Compliance & Regulation
Updated
September 7, 2026

Data Integrity in Regulated Finance: Why Records Fail Review and What It Costs

Data integrity means a record can show who created it, when it existed and whether it changed. What the gap costs in audits, disputes and deals.

Data Integrity in Regulated Finance: Why Records Fail Review and What It Costs
In short
Data integrity means a record can show who created it, when it existed in its current form, and whether it changed since. In regulated finance it applies to the supporting records behind valuations, NAV reports, approvals and regulatory filings.

Regulated firms store records well and prove them badly. Storage systems describe what happened inside their own boundary, while a reviewer asks the question from outside it. This article, part of our guide to audit-ready records, sets out where that gap opens, what EU rules already require, what the gap costs in audits, disputes and deals, and how to close it without replacing existing systems.

What is data integrity in regulated finance?

Data integrity is the property that lets a record be relied on by someone who was not there when it was made. It has three parts: attribution (which identity created or approved this), existence (when this content existed in this exact form), and change history (whether anything was altered afterwards, and by whom).

That is narrower than the word means in IT, where data integrity often describes referential consistency in a database, and it is different from data quality. A NAV report can be accurate and still have no integrity, because accuracy is a statement about the number and integrity is a statement about the record. Poor data integrity is not wrong data. It is data that exists, may well be correct, and cannot be checked by anyone outside the system that holds it.

The records management standard ISO 15489-1 names the same idea from the other direction. It calls an authoritative record one that is authentic, reliable, usable, and has integrity: you can tell what it is, who made it, and that it has not been changed without that change being visible.

Why regulated finance has a data integrity problem

Ask a compliance officer whether the firm stores its data securely and the answer is yes. Ask whether the firm can show, for one record from fourteen months ago, who created it, who approved it and whether it was altered, and the answer becomes a project.

This is not a failure of intent. It is a failure of infrastructure. ERP systems, cloud databases and document management tools were built to store and retrieve. Their timestamps are internal. Their access logs are administered by the same people whose work the logs are being used to validate. Their version histories belong to whoever administers the platform. In a review, the firm is presenting what its own system says about its own data.

Auditors already grade evidence this way. The application material of ISA 500 states that the reliability of audit evidence increases when it is obtained from independent sources outside the entity, that internally generated evidence is only as reliable as the controls around it, and that original documents are more reliable than photocopies. Records exported from a system the firm administers sit at the weak end of that scale by construction. Nobody is accusing anyone of anything. The reviewer simply has no way to separate the record from the firm's word about the record.

The three questions a reviewer is actually asking

Under every audit request, dispute letter and due diligence questionnaire are the same three questions.

Who created this? Not which system logged it. Which identity, meaning a named person or an authorized entity, committed to this content. In regulated markets accountability is personal. Systems do not sign off on valuations.

When did it exist in this exact form? Not when it was uploaded, and not when a system wrote a row. When this precise content demonstrably existed, in a way a third party can check without access to the system that produced it.

Has it changed since? Not whether anything was flagged as changed. Whether any alteration would itself become a visible, attributed, timestamped event, with the earlier state still available.

If the honest answer to any of the three is "it depends who you ask", the gap is open, and it is open for every record in the workflow, not just the one being questioned.

What EU rules already require

The idea that a record must be checkable from outside is not new, and it did not arrive with blockchain. It is written into rules that regulated firms have been living with for years. The following is a summary of published requirements, not legal advice; the applicable obligations depend on the firm's licence and activities.

MiFID II record keeping. Commission Delegated Regulation (EU) 2017/565, Article 72(1), tells investment firms how records must be retained: in a medium that lets a competent authority reconstitute each key stage of the processing of each transaction, in which "any corrections or other amendments, and the contents of the records prior to such corrections or amendments, [can] be easily ascertained", and in which "it is not possible for the records otherwise to be manipulated or altered". The rule has applied since January 2018. It describes a tamper-evident record with a preserved change history, in the plainest possible terms, and it says nothing about which technology delivers it.

DORA. The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied since 17 January 2025. Article 17(2) requires financial entities to record all ICT-related incidents and significant cyber threats; Article 17(3)(b) requires procedures to identify, track, log, categorise and classify them. The obligation is to produce a trail that holds up when a supervisor follows it, which is a different exercise from having logs.

MiCA. Article 68(9) of Regulation (EU) 2023/1114 requires crypto-asset service providers to keep records of all services, activities, orders and transactions for five years, extendable to seven if a competent authority asks before the five years are up. Delegated Regulation (EU) 2025/1140, in force since 30 June 2025, sets out what those records must contain. A five to seven year duty outlives most system migrations, which is the practical reason integrity has to be a property of the record rather than of the platform currently holding it.

The Travel Rule. Regulation (EU) 2023/1113 has applied since 30 December 2024 and requires originator and beneficiary information to accompany transfers of crypto-assets. One detail is worth correcting, because it is widely repeated: in the EU there is no de minimis threshold for crypto-asset transfers between providers. The €1,000 figure people cite is the point above which a provider must verify that a customer actually controls a self-hosted wallet. The regulation is replaced by the EU anti-money laundering package from 10 July 2027, so firms building for it should build for the record, not for the current article numbering.

