Data governance and compliance for financial institutions rests on a stack of overlapping federal rules: banks, credit unions, broker-dealers, and other financial firms must protect customer information under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule, maintain internal controls over financial reporting under Sarbanes-Oxley, run anti-money-laundering programs under the Bank Secrecy Act, honor consumer data rights under Dodd-Frank, and, if they operate in Europe, comply with the GDPR. Meeting those rules means building internal systems that classify data, restrict access, retain records for defined periods, report breaches within tight deadlines, monitor third-party vendors, and produce documentation regulators can examine. Getting it wrong carries civil penalties that can reach six or seven figures per violation and, in some scenarios, criminal exposure for individual officers.
The Federal Laws That Apply
Several statutes create the baseline. Each targets a different risk, and together they cover almost every type of information a financial institution touches.
Gramm-Leach-Bliley Act and the Safeguards Rule
The Gramm-Leach-Bliley Act (GLBA), at 15 U.S.C. §§ 6801–6809, requires every financial institution to protect the security and confidentiality of customers’ nonpublic personal information. It prohibits sharing that information with unaffiliated third parties unless the institution first delivers a privacy notice and gives consumers a chance to opt out.1Office of the Law Revision Counsel. 15 USC Chapter 94 – Disclosure of Nonpublic Personal Information Federal regulators are directed to set standards for administrative, technical, and physical safeguards.2Office of the Law Revision Counsel. 15 USC 6801 – Protection of Nonpublic Personal Information
On the criminal side, fraudulently obtaining customer financial information from an institution carries up to five years in prison, doubling to ten if the conduct is part of a pattern involving more than $100,000 in a twelve-month period.3Office of the Law Revision Counsel. 15 USC 6823 – Criminal Penalty
The FTC Safeguards Rule at 16 CFR Part 314 puts operational teeth behind GLBA. Institutions under FTC jurisdiction must develop, implement, and maintain a written information security program scaled to their size, complexity, and data sensitivity. Technical requirements that took effect in 2023 mandate encryption of customer information in transit and at rest, multi-factor authentication for anyone accessing customer data, and continuous monitoring of information systems.4eCFR. 16 CFR Part 314 – Standards for Safeguarding Customer Information References to a “written security plan” under GLBA are pointing at this rule.
Sarbanes-Oxley Act
Sarbanes-Oxley (SOX), beginning at 15 U.S.C. § 7201, targets the integrity of financial reporting at publicly traded companies. Section 404 (15 U.S.C. § 7262) requires each annual report filed with the SEC to include an internal control report in which management assesses the effectiveness of the internal control structure over financial reporting. For larger issuers, an independent auditor must attest to that assessment.5Office of the Law Revision Counsel. 15 USC 7262 – Management Assessment of Internal Controls Every system that feeds into financial statements needs documented controls covering who can modify data, what approval chains exist, and how errors are caught.
Under 18 U.S.C. § 1519, knowingly altering, destroying, or falsifying records to obstruct a federal investigation carries up to 20 years in prison.6Office of the Law Revision Counsel. 18 USC 1519 – Destruction, Alteration, or Falsification of Records in Federal Investigations The statute reaches beyond accountants. A compliance officer who deletes audit logs or a database administrator who modifies records during a regulatory inquiry faces the same exposure.
Bank Secrecy Act
The Bank Secrecy Act (BSA), at 31 U.S.C. § 5311, is the government’s primary tool against money laundering and terrorist financing. It requires financial institutions to maintain anti-money-laundering programs, report suspicious activity, and file reports on cash transactions exceeding $10,000 in daily aggregate.7FinCEN. The Bank Secrecy Act Institutions need systems capable of flagging unusual transaction patterns and preserving the underlying records for years.
Civil penalties for willful BSA violations can reach the greater of $100,000 or $25,000 per violation. Negligent violations cap at $500 per occurrence, but a pattern of negligent violations can trigger penalties up to $50,000. International counter-money-laundering violations carry penalties between two times the transaction amount and $1,000,000.8Office of the Law Revision Counsel. 31 USC 5321 – Civil Penalties
Dodd-Frank and the CFPB’s Open Banking Rule
Dodd-Frank, beginning at 12 U.S.C. § 5301, created the Consumer Financial Protection Bureau and gave it broad authority over consumer financial products and services.9Office of the Law Revision Counsel. 12 USC 5301 – Definitions The CFPB’s Section 1033 open banking rule requires financial institutions to make consumer financial data available in usable electronic form to consumers and authorized third parties on request. Third parties receiving that data must apply information security programs consistent with GLBA standards.10Federal Register. Required Rulemaking on Personal Financial Data Rights Institutions that have never shared data through APIs now need governance frameworks to handle those outbound flows securely.
