Data governance in financial institutions is the set of controls that decide who holds customer data, who may move it, and how every one of those decisions is evidenced to a supervisor. Most failures in the sector happen inside working controls rather than because controls are missing, which is why examiners increasingly ask institutions to prove that employee behavior changed.
Table of Contents
ToggleWhat Data Governance Covers in a Financial Institution
Data governance in a bank, broker-dealer, insurer, or asset manager covers six things: what customer data the institution holds, where it lives, who may access it, how long it is retained, how it leaves the organization, and what record proves each of those answers. The last item is the one that separates financial services from other regulated sectors. A manufacturer with weak lineage documentation has an operational problem. A financial institution with weak lineage documentation has a supervisory finding.
That evidentiary burden is why data governance and cybersecurity governance, risk, and compliance have converged in the sector. A supervisor rarely asks whether a policy exists. The question is whether the institution can show the policy operating, on named systems, across named people, over a defined period. Institutions that treat governance as documentation discover the gap during an examination, which is the most expensive place to discover it. The broader control picture is covered in this guide to cybersecurity in banking and financial institutions.
Why Financial Data Governance Fails in the Behavior Layer
The largest data governance enforcement campaign in the history of financial services was not about a technology gap. It was about what employees did with their phones. In September 2022, the SEC and the CFTC announced $1,820,000,000 in combined penalties against 11 firms and their affiliates for failing to preserve business communications sent through personal messaging apps. In January 2025, the SEC penalized a further 12 firms $63,000,000 for the same failure. Counting from the $200,000,000 JPMorgan settlement in December 2021, the campaign has passed $3,000,000,000 across more than 100 firms.
Every one of those institutions had a written communications policy, a supervisory system, and a recordkeeping platform. The SEC’s own orders noted that the violations reached supervisors and senior managers, not only junior staff. The control existed. People worked around it.
Breach data points the same direction. Verizon’s 2026 Data Breach Investigations Report found the human element present in 62% of breaches, up slightly from 60% the year before and effectively unmoved across three editions. IBM’s Cost of a Data Breach Report 2025 put the average financial services breach at $5,560,000, second only to healthcare. Institutions that respond by buying another detection layer are treating the symptom, which is why data loss prevention strategies alone rarely move the number. The sector-specific pressures behind that pattern are set out in this analysis of challenges facing the financial sector.
What GLBA, DORA, NYDFS, and SEBI Require From Employee Training
Four major regimes now write employee training into financial data governance as a mandatory control rather than a recommendation, and three of the four tie the content of that training to the institution’s own risk assessment or to specific job roles.
| Regime | Who it binds | The training obligation | Evidence a supervisor expects |
|---|---|---|---|
| FTC Safeguards Rule, 16 CFR 314.4(e) | Non-bank financial institutions under FTC jurisdiction | Security awareness training for all personnel, updated to reflect risks identified by the written risk assessment, plus specialized training for information security staff | The risk assessment, and training content traceable to its findings |
| DORA Article 13(6), EU | Banks, insurers, investment firms, crypto-asset service providers, and their critical ICT providers | Compulsory ICT security awareness and digital operational resilience training for all employees and senior management, at a complexity matched to each role | Role-differentiated curricula and board-level participation records |
| NYDFS 23 NYCRR Part 500 | DFS-licensed banks, insurers, mortgage lenders, and virtual currency businesses | At least annual cybersecurity awareness training covering social engineering, for all personnel | Annual certification of material compliance, supported by training records |
| SEBI CSCRF, India | Stock exchanges, depositories, brokers, AMCs, RTAs, and other regulated entities | Awareness and training obligations graded by entity category within the framework’s five resilience goals | Cyber audit reports in the prescribed formats, on a recurring cycle |
The dates matter because the grace periods have closed. The amended Safeguards Rule has been fully enforceable since June 2023. DORA has applied across the EU since 17 January 2025. The final phase of the NYDFS Second Amendment took effect on 1 November 2025, leaving no remaining implementation runway. SEBI issued the CSCRF on 20 August 2024, and after two extensions the principal deadline landed on 31 August 2025, converting compliance into a recurring audit obligation. Comparable expectations are appearing in other jurisdictions, as this review of NESA, IRDAI, and FCC requirements shows.
