
The 2026 data governance mandate — BCBS 239, DORA, AI Act and NIS2 converged.
Four regimes are now reading the same evidence base. The institutional substrate is the only place that holds the obligation across them.
Cabier Intelligence · 8 June 2026 · ~16 min read
Executive summary
In 2026 the BCBS 239 risk-data perimeter, the DORA ICT and third-party perimeter, the EU AI Act high-risk data perimeter and the NIS2 cyber perimeter all read from the same institutional evidence base. Each retains a separate supervisor and a separate report. The substrate that produces those reports is operationally one thing.
Institutions that maintain four substrates will reconcile them indefinitely. Those that consolidate to one substrate will absorb the next regime — Korea's AI Basic Act, Brazil's PL 2338, the next iteration of NYDFS — without re-platforming. That is the bet the convergence rewards.
The four regimes converging
The convergence is not in the law. It is in the artefact. Each regime asks the institution to produce, retain and surface evidence drawn from the same underlying pool — data flows, controls, incidents, third parties, models. The substrate that holds the pool is therefore the convergence point.
BCBS 239 — the older mandate
BCBS 239 is the senior regime. It asks for accurate, complete, timely, adaptable and distributable risk data, supported by a traced and graded substrate. Its 2026 read is less patient: see the substrate, not the substrate plan. A separate flagship analyses the recurring failure pattern.
DORA — the ICT and third-party mandate
DORA's binding contribution is the ICT third-party perimeter. It forces the institution to record the dependencies — including data dependencies — on external technology providers, and to evidence operational resilience across them. The data lineage carried for BCBS 239 is the same lineage DORA reads.
EU AI Act — the data-governance mandate inside the AI mandate
Article 10 is the data-governance backbone of the AI Act. Training, validation and testing data must be relevant, representative and error-controlled. Where AI is embedded in regulated workflows, that data lives on the same substrate as the rest of the institution's regulated data. Article 73 incident reporting reads the same substrate as NIS2 Article 23 — the incident record is one record.
NIS2 — the cyber and incident mandate
NIS2 governs cyber resilience for essential and important entities. Where cyber incidents touch regulated data flows, the incident record and the lineage have to be reconcilable. The substrate that carries one carries the other; otherwise the institution reconciles two records every time the supervisor asks.
The single substrate
Cabier's Enterprise Data Governance OS is the substrate the four regimes are converging on. It carries the lineage for BCBS 239, the ICT and data dependencies for DORA, the Article 10 evidence chain for the AI Act, and the incident substrate for NIS2 Article 23. It surfaces the regulator-facing artefact each supervisor expects, without producing four reconciliations of the same fact.
Sibling modules sit alongside: AI Assurance OS for the model-side obligation, Tokenization Control OS where tokenised activity is in scope, andthe hyperscaler assurance layer for foundation-model and sovereign-cloud providers.
What this is not
This is not a legal opinion. It is an operating analysis. Statutory interpretation remains the institution's own; Cabier provides the substrate that holds the interpretation in evidence. We do not publish weighting, rubric or library specifics in public material.
Frequently asked questions
Why are these four regimes treated together?
Because in 2026 they read the same evidence base. The substrate that satisfies one is the substrate that satisfies the others. Treating them separately produces four reconciliations of the same artefact.
Are these regimes legally equivalent?
No. They are legally distinct and have different supervisors. They are operationally adjacent — the underlying data, lineage, control and incident records are shared.
Does BCBS 239 apply outside the EU?
Yes. It is a Basel Committee standard applied to G-SIBs globally and to D-SIBs by domestic supervisors.
Does DORA only apply in the EU?
DORA is an EU regulation, but third-country ICT third parties serving EU financial entities are in scope through the contractual perimeter. Cross-border effect is meaningful.
What does the EU AI Act require on data?
Article 10 requires data and data-governance practices for training, validation and testing of high-risk AI systems — relevant data, representative, free of errors and complete to the extent feasible. The substrate that carries this is shared with BCBS 239 and DORA.
What does NIS2 require on data?
NIS2 is a cyber-resilience regime. Where incidents touch regulated data flows, the lineage and the incident record have to be reconcilable. The substrate again converges.
What about the UK after divergence?