GDPR for Institutions with European Customers
If you serve European customers or operate in Europe, the General Data Protection Regulation applies. Its right to erasure lets individuals demand deletion of their personal data when it’s no longer necessary for the purpose it was collected, when they withdraw consent, or when the data was unlawfully processed.11General Data Protection Regulation. General Data Protection Regulation Article 17 – Right to Erasure That creates direct tension with U.S. record-retention laws. Firms operating across both jurisdictions need policies that satisfy the strictest applicable rule on each record.
The most serious GDPR violations carry fines up to €20 million or 4% of total worldwide annual turnover from the prior year, whichever is higher.12Privacy Regulation. Article 83 GDPR – General Conditions for Imposing Administrative Fines
Breach Notification Deadlines You Can’t Miss
When a cybersecurity incident hits, the clock starts immediately. Different regulators impose different windows, and missing them is a violation independent of whatever damage the breach caused.
National banks and federal savings associations supervised by the OCC must notify their supervisory office no later than 36 hours after determining that a notification incident has occurred. A notification incident is one the institution believes in good faith could materially disrupt operations, cause a material loss of revenue, or threaten U.S. financial stability.13eCFR. 12 CFR 53.3 – Notification The same 36-hour deadline applies to FDIC-supervised institutions under a parallel rule.14Federal Deposit Insurance Corporation. Computer-Security Incident Notification
Federally insured credit unions have 72 hours. The NCUA requires notification within that window of reasonably believing a reportable cyber incident has occurred, including incidents causing a substantial loss of data confidentiality or integrity, disruption of vital member services, or unauthorized access to sensitive data through a compromised third-party provider.15National Credit Union Administration. Cyber Incident Notification Requirements
Publicly traded financial companies face an additional layer. The SEC requires disclosure of material cybersecurity incidents on Form 8-K within four business days after the company determines the incident is material, and the materiality determination itself must be made without unreasonable delay after discovery.16U.S. Securities and Exchange Commission. Form 8-K – Item 1.05 Material Cybersecurity Incidents The only exception is a written determination by the U.S. Attorney General that disclosure would pose a substantial risk to national security, which can delay filing by up to 120 days in extraordinary circumstances.
A publicly traded bank could hit all three deadlines at once: 36 hours to notify the OCC, a few days to notify state attorneys general under state breach laws, and four business days to file the 8-K. Incident response procedures need to trigger the required notifications in parallel, not sequentially.
Record Retention and Disposal
Holding data too long creates risk. Not holding it long enough violates the law. Retention rules vary by regulator and record type, and a blanket policy rarely works.
BSA regulations generally require banks to keep records for at least five years. That covers records tied to customer identity (five years after the account closes), international transactions exceeding $10,000, checks over $100, signature cards, and records of monetary instrument purchases of $3,000 or more.17FFIEC BSA/AML InfoBase. Appendix P – BSA Record Retention Requirements
Broker-dealers follow a different schedule under SEC Rule 17a-4. Core books and records such as ledgers, customer account records, and securities transaction blotters must be preserved for at least six years, with the first two years in an easily accessible location. Other business records including communications, bank statements, and trial balances require three-year retention.18eCFR. 17 CFR 240.17a-4 – Records to Be Preserved by Certain Exchange Members, Brokers and Dealers
For tax records, the IRS requires businesses to keep records as long as needed to prove income or deductions on a return. Employment tax records must be kept for at least four years.19Internal Revenue Service. Recordkeeping
When records reach the end of their retention period, disposal must follow the FACTA Disposal Rule at 16 CFR Part 682. Any business that maintains consumer report information must take reasonable measures against unauthorized access during disposal. Acceptable methods include burning, pulverizing, or shredding paper records so they can’t be reconstructed, and destroying or erasing electronic media so data can’t be recovered. Firms can contract with certified record-destruction companies but must exercise due diligence in selecting and monitoring them.20eCFR. 16 CFR Part 682 – Disposal of Consumer Report Information and Records
What Your Internal Program Has to Include
Meeting these overlapping rules takes infrastructure. The systems a financial institution builds decide whether compliance happens by design or by accident.
