
The FStech Podcast · 2025-08-18 · 29 min
DORA and evolving financial regulations have elevated operational resilience from best practice to strategic imperative, but legacy systems designed for traditional risks like power outages now face cyber threats that require fundamentally different approaches - including air gapping, offline data copies, and real-time anomaly detection. Duncan Ash and Jenny Glensky from BMC Software discuss findings from their report on DataOps adoption in financial services, revealing that early adopters embedding DataOps into resilience strategies are distinguishing themselves through proactive infrastructure investment, automation, cross-functional teams, and governance frameworks. However, over half of respondents cite poor data quality as a primary barrier, stemming from heterogeneous data sources (transactional systems, log files, unstructured security data) requiring constant monitoring and automation. The conversation emphasizes that competitive advantage flows from treating operational resilience as a data problem - using AI for simulation testing, anomaly detection, and predictive risk management while breaking organizational silos between fraud, security, and compliance teams. Senior leadership must mandate these approaches as mission-critical, with zero tolerance for data loss in systems processing millions of transactions per second.
DORA (Digital Operational Resilience Act) is EU regulation that mandates stringent expectations around cyber resilience, fraud prevention, and money laundering controls, shifting financial institutions from designing systems for accidental failures (power cuts, floods) to defending against intentional cyber attacks. This requires new technical approaches like air gapping and offline data copies, not just traditional failover sites, and makes operational resilience a board-level strategic priority with significant fines for non-compliance.
Data quality challenges stem from integrating highly heterogeneous sources - structured transactional data, unstructured log files, data updated at different frequencies (real-time trading versus monthly address changes) - from legacy systems designed without quality governance. Solutions require automation of data ingestion, constant monitoring and analysis at every step, and alerting systems to catch inconsistencies, rather than manual inspection which misses anomalies in apparently normal-looking data.
Rather than generative AI, financial firms are deploying machine learning models for anomaly detection, simulation testing of disruption scenarios, predictive risk assessment, and fraud/cybersecurity pattern recognition. Success requires consolidating data silos so fraud, security, and compliance teams can access transactional data, log data, and authentication data together, supported by DataOps infrastructure and cross-functional team organization.
Leaders have invested in data infrastructure, automation, and cross-functional teams with strong governance, enabling them to shift from reactive risk management to predictive approaches. They report reduced downtime, enhanced ROI, and better ability to anticipate disruptions - versus planning-stage firms facing barriers like poor data quality, lack of automation, and cultural resistance to change.
Senior leadership must mandate operational resilience as mission-critical with no optionality, recognizing that extended downtime in payment systems could create systemic financial risk, and that fines for non-compliance could be severe. They need to ensure plans are tested, staff trained, and architecture designed to tolerate downtime while guaranteeing zero data loss in systems processing millions of transactions per second.
Computed from the transcript - who did the talking, and the words that came up most.
How are leading financial institutions turning regulatory demands into strategic advantage? In this FStech podcast, sponsored by BMC Software, we explore how DataOps and AI are reshaping operational resilience across the sector. Drawing on the new report, "Shaping the future: The strategic role of DataOps and emerging technologies in enhancing operational resilience for modern financial services, " our discussion explores why a third of firms now place DataOps at the centre of their resilience strategy, and how barriers such as poor data quality, limited automation, and cultural resistance are being overcome. Listeners will discover practical steps for building a data-driven culture, overcoming implementation challenges, and using automation to transform compliance into a true and lasting competitive edge.
Transcribed and scored by The B2B Podcast Index.