Read the Safeguards Rule text closely and the design constraint becomes explicit. Section 314.4(e)(1) requires training “updated as necessary to reflect risks identified by the risk assessment.” A generic annual module delivered identically to every employee does not satisfy that clause, because nothing in it derives from the institution’s own findings. The same logic runs through DORA’s requirement that complexity be commensurate with the employee’s function. Overlapping obligations of this kind are mapped in more detail in this look at compliance and people security.
Why Do Completion Rates Fail as Regulatory Evidence?
A completion rate proves attendance. It does not prove capability, and it does not answer the question a regulator is actually asking, which is whether the institution identified its highest-risk behaviors and did something specific about them. An institution reporting 100% completion across 4,000 employees has demonstrated that its learning management system works. It has demonstrated nothing about the 40 people who approve wire transfers.
This matters more now that enforcement has become concentrated rather than frequent. Eversheds Sutherland’s study of FINRA’s 2025 disciplinary data found 431 actions, down 22% from 552 the prior year, while total monetary sanctions rose 77% to $154,000,000. Fewer cases, larger penalties, and a supervisory posture that rewards firms who can show specific remediation over firms who can show general activity.
The alternative evidence set is behavioral: which employees were exposed to which simulated attack, how they responded, what training followed, and whether the response changed on retest. Approaches for building that record are covered in this piece on security training metrics that show behavioral change, and the shift away from completion as the headline number is explored in compliance training that moves from completion to behavior change.
How to Baseline Employee Exposure Before Designing Compliance Training
Baselining means running controlled simulations across the channels the institution actually uses, then scoring individual exposure before any curriculum is written. For a financial institution that means email, but also voice, SMS, QR codes, and messaging apps, because those are the channels where off-channel communication and social engineering now converge. A baseline built on email alone will understate risk in exactly the places enforcement has concentrated.
The output that matters is per-person, not per-department. A department average of 12% tells a compliance officer nothing actionable. A named list of the employees who clicked, who entered credentials, and who did both twice tells them who to train first, and gives the risk assessment a finding specific enough to cite in a curriculum. Mechanics of the assessment stage are covered in this explanation of how phishing simulations contribute to enterprise security and this guide to the employee cyber risk score.
Threatcop’s TSAT produces both halves of that record. It scores each employee’s vulnerability individually and measures average breach time, the interval between a lure landing and the first compromise, so an institution can show a regulator which population its training targeted and on what evidence.
Building Role-Based Training That Traces Back to the Risk Assessment
Role-based training in a financial institution means a wire-transfer approver, a relationship manager, and a back-office reconciliation clerk receive different content, because their exposure differs and because DORA and the Safeguards Rule both require the difference. Content matched to the role is also content people finish, and a module nobody completes changes no behavior regardless of what the compliance dashboard reports.
Threatcop’s TLMS delivers that layer as role-based and category-based courses in multiple languages, with gamified assessments and microlearning refreshers, so a multilingual branch network trains in the language each team works in rather than the language head office writes in. Delivery choices of this kind are the difference between a security awareness training program that produces certificates and one that produces evidence.
A 90-Day Sequence for Rebuilding the Human Layer of Data Governance
Financial institutions rarely have a year-long program design cycle available between examinations, and a remediation plan agreed with a supervisor usually runs on a shorter clock than that. The sequence below compresses the work of rebuilding the human layer of data governance into three phases, each ending in an artifact that can be handed to an examiner rather than described to one. Owners are named because a phase with no owner slips into the next quarter.
| Phase | Activity | Owner | Artifact produced |
|---|---|---|---|
| Days 0 to 30 | Map customer data flows against job roles, then run a multi-vector baseline simulation across email, voice, SMS, and messaging channels | CISO with the data governance lead | Risk assessment updated with named behavioral findings |
| Days 0 to 30 | Inventory approved and unapproved communication channels actually in use, including personal devices | Compliance | Channel register with gaps flagged |
| Days 31 to 60 | Build role-differentiated curricula that cite specific baseline findings, prioritizing the highest-scoring population | Security awareness owner with HR | Curriculum map linking each module to a risk assessment finding |
| Days 31 to 60 | Set the reporting path for suspicious messages and publish it to every role | Security operations | Documented reporting procedure with response times |
| Days 61 to 90 | Retest the baselined population on the same vectors, then compare scores | CISO | Before-and-after exposure comparison |
| Days 61 to 90 | Assemble the examination pack: risk assessment, curriculum map, delivery records, retest results | Compliance | Single evidence file per regulatory regime |
The sequencing is the point. Training built before the baseline cannot cite the baseline, and an examination pack assembled after the fact tends to reveal that the three documents were never connected.
