Relativity Home logo

Your single source for new insights on AI, legal data intelligence, and the humans holding the reins.

5 Myths Keeping FinServ Firms from Unlocking Intelligence in Their Legal Data

Adam Rouse
5 Myths Keeping FinServ Firms from Unlocking Intelligence in Their Legal Data Icon

The financial services industry stores more data than any other, according to a 2024 Forrester report. The data estate is vast and complex, comprising everything from personally identifiable information like customer account data and complaints, to trade logs, telecommunication records, executive communications, and more.

But if you are working with a data corpus that exceeds five petabytes*, how do you efficiently access, retrieve, analyze, and de-risk that data? What makes the situation even more challenging is that every time a regulatory inquiry or lawsuit arises, legal teams have to wade through a patchwork of on-premises servers, legacy systems, and a technology infrastructure that served a bygone era.

Cloud adoption inside many FinServ legal departments has been held back by a set of persistent myths and misconceptions about security, control, migration risk, cost, and AI safety.

In this post, we will explore common myths associated with cloud adoption, looking at what’s changed, and examining them against the current evidence.

In our new e-book, developed in coordination with KPMG, we examine these myths in greater detail, explore the pivotal factors driving financial services firms to move to the cloud, and provide real-world examples of how legal teams are saving time and money by leveraging AI capabilities native to the cloud.

Check out “The Tipping Point: Why Financial Services Firms Are Migrating Legal Workflows to the Cloud.”

Myth #1: The cloud is less secure than on-premises systems

The belief that the cloud is inherently less secure than local servers no longer aligns with where regulators, or the evidence, have landed.

The US Department of the Treasury's 2023 report, “The Financial Services Sector's Adoption of Cloud Services,” found that the security capabilities offered by public cloud providers "generally match or exceed" the on-premises capabilities of the financial institutions interviewed. The report points to several specific advantages:

Rapid patching and zero-day defense: Services running on cloud environments can be patched quickly to protect against newly disclosed exploits – a meaningful edge over legacy systems where remediation depends on a firm's own update cycles.

Advanced security configurations and continuous monitoring: Cloud providers offer built-in logging capabilities that, according to the institutions that the Treasury Department interviewed, are often superior to what firms can deploy on their own infrastructure. Data can be encrypted more readily, both at rest and in transit.

Geographic redundancy: Cloud providers offer physical redundancy "beyond what most financial institutions could develop independently." Workloads can be configured across multiple, geographically isolated data centers, providing resilience against localized incidents like natural disasters, power failures, or regional outages.

Myth #2: Proximity = Control

There's a particular kind of comfort in being able to walk past the server rack where your data lives. But proximity and control are not the same thing. What regulators actually care about has very little to do with the building the data sits in. It has to do with whether the firm can demonstrate, with rigor, who accessed what, when, and why.

"When managing legacy systems, organizations face complex operational questions regarding monitoring, access controls, backups, data integrity, and system upgrades. Transitioning to the cloud can streamline these challenges; cloud platforms often feature built-in audit trails, established security policies, and native preservation and collection tools that significantly reduce data integrity risks."
 

Matthew R. Birnbaum, Managing Director, KPMG US

Modern cloud environments provide audit trails, access logging, and data integrity controls that are, in many cases, harder to replicate on-premises. The same Treasury report found that the built-in logging capabilities of cloud services were "often superior" to what firms could produce on local servers. Encryption at rest and in transit, immutable records, fine-grained access permissions, real-time monitoring – these are the things regulators look for, and they are increasingly the things the cloud does best.

Myth #3: On-premises solutions are cheaper

It is true that the cloud shows up as a new line item, while the on-premises infrastructure has already been paid for. But the cost of legacy infrastructure is more than just the cost of maintaining and updating it. The hidden cost rears up in the form of time and labor every time the legal team needs to find information buried inside disconnected systems and data pools.

This doesn't mean the cloud is always cheaper, but when the comparison includes the full cost of working with the data, not just the cost of housing it, legacy environments are often more expensive than they look on the balance sheet.

On a single matter, these hidden costs might seem like an unplanned expense, but they become harder to ignore when they accumulate across hundreds of matters over time.