Speaker A: This is the fstech podcast. Hello and welcome to this FSTECH podcast. From Compliance to Competitive Edge. Rethinking Operational Resilience with Data Ops and AI Sponsored by bmc. I'm Jonathan Easton, Editor at FSTECH and I will be your host for today's discussion. In recent years, operational resilience has moved firmly up the agenda for financial institutions across Europe. Heightened regulatory scrutiny through frameworks such as DORA has brought with it stringent expectations and significant consequences for non compliance. But beyond the regulatory drivers, resilience is fast becoming a strategic priority as firms look to data and emerging technologies not only to safeguard operations, but to deliver competitive advantage in a volatile market environment. Today's conversation takes its cue from our newly published report Shaping the the strategic role of DataOps and emerging technologies in Enhancing Operational Resilience for Modern Financial Services. The report explores how a growing number of firms are embedding DataOps into their resilience strategies, with around a third doing so already, while also confronting significant hurdles around data quality, cultural resistance and lack of automation. It also reveals how AI is starting to play a pivotal role in resilience planning, particularly in simulation testing and predictive analytics. To help us unpack these findings and discuss how the sector is adapting, I'm joined by two experts from BMC Software. First, Duncan Ash is global Head of Banking and Financial Services, which with deep experience advising financial institutions on transformation and operational risk. Also with us is Jenny Glensky, Director of Portfolio Marketing, whose work spans data management, automation and enterprise resilience. Today we'll explore how institutions can move beyond a compliance first mindset to build more dynamic data driven resilience strategies and what it will take to turn regulatory pressure into a platform for long term success. So with that all said, um, Duncan, let's kick off the discussion by looking at how the introduction of DORA and the FCA's regulations have fundamentally shifted operational resilience from a best practice to a strategic imperative for financial institutions.
Speaker B: Sure. Thanks, Jonathan. Well, I mean uh, it has become uh, a strategic imperative. Obviously DORA and the other regulations in different countries have pushed it up the agenda and made it uh, a priority for uh, the boards running these financial institutions. And I think it presents some of them with a lot of challenges because these institutions have been around for a long time. Um, when you look inside the details of dora, there's a lot of content in there around cyber resilience, um, fraud prevention, money laundering controls, that sort of thing. And a lot of the organizations designed their production systems, particularly their transactional systems back in the days when cybersecurity wasn't a thing. So when we were designing resilient systems 20 or 30 years ago, uh, we were worried about unintended consequences of accidents or uh, a power cut or a flood or a network failure, hardware going wrong, which we still have problems with, but that was the biggest risk back then. So we designed systems that had resilience built in through having maybe a second data center, uh, um, your real time copies of the data, making sure that everything was in sync. And it was always um, a failover site where you could uh, store your data or recover to. And firms still have that capability. However, cyber resilience makes it much harder because obviously if somebody infiltrates your organization and um, starts putting bad data into one of your systems, um, then you're just going to replicate that to your Dr. Site and you're going to have two copies of something that's wrong rather than just one copy. So organizations have had to start looking at that a little bit differently and um, putting in different systems and different processes. And so yes, it's become, it's become front of mind. And I would say that as part of it becoming a strategic imperative, it goes beyond just technology. So firms have to have an incredibly good plan in place for what they're going to do in a specific set of scenarios. They have to test those scenarios partly to make sure they work and partly because the regulations say they have to. Um, but then they have to train their staff and make sure that their staff really understand how to execute the uh, plan in the event of an outage. And typically things don't go wrong 11 o' clock on a Monday morning when everyone's in the office, they go wrong at uh, 3:00am on a bank holiday when nobody's there. So people need to get their plans, they need to train and they need uh, very well designed systems that store data in a way that it's really resilient. And people talk about techniques like air gapping and having completely um, offline copies of all of the data. So if something goes really wrong, they can rebuild their systems almost transaction by transaction, uh, to get everything back up and running. And also they need to be able to do it really quickly. So yes, it's a hard job but um, it's necessary in order to uh, make the financial firms um, as resilient as they need to be.
