– My name is …

The topic I'm going to talk about is important now and will become increasingly important in the future.

I’d like to leave you with three things :-

1) Something to think about (The Data Architecture).

2) Something to take away

3) Something to call on in the future, (Tutorial and Method on Web Site).



1. WHY ? (New Regulations)

The Events and results cannot be ignored.
There are a number of Initiatives -
Basel II Accord, Patriot Act, Homeland Security, Sarbanes-Oxley.

1.1 Basel (Banks and Risk Reporting)

– Compliance date – end 2006.

1.2 Homeland Security (‘Keep out the Bad Guys’)

January 24, 2003

- includes Border, Transportation and Port Security

- The new U.S. Visitor and Immigrant Status Indication Technology system (U.S. VISIT) entry-exit system backed by 21st. century technology - is designed to make entering the U.S. easier for legitimate tourists, students and business travelers, while making it more difficult to enter the U.S. illegally through the implementation of biometrically authenticated documents.

- in its first phase of operation at international air and ports of entry by end of 2003.


1.3 Office of Foreign Assets Control (‘Who owns What’)

OFAC– (of the Dept. of the Treasury)

OFAC enforces sanctions based on US foreign policy against targeted foreign countries, terrorists, international narcotics traffickers, and those engaged in activities related to the proliferation of weapons of mass destruction.

Vendors - Bridger -

- Innovative systems -

- OFAC Compliance -

1.4 International Accounting Standards (“Let’s do things Right”)

 - by 2005.

EU members are mandated to report financial results as per the IAS by 2005. 

1.5 Patriot Act (‘Keep out the Bad Guys’)

– October 26th. 2001

– Became law in October 26th. 2001

- Section 326 – requires identity verification.

Vendors - Bridger -

The US PATRIOT Act requires timely and accurate reporting required by industry regulations.

Impact on IT : Need to create a firm-wide infrastructure to understand overall position of any client across all business units

(Extract from : Fti_data_integration.pdf - Area of IT Spending : Regulatory reporting)


Financial Enterprise Software December 2002

© 2002, Financial Technologies International . Reproduction prohibited.

Enterprise-wide risk management.

Securities firms are finally coming to understand the importance of calculating firm-wide risk levels.

Too many firms have been hurt financially by poor risk management. Firms have too often failed to curb activities of rogue traders whose activities may sink the entire operation, as was the case

with Barings (the highest-profile case of many) when one of its traders in Singapore engaged in illegal trading in Japanese derivatives.

1.6 Sarbanes-Oxley Act (‘By the Book’)

– SOX – enacted July 30th. 2002 in response to a number of major corporate accounting scandals, eg Enron and Worldcom

- requires company executives to certify the accuracy and legitimacy of corporate financial statements or face the possibility of punitive and criminal action.


 - 23rd. October 2003 (Governance)

-- 23rd.October 2003 – must register to do audit work.

-- 15th. June      2004 – additional disclosures required.


Sections 302 and 404(a) deal with the inernal controls that a company has in place to ensure the accuracy of their data.

302 – CEOs and CFOs must attest the accuracy of their company’s quarterly and annual reports:-

1) they have seen the reports.

2) the report contains no false statements, and leaves nothing material out.


404(a) – originally sept 15th. 2003, then extended to June 15th. 2004

1) Annual report must contain an internal control report .



22nd. Augustt - META Group Poll Shows 90 Percent of Companies Engaged in Sarbanes-Oxley Projects

Sixty-five percent of polled respondents claim to be actively involved in an ongoing Sarbanes-Oxley (SOX) project, while 25 percent are said to be planning to initiate a project in the near term, according to a META Group, Inc. survey. The results were based on a recent survey of more than 100 companies regarding their efforts to meet SOX compliance.

While SOX is the major lightning rod for compliance initiatives in the U.S., along with HIPAA and the USA PATRIOT Act, 88 percent of respondents from multinational firms claim SOX projects are managed as global initiatives.

"Because of the required high level of preparation on a global scale, many firms will utilize SOX as a means of improving business efficiency, going beyond what is merely required to comply," said John Van Decker, META Group's lead Sarbanes-Oxley compliance analyst and author of the survey. "We expect company leaders to initiate projects that deploy applications providing visibility/transparency, financial controls and communications and fraud protection."

According to 45 percent of surveyed respondents, CFOs are the most likely leaders to initiate SOX projects, due to their focus on financial management. Internal auditors ranked a distant second (24 percent of respondents). However, an overwhelming majority favor their audit partner for compliance work (59 percent), and this is contrary to META Group's recommendation that a third party be used.

