Cases/04 · Data trust

Top-tier Nordic banks.Customer definition reconciliation and PSD2 alignment.

Banking·Regulatory and compliance·Enterprise architecture·Practitioner: Lars·Named on request

Two engagements at top-tier Nordic banks. The same practitioner, the same underlying capability, two different angles on the same problem: when an organisation can't trust its own information, large decisions get made on the wrong version of reality.

The first engagement: a top-tier Nordic bank with no shared definition of 'customer.' Legal, compliance, internal audit, and technology each used their own criteria — defensible in isolation, irreconcilable in aggregate. Regulatory reporting that couldn't be tied out. Customer-level analytics nobody trusted. Decisions distorted by whichever definition surfaced first.

The second engagement: a Northern European bank facing PSD2alignment across a complex legacy payments estate, with PCI-DSSexposure throughout. The kind of work that normally fragments across three teams — compliance, process, architecture — each with its own vendors and its own opinion, with the bank at risk of paying twice for parallel workstreams that wouldn't meet at the end.

Customer reconciliation. Four departments, four definitions of the same entity. The cost of misalignment was compounding silently — regulatory reports that didn't reconcile, customer economics that couldn't be steered, decisions made on whichever number came up first. The organisation didn't need another report; it needed a single answer the four departments could all defend.

PSD2 alignment. The compliance trajectory needed to land cleanly across legal, technology, and operations — without three parallel programmes producing contradictory plans. The estate was complex, the regulatory clock was ticking, and the executive needed a single trajectory it could act on rather than a binder full of expert opinions.

For the customer-definition engagement, BPMNprocess mapping was applied with data-entity reconciliation across systems. The work used a three-level enterprise architecturelens — conceptual, logical, physical — to expose where the same entity lived differently in different parts of the business. Cross-departmental working sessions reconciled the definitions, and a single signed-off customer-population breakdown was produced — agreed by compliance, legal, internal audit, and technology together.

For the PSD2 engagement, a top-to-bottom review was carried out across business, logical, and physical architectural layers. Processes were mapped against PSD2 and PCI-DSS in BPMN. A remediation roadmap was produced, prioritised by regulatory risk and commercial impact. PRINCE2 governance held the work together, with hands-on architectural specification anchoring the deliverables.

A single signed-off customer-population breakdown, agreed by compliance, legal, internal audit, and technology.

Regulatory reporting unblocked; customer-level economics — until then unreliable — became usable as a steering instrument.

A single coherent PSD2 plan the executive could act on directly — not one plan for compliance and a different one for engineering.

Fragmented expert opinions consolidated into defendable single trajectories.

Lars — Enterprise architecture, Data governance, Regulatory alignment, BPMN, PSD2 / PCI-DSS.

This case maps to 'We're making decisions on information we don't fully trust'. Both engagements are versions of the same problem: a senior stakeholder needs a single defendable answer in a domain where four different professional perspectives are each producing their own. The work is the third independent read that boards and CEOs commission when they suspect they're being told different versions of the truth by different parts of the organisation. The engagements combined Analysis (the structured architectural and process review) with Implementation (the remediation work, governance, and hands-on architectural specification).