Your risk reports run on an unassessed supply chain
How data lineage brings assessment discipline to financial services data flows
A bank’s risk office assesses nearly everything that moves. Material business processes go through the risk and control self-assessment (RCSA), controls carry named owners and testing schedules, and new products clear approval committees before launch. The data supply chain feeding the bank’s own risk reports rarely receives equivalent scrutiny. Between the system that first captures a trade and the report that aggregates its exposure, data passes through transformations, integrations, and manual touchpoints that no assessment has named, rated, or assigned to anyone.
Eric Hirschhorn, Chief Data Officer at Bank of New York, describes the problem from the inside. Firms would love a world where data moves cleanly from producer to consumer, he notes, but “many of us see 5, 10, 15 hops from a piece of data being produced to a piece of data being consumed, and every one of those hops is an opportunity to get it right or to have a challenge.”1
Data lineage closes that shortfall. When the lineage model carries ownership and risk context alongside the technical flows, the supply chain behind every risk report becomes something you can assess with the same rigor the RCSA applies everywhere else.
Each handoff between systems exists for a reason. An exchange delivers market data in a format the accounting platform cannot consume, so a transformation reshapes it. A decades-old settlement system uses a format that nothing else does, so integration and translation are needed. And when no interface connects two screens, a team under deadline types in the figures across by hand. None of these steps appear on an organization chart, and few appear in any assessment, yet each can alter a value that ultimately ends up in a regulatory filing.
An error can enter a handoff without detection, because monitoring watches systems rather than the connections between them. A transformation can also run correctly yet remain unprovable, because nobody documented what it does, which leaves the figure it produced without evidence when an examiner asks about provenance.
Gartner reports that data sources in banking, from open banking APIs to market feeds and IoT telemetry, are growing at a pace that overwhelms traditional centralized data architectures, so the number of connections needing assessment rises every year.2 More sources mean more handoffs, and an assessment program cannot cover what nobody has mapped.
Hirschhorn describes building a risk report whose inputs span 211 systems, each of which performs activities that produce the artifacts the report requires. Those 211 systems feed 36 sub-ledgers, which in turn feed the risk engine. Every stage raises the same questions. Who owns those systems? Who owns the sub-ledgers? How are the fields transformed along the way?3
Laying the supply chain out on a lineage diagram turned those questions into assignable work. Bank of New York systematized the answers into policies, desktop procedures, and artifacts, backed by its own check-and-challenge process, so that accountability survives staff turnover and reorganizations rather than living in someone’s head.
The operating pattern is consumer-driven. The risk report’s owner specifies what the report requires, and every upstream producer is accountable for meeting that requirement. Ownership is not optional at any point in the chain. “If you are responsible for managing risk at this company, you have to opt in to that supply chain, and you don’t have a choice,” Hirschhorn says.4
A risk report built this way behaves like any other assessed process. The exposures are named, the owners are known, and anyone preparing for an examination can point to the lineage model as evidence of both.
Automated scanning tools can discover much of the data landscape and map it. Their output, though, is a picture of nodes and edges. Run one against the supply chain above, and you get 211 systems rendered as boxes and arrows, with no owner on any of them, no risk rating on any flow, and no regulatory obligation attached anywhere. The map is accurate and fast, and it gives a risk officer nothing to act on. Tools built for technical discovery are blind to business meaning.
Business context converts the map into a control. A lineage platform that holds ownership, service-level agreements, risk ratings, and regulatory tags directly on the flows starts to behave like a controls inventory. Exposure is computed from the lineage model rather than compiled through interviews. Ask which report inputs cross a jurisdictional border, or which upstream systems carry a high operational risk rating. The answer comes back in minutes, current as of the model’s last update.
Insurers and asset managers often apply this discipline via a risk register rather than an RCSA, and they face the same problem. A hand-compiled register describes the data ecosystem as it stood at the last refresh, and the limitation applies to the RCSA itself. Workshops and interviews capture a moment, and the underlying data flows keep changing after the moment passes. For a fuller comparison of how lineage platforms and metadata catalogs differ on this point, see the data lineage vs. metadata management comparison.
Supervisors have moved their expectations in the same direction. The European Central Bank’s May 2024 guide on risk data aggregation expects banks to maintain complete and current data lineage down to the individual data attribute, and a lineage rebuilt after the examination notice arrives does not meet that bar.5
A global investment bank shows what meeting that expectation looks like in practice. To bring an environment centered on an Oracle data warehouse with 30 source systems under BCBS 239, the bank built its lineage model in Solidatus and activated data quality rules inside it, so issues alert their owners the day they appear.6
Change-impact assessment that once took months now takes minutes, and the same lineage model produced the bank’s first data dictionary that updates itself.7 Preparing for an examination stopped being a scramble to assemble evidence, because the evidence never goes stale.
Firms that stay ahead of the exam cycle treat data quality as an operating rhythm. Quality scorecards raise incidents, teams address them, and the lineage model stays clean between assessments.
