Who and what does BCBS 239 apply to? The exact scope according to the Basel Committee and the ECB

"BCBS 239 applies to large banks' risk data" — the phrase is accurate, but it conceals a scope that is actually much more precise. The Basel Committee's text, complemented by the ECB's RDARR Guide, explicitly sets out who must comply, which data and models it applies to, and how far this requirement extends.

Which banks are covered, and since when

The principles are primarily aimed at Global Systemically Important Banks (G-SIBs) designated by the Financial Stability Board (FSB). Those identified as G-SIBs in November 2011 or November 2012 had to comply from January 2016; G-SIBs designated in subsequent annual updates have three years from their designation. The Basel Committee also strongly recommends that national supervisors apply the same principles to Domestic Systemically Important Banks (D-SIBs), three years after their designation as such. National supervisors may, if they wish, extend these principles to a wider range of banks, in a manner proportionate to the size, nature and complexity of their operations. (BCBS 239, "Scope and initial considerations" section)

A point often overlooked: the principles apply both at the banking group level and on a solo basis. They also cover processes outsourced to third-party providers — outsourcing a function therefore does not exempt the institution from compliance. (BCBS 239, "Scope and initial considerations" section)

Not just "risk data": a precise scope for data and models

The 2013 text specifies that the principles apply to the bank's risk management data, including data deemed critical to enabling the institution to manage the risks it faces. But it goes further: the principles also cover all key internal risk management models — including, but not limited to, Pillar 1 regulatory capital models (for example internal ratings-based approaches for credit risk, or advanced measurement approaches for operational risk), Pillar 2 capital models, and other key models such as value-at-risk (VaR). (BCBS 239, "Scope and initial considerations" section)

While the principles primarily apply to group-level risk management processes, the Basel Committee notes that banks may also benefit from applying them to other processes, such as financial and operational processes, as well as supervisory reporting. (BCBS 239, "Scope and initial considerations" section)

What the ECB makes concrete in 2024

Eleven years later, the ECB's RDARR Guide devotes an entire section — "Sufficient scope of application" — to translating this scope into an operational list. According to the ECB, an institution's data governance framework must, at a minimum, cover three categories of reporting:

  • internal risk reports used in decision-making and steering processes — including risk appetite indicators (metrics and limits) and the main risk reports, by type of financial and non-financial risk;
  • externally published financial reports, as well as annual financial statements;
  • supervisory reports submitted to supervisory or regulatory authorities — including FINREP/COREP templates, "Short Term Exercise"-type exercises, submissions to EU-wide EBA stress tests and SREP stress tests, as well as Pillar 3 disclosures.

On the model side, the Guide specifies that the scope must cover, without being limited to, Pillar 1 regulatory capital models (such as internal ratings-based approaches for credit risk), Pillar 2 risk and capital models, and other key risk management models — including IFRS 9 collective provisioning models and value-at-risk models — covering both the data used to develop these models and the outputs they produce (probability of default, loss given default, exposure at default, etc.). Finally, the scope must include at least the institution's risk appetite indicators as well as the other key risk indicators referred to in these reports and models — with the institution required to explicitly identify the critical data elements underlying each of these indicators. (ECB Guide, section 3.2)

The Guide also specifies that this data governance framework must cover the entire data lifecycle — that is, every process, from data origination and capture through to aggregation and reporting. (ECB Guide, section 3.2)

Strictly limited exceptions

BCBS 239 does not demand blind, unnuanced application: the text allows for trade-offs between principles in exceptional circumstances, for example urgent or ad hoc requests for information on new or poorly understood risk areas. But these trade-offs must never have a material impact on risk management decisions; the board and senior management must be aware of these trade-offs and their limitations, and supervisors expect banks to have policies governing their use. (BCBS 239, "Scope and initial considerations" section)

The text also precisely defines the concept of materiality used throughout the document: data or a report may exceptionally exclude information only if its omission does not affect the bank's decision-making process — that is, if decision-makers, in particular the board and senior management, would not have been influenced, or would not have made a different decision, had they had the correct information. To assess this materiality, banks must take into account criteria that go beyond the mere number or size of the exposures not included, such as the type of risks involved or the evolving nature of banking activity. (BCBS 239, "Scope and initial considerations" section)

A scope that expands, not shifts

Comparing the two texts, one thing stands out: the ECB did not redefine BCBS 239's scope in 2024, it made it operational. Where the Basel Committee spoke in 2013 of "risk management data" and "key models", the ECB in 2024 lists precise regulatory templates (FINREP, COREP, Pillar 3), specifically named model types (IFRS 9, VaR), and requires explicit identification, indicator by indicator, of the underlying critical data. For an institution still asking today "does this apply to my report / my model / my indicator?", section 3.2 of the RDARR Guide gives the most concrete answer.

This article is based exclusively on two documents: the Basel Committee's 14 BCBS 239 principles (January 2013) and the ECB's RDARR Guide (May 2024), both available on the Resources page.