Data Lineage, Quality, and Access Controls
Data lineage tracks how information moves from the point it enters the institution through every system that transforms, aggregates, or stores it. When regulators ask how a number on a quarterly financial statement was derived, lineage documentation answers. Without it, tracing an error means a manual audit across disconnected systems. A data dictionary standardizes what every field means: when the mortgage department and the wealth management division both use a field called “account balance,” the dictionary ensures they mean the same thing.
Automated data quality checks flag empty required fields, out-of-range entries, and records that don’t match across systems. A loan application with a missing income field should be caught at intake, not discovered in an audit six months later.
Encryption converts readable information into a format unauthorized parties can’t decipher without the correct key. Under the updated Safeguards Rule, encryption must cover customer information both in transit and at rest.4eCFR. 16 CFR Part 314 – Standards for Safeguarding Customer Information Access controls restrict visibility so employees only see what their work requires. A teller processing deposits has no reason to see a corporate merger file, and the system should enforce that automatically.
Third-Party Vendor Oversight
A financial institution’s governance responsibilities don’t stop at its own walls. When a cloud provider hosts customer data, a payment processor handles transactions, or an analytics vendor runs models on consumer information, the institution stays accountable. Federal regulators made this explicit in 2023 interagency guidance on third-party relationships.
The guidance requires due diligence before entering any third-party relationship, scaled to the risk involved. For vendors handling sensitive data, that means assessing the vendor’s information security program, compliance history, financial stability, and ability to meet the institution’s own security standards. Contracts must define each party’s responsibilities, include the institution’s right to audit, and set performance benchmarks.21Federal Register. Interagency Guidance on Third-Party Relationships Risk Management
Ongoing monitoring continues for the life of the relationship: periodic review of performance reports and control effectiveness, testing of the institution’s own controls around the vendor, and independent audits of the vendor’s operations. A common failure pattern is solid upfront due diligence followed by lapsed monitoring. The vendor that passed your security assessment two years ago may have changed platforms, lost key personnel, or suffered its own breach since.
Governance of Automated Models and AI
Financial institutions increasingly rely on automated models for credit decisions, fraud detection, home valuations, and investment recommendations. Each creates governance obligations beyond traditional data management.
The CFPB approved a rule in 2024 requiring institutions that use automated valuation models for mortgage lending to implement safeguards ensuring accuracy, protecting against data manipulation, avoiding conflicts of interest, and complying with nondiscrimination laws. The agency’s position is that there is no technology exemption from consumer financial protection and fair lending requirements.22Consumer Financial Protection Bureau. CFPB Approves Rule to Ensure Accuracy and Accountability in the Use of AI and Algorithms in Home Appraisals
The SEC has proposed rules targeting conflicts of interest when broker-dealers and investment advisers use predictive data analytics in interactions with investors. Under the proposal, firms would evaluate every use of covered technology for conflicts that place the firm’s interest ahead of the investor’s, and either eliminate or neutralize any conflict identified. Written policies documenting the evaluation and the firm’s response would be required.23U.S. Securities and Exchange Commission. Conflicts of Interest and Predictive Data Analytics
In April 2026, the OCC, Federal Reserve, and FDIC issued updated interagency model risk management guidance. It applies primarily to banking organizations with over $30 billion in total assets and covers model development, validation, monitoring, and governance. The agencies excluded generative AI and agentic AI from the guidance’s scope, describing those technologies as “novel and rapidly evolving.” That exclusion doesn’t mean the technologies are unregulated. It means institutions using them can’t rely on this particular guidance as a safe harbor and should expect separate supervisory attention.24Office of the Comptroller of the Currency. Model Risk Management Revised Guidance
Classifying the Data You Hold
Not all data deserves the same protection, and treating everything identically wastes resources while leaving genuinely sensitive records exposed. Governance starts with sorting information into categories that drive security decisions.
