Attention: You are using an outdated browser, device or you do not have the latest version of JavaScript downloaded and so this website may not work as expected. Please download the latest software or switch device to avoid further issues.

ANALYSIS > Blogs > The Value of Data Standards in Enterprise Data Management Models

The Value of Data Standards in Enterprise Data Management Models

How simplicity, consistency, and governance turn data standards into a strategic advantage for GSIBs and regulators alike
3 Aug 2026
Blogs

By Tom Dunlap, Senior Fellow, Data Foundation


Long before the emergence of senior data stewards, such as Chief Data Officers, organizational leaders across industries and sectors have understood that an effective data management model begins with data standards and endures because of strong data governance. Although most senior executives now understand that data standards can provide value for managing their data, far fewer know exactly what a good data standard actually looks like, particularly for achieving the dual objectives of complying with government regulations and gleaning the useful operational insights out of their data.  

Defining Good Data Standards

Let’s take a step back and consider what good looks like for data standards in the first place. 

The following are best practices to keep in mind for defining what the data standards are, as they get promoted and understood across the enterprise organization:

  • Simplicity. At a high-level, keep the data standards themselves simple and easy to understand. Don’t over-complicate what you are trying to achieve.
  • Intention and focus. Focus on what it really takes to have consistently high data quality with respect to coverage, completeness, timeliness, and accuracy.
  • Consistency is key. Use consistent formats, naming conventions, and metadata.
  • Define. Standardize data definitions across systems to ensure interoperability and clarity.
  • Uniqueness. Use unique identifiers, do not allow for duplicates to exist.
  • Traceability. Ensure good data lineage and traceability to know what, how, and why data gets created and changed.
  • Known connections. Utilize the data mesh concept to ensure agreement on use cases for the data standards between the data stewards, custodians, and owners.

Impact of Data Standards

The data standards, as they get adopted across the organization, further support goals for enterprise data management with respect to:

  • The underlying data governance framework where roles are defined. Policies develop from these defined roles, related to data access, usage, and quality, and lead to implementation processes for data classification, lineage, and stewardship.  This framework approach needs to apply when using Gen AI to support workflow processes for data changes and updates to enable a set of controlled guardrails.
  • Ensuring data quality assurance by continuously monitoring and cleansing data to eliminate errors and inconsistencies, while using automated tools for data validation and profiling.
  • Having a single source of truth via “data quality at source.”
  • Expanding the data lifecycle model for data retention, archival, and deletion.
  • Supporting data security and data privacy via encryption, access controls, and auditability.
  • Training staff on core data policy and data standards’ needs.

Data standards are foundational to achieving conformance with regulatory requirements such as Non-Financial Reportings (e.g., Position Limits, Shareholder Disclosures), General Data Protection Regulation (GDPR), Digital Operational Resilience Act (DORA), the Basel Committee on Banking Supervision's standard number 239 (BCBS 239), and other types. They do so by helping with:

  • Consistency and Accuracy: normalized data ensures that information is accurate and consistent across systems, especially as consumed by Gen AI models in that using the ‘right’ data in the first place is key for model trainings to promote correctness and avoid wrong outputs and hallucinations.
  • Data Classification and Protection: standards enable the classification of sensitive data, which enables appropriate security measures, such as encryption and access control.
  • Auditability: normalized data makes it easier to demonstrate regulatory rule conformance with inquiries and audits, better demonstrating being in control.
  • Risk Mitigation: standardized data handling reduces the risk of breaches and non-compliance penalties, whether financially, reputationally, or both.

In 2024, I co-authored a white paper for DIACSUS, a global advisory and consulting firm, and Kingland Systems, a software and technology company, about critical data needs in the financial services sector. The paper analyzed data from a survey of the Top 10 Global Systemically Important Banks (GSIBs) in North America about what they were focusing on with respect to getting data right in view of regulatory conformance needs. The study surfaced the following high-level themes:

  • The regulatory environment is intense for the GSIBs with no signs of easing.
  • Compliance shortcomings by the GSIBs have been highlighted with substantial fines and publicly disclosed consent orders requiring significant remediation programs. 
  • Regulatory bodies have evolved beyond historic trust and verify approaches. Regulators are now using more sophisticated approaches, expanding breadth and depth of regulatory conformance, including:
  • Highly upskilled staff
  • Sophisticated data science techniques
  • Precision technology applications
  • Good data insights and analysis to assess compliance 
  • Data quality is foundational to get right alongside good risk control activities and supporting evidence, showing firms are “in control.” 
  • GSIBs are prioritizing transformation programs (via large budgets) to address and mitigate their regulatory shortcomings more proactively rather than budgeting for “risk acceptance.”

We noted four major themes and patterns from our survey that are relevant for the GSIBs, as essential priorities, to progress their uplift missions to mitigate related regulatory lapses, issues, and failures:

  1. Deploying highly effective operational risk management capabilities
  2. Having a robust risk control framework
  3. Ensuring strong resilience
  4. Maintaining a committed data governance framework and collaboration model 

Data completeness and data quality were underlying needs in all aspects of these themes. 

In addition to the four major themes and patterns, there are twenty-two sub-themes and patterns per the table below:

We also noted common sub-themes across the prominent themes and patterns drawing regulators’ focus. The intersection of the common sub-themes for data quality, automation to reduce manual processes, controls effectiveness, and data insight and analysis along with self-detection resonated across participants of the study:

In understanding how banks view the importance of data standards in complying with regulations, it’s important to also understand regulators’ priorities and how good data standards can meet their needs. 

What do the regulators care about the most with the data?

  • The quality and adequacy of reference data, enabling GSIBs to comply with regulations and rules, better support the integrity of the markets, and improve clients’ trust. Regulators, through inquiries and examinations, aim to review the controls in place to detect and prevent fraudulent behaviors affecting the markets and ensure compliance with the rules in place. Additionally, they want to ensure GSIBs are protecting Personally Identifiable Information (PII), and that fair practices are being followed to maintain consumer confidence.
  • Progress in how the controls around reference data are operating effectively to meet rule requirements while making sure any additional controls are in place to enable GSIBs to strengthen areas of concern identified in past reviews or notable incidents. Regulators want GSIBs to learn from past lessons and better mitigate risks by effectively executing controls, especially on issues previously identified through examinations or incidents.
  • As an ongoing focus area, ensuring that client and entity data are accurate; making sure the entity tree structures are correct for validating direct and beneficial ownership, e.g., AML / KYC. Regulators want to see data traceability with clients, specifically with entities (companies, trusts, etc.), ensuring that the GSIBs understand whom the underlying beneficial owner of an account is and are properly managing their AML / KYC risk exposure and links to client money and assets.

Data standards, as part of an effective enterprise data management model, strongly support regulatory rule conformance. Firms that do not invest upfront resources in developing good data standards and adhering to them through strong data governance  often incur additional data and technical debt that can become costly and difficult to remediate in the longer-term. And when a firm falls short in frequently meeting regulatory reporting requirements, regulators have become a lot better at detecting if compliance shortcomings are due to poor data governance, data standards, and data management framework capabilities requiring an uplift.

image

DATA FOUNDATION
1100 13TH STREET NORTHWEST
SUITE 800, WASHINGTON, DC
20005, UNITED STATES

INFO@DATAFOUNDATION.ORG

This website is powered by
ToucanTech