Story 361

Citi’s consent order on risk management and the consent order on data are not independent.

Yet, the organization has decoupled them to check the box on one while the prerequisite for doing it properly remains unmet. Out of strategy for closure. All the while understanding their dependency.

Risk management systems rely entirely on underlying data. If data quality, governance, lineage, and architecture are broken, any risk management framework built on top of them is essentially “garbage in, garbage out.”

Regulatory remediation is unglamorous, slow, and expensive “plumbing” work that rarely gets anyone promoted.

Building flashy tools for C-suite demos generates high visibility and advances personal career timelines, even if it diverts budget, top talent, and engineering focus away from tedious consent order remediation.

Understanding this, two MDs had no problem disrupting the execution of their team and prioritizing feature development to satisfy the dog and pony show over remediation resources and timelines.

You guessed it: basic access controls, data security and identity management were a problem for the engineering team.

Reading now about Citi’s public push for AI adoption makes me shake my head. You cannot innovate your way out of foundational neglect, especially when technical debt is compounded by misaligned incentives.

AI tooling relies on existing enterprise access controls, data security, and identity management. Deploying AI on top of legacy tech stacks with weak foundational infrastructure accelerates exposure.

This is your classic enterprise transformation failure: prioritizing executive-facing innovation over fixing data architecture—which is the prerequisite for both risk management and safe AI adoption.

Similar Posts

  • Story 58

    I am based in Citigroup’s New York office. While I cannot speak to other business units, the Equities floor regrettably lives up to its longstanding and notorious reputation for dysfunction. A small cadre of MDs and their favored allies effectively dominate the culture, fostering a cliquish environment. Although the Equities division now includes a notable…

  • Editor’s Note

    To whomever submitted the story at 12:35PM ET, we have reason to believe you are not acting in good faith – we have suspected this for a while – and will no longer post your submissions. Please take your energy elsewhere. This is a space for people who are telling the truth and interested in…

  • Story 315

    A Forensic Autopsy of a Career Assassination: The Promise. The Reorg. The Demotion. There is a particular kind of institutional betrayal that is engineered to look like circumstance. In ERM Tech & Data at Citi, where in-group loyalty overrides merit and the rule of law, a role was promised. Then she raised concerns — about…

  • Story 124

    The Financial Times is reporting today that Citi’s former head of the family office previously served as Jeffrey Epstein’s personal banker – a detail one might reasonably expect any competent organisation to identify during the most elementary due-diligence checks. The article drily observes, it “begs the question of what Citi’s process actually involves.” This on…

  • Story 302

    Is it just me, or does Citi seem more willing to settle matters involving regulators and clients while digging its heels in against employees—particularly women—who bring claims of harassment, discrimination, or retaliation? I guess like its Epstein lawyer, Paul Weiss, it doesn’t care how its own people are treated but the C-suite is worried about…

  • Story 14

    I was recruited to Citi in early 2023. At my first company mixer, during a conversation with three female Managing Directors, they openly discussed HR’s flagrant hostility toward women. Spent the next two years networking my way back to my former firm and escaped in 2025. Don’t understand how this isn’t a risk issue for…