The RegTech Pulse
The RegTech Pulse examines the latest industry and technology trends that help organizations fight financial crime and streamline payments, so money and goods can move safely and securely around the world. Industry experts across the world join the conversation to discuss their insights and share best practices. The RegTech Pulse is brought to you by LexisNexis Risk Solutions, which helps power compliant and assured client transactions to build an interconnected and trusted financial ecosystem.risk.lexisnexis.com/regtechpulse
The RegTech Pulse
Data Governance, Model Risk Management and the Future of Risk-Relevant Data Sharing
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Organizations are under increasing pressure to demonstrate that their compliance decisions are supported by robust data, well-governed models and effective oversight. Whether supporting sanctions screening, transaction monitoring or customer risk assessment, strong data governance and model risk management are essential foundations for effective compliance.
In this episode, Everest Group's Dheeraj Maken and Kriti Gupta discuss the changing landscape of data governance and model risk management, what good looks like in practice, and how firms can ensure compliance outcomes remain transparent, defensible and effective.
They also explore risk-relevant data sharing - one of the top financial crime compliance trends to watch in 2026 - and how organizations can balance collaboration with privacy, regulatory and operational requirements.
Learn more about Everest Group's work at www.everestgrp.com. Learn more about LexisNexis® Risk Solutions at www.risk.lexisnexis.com.
Speakers:
Dheeraj Maken, Vice President, Everest Group
Dheeraj Maken brings 15+ years of experience across banking, financial crime and compliance, capital markets, and digital transformation. He leads Everest Group’s research on financial crime and compliance, with coverage spanning anti-money laundering, know your customer, transaction monitoring, fraud, sanctions screening, and regulatory technology. He advises financial institutions and technology providers on market developments, technology strategy, operating-model transformation, and emerging compliance priorities.
Kriti Gupta, Vice President, Everest Group
Kriti Gupta brings 11+ years of experience across banking, lending, payments, risk, compliance and financial services technology. She leads Everest Group's research on financial services technology with a keen focus on financial crime compliance. She has extensive expertise in provider assessment, vendor management, business case quantification, competitive intelligence, and platform modernization. Her research covers banking technology, AI in FCC, customer experience orchestration, and wealth management.
DISCLAIMER: The information provided in this podcast is for informational purposes only and is not intended to and shall not be used as legal advice. The views and opinions expressed in this podcast are solely those of the speakers and do not necessarily reflect the views or positions of LexisNexis Risk Solutions. LexisNexis Risk Solutions does not warrant that the information provided in this podcast is accurate or error-free.
Why Data Now Drives Compliance
Julia ThornWelcome to the RegTech Pulse podcast, everyone, where industry experts discuss the latest trends in financial crime compliance. I'm your host, Julia Thorn, and today we'll be discussing data. Specifically, why data governance, model risk management, and responsible data sharing are now sitting at the center of effective financial crime compliance.
Meet Everest Group And Their Work
Julia ThornI'm joined by Dheeraj Maken and Kriti Gupta from Everest Group. Dheeraj, thank you so much for joining. Maybe if you could start by giving our listeners a quick introduction to Everest Group and specifically your role.
Dheeraj MakenThank you, Julia. Great to be here. Of course, uh Everest Group is a global research and advisory firm. We work with enterprises, technology providers, and service providers, and we basically help them understand where markets are heading, what best practices look like. My own focus area is financial crime in compliance and risk transformation. So I spend a lot of my time researching how banks and financial institutions are modernizing their compliance operations and technology, and also help them take decisions around uh how to source different technology, how to source different service providers in this particular space.
Julia ThornThanks, Dheeraj. And Kriti, maybe the same from you?
Kriti GuptaThanks, Julia. Great to be here today. Uh so I'm Kriti Gupta. I look after our banking financial services technology research here at Everest Group with a keen focus on the broader risk and compliance space and how it is evolving. Uh so those are my focus areas in my day-to-day uh role. I work extensively with a lot of banking and financial services institutions as they look through their entire sourcing strategy across different platforms and technology areas, cutting across banking, lending, payments, risk compliance.
Julia ThornBrilliant. Well, I appreciate you giving your time to be here today. It's fabulous to have you here. Let's let's dive into it. So
What Is Fueling Data Governance
Julia Thornlet's start off with with the data governance, which is the one of the main themes of our discussion today. And Dheeraj, maybe starting with you, what are you seeing as some of those key drivers behind this renewed focus on data governance?