Speaker A: It's, it's really interesting you uh, mentioned, you know, the, the cultural side of things as well. Um, you know, I think that that is uh, often underappreciated you know, I think of it almost like an F1 team or anything like that, where, you know, you can have a race car that's worth hundreds of millions of dollars, but if you've got, you know, your local mechanics changing the tires, you know, even the best driver in the world is going to go around slowly. So it's all about having the different parts of the machine, uh, working and everyone on the same uh, wavelength. And that's kind of what DataOps is. It's not just the tech side, it's the marrying of the tech and the skills and cultural mindset. Um, and certainly the report um, shows that that is becoming an increasing focus for uh, financial institutions. With a third of our survey respondents place data ops at the centre of their resilience strategy. Um, Jenny, what distinguishes these leaders from Those slightly more 34% in the survey who are still at uh, that planning, implementation stage?
Speaker C: Well, organizations that have already embedded DataOps into their resiliency strategies are distinguishing themselves through their proactive investment in the data infrastructure. Talent and culture, like you're talking about, takes culture as well. These leaders are leveraging DataOps to yield various benefits. I think the respondents in the report talked about reduced downtime, enhanced ROI and the better ability to anticipate disruptions. In contrast, those that are still in the planning and implementation phase reported that uh, they're facing barriers such as poor data quality, lack uh, of automation and that cultural resistance to change that's difficult to overcome. The organizations already using DataOps, they're implementing automation, they're building those cross functional teams and they are instituting strong governance and policies and controls that allow them to move from being more reactive to risks to taking on more of a predictive risk management approach. And these more mature data processes and data management practices allow them to respond better and faster to those risks when they evolve and to both the uh, changes and shifts in the market and in regulations as well.
Speaker A: Yeah, it's really interesting that, you know, these banks that have access to so much data think they should be kind of at the forefront of this. But poor, um, data quality was cited by over half respondents as a primary barrier. Um, Duncan, what are your thoughts on how financial institutions can break this cycle when quality data is essential for the very solutions they need?
Speaker B: Yeah, it's a good question because data quality's always been an issue as long as I've been working and different types of systems tend to be more susceptible to errors in data quality. Um, so if you look at um, production systems for transactions or payments Say, um, they tend to be more reliable because they're automated and you tend not to get too many errors in those systems. However, um, other types of system and systems, um, where humans are involved, where a human has to put a name or a number in a form, um, is typically where you get things going wrong. Sometimes it could be something as simple as a, um, a poorly formatted post or code or a phone number that's got too many digits in. Um, and sometimes it's just something much worse and it's made harder by the fact that when you look at a regulation like DORA or the equivalence, you're looking at data that's coming from a lot of different systems with a lot of different uh, compositions. So you're looking at highly structured transactional data, uh, rows and columns, the general ledger, uh, uh, then you're looking at things like log files, which the security teams look at extensively, which are completely unstructured, um, and can be quite hard to decipher. Although log systems tend to be a bit more, uh, accepting of unknown or interesting data in them. So uh, they can be quite resilient to that. Um, but you're looking at lots of different data formats from lots of different data systems, some that are updated very frequently. Firms who trade, they're updating the data multiple times per second. Same with payment systems and transaction systems. Some pieces of data don't change very often. Um, some pieces of data change maybe once a week, once a month, maybe your postal address changes every five or ten years. So huge range of different types of data you have to deal with, um, from a huge range of systems and it all has to be correct and it all has to work together. Um, because if any of it goes wrong then you can't ask the questions you need to ask a bit and mistakes get made. And so if you, if you rely on that, that data, uh, as a source for your analytics and your analytics are going to be wrong. Someone's postal address is wrong, you send them a statement, it goes to the wrong place or much worse. So, um, the data quality is an issue. How do you fix it? Well, you can fix it a bit by automating it. Um, so any of the, anything that you possibly can benefits from automation, uh, automate the process to get hold of that data. Some of that data is real time. Some of that data comes through in batches. Um, sometimes it's hourly, sometimes it's overnight, sometimes less frequently. Um, when you can automate those data processes and you have a framework in place that can not just Automate the data, but monitor the automation of that data and analyze it every step of the way and look for inconsistencies. Then you get a lot closer to being able to uh, be confident in the data you're using. And when there's a situation where uh, your data quality starts to break down, then actually the analytics will pick it up and alert you to uh, the fact that something's gone wrong. So um, yes, automation, monitoring and analysis, constant analysis and measurement, um, is what's required and that will get you a lot closer to perfect data. I don't know anybody who has perfect data. But um, but we can get closer to it.
