First Republic was acquired by JPMorgan in May 2023. Within weeks, the OCC issued guidance about governance continuity during absorption. What got less attention: the acquired bank's data governance certifications, some less than six months old, became instantly invalid. New ownership structures meant new data domain owners. New system integrations meant new lineage paths. New risk tolerances meant new thresholds. Every certification the bank had earned was void, not because the content was wrong, but because the context had changed.
That is the reorg tax. And it is screaming through Tier 2 banks at a rate most C-suites do not calculate.
The Hidden Line Item
Reorganizations are supposed to create efficiency. In data governance, they do the opposite. Every restructuring, whether a merger, a leadership change, or a business line realignment, invalidates the governance fabric that certifications were built on.
Consider what a certification actually proves. It proves that a specific person, in a specific role, with specific authority, attested that a specific data element, flowing through a specific lineage, meets a specific quality threshold, under a specific policy. Change any one of those variables and the certification is no longer valid. Not questionable. Invalid.
Now count how many of those variables change in a typical reorg. Business lines get renamed. Data domain ownership shifts. Risk thresholds get recalibrated. System integrations create new lineage paths. Vendor relationships consolidate. Each change is a broken link in the certification chain.
The Math Nobody Runs
Here is a simple calculation for any bank that has reorganized in the last 18 months:
1. Count the number of data governance certifications you held before the reorg.2. Count how many of those certifications reference a data domain owner, a system of record, or a quality threshold that changed during the reorg.3. The second number divided by the first is your reorg invalidation rate.
Most banks we have worked with land between 60 and 80 percent. That means the governance capital they built over months or years evaporated in a single quarter. And the cost of recertifying is not trivial. Each certified data element requires re-validation of its lineage, re-attestation by its new owner, and re-alignment with current policy. At scale, this is months of work.
Why This Keeps Happening
Certifications are typically managed as documents. A PDF, a spreadsheet, a SharePoint file. They describe governance at a point in time. When the organizational context changes, nothing automatically flags the certifications as stale. The documents still exist. They still look valid. Nobody throws them out.
This is the same problem as technical debt, but quieter. Technical debt shows up in systems that slow down or break. Governance debt from reorgs shows up in certifications that look current but are disconnected from reality. The first time anyone notices is when an examiner asks for proof and the owner named in the certification left the bank three months ago.
The Structural Fix
The fix is not to stop reorganizing. It is to stop treating certifications as documents and start treating them as living records tied to organizational context.
When a data domain owner changes, every certification tied to that owner should automatically enter a recertification queue. When a system of record is deprecated or migrated, every certification referencing that system should flag for re-validation. When risk thresholds are recalibrated, every certification measured against the old threshold should surface for review.
This is not a manual process. At the scale of a Tier 2 bank with thousands of certified data elements, manual recertification after every reorg is a fantasy. It has to be automated, and it has to be triggered by the organizational change itself, not by a quarterly audit that discovers the gap six months late.
The CoComply Approach
CoComply ties certifications to organizational context. When the context changes, ownership, systems, thresholds, the certifications automatically flag for recertification. No manual discovery. No stale documents floating around looking valid. The governance fabric adapts to the reorg instead of breaking under it.
Calculate Your Reorg Tax
Take your last reorg or acquisition. Pull your certification inventory from before and after. Count the certifications that would fail validation today because the owner, system, or threshold they reference no longer exists. Multiply that count by the hours it takes to recertify each one. That number is the governance debt your reorg created. If it is more than a few weeks of effort, you are not governing data. You are rebuilding governance from scratch every time the org chart moves.
