Your risk reports run on an unassessed supply chain

The EU AI Act deadline has moved, but data lineage can’t wait

How data lineage brings assessment discipline to financial services data flows

A bank’s risk office assesses nearly everything that moves. Material business processes go through the risk and control self-assessment (RCSA), controls carry named owners and testing schedules, and new products clear approval committees before launch. The data supply chain feeding the bank’s own risk reports rarely receives equivalent scrutiny. Between the system that first captures a trade and the report that aggregates its exposure, data passes through transformations, integrations, and manual touchpoints that no assessment has named, rated, or assigned to anyone.

Eric Hirschhorn, Chief Data Officer at Bank of New York, describes the problem from the inside. Firms would love a world where data moves cleanly from producer to consumer, he notes, but “many of us see 5, 10, 15 hops from a piece of data being produced to a piece of data being consumed, and every one of those hops is an opportunity to get it right or to have a challenge.”1

Data lineage closes that shortfall. When the lineage model carries ownership and risk context alongside the technical flows, the supply chain behind every risk report becomes something you can assess with the same rigor the RCSA applies everywhere else.

What happens in a handoff

Each handoff between systems exists for a reason. An exchange delivers market data in a format the accounting platform cannot consume, so a transformation reshapes it. A decades-old settlement system uses a format that nothing else does, so integration and translation are needed. And when no interface connects two screens, a team under deadline types in the figures across by hand. None of these steps appear on an organization chart, and few appear in any assessment, yet each can alter a value that ultimately ends up in a regulatory filing.

An error can enter a handoff without detection, because monitoring watches systems rather than the connections between them. A transformation can also run correctly yet remain unprovable, because nobody documented what it does, which leaves the figure it produced without evidence when an examiner asks about provenance.

Gartner reports that data sources in banking, from open banking APIs to market feeds and IoT telemetry, are growing at a pace that overwhelms traditional centralized data architectures, so the number of connections needing assessment rises every year.2 More sources mean more handoffs, and an assessment program cannot cover what nobody has mapped.

One risk report across 211 systems

Hirschhorn describes building a risk report whose inputs span 211 systems, each of which performs activities that produce the artifacts the report requires. Those 211 systems feed 36 sub-ledgers, which in turn feed the risk engine. Every stage raises the same questions. Who owns those systems? Who owns the sub-ledgers? How are the fields transformed along the way?3

Laying the supply chain out on a lineage diagram turned those questions into assignable work. Bank of New York systematized the answers into policies, desktop procedures, and artifacts, backed by its own check-and-challenge process, so that accountability survives staff turnover and reorganizations rather than living in someone’s head.

The operating pattern is consumer-driven. The risk report’s owner specifies what the report requires, and every upstream producer is accountable for meeting that requirement. Ownership is not optional at any point in the chain. “If you are responsible for managing risk at this company, you have to opt in to that supply chain, and you don’t have a choice,” Hirschhorn says.4

A risk report built this way behaves like any other assessed process. The exposures are named, the owners are known, and anyone preparing for an examination can point to the lineage model as evidence of both.

A lineage map becomes a control when it names owners

Automated scanning tools can discover much of the data landscape and map it. Their output, though, is a picture of nodes and edges. Run one against the supply chain above, and you get 211 systems rendered as boxes and arrows, with no owner on any of them, no risk rating on any flow, and no regulatory obligation attached anywhere. The map is accurate and fast, and it gives a risk officer nothing to act on. Tools built for technical discovery are blind to business meaning.

Business context converts the map into a control. A lineage platform that holds ownership, service-level agreements, risk ratings, and regulatory tags directly on the flows starts to behave like a controls inventory. Exposure is computed from the lineage model rather than compiled through interviews. Ask which report inputs cross a jurisdictional border, or which upstream systems carry a high operational risk rating. The answer comes back in minutes, current as of the model’s last update.

Insurers and asset managers often apply this discipline via a risk register rather than an RCSA, and they face the same problem. A hand-compiled register describes the data ecosystem as it stood at the last refresh, and the limitation applies to the RCSA itself. Workshops and interviews capture a moment, and the underlying data flows keep changing after the moment passes. For a fuller comparison of how lineage platforms and metadata catalogs differ on this point, see the data lineage vs. metadata management comparison.

