Story 361
Citi’s consent order on risk management and the consent order on data are not independent.
Yet, the organization has decoupled them to check the box on one while the prerequisite for doing it properly remains unmet. Out of strategy for closure. All the while understanding their dependency.
Risk management systems rely entirely on underlying data. If data quality, governance, lineage, and architecture are broken, any risk management framework built on top of them is essentially “garbage in, garbage out.”
Regulatory remediation is unglamorous, slow, and expensive “plumbing” work that rarely gets anyone promoted.
Building flashy tools for C-suite demos generates high visibility and advances personal career timelines, even if it diverts budget, top talent, and engineering focus away from tedious consent order remediation.
Understanding this, two MDs had no problem disrupting the execution of their team and prioritizing feature development to satisfy the dog and pony show over remediation resources and timelines.
You guessed it: basic access controls, data security and identity management were a problem for the engineering team.
Reading now about Citi’s public push for AI adoption makes me shake my head. You cannot innovate your way out of foundational neglect, especially when technical debt is compounded by misaligned incentives.
AI tooling relies on existing enterprise access controls, data security, and identity management. Deploying AI on top of legacy tech stacks with weak foundational infrastructure accelerates exposure.
This is your classic enterprise transformation failure: prioritizing executive-facing innovation over fixing data architecture—which is the prerequisite for both risk management and safe AI adoption.