"While this may make the audit attestation process smoother, it limits the multiple views and guidance that may prove invaluable for a relatively new and untested regulatory environment," said Van Decker. "Only 6 percent project that they will use a different audit vendor, and only 3 percent will employ a specialty compliance vendor." META Group also cautions the 29 percent that believe they can do this on their own, again pointing to the relatively untested regulatory environment and the lack of experienced resources (actually none) internally.

2. WHAT ? (BMEWS Data Architecture)

2.1 Implications of the Regulations

Two implications (deceptively simple) :-
1) Transparency
2) Accountability
User Scenarios help to provide insight.


2.2 Meeting the Regulations

This diagram shows the User’s eye view of the Data Architecture.


If the right things are done in the right way, then the right (measurable) results should follow.

Therefore, if Users follow the Best Practice, then their Personal Objectives should be achieved.


Example 1 : Homeland Security and Patriot Act

Enterprise Customer Databases must be matched against Government lists of Suspects.

Example 2 : SOX and CEO of a Public Corporation

The CEO is legally responsible for the integrity of the data in all corporate publications – eg annual reports.

Example 3 : Poisoning the Drinking Water

Federal or State Regulations require measurement of chemicals in the Water Supply :-


2.3 Adding Accountability and Transparency

This diagram shows the Data Architect’s eye view of the Data Architecture –

- adding Accountability and Transparency.


2.4 Adding Enterprise Data Sources

This diagram shows that Enterprise Data Sources can be integrated using a standard approach.

2.5 The Evolution of Business Intelligence  

            1) Gartner has coined the term ‘Business Activity Monitoring’

            Companies need to track business processes-such as order processing, quality

assurance, inventory, logistics, compliance, etc.- in real time, to improve operational efficiency as business events are happening. In order to satisfy real-time business needs.

BI has evolved from Data Warehousing, to Data Marts, and operational data stores to Performance Monitoring Systems based on KPIs. These solutions allow business managers to monitor key operational business events, detect changes or trends and immediately take corrective action - in real time, or as real-time as appropriate.


2.6 The BMEWS Data Architecture

If we expand the Users-eye View of the Data Architecture, we derive this diagram. It shows the major Layers and  Components in the Data Architecture to meet the requirements of the Regulations.





2.7 The BMEWS Data Model



User Layer


MetaData Layer


BI Layer


Base Data Layer


3. WHEN ? (Requirements à Vendors)

Each of the Acts has a timescale.

A number of vendors have produced specific offerings for the Acts.

Different Enterprises will have different requirements, depending on the nature of their business.

Different Enterprises will be in different states of readiness. For example, some may have a Consolidated Customer Data Model. Others may have Portals and User Performance Objectives in place.


Here are some timings :-

3.1 Basel II Accord - Banks must implement by end 2006.
3.2 Homeland Security (US Govt) - First 100 Days  -  inception on
January 24, 2003
3.3 OFAC

3.4 Patriot Act signed into law by President Bush on October 26, 2001.

* penalties up to $1 million, money laundering, (UK in July)

3.5 Sarbanes-Oxley (CPAs) - 23 Oct 03 - 'initiate cut-off process'.
Toward the end of July,2003, Congress passed the Sarbanes-Oxley Act, requiring chief executives and chief financial officers to certify their company's financial statements as fair, accurate and consistent with the provisions of the Security and Exchange Act of 1934.


Two provisions in the law that have yet to take effect may fuel new IT projects.

Section 404, which public companies must begin to comply with by the end of the year, relates to the certification of financial reporting and controls.

Section 409, which doesn't have a clear compliance deadline, calls for companies to report material financial events as they occur, rather than at the end of their financial quarter.


Vendor solutions fall into three Categories:-

a)      Architecture Components- eg  Data Integration Software from Ascential or MetaMatrix.

b)      Compliance Software – SOX 1 from Innovative Systems.

c)       List of ‘Suspects’ – eg Bridger’s Tracker.




Let’s look at how to produce a Plan

Therefore what is required is to produce a Plan, geared to the required End-Point for the Enterprise.

Here are some notes :-

a) Establish which Regulations apply and how.

b) Identify which Vendors offerings apply.

c) Produce a Plan with an acceptable end-date.



4. HOW ? (General Method à Checklist à Specific Plan)

4.1 The BMEWS Method

The deliverables are tailored Data Dictionary, Data Models, Templates and Checklist to monitor progress.

This leads to Data-driven Agile Development,(the subject for another Paper at another time).