Evergreen evidence instead of annual assessment

Supervisors have moved their expectations in the same direction. The European Central Bank’s May 2024 guide on risk data aggregation expects banks to maintain complete and current data lineage down to the individual data attribute, and a lineage rebuilt after the examination notice arrives does not meet that bar.5

A global investment bank shows what meeting that expectation looks like in practice. To bring an environment centered on an Oracle data warehouse with 30 source systems under BCBS 239, the bank built its lineage model in Solidatus and activated data quality rules inside it, so issues alert their owners the day they appear.6

Change-impact assessment that once took months now takes minutes, and the same lineage model produced the bank’s first data dictionary that updates itself.7 Preparing for an examination stopped being a scramble to assemble evidence, because the evidence never goes stale.

Firms that stay ahead of the exam cycle treat data quality as an operating rhythm. Quality scorecards raise incidents, teams address them, and the lineage model stays clean between assessments.

AI multiplies the cost of a stale assessment

AI accelerates the rate at which enterprise data changes and broadens the scope of what any single decision consumes. An AI model retrained quarterly, or an agent pulling from dozens of systems per decision, sits downstream of far more handoffs than any human analyst ever did, so each unassessed handoff now feeds more outcomes than it used to. Gartner notes that AI in banking has to run inside regulated workflows with provable controls and auditability, which puts the data supply chain behind every AI model inside the scope of risk management, whether or not anyone has assessed it.8

The same lineage foundation extends assessment discipline to AI-driven change. The AI Lineage Assistant in Solidatus reasons over the full lineage graph, including business relationships and regulatory frameworks such as BCBS 239, so recommendations about your data environment arrive with regulatory context already attached. Risk teams get the same ownership answers for an AI model’s inputs as for a risk report’s inputs.

Where to start

Three moves put this discipline in place, and each one depends on lineage that combines end-to-end coverage with business context.

  1. Run the RCSA question against one risk report: Pick the report with the most at stake and, working with the chief data officer, enumerate its supply chain, assigning a named owner at every handoff. Where the enumeration stalls, usually at a system an automated scanner cannot reach, you have found exposure you are carrying unmeasured. Closing it requires a lineage platform that combines automated capture with curated modeling, so the chain runs to its true source rather than stopping at the first unreachable system.
  2. Attach risk context to the flows themselves: Ownership, risk ratings, and regulatory tags belong on the connections where the risk lives, and once they are there, the assessment updates when the graph changes rather than when the next workshop convenes.
  3. Make one attestation evergreen: Choose an attestation your team assembles evidence for annually and move it onto a living lineage model with active data quality rules. An asset management firm that made this move cut related costs by 60 percent and now reaches decisions in minutes instead of months.9

If you want to see what an assessed supply chain looks like on your own data landscape, request a demo and bring your hardest risk report.

1Hirschhorn, Eric. “Pioneering Data Strategies: How Bank of New York Is Shaping Business Success in the Age of AI.” Solidatus webinar, 2025.
https://www.solidatus.com/resource/pioneering-data-strategies-how-bank-of-new-york-is-shaping-business-success-in-the-age-of-ai-webinar-recording/.

2Bhattacharya, Sudarshana, Kimberly Harris-Ferrante, and Jasleen Kaur Sindhu. “Top Data and Analytics Trends in Banking and Insurance for 2026.” Gartner, February 3, 2026. G00843275.

3Hirschhorn, Eric. “Pioneering Data Strategies: How Bank of New York Is Shaping Business Success in the Age of AI.” Solidatus webinar, 2025.
https://www.solidatus.com/resource/pioneering-data-strategies-how-bank-of-new-york-is-shaping-business-success-in-the-age-of-ai-webinar-recording/.

4Hirschhorn, Eric. “Pioneering Data Strategies: How Bank of New York Is Shaping Business Success in the Age of AI.” Solidatus webinar, 2025.
https://www.solidatus.com/resource/pioneering-data-strategies-how-bank-of-new-york-is-shaping-business-success-in-the-age-of-ai-webinar-recording/.