Speaker A: I mean if there's even such a thing as perfect data, uh, or as perfect as it can be, uh, but it is interesting because it's not like a garden where you see the weeds shooting up through the pavement. So much of this stuff is outside out of mind. And even if you've got the most sophisticated data scientists looking through this stuff, if the data kind of looks normal, the anomalies aren't going to jump out. Even if it's wrong. Just because it's appropriate in the right place doesn't mean it's necessarily uh, going to be um, obvious to uh, the people looking at it. So it's having those systems in place which are able to monitor these things as you say, seems uh, to be the best course of action. And one thing you mentioned as well is having that oversight and the human in the loop as they say, with all the kind of AI stuff that we're going to get to a little bit later in this conversation, which is not just best practice from a business perspective, but it is a requirement of the regulations that are coming in the eu, AI act, dora, requiring that human element and beyond, not just in this aspect, but just beyond compliance and just the box ticking that DataOps helps with. What are some of the competitive advantages that early uh, adopters of DataOps and automation are realizing? Sure.
Speaker B: So um, yeah, DataOps, um, and having good quality data is a fundamental requirement. Your data forms the bedrock of all of the business applications that you run. So your production data needs to be accurate, as uh, accurate as possible. Um, and also people often have uh, separate sets of data for analysis. They tend not to run their analytics on their production database or production data store because of the risks of potentially somebody causing a problem. So uh, you need to make sure that your analytical data and your production data are constantly in sync. That's really important. And you need to make sure that the quality is really high and you need to make sure that uh, whenever a new data point comes along, you're able to include that in uh, your analysis. Otherwise it's going to be wrong. So um, I think your question was about um, what advantages the early adopters are seeing. And I would say better data means ah, better quality applications with less errors, less complaints and a financial firm with less people complaining, more people happy means um, a better brand and a better net promoter score and all of the good marketing things that you get from not making mistakes. So uh, yes, you've got to do it because a regulator says you've got to do it and you've uh, got to do it because you don't want to get fined. But actually there's a massive upside of doing it, having good data. So there's everything to gain right across the business from your production systems right through to all of your analytical applications and all of the things that your customers want to see. Imagine logging into your app. Imagine logging into your banking app, on your iPhone and then somebody or m you looking into your website to look at the same bank account and getting different answers. Imagine if your balance was different in two places would be a disaster. So you need to make sure that that data is in sync and always, uh, always correct. Um, so many examples, so many things that uh, could go wrong that you need to make sure that uh, you've got covered.
Speaker A: What's one of those kind of buzzwords, as it were. But single source of truth is fundamental
Speaker B: there and we've been talking about it for 20 years and uh, we're still talking about it. So um, obviously because people haven't cracked it yet.
Speaker A: And do you think that we're in this new AI automation age? We're any closer, uh, to that? Or is it a bit of a white whale?
Speaker B: I think we're getting better, but the problem is the data in the universe is getting more prolific, um, both in types and in volume. Um, that's not a news story. We've been talking about it for years and the techniques have got better. People have introduced things like event driven architectures, which probably we don't have time to talk about on this podcast, but that's changed the way people are working. So people are replicating their data around the world much better. Um, so we're getting closer. Is data perfect? No, um, but we're getting a lot closer and we're giving people, I think a lot more comfort by putting automation in place and by monitoring that automation that we're doing the best possible job we can with what we've got. So it is getting better?
Speaker A: Well, we talk about automation and AI being so tightly linked together, um, throughout all of this, but particularly when we're looking at risk management. What's the role that AI is playing in transforming how firms are approaching that?