Metrics That Hold Up in a Regulatory Examination
Six measures answer supervisory questions directly, and each one links a behavioral finding to an action the institution took.
| Metric | What it shows | Why it survives scrutiny |
|---|---|---|
| Employee vulnerability score distribution | Where exposure concentrates across the workforce | Identifies a specific population rather than an average |
| Average breach time | How quickly a lure converts to compromise | Measures attacker experience, which click rate does not |
| Repeat-offender count, quarter over quarter | Whether the same people keep failing | Shows whether intervention worked or only occurred |
| Role coverage against risk assessment findings | Whether training reached the roles the assessment flagged | Maps directly to the Safeguards Rule and DORA wording |
| Time from finding to training deployed | Program responsiveness | Evidence of a live process rather than an annual event |
| Suspicious message report rate | Whether the workforce detects and escalates | Demonstrates a functioning human detection layer |
Click rate is absent from that list deliberately. A falling click rate can mean employees learned, or it can mean the simulation got easier, and a supervisor cannot distinguish the two from the number alone. Wider guidance on selecting these measures is set out in this article on measuring human risk in a security program, and the cost side of the argument is covered in why weak human controls raise compliance fines.
Where a Financial Institution Should Start
Pull the last risk assessment and the last training completion report, then try to draw a line between them. If the training content cannot be traced to a finding in the assessment, the program satisfies the administrative form of GLBA, DORA, NYDFS, and CSCRF while missing what each of them asks for. That gap is where the examination findings come from.
Threatcop’s people security management approach closes it by treating the human layer as a measured domain: baseline exposure with TSAT, train the population the baseline names with TLMS, then retest and keep the record. Book a walkthrough to see what a defensible evidence file looks like for your regulatory regime.
Frequently Asked Questions
What is data governance in financial institutions?
Data governance in financial institutions is the framework of policies, ownership assignments, access controls, and retention rules that determine how customer and market data is handled, plus the records that evidence each decision. In banking and securities, governance carries a supervisory dimension other sectors lack: an institution must be able to demonstrate the framework operating, not merely show that it was written down.
Does DORA require security awareness training for all employees?
Yes. DORA Article 13(6) requires financial entities to make ICT security awareness programmes and digital operational resilience training compulsory modules in staff training schemes, covering all employees and senior management staff, at a level of complexity commensurate with each person’s function. The regulation has applied across the EU since 17 January 2025, and where appropriate it extends to ICT third-party service providers.
Is security awareness training mandatory under GLBA?
Yes, for institutions covered by the FTC Safeguards Rule. Section 314.4(e)(1) of 16 CFR Part 314 requires covered financial institutions to provide personnel with security awareness training updated as necessary to reflect risks identified by the written risk assessment, and to give information security staff additional role-specific training. The amended rule has been fully enforceable since June 2023.
Why do banks still have data breaches if they have data loss prevention?
Data loss prevention inspects content and blocks policy violations it can recognize, which leaves the decisions employees make outside monitored channels untouched. The SEC and CFTC off-channel communications cases are the clearest example: employees moved business conversations onto personal messaging apps, where no outbound control was watching. Verizon’s 2026 DBIR found the human element in 62% of breaches, a figure that has barely moved in three years.
What evidence do regulators accept that security training works?
Supervisors look for a traceable chain rather than a single number: a documented risk assessment, training content that cites its findings, delivery records showing which roles received what, and measurement showing behavior after the intervention. Completion percentages support the delivery step only. Before-and-after exposure scores, repeat-offender trends, and reporting rates carry the behavioral part of the argument.
Cyber Security Specialist
Department: Compliance, Threatcop
Sara Abraham is a Cyber Security Specialist at Threatcop, where her extensive expertise in the field is instrumental in strengthening the company’s cyber security initiatives. She is a key contributor to the company’s mission of providing top-notch security solutions.
Cyber Security SpecialistDepartment: Compliance, ThreatcopSara Abraham is a Cyber Security Specialist at Threatcop, where her extensive expertise in the field is instrumental in strengthening the company's cyber security initiatives. She is a key contributor to the company's mission of providing top-notch security solutions.
