Converging motorway interchanges at night — symbolic of converging regulatory regimes
    Flagship — Regime Convergence

    The 2026 data governance mandate — BCBS 239, DORA, AI Act and NIS2 converged.

    Four regimes are now reading the same evidence base. The institutional substrate is the only place that holds the obligation across them.

    Cabier Intelligence · 8 June 2026 · ~16 min read

    Executive summary

    In 2026 the BCBS 239 risk-data perimeter, the DORA ICT and third-party perimeter, the EU AI Act high-risk data perimeter and the NIS2 cyber perimeter all read from the same institutional evidence base. Each retains a separate supervisor and a separate report. The substrate that produces those reports is operationally one thing.

    Institutions that maintain four substrates will reconcile them indefinitely. Those that consolidate to one substrate will absorb the next regime — Korea's AI Basic Act, Brazil's PL 2338, the next iteration of NYDFS — without re-platforming. That is the bet the convergence rewards.

    The four regimes converging

    The convergence is not in the law. It is in the artefact. Each regime asks the institution to produce, retain and surface evidence drawn from the same underlying pool — data flows, controls, incidents, third parties, models. The substrate that holds the pool is therefore the convergence point.

    BCBS 239 — the older mandate

    BCBS 239 is the senior regime. It asks for accurate, complete, timely, adaptable and distributable risk data, supported by a traced and graded substrate. Its 2026 read is less patient: see the substrate, not the substrate plan. A separate flagship analyses the recurring failure pattern.

    DORA — the ICT and third-party mandate

    DORA's binding contribution is the ICT third-party perimeter. It forces the institution to record the dependencies — including data dependencies — on external technology providers, and to evidence operational resilience across them. The data lineage carried for BCBS 239 is the same lineage DORA reads.

    EU AI Act — the data-governance mandate inside the AI mandate

    Article 10 is the data-governance backbone of the AI Act. Training, validation and testing data must be relevant, representative and error-controlled. Where AI is embedded in regulated workflows, that data lives on the same substrate as the rest of the institution's regulated data. Article 73 incident reporting reads the same substrate as NIS2 Article 23 — the incident record is one record.

    NIS2 — the cyber and incident mandate

    NIS2 governs cyber resilience for essential and important entities. Where cyber incidents touch regulated data flows, the incident record and the lineage have to be reconcilable. The substrate that carries one carries the other; otherwise the institution reconciles two records every time the supervisor asks.

    The single substrate

    Cabier's Enterprise Data Governance OS is the substrate the four regimes are converging on. It carries the lineage for BCBS 239, the ICT and data dependencies for DORA, the Article 10 evidence chain for the AI Act, and the incident substrate for NIS2 Article 23. It surfaces the regulator-facing artefact each supervisor expects, without producing four reconciliations of the same fact.

    Sibling modules sit alongside: AI Assurance OS for the model-side obligation, Tokenization Control OS where tokenised activity is in scope, andthe hyperscaler assurance layer for foundation-model and sovereign-cloud providers.

    What this is not

    This is not a legal opinion. It is an operating analysis. Statutory interpretation remains the institution's own; Cabier provides the substrate that holds the interpretation in evidence. We do not publish weighting, rubric or library specifics in public material.

    Frequently asked questions

    Why are these four regimes treated together?

    Because in 2026 they read the same evidence base. The substrate that satisfies one is the substrate that satisfies the others. Treating them separately produces four reconciliations of the same artefact.

    Are these regimes legally equivalent?

    No. They are legally distinct and have different supervisors. They are operationally adjacent — the underlying data, lineage, control and incident records are shared.

    Does BCBS 239 apply outside the EU?

    Yes. It is a Basel Committee standard applied to G-SIBs globally and to D-SIBs by domestic supervisors.

    Does DORA only apply in the EU?

    DORA is an EU regulation, but third-country ICT third parties serving EU financial entities are in scope through the contractual perimeter. Cross-border effect is meaningful.

    What does the EU AI Act require on data?

    Article 10 requires data and data-governance practices for training, validation and testing of high-risk AI systems — relevant data, representative, free of errors and complete to the extent feasible. The substrate that carries this is shared with BCBS 239 and DORA.

    What does NIS2 require on data?

    NIS2 is a cyber-resilience regime. Where incidents touch regulated data flows, the lineage and the incident record have to be reconcilable. The substrate again converges.

    What about the UK after divergence?

    PRA and FCA expectations on operational resilience, data and AI overlap substantively with EU positions. The substrate is the same; the reporting surface changes.

    What about the US?

