20 business days: what the ECB requires for risk reporting speed
BCBS 239 and the ECB's RDARR Guide mostly avoid setting universal numerical thresholds — both texts consistently defer to the nature of the risk and the size and complexity of the institution. There is, however, one notable exception: a precise numerical benchmark, set by the ECB, for judging the speed of risk reporting.
Principle 5: Timeliness under BCBS 239
A bank must be able to generate aggregated, up-to-date risk data quickly, while still meeting accuracy, completeness and adaptability requirements. The Basel Committee acknowledges that different types of data will be needed at different speeds depending on the type of risk, and that some data may be required faster during periods of stress or crisis — banks must therefore build their systems to be able to rapidly produce aggregated risk data, for all critical risks, during periods of stress. The text cites examples of critical risks: aggregated credit exposure to a large corporate borrower, counterparty exposures (including derivatives), trading exposures and operating limits, liquidity indicators such as cash flows and funding, and time-sensitive operational risk indicators, such as systems availability or unauthorised access. (BCBS 239, Principle 5)
Principle 6: Adaptability to ad hoc requests
A bank must also be able to respond to a broad range of ad hoc, unplanned reporting requests — including during periods of stress, in response to changing internal needs, or to answer supervisors' questions. This requires flexible aggregation processes that enable quick decision-making, customisation capabilities for users (dashboards, key takeaways, anomalies), the ability to drill down into data on demand, and the capacity to quickly produce summary reports. The text gives a concrete example: a bank should be able to quickly aggregate its credit exposures by country or industry, as of a given date, across all its business lines and geographic areas. (BCBS 239, Principle 6)
What the ECB clarifies: two factors, not one
The 2024 RDARR Guide identifies two distinct factors that determine the timeliness of risk reporting: the frequency with which reports are produced, and the time needed to produce them. Frequency must be consistent with how quickly the relevant risk figures can change — the more volatile an indicator, the higher the reporting frequency must be. The Guide cites the ECB's Guide on the ICAAP in this regard, which specifies that the frequency of reporting ICAAP results to the management body is expected to be at least quarterly, but may need to be more frequent depending on the institution's size, complexity, business model and types of risk. Economic risk measures, generally more volatile than regulatory risk measures, therefore most often require a higher reporting frequency. (ECB Guide, section 3.6)
The 20-business-day rule
This is where the Guide introduces one of the rare explicit numerical thresholds in the entire RDARR framework: the ECB expects an institution to calibrate the combination of reporting frequency and production time so as to allow for a rapid response to changes in its risk situation, in line with its internal risk appetite indicators. For internal risk reports under normal conditions, it is generally accepted that an institution will not be able to react to changes in time if a monthly or quarterly risk report takes more than 20 business days to produce. This production time itself depends on the materiality and volatility of the key risk indicators being reported. (ECB Guide, section 3.6)
And during periods of stress?
Beyond this benchmark for normal conditions, the ECB expects institutions to have effective RDARR capabilities for periods of stress or crisis — to handle unexpected shocks, such as the COVID-19 pandemic explicitly cited by the Guide as a recent example, or to adapt to new or amended reporting and disclosure requirements. In periods of emerging stress, aggregation capabilities must be sufficiently adaptable to respond to ad hoc requests with a sufficient level of granularity — for example, client-level data to manage credit risk concentrations — at both entity and group level. The ECB expects that reporting speed will not be compromised, even during periods of stress, by fragmented IT infrastructure or a high volume of manual aggregation processes. (ECB Guide, section 3.6)
A benchmark to gauge yourself against, not an absolute standard
The 20 business days are not presented as a regulatory ceiling applying uniformly to every report at every institution — the Guide mentions it as a benchmark for monthly or quarterly reports under normal conditions, with actual production time remaining a function of the materiality and volatility of each indicator. It is nonetheless one of the rare points in the entire BCBS 239 / RDARR framework where a concrete figure sheds light on an otherwise qualitative requirement — and therefore a useful benchmark for an institution looking to self-assess on this specific point.
This article is based exclusively on two documents: the Basel Committee's 14 BCBS 239 principles (January 2013) and the ECB's RDARR Guide (May 2024), both available on the Resources page.