Risk data aggregation principles

BCBS 239

Principles for effective risk data aggregation and risk reporting.

Born of the shortcomings revealed by the 2007-2008 financial crisis, this standard requires large banks to have strong governance, data architecture and aggregation capabilities, so that senior management and the board of directors can identify and steer risks quickly — including during periods of stress. More than ten years after its publication, the ECB (the European banking supervisor) finds that no significant institution examined yet fully applies these principles, and published a guide in May 2024 detailing its minimum supervisory expectations.

This site brings together, in English, the 14 BCBS 239 principles detailed pillar by pillar, the ECB's RDARR Guide (May 2024) and its seven supervisory expectations, a timeline of the standard, and sourced articles on risk data aggregation and risk reporting. Every statement is tied back to its original paragraph — Basel Committee (January 2013) or ECB (May 2024) — so it can be verified. Depending on your role (board, IT and data, audit and control), the reading path by profile leads directly to the principles, articles and the compliance self-assessment relevant to you.

14
BCBS 239 Principles
04
BCBS 239 Pillars
2013
BCBS Publication
07
Areas — ECB Guide 2024