Are financial reports covered by BCBS 239? The ECB's response to the industry
Reading BCBS 239's title, one might think only risk reports are concerned. But the ECB's RDARR Guide explicitly includes, within its minimum scope, "externally published financial reports as well as annual financial statements" (ECB Guide, section 3.2) — a choice that triggered one of the most substantial series of comments in the entire public consultation.
What exactly does "financial reports" cover?
The first point to clarify: several respondents (EBF, AFME) asked for confirmation that "financial reports" means externally published reports — annual and/or quarterly financial statements — and not reports for internal use (such as cost or profit tracking). The ECB confirms: that is the correct interpretation. A second clarification concerned frequency: the Guide targeted reports "published at least quarterly"; some respondents (EBF, DZ BANK) asked whether this excluded semi-annual statements. The final version of the Guide was amended on this specific point to clarify the frequency requirement. (ECB consultation feedback statement, May 2024 — Table 3, comments 30 and 31)
"A redundant layer": the industry's argument
Five federations and institutions (EBF, EACB, German Banking Industry Committee, DZ BANK, UniCredit Spa) challenged the inclusion of financial reports in the minimum scope, for two main reasons. First, a large part of BCBS 239's founding principles already effectively apply to the financial reporting process: numerous regulations, including national ones (Law 262/2005 in Italy, the IDW PS 900 standard in Germany), set high standards and clear responsibilities for the management body and senior management, and financial statements are already subject to strict accounting standards and independent external audit. Why, then, extend the scope to reports already governed? Second, most BCBS 239 principles already implicitly apply to financial statements (accuracy, completeness, timeliness, comprehensiveness) without needing to be spelled out — while others (adaptability, usefulness, distribution) are, in these respondents' view, not relevant to financial statements. (ECB consultation feedback statement, May 2024 — Table 3, comment 32)
The ECB's answer: not a new layer, an integration
The ECB does not back down, but reframes the debate. It recalls that applying the BCBS 239 principles to financial reporting is itself recognised by the Basel Committee as an example of effective governance, and that the ECB had already suggested it in its 14 June 2019 letter to significant institutions. The key point of the response: where other processes and control mechanisms already exist to ensure the quality of financial reporting, institutions must fully integrate their data governance framework with existing governance arrangements — not build a parallel system. Regulations apply to risk, financial and supervisory reporting alike, and the Guide expects the internal data governance framework to take this into account; this is not seen as conflicting with existing standards, regulations or laws. (ECB consultation feedback statement, May 2024 — Table 3, comment 32)
BCBS 239 already distinguishes risk data from accounting data
A nuance raised by the EACB and DZ BANK deserves attention: BCBS 239 explicitly differentiates accounting data from risk data, requiring that "controls surrounding risk data should be as robust as those applicable to accounting data" (BCBS 239, Principle 3(a)). In other words, the founding text already treats accounting data as a robustness benchmark to be reached for risk data — not as a scope to be duplicated. The ECB confirms that applying the principles to financial reporting is recognised both by the Basel Committee and by itself as an example of effective governance, while noting that accounting data forms a significant basis for this reporting — banks also using financial data to steer the institution. (ECB consultation feedback statement, May 2024 — Table 3, comment 33)
The compromise reached: reuse, don't duplicate
One EBF comment nicely illustrates the solution adopted: banks should be able to rely on or reuse the data quality processes already in place as part of the audit of financial statements. In Germany, for example, the audit of consolidated accounts is carried out in accordance with paragraph 317 of the Handelsgesetzbuch (HGB), and banks receive, on that occasion, an attestation from their external auditor, published in their annual report. The ECB's answer is unambiguous: existing controls can be used to the extent that they are sufficient to ensure data quality — there is no need to duplicate controls that are already fit for purpose. The Guide was amended to clarify this point. (ECB consultation feedback statement, May 2024 — Table 3, comment 35 — amendment made)
The whole report, or just the key indicators derived from it?
A final disputed point, raised by the EBF and AFME: a financial report can be voluminous, and its data often serves as the basis for further calculations and analyses. Should the scope cover the financial report as a whole, or only the key risk indicators derived from it? The ECB clarifies: the scope must cover, at a minimum, the risk appetite indicators as well as the other key risk indicators contained in the reports concerned. It gives the example of the ICAAP: its normative perspective relies on financial (and regulatory) data — the financial metrics needed to produce ICAAP data are therefore also expected to be within scope. It is up to institutions to precisely define which reports and which risk indicators fall within the scope of application of their data governance framework. (ECB consultation feedback statement, May 2024 — Table 3, comment 34 — amendment made)
Key takeaway
The debate did not result in financial reports being removed from RDARR's scope — the ECB held its position on the principle. But the clarifications obtained meaningfully change things for an institution worried about duplication: no need to build a second quality control framework alongside the existing external audit, provided the latter is sufficient; and the exact scope — the whole report or derived indicators — remains each institution's own call, based on a case-by-case analysis.
This article is based on three documents: the Basel Committee's 14 BCBS 239 principles (January 2013), the ECB's RDARR Guide (May 2024), and the ECB's feedback statement on the RDARR Guide's public consultation (May 2024).