Data quality: what the Basel Committee and the ECB expect
"The bank must ensure the quality of its risk data" — put this way, the objective seems almost too general to be verifiable. But BCBS 239, and then the ECB's RDARR Guide, do not stop at this generality — they describe precise mechanisms, checkable one by one.
Principle 3: Accuracy and Integrity
The Basel Committee requires that a bank be able to generate accurate and reliable risk data, meeting precision requirements in both normal times and periods of stress, with aggregation that is largely automated to minimise the risk of errors. In concrete terms, the text sets several minimum requirements: controls over risk data as robust as those applied to accounting data; where spreadsheets or desktop databases are used by risk teams to develop their own tools, effective mitigants must be in place — including end-user computing policies; risk data must be reconciled with the bank's sources, including accounting data where relevant; and a bank should strive towards a single authoritative source for risk data, for each type of risk. (BCBS 239, Principle 3)
Another structuring requirement: having a "dictionary" of the concepts used, so that data is defined consistently across the organisation. Supervisors expect banks to document and explain all of their aggregation processes, whether automated or manual — with, for each manual workaround, an explanation of its appropriateness, a description of its criticality to aggregation accuracy, and proposed actions to reduce its impact. (BCBS 239, Principle 3)
Principle 4: Completeness
A bank must be able to capture and aggregate all material risk data group-wide, including off-balance-sheet exposures, available by business line, legal entity, asset type, industry, region and other relevant groupings. Where data is not entirely complete, the impact must not be critical to the bank's ability to manage its risks — and supervisors expect any exception to be identified and explained. (BCBS 239, Principle 4)
Integrated data architecture according to the ECB
The 2024 RDARR Guide makes these two principles operational. It requires an integrated data architecture, documented at group level, including data taxonomies — in particular a dictionary of key business definitions and a metadata repository — covering significant legal entities, business lines, material risks and their associated reports, key risk indicators and their critical data elements, and the models within scope. Managing these taxonomies must include: consistent data definitions with clearly established ownership; validation rules allowing specific values or ranges of values; and complete, up-to-date lineage, at the level of each data attribute, from capture through extraction, transformation and loading. (ECB Guide, section 3.4)
The group-wide quality framework
The Guide's section on group-wide data quality management lists six expected elements. First, data quality controls covering at least accuracy/integrity, completeness and timeliness, from front-office systems through to the reporting layer, automated as far as possible, supplemented by periodic reconciliation with the bank's sources. Second, data quality indicators covering these same dimensions, including tolerance thresholds and documented correction processes in the event of breaches, periodically reported to the management body along with an analysis of their impact on risk measurement. (ECB Guide, section 3.5)
Third element: an up-to-date and complete log of data quality issues and limitations, including a severity assessment, root cause analysis, a quantitative impact assessment on the risk and business areas concerned, clearly defined processes and responsibilities for remediation and escalation, remediation deadlines, and a duly justified effective remediation date. Fourth element: full integration of end-user computing into data quality management policies and processes, with an overview of these applications. Fifth element: arrangements governing any manual workaround — the four-eyes principle, rigorous documentation, traceability of changes and approvals — until the steps concerned are integrated into a controlled and audited IT environment. Finally, sixth element: adequate consideration of data quality risks in the ICAAP and ILAAP, since such issues can lead to an underestimation of risk and must be offset by an additional margin of conservatism. (ECB Guide, section 3.5)
Two texts, one common thread
Eleven years separate the two documents, but the common thread is the same: a piece of risk data is only useful if its origin, transformation and limitations are traceable and documented. What BCBS 239 formulated in 2013 as a general principle — single authoritative source, data dictionary, documentation of manual workarounds — the ECB turns in 2024 into an operational checklist: taxonomies, an issues log, numerical tolerance thresholds, integration of spreadsheets into control frameworks.
This article is based exclusively on two documents: the Basel Committee's 14 BCBS 239 principles (January 2013) and the ECB's RDARR Guide (May 2024), both available on the Resources page.