Nonpublic personal information (NPI) is the category at the heart of GLBA: personally identifiable financial information a consumer provides to obtain a financial product or service, that results from a transaction with the consumer, or that the institution otherwise obtains. Publicly available information is excluded.25Legal Information Institute. 15 USC 6809 – Definitions Loan application details and data pulled from consumer reports fit squarely here.
Personally identifiable information (PII) is broader. NIST defines it as any information that can distinguish or trace an individual’s identity, either alone or combined with other data linked to that person. Names, Social Security numbers, biometric records, and dates of birth all qualify.26National Institute of Standards and Technology. Computer Security Resource Center Glossary – Personally Identifiable Information Every piece of NPI is also PII, but PII extends beyond financial contexts.
Biometric data deserves separate attention. Fingerprints, voiceprints, and facial geometry used for customer authentication are increasingly common in mobile banking, and they’re arguably the most sensitive category because they can’t be reset like a password. No comprehensive federal biometric privacy law exists as of 2026. A growing number of states have enacted their own requirements, some mandating written retention and destruction policies and others imposing per-violation statutory damages. Institutions operating across multiple states need policies that satisfy the strictest applicable standard.
Corporate financial records form a separate category: internal ledgers, transaction histories, and reporting data that reflect the firm’s financial health. They carry their own obligations under SOX and SEC reporting rules. Metadata tagging at the point of collection lets automated systems apply the correct retention schedule and access rules. When a regulator requests a specific report, proper tagging isolates relevant fields without exposing unrelated sensitive data.
Who Owns Governance Inside the Institution
Clear delegation of authority separates a governance framework that works from one that exists only on paper.
The board of directors owns the strategy. Members don’t manage daily operations, but they approve policies, allocate resources, and review regular reports on security incidents and audit results. When regulators find deficiencies, the trail often leads back to insufficient board oversight or resources.
A Chief Data Officer or Chief Information Security Officer translates board-level strategy into technical architecture. These executives design and maintain the security infrastructure, respond to large-scale threats, and serve as the primary point of contact during regulatory examinations. Below them, data owners (usually the heads of individual business units like mortgage lending or wealth management) decide who should have access to data within their departments and make judgment calls about lifecycle and usage based on business need.
Data stewards handle ground-level work: resolving inconsistencies in databases, running quality reviews, and making sure records match the definitions in the data dictionary. In larger institutions, a dedicated privacy officer focuses on consumer rights requests, opt-out processing, and privacy compliance across jurisdictions.
Proving Compliance to Regulators
All of the above ultimately needs to be demonstrable. Regulators don’t take your word for it. They want documentation, audit trails, and independently verified reports.
Filings
Financial institutions submit information through specialized portals. The SEC’s EDGAR system is the primary channel for securities filings and requires data formatted in XBRL (eXtensible Business Reporting Language) so regulators can analyze submissions efficiently.27U.S. Securities and Exchange Commission. Submit Filings FINRA maintains its own centralized gateway for registration, financial filings, and compliance reporting by broker-dealers.28Financial Industry Regulatory Authority. Filing and Reporting Internal data structures need to produce outputs compatible with these systems without manual reformatting.
Audit Trails and Internal Reviews
An audit trail is a chronological log of every action taken within a database: who accessed a record, when, and what changed. Internal audits review these trails systematically to verify that access controls work, that unauthorized attempts were blocked, and that sensitive data stayed encrypted throughout its lifecycle. Reviews also confirm that documented policies match what actually happens in practice.
External audits by independent third parties give regulators and investors verification they can rely on. For public companies subject to SOX, the external auditor must attest to management’s assessment of internal controls over financial reporting.5Office of the Law Revision Counsel. 15 USC 7262 – Management Assessment of Internal Controls
Examinations and Deficiency Letters
During a regulatory exam, inspectors request specific samples from the audit trail to test whether security protocols work as described. They look for evidence of blocked unauthorized access attempts, encryption coverage, and timely response to detected anomalies. If gaps turn up, the institution may receive a deficiency letter requiring corrective actions and a written response describing what was done. Failing to remediate adequately can lead to a second deficiency letter, escalation to a conference call or meeting with regulators, or referral to the enforcement division.29U.S. Securities and Exchange Commission. Compliance Examination Deficiency Letter Process The documentation trail a well-designed governance program produces is, in practical terms, the institution’s primary defense against enforcement.