Dheeraj MakenAbsolutely. So uh I think the biggest driver is transformation itself. Banks and financial institutions are going through significant change programs right now. Uh, and the more focuses uh on change the bank rather than just run the bank. Uh, and hence they are adopting more advanced tools and systems across the uh compliance stack, right? Uh, and all of these programs depend on uh data flows and pipelines, right? So the important part here would be that these data pipelines very often carry client sensitive and uh personally identified or uh personally identifiable or PII information. So the more ambitious the transformation, the more data is moving through the organization, and hence when it comes to the uh stakes, it becomes larger or higher, right? So, strong data governance is what reduces the risk of data leakage or even um data being used inappropriately by some of the bad actors. So, governance needs to be much more uh proactive rather than uh being a post facto decision, hence, it becomes uh something which is quite strategic and a pre-condition for transformation. That's exactly why uh across the board you would see uh there is a strong emphasis on governance, and hence uh simply thinking about modernizing compliance without uh having a proper governance plan, uh it's something which organizations cannot uh take a risk of and and so that that's it's it's all well in terms of being proactive around this, but we know that that's not always the case, and it's not always as easy as maybe people think it's going to be a challenge.
Julia ThornAnd Kriti, where are you seeing firms encountering those challenges when it comes to improving their data governance?
Kriti GuptaSure. So while we are also looking at why governance is important, and I know Dheeraj talked about the more ambitious the transformation, the more different types of data uh are flowing through the pipelines, and then where that poses a lot of challenges today in enterprises in their product transformation journey, I would say I see two broad challenges. Uh the first one is more around uh while enterprises today will have these policies in place, they will have the platforms in place, how do they change the day-to-day operating models? Because that's the biggest change management shift, the day uh the ways of working shift that needs to come in and how that manifests. So data is still spread across legacy systems, it is still spread across technology platforms, ownership is not defined, different teams have different typologies and methodologies of classifying data. So, how do you bring all of it on the same stage? So that that's the biggest challenge today uh that enterprises face. The second one being around as AI adoption happens, right? So we just touched upon the external data, the internal data that you are working on, the complexities is still growing, right? So in that manner, compliance and the broader governance piece, it cannot be a periodic exercise. It has to be something that how do you embed into your day-to-day working? How do you manage the data? How do you use the data? How do you share that data? So more than anything, more than having a policy in place, it's about bringing that operationalization of governance at scale and ensuring your teams are on the same page. Those are the two broad challenges I see enterprises are facing today.
Julia ThornYeah, and if and if I may, I'll do a shameless plug for a white paper which we are releasing very shortly around, specifically for Asia Pacific businesses. So a lot of the focus in that white paper around is around sort of optimizing data and screening. And we do talk about rich data, consistency, explainability of decisions, transliteration, and how companies can deal with all of those challenges. So hopefully that might help with with some of the challenges that we're seeing now anyway.
Model Risk Management As An Enabler
Julia ThornUm, and so we've talked a bit about the importance of well-governed data, but ultimately that's the data which is being used to make decisions, and that's where this term model risk management comes in, or is increasingly important, I should say. So, from Everest's perspective, why is model risk management such a critical part of financial crime compliance, particularly around this transformation piece which you've talked about?
Dheeraj MakenYeah, so it comes down to a fundamental shift in how compliance needs to be done, right? Organizations are moving away from just a checklist-based compliance towards more of a risk-based compliance approach, right? And once they move into a risk-based approach, the models are the ones which sit at the heart of decision making based on uh how much an organization's risk appetite is. Basically, these models are determining which customers, what sort of transactions, what sort of alerts are the ones which uh gets more scrutiny compared to the ones which would uh have a straight uh through pass, right? So these risk tiers essentially are the ones which again won't be a uh one size fit-all uh approach to model risk management, and it would be different for different sorts of organizations. Now, what's appropriate for one organization may be completely opposite for another, depending on the kind of businesses they are, the kind of SLAs they are tracking, the kind of um shift they are looking at in their operating model, right, and the kind of customer experience they are chasing. At the same time, uh, what sort of risk are they willing to take, right? Or what sort of exposure are they willing to provide to their customers? The other point would be that the model risk management isn't a break on transformation, right? It's a very important transformation enabler. Why? Because it uh supports model tuning, it supports uh your various scenarios, testing and backtesting, and it also gives you proper audit trails. So you have auditability, you have explainability built in in the models, right? So, what all of these uh characteristics of a uh MRM platform does is that it basically builds regulator confidence, which then allows you to keep innovating, right? Because for regulators, what's most important is that your solution should be robust, it should not be just ticking off some of the validation uh checkpoints or a simple uh QA or an audit exercise, right? The model risk management is basically bringing in all of the uh confidence parameters into the picture so that the regulators are brought within the confidence and hence uh would be happy to uh work with you in the innovation journey.
