Deep TrustGovernance Series

Governance that holds up under pressure.

175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.

DTG-267 · Cross-Border Data · 10 min

Regulatory Obligations Vary. Systems Do Not Adapt

Global enterprises operate under different regulatory obligations in different jurisdictions. Their systems were built for efficiency, not jurisdictional differentiation.

DTG-266 · Cross-Border Data · 8 min

Cross-Border Incident Response Is Slower Than Risk Propagation

Security incidents in cross-border data environments do not wait for regulatory notification timelines, governance approval chains, or the coordination complexity of mult…

DTG-264 · Cross-Border Data · 10 min

Data Is Stored in One Region. It Is Processed Everywhere

Data residency controls where data rests. It does not control where data is processed, accessed, or analyzed. In cloud architectures, processing routinely occurs across r…

DTG-263 · Cross-Border Data · 9 min

Encryption Protects Data. It Does Not Address Jurisdictional Exposure

Encryption is a technically effective data protection control. It prevents unauthorized access to data in transit and at rest. It does not prevent authorized access, incl…

DTG-262 · Cross-Border Data · 10 min

Data Flows Through Vendors Faster Than Governance Can Track

Your data governance program maps the flows you know about. Vendor ecosystems create flows you did not design, did not authorize, and may not know exist.

DTG-258 · Cross-Border Data · 10 min

Subprocessor Chains Extend Beyond Organizational Visibility

You contracted with a vendor. You reviewed their DPA. You confirmed their security certifications. What you did not do is follow your data through the subprocessors they…

DTG-256 · Cross-Border Data · 11 min

Data Sovereignty Conflicts with Distributed Systems by Design

Data sovereignty requires that data stay within a defined jurisdiction. Distributed systems are architecturally designed to move data across boundaries for resilience, pe…

DTG-255 · Cross-Border Data · 8 min

Data Localization Strategies Break Under Cloud Architectures

Data localization requires that data stay within defined geographic boundaries. Cloud architectures are designed to distribute data across boundaries for performance, ava…

DTG-254 · Cross-Border Data · 10 min

SCCs Provide Legal Cover. Not Operational Control

Standard Contractual Clauses create a legal framework for cross-border data transfers. They do not create operational controls that constrain what happens to data after i…

DTG-252 · Cross-Border Data · 8 min

Cross-Border Data Flows Exist. Even When You Think They Do Not

Organizations document the cross-border data flows they know about. The flows they do not know about are determined by how their technology architecture actually behaves.

DTG-251 · Cross-Border Data · 10 min

Data Residency Is Defined. Data Movement Ignores It

Data residency defines where data should be. Data movement defines where data goes. In modern enterprise architectures, these two things are frequently different, and the…

DTG-240 · AI Governance · 11 min

AI Governance Depends on Data Governance That Does Not Exist

Every AI governance requirement that references data, training data quality, data minimization, purpose limitation, data subject rights, data lineage, assumes the existen…

DTG-238 · AI Governance · 7 min

Change Management Exists. AI Evolution Outpaces It

Traditional change management was designed for discrete, intentional changes: a software release, a configuration update. AI systems change in ways that are gradual, emer…

DTG-237 · AI Governance · 10 min

Model Development Is Controlled. Deployment Introduces New Risk

AI model development is governed by the best process discipline in most organizations: version control, testing, review, documentation, approval.

DTG-230 · AI Governance · 8 min

AI Governance Must Extend Beyond Regulatory Scope

Regulatory frameworks govern the AI systems that fall within their explicit scope. What these frameworks do not govern is the full range of AI capabilities that create or…

DTG-229 · GRC & Control Reality · 7 min

Compliance Is Point-in-Time. Risk Is Continuous

Every compliance assessment produces a result that was accurate when it was produced. The environment that assessment described has continued changing from the moment it…

DTG-225 · AI Governance · 7 min

Post-Market Monitoring Is Required. It Is Not Continuous

Article 72 of the EU AI Act requires deployers of high-risk AI systems to implement post-market monitoring. Most organizations have interpreted this as establishing a mon…

DTG-222 · AI Governance · 10 min

Traceability Is Required. Systems Are Not Built for It

Every AI governance framework that addresses accountability requires traceability: the ability to follow a decision back through the system that made it, to the data that…

DTG-218 · AI Governance · 7 min

Bias Mitigation Is Required. Measurement Is Inconsistent

Every AI governance framework that addresses bias requires that it be detected and mitigated. What no framework specifies is which measurement methodology constitutes ade…

DTG-217 · AI Governance · 11 min

Training Data Quality Is Assumed. It Is Not Verified

The quality of an AI model's output is bounded by the quality of the data it learned from. Organizations that deploy AI systems without verifying the quality of their tra…

DTG-215 · AI Governance · 8 min

Oversight Mechanisms Fail in Automated Workflows

Human oversight was designed to review AI outputs before they produce consequences. Automated workflows execute AI outputs immediately, at machine speed, connecting AI re…

DTG-212 · AI Governance · 8 min

Oversight Exists. Humans Don't Intervene in Practice

Human oversight of AI systems is required by virtually every AI governance framework. Organizations implement it through review queues, exception processes, and human-in-…

DTG-211 · AI Governance · 10 min

Human Oversight Is Mandated. It Is Not Enforceable at Scale

Regulators require that humans remain in control of consequential AI decisions. Operational reality requires that AI systems process thousands of decisions per hour.

DTG-209 · AI Governance · 11 min

AI Outputs Are Visible. Decision Logic Is Not

The output of an AI system is what the system produced. The decision logic is why it produced it. These are not the same thing. Governance that evaluates outputs without…

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center