"Being more efficient by having your data in the cloud significantly drives down overall e-discovery spend – greater workflow flexibility and automation, rapid innovation and scaling, less redundant data. Based on assessments we've done at multiple financial institutions against their legacy on-premises workflows, a cloud-based e-discovery program produces real and significant cost savings."
 

Aaron Vidmar, Managing Director, Forensics & Discovery Consulting, KPMG

Myth #4: The migration process is too risky to undertake

Anyone who has watched a major IT migration go sideways understands what's at stake: metadata stripped in transit, chain of custody broken between source and destination, files arriving in the new environment corrupted or simply missing. For a FinServ legal team, where a single missing record can be the cause of a hefty penalty, the conservative instinct is rational.

But the framing of migration as an inherently high-wire act is increasingly out of step with how the work gets done today. The tooling available today is not what it was even five years ago. The old playbook – manual exports, custom scripts written to preserve metadata, late-night handoffs between source and destination systems – has been replaced by software built for this exact problem.

Part of the resistance also stems from a misreading of what migration truly requires. Many organizations assume it's binary: that they have to move everything they own, including decades of mostly inactive legacy matters, or move nothing at all.

Instead of going all in, a practical and prudent approach could be a hybrid one in which FinServ firms migrate less critical applications first to test the waters and gain the confidence of stakeholders before touching the more sensitive systems.

Myth #5: AI isn’t a good fit for sensitive data

Few industries handle data as sensitive as financial services. There are licensed market feeds, alternative data sets like satellite imagery, card transaction flows, and trading signals. Firms are also stewards of confidential client communications, detailed financial records, and personally identifiable information. Feeding any of it into a generative AI system raises a series of related questions:

  • Where does the data go when an AI tool processes it?
  • Who can see it?
  • Is it retained?
  • Is it used to train or improve the model?
  • Does the system remember sensitive content from one session to the next?
  • Could another customer of the same vendor somehow access or benefit from what we put in?

These concerns are legitimate, and they're widely shared. In KPMG's “2026 Banking Technology Survey” of 200 U.S. banking executives, 72 percent cited data privacy and risk concerns as a top challenge to modernizing their data infrastructure, just behind data quality (100 percent) and legacy systems (85 percent). The concerns haven't slowed adoption: the same survey found 95 percent of the same banks have active pilots or live use cases for generative AI in operational efficiency and automation, and 90 percent in security and fraud prevention.

The answer isn't to avoid AI but to be deliberate about where it runs and what the vendor is contractually bound to do with the data. Many institutions choose to embed AI capabilities into platforms they already trust and have already cleared through compliance and security review, rather than experiment in unvetted environments. Alongside that, they insist on explicit contractual guarantees around data handling.

At a minimum, that means three things:

  • AI tools should not retain or access customer data outside the immediate task.
  • Customer data should not be used to train any model, including public ones.
  • Customer data should not be used to improve any third-party product or service.

What this Means for Legal Teams

In 2026, the FinServ firms that haven't migrated face a different problem: every year they delay, their legacy environment becomes a larger archaeological dig, and an eventual migration grows correspondingly harder. Meanwhile, AI capabilities that seemed beyond reach only a few years ago are now standard features inside cloud-based legal platforms, setting a new baseline for what a legal team can do with its own data.

We recently published an e-book which takes a deep dive into the subject. Check out “The Tipping Point: Why Financial Services Firms Are Migrating Legal Workflows to the Cloud” to learn how teams are turning to the cloud to reclaim time, reduce costs, and turn raw data into intelligence that drives the business forward.

* 22% of firms surveyed by Forrester reported that they stored more than 5 PBs of data.

Graphics for this article were created by Sarah Vachlon.

The Tipping Point: Why Financial Services Firms Are Migrating Legal Workflows to the Cloud

Adam Rouse is the head of corporate legal community engagement at Relativity and a founding member of the Legal Data Intelligence project.

The latest insights, trends, and spotlights – directly to your inbox.

The Relativity Blog covers the latest in legal tech and compliance, professional development topics, and spotlights on the many bright minds in our space. Subscribe today to learn something new, stay ahead of emerging tech, and up-level your career.

Interested in being one of our authors? Learn more about how to contribute to The Relativity Blog.