BCBS 239, ten years on: why the ECB still considers implementation insufficient
In 2013, the Basel Committee published its 14 principles on risk data aggregation and risk reporting — BCBS 239. Eleven years later, in May 2024, the European Central Bank in turn published a guide detailing seven minimum supervisory expectations on the same subject. Between the two texts, one question deserves to be asked: why did the ECB have to come back to this?
A finding born of the 2007-2008 crisis
The Basel Committee's text starts from a simple diagnosis: one of the most significant lessons of the financial crisis that began in 2007 is that banks' IT architectures and data frameworks were inadequate to support broad financial risk management. Many institutions were unable to quickly and accurately aggregate their risk exposures, or identify their concentrations, at group level, across business lines and legal entities. Some banks were unable to properly manage their risks simply because of weak aggregation capabilities and reporting practices — with severe consequences, both for those banks and for the stability of the financial system as a whole. (BCBS 239, introduction)
It was the Financial Stability Board (FSB) that recommended, in November 2011, developing a set of supervisory expectations to bring systemic institutions' data aggregation capabilities to a level that would give supervisors, the banks themselves and other data users confidence in the accuracy of the reports produced. The FSB had already set the deadline: early 2016 for G-SIBs — a date chosen because it coincides with the start of their added loss-absorbency requirement taking effect. (BCBS 239, introduction)
The foundation: four pillars, fourteen principles
Published in January 2013, BCBS 239 organises its expectations into four pillars: overarching governance and infrastructure, risk data aggregation capabilities, risk reporting practices, and supervisory review with its supervisory cooperation tools. The text is primarily addressed to Global Systemically Important Banks (G-SIBs), with a January 2016 deadline for institutions designated in 2011 or 2012, and a three-year window from designation for those designated subsequently. The Basel Committee strongly recommends that national supervisors apply the same principles to Domestic Systemically Important Banks (D-SIBs), three years after their designation. (BCBS 239, §14-15; the details of the 14 principles are available here)
The stated objectives are concrete: enhancing the reporting infrastructure used by the board and senior management, making decision-making more reliable across the banking organisation, enabling a consolidated view of exposures at group level, reducing the probability and severity of losses arising from risk management weaknesses, and speeding up how quickly information is available for decision-making. (BCBS 239, "Objectives" section)
2016: the ECB goes to check on the ground
The ECB did not passively wait for the 2016 deadline. That very year, it launched a thematic review of risk data aggregation and risk reporting (RDARR), covering a sample of 25 significant institutions. This review assessed banks' overall governance, data aggregation capabilities and reporting practices, drawing directly on the BCBS 239 principles. It was supplemented by an extended benchmarking exercise and two additional analyses: a "data lineage" exercise on credit risk, and a "fire drill" exercise on liquidity risk — in other words, a full-scale test of banks' ability to rapidly produce reliable data in an emergency situation. (ECB Guide, introduction)
2018: an unequivocal finding, even for the largest banks
The results of this thematic review, combined with those of on-site inspections, revealed gaps in the effectiveness of data governance frameworks. The ECB's conclusion is stark: none of the significant institutions in the sample — including those classified as globally systemically important — fully followed the BCBS 239 principles. Serious weaknesses in RDARR practices were therefore identified. (ECB Guide, introduction)
2019: a letter to all significant institutions
The problems identified were followed up through dedicated on-site inspections, as part of the SREP and ongoing supervision. But observed progress stalled on several key deficiencies: the effectiveness of governance arrangements, risk data architectures and the associated IT infrastructure. Faced with this stagnation, the ECB sent a letter in 2019 to all significant institutions under its direct supervision within the Single Supervisory Mechanism (SSM), urging them to make substantial and rapid improvements, and to implement the integrated reporting solutions considered industry best practice. (ECB Guide, introduction)
2024: the RDARR Guide, or the end of tolerance
Despite this strengthened supervisory vigilance, the ECB concludes that the progress made by significant institutions remains, to date, broadly insufficient. RDARR has not received an appropriate level of attention, has not been properly steered, and numerous structural deficiencies remain unaddressed. Adequate RDARR capabilities remain the exception, and full adherence to the BCBS 239 principles has yet to be achieved. (ECB Guide, introduction)
It is this finding that led the ECB to publish, in May 2024, its Guide on risk data aggregation and risk reporting — not a fifth pillar or a rewrite of BCBS 239, but a document setting out the ECB's minimum supervisory expectations, built around seven areas: management body responsibilities, scope of application, the data governance framework, integrated data architecture, group-wide data quality management, timeliness of internal reporting, and the effectiveness of implementation programmes. (the details of the 7 areas are available here)
One editorial choice of the Guide deserves to be highlighted: it devotes its very first section to management body responsibilities — that is, to the board and senior management. This is not incidental: the text explicitly states that the Guide's content prioritises project management and the role of the management body, because these two elements were identified as the root causes of the insufficient progress observed so far. In other words, for the ECB, the problem is not primarily technical — it is primarily a matter of steering and prioritisation at the highest level. (ECB Guide, introduction)
What is actually at stake for institutions
The Guide is not merely a statement of intent. The ECB explicitly states that it is stepping up its intrusiveness as part of annual SREP assessments and more targeted engagement. If the qualitative requirements and associated deadlines are not met by institutions, or if material gaps breaching the applicable framework are found, the matter can be taken further — up to the imposition of enforcement measures, penalties and capital add-ons. Since the management body is responsible for implementing effective and prudent governance arrangements, deficiencies in this area can also lead to a fit-and-proper reassessment of the responsible members, and, in the most serious cases, to their removal. (ECB Guide, "Supervisory approach" section)
Ten years after BCBS 239 was published, the ECB's message is therefore unambiguous: risk data aggregation is no longer a second-tier IT project, but a governance issue tracked at the highest supervisory level — with direct consequences for prolonged inaction.
This article is based exclusively on two documents: the Basel Committee's 14 BCBS 239 principles (January 2013) and the ECB's RDARR Guide (May 2024), both available on the Resources page.