.
Because today’s institutions are increasingly decision enterprises: Pricing, eligibility, underwriting, fraud intervention, servicing actions, complaint outcomes, collections and dispute handling are shaped — often in real time — by data and models. When an institution’s most consequential outcomes are data-mediated, its most consequential control system must be data governance.
That leads to a conclusion boards can no longer treat as optional: Having a chief data officer who is not a principal at the senior management table is not a viable governance model going forward.
This is not because data matters, but because an institution’s ability to defend outcomes at scale now depends on whether it can prove:
- How a decision was produced;
- Whether the decision path was permissible; and
- If it remained controlled over time.
As LatentView Analytics’ Global Head of Financial Services Parijat Banerjee puts it, risk models must be explainable, auditable and compliant, and data governance enforces lineage. Meaning it proves where the data came from and how it was transformed. Without that evidence chain, model outcomes cannot be defended, internally or externally.
Mindset shift
Banks will always be a decision factory with a balance sheet, but the operating engine has changed. The modern institution is a high-volume decision system that must approve, price, flag, freeze, investigate, reverse, waive, escalate and report — all at scale.
As decisions become more automated and interconnected, outcomes depend less on individual judgment and more on whether the underlying data is governed with rigor.
This is where many institutions missequence priorities. They treat AI as strategy and governance as overhead. In reality, governance is the strategy that makes automation and AI safe, defensible and scalable.
Boards should ask a simple question before approving AI roadmaps: Can management prove, end-to-end, how a material decision was produced, and that it remained permissible, explainable and controlled?
If the answer is “not reliably,” then the organization does not have an AI strategy. It has an acceleration plan for unmanaged exposure.
Data governance
Many executives have seen data governance fail because it came down to committees, policy binders and sporadic remediation projects. That is not governance; it is administration.
Modern data governance is an enterprise control system that makes data:
- Meaningful, with consistent definitions and semantics;
- Trustworthy, with quality controls, monitoring and thresholds;
- Traceable, with lineage, metadata and transformation evidence;
- Permissible, with purpose limitation, access policy and consent alignment; and
- Auditable, with documented controls, exceptions and remediation evidence.
This is not an academic preference. It is the minimum condition for defensible decisioning at scale. And as Banerjee warned, without lineage and governance, model outcomes cannot be defended. So, boards should stop hearing data governance as an IT hygiene initiative and start hearing it as enterprise risk control.
Weak governance degrades enterprise value
Banks have always governed one form of capital ruthlessly: Financial capital. They measure it, allocate it, protect it, stress it and manage it at the top table.
But in a digital, automated, AI-influenced institution, capital preservation is inseparable from the integrity and defensibility of the decision system — and the decision system runs on data.
When data is poorly defined, weakly owned, non-traceable or used outside permitted purposes, an institution does not merely suffer data quality problems. It suffers enterprise capital degradations, such as:
- Financial capital: Loss events, pricing errors, remediation programs, restitution;
- Operational capability: Manual workarounds, exception handling, unstable processes;
- Intellectual assets: Models running on inconsistent semantics and uncontrolled inputs;
- Human capability: Perpetual reconciliation, forensic cleanup and rework; and
- Trust capital: Customer harm, regulatory confidence loss and reputational impairment.
This is why governance is no longer best practice, it’s critical.
Data capital
Banks understand capital because it disciplines behavior: constraints, measurement, accountability. Boards should adopt an analogous construct.
Data capital is the institution’s capacity to produce defensible, scalable decisions because its data is governed as an enterprise asset, defined, owned, controlled, traceable and permissible to use.
An institution with strong data capital moves faster with less risk because it can say yes safely. One with weak data capital may modernize platforms, but it will remain slow where it matters most.
Banerjee captured a hard truth: Lineage and metadata must be built by design, from Day One. Retrofitting evidence after automation is deployed is not governance; it is forensic remediation.
AI comes after governance
AI intensifies the consequences of weak governance. A defect that once created limited harm can propagate across large populations quickly. Root-cause analysis becomes materially harder without lineage and semantic integrity.
So, AI-ready is not a vendor selection exercise. It is evidence of governance and monitoring that can withstand scrutiny — lineage, permitted use, bias and drift monitoring, and control gates for production deployment — Banerjee said.
The CDO role
Elevating the chief digital officer in name only produces the worst outcome: a symbolic seat with an unclear mandate.
A boardworthy CDO seat must represent enterprise authority over the control system for truth and decision defensibility. In practice, the CDO mandate must own and enforce:
- Enterprise semantic standards: A single meaning of critical concepts (for example, dispute, income, delinquency, consent, resolution, fee waiver)
- Business ownership of critical data elements: Named owners in the business accountable for integrity and control outcomes;
- Lineage requirements for material decisioning and reporting: Evidence chains that allow the institution to explain and defend decisions;
- Quality control frameworks and defect governance: Integrating thresholds, monitoring, triage, aging, remediation velocity and defect escape rates into production decisioning;
- Permitted-use governance and exception control: Who can use what data, for what purpose, under what consent and policy constraints, and how exceptions are approved, monitored and retired; and
- AI production governance gates: No production AI without lineage evidence, data integrity controls and monitoring for drift and bias.
Boards should require a governance-grade scorecard to enforce this mandate.
A support function cannot credibly enforce enterprise truth. It can advise. It cannot govern. And governance is why the senior management table exists.
Reseating the top table
Senior management committees have finite seats. They represent what leadership believes most determines survival and performance.
Many institutions expanded the table over time, adding digital, strategy, product, marketing or customer leadership. The question is not whether those roles matter. The question is whether the table reflects the institution’s dominant value-and-risk surface today.
In a data-mediated decision enterprise, that dominant surface is enterprise truth and decision defensibility.
That is why the CDO must be a principal. And where tradeoffs must be made, the redesign is inevitable: top-table authority must shift from delivery and messaging toward truth, controls and defensibility.
Build data capital. Seat the CDO as a principal. Then, and only then, declare the institution’s AI strategy credible.
Jim McCarthy is chairman for McCarthy Hatch, which provides data-driven insights for risk management. A founding member of the Consumer Financial Protection Bureau, he is a keynote speaker and fractional CRO/CCO in the financial services industry with more than three decades of experience.






