Who must do what? RDARR's lines of defence according to BCBS 239 and the ECB
Who, within a bank, is responsible for the quality of a risk indicator? Who must independently control it? And who, finally, checks that this control itself works? BCBS 239 raises the question as early as 2013, but answers it in a few lines. The ECB's RDARR Guide, in 2024, picks it up and details it over several pages, with a much more operational division of roles.
BCBS 239: an independent validation requirement, set out between the lines
BCBS 239 Principle 1 (Governance) requires that a bank's risk data aggregation capabilities and risk reporting practices be fully documented and subject to high standards of validation. This validation must be independent and cover the bank's compliance with all the principles in the text. Its primary purpose is to ensure that aggregation and reporting processes function as intended and are appropriate for the bank's risk profile. The text specifies that this independent validation must be aligned and integrated with the bank's other independent review activities within its risk management programme, and cover all components of its aggregation and reporting processes — drawing, as far as possible, on staff with specific IT, data and reporting expertise. (BCBS 239, Principle 1)
It is in a footnote that the text explicitly names the concept: this validation function is what is known as the "second line of defence" within the bank's internal control system. Another footnote specifies that validation must be conducted separately from audit work, to fully preserve the distinction between the second and third lines of defence within the internal control system. (BCBS 239, Principle 1, footnotes 13 and 14)
The 2024 RDARR Guide: four levels of responsibility
Where BCBS 239 sketches out the principle, the ECB's RDARR Guide, in its section on the data governance framework, details the minimum expected elements — both at group level and at the level of significant legal entities. Four levels of responsibility fit together.
1. Data owners
First level: data owners responsible for key risk indicators and critical data elements, throughout the end-to-end aggregation process. This responsibility can be delegated, provided it includes: contributing, together with data users, to defining quality controls and to classifying key risk indicators and their underlying critical data elements; ensuring the accuracy, integrity, completeness and timeliness of data; monitoring and reporting on data quality through data quality processes; remediating insufficient-quality issues; and managing metadata relating to data lineage and the data dictionary. (ECB Guide, section 3.3)
2. A central data governance function
Second level: a central data governance function, responsible for issuing data quality management policies and processes, overseeing the sound implementation of the data governance framework across the organisation, assessing and monitoring data quality, and taking part in change management processes with a material impact on RDARR — whether mergers or acquisitions of significant legal entities, outsourcing of functions, launches of new products or tools, upgrades of existing tools, or other IT change initiatives. (ECB Guide, section 3.3)
3. A validation function, as the second line of defence
Third level: a validation function, positioned as the second line of defence, independent of the units involved in data governance and RDARR processes, responsible for ensuring those processes function as intended. Where this validation function sits within the same entity as the one responsible for data governance or RDARR — the risk management function, for example — adequate segregation of duties and other mitigating measures must be put in place to avoid or limit conflicts of interest. This function must carry out regular assessments of the institution's RDARR capabilities across all significant entities and risk types, and cover every component of RDARR processes — IT infrastructure, data traceability, data taxonomy — including oversight of outsourced functions, IT change initiatives, mergers and acquisitions, and new product launches. It must have sufficient staff resources and the necessary IT, data and reporting expertise, with organisational arrangements ensuring its effective independence — the nature of which depends on the institution's size, scale and complexity. (ECB Guide, section 3.3)
4. Internal audit, as the third line of defence
Fourth level: an internal audit function, constituting the third line of defence, which periodically provides independent reviews of the validation function, the data governance framework, RDARR capabilities and processes, and the quality of data used for risk quantification. These independent reviews may be supplemented by supervisory reviews or, if the institution deems it necessary, by an independent external review. (ECB Guide, section 3.3)
At the top: the management body
These four levels are not self-standing: the RDARR Guide places them under the overall responsibility of the management body, which must take responsibility for risk data quality and governance, approve and implement the data governance framework, and designate one or two of its members to bear responsibility for its implementation — without that designation relieving it of its overall responsibility. It is also the management body that must set clear roles and responsibilities for RDARR across the organisation, including for the relevant committees. (ECB Guide, section 3.1)
A long-standing framework, still incompletely applied
The three-lines-of-defence model is nothing new: it structures banking internal control well beyond RDARR alone. What a cross-reading of the two texts shows is that the Basel Committee had already set out the principle back in 2013 — through a simple independent validation requirement — but that the ECB judged it necessary, eleven years later, to detail its concrete application, function by function. One sign, among others, that the general principle was widely known to institutions, but that its effective implementation still had to be built.
This article is based exclusively on two documents: the Basel Committee's 14 BCBS 239 principles (January 2013) and the ECB's RDARR Guide (May 2024), both available on the Resources page.