Why AI doesn’t fix bad data, but you can
By James Dickson, Founder and Managing Director, Oceanic Consulting Group (OCG)
Data governance has been on the agenda in financial services for a decade, and the industry still hasn’t broken the back of it. With AI arriving, the cost of leaving it unfixed is about to compound. It helps to break the problem into its three limbs.
Data governance has been on the agenda in Australian financial services since before the Royal Commission, and nobody disputes that it matters. It has also proved hard to finish, which is why so many capable firms are still working at it.
Walk into a typical broking, advice or wealth business today and the data picture is much like it was ten years ago, only bigger. That is rarely for want of effort: the problem grows faster than most programs can close it. What has changed is that AI is now being layered on top of records that were never built to carry it.
AI doesn’t fix bad data. It believes it.
Most business plans assume more AI for the year ahead. Fewer account for the state of the records underneath, which is understandable, because until now those records have not had to withstand this kind of scrutiny. Advice failures are back in the headlines, and behind them sit files that look complete but cannot defend the core decision: why the advice was right for that client.
‘A model trained on messy records hands the mess back looking confident and polished. When the first big AI failure in advice happens, it won’t be because the model failed. It will be because AI did the right thing with the wrong information.’
Firms treat data governance as one amorphous program, too big to start and too vague to finish. Break it into three limbs and each can be fixed on its own.
The three limbs of data governance
Sovereignty
The first limb is data sovereignty: knowing where your data is and who controls it. A client record might sit in a CRM hosted in one jurisdiction, be processed by a vendor’s support team in another, flow through a platform whose sub-contractors you have never met, and now be pasted into AI tools whose storage arrangements nobody has read.
Sovereignty means answering plain questions. Where does this data live? Which laws apply? Who can see it, including inside your vendors? Could you get it back if the relationship ended tomorrow?
APRA has made its expectations clear through CPS 230. Most broking firms sit outside that perimeter, but the standard is worth reading as a benchmark rather than an exemption, because ASIC’s expectations on outsourcing and data handling are unlikely to diverge materially. If you cannot answer these questions, you don’t have full control of your data, whatever the organisational chart says.
Duplicated data
The second limb is duplicated data. If the same client exists more than once across your CRM, your platform and the registry, and nobody can say which version is the source of truth, you have this problem. Decades of systems, mergers and migrations built it.
Nobody fixes duplicates until something forces the issue. Usually it’s advice written from a stale record, or a remediation program that burns its first six months working out what the records actually say. CHESS replacement will force it too. If your plan is to move onto a modern books and records platform and let the migration sort the data out, expect problems: you’ll be loading the same duplicates into a new system, and it will pick a version for you.
No system will resolve this for you, because the question isn’t a technical one. Someone has to decide which record is the client, and the rest have to go. We see this everywhere, from single-adviser practices to the largest super funds in the country.
Toxic data
The third limb gets far less attention: toxic data. This is information sitting in your systems that should never have been stored, or should have been destroyed long ago. Tax file numbers in free-text fields and email trails. Scanned passports and driver licences from onboarding a decade ago. Old KYC packs copied across shared drives.
It has no business value and an unlimited downside: it does nothing for the client, and all of it is available to whoever gets into your systems.
If you would struggle to explain to the regulator, or to the client, why you still hold something, you shouldn’t hold it. Find it, destroy it and stop collecting it.
What this now costs
Poor data handling used to mean a determination and some reputational damage. A serious interference with privacy now attracts the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover, with two lower tiers beneath it worth roughly $3.64 million and $364,000 for a body corporate since the penalty unit rose on 1 July 2026. The $50 million figure gets the headlines. The tier below it is the one most firms will meet, and the conduct that takes you there is as mundane as a shared drive full of decade-old passport scans.
Penalties run per contravention. The first was ordered in October 2025, $5.8 million against Australian Clinical Labs, and the Optus and Medibank proceedings continue through 2026. From 10 December 2026, privacy policies must also disclose where personal information is used in automated decision-making.
How to get on top of data governance with a clear plan
Not another enterprise data strategy. Firms that make progress work limb by limb, against a short plan:
- Put the three limbs on one page. For each critical data set: where it lives, which system owns the truth, and whether it should exist at all.
- Hunt the toxic data first. Searching systems and mailboxes for TFNs and identity documents is the cheapest, fastest risk reduction available, and specialist tools do it quickly.
- Name a source of truth for every field. Then retire the duplicates rather than reconciling them forever.
- Ask your vendors the sovereignty questions. Where is it, who can see it, what leaves the country, and what happens when the contract ends.
- Put controls between the data and the AI. Nothing reaches a client without human oversight and a named person accountable for the output.
Why AI is good news for data governance
None of this is fixable with a technology program, which is why a decade of technology programs hasn’t fixed it. That is the good news, because what it needs instead is ordinary governance: decisions, owners and rules that get enforced. Hand it to the technology team alone and you keep the business problem while adding a layer that reproduces it at speed.
What AI has changed is the timeline. Taken one limb at a time, the work is smaller than it looks, and a great deal cheaper than finding out what your data really says during a breach or a regulator’s review.
At OCG, we work with firms to turn data governance into something that can actually be finished. For a confidential discussion, please reach out.
DOWNLOAD SIAA Monthly – August edition PDF
BACK TO SIAA MONTHLY – AUGUST 2026