Data-Driven Risk Management is Critical to Survive and Thrive

The Financial Services industry's increasing intricacy, combined with recent adverse events, has heightened regulatory scrutiny on banks. This is further compounded by liquidity challenges, creating a landscape of unprecedented risk management demands.

To navigate this new terrain, a robust Enterprise Risk Management (ERM) Program is essential. Such a program should integrate both proprietary and public data sources, encompassing loans, accounts, complaints, risk assessments, census tracts, and even social media feeds. By harnessing this array of data, a Data-Driven Risk Management Program can be crafted to effectively counter emerging risks.

Data-Driven Risk Management is critical, and the concept is being embraced across the banking sector due to its evident advantages. However, its implementation remains a formidable challenge for banks of all sizes, marked by diverse strategies. The concept of "Actionable Intelligence" is central, allowing risk managers to easily identify and mitigate underlying risks. However, several hurdles obstruct this:

  • Data Silos, Quality and Accuracy: Ensuring the accuracy, completeness, and consistency of data is a fundamental challenge. Inaccurate data can lead to faulty decisions, regulatory compliance issues, and operational inefficiencies. Data aging and archiving is also often a problem. Banks often have multiple systems and departments that generate and store data independently. This can result in data silos, making it difficult to gain a holistic view of customer relationships, risks, and business performance. Furthermore, ensuring the accuracy, relevance, and legality of external data from vendors or FinTechs can be challenging.
  • Many risk managers lack the experience to articulate precise analytics needs, particularly compliance teams relying on anecdotal information from the business.
  • Dependency on reports and analytics from the First Line of Defense (1LOD) compromises the independence intended by the three lines of defense model.
  • Traditional volume-focused reports from First Line of Defense often lack the potential to generate actionable intelligence.
  • The strength of risk management lies in detecting emerging patterns rather than just rules-based reports.
  • Swift regulatory changes, like the 2021 CARES Act, often demand deployment speed beyond organizational capabilities.
  • Advanced analytics techniques like Artificial Intelligence (AI) and Natural Language Processing (NLP) are underutilized by risk management, hampering their effectiveness in creating regulatory-ready artifacts.

An effective Data-Driven Risk Management program hinges on closely aligning with risk assessments, prioritizing high residual risk areas while staying vigilant for emerging risks. The significance extends beyond data alone; the underlying policies and procedures must be designed to optimize the application of analytics. Moreover, effective Data Management Programs produce artifacts connecting seemingly unrelated data sources, empowering risk managers to make immediate and specific connections. For instance, combining loan application denials from minority-populated census tracts with complaints. The integration of AI and NLP enhances pattern recognition. Artifacts should be user-friendly and effortlessly facilitate the creation of monitoring artifacts, potentially including an integrated "issue summary" feature.

Success in a Data-Driven Risk Management Program necessitates agility through automated artifact development and deployment processes. The "Tyranny of Training an Algorithm" underscores the challenges in AI and NLP adoption. Banks, particularly larger ones, allocate substantial resources to AI DevOps teams. However, many are still trapped in the "Supervised Learning" paradigm, training algorithms on historical data. This approach falters in rapidly changing scenarios, such as the rushed implementation of the CARES Act in 2021.

Addressing this challenge requires an "Open Visualization" or "Unsupervised Learning" approach, focused on inherent data patterns. This approach bridges structured data (e.g., loans) with unstructured data (e.g., customer feedback). Unsupervised Learning treats patterns as emerging until recognized and automated for recurring production. It is more interactive and cost-effective compared to Supervised Learning, while also being easily explainable.

Let me provide an example - news of regulatory actions has become commonplace in the banking industry, and risk and compliance teams must quickly ascertain if their firm also has a similar exposure. In these situations, there is no reliably labeled historical data to train an algorithm. One of the solutions that I put forward was recently patented, and involved specific application of NLP for complaints. In cases where we may have a way to conceptualize a fixed pattern, such as a complaint related to discrimination in the refund of Good Faith Funds (GFF) in the Mortgage application process, it is possible to complement an Unsupervised Learning process by introducing a known pattern, like a discrimination-related complaint. Such an example could be a real complaint that we are aware of or could be synthetically created based on what is known about the “other bank’s problem.” Similar mechanisms can be applied to situations involving structured data, such as transactions. In each case, a synthetic or representative example is introduced in the Unsupervised Learning process, functions as a “trap” and attracts other artifacts which are similar. This results in an incredibly efficient and cost-effective way to answer the commonly asked question “Do I have the same problem as the other bank in the news?”. This is just one example of how to use data and AI tools to enhance risk management and compliance.

In conclusion, banks must harness data for effective risk management, recognizing that traditional methods might fall short. Data-driven risk management also contributes to improved governance by providing a transparent and auditable process for risk assessment and mitigation. These practices align with regulatory expectations for robust risk management practices and will ultimately become standards for the industry. The success of risk and compliance depends on an effective Data Management Program, securing not just their success but the stability of the entire banking ecosystem.

