Are internal models covered by BCBS 239? From Pillar 1 to Pillar 2
BCBS 239 is not just about risk reports. From its founding 2013 text, the Basel Committee explicitly extends its principles to the internal models that produce the risk figures themselves — a point the RDARR Guide's public consultation went on to clarify in detail.
What BCBS 239 says from 2013
The Basel Committee's text specifies that the principles cover all key internal risk management models — including, but not limited to, Pillar 1 regulatory capital models (for example internal ratings-based approaches for credit risk, or advanced measurement approaches for operational risk), Pillar 2 capital models, and other key models such as value-at-risk (VaR). (BCBS 239, "Scope and initial considerations" section)
No hierarchy between Pillar 1 and Pillar 2
The EBF asked for a clear distinction in severity between Pillar 1 reporting and Pillar 2 stress testing, with a lighter workload for the latter, since it does not directly affect the CET1 ratio. The ECB flatly refuses this request: to ensure sound risk management, the data governance framework must cover all material risks, their main risk reports and the risk indicators used in decision-making and steering processes — whether the information relates to Pillar 1 or Pillar 2. Paragraphs 16 and 17 of BCBS 239 refer to both pillars without any distinction in severity. (ECB consultation feedback statement, May 2024 — Table 3, comment 40)
What's in scope: input data AND outputs
One point the consultation clarified: the scope is not limited to a model's outputs. The Guide stresses that RDARR practices must apply both to the input data used to develop a model and to the estimates that result from it — for example probability of default or loss given default for an internal ratings model. On this point, the Guide specifies (section 3.4) that complete, end-to-end lineage is expected for the risk indicators and their critical data elements identified within scope — which therefore applies fully to models. (ECB consultation feedback statement, May 2024 — Table 3, comment 41)
Model development and production use: a nuance left unsettled
A comment from the German Banking Industry Committee raises an important technical distinction: the nature of data use during a model's development differs from its use during production application — which has direct consequences for data lineage documentation and for quality monitoring/reporting, potentially different between the two phases. The ECB does not settle the question with a separate regime: it reaffirms the general expectation (coverage of input data and outputs, end-to-end lineage) without creating a specific regime for the development phase — a point the final text therefore leaves, on this specific issue, to each institution's judgement. (ECB consultation feedback statement, May 2024 — Table 3, comment 41)
IFRS 9 and VaR, named explicitly
The 2024 RDARR Guide makes the scope for models very concrete. It specifies that it must cover, without being limited to, Pillar 1 regulatory capital models (such as internal ratings-based approaches for credit risk), Pillar 2 risk and capital models, and other key risk management models — including IFRS 9 collective provisioning models and value-at-risk (VaR) models — covering both the data used to develop these models and the outputs they produce. (ECB Guide, section 3.2)
Proportionality, once again
Faced with concerns about the scale of the burden (how to reconcile this scope with model risk management frameworks already in place?), the ECB's response draws on a principle that runs throughout the Guide: application must be proportionate, reflecting the nature, scale and complexity of the institution and its risk profile. The ECB goes further: it asks institutions to take into account the processes already in place to meet existing binding requirements on the quality of the main data used to develop and quantify risk parameters — for example those required for internal ratings-based approach data under the ECB's Guide on internal models. The same logic as for financial reports applies here: don't duplicate what already works. (ECB consultation feedback statement, May 2024 — Table 3, comment 39)
Who decides the exact scope?
On this topic as on that of reports, the Guide does not provide an exhaustive, definitive list. It is up to each institution to define which models and which risk indicators fall within the scope of application of its data governance framework, and how to apply the proportionality principle to them. (ECB consultation feedback statement, May 2024 — Table 3, comments 39 and 41)
Key takeaway
An internal model — IRB, VaR, IFRS 9 provisioning — does not escape RDARR discipline on the grounds that it already has a model risk management framework. But that existing framework can, and must, be leveraged rather than duplicated: the ECB is asking for integration, not addition. What remains, for each institution, is to precisely document where the line falls between what belongs to model risk management and what belongs, in its own right, to data governance.
This article is based on three documents: the Basel Committee's 14 BCBS 239 principles (January 2013), the ECB's RDARR Guide (May 2024), and the ECB's feedback statement on the RDARR Guide's public consultation (May 2024).