In data we trust? Emerging policy and supervisory approaches to AI data use in financial services

Tag: S-2026-03-26-bis-fsi-insights-73-in-data-we-trust Type: paper (FSI Insights on policy implementation No 73) Author(s): Juan Carlos Crisanto, Adrien Currat, Johannes Ehrentraud, Wenguang Wu Date of source: 2026-03-26 Date ingested: 2026-05-29 Authority weight: high — Financial Stability Institute staff paper hosted on BIS; not a Basel Committee standard but widely treated as a leading supervisory reference. Raw file: S-2026-03-26-bis-fsi-insights-73-in-data-we-trust

What it claims

The paper positions data as the central transformation axis of AI in financial services and frames data-related risk as the dominant supervisory concern as AI adoption — particularly generative AI — becomes embedded in core financial-institution activities. It argues that long-standing data-management challenges have become significant barriers to wider adoption of advanced AI systems and that the principal concerns are data privacy, data quality and data security, each of which is intensified by third-party dependencies and market concentration among major service providers.

The authors argue that effectively managing data-related risks is essential for AI adoption to foster innovation while upholding trust, resilience and financial stability. The paper explores: the critical role of data in AI; the associated challenges and supervisory expectations for AI-related data usage with a particular focus on generative AI; common themes in cross-sectoral obligations and guidance issued by financial authorities; and how supervisors can effectively respond to emerging issues. It concludes by identifying areas that could particularly benefit from more tailored supervisory guidance.

The publication runs to 43 pages and is positioned in the FSI Insights on policy implementation series. JEL classification (C60, G29, G38, O30) and keywords (artificial intelligence, machine learning, corporate governance, data governance, risk management, risk modelling) locate the paper at the intersection of governance, risk modelling and data-management policy.

Notable quotes

“Data play a critical role in the transformation of the financial sector through artificial intelligence (AI). While challenges in data management are not new, they pose significant barriers to the wider adoption of advanced AI systems, such as generative AI (gen AI).” — Executive framing, FSI Insights No 73.

“Key concerns include data privacy, quality and security, which are further intensified by third-party dependencies and market concentration among major service providers.” — Executive framing, FSI Insights No 73.

“Effectively managing data-related risks is essential to ensure that AI adoption in financial services fosters innovation while upholding trust, resilience and financial stability.” — Executive framing, FSI Insights No 73.

What’s speculative vs. asserted

  • Asserted: data privacy, quality and security are the principal concerns; third-party dependencies and provider concentration intensify those concerns; common cross-sectoral themes can be observed across financial-authority guidance.
  • Speculative / suggested: the paper identifies areas that could particularly benefit from more tailored supervisory guidance — i.e. it frames policy recommendations as authors’ observations, not as binding standards. The conventional FSI disclaimer applies: views are those of the authors, not of the BIS, member central banks or Basel-based standard-setting bodies.

Topics this feeds

Open questions raised

  • Which specific cross-sectoral themes in supervisory expectations does the paper highlight as most widely adopted?
  • Which areas does the paper identify as needing more tailored supervisory guidance? (Full text not yet read into the wiki — flagged in Open Questions until summarised from the 43-page PDF.)
  • How does the paper treat provider concentration as a systemic-risk axis vs. firm-level third-party risk?
  • How well do existing Basel standards (BCBS 239, BCBS d605) cover the data-risk surface identified here?