Speaker B: Yeah, sure. So it's probably worth qualifying what we mean by AI but also qualifying what we mean by risk management. So AI obviously has been something that's taken up the whole world over the last few years, but it's been a gradual transition from basic data analysis and statistics through to business intelligence and um, more sophisticated analysis. And then that's kind of transitioned over the last few years to something more sophisticated. People have started, not started doing machine learning because machine learning has been around for ages. But um, started to use it very, very well. And then suddenly a few years ago machine learning jumped the gap and generative AI came along. But also lots of other types of machine learning based AI that allowing people to solve really difficult problems and make a lot of things better, but also in some cases getting it wrong as well. Um, there are all the stories about people typing things into well, uh, known chatbots and getting crazy answers that still happen. So the industry hasn't got it completely right yet, but it's getting better every week the way it seems at the moment. So AI has come a long way and we talk about risk management. In this case we're talking about operational risk. See we get involved in things like credit and market risk as well. Um, but that's probably outside of the scope of this conversation. This is talking about risk management specifically for operational risk and resilience. Um, and I'm going to include cybersecurity and fraud detection and money laundering, um, money laundering prevention in that conversation. Um, and it's being used a lot less on the generative side. More sophisticated machine learning models, improving risk, um, looking for things that are wrong. Um, people have been using sophisticated techniques for cybersecurity for quite a long time. Similar but slightly different techniques for fraud detection. Again, that's just getting better. So we can use it and we are using it to improve things. It is reducing risk in the system, it is helping people improve their cybersecurity posture. Um, fraud is still a big problem in the industry and again that's probably an entirely separate podcast in its own right. But a lot of these things are about getting all the data together, getting them in the same place. And people who are really successful in uh, reducing risk in an operational risk sense can be more successful if they have all of the data in one place. So teams that are trying to fight, uh, cyber or fraud problems, if they don't have all of the transactional data and they don't have all of the log data and they don't have the authentication data and all of those kind of critical sources, um, then they can't do as good a job. And the way that some firms have been organized over the years has led to silos getting created. The fraud and the security teams don't always know each other. That doesn't help. Um, they don't always share data. That doesn't help either. So again, we're back to the culture and organizational design of firms. Um, if you really want to get good at this, you need to think about how your firm is designed, who works together, how you bring cross functional teams together, how you help them work together, um, and how you help them share data and systems and processes and all those teams being part of the big plan. When you're successful in doing so, um, then you're going to be really good at, uh, reducing the operational risk and um, um, you'll be more compliant with these regulations and get back to DataOps. That's all a really clear part of it. If you need to bring all of those data silos together, then automate it. Don't ask people to bring the data to the table. Automate bringing the data to the table so that, uh, people can just work with it. Um, so yes, there's a lot going on, um, and I think it's going to keep on evolving a lot.
Speaker A: Yeah, really fascinating. Uh, thank you, Duncan. You know, even people say that we're at kind of this dawn of this AI era and it just seems as though it's already playing such a big role in risk management, as you say, operational risk more so than, you know, cyber, but all across, uh, the industry. Jenny, just curious to get your thoughts, if there's anything you'd like to add from what Duncan's talked about there.
Speaker C: Certainly. Well, I noticed that the survey highlights particularly that organizations are using AI to simulate disruptions, enhance their predictive capabilities and identify root cause and anomalies. And these are allowing them to move faster and make more accurate operational risk assessments. Not surprisingly, over half of the early adopters of data ops and automation also reported reduced operational downtime as one of their biggest benefits. So I think there really is a very clear direct link between that AI and DataOps and that automation and those immediate benefits you're getting from the reduced operational risk, which is Great to see because that's now with all these new regulations, definitely the front of mind and a very important topic that a lot of organizations are trying to get under control.
Speaker A: And um, you know, so much of this is, has to be driven from the top down. It's not just, uh, we implement this tech and it kind of does its own thing. It's uh, about the role of senior leadership. And what actually does that look like in reality? What role should senior leadership play in transitioning an organization from viewing operational resilience as this box ticking exercise regulatory burden as we've talked about, to using it as a strategic differentiator?
