This article is by Errol Rodericks, Product & Solutions Marketing Director at Denodo
For years, people have discussed sovereignty in financial services primarily in terms of geography. Where is the data stored? Which jurisdiction applies? Who operates the infrastructure?
Those questions still matter. But they are no longer enough.
Banks and insurers now operate through an increasingly complex web of cloud providers, SaaS platforms, data ecosystems, third parties, AI models and legacy systems. Modern financial services could not function without these dependencies. The more important question is whether the institution remains in control.
Can it determine where sensitive information is used? Can it understand which critical services depend on which providers? Can it change a platform without rebuilding every data integration? Can it preserve consistent policies and business definitions as information crosses systems? And if a provider, region or legal basis suddenly becomes unavailable, can it continue serving customers within acceptable tolerances?
That leads to a different definition of sovereignty. Sovereignty is not technological self-sufficiency. It is controlled choice.
The objective is not to remove dependency, but to ensure that critical dependency remains deliberate, governed and, where necessary, reversible.
The sovereignty problem is becoming an architecture problem
One of the biggest threats to institutional control is not simply fragmented data. It is fragmented control.
A typical financial institution has authoritative information distributed across core systems, SaaS applications, multiple clouds, data warehouses, lakehouses, APIs and external providers. Over time, integrations multiply, data is copied, pipelines proliferate, policies are implemented differently across platforms, and business definitions diverge.
Each individual decision may appear reasonable. Collectively, they can make the institution increasingly difficult to govern.
The same customer may be represented differently across systems. A masking policy may exist on one copy but not another. An application can become tightly coupled to a provider-specific schema. During an incident, identifying which services, data and customers are affected may require manual reconciliation.
The institution may still own its data and hold contracts with its providers, yet its practical ability to exercise control has diminished.
Risk accumulates at every hand-off through aggregation risk, policy drift, conflicting meaning and exit friction. The sovereignty problem therefore becomes architectural: how do you maintain consistent control across a distributed environment without forcing every workload into the same place?
Geography remains one control. Architecture determines whether that control survives across the wider estate.
From data sovereignty to decision sovereignty
AI makes this question more consequential.
When technology primarily stored and reported information, sovereignty could be discussed largely in terms of data, infrastructure and access. AI consumes information to interpret, recommend and increasingly act.
That introduces another question: who controls the context through which the institution is understood?
Consider a fraud system assessing an unusual international payment. The transaction may genuinely look anomalous, and the model may be functioning perfectly. But perhaps the payment is associated with a corporate Treasury event that has already been authorised.
The data may be correct. The model may be correct. Yet without the relevant business context, the resulting action may still be wrong.
The same issue appears elsewhere in financial services.
A lending decision requires more than a credit score. It may also require current exposure, affordability, product policy and delegated authority. An insurance claim cannot always be understood from the claim record alone: policy conditions, catastrophe events, customer circumstances, fraud indicators, documents and third-party information can all change the appropriate response. An AI customer-service agent may know the customer and product but still need to understand consent, entitlement, jurisdiction and what actions it is authorised to perform.
Sovereignty therefore has to extend beyond controlling where information resides to controlling how it is understood and how that understanding influences decisions.
That is the emerging challenge of decision sovereignty: can the institution reconstruct what information was used, what it meant at that moment, which policies applied, which technology participated, what authority was delegated and why the resulting action occurred?
Institutional understanding should not belong to the model
This creates an important architectural question for enterprise AI.
Financial institutions are unlikely to depend on one AI model forever. They will use combinations of commercial models, specialist models, internally developed models, agents and orchestration technologies. Those technologies will change rapidly.
Institutional understanding should not have to change with them.
If the meaning of “customer exposure”, “vulnerable customer”, “suspicious transaction” or “eligible claim” is embedded independently inside every application, vector store or AI model, changing technology becomes much harder. Part of the institution’s business understanding has effectively become coupled to the technology consuming it.
A more sovereign architecture separates the two.
Authoritative enterprise sources remain authoritative. A governed information and semantic layer can provide approved views, business definitions, relationships, lineage, access policies and current operational context. Applications, analytics and AI can then consume that governed context rather than reconstructing institutional meaning independently.
This leads to an important principle for AI-era sovereignty: Models should be replaceable. Institutional understanding should not be.
The architecture in the underlying briefing makes this separation precise: enterprise sources remain authoritative and policy-bound, governed semantic context sits between those sources and AI, and model selection remains a separate policy decision.
Sovereignty does not mean zero-copy
The same nuance applies to data movement.