Four instruments, four vocabularies, one requirement: the record has to survive examination by someone who does not have to take the firm's word for anything.

Where the cost accumulates

The cost of poor data integrity is rarely a single event. It is a drag that shows up in four predictable places.

Audit preparation. The recurring pattern in our conversations with compliance and fund administration teams is reconstruction: reconciling timestamps across systems, finding who approved what and when, and assembling a history out of email threads, document versions and system logs that were never designed to be an audit trail. The audit slows down not because the data is wrong, but because the data cannot speak for itself.

Dispute resolution. When a counterparty contests a NAV figure, a valuation date or the version of a document that applied at a decision point, the burden of proof falls on whoever is making the claim. Without an attributed, timestamped record of the state of the data at that moment, the dispute moves from evidence to legal process, where duration is the main cost driver and the better documented party has the advantage over the party that is right.

Regulatory friction. A review that closes on the first round of questions costs one amount. A review that turns into repeated document requests, then into a formal finding, costs several multiples of it in direct expense, management attention and supervisory relationship.

Deal friction. In tokenization and private credit, due diligence on the data behind an asset has become more sophisticated. A counterparty who cannot independently check the integrity of the supporting records will either price the uncertainty or step back. At that point poor data integrity has stopped being an operations problem and has become a valuation problem.

Stored, and audit-ready: what a reviewer can actually check

The reviewer's questionWhat a stored record showsWhat an audit-ready record shows
Who created this?A user ID inside a system the firm administersA signature tied to a key held by the responsible party
When did it exist in this form?A timestamp an administrator can changeA timestamp recorded independently of that system
Has it changed since?A version history in the same systemA history in which a change adds an entry and any alteration is detectable
Can a third party check it without us?No, not without access to the systemYes, from the record's integrity data alone

Common mistakes

Treating retention as integrity. Five or seven years of retention answers where the record is, not whether it is the one that was signed. Most firms pass the retention test and fail the integrity test.

Sending copies. A PDF sent by email is a second version with no relationship to the first. Auditing standards already rank an original above a copy. Sharing access to a record, rather than a duplicate of it, keeps that distinction intact.

Keeping the proof in the same place as the file. If the recorded fingerprint of a document sits in a folder the same administrator controls, the reviewer is back to trusting that administrator. Integrity information has to be checkable somewhere the firm does not control.

Over-claiming. "Immutable", "tamper-proof" and "audit-proof" invite one question: proven by whom. Tamper-evident is the accurate word. It means a change becomes detectable, not that a file cannot be changed.

Where Filedgr fits

Filedgr is verification infrastructure for critical records. It does not replace the systems a firm already runs, and it does not require a migration project. It adds the layer those systems were never built to provide: records are captured with their context, governed with permissions per recipient, and preserved with the signature, timestamp and append-only history that make integrity demonstrable (Capture. Control. Prove.).

For records that have to leave your systems, Proof Packages carry the integrity information with the file, so a recipient can check it outside Filedgr. For asset and fund records specifically, Filedgr AssetID applies the same approach to NAV data, documents and corporate actions. Since June 2026, the public Filedgr Explorer lets a third party check a record's signature and its blockchain transaction without a Filedgr account and without seeing the content behind it.

Filedgr does not decide whether a record satisfies a regulation, does not calculate or audit values, and does not replace an audit. It supports compliance evidence, review and reporting workflows by keeping the supporting record attributable, controlled and verifiable.

Review controls → Controlled Data Management

Get started today

Stay ahead of audits and evolving regulations with verified integrity.
Get in touch to learn more.

Frequently asked questions

What is data integrity in regulated finance?

Data integrity means a record can show which identity created it, when the content existed in its current form, and whether it changed afterwards. It describes whether a record can be relied on by an outside reviewer, not whether the figures in it are correct.

Is data integrity the same as data quality?

No. Data quality describes whether the content is accurate, complete and current. Data integrity describes whether the record can be attributed, dated and shown to be unchanged. A report can be accurate and still fail an integrity check, and a record can have integrity and contain an error.

Does EU law require tamper-evident records?

In substance, parts of it do. Delegated Regulation (EU) 2017/565, Article 72(1), requires investment firm records to be kept so that corrections and their prior contents can be easily ascertained and the records cannot otherwise be manipulated or altered. It does not name a technology.

Does the EU Travel Rule only apply above €1,000?

No. Regulation (EU) 2023/1113 applies to transfers of crypto-assets with no de minimis threshold. The €1,000 figure is the point above which a provider must verify that a customer controls a self-hosted wallet. The rule is replaced by the EU anti-money laundering package from 10 July 2027.

Kim Dinse

Kim Dinse

Kim is a B2B marketing strategist with a background in business economics and over five years of experience. As CMO of Filedgr, she drives brand growth around verifiable data infrastructure, with a focus on tokenized assets and financial data.