5European Central Bank Banking Supervision. Guide on Effective Risk Data Aggregation and Risk Reporting. May 2024.
https://www.bankingsupervision.europa.eu/ecb/pub/pdf/ssm.supervisory_guides240503_riskreporting.en.pdf.

6Solidatus. “Global Bank Automates BCBS 239 Compliance” (case study). 2023.
https://www.solidatus.com/resource/providing-accurate-complete-and-timely-data-for-bcbs239-compliance/.

7Solidatus. “Global Bank Automates BCBS 239 Compliance” (case study). 2023.
https://www.solidatus.com/resource/providing-accurate-complete-and-timely-data-for-bcbs239-compliance/.

8Bhattacharya, Sudarshana, Kimberly Harris-Ferrante, and Jasleen Kaur Sindhu. “Top Data and Analytics Trends in Banking and Insurance for 2026.” Gartner, February 3, 2026. G00843275.

9Solidatus. “Asset Management Firm Transforms Investment Environment” (case study). 2023.
https://www.solidatus.com/resource/asset-management-firm-transforms-investment-environment/.

Frequently asked questions

01.

How does data lineage reduce risk in financial services?

Data lineage reduces risk by mapping every transformation, integration, and manual touchpoint that data passes through between its source and the reports it feeds, then attaching owners, risk ratings, and regulatory obligations to those flows. This turns an unexamined data supply chain into an assessed one, so errors are caught at the point of entry, accountability is assigned before an incident occurs, and evidence for supervisors stays current rather than being rebuilt for each examination.

02.

What is data lineage risk management?

Data lineage risk management is the practice of applying risk assessment discipline to data flows themselves, treating each handoff between systems as a potential point of error, unevidenced transformation, or unassigned accountability. A business lineage platform such as Solidatus supports the practice by holding ownership, service-level agreements, risk ratings, and regulatory tags directly on the flows, so exposure is computed from a living model of the data supply chain.

03.

How is data lineage different from an RCSA?

A risk and control self-assessment (RCSA) captures risks and controls through workshops and interviews at a point in time, and it covers business processes more often than the data flows beneath them. Data lineage complements the RCSA by extending the same discipline to the data supply chain and keeping it current, because a lineage model updates as systems and flows change rather than waiting for the next assessment cycle.

04.

Why can't automated scanning tools manage data risk on their own?

Automated scanners discover technical flows and produce an accurate map, but the map arrives without owners, risk ratings, or regulatory context, leaving a risk officer with nothing to act on. Managing risk requires business context attached to the lineage, including who owns each system, which obligations govern each flow, and how severe an upstream issue would be. Scan-only tools are fast at technical discovery and blind to business meaning.

05.

What do regulators expect from risk data lineage?

The European Central Bank’s May 2024 guide on risk data aggregation and risk reporting expects banks to maintain complete and current data lineage down to the individual data attribute, building on the BCBS 239 principles for risk data aggregation. In practice, supervisors expect lineage to be maintained as a control, rather than for documentation to be assembled after an examination is announced.

06.

Where should a chief risk officer start with data lineage?

Start with one high-stakes risk report and enumerate its data supply chain, assigning a named owner at every handoff between systems. Where the enumeration stalls, you have found unmeasured exposure. From there, attach risk ratings and regulatory tags to the flows, and move one annual attestation onto a living lineage model with active data quality rules, so its evidence stays current year-round.

Published on: August 26, 2026

Contents

Related articles

Blog

What to look for in a data lineage platform

A buyer's guide to choosing the foundation of your AI stack.

Data Lineage is Finally Getting the Attention
Blog

Your riskiest change ticket says low risk

Pre-change impact analysis for data estates that feed AI

Blog

Why banks can’t meet modern regulations without data lineage

What BCBS 239 and SR 26-2 now demand at the column level

Blog

Solidatus 2026.3 puts data lineage where AI agents can reach it

MCP support, Bring Your Own LLM, and an assistant that keeps its context

Blog

Lineage tools forget what your AI model saw

Bi-temporal data lineage is the foundation of forensic AI investigation

blogImgShadowAI
Blog

Shadow AI is a sovereignty problem

Why an AI use policy cannot enforce itself.

