
The banks that will define the next decade will not be built by AI models alone, but on trusted, well-governed data. As financial institutions accelerate AI adoption, data architecture, governance, and quality are becoming strategic priorities. IBS Intelligence spoke with Ruqsana Nuruddin, Head of Data Analytics and Product (Financial Crime & Fraud) at Barclays, who draws on more than 22 years of experience in financial services technology to share her insights on data products, AI governance, financial crime, and what it takes to build a future-ready data foundation.
How are data products reshaping the way financial institutions manage enterprise-wide risk, governance, and decision-making?
Here is what most people get wrong about data products in banking — they think it is a technology story. It is not. It is a trust story.
For decades, risk and governance functions in banks operated on data they could not fully trust. Numbers were reconciled the night before board meetings. In financial crime — where I have spent a significant part of my career — the consequences are even starker. A missed SAR. A sanctions breach. Regulatory censure. The stakes reframe everything. Data products change the fundamental contract between data and the business. They are not datasets or reports or dashboards. They are self-contained, accountable units of data — with defined semantics, measurable quality, clear ownership, and published lineage. When a financial crime analyst makes a decision to file or dismiss a suspicious activity, the data underneath that decision must be unambiguous and defensible — not reconciled the night before a regulator asks.
The institutions furthest ahead have stopped treating data as a by-product of operations and started treating it as a product in its own right — designed, managed, and measured with the same rigour they apply to any customer-facing capability.
What are the key ingredients for building scalable data products that deliver measurable business value while supporting strong governance and regulatory compliance?
I always come back to three things: domain ownership, quality transparency, and product discipline.
Domain ownership means the team closest to the data — in financial crime, the transaction monitoring function, the screening team, the compliance desk — owns and publishes their data products. Not a central IT team that does not understand the business context. The people who understand what an alert means in transaction monitoring are the people who should define it, certify it, and be accountable for it. Semantic precision is not a technical detail. It is the difference between a productive investigation and a false positive that wastes an analyst’s morning.
Quality transparency means making data quality visible at the point of consumption — live completeness scores, freshness timestamps, lineage trails — not buried in a catalogue that nobody reads. When a screening analyst can see that the sanctions list was refreshed four hours ago and is 99.8% reconciled against source, they act with confidence. When they see a static approved stamp from six months ago, they reach for the workaround.
Governance becomes a feature of the product, not a process imposed on top of it. That is the shift that makes compliance sustainable rather than performative.
Product discipline means treating each data product like an internal product — with a roadmap, adoption metrics, a named owner, and a deprecation cycle. In my experience, the absence of this discipline is why institutions keep rebuilding the same capabilities every three years — because nobody owned them well enough to maintain them.
As AI adoption accelerates across banking, how can organisations ensure their data foundations are trusted, governed, and capable of delivering reliable outcomes?
The honest answer is that most banks are not ready — and the gap is wider than they think.
An AI model is only as reliable as the data it consumes. But agentic AI — systems that reason, act, and iterate autonomously across multiple steps — creates a fundamentally different demand on data infrastructure than a dashboard or a predictive model. I explore this in depth in a forthcoming piece on why agentic AI in banking fails not at the model layer but at the data layer.
An AI agent processing transaction alerts at scale will not pause to question whether the customer definition in System A matches the one in System B. It will propagate the error across thousands of decisions before a human catches it. The tolerance for ambiguity in data drops to near zero when AI agents are in the loop. Agent-ready data needs semantically complete definitions, continuous quality guarantees at the interface, and immutable lineage that makes every AI decision auditable from output back to raw source.
Regulators across the UK and EU are already signalling that AI explainability in financial services is non-negotiable. That explainability is built in the data product layer — not in the model.
How do you see analytics transforming the role of Group Controls, particularly as organisations shift from reactive monitoring to predictive and data-driven risk management?
The controls function has historically been the last to receive good data and the first to be blamed when something goes wrong. That paradox is being addressed — and analytics is the mechanism.
The shift from reactive to predictive is not primarily a modelling challenge. The models exist. The challenge is getting controls functions access to clean, consistent, timely data they can act on before an issue crystallises — rather than after it appears in a report. In transaction monitoring, this means surfacing emerging behavioural signals before a suspicious pattern completes. In screening, it means detecting anomalies in real time rather than discovering a stale match in the next quarterly review.
The controls function of the future is not a gatekeeper. It is a forward-looking intelligence capability — and data products are the foundation it needs to operate at that level.
The investment required is rarely in more sophisticated models. It is in making the underlying data trusted, defined, and accessible in real time. Get that right, and the analytical capability follows naturally. Get it wrong, and even the most advanced models produce outputs that nobody acts on — and ignored outputs are the most dangerous kind.
What are the biggest challenges in creating consistent, high-quality data products across global banking operations, and how can institutions balance standardisation with local regulatory requirements?
This tension sits at the heart of every global bank’s data strategy — and most institutions resolve it badly, in one of two directions.
Over-standardisation produces a global data model that satisfies nobody — too rigid to accommodate genuine jurisdictional differences. What beneficial owner means for AML purposes in one market is not what it means in another. Fragmentation produces regional silos that make group-level risk aggregation impossible. Neither is acceptable.
The resolution is a layered architecture — canonical definitions at the group level, with domain-level data products that interpret those definitions for local regulatory context. A Name Screening alert means the same thing at the group level. The regulatory obligation that attaches to it in the UK, EU, or APAC is local — and should be expressed locally, within a globally consistent structure.
Standardisation and local compliance are not in opposition. The institutions that understand this build data products that are globally coherent in semantics and locally precise in implementation.
As Barclays continues to strengthen its data and analytics capabilities within Group Controls, what strategic investments and capabilities do you believe will be most critical in building more intelligent and future-ready control functions?
Three things stand out — not as aspirations, but as concrete investment priorities drawn from direct experience.
Having been part of the transformation of Transaction Monitoring and Name Screening within Barclays Group Controls — moving from fragmented, siloed systems toward an integrated financial crime platform where data flows consistently across detection, investigation, and reporting — I can say with conviction where the real leverage lies.
First: integrated data over integrated tools. The temptation is to buy a platform that promises to unify everything. The reality is that integration begins with data — consistent definitions of customers, transactions, counterparties, and alerts across every system that touches financial crime. Without that foundation, no platform delivers on its promise.
Second: real-time quality intelligence embedded in the workflow. In screening, a stale sanctions list is not an inconvenience — it is a compliance failure. Continuous, visible data quality monitoring at every step of the financial crime lifecycle is not optional infrastructure. It is the control itself.
Third — and most underrated: the human capability to own data products. Technology without ownership degrades. The most critical investment is in people who sit at the intersection of financial crime expertise and data product management. Not technologists who learn the domain. Domain experts who learn to own their data.
The future-ready controls function is not defined by the sophistication of its models. It is defined by the reliability of its data — and the discipline with which that data is treated as a strategic asset, governed with the same rigour as capital, liquidity, or conduct risk.
The institutions that build that foundation first will not just be more compliant. They will be more intelligent.