Back to Blog Listing

The Marketing Compliance Data Model Most Banks Still Build in Email

The Marketing Compliance Data Model Most Banks Still Build in Email
Kamil Ponicki Sep 12, 2026 4 min read

Written by: Kamil Ponicki, Director of Talent Acquisition, Digital Colliers

Blee raised $20M last month because most mid-market banks cannot answer a simple question: which version of this ad creative passed compliance review? The team that approved it has moved on. The email thread is 140 messages deep. The Slack channel was archived. The creative file is in someone's Dropbox. The published ad is still running on Meta.

This is not a small bank problem. Regional banks with $5B to $50B in assets still run marketing compliance in email. The pattern is everywhere.

The Email Compliance System

Here's the workflow at most mid-market banks. Marketing creates an ad in Canva or Figma. They post the PNG in Slack asking for review. Compliance replies with edits. Marketing makes the changes. Another PNG goes into the thread. Compliance says approved. Marketing publishes to Meta or Google. The audit trail is now scattered across three tools and nobody's sure which file version went live.

When the audit comes, someone rebuilds the timeline by hand. They grep email. They scroll Slack. They pull screenshots from the ad platform. It takes a day to reconstruct one campaign's approval history.

The regulatory risk is real. GDPR fines reach up to €20M or 4% of global turnover. If a customer complains that you used their data in a way they didn't consent to, you need to prove what you published and when you got approval. Email threads don't cut it.

The Three Tables You Actually Need

The solution is not enterprise DAM software. It's three simple tables.

Creative version store. Every version of every creative gets an ID. The PNG or MP4 file. A hash of the content. The timestamp. The person who uploaded it. Version 1, version 2, version 3. You can diff any two versions. You know exactly what changed.

Approval event log. Every time someone reviews a creative, you log it. The creative version ID. The reviewer's name. The timestamp. The decision: approved, rejected, or needs changes. If rejected, the reason. This log is append-only. You can't edit it. You can't delete it.

Publish timestamp. When marketing pushes the creative to Meta or Google, you log that. The creative version ID. The ad platform. The campaign ID. The timestamp. If you pull the ad down later, log that too.

That's it. Three tables. You can build this in Postgres in an afternoon. Pair it with an S3 bucket for the actual files. Wrap a minimal UI around it so marketing can upload and compliance can review without leaving the browser.

Building It In-House

You don't need to buy Blee's $20M product. Most mid-market banks can ship a lightweight version in a week.

Day one: stand up Postgres and S3. Create the three tables. Write the file upload endpoint.

Days two and three: build the approval interface. A simple web form where compliance sees the creative, the previous version if there is one, and clicks approved or needs changes. Make sure the approval event writes to the log immediately.

Days four and five: build the marketing view. They can see all their creatives, which ones are approved, which ones are waiting. Add a publish button that logs the publish event and shows them the ad platform IDs.

Day six: write the audit export. A SQL query that pulls all three tables for a date range and dumps to CSV. Compliance or legal can hand this to the auditor directly.

Day seven: cut access to the old email and Slack workflow. Marketing uploads here. Compliance reviews here. Nothing gets published without a logged approval.

You now have a defensible audit trail. You know which creative version passed review. You know who approved it. You know when it went live. You can pull that data in 30 seconds instead of 30 hours.

What's Changing

DORA has been in force since 17 January 2025. It requires financial institutions to maintain operational resilience, which includes audit trails for critical workflows. Marketing compliance isn't the highest-risk workflow, but it's in scope if you publish to customers.

EU AI Act Article 50 transparency obligations apply from 2 August 2026. If you use automated systems to decide which customers see which ads, you'll need to document those decisions. The three-table model gives you the foundation.

The pattern is clear: regulators want proof. They want timestamps. They want version control. Banks that move now get ahead of the audit pain. Banks that wait are building this under pressure when the auditor asks the question they can't answer.

The data model is simple. The build is short. The alternative is explaining to your board why a $50M bank still runs compliance in email.

Related Posts