These Steps are, of course, Best Practice, and can be set-up using the BMEWS facilities.

The Method can be applied :-

5.1 Bottom-Up staring with the Base Data Layer

5.2 Top-Down, starting with the User Layer,

5.3 Middle-Outwards starting with the MetaData Layer.


The Information Catalog is populated during the application of the Method, and can be used to control and track the work so that progress proceeds to a logical, consistent and complete conclusion.

4.2 Approach

If you want to do it, this is how you do it … (and by the way, you don’t have any choice) …

Conceptual --à Specific Physical --à Integrate with Corporate Data Architecture.

Therefore, you need a CDA !!!

1) Assess your Readiness
2) Gap Analysis
3) Make a Plan to plug the Gaps

3.1 Identify your Requirements

3.2 Evaluate Vendor offerings

3.3 Draw up a detailed Plan.


Patriot Act – signed into Law by Bush in October 26th. 2001.

Requires that “…all domestic financial institutions implement [data] screening policies and establish an independent audit function.

Non-compliance : - Penalties up to $1,000,000

Screening solutions must identify suspect Individuals, Organizations and Transactions.

This requires a common approach to handling Customer information, so that suspect individuals and organizations within your Database can be easily compared against government-provided lists.

These lists can be provided by vendors such as Innovative Systems, and include the OFAC list, the FBI’s Most Wanted and Fugitive List, and the Bureau of Export Administration’s Denied Persons List.

Cleansing detail includes :-

                Names, aliases, name order, etc..

Therefore we are looking for Customer Data Integration solutions.


















4.3 Legislation and Implications













Basel II


Risk Reports










Security – Suspects





Yes (Bridger)
















Oct 2001














Yes (Stellent)





Individuals and Organizations both require matching against Customer Databases.




4.4 Steps in the BMEWS Method




BDL. The Base Data Layer (Bottom-up)

STEP      DESCRIPTION                                                                                    DATA MODELS

These are draft Steps in the Base Data Layer - Data Sources, ERL and Consolidation.

These include specification of the Generic Consolidated Data Model.



BDL.1     Identify the Data Sources.   

BDL.2     Identify the Owners of the Data Sources.         

BDL.3     Choose a Data Feed and create a Schema using Schema Logic,

                (to be confirmed with Carole and Andrei).     

                3.1 Sample Schema for Hotel Bookings


BDL.4     Choose the Generic Consolidated Data Model,(GCDM).

                4.1 DBA Generic Customer Data Model

                4.2 IBM Financial Services Data Model

                  4.3 FTI StreetModel


BDL.5     Map the Data Sources to the GCDM.              

                5.1 Schema Logic

                5.2 ToBeDetermined

                  5.3 ToBeDetermined


6              Choose the Data Warehouse Model.              

                6.1 DBA Financial Star DW

                6.2 DBA Financial Snowflake DW

                6.3 DBA Visits Data Warehouse

                  6.4 IBM Banking Data Warehouse


7              Map the GCDM to the DW.              

                7.1 Schema Logic

                7.2 ToBeDetermined

                  7.3 ToBeDetermined


8              Choose the Data Marts Model.        

                8.1 IBM Banking Data Marts/Templates

                  8.2 Business Objects


9              Map the DW to the Data Marts.      

                9.1 Schema Logic

                  9.2 ToBeDetermined




BI. The BI Layer (Start in the Middle)

STEP      DESCRIPTION                                                                                    DATA MODELS

BIL.1       Define the Data Marts (in InfoCat)

BIL.2       Define Key Performance Indicators (KPIs)                                      KPI Derivation.

BIL.3       Define Available Library of Risk Reports                                        Publish and Subscribe



MDL. The MetaData Layer (Can Begin Here)

STEP      DESCRIPTION                                                                                    DATA MODELS

MDL.1    Set-up Best Practices                                                                          Best Practice Manuals

MDL.2    Define the Business Rules (in InfoCat)

MDL.3    Establish Audit Trail Facilities

MDL.4    Initialize Information Catalog / Data Dictionary                              Data Dictionary



UL. The User/Content Layer (Top-Down)

STEP      DESCRIPTION                                                                                    DATA MODELS

UL.1        Set-up Job Descriptions (Content)

UL.2        Set up Publications (eg Library in InfoCat) (Content)                   FI/KPI Portal Model

UL.3        Create Users                                                                                         Users and Communities

UL.4        Create Communities

UL.5        Create User Job Responsibilities (Content)

UL.6        Register User Subscriptions                                                              Publish and Subscribe

UL.7        Specify Portal Features                                                                       Portal Model

UL.8        Define Data Ownerships and Quality Responsibilities

UL.9        Define User Access Privileges,(eg Query MetaData).