Julia ThornYeah, it's interesting. This theme around confidence and explainability, I think, is just coming through so so strongly with with conversations with customers as well. So I think it's a really good
Where Model Risk Still Breaks
Julia Thornpoint. And and so if we've talked about this is what good model risk management is, this is the purpose of it, where are firms still getting caught out? What is what is stopping it, or what is what is bad model risk management look like?
Kriti GuptaYeah, so um I can start, I can start on that, Julia. So while I know we touched upon why it is critical, what is happening, I still feel organizations today are exposed in two broad areas. The first one being the third-party model risk. So what is happening today is financial institutions are relying on a lot of the platforms, and they're assuming that the governance responsibility is shifting to the platform provider or the supplier in this case. While in reality, regulators will still continue to hold the institution or the enterprise accountable because that's where decisioning is actually happening, and they are responsible for those decisions. So the bigger piece here for enterprises and institutions is they really need to understand how these third-party models work, how is the data flowing, what are the limitations, how do they monitor the performance over time? So just simply adopting a platform will not transfer uh the ownership or the accountability. I think that's the key piece, and every enterprise is different, so it needs to be in that context. The other piece where I still feel organizations remain exposed is the ecosystem complexity. I know we touched upon this a minute back, uh, that different models are assessing uh sanction screening or they're doing a customer risk assessment profile. And in all, if you look at the decision pipeline, it is a mix of these different models coming together, the outcome of multiple models operating together. And this is where each component is individually governed. But what organizations really need to build in is how that entire system of models is getting governed. How are you ensuring that you are able to have a full view on the transparency, the explainability, and auditability from start to finish and not just on components? So that is where just uh restraining ourselves to testing individual models, but then looking at the entire decision ecosystem, which we were talking about a few minutes earlier, is the other gap that I am seeing, which enterprises are investing in today.
Julia ThornAnd I think so. We've we've and we've talked about so there's the data governance piece, and you talked about the the ecosystem piece. I
Safer Data Sharing Across Institutions
Julia Thornthink if I may, I'll just touch on one of the trends that we've explored this year. We we every year we release our top top trends to watch for for financial crime compliance professionals, and one of those is around data sharing. So it's almost the governance piece beyond an organization's boundaries. So obviously, we know that financial crime isn't happening in isolation, you've got networks that are operating across multiple jurisdictions, and those the the PII piece, obviously, which you talked about earlier, Dheeraj, is you know, historically you can't share particular pieces of data because of these privacy legislations, which is absolutely fair. But there are these newer frameworks coming in to support safer sharing of relevant information, which can help to fight financial crime. So there is an opportunity for more collaboration for multiple organizations to identify those patterns and connections that might not be visible if they're only looking at their own data. So it's an interesting piece, and we'll we'll include a link in the show notes around that and some of the legislation that is coming in to facilitate that. But I wondered if if that's what you're seeing on the on the Everest side, this may be sort of starting to see public-private partnerships more collaboration across industries.
Dheeraj MakenYeah, you are right that financial crime doesn't happen in isolation, right? Uh when it comes to these different criminal networks, right, they are also sophisticated, they are also utilizing a lot of these uh technology stack or AI tools, right, to make sure that the crime is more complex and sophisticated. So they deliberately operate across multiple jurisdictions, multiple institutions, uh, precisely because they know each firm can only see its own slice of the activity, right? So not a single institution view is there which has the 360-degree uh picture, right? So historically, though firms have faced real barriers in sharing intelligence, uh, multiple reasons, privacy constraints, legal restrictions, um, geographic boundaries, and some of the other operational hurdles, right? And those barriers exist for good reasons, but they have had the side effect of keeping these institutions siloed while criminals were able to collaborate uh freely, right? So, now what is changing is that there are newer frameworks uh which are emerging that are supporting safer sharing of risk-relevant information. Of course, the lot of this uh PII information would be redacted, and then there are uh public-private partnerships and information sharing initiatives which are maturing. We are hearing a lot from some of the other um providers who have created those consortiums for federated learning in some of the uh APAC geographies, uh, is what we are seeing currently, and the benefits which they are seeing is also quite strong. Uh, stronger collaboration is helping these organizations identify some of the newer typologies and patterns and also connections that simply weren't visible earlier when um each firm had access to their own data.
