BCBS 239 and RDARR Glossary
The technical terms in this dossier, defined from the two reference documents.
No term matches this search.
- Risk data aggregation
- The process of defining, gathering and processing risk data in accordance with the bank's risk profile, to measure its performance against the established risk tolerances. (BCBS 239, §8)
- Data lineage (traceability)
- Information on a piece of data's path and transformation, from its capture to its final use; it allows quality controls to be verified, the origin of an incident to be traced, and external validation to be ensured. (ECB Guide, section 3.4)
- G-SIB
- Global Systemically Important Bank — designated by the Financial Stability Board (FSB). Must comply with BCBS 239 since January 2016. (BCBS 239, §14)
- D-SIB
- Domestic Systemically Important Bank — the Basel Committee strongly recommends that national supervisors also apply the principles to them, three years after their designation. (BCBS 239, §15)
- Manual workaround
- The use of human-based processes or tools (e.g. spreadsheets) to transfer or alter data; to be documented and governed by controls such as the four-eyes principle. (BCBS 239, §38; ECB Guide, section 3.5)
- Data architecture
- An integrated set of rules, taxonomies and standards — including a data dictionary and a metadata repository — defining how data is collected, stored and structured. (BCBS 239, Principle 2; ECB Guide, section 3.4)
- RDARR
- Risk Data Aggregation and Risk Reporting — the abbreviation used by the ECB for risk data aggregation and risk reporting. (ECB Guide)
- Critical data element
- Data used to calculate a key risk indicator and having a direct or significant impact on its value or method of calculation. (ECB Guide, footnote 19)
- Validation function (2nd line of defence)
- A function independent of the operational units, responsible for verifying that RDARR processes function as intended; distinct from internal audit. (BCBS 239, §29; ECB Guide, section 3.3)
- Internal audit (3rd line of defence)
- A function carrying out periodic independent reviews of the validation function, the data governance framework and RDARR capabilities. (ECB Guide, section 3.3)
- SREP
- Supervisory Review and Evaluation Process — the ECB's annual supervisory review process; RDARR was its worst-rated internal governance sub-category in 2023. (ECB Guide, footnote 9)
- Period of stress
- A crisis or market-shock situation during which aggregation and reporting capabilities must remain reliable and fast, or even faster than under normal conditions. (BCBS 239, Principles 5 and 6)
- Accuracy
- Closeness of agreement between a measurement, record or representation and the value actually measured, recorded or represented; this definition applies to both risk data aggregation and risk reports. (BCBS 239, Annex 1)
- Adaptability
- The ability of risk data aggregation capabilities to change, or be changed, in response to changed internal or external circumstances. (BCBS 239, Annex 1)
- Approximation
- A result that is not necessarily exact, but acceptable for its given purpose. (BCBS 239, Annex 1)
- Clarity
- The ability of risk reporting to be easily understood and free from indistinctness or ambiguity. (BCBS 239, Annex 1)
- Completeness (of data)
- Availability of relevant risk data aggregated across all of the firm's constituent units (legal entities, business lines, jurisdictions, etc.). (BCBS 239, Annex 1)
- Comprehensiveness (of reports)
- The extent to which risk reports cover all risks relevant to the firm — to be distinguished from "Completeness", which concerns the data itself. (BCBS 239, Annex 1)
- Distribution
- Ensuring that the appropriate people or groups receive the relevant risk reports. (BCBS 239, Annex 1)
- Frequency
- The rate at which risk reports are produced over time. (BCBS 239, Annex 1)
- Integrity
- Freedom of risk data from unauthorised alteration or manipulation that compromises its accuracy, completeness or reliability. (BCBS 239, Annex 1)
- Precision
- Closeness of agreement between indications or measured values obtained by replicating a measurement on the same, or similar, objects under specified conditions. (BCBS 239, Annex 1)
- Reconciliation
- The process of comparing items or outcomes and explaining the differences found. (BCBS 239, Annex 1)
- Risk tolerance / risk appetite
- The level and type of risk a firm is able and willing to assume in its exposures and activities, given its business model and its obligations to stakeholders; generally expressed through both quantitative and qualitative means. (BCBS 239, Annex 1)
