Writing

The Governance Crisis: The Reckoning

Under Quebec’s Law 25, we face administrative monetary penalties of up to $25 million or four percent of worldwide turnover, whichever is greater.

The Governance Crisis, part 2 of 5

The Seven Pillars of Data Management, a novel in seven acts.

Chapter I, The Governance Crisis. Pillar I: Data Governance. Part 2 of 5.

The War Room

By 7:30 that morning, the morning of the call from Marcus Pellerin, Nadia was in the boardroom on the forty-second floor of Northbridge Tower. The room was designed to impress: floor-to-ceiling glass overlooking Lake Ontario, a table of reclaimed Canadian walnut that could seat twenty-four, portraits of former CEOs lining the interior wall like a gallery of financial saints. Alistair Northbridge himself stared down from above the credenza, his oil-painted eyes carrying the stern certainty of a man who had survived U-boats and believed that discipline was the answer to every question.

Discipline. If only.

Around the table sat the crisis team that Nadia had assembled in the forty-five minutes since Pellerin’s call. Each face told a different version of the same story: how an organization of 11,000 employees, operating under the regulation of multiple sovereign jurisdictions, had allowed its data to become ungoverned, unclassified, and uncontrolled.

Jean-François Leclerc, the General Counsel, sat at the far end of the table with his jacket already off, his sleeves rolled to the elbows, the posture of a man preparing for a fight he knew he was going to lose. He had spent the last hour on the phone with outside counsel in London and Sacramento, and the news from both calls was identical: the regulators already had enough to open formal proceedings. The question was not whether there would be an investigation, but how many investigations, in how many jurisdictions, and how large the fines would be.

“Walk me through the exposure,” Nadia said. Her voice was steady. She had learned, in two decades of crisis management, that the leader’s voice sets the emotional temperature of the room. Panic is contagious. So is calm.

Leclerc opened a folder. “Under PIPEDA, the Privacy Commissioner can refer the matter to Federal Court, which can award damages up to $100,000 per individual for a violation involving sensitive personal information. With sixty-two million records potentially affected...”

“That’s a theoretical maximum,” interrupted Aisha Karim, the Chief Risk Officer, from across the table. “No court has ever awarded anything close to...”

“Let me finish,” Leclerc said, and something in his tone, a weariness, a gravity, silenced the room. “Under PIPEDA, the exposure is significant but manageable. Under Quebec’s Law 25, we face administrative monetary penalties of up to $25 million or four percent of worldwide turnover, whichever is greater. Under UK GDPR, the Information Commissioner’s Office can impose fines of up to £17.5 million or four percent of global annual turnover. Under the California Privacy Rights Act, the California Privacy Protection Agency can impose fines of $7,500 per intentional violation.”

He paused, letting the numbers settle over the room like sediment.

“Our worldwide turnover last fiscal year was $9.4 billion Canadian. Four percent of that is $376 million. And that’s per jurisdiction. If the UK, Quebec, and California each impose maximum penalties, we are looking at potential fines exceeding one billion dollars. Before class action litigation. Before the stock price impact. Before the cost of remediation.”

Silence. The kind of silence that has weight to it, that presses down on the chest and makes breathing feel like effort. Through the glass, a ferry was crossing the harbour toward the Toronto Islands, carrying no one in particular to nowhere in particular, indifferent to the catastrophe unfolding forty-two stories above the waterline.

Nadia looked at each person around the table. “How did we get here?”

No one spoke.

“That was not a rhetorical question.”


The Archaeology of Failure

What emerged over the next four hours, as the crisis team reconstructed the chain of events, was not a story of malice. It was a story of neglect: the slow, quiet, institutional kind of neglect that accumulates like silt in a river, invisible at any single point in time but devastating in aggregate.

The story began in 2016, when Northbridge acquired Commonwealth Life & Health, a mid-sized insurer based in Vancouver with a book of 1.8 million health and life insurance policies and a UK subsidiary operating out of Edinburgh. The acquisition was celebrated as a strategic masterstroke, Northbridge’s entry into the health insurance market and its expansion into the United Kingdom in a single transaction. The deal closed for $2.1 billion, and the CEO at the time, Richard Chen, rang the opening bell at the Toronto Stock Exchange with a smile that the Globe and Mail described as “the grin of a man who has just won the lottery and knows it.”

What the Globe and Mail did not describe, because no journalist thought to ask, and no executive thought to disclose, was the state of Commonwealth’s data infrastructure. The company ran on a patchwork of systems dating back to the early 2000s: an AS/400 mainframe for policy administration, a Microsoft Access database (yes, Access) for claims tracking in the UK subsidiary, a homegrown CRM built on Visual Basic, and a series of Excel spreadsheets that individual underwriters maintained on their personal drives and referred to, without irony, as “the source of truth.”

There was no data classification scheme. No data ownership model. No retention policy. No access control matrix. No data lineage documentation. No data quality framework. There was, in the most literal sense, no data governance.

And when Northbridge absorbed Commonwealth’s systems into its own environment, a process that the integration team completed in eighteen months, under budget, to great internal applause, it absorbed those ungoverned datasets like a body absorbing a toxin. The health records mixed with the property records. The UK data mixed with the Canadian data. The consent frameworks, such as they were, were overwritten by Northbridge’s master customer database, which had been designed for property and casualty insurance and had no fields, no logic, and no processes for tracking the enhanced consent requirements that health data demanded under every privacy regime on the planet.

For eight years, this data sat in Northbridge’s systems. Unclassified. Ungoverned. Accessible to anyone with a standard business intelligence login. A ticking bomb disguised as a successful integration.

And nobody knew. Or rather, and this was the part that would haunt Nadia, some people knew fragments of the truth, but no single person had the authority, the mandate, or the institutional position to see the full picture and act on it.

The IT team knew the systems were fragmented but had no budget for remediation. The compliance team knew the privacy regulations but had no visibility into how data actually flowed through the organization. The business units knew their own data but had no incentive to coordinate with each other. The board knew the company was “digitally transforming” but had no mechanism to evaluate whether that transformation was happening in a way that was lawful, prudent, or sane.

This was the governance gap. Not a gap in technology. Not a gap in talent. A gap in the most fundamental question an organization can ask about its data: Who is responsible?

The answer, at Northbridge Mutual Insurance, had been: nobody.

Papa S. Nguer

Papa S. Nguer is a keynote speaker, presales leader, and author of Winning the Moments That Matter. 25 years in enterprise data and technical sales, $93M+ influenced, 300+ proving engagements.

Book him to speak  ·  Work with him  ·  LinkedIn

← All writing