PRA and FCA expectations on operational resilience, data and AI overlap substantively with EU positions. The substrate is the same; the reporting surface changes.
What about the US?
FRB SR 11-7 (model risk), SR 15-18 (data), NYDFS 23 NYCRR 500 (cyber), and emerging AI executive orders read the same substrate from a different vocabulary.
What about Canada?
OSFI E-23 (model risk), B-10 (third-party), Integrity & Security Guideline (cyber and data) and the federal AIDA proposal sit in the same convergence pattern.
What about Japan?
JFSA model-risk guidance, BOJ resilience expectations, APPI 2026 amendments and METI's AI Guidelines for Business follow the convergence.
Is the convergence formal or operational?
Operational. Each regime retains its own legal basis and supervisor. The convergence is at the substrate the institution maintains, not at the level of the statute.
Does this mean one report can satisfy all four?
No. Each supervisor expects its own report. The convergence means the report is drawn from a single substrate rather than reassembled from four.
Where does third-party data risk fit?
It sits in all four regimes. DORA treats it explicitly; BCBS 239 treats it through the perimeter; the AI Act treats it through data provenance; NIS2 treats it through ICT supplier resilience.
Where does AI fit in BCBS 239?
Where AI is embedded in the production of risk data — surveillance, screening, valuation — the model's data lineage is part of the BCBS 239 trace.
Does the substrate handle privacy obligations?
Yes. GDPR, UK DPA, CPRA, PIPEDA, APPI and LGPD are carried on the same lineage and control substrate, with jurisdiction-specific surfacing.
What does the institution have to commit to?
A single substrate, an accountable executive, multi-year horizon, and supervisor engagement on the milestones. Anything less reproduces the BCBS 239 pattern.
Is there a public Cabier price list?
No. Every engagement is custom-quoted under signed terms.
How does an institution begin?
Through the Enterprise Data Governance OS module, with a closed conversation between the CDO, the Head of Risk Data, and the Cabier engagement lead.
Glossary
- BCBS 239
- Basel Committee Principles for Effective Risk Data Aggregation and Risk Reporting.
- DORA
- EU Digital Operational Resilience Act — ICT risk and third-party regime for financial entities.
- EU AI Act
- EU regulation on artificial intelligence; risk-based with specific obligations for high-risk systems and general-purpose AI models.
- NIS2
- EU Network and Information Security Directive (recast) — cyber-resilience regime for essential and important entities.
- Article 10 (AI Act)
- Data and data-governance requirements for high-risk AI systems: relevant, representative, error-controlled training data.
- Article 73 (AI Act)
- Serious-incident reporting obligation for providers of high-risk AI systems.
- Article 6 (DORA)
- ICT risk-management framework requirement.
- Article 23 (NIS2)
- Incident-reporting obligations — early warning, incident notification, intermediate report, final report.
- Operational resilience
- The institutional ability to deliver important business services through severe-but-plausible disruption.
- ICT third party
- Provider of information and communication technology services to a financial entity (DORA definition).
- FRFI
- Federally Regulated Financial Institution (Canada).
- G-SIB
- Global Systemically Important Bank — FSB designation.
- D-SIB
- Domestic Systemically Important Bank — home supervisor designation.
- Lineage
- Traced path of a data element through every transformation into the report line.
- Substrate
- Cabier's term for the single institutional record behind every regulator-facing number.
- Evidence vault
- Immutable repository of the artefacts behind every supervisory question, attestation and walkthrough.
- Effectiveness grading
- Graded judgement on whether a control is fit for the supervisory use it supports, beyond pass / fail.
- Three lines of defence
- Risk operating-model convention separating business, oversight and assurance.
- CDO
- Chief Data Officer — accountable executive for the data substrate.
- CAIO
- Chief AI Officer — accountable executive for AI governance, increasingly named for AI Act and SR 11-7 purposes.
- PRA
- UK Prudential Regulation Authority.
- FCA
- UK Financial Conduct Authority.
- OSFI
- Office of the Superintendent of Financial Institutions (Canada).
- JFSA
- Japan Financial Services Agency.
- Custom quote
- Cabier's standing pricing policy: no engagement is publicly priced; every scope is sized under signed terms.
Continue