    FRB SR 11-7 (model risk), SR 15-18 (data), NYDFS 23 NYCRR 500 (cyber), and emerging AI executive orders read the same substrate from a different vocabulary.

    What about Canada?

    OSFI E-23 (model risk), B-10 (third-party), Integrity & Security Guideline (cyber and data) and the federal AIDA proposal sit in the same convergence pattern.

    What about Japan?

    JFSA model-risk guidance, BOJ resilience expectations, APPI 2026 amendments and METI's AI Guidelines for Business follow the convergence.

    Is the convergence formal or operational?

    Operational. Each regime retains its own legal basis and supervisor. The convergence is at the substrate the institution maintains, not at the level of the statute.

    Does this mean one report can satisfy all four?

    No. Each supervisor expects its own report. The convergence means the report is drawn from a single substrate rather than reassembled from four.

    Where does third-party data risk fit?

    It sits in all four regimes. DORA treats it explicitly; BCBS 239 treats it through the perimeter; the AI Act treats it through data provenance; NIS2 treats it through ICT supplier resilience.

    Where does AI fit in BCBS 239?

    Where AI is embedded in the production of risk data — surveillance, screening, valuation — the model's data lineage is part of the BCBS 239 trace.

    Does the substrate handle privacy obligations?

    Yes. GDPR, UK DPA, CPRA, PIPEDA, APPI and LGPD are carried on the same lineage and control substrate, with jurisdiction-specific surfacing.

    What does the institution have to commit to?

    A single substrate, an accountable executive, multi-year horizon, and supervisor engagement on the milestones. Anything less reproduces the BCBS 239 pattern.

    Is there a public Cabier price list?

    No. Every engagement is custom-quoted under signed terms.

    How does an institution begin?

    Through the Enterprise Data Governance OS module, with a closed conversation between the CDO, the Head of Risk Data, and the Cabier engagement lead.

    Glossary

    BCBS 239
    Basel Committee Principles for Effective Risk Data Aggregation and Risk Reporting.
    DORA
    EU Digital Operational Resilience Act — ICT risk and third-party regime for financial entities.
    EU AI Act
    EU regulation on artificial intelligence; risk-based with specific obligations for high-risk systems and general-purpose AI models.
    NIS2
    EU Network and Information Security Directive (recast) — cyber-resilience regime for essential and important entities.
    Article 10 (AI Act)
    Data and data-governance requirements for high-risk AI systems: relevant, representative, error-controlled training data.
    Article 73 (AI Act)
    Serious-incident reporting obligation for providers of high-risk AI systems.
    Article 6 (DORA)
    ICT risk-management framework requirement.
    Article 23 (NIS2)
    Incident-reporting obligations — early warning, incident notification, intermediate report, final report.
    Operational resilience
    The institutional ability to deliver important business services through severe-but-plausible disruption.
    ICT third party
    Provider of information and communication technology services to a financial entity (DORA definition).
    FRFI
    Federally Regulated Financial Institution (Canada).
    G-SIB
    Global Systemically Important Bank — FSB designation.
    D-SIB
    Domestic Systemically Important Bank — home supervisor designation.
    Lineage
    Traced path of a data element through every transformation into the report line.
    Substrate
    Cabier's term for the single institutional record behind every regulator-facing number.
    Evidence vault
    Immutable repository of the artefacts behind every supervisory question, attestation and walkthrough.
    Effectiveness grading
    Graded judgement on whether a control is fit for the supervisory use it supports, beyond pass / fail.
    Three lines of defence
    Risk operating-model convention separating business, oversight and assurance.
    CDO
    Chief Data Officer — accountable executive for the data substrate.
    CAIO
    Chief AI Officer — accountable executive for AI governance, increasingly named for AI Act and SR 11-7 purposes.
    PRA
    UK Prudential Regulation Authority.
    FCA
    UK Financial Conduct Authority.
    OSFI
    Office of the Superintendent of Financial Institutions (Canada).
    JFSA
    Japan Financial Services Agency.
    Custom quote
    Cabier's standing pricing policy: no engagement is publicly priced; every scope is sized under signed terms.

    Continue

    References and citations

    Primary sources. Positions change; verify at source before relying on any figure or determination.

    1. 1Basel Committee on Banking Supervision, BCBS 239Risk data aggregation principles underpinning the mandate.Source
    2. 2Regulation (EU) 2016/679 (GDPR), Articles 5, 30 and 32Data minimisation, records of processing and security of processing.Source
    3. 3Regulation (EU) 2022/2554 (DORA)ICT and data asset register obligations.Source
    4. 4Federal Reserve, SR 15-18US large-institution data and reporting expectations.Source