What we do · Governance framework
The rulebook the operating model
executes against.
The rules-and-controls layer that sits above the operating model. Policies, a control library, committee charters, standing agendas, and the documentation cadence that keeps every market-data decision defensible under audit and internal review. The artifact that outlives the org chart.
The controls problem
Why the controls are not there when the letter arrives.
-
Policy by precedent
Most firms have a market data policy in the sense that things have been done a certain way. Few have one an auditor or an internal reviewer can read, and fewer have a control that proves it was followed.
-
No standing forum
Renewals, audit responses, and new-feed requests are decided in whatever meeting they land in. Without a committee with a charter and an agenda, decisions have no record and no consistency.
-
Controls that live in one person
The person who knows how the vendor portal maps to the ledger is the control. When they leave, so does it.
-
Documentation as an afterthought
The evidence an audit asks for exists, scattered across email, spreadsheets, and portals. A cadence that produces it as a by-product of the work is the difference between a week and a quarter.
The methodology
Four steps to a defensible rulebook.
- 01
Obligation register
Every regulatory, contractual, and vendor obligation the firm carries for market data, in one register.
- Vendor and exchange license obligations by agreement
- Regulatory adjacency: MiFID II, GDPR, record-keeping
- Internal audit and risk requirements
- AI and machine-consumer use obligations
- 02
Policy and control library
Policies written to be followed; controls written to be tested. Each control maps to an obligation and an owner.
- Market data policy, plain and short
- Control library mapped to regulatory and vendor obligations
- Entitlement, approval, and renewal controls
- Evidence requirements defined per control
- 03
Committee and cadence
A market data committee with a charter, a standing agenda, and a reporting rhythm that produces the evidence as it goes.
- Committee charter and membership across finance, operations, compliance, and procurement
- Standing agenda: renewals, audits, exceptions, spend
- Procurement calendar and renewal sequencing
- Documentation and reporting cadence
- 04
Test and embed
Controls tested, gaps closed, and the framework handed to the operating model to run.
- First-cycle control testing
- Exception and remediation process
- Long-term prevention of spend creep
- Handover with a review after the first audit or renewal
What the work produces
Defensible under audit and internal review.
- Durable
Survives turnover
The framework is the artifact that outlives the org chart and the people who wrote it.
- Mapped
Every control to an obligation
Nothing in the library exists without a reason a reviewer can read.
- Standing
Committee and calendar
Decisions made in one forum with a record, on a cadence the renewal calendar drives.
- Ready
Evidence on demand
The documentation an audit or internal review asks for exists as a by-product of the work.
Who we work with
Who asks for the rulebook.
-
Heads of compliance and risk
Audit risk and regulatory adjacency, with a defensible file, a documented process, and an exposure number with evidence behind it.
-
COOs and chief data officers
Where the function lives, who owns it, and how its decisions are recorded, as part of a broader data governance program.
-
Firms after an audit finding
A repeat finding is the most expensive kind. The framework is what prevents it.
Questions we get asked
Six questions, answered before the internal review.
-
What does a market data governance framework contain?
An obligation register, a market data policy, a control library mapped to those obligations, a committee charter with a standing agenda, a procurement and renewal calendar, and a documentation cadence. Together they make every market data decision defensible under vendor audit and internal review.
-
How does this relate to the operating model?
The operating model is who does the work and on which system; the framework is the rules and controls they follow. The framework is designed after, or alongside, the operating model so that every control has a process to live in.
-
Is this only relevant to regulated firms?
No. The heaviest obligations most firms carry for market data are contractual, from vendor and exchange licenses, not regulatory. Every firm that licenses data has them; regulated firms carry additional record-keeping and data-protection obligations on top.
-
How much documentation is this going to create?
Less than you fear. The policy is short, controls are one page each, and the committee record is the agenda and its decisions. The point is that evidence is produced as a by-product of normal work, not as a project when a letter arrives.
-
Does this cover AI use of market data?
Yes. Obligations for model inference, agent tools, and machine-consumer distribution are added to the register, and approval and entitlement controls are extended to applications, not only people.
-
Who should sit on the market data committee?
Finance, operations, compliance or risk, procurement, and the head of market data where one exists, with technology and the front office represented as needed. The charter sets membership, quorum, and decision rights.