Breaking Down Fraud And Risk Silos
Julia ThornYeah, that's a really interesting point, and and maybe if we look at this from a holistic perspective, moving now to what we're seeing in the Lexis Nexis Risk Solutions side of things, we're increasingly finding that clients are coming to us wanting a far more joined up approach in terms of everything financial crime compliance, uh, as well as fraud prevention, trade compliance, credit risk, everything like that. So there seems to be an appetite for a much more joined up approach, um, one provider to kind of help make life a little bit easier, I think. Is that what you're seeing as well from the Everest side of things?
Kriti GuptaYeah, so uh definitely, Julia. I think this is one trend that we are also seeing converge in the past few years. So historically, what we had seen um at these specifically financial services enterprises, there used to be separate systems for fraud or even risk. Even the risk and compliance teams uh they they're still as separate units today. So even credit risk, for instance, is a separate team. But uh the bigger piece here in all of this is they are all working on the same um underlying customer, the same entity data, or even the same transaction data at times. And what that created is each of these silos built their own interpretation over time. Now we are seeing those silos uh starting to break away because uh increasingly enterprises are realizing there was a lot of duplication, there were a lot of inconsistent risk assessments, a lot of inconsistencies overall within the same institution looking at the same entity. So we are seeing um investments and rather intent to come into building these uh shared data foundations, which again uh is best driven by good governance models that can come in. At the same time, I would say AI has also accelerated this shift because these AI platforms today need access to the continuous pipeline of data and more like a 360-degree view of the same customer, not something that resides in parts within, say, a fraud system or or the broader risk management system. So that's where we are seeing this trend converging. Uh, I would say it it is still in the early stages, uh, but how do you manage the enterprise risk holistically is is something we are also seeing uh as part of the trends in the industry today.
Julia ThornIt's not a conversation in in 2026 without the uh the AI topic coming up. Um, in terms of looking ahead, so obviously we've we've covered where organizations are today, we've talked a little bit about you know AI as as we as as we mentioned.
Agentic AI And Defensible Decisions
Julia ThornUm maybe looking ahead holistically, what uh what are what are some of the things that that Everest Group is is researching? What do you think is going to be having the biggest impact on financial crime compliance in the next few years?
Dheeraj MakenYeah, so a lot of these discussions around uh having a more of a holistic view is shaping up our research agenda as well, right? Uh so Everest Group is expanding its financial crime and compliance research lens towards a broader risk and compliance view, uh, because that's where the clients are also heading. The adjacent areas that are uh coming up are, of course, credit risk, data governance, cyber, audit and assurance, trade compliance, and controls. So financial crime and compliance remains an important tower in its own right. That's not going away. But banks are telling us they want more control and stronger links across these adjacent areas as well. So rather than running each one uh as a separate silo, banks would like to look at uh more of a holistic view on some of these adjacent areas as well, uh, along with that, having more control over the data and much more robust governance uh frameworks on top of.
Kriti GuptaYeah, and if I can add to that, um, Julia, so one of the other things you also mentioned is uh no conversation today is complete without um touching up on AI. So as we have been in this industry and as we track how the technology themes are impacting the broader financial crime compliance space. So, 12 months back, say enterprises were asking us, hey, how can we reduce false positives? How can we improve operational efficiency? Today, if we look at the advent of agentic AI in the broader financial crime compliance space, the discussion is more about uh how do we make defensible risk decisions, how do we make our data foundation stronger? I think that is one key theme we are also seeing. So we are coming up with our agentic AI research in the financial crime compliance space, and all of this is boiling down to hey, we really need to have strong data governance and better modeled risk management. So that's that's one thing we are also seeing, and um that that's where we are seeing the industry also move towards uh its adoption in the broader AI technology.
Data Quality As The Final Word
Julia ThornYeah, and it seems as though I think I think everything seems to come back to the the quality of data. You know, if if you're feeding anything, whether it's a whether it's a system, whether it's an AI tool, if you're feeding it with poor quality or poorly governed data, everything's going to just fall apart. So I think that that's kind of a a key point that we can we can close this this episode with. So Diraj Kriti, thank you so much for joining me today. It's been an absolute pleasure. Thank you.
Dheeraj MakenThank you so much for having us.
Resources And Closing
Julia ThornAnd to our listeners, if you would like to learn anything more about the work of Everest Group or keep an eye out for their upcoming reports, you can visit their website, which is Everestgrp.com. If you want to learn more about uh how we can help organisations in the latest industry standards, you can visit risk.lexisnexis.com. Thanks everyone. Thanks, Dheeraj and Kriti, and stay tuned for the next episode.