Bridging Legal, Financial, and Data Governance in Enterprise AI: Emerging Trends
Abstract
Enterprise adoption of artificial intelligence (AI) has moved faster than the institutional machinery meant to govern it. Within a single organization, an AI system is simultaneously a legal object subject to regulation and liability, a financial object subject to model risk management and audit, and a data object subject to lineage, quality, and privacy controls. These three governance domains (legal, financial, and data) have historically evolved in separate professional communities, with distinct vocabularies, control catalogues, and assurance rhythms. The result is fragmentation: overlapping obligations are duplicated, gaps between domains go unowned, and accountability becomes diffuse. This paper surveys the state of the art across the three domains and argues that their convergence is the defining governance trend for enterprise AI. We review advances in AI regulation and standards (the EU AI Act, the OECD AI Principles, and the NIST AI Risk Management Framework), model risk management practice inherited from finance (notably SR 11-7), data governance frameworks (Abraham and colleagues; DAMA-DMBOK), and the maturing toolkit of documentation and explainability artefacts, including model cards, datasheets for datasets, and explainable AI methods. We propose a conceptual crosswalk that maps controls across domains onto shared AI lifecycle stages, exposing redundancy and gaps. We then examine open challenges (regulatory fragmentation, the pace of rule-making, unresolved liability allocation, and cross-border friction) and set out a research agenda for integrated governance that treats legal, financial, and data controls as a single accountable system rather than three parallel ones. The contribution is a synthesis and an organizing frame intended to guide both practitioners and future scholarship.