HOW (continued)

Agile Databased Development




4.5 RBW -  Add Data Models and Patterns / Templates


4.5 Analysis of Vendors and Architecture Components

Vendors are listed alphabetically, (MS=Microsoft).











Data Quality


Ascential, Arhenor, Axio, Data Quality.


Query MetaData


Informatica’s SuperGlue.


User Portal

IBM (WebSphere Portal)

MS (Shared Portal)

Oracle (Portal Studio)



Publish & Subscribe

Oracle AQ.



Traffic Lights

MS (Digital Dashboard)

Ergometrics, Informatica’s SuperGlue.






Audit Trail




Best Practice

IBM (Content Manager)



Business Rules


eg Clean-up

Scientio - ,Versata

Info Catalog



OneData, CA-Platinum, Rochade, Schema Logic, SUN MetaDirectory.






Data Marts

IBM (Business Templates) ?

Business Objects




Genie Software -


Risk Reports


Business Objects

Base Data





Data Sources




Mapping (ETL)


Ascential,Informatica,DataJunction, ETI,MetaIntegration, MetaMatrix.



IBM,(Fin Services Data Model).

ADRM(?), FTI (StreetModel), Saphir**
 - Looks good and offers ASP.


Data Warehouse

IBM, (Banking Data Warehouse).







Data Marts


Business Objects


Reference Data


Data Foundations (






4.6 Analysis of Vendors and Legislation





Basel II Accord


Bank of International Settlements,(




Compliance Analyzer -



OFAC Compliance Software -






Bridger, Innovative Systems



Visual Banker -



Fuego - Automating financial controls -

Official SOX Reference Site ( Solution helps with Section 404 compliance.



4.7 Implementation of User Scenarios

This Section discusses how some specific Vendor Products can be used to implement the sample Scenarios.


This diagram shows the User’s eye view of the Data Architecture.

If the right things are done in the right way, then the right (measurable) results should follow.

Therefore, if Users follow the Best Practice, then their Personal Objectives should be achieved.







4.7.1 : Homeland Security and Patriot Act


Enterprise Customer Databases must be matched against Government lists of Suspects The CEO reviews the appropriate Regulations. The CTO the List of Suspects from vendors,(eg Bridger) in compliance with the Homeland and Patriot Acts. The CTO provides background for the list of corporate Customers. The CTO and CEO reviews the list of Customers who appear match the List of Suspects.




4.7.2 : SOX and CEO of a Public Corporation


The CEO is legally responsible for the integrity of the data in all corporate publications – eg annual reports.

Enterprise Customer Databases must be matched against Government lists of Suspects The CEO reviews the appropriate Regulations. The CEO specifies the publications that he/she will review. The CTO provides background for the specified Publications. The CEO drills down to verify transparency of the processes involved in the derivation of the data. The CEO drills down to verify the accuracy of a sample of the  transparency of  the derived data.





4.7.3 : Poisoning the Drinking Water

Federal or State Regulations require measurement of chemicals in the Water Supply :-


The Job Description for the VP Operations includes responsibility for ensuring that the drinking water is of an acceptable quality.

Daily measurements must be checked against specific standards of cleanliness.

This is a bottom-up analysis and monitoring operation. Following his/her Job Description, the Water Engineer takes a daily sample of the Drinking Water. Values are entered into an online Spreadsheet. The values are summarized and automatically compared against KPI Threshold values. If Threshold values are exceeded then the appropriate Traffic Lights change from Green to Red in the Portal Dashboard.. The VP Ops notices the Red Traffic Light and reviews the appropriate Regulations. He/She drills down to the detail and determines the appropriate action. The Occurrence and the Action are logged and automatically included in Progress Report.  





5 WHO ? (Are You Ready ?)

5.1  Readiness Checklist








- Job Descriptions include Objectives



- Job Descriptions include Reports and Documents.



Does Information Catalog exist ?



Have Data Owners been identified ?






Does ‘Single View Data Model’ available ?



Have Risk Reporting Requirements been defined ?



Business Processes defined ?







5.2  Getting Started





Decide format for Information Catalog






- Check Organization Chart






Have Risk Reporting Requirements been defined ?



Business Processes defined ?












Identify Data Sources and Owners



Rationalize and Reconcile Data



Establish Data Quality



Establish Data Profiles






Define ‘Single View Data Model’






Define Data Mapping to Single View Model



Define Data Validation Rules

