AI accelerates the rate at which enterprise data changes and broadens the scope of what any single decision consumes. An AI model retrained quarterly, or an agent pulling from dozens of systems per decision, sits downstream of far more handoffs than any human analyst ever did, so each unassessed handoff now feeds more outcomes than it used to. Gartner notes that AI in banking has to run inside regulated workflows with provable controls and auditability, which puts the data supply chain behind every AI model inside the scope of risk management, whether or not anyone has assessed it.8
The same lineage foundation extends assessment discipline to AI-driven change. The AI Lineage Assistant in Solidatus reasons over the full lineage graph, including business relationships and regulatory frameworks such as BCBS 239, so recommendations about your data environment arrive with regulatory context already attached. Risk teams get the same ownership answers for an AI model’s inputs as for a risk report’s inputs.
Three moves put this discipline in place, and each one depends on lineage that combines end-to-end coverage with business context.
If you want to see what an assessed supply chain looks like on your own data landscape, request a demo and bring your hardest risk report.
1Hirschhorn, Eric. “Pioneering Data Strategies: How Bank of New York Is Shaping Business Success in the Age of AI.” Solidatus webinar, 2025.
https://www.solidatus.com/resource/pioneering-data-strategies-how-bank-of-new-york-is-shaping-business-success-in-the-age-of-ai-webinar-recording/.
2Bhattacharya, Sudarshana, Kimberly Harris-Ferrante, and Jasleen Kaur Sindhu. “Top Data and Analytics Trends in Banking and Insurance for 2026.” Gartner, February 3, 2026. G00843275.
3Hirschhorn, Eric. “Pioneering Data Strategies: How Bank of New York Is Shaping Business Success in the Age of AI.” Solidatus webinar, 2025.
https://www.solidatus.com/resource/pioneering-data-strategies-how-bank-of-new-york-is-shaping-business-success-in-the-age-of-ai-webinar-recording/.
4Hirschhorn, Eric. “Pioneering Data Strategies: How Bank of New York Is Shaping Business Success in the Age of AI.” Solidatus webinar, 2025.
https://www.solidatus.com/resource/pioneering-data-strategies-how-bank-of-new-york-is-shaping-business-success-in-the-age-of-ai-webinar-recording/.
5European Central Bank Banking Supervision. Guide on Effective Risk Data Aggregation and Risk Reporting. May 2024.
https://www.bankingsupervision.europa.eu/ecb/pub/pdf/ssm.supervisory_guides240503_riskreporting.en.pdf.
6Solidatus. “Global Bank Automates BCBS 239 Compliance” (case study). 2023.
https://www.solidatus.com/resource/providing-accurate-complete-and-timely-data-for-bcbs239-compliance/.
7Solidatus. “Global Bank Automates BCBS 239 Compliance” (case study). 2023.
https://www.solidatus.com/resource/providing-accurate-complete-and-timely-data-for-bcbs239-compliance/.
8Bhattacharya, Sudarshana, Kimberly Harris-Ferrante, and Jasleen Kaur Sindhu. “Top Data and Analytics Trends in Banking and Insurance for 2026.” Gartner, February 3, 2026. G00843275.
9Solidatus. “Asset Management Firm Transforms Investment Environment” (case study). 2023.
https://www.solidatus.com/resource/asset-management-firm-transforms-investment-environment/.
01.
Data lineage reduces risk by mapping every transformation, integration, and manual touchpoint that data passes through between its source and the reports it feeds, then attaching owners, risk ratings, and regulatory obligations to those flows. This turns an unexamined data supply chain into an assessed one, so errors are caught at the point of entry, accountability is assigned before an incident occurs, and evidence for supervisors stays current rather than being rebuilt for each examination.
02.
Data lineage risk management is the practice of applying risk assessment discipline to data flows themselves, treating each handoff between systems as a potential point of error, unevidenced transformation, or unassigned accountability. A business lineage platform such as Solidatus supports the practice by holding ownership, service-level agreements, risk ratings, and regulatory tags directly on the flows, so exposure is computed from a living model of the data supply chain.
03.
A risk and control self-assessment (RCSA) captures risks and controls through workshops and interviews at a point in time, and it covers business processes more often than the data flows beneath them. Data lineage complements the RCSA by extending the same discipline to the data supply chain and keeping it current, because a lineage model updates as systems and flows change rather than waiting for the next assessment cycle.
04.
Automated scanners discover technical flows and produce an accurate map, but the map arrives without owners, risk ratings, or regulatory context, leaving a risk officer with nothing to act on. Managing risk requires business context attached to the lineage, including who owns each system, which obligations govern each flow, and how severe an upstream issue would be. Scan-only tools are fast at technical discovery and blind to business meaning.
05.
The European Central Bank’s May 2024 guide on risk data aggregation and risk reporting expects banks to maintain complete and current data lineage down to the individual data attribute, building on the BCBS 239 principles for risk data aggregation. In practice, supervisors expect lineage to be maintained as a control, rather than for documentation to be assembled after an examination is announced.
06.
Start with one high-stakes risk report and enumerate its data supply chain, assigning a named owner at every handoff between systems. Where the enumeration stalls, you have found unmeasured exposure. From there, attach risk ratings and regulatory tags to the flows, and move one annual attestation onto a living lineage model with active data quality rules, so its evidence stays current year-round.
Published on: August 26, 2026