When Every Business Line Certifies Its Own Data, Who Certifies the Overlaps?
Risk Data AggregationRisk Management

When Every Business Line Certifies Its Own Data, Who Certifies the Overlaps?

written byCoComply Team
published on07/07/2026

A $38 billion-asset bank restructured in 2023 to push data governance accountability into the business lines. Each line of business, commercial lending, retail banking, wealth management, and treasury, got its own certification authority. The CDO's office shifted from certifier to auditor. Six months later, the bank's stress testing data failed validation. The issue: commercial lending and treasury both certified overlapping exposure data using different quality thresholds. The gap between the two certifications produced a $600 million discrepancy in aggregate exposure figures.

The bank had done the right thing, distributing accountability. It had done it wrong, by leaving the overlaps ungoverned.

The Overlap Problem

Distributed accountability creates a specific governance gap at the seams. When each business line owns its data certifications, three things happen:

Overlapping data domains get double-certified. The same counterparty exposure data lives in the commercial lending system and the treasury system. Each business line certifies its version. The certifications use different thresholds, different quality checks, and different attestation cycles. Both are valid within their domain. Neither is valid at the overlap.

Shared data elements get inconsistent governance. Customer master data flows through every business line. Each line applies its own quality standards based on its own use case. The wealth management line tolerates address format variations that the retail line flags as quality failures. The commercial line enforces completeness standards that the treasury line does not. The data element is governed. It is not governed consistently.

Cross-lineage paths break. When data flows from one business line to another, the lineage crosses a governance boundary. The sending line certifies the data at the point of handoff. The receiving line assumes the certification transfers. But the receiving line's use case may require stricter governance than the sending line's certification provides. The lineage is documented. The governance gap at the boundary is not.

Why This Pattern Is Emerging Now

The trend toward distributed data accountability is accelerating. Regulatory guidance, particularly the OCC's expectations around business line ownership of data risk, is pushing banks to put governance where the data is created and used. This is the right direction. Centralized governance teams cannot scale to cover every data domain in a growing bank. They become bottlenecks, not governors.

But the transition from centralized to distributed accountability is creating seam gaps that most banks have not yet addressed. The CDO's office was the seam manager. It reconciled cross-domain certifications, enforced consistent thresholds, and governed the handoff points. When accountability shifts to the business lines, the seam management often does not transfer with it.

The Governance Architecture for Seams

The answer is not to re-centralize. It is to build seam governance as a distinct function. This means:

Overlap registries. Every data domain that is owned by more than one business line should be registered as an overlap. The registry identifies the overlap, the owning business lines, the certification differences, and the use-case requirements that drive the differences. Overlaps are not problems. Unmanaged overlaps are problems.

Federated threshold frameworks. A single set of base quality thresholds that applies across all business lines, with permitted variations documented and approved by the CDO's office. The variations are explicit. They can be tested. They can be examined.

Boundary certification. When data crosses a business line boundary, the handoff point gets its own certification. Not a duplicate of the sending line's certification. A specific certification that the data meets the receiving line's governance requirements at the point of transfer.

The CoComply Approach

CoComply supports distributed accountability with built-in seam governance. Overlaps are detected automatically when multiple business lines certify overlapping data domains. Threshold variations are tracked and flagged for approval. Boundary certifications are generated at handoff points. Distributed governance stays distributed. The seams do not fall through.

Find Your Overlaps Today

Ask your CDO: which data domains are currently certified by more than one business line? If the answer is "we are not sure," your seam governance is based on hope. Pull the certification records for three data elements that cross business lines. Compare the thresholds, the quality checks, and the attestation cycles. The differences are your overlap risk. Undocumented, it is a gap. Unmanaged, it is a finding waiting for an examiner.