Topic hub
Regulated Technology
Regulation sets the questions technology leaders will be asked; it rarely tells them how to answer. These articles read banking and data regulation from the technology side: what BCBS 239, SR 11-7, DORA and their peers expect of platforms, data and the people accountable for them.
Banking technology · BCBS 239 · SR 11-7 · operational resilience
Risk data and model risk
The supervisory expectations that shape banking data and models.
- Regulation
BCBS 239: The Backbone of Risk Data Aggregation & Reporting in Modern Banking
The 14 principles, common industry gaps, and where cloud, AI and modern data governance can help.
- Fundamentals
A Guide to Federal Reserve SR 11-7 (Model Risk Management)
A plain-terms introduction to the Federal Reserve's guidance on managing the risks that come with using models.
- Executive
SR 11-7 in the AI/ML Cloud Era
Applying the SR 11-7 model-risk framework to AI/ML and cloud-native deployments, from board oversight to MLOps pipelines.
- Executive
Why Most Global Banks Underestimate OSFI E-23 Until It Changes Their Operating Model
Why reading E-23 as a vendor-governance exercise misses the larger operating-model shift.
Operational resilience and technology risk
Resilience and technology-risk regimes across jurisdictions.
- Regulation
DORA in Practice: Building Technology Resilience in the Age of AI
How DORA treats resilience as proof rather than paperwork, and how it lines up with OCC, FFIEC and NIST expectations.
- Regulation
Mastering the MAS TRM Guidelines
Translating MAS expectations on technology-risk governance, cloud resilience, vendors and cyber hygiene into strategy.
- Executive
Risk Regulations in Banking and AI for Senior IT Leaders
What U.S. regulators expect banks to do about technology-driven risk: cyber threats, AI model transparency and resilience.
Banking law and accountability
Statutes that change how technology decisions are governed.
- Executive
Dodd-Frank Act Explained for Executives
Dodd-Frank read as a decision-accountability framework rather than a compliance checklist.
- Regulation
Regulation W: Managing Affiliate Risk in the Age of AI and Cloud Banking
Embedding Sections 23A and 23B into the technology stack by design, as AI and cloud make intra-group services pervasive.
Data protection
Privacy regulation from the data platform's point of view.
- Guide
GDPR Compliance Guide for Data Engineers
What GDPR means for the people who build pipelines, data lakes and distributed systems.
- Regulation
FERPA in the Age of AI: Data Governance, Privacy, and Compliance
FERPA through an enterprise data, AI and risk lens, where compliance becomes a capability rather than a checkbox.