Speaker B: Sure. I would say that the way the regulations are written now, the senior leadership needs to be quite tough on this and mandate it. I think that firms are making their plans on the basis that there are going to be significant fines for firms that get this wrong. And those fines could potentially hit individuals as well in multiple ways. And so the kind of thing that
Speaker A: will make using WhatsApp, uh, look like a drop in the bucket.
Speaker B: Yeah, absolutely. And firms are worried about downtime, as Jenny mentioned. And I think in a financial institution you can probably tolerate, you can probably get away with a bit of downtime. Minutes, possibly hours in a really bad example is possibly something that you can survive. I know that people are very familiar with, uh, an incident that took place in the retail space not so long ago with an organization who um, had really significant downtime. I think a financial firm wouldn't survive that. So something where a firm is down for multiple weeks, if people don't get paid, if payrolls don't go through, if payments don't clear, there's a systemic risk there. Ah, so it's a really serious problem. Uh, and therefore as a senior exec, I would be putting these plans in place and mandating them. And certainly there's no optionality in any of this. It's absolutely mission critical. Um, so they need to get it right and they need to make sure that if they do ever have any downtime, they certainly mustn't have any data loss. When you look at firms who transact and that, you frequently see examples of systems where a million transactions a second take place, um, both in trading and in things like payments. Well, if you're down for a second and a million payments go missing, then you have a really major incident. So you can't lose a single byte. And you need a plan, you need a resilient architecture that can tolerate downtime and still not lose a single bite. So that's really what people are working towards and that's really hard. So um, yeah, senior leadership should be taking it very seriously and I believe they are. I think uh, all the firms I've spoken to are taking it really seriously. They put teams in place. They've had teams in place for a while and they're putting a lot of resource and expense into it. So um, yeah, this is a, a big ticket item and uh, I think it's something that people are going to be working on for a long time.
Speaker A: Any final words of advice from you Jenny, when it comes to the senior management role position in all of this?
Speaker C: Absolutely. We're seeing the leaders in organizational resiliency, investing in the infrastructure and the data ops and AI tools. They are aligning their resiliency goals with their broader business objectives like Duncan mentioned and they're setting the tone from the top to embed into their strategy their leadership conversations. They're investing in those cross functional teams. All of that's helping them to not just manage operational risk, but to accelerate their innovation, to give them a competitive edge and to position them better in their industries and in their market.
Speaker A: Well, I think that's a great way to wrap up today's discussion which has been a fascinating look into the evolving role of DataOps, uh, in financial services. So sincere thank you to our uh, speakers from BMC Software, Duncan Ash and Jenny Galensky for sharing your insights and expertise. So we've covered a great deal today from the shifting regulatory landscape through to the practical challenges of implementing DataOps across complex environments. One of the key messages to emerge is that operational resilience is no longer a compliance exercise. The firms that are embedding DatOps and generative AI and AI more broadly into their resilience strategies are not only best prepared to meet regulatory demands, they're also gaining meaningful advantages in risk forecasting, processing efficiency and decision making. We've also heard that data quality, automation and organizational culture remain persistent barriers to. But with the right investment and leadership focus, particularly around building a data literate culture and standardizing operations, these challenges can be addressed. So for those of you who are yet to read the full report, shaping the the strategic role of DataOps and emerging technologies Enhancing Operational Resilience for Modern Financial Services, I'd heartily encourage you to do so.
Speaker B: They can be found over on the FSTECH website.
Speaker A: I think it offers uh, valuable findings and practical guidance that we weren't able to cover fully today. Uh, so we just scratched the surface. But uh, yes, thank you again to Duncan and Jenny and we hope that you listening. Uh, continue the conversation with your colleagues as you consider how resilience strategies can evolve within your own organization. For FSTech, I'm Jon Easton. And goodbye for now. Thank you for listening to the fstech podcast test.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.