AI Data Governance in Investment Advice: When Legacy Decisions Become Model Risk
A client profile can look complete while the path from that profile to a recommendation tells a different story. Historical advisory notes, product choices, exceptions and overrides may later become training data. If their original context is lost, yesterday’s decision pattern can become tomorrow’s model behaviour.
Why the data question is also a governance question
Data quality is more than whether a field is present. A record reflects choices about what was asked, which answer was accepted, how it was labelled, what was omitted and which commercial or operational pressure surrounded the interaction. A model trained on that record may inherit the pattern without inheriting the explanation.
That does not mean every historical dataset is biased or unusable. It means an institution should be able to explain provenance, intended purpose, representativeness, preparation, assumptions, gaps and the decisions that produced the labels. FINMA’s 2024 AI guidance identifies data quality, model robustness, bias, explainability and clearly assigned responsibility as material governance concerns for supervised Swiss institutions. For high risk AI systems within the EU AI Act’s scope, Article 10 addresses data origin, preparation, assumptions, possible bias, gaps and suitability for the intended purpose.
The illustrative pathway
- A client’s knowledge, experience, financial situation, loss bearing capacity, objectives and risk tolerance are recorded.
- An adviser interprets the profile, the conversation, available products and the client’s behaviour.
- A recommendation is made, perhaps with an exception, an override or a change in the documented rationale.
- The interaction becomes a note, label, transaction or outcome in a historical dataset.
- That dataset may later inform analytics, a recommendation model or an automated advisory workflow.
The governance issue is not simply whether the final recommendation was accepted. It is whether each transition remained understandable, suitable, accountable and reviewable. In the EU context, MiFID II Article 25 connects suitability to information about knowledge and experience, financial situation, ability to bear losses, objectives and risk tolerance. ESMA’s suitability guidance also takes account of automated and semi automated advice. The applicable regime depends on the institution, jurisdiction, service and system.
Where a hidden pattern can enter
1. Capture and representation
A structured profile may not capture ambiguity in the conversation, a client’s changing circumstances or the reason an answer was revised. Missing values and inconsistent records can be mistaken for neutral facts.
2. Interpretation and labelling
Advisory notes and outcome labels may encode an adviser’s assumptions, product framing or local incentives. An accepted recommendation is not automatically evidence that the recommendation was suitable. A rejected recommendation is not automatically evidence that the client was unsuitable.
3. Exceptions and overrides
Overrides can be responsible judgement, a sign of an incomplete rule, or an indication that a control is being bypassed. Without a reason, authority and subsequent review, the dataset cannot distinguish those possibilities.
4. Reuse and feedback
When legacy decisions become training, validation or evaluation data, the original selection and interpretation can be amplified. Later model outputs may also influence future records, creating a feedback loop. A data inventory alone does not resolve that loop.
A controlled diagnostic, before automation
A useful pilot would begin with a bounded sample and an agreed governance question, not with a promise to detect every bias. Three complementary workstreams can be designed:
- Data and decision lineage: map source systems, original collection purpose, transformations, labels, missing data, version history, exceptions and ownership.
- Advisory pathway review: examine a controlled sample of anonymised or lawfully processed interactions for profile and recommendation mismatch, pressure signals, reasoning changes, escalation and documented authority.
- Training data readiness: test whether the historical sample is suitable for the intended model purpose, whether labels are reliable, and which patterns require correction, exclusion, additional context or independent review.
The earlier Brandmind profiling lineage offers a reasoning mechanism: identify meaningful observable attributes, weight them explicitly and interpret the combined pattern. NomaMind has continued that architecture through connections among Personality ASPECTS, biases and Ego Development. Applying such reasoning to advisory decision pathways is a research and validation question, not proof of a deployed real time Drift detector. Proprietary mappings are not disclosed here.
What the pilot would need to establish
- A precise population, period, service and decision boundary.
- A lawful basis, purpose limitation, minimisation, access controls and retention plan for personal data.
- Clear definitions for mismatch, override, escalation, pressure and outcome.
- Independent review, inter reviewer agreement and a process for challenging interpretations.
- Predefined measures such as coverage, data gaps, label consistency, exception rates and the quality of documented rationale.
- A decision owner who can act on the findings and a route to legal, compliance, model risk and data governance review.
Pseudonymisation is a security and governance measure, not the same as anonymisation. Any client or employee profiling requires a separate legal and ethical assessment. The pilot should not automatically label individuals or change live recommendations. It should test evidence quality and control design in a controlled setting first.
The practical output
A credible diagnostic could produce a decision and data lineage map, a sample based risk heatmap, a register of gaps and assumptions, an override and escalation analysis, and a prioritised control roadmap. Any improvement in suitability, retention, model performance or regulatory defensibility would have to be measured against an agreed baseline. It is not an outcome that can be claimed in advance.
Start with the governance foundation
NomaMind’s paid AI Governance Readiness Assessment examines the current ecosystem, material gaps, decision ownership and implementation priorities. A short fit request comes before any paid engagement is scoped.