- Timeliness
- Availability of aggregated risk data within a timeframe that enables the bank to produce its risk reports at the established frequency. (BCBS 239, Annex 1)
- Validation (general definition)
- The process by which the correctness, or otherwise, of inputs, processing and outputs is identified and quantified. (BCBS 239, Annex 1)
- ICAAP
- Internal Capital Adequacy Assessment Process; data quality issues must be taken into account here, or risks may be underestimated. (ECB Guide, section 3.5)
- Pillar 2
- The strand of the Basel prudential framework relating to the supervisory review process; the Basel Committee has incorporated complementary guidance on data aggregation into it, and supervisors may use it, including through capital add-ons, in the event of RDARR shortcomings. (BCBS 239, introduction and Principle 13)
- Key Risk Indicator
- A risk metric appearing in internal, financial and supervisory risk reports as well as in models; its underlying critical data elements must be explicitly identified. (ECB Guide, section 3.2)
- End-user computing
- Applications developed or used directly by business users (spreadsheets and desktop databases in particular), outside of controlled IT systems; their full integration into data quality management policies is expected by the ECB. (ECB Guide, section 3.5)
- Root cause analysis
- An expected element of the data quality issues log, consisting of identifying the underlying cause of an observed anomaly. (ECB Guide, section 3.5)
- Management body
- The body carrying out an institution's supervisory and management functions, which may be exercised by a single body or by two separate bodies depending on the governance structure adopted. (ECB Guide, section 3.1; CRD, Article 88(1))
- CRD (Capital Requirements Directive)
- The European directive on capital requirements, whose application by banking supervision the ECB's RDARR Guide clarifies (notably Articles 74, 76, 88(1) and 91). (ECB Guide, Annex 1)
- Data quality issues log
- An up-to-date overview of data quality issues and limitations, including a severity assessment, root cause analysis, a quantitative impact assessment, remediation responsibilities and associated deadlines. (ECB Guide, section 3.5)
- ICT and security risk
- The risk of loss due to a breach of confidentiality, a failure of the integrity of systems and data, unavailability of systems, or an inability to evolve IT within reasonable timeframes and costs; includes risks linked to cyberattacks or inadequate physical security. (EBA guidelines cited in the ECB Guide, Annex 1)
- Materiality
- The concept that data or a report may exceptionally exclude information only if that omission does not affect the bank's decision-making process — that is, if decision-makers, in particular the board and senior management, would not have been influenced by or made a different decision had they had the correct information. (BCBS 239, "Scope and initial considerations" section)
- EUDA (End-user developed applications)
- Applications developed directly by business users, to be distinguished from end-user computing (EUC) taken in the broad sense; subject to the same expectations of full integration into data quality management policies and processes. (ECB Guide, section 3.5; ECB consultation feedback statement, May 2024)
- Full integration
- Applying the same data quality standards and controls to EUC/EUDA applications as to a normal application, from a functional and logical standpoint — without necessarily requiring technical migration; controls should focus on the points most exposed to risk rather than being uniform across all applications. (ECB consultation feedback statement, May 2024, Table 5)
- Proportionality
- The principle that the application of RDARR requirements must reflect the size, nature and complexity of each institution's operations and risk profile; it allows both extending the scope of the RDARR Guide to institutions not explicitly targeted by BCBS 239, and adjusting or removing certain requirements deemed disproportionate. (BCBS 239, "Scope and initial considerations" section; ECB Guide, sections 3.2 and 3.3)
Sources
Content established exclusively from: Basel Committee on Banking Supervision, "Principles for effective risk data aggregation and risk reporting", January 2013 — and European Central Bank / Banking Supervision, "Guide on effective risk data aggregation and risk reporting", May 2024.