From fragmented controls to scalable regulatory data quality

Introduction

Degroof Petercam is a Belgian investment house and private bank with deep roots in wealth management. Since 2024, it operates as part of Indosuez Wealth Management, the global wealth arm of Crédit Agricole Group. That integration created an immediate compliance pressure: the group needed a unified, scalable data quality framework across multiple entities... and fast.

Client

Degroof Petercam

Client since

2021

Technologies

No items found.

The problem

BCBS239 demands that banks know exactly where their risk data comes from and how reliable it is. For Degroof Petercam's CDO department, that meant building a data quality framework across nine or more group entities. Each with its own data, its own reporting requirements, and its own compliance obligations. The naive path was duplication: copy the same quality rules for every entity. That approach would have buried the development team in maintenance overhead and produced a fragile setup that broke every time something changed.

How we solved it

Design a segmented quality scoring field

DTA created a dedicated field within the data quality assets to store segmented quality scores based on a single discriminant variable — country, entity, date, or any other filter the business needs. The field follows a standardised format so it stays easy to maintain and works across any use case, not just the one it was first built for.

Build a reusable rule workflow

Rather than treating each quality rule as a one-off build, DTA designed a single workflow that all other rules can use. The underlying scoring functions were extracted, normalised, and published as global functions. Any new rule can call them directly — no duplication, no drift between entities.

Extend the framework to cover incoming RDARR data

With the initial architecture in place, DTA applied the same approach to new data flows arriving under RDARR guidelines. Because the framework was built for reuse, onboarding new data sources required no structural changes, just configuration.

The results

Building a scalable data quality framework across nine entities is not a technical exercise, it's an architectural one. Here's what that difference delivered.

Hundreds of quality rules implemented once, running across 9+ entities

Instead of duplicating every control per entity, DTA implemented each rule a single time. The segmentation logic handles the rest. That means less maintenance, fewer errors, and a development team that isn't spending its time on repetitive work.

Unified dashboard with entity-level and group-level views

The CDO department now runs all quality review meetings and remediation plans from a single dashboard. Scores are adapted per entity where needed, and the group-level view gives Crédit Agricole the consolidated picture it requires.

Framework ready for RDARR without rework

The architecture DTA built for BCBS239 was directly reusable for incoming RDARR obligations. The group gains a compliance foundation that extends — not a point solution that expires.

Key Learnings

Every project leaves you with things you'd do the same and things you'd do differently. These are the ones worth passing on.

No duplication

Mergers and acquisitions don't require duplicating everything. Before reaching for copy-paste, take the time to ask whether the existing setup can be adapted. In most cases, it can, and the result is more maintainable than what you started with.

Investing time

Upfront in a reusable workflow pays off faster than expected. The instinct on a tight deadline is to solve the immediate problem. The better call is usually to solve it once, correctly.

Segmentation logic

Belongs in the architecture, not the rules. Encoding entity-level distinctions at the infrastructure level, rather than rebuilding them in every rule, is what made this approach scale.

Mega

Managing GDPR compliance across a complex stakeholder landscape

Mega is an internationally active energy-sector company with a complex supplier network spanning both the EU and non-EEA countries. Alongside external vendors, Mega relies on intra-group relationships with holding and sister organisations, each carrying its own data transfer risk profile.

LM Oost-Vlaanderen

From regulatory scrutiny to demonstrated compliance

LM Oost-Vlaanderen is a Belgian social security mutuality serving members across the province of East Flanders. As a social security organisation, it operates under strict sector-specific regulations and handles some of the most sensitive personal data categories that exist: health records, financial entitlements, and member identity.

Transport Infrastructure Organization

From manual RoPA management to continuous compliance

Our client is a public railway infrastructure manager, responsible for building, maintaining, and operating the country's rail network. As a public-sector organisation handling a broad range of personal data across multiple domains and subdomains, maintaining a compliant and well-governed Register of Processing Activities (RoPA) is both a legal obligation and an operational challenge.