Ai lineage company
Blog

Your Data Governance Team Already Built Your AI Governance Foundation

How LSEG turned data lineage into a strategic asset for AI trust

Blog

Proving data lineage to regulators

What regulators expect when they ask you to prove data lineage

Blog

Data lineage vs metadata management: The architecture behind AI governance

Why catalog-first tools fall short when regulators ask how your training data moved

Blog

Model Risk Starts in the Data Supply Chain

When an AI model starts producing unexplainable results, the first instinct is to blame the model. Teams often rush to...

Blog

The Data Fairy is Dead

Five data lineage myths that the masterclass got right

Four AI governance questions your data catalog cannot answer
Blog

Four AI governance questions your data catalog cannot answer

What regulators are already asking about your AI, and what it takes to respond

Ai lineage company
Blog

The Engineering of Trust: Why Metadata isn’t enough for AI

Three questions your AI governance approach must answer

Blog

The 48-Hour Test: Does Your AI Have Complete Data Lineage?

Three institutions receive the same question during Model Risk Management reviews: “Walk us through the complete data lineage for your...

Data lineage and AI
Blog

How data lineage prevents AI failures in financial services

Solidatus’ Tina Chace and fellow experts reveal why 90% of AI model failures trace back to upstream data changes

Blog

Why Data Lineage is Essential for AI: 7 Governance Challenges Solved by AI-Ready Lineage

AI-ready data lineage is a comprehensive, auditable record of how data flows through your organization, designed to support AI governance...

ai data lineage
Blog

Detailed Expectations Around End-to-End Data Lineage and BCBS 239 From the European Central Bank RDARR Guide

In May 2024, the ECB released its ‘Guide on effective risk data aggregation and risk reporting (RDARR)’...

Blog

Why is Advanced Data Lineage Fundamental for Financial Services Organizations?

Read why advanced data lineage is crucial for business success

Blog

Continuing Innovation in Advanced Data Lineage to Help Answer Business Questions

An update on some recent developments in our latest product releases

Blog

Unveiling the Path: Why Data Lineage is Crucial for Building Effective AI Products

Read more about data lineage and its business impact, including on AI, BCBS 239 and more

Blog

Solidatus & Microsoft Purview: Elevating Data Governance in the AI Era

Solidatus data lineage partners with Microsoft Purview to help enterprises trust their data

Blog

Blasting Off: Why Proactive Data Governance is Propelling Innovation

Read our key takeaways from Gartner D&A Summit 2024

Blog

Live Demo: Explore our All-new Interface

Video introducing our new interface and core features like Connected Catalog and Data Map

Blog

Visualize Snowflake Horizon and Enhance its Impact

Read about Solidatus and Snowflake Horizon's governance solution

Blog

Advanced Data Lineage: The Cornerstone of Modern Data Governance

Explore the various aspects of data lineage and its crucial role in your organization.

Blog

Achieving Basel III Compliance: A 3-Step Action Plan

Basel III is changing – are you prepared? Read 3 easy steps with Solidatus

Blog

Building a Data Community

Read how we helped successfully launched the Houston Women in Data Chapter

Blog

Data Lineage for Better Planning

Exploring the parallels between urban planning and data planning projects

Blog

Data Distress: Data Leaders on Brink of Quitting Jobs

71% of senior data leaders in financial services polled are close to quitting their jobs

Blog

Supercharging your Snowflake Governance with Solidatus

Take a look at what's new in our partnership with Snowflake

Blog

The Value of Data: Reflections from Attending Gartner

VP Product, Tina Chace, reflects on the Gartner conference, covering data governance and AI

Blog

Douze Points for New Way to Visualize Eurovision Data

We’ve linked the Eurovision Song Contest to the realm of data governance and data lineage

Blog

Quick Answer: What is Active Metadata?

In the latest Gartner® research note, find out what active metadata is

Blog

The Amazing World of Active Metadata

The role of metadata, dynamic visualization and inference across metadata

Blog

5 Ways Great Metadata Connectors are Game-Changers

Automatic connectors are essential for efficiently mapping metadata but not all are created equal. We look at the most important...

Blog

5 Things we Can’t Wait to Do at the Gartner Summit, Orlando

We discuss injecting active metadata into your governance and 4 other things we’re looking forward to at the Gartner® Data...