
The data governance overlay above your stack.
BCBS 239 risk data aggregation, field-to-report lineage, data quality grading, privacy and residency attestation, and an immutable audit substrate — instrumented for Tier-1 banks, insurers, sovereign ministries, critical-infrastructure authorities, and the hyperscalers that serve them.
Cabier does not replace Collibra, Alation, Informatica or Microsoft Purview. It sits above them, carrying the regulator-facing obligations that no catalogue and no warehouse can discharge on its own.
Scope boundaries
Six pillars
Each pillar is delivered against your existing CDO function, data office and second-line risk team — instrumenting the substrate they already need rather than displacing the tools they already run.
Lineage & BCBS 239
Field-to-report lineage instrumented to BCBS 239 principles and FRB SR 15-18 supervisory expectations. The substrate carries the chain from system of record through every transformation into the report line a supervisor questions.
BCBS 239 · FRB SR 15-18 · EBA RDARR thematic
Data Quality Controls
Completeness, accuracy, timeliness, reconciliation. Effectiveness grading replaces the binary pass / fail check so the institution can defend why a control is sufficient — not just that it ran.
BCBS 239 Principles 3–6 · OSFI E-23 · DORA Art. 6
Metadata Synthesis
A real-time dependency graph behind every regulator-facing number. The overlay sits above Collibra, Alation, Informatica, Microsoft Purview, Snowflake and Databricks — it does not replace them.
Canonical overlay data model · Single evidence vault
Privacy & Residency
Cross-jurisdiction obligations carried on one substrate: GDPR, UK DPA, CPRA, PIPEDA, APPI, LGPD, PDPL. Data-residency claims are attestable from the lineage record, not asserted in a policy document.
GDPR · CPRA · PIPEDA · APPI · LGPD
Third-Party & Vendor Data Risk
Where data leaves the institutional perimeter — to a hyperscaler, a SaaS processor, a model vendor — the obligation does not. The lineage carries through. The third-party register and the data flow are the same artefact.
OSFI B-10 / E-23 · DORA TPRM · FFIEC IT · PRA SS2/21
Audit & Attestation
An immutable evidence vault behind every supervisory letter, walkthrough, and audit response. Regulator-ready scoping windows let supervisors see exactly what they need — no more, no less — with the calculation chain intact.
BCBS 239 Principle 11 · SOX ITGC · ISAE 3402
Frameworks covered
One substrate, dozens of regimes. Obligations are mapped once and surfaced through the reports each supervisor expects — not re-translated for every jurisdiction.
Who it is for.
Tier-1 banks & insurers
Where BCBS 239 RDARR remains a recurring supervisory finding and data quality is the binding constraint on capital, liquidity, and recovery reporting.
Sovereign & public sector
Ministries, port and transport authorities, and critical-infrastructure operators carrying privacy, residency and breach-notification obligations across multiple jurisdictions on shared data flows.
Hyperscalers & SaaS
Vendors who need a deployer-side assurance envelope their regulated customers can hand to their own supervisor — lineage, residency claim, and audit ID, every time.
Companion analysis
A three-part flagship series accompanying this module. Each piece carries the regulator-facing depth expected of an institutional intelligence brief.
BCBS 239 at 12: why risk data aggregation still fails
Twelve years after the Principles, large banks remain non-compliant on aggregation. The pattern is structural, not technical.
Read briefBeyond the data catalogue: governance above the stack
Catalogues describe. Pipelines move. Neither attests. The case for an institutional overlay above Collibra, Alation, Informatica and Purview.
Read briefThe 2026 data governance mandate: BCBS 239, DORA, AI Act, NIS2 converged
Four regimes are now reading the same evidence base. The institutional substrate is the only place that holds.
Read briefFor a confidential briefing.
Conversations begin with the Chief Data Officer, the Head of Risk Data, or the Head of Privacy & Records. We work with a small number of institutions each year under signed terms.