1 of 12

Architecting Trust

Data, Analytics and Regulatory Resilience Beyond the Legacy Stack

Aleksandra Brdar Turk, Ph.D, FRM, RAI Holder

Chief Transformation Officer, OTP Banka Slovenia

1

2 of 12

Trust is engineered — not audited.

2

3 of 12

If your architecture is fragmented, your compliance is fragile.

3

Legacy fragmentation

Engineered trust

In regulated finance, trust is no longer produced by documentation alone — it’s produced by architecture.

DORA and the AI Act shift expectations toward traceability, operational resilience, and continuous assurance.

REGULATORY CONTROL PLANE

AI & Analytics

Governance & Quality

Integration & Events

Core Systems

4 of 12

Regulation has become architectural.

Trust as Architectural Outcome

Trust must be designed into financial technology architectures, not treated as a compliance afterthought.

Regulatory Resilience

Building resilient systems helps meet regulatory expectations proactively and respond to evolving risks.

Responsible AI Adoption

Embedding trust ensures AI adoption is responsible, transparent, and aligned with ethical standards.

Data and Analytics Integrity

Reliable data and transparent analytics form the foundation for preventing financial crime and building trust.

The ability to achieve regulatory resilience, foster responsible AI adoption, and prevent financial crime is fundamentally dependent on the design and integrity of data and analytics architectures.

4

5 of 12

The Trust Problem in Modern Banking.

Driven by rising regulatory expectations and the complexity of digital transformation

5

Rising Regulatory Expectations

New regulations like DORA and the EU AI Act increase demands on data governance and operational resilience in banking.

Assessment of Processes and Outcomes

Supervisors evaluate both results and underlying processes including data lineage, model governance and ICT dependencies.

Legacy Technology Challenges

Many banks rely on outdated systems that lack transparency and real-time responsiveness needed for compliance.

Impact on Trust and Compliance

Inadequate systems struggle to provide the transparency, traceability, and real-time responsiveness expose banks to compliance risks and erode stakeholder trust in modern banking.

6 of 12

Legacy Stacks: Where Trust Breaks

Fragmentation creates compliance fragility and operational drag.

6

Core Systems

Batch ETL

Data Marts

Manual Recons

Reports / Evidence

Typical failure modes

  • Lineage is incomplete or manual.
  • Evidence is assembled after the fact.
  • Batch latency hides real-time risk.
  • Vendor black boxes complicate accountability.

What it costs

  • Slow incident response and hard-to-prove controls.
  • High false positives in AML/fraud (data quality).
  • Unpredictable delivery: every change breaks something.
  • Regulatory conversations become defensive rather than strategic.

7 of 12

Why Legacy Architectures Undermine Compliance?

Inefficient Data Processes

Legacy systems depend on batch ETL, duplicated data marts, and manual reconciliations causing risks and inefficiencies.

Weak Governance Integration

Governance is documentation-based, not embedded in operations, leading to gaps between compliance and execution.

Lack of Real-time Transparency

Disconnected AI experiments and legacy systems hinder real-time data management and end-to-end regulatory transparency.

Reactive Compliance Challenges

Compliance becomes reactive and burdensome, undermining regulatory trust and operational effectiveness.

7

8 of 12

From Reporting Layer to Control Plane

A fundamental shift in how financial institutions approach compliance and risk management: embed governance, quality, monitoring, and evidence into the platform.

8

Traceability

Accountability

Resilience

Explainability

What the control plane delivers

  • Traceability: source → transformation → report/model → decision.
  • Quality controls: automated checks, thresholds, and exception handling.
  • Continuous assurance: real-time monitoring + evidence generated as a byproduct.
  • Clear accountability: ownership mapped to data products and controls.

REGULATORY CONTROL PLANE

AI & Analytics

Governance & Quality

Integration & Events

Core Systems

9 of 12

DORA as a Design Catalyst

Regulatory requirements should drive architectural maturity

Meeting DORA requires designing systems with inherent transparency, traceability, and resilience.

Future-proofing Operations

Treating DORA as a design imperative helps institutions future-proof operations and exceed regulatory standards.

DORA mandates ICT risk transparency, incident reporting, third-party risk mapping, and operational resilience testing. It is fundamentally architectural: you must know what depends on what, and prove resilience

9

10 of 12

AI & Financial Crime Case: Trust at Machine Speed

The Ambition

🡪 High-quality trustworthy data reduces false positives and ensures explainable AI decisions in financial crime prevention,.

🡪 Delivering trusted insights at machine speed enhances detection, prevention, and customer confidence.

The Roadmap: Practical Next Steps

    • Start with critical data
    • Implement quality gates
    • Operationalize the control plane
    • scale AI with lifecycle governance

How fundamental building blocks of underlying data impact decision-making.

10

11 of 12

Trust is a strategic control layer integrated into technology architecture, vital for financial institutions.

Trust must be proactively engineered into data and analytics platforms, not added after the fact.

Institutions with built-in trust achieve regulatory resilience, encourage innovation, and maintain competitive advantage.

Adopting a trust-first architecture equips organizations to manage complex regulations and deliver stakeholder value.

11

12 of 12

Every day is a great day to learn something new

Enthusiastic problem solver, technology lover and disruptor who thrives outside the box and happily shares ideas with

a team of fabulous

co-workers.

Aleksandra Brdar Turk