It is tempting to equate sovereignty with never moving data. But that is neither practical nor always desirable. Some workloads require persistent history. Others need caching for performance or continuity. Some analytical workloads suit physical data platforms better.
The better question is whether movement is a governed decision rather than an integration default.
Can a query run against the authoritative source when appropriate? If information must be cached, can the institution control where that cache resides, how long it persists and how it is protected? If a physical copy is required, is its purpose explicit and are retention, deletion and access obligations preserved?
Live federated access, controlled caching and physical pipelines can all be legitimate patterns. The appropriate choice depends on sensitivity, lawful location, freshness and latency requirements, source capacity, continuity requirements and economics.
The principle is not “copy nothing.” Do not make another copy the automatic price of using information.
Policy must survive consumption
Control can also disappear between policy definition and actual use.
An institution may have strong privacy, security and conduct policies, but if those controls are implemented differently across copies, applications and channels, policy is no longer consistently authoritative. The risk grows when information is dynamically assembled for analytics or AI.
A stronger architectural approach brings together identity context, approved semantic views, fine-grained controls and source-native permissions at the point information is accessed. As the briefing argues, policy is strongest when business meaning, access context and source controls agree.
That does not mean technology determines policy. Legal, compliance, risk and business functions still decide what is permissible.
Technology’s role is to make those decisions enforceable and evidenced when information is actually used.

Exit clauses are not the same as exit capability
Another uncomfortable aspect of sovereignty is something financial institutions increasingly need to confront.
A contract may contain excellent portability and termination provisions. That does not mean the institution can actually leave.
Applications may depend on proprietary schemas. Pipelines may embed provider-specific logic. Business definitions may exist only inside a platform. Identities, caches, networks and operational processes may all be intertwined with the provider.
True reversibility therefore requires more than contractual rights. It requires stable interfaces, reusable semantics, visibility of dependencies, replacement patterns and, critically, rehearsal.
As the briefing puts it, exit is a capability only after rehearsal. Contracts are necessary, but measured execution determines whether portability is real.
That gives boards a more useful question.
Do not ask only, “Do we have an exit clause?”
Ask, “When did we last prove that we could exercise it?”
Controlled interoperability is the alternative to isolation
None of this means financial institutions should retreat from cloud, SaaS, external data, ecosystem partnerships or AI.
Quite the opposite. Greater control can enable greater openness.
A bank that knows where its information comes from, understands how it is being used, can enforce access policies consistently, preserves its own business semantics and can change consuming technology is in a stronger position to collaborate.
This is why the future of sovereignty is not technological isolation. It is controlled interoperability.
Institutions should be able to connect what they need without surrendering control of what they own.
That requires infrastructure controls, identity and cryptographic controls, cybersecurity, model governance, contractual protections, operational resilience, human authority and accountable business ownership. No data platform replaces those responsibilities.
A logical data and context layer can, however, address an important part of the problem: keeping distributed information connected, governed and understandable without requiring every consumer to create another proprietary representation of the institution.
The board question is changing
Financial-services sovereignty should ultimately be judged not by where a server is located or by a provider’s nationality, but by the institution’s ability to exercise control when conditions change.
Can it identify critical dependencies? Can it govern sensitive information wherever it is legitimately used? Can it preserve its business definitions and institutional context? Can it change providers, platforms or AI models without reconstructing its information environment? Can it continue operating when a dependency fails? And when an automated decision has consequences for a customer, can it explain what happened and remain accountable for the outcome?
Those questions turn sovereignty from a political or technological abstraction into an operational capability.
Financial institutions will remain interdependent. They will continue to rely on global cloud providers, SaaS platforms, data ecosystems, and rapidly changing AI technologies. The objective is not independence from them, but ensuring dependency never quietly becomes a loss of control. That requires an architecture in which authoritative data can remain governed, institutional meaning can remain consistent, and applications, platforms and AI models can change without forcing the organisation to reconstruct its trusted information environment each time.
This is where a governed logical data and context layer plays an increasingly important role. By connecting distributed information without making another central copy the default, preserving semantics and lineage, enforcing governance at the point of access, and making trusted business context reusable across applications and AI, financial institutions can preserve control while continuing to innovate.
They do not make an institution sovereign. Infrastructure, security, governance, resilience and accountable business authority remain essential. But by helping separate institutional data and understanding from the technologies that happen to consume them today, they can help preserve something increasingly valuable as those technologies change: control of the institution’s data and understanding remains with the institution.

Be the first to comment