What should a good risk report contain? The 5 qualities of BCBS 239's Pillar III
BCBS 239's Pillar III starts from a finding many institutions have learned the hard way: accurate, complete and timely data is a necessary condition for effective risk management — but it is not enough on its own. The text says so directly: data alone does not guarantee that the board and senior management will receive the appropriate information to make effective decisions about risk. The right information also needs to be presented to the right people, at the right time. That is what the five Pillar III principles are about — the only constraint being that meeting them must not come at the expense of one another. (BCBS 239, Pillar III introduction)
1. Accuracy (Principle 7)
Risk management reports must accurately and precisely convey aggregated data, reflect risk in an exact manner, and be reconciled and validated. To ensure this accuracy, a bank must maintain, at a minimum: defined requirements and processes to reconcile reports to risk data; automated and manual consistency checks, including an inventory of the validation rules applied to quantitative information, with an explanation of the conventions used to describe the mathematical or logical relationships to be verified; and integrated procedures for identifying, reporting and explaining data errors or integrity weaknesses through exception reports. (BCBS 239, Principle 7)
The text explicitly recognises the legitimacy of approximations — model results, scenario analyses, stress tests — provided the bank sets documented reliability requirements for these approximations, just as it does for other types of reporting. Supervisors expect senior management to set accuracy and precision requirements for both normal and crisis reporting, drawing on a concept of materiality analogous to accounting materiality: if an omission or misstatement could influence users' risk decisions, it may be considered material. (BCBS 239, Principle 7)
2. Comprehensiveness (Principle 8)
Risk management reports must cover all material risk areas within the organisation, with depth and scope consistent with the bank's size and complexity. This includes exposure and position information for all significant risk areas — credit, market, liquidity, operational — and their significant components (for example, by counterparty, country or sector for credit risk), as well as risk-related measures such as regulatory and economic capital. Reports must identify emerging risk concentrations, place information in the context of limits and risk appetite, and propose recommendations for action where appropriate — including a forward-looking dimension, with forecasts or scenarios, rather than just a snapshot of the past. (BCBS 239, Principle 8)
The text gives an indicative list of what an aggregated risk report should cover at a minimum: capital adequacy, regulatory capital, capital and liquidity ratio projections, credit, market, operational and liquidity risk, stress test results, inter- and intra-risk concentrations, and funding positions and plans. (BCBS 239, Principle 8)
3. Clarity and usefulness (Principle 9)
A risk report must communicate information in a clear and concise manner — easy to understand, yet comprehensive enough to facilitate informed decision-making, with meaningful information tailored to the needs of its recipients. The right balance between raw data, analysis, interpretation and qualitative explanations varies by organisational level: the higher up the organisation, the greater the degree of aggregation, and the more necessary qualitative interpretation becomes. The board, in particular, is responsible for determining its own reporting requirements and must alert senior management when the reports it receives do not meet its needs for fulfilling its governance mandate. (BCBS 239, Principle 9)
Supervisors expect a bank to periodically confirm with recipients that the information aggregated and reported remains relevant and appropriate, in both amount and quality, for the governance and decision-making process. (BCBS 239, Principle 9)
4. Frequency (Principle 10)
It is up to the board and senior management — or other recipients as appropriate — to set the frequency of production and distribution of risk reports, based on the needs of the recipients, the nature of the risk, the speed at which it can potentially change, and the importance of the report for sound and effective decision-making. This frequency must increase during periods of stress or crisis. A bank must regularly test its ability to produce accurate reports within established timeframes, particularly in periods of stress — supervisors expect that during a crisis, all relevant and critical credit, market and liquidity reports be available within a very short period, with some position or exposure information needing to be available intraday. (BCBS 239, Principle 10)
5. Distribution (Principle 11)
Finally, risk management reports must be distributed to the relevant parties while maintaining confidentiality. Procedures must allow for the rapid collection and analysis of risk data, as well as the timely distribution of reports to all appropriate recipients — balancing this speed against confidentiality requirements. Supervisors expect a bank to periodically confirm that the relevant recipients do in fact receive their reports on time. (BCBS 239, Principle 11)
Five qualities, not a hierarchy
The Basel Committee is explicit on one point: these five principles must not be met at the expense of one another. A perfectly comprehensive but unreadable report is not compliant; a clear report produced too late to inform a decision is no more compliant. It is the combination of all five — accuracy, comprehensiveness, clarity, frequency, distribution — that defines, according to BCBS 239, what makes a good risk report.
This article is based exclusively on two documents: the Basel Committee's 14 BCBS 239 principles (January 2013) and the ECB's RDARR Guide (May 2024), both available on the Resources page.