Story 323
80% Done. Just Missing the Lines of Defense Structure.
Citi’s Consent Order began in 2020. By the bank’s own account, remediation is near complete.
A Data Risk function in the second line of defense — the independent oversight layer whose entire purpose is to challenge and govern data risk taken by the business — did not exist until spring 2025.
Let that land.
Five years into a regulatory enforcement action predicated on data governance failures, the independent function responsible for overseeing data risk was not yet built.
It was created while the organization was claiming to be in the final stretch. The second line of defense is not a finishing touch. It is a foundational control.
It ought to have been built at the beginning — unless the organization considered independent oversight a feature of normal operations rather than a requirement of remediation.
You know the answer.