AI Governance Institute
← News

Moniepoint's 100 Billion Transactions Show Data Lineage Is an AI Governance Prerequisite

What happened

In a post titled What I Learned About AI Trust from Reconciling over 100 Billion Transactions, Moniepoint engineering lead Wole Olorunleke describes the data infrastructure built to manage the company's transaction volume and explains how that same infrastructure now governs its AI systems. The article identifies four foundational controls: maker-checker approval workflows that enforce human sign-off on consequential decisions, full chain-of-custody logging for every transaction, canonical data definitions that prevent ambiguity across systems, and automated reconciliation pipelines designed so that every decision can be traced back to the specific logic and engineer responsible. Olorunleke argues that organizations attempting to govern AI outputs without first governing the data layer underneath them will find that no model documentation or output guardrail can substitute for upstream data integrity. The piece is a practitioner-level counterpart to the model risk guidance increasingly issued by financial regulators, including the OCC Model Risk Management: Revised Guidance (Bulletin 2026-13) and the Financial Stability Board Recommendations on Agentic AI Controls in Financial Services, both of which demand end-to-end auditability for AI-assisted financial decisions.

Why it matters

  • ·Financial regulators are converging on end-to-end auditability as a minimum standard for AI in transaction processing. The OCC Model Risk Management: Revised Guidance (Bulletin 2026-13) and the MAS Guidelines on Artificial Intelligence Risk Management both require firms to demonstrate that AI-assisted decisions can be fully traced, a standard that cannot be met if the underlying data layer lacks chain-of-custody controls.
  • ·The maker-checker pattern described in the article maps directly to human-in-the-loop requirements in emerging AI governance frameworks. Compliance teams that have addressed human oversight only at the model output level, rather than embedding it into data workflows, may find their controls fall short during regulatory examination.
  • ·Many enterprises assume that vendor-provided audit logs are sufficient to satisfy AI auditability obligations. This case study illustrates that without canonical data definitions and provenance controls at the infrastructure layer, vendor logs cannot establish who or what logic was responsible for a given AI output, creating a material gap in audit trail completeness.

Governance controls affected

What to do now

  • Audit whether your AI systems in financial workflows can trace each output back to a specific data source, transformation step, and responsible engineer or logic unit — not just to a model version.
  • Map your existing maker-checker or dual-control workflows to the human oversight requirements in applicable regulatory guidance, and document where human approval gates exist only at the policy level rather than in the system architecture.
  • Review canonical data definitions across AI pipelines to confirm that identical terms mean the same thing in every upstream and downstream system feeding AI models used in reconciliation or credit decisions.
  • Assess whether your log retention policy captures the full chain of custody from raw transaction data through model input and output, and verify that logs are tamper-evident and retrievable within your audit trail SLA.
  • Include data governance infrastructure maturity as a criterion in your AI vendor due diligence process, specifically asking vendors whether their AI outputs can be traced to source data provenance.

What to watch next

Regulatory expectations for AI auditability in financial services are tightening across jurisdictions. The Financial Stability Board Recommendations on Agentic AI Controls in Financial Services signal that supervisors will increasingly treat data lineage gaps as control failures rather than documentation gaps. Compliance teams should also monitor how the Treasury Department AI Risk Management Framework for Financial Services translates auditability principles into examination criteria, as that framework is likely to influence how US regulators evaluate AI-assisted reconciliation and reporting systems in the near term.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-08-30

Static AI Compliance Documentation Is No Longer Enough, Collibra Warns

Collibra published a practitioner guide on operationalizing AI regulatory compliance across the EU AI Act, US executive orders, and state laws. The guide argues that compliance teams must build a unified AI inventory covering every model, use case, and agent, then encode obligations as automated, evidence-generating controls rather than relying on static documentation. It identifies inventory completeness, policy-as-code, lineage tracking, audit trails, and continuous monitoring as the five pillars of a defensible program.

Corporate Policy2026-08-23

FPF and Five HR Tech Giants Set AI Hiring Risk Assessment Standard

The Future of Privacy Forum, together with Dayforce, LinkedIn, UKG, Workday, and Beamery, published a risk assessment framework and updated best practices for AI used in hiring and workplace assessment. The framework covers non-discrimination testing, transparency obligations, data privacy, human oversight, and vendor accountability. Organizations using AI in employment decisions should treat this as a de facto industry benchmark that will inform regulatory and litigation scrutiny.

Research2026-08-19

EU AI Office Tightens GPAI Monitoring and Crawler Transparency Expectations

The European Commission AI Office has issued a readout from its General-Purpose AI signatory taskforce clarifying expectations around model monitoring, risk exceptions, and web crawler transparency. The guidance has direct implications for how organizations evidence oversight of GPAI models and structure their logging and transparency controls. Compliance teams deploying or distributing foundation models in the EU should treat these clarifications as operational requirements, not interpretive guidance.