Skip to content

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Sep 2026

Governing data risks in the age of AI

Artificial intelligence (AI) and in particular generative AI (GenAI) has accelerated data risk in financial services by changing how data is accessed, transformed, and used to drive decisions that regulators closely scrutinise. The pace of AI adoption has outrun many organisations’ data control foundations: AI tools frequently require broad access to data systems, deepen reliance on third-party vendors, and create new pathways through which sensitive data can leak, via prompts, model outputs, automated retrieval processes, and AI-driven actions. At the same time, regulatory expectations for data accuracy, completeness, timeliness, and traceability remain uncompromising, particularly for high-stakes use cases such as capital and liquidity management, regulatory and financial reporting, and financial crime detection. This paper proposes a practical, audit-ready approach to governing data risks in the AI era. The central idea is to add a second lens to traditional data classification, one focused on business consequence rather than confidentiality alone. Specifically, it introduces the concept of critical data elements (CDEs): data elements whose inaccuracy, unavailability, or misuse can produce material regulatory, financial, or customer-facing impact. Pairing CDE designation with conventional confidentiality classifications creates a dual-axis model that directs the strongest controls to the highest-consequence data, even when that data may not appear sensitive on the surface. Drawing on established regulatory frameworks including BCBS 239 (risk data aggregation and reporting), SR 26-2 (model risk management, the interagency guidance issued jointly by the Federal Reserve, Office of the Comptroller of the Currency (OCC), and Federal Deposit Insurance Corporation (FDIC) in April 2026, superseding SR 11-7), and US interagency third-party risk guidance, the paper explains why AI amplifies data risk across four dimensions (privacy, security, integrity, and accountability), and presents an eight-domain data governance framework with concrete audit evidence examples. The goal is to equip compliance, risk, and audit leaders with a repeatable structure for demonstrating that AI innovation rests on controlled, auditable data foundations. This article is also included in The Business & Management Collection which can be accessed at http://hstalks.com.business/.

Xin-Fa Tu · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.