A $28 billion-asset regional bank discovered in late 2023 that its commercial lending team had built 340 separate dashboards in its self-service analytics platform. Each dashboard pulled from slightly different data cuts, applied different filters, and used different definitions of "exposure." When the CRO asked for the bank's total commercial exposure across three risk categories, she got six different answers from six different dashboards, all built by smart analysts who trusted the data they were working with.
Nobody had violated any policy. The self-service platform was working exactly as designed. What was not working was governance. And the gap between self-service capability and governance coverage is now the single largest source of unmanaged data risk in Tier 2 banks.
The Scale of the Problem
Self-service analytics adoption in banking has grown 300 percent since 2020, according to Gartner's 2024 banking technology survey. Governance coverage for self-service outputs has not kept pace. In most banks, the governance framework covers production reports: regulatory filings, board packs, risk reports. It does not cover the 340 dashboards, the ad-hoc queries, the data extracts that business analysts pull to make operational decisions every day.
These decisions are not trivial. A commercial lending officer using a dashboard with stale counterparty data green-lights a facility that should have been flagged. A portfolio manager working from a self-constructed view misses a concentration risk that the formal risk system would have caught. A treasury analyst working from a filtered subset overestimates liquidity buffers. Each of these is a governance gap masquerading as empowerment.
Why Traditional Governance Cannot Reach Here
Governance programs were not designed for self-service. They were designed for controlled environments: data warehouses with defined schemas, report factories with change control, and regulatory filings with sign-off workflows. Self-service analytics is the opposite. It is a sandbox. Users create, modify, and share analyses without governance touchpoints.
The typical governance response is to try to extend control: require certification of self-service datasets, mandate review of dashboards, impose change control on queries. This works in the same way that putting a speed limit sign on the autobahn works. Everyone sees it. Nobody obeys it. The volume of self-service output is too high and the velocity too fast for manual governance to keep up.
The Friction Problem
There is a deeper tension. Self-service exists because governed reporting is too slow. If the commercial lending team had to wait three weeks for a new report from the data team, they would build it themselves. They did build it themselves. Adding governance constraints to self-service does not make it governed. It makes it slow, and then users bypass the governance the same way they bypassed the central reporting function.
The answer is not more friction. It is governance that travels with the data, not governance that sits on top of the platform.
What Governance-in-the-Data Looks Like
Instead of certifying dashboards after they are built, certify the data before it arrives in the self-service environment. Every dataset available in the self-service platform should carry metadata that says: this data is certified for these purposes, by this owner, with these quality thresholds, as of this date. When an analyst builds a dashboard, the certification context travels with every widget.
If the analyst filters the data in a way that invalidates the certification, say by excluding a segment that the certification requires, the dashboard should surface a warning, not block the work. The analyst can proceed. But the decision is flagged. The governance is informational, not bureaucratic. It informs the decision instead of preventing it.
This requires a different architecture. It requires data quality scores embedded in the datasets themselves. It requires lineage information that is accessible from within the analytics tool. It requires certification context that updates automatically, not just at quarterly review.
The CoComply Position
CoComply certifies data at the source and extends that certification into consumption layers, including self-service. When data enters the analytics platform, it carries its governance context. Analysts work with governed data without waiting for reports. Governance travels with the data, not after it.
Test Your Exposure
Ask your top self-service analytics user to show you the dashboard they use most often. Then ask: when was the data in this dashboard last certified? Who owns the underlying data elements? Would you know if the certification had lapsed? If the answer to any of those is a blank stare, your self-service analytics is an ungoverned decision factory. It is producing confidence without governance. That is not empowerment. That is exposure.
