BANKSTER API / BLOG

Blog

Signed opinion from the desk and the back office: positions on data, money, controls and the systems institutional finance runs on.

38 POSTS

Market Data Licensing Is an Architecture Constraint

Vendor and exchange terms distinguish display from non-display use, restrict derived data and redistribution, and price by user, application, or location. Moving analytics to the cloud, adding a data platform, or feeding an AI model can change what you owe.

Read post

What Does PCI DSS Compliance Actually Buy You?

PCI DSS compliance is a commercial requirement to keep processing cards, not a security warranty. The attestation is a point-in-time snapshot of a sampled environment, and the real work is scope reduction and the risk narrative that sits beside it.

Read post

Regulatory Reporting Is a Data Lineage Problem

Regulators increasingly expect every reported number to be traceable to its source and reproducible on demand. Most reports are assembled downstream, through extracts, adjustments, and spreadsheets that nobody can fully trace. Lineage has to be designed into the data flow; it cannot be reconstructed the week before a regulatory review.

Read post

Stop Storing Money in Floating Point

Binary floating point can't represent 0.1 exactly. The screen rounds it politely; the reconciliation team doesn't. Money needs an exact representation and a rounding rule decided in advance.

Read post

Excel Ate Your Security Identifiers

Excel sees ISINs and CUSIPs that look like dates or numbers and helpfully converts them. Identifiers are labels, not numbers, and a spreadsheet that rewrites them is inventing reference data.

Read post

Do You Actually Need a SOC 2 Report?

SOC 2 is an auditor's attestation, not a certification, and a Type I report says less than a Type II. Whether you need one depends on who your clients are, what they would otherwise send you, and whether ISO 27001 or a client's own audit rights would serve them better.

Read post

When Your Pivot Table Gives You Meaningless Numbers

Some figures do not aggregate. The average of fund-level internal rates of return is not the portfolio's IRR; that requires pooling the underlying cash flows. Money-weighted and time-weighted returns answer different questions; percentages and ratios summed or averaged across rows produce numbers that look precise and mean nothing.

Read post

The London Whale Was Also a Spreadsheet Problem

JPMorgan's 2012 trading loss was first disclosed at around $2 billion and grew to roughly $6.2 billion. The bank's own review found that the value-at-risk model behind that trading ran on spreadsheets fed by manual copy and paste, with a formula that divided by a sum where it should have divided by an average, understating the risk. What the case says about end-user computing in risk management, model change control, and who reviews the arithmetic.

Read post

Why the Fund Won't Leave Its Custodian

Custodians hold the assets, but over time they also become the data platform, the reporting engine, the accounting provider, and the source of dozens of integrations built on their message formats. Switching becomes a multi-year program nobody wants to sponsor.

Read post

Would You Pass an Audit If You Copied the Standard and Replaced "Should" With "Must"?

Policies written by pasting every clause of a framework and hardening the verbs look complete and fail on first contact with an auditor. Auditors test whether controls operate and whether evidence exists, and standards like ISO 27001 expect controls chosen from a risk assessment, not adopted wholesale. A policy you do not follow is documented non-compliance. Writing policies the organization can actually run.

Read post

End of Day Is a Time Zone Argument

A global portfolio has no single close. Which price counts for a Tokyo holding in a Toronto fund, when the NAV cut-off falls, and when fair-value adjustments apply are business decisions that end up hard-coded differently in each system.

Read post