Two Regulators, One Data Set, Zero Agreement: Cross-Border Governance at the Breaking Point
Data GovernanceCorporate Governance

Two Regulators, One Data Set, Zero Agreement: Cross-Border Governance at the Breaking Point

written byCoComply Team
published on07/10/2026

In September 2024, a $68 billion-asset bank with operations in the US, UK, and EU received simultaneous examination requests. The OCC wanted proof that its US consumer lending data met BCBS 239 accuracy standards. The FCA wanted evidence that the same data, processed through its UK entity, complied with Consumer Duty reporting requirements. The EBA wanted assurance that the data flowing into its European stress test models had complete lineage documentation back to source systems.

Same data. Three jurisdictions. Three different definitions of "accurate," three different lineage requirements, three different attestation standards. The bank's governance team spent four months and $2.3 million in consulting fees producing three separate proof packs for what was essentially one data ecosystem.

This is cross-border governance debt, and it is the fastest growing category of risk for banks operating across US, UK, and EU regulatory boundaries.

Where the Fractures Appear

Cross-border governance breaks at four specific seams:

Definitional divergence. The same data element, "estimated credit loss," has different calculation methodologies under US GAAP (CECL), IFRS 9, and regulatory stress test frameworks. When your US entity reports one number and your UK entity reports another, both derived from the same underlying portfolio, your governance framework has to explain the divergence. Most cannot.

Lineage fragmentation. Data lineage in a cross-border bank does not flow through a single path. A trade originated in London, booked in New York, risk-weighted in Frankfurt, and reported in all three jurisdictions has at least three branch points where lineage documentation breaks. Each break is a governance gap that one of your three regulators will find.

Attestation conflicts. Data domain owners are typically regional. The US CDO owns US data. The UK CDO owns UK data. But when shared data feeds cross boundaries, who attests to quality? The US owner who sourced it? The UK owner who transformed it? The answer matters, and most governance frameworks do not have one.

Regulatory pace mismatch. The OCC moves on one timeline. The FCA on another. The EBA on a third. A governance program that satisfies today's OCC exam may be six months behind the FCA's latest guidance. Staying current across all three is a full-time job that nobody has time for.

Why It Is Getting Worse, Not Better

The regulatory trajectory is clear, and it is not toward harmony. Post-2008 reforms converged on capital standards. Post-2020 reforms are diverging on data standards.

The EU's Digital Operational Resilience Act (DORA) creates ICT risk reporting obligations that have no US equivalent. The UK's Consumer Duty requires outcome-based evidence that US regulations do not demand. US supervisory expectations around third-party risk (OCC Bulletin 2023-17) have specifics that neither UK nor EU frameworks match.

Each new regulation adds a governance surface that is partially overlapping and partially unique. The partial overlap is the trap. It tempts banks into building one governance program and stretching it across jurisdictions. The unique parts then become gaps that examiners find.

The Architecture Question

The wrong approach is to try to unify governance across jurisdictions. You cannot make three regulators agree on one standard. You can make one governance architecture produce three proofs.

This means building a governance fabric that is jurisdiction-aware from the start. Every data element should carry metadata that identifies which regulatory regimes it touches. Every certification should specify which standards it satisfies. Every attestation should declare which jurisdiction's requirements it addresses.

This is not three times the work. It is structured governance versus unstructured compliance. The difference is whether you spend four months assembling proof packs after the fact, or whether your proof packs assemble themselves because the governance was built to answer the question before it was asked.

The CoComply Connection

CoComply's certification model is jurisdiction-aware by design. Certifications carry metadata about the regulatory regimes they satisfy. When a data element touches multiple jurisdictions, the certification produces multiple proofs from the same governed base. One governance fabric, three exam-ready outputs. No four-month scramble, no $2.3 million consulting bill.

Check This Before Your Next Cross-Border Exam

Pick one data element that flows through more than one regulatory jurisdiction. Trace the lineage from source to report in each jurisdiction. Now ask: does your governance produce separate, exam-ready proof for each regulator from the same underlying certification? Or would you need to build it from scratch? If it is the latter, your cross-border governance is a project waiting to happen. And your regulators will schedule it for you.