This presentation is being furnished on a confidential basis to provide preliminary summary information. The information, tools and material (collectively, information) contained herein is not directed to or intended for distribution or use by any person or entity who is a citizen or resident of or located in any jurisdiction where such distribution, publication, availability or use would be contrary to law or regulation or which would subject Endurance Advisory, LLC, to any registration or licensing requirement within such jurisdiction.

The information presented herein is provided for informational purposes only and is not to be used or considered as an offer to sell, or buy securities or other financial instruments, or any advice or recommendation with respect to such securities or other financial instruments. The information may not be reproduced in whole or in part or otherwise made available without the prior written consent of Endurance Advisory, LLC. Information and opinions presented have been obtained or derived from sources believed to be reliable, but Endurance Advisory, LLC makes no representation as to their accuracy or completeness. Endurance Advisory, LLC, accepts no liability for any loss arising from the use of the information contained herein.

This information is subject to periodic update and revision. Materials should only be considered current as of the date of the initial publication, without regard to the date on which you may access the information. Endurance Advisory, LLC, maintains the right to delete or modify the information without prior notice.

Under no circumstances and under no theory of law, tort, contract, strict liability or otherwise, shall Endurance Advisory, LLC be liable to anyone for any damages resulting from access or use of, or inability to access or use, this information regardless of whether they are dire, indirect, special, incidental, or consequential damages of any character, including damages for trading losses or lost profits, or for any claim or demand by any third party, even if Endurance Advisory, LLC knew or had reason to know of the possibility of such damages, claim or demand.

More insights

General
Article

What the Iran Conflict Taught Business Leaders

The February 2026 US-Israel operation, read through Kagan, Kissinger, Toll & Ferguson. What it teaches business leaders about diplomacy, decision speed & institutional resilience.

Digital & AI
Article

What a Mathematician, an Aerospace Engineer, and a Mechanical Engineer Taught Me About Governing AI

Lessons from a mathematician, an aerospace engineer & a mechanical engineer on governing what you cannot fully understand, & the posture bank directors need toward AI oversight.

Strategy & Liquidity
Article

Postulate for Global Finance and Geopolitics in 2026

Large dislocations in currency, credit, sovereign debt & digital-asset markets are rarely driven by the scale of an attacker. A 2026 postulate on structural vulnerability & how to assess stability.

General
Article

The Administrative Load: When Systems Drift Away from Value

Healthcare & finance keep adding layers of intermediation between payment & value. A systems view of why complexity accumulates, when it stops serving purpose, & what resilience through alignment looks like.

Risk & Compliance
Article

Three Crises. One Pattern. And We're Watching It Again.

Three credit dislocations across four decades, Texas energy & real estate, the dotcom IPO boom, and today's private-credit market, share one behavioral sequence. Why this one looks familiar.

Strategy & Liquidity
Article

The $2.9 Trillion Bet

How the $2.9 trillion AI data-center buildout is reshaping global capital, construction & the communities absorbing it, and where the $800 billion private-credit opportunity sits.

Digital & AI
Article

The Agentic Trap: Reading Between the Lines of Deloitte's AI Report

Deloitte's 2026 State of AI report reads as inevitable growth. An operator's view of the implementation risk beneath the optimism, from a 40% agentic failure rate to the governance banks need before decisions run autonomously.

Strategy & Liquidity
Article

Key Insights from Apollo's 2026 Outlook

Apollo's 2026 outlook read for financial services: a resilient US economy, a brief stagflationary slowdown, then AI-driven reacceleration, with the consumer-stress, policy & private-markets signals that matter for banks & investors.

Regulatory & Remediation
Article

A Shift Toward Greater Flexibility with Changes to Leveraged Lending Regulatory Guidance

The OCC & FDIC rescinded the 2013 Interagency Guidance on Leveraged Lending on December 5, 2025. What the move to principles-based supervision means for bank participation, private credit & internal risk governance.

General
Article

Surviving the Shadow: My Journey with Cancer and the Power, and Importance, of Early Detection

Stage 3B Hodgkin's lymphoma at 22, in 1984, when there were no records of long-term survival at that stage. A first-person case for early detection and for taking ownership of your own diagnosis.

General
Article

9/11 - A Personal Perspective by Stephen K. Curry

From the 48th floor of 9 West 57th, four miles north. An account of the day, the roll call that ran past midnight, and the colleagues who did not make it home.

Strategy & Liquidity
Article

Liquidity in 2025: A Shifting Landscape for Banks

Deposits are more volatile, more concentrated, and more rate-sensitive than at any point since the 1980s. What examiners now expect on ratios, stress testing, intraday readiness, and collateral.