BCBS 239 Principles - Basel Committee, January 2013

The 14 BCBS 239 principles (Basel Committee, January 2013), grouped into their original four pillars and detailed principle by principle. Click a clause to expand it. The ECB's complementary expectations are presented on the "RDARR Guide" page.

0 / 14 principles viewed
No principle matches this search.

A few key dates to place the 14 principles in context — the full timeline, told across two threads (the Basel Committee's standard and ECB supervision), is detailed on the Timeline page.

2007–2008
Global financial crisis: banks struggle to quickly aggregate their risk exposures, worsening their own difficulties and those of the financial system.
January 2013
The Basel Committee publishes the 14 BCBS 239 principles on risk data aggregation and risk reporting.
2016
G-SIBs designated in 2011 or 2012 must comply with the principles. The ECB launches a thematic review of 25 significant institutions.
May 2018
The ECB publishes its thematic review report: no institution in the sample, including the G-SIIs, fully follows the BCBS 239 principles.
June 2019
The Chair of the ECB's Supervisory Board sends a letter to all significant institutions, demanding substantial progress.
2023
RDARR is the worst-rated internal governance sub-category of the SREP cycle; the ECB observes an ever-growing number of outstanding supervisory measures.
May 2024
The ECB publishes its "Guide on effective risk data aggregation and risk reporting", detailing seven minimum supervisory expectations.

→ Full timeline: from the 2007-2008 crisis to the 2024 Guide

I

Overarching governance and infrastructure

A bank must have a strong governance framework, data architecture and robust IT infrastructure: these are the preconditions for compliance with all the other principles. The board of directors oversees how senior management implements all of the principles, according to a timetable agreed with supervisors.

BCBS 239 requirementPrinciple 1Guide cross-refs: §3.1 · §3.3 · §3.7

A bank's risk data aggregation capabilities and risk reporting practices should be subject to strong governance arrangements consistent with other principles and guidance established by the Basel Committee.

  • The board and senior management should promote the identification, assessment and management of data quality risks, with service level standards for both in-house and outsourced processes, and policies on data confidentiality, integrity and availability.
  • The board and senior management should review and approve the group's risk data aggregation and reporting framework, and ensure that adequate resources are devoted to it.
  • Capabilities should be fully documented and subject to high-standard independent validation, carried out by staff with specific IT, data and reporting expertise.
  • They should be considered as part of any new initiative: acquisitions, divestitures, new products, or changes to processes or IT systems. For a material acquisition, the board should explicitly assess the impact on aggregation capabilities before deciding.
  • The group structure should not hinder data aggregation at a consolidated level or at any relevant level (sub-consolidated, jurisdiction): capabilities should remain independent from legal and geographical organisation choices.
  • Senior management should be fully aware of the limitations preventing full aggregation — in terms of coverage, technical or legal constraints — and ensure that the IT strategy provides for solutions.
  • The board is responsible for determining its own reporting requirements and should be aware of the limitations of the reports it receives, as well as the bank's compliance status with the principles.
Role: board of directors & senior management · BCBS 239 §26-31
BCBS 239 requirementPrinciple 2Guide cross-refs: §3.4

A bank should design, build and maintain data architecture and IT infrastructure which fully supports its risk data aggregation capabilities and risk reporting practices not only in normal times but also during times of stress or crisis, while still meeting the other Principles.

  • Aggregation and reporting capabilities should be directly factored into business continuity planning and be subject to a business impact analysis.
  • The bank should establish group-wide integrated data taxonomies and architecture, including metadata (data characteristics), as well as unique identifiers and/or harmonised naming conventions for legal entities, counterparties, customers and accounts.
  • Banks do not necessarily need a single data model, but should have robust automated reconciliation procedures where multiple models coexist.
  • Roles and responsibilities for data ownership and quality should be established for both business and IT functions. Owners, in partnership with risk managers, should ensure adequate controls throughout the data lifecycle and the technology infrastructure.
Focus: systems & business continuity · BCBS 239 §32-34
See also — RDARR Guide:§4 Integrated data architecture
II

Risk data aggregation capabilities

Banks must develop and maintain strong aggregation capabilities so that risk management reports reliably reflect risks. These four principles must be met simultaneously, without trade-offs that would undermine decision-making.

BCBS 239 requirementPrinciple 3Guide cross-refs: §3.3 · §3.5

A bank should be able to generate accurate and reliable risk data to meet normal and stress/crisis reporting accuracy requirements. Data should be aggregated on a largely automated basis so as to minimise the probability of errors.

  • Controls over risk data should be as robust as those applicable to accounting data.
  • Where the bank relies on manual processes and desktop applications (spreadsheets, databases), it should put in place effective mitigants (end-user computing policies) and controls applied consistently.
  • Risk data should be reconciled with the bank's sources, including accounting data where relevant, to ensure its accuracy.
  • The bank should strive towards a single authoritative source for each type of risk.
  • Risk personnel should have sufficient access to data to be able to aggregate, validate and reconcile it against risk reports.
  • A 'dictionary' of the concepts used should ensure data is defined consistently across the organisation.
  • An appropriate balance should be struck between automated and manual systems: human intervention may be warranted where professional judgement is required, but a higher degree of automation is desirable to reduce the risk of errors.
  • All aggregation processes, whether automated or manual, should be documented and explained, including the appropriateness of manual workarounds and their criticality to data accuracy.
  • Supervisors expect banks to measure and monitor data accuracy and to have escalation channels and action plans in place to remedy poor data quality.
Keyword: fewer manual workarounds · BCBS 239 §36-40
BCBS 239 requirementPrinciple 4Guide cross-refs: §3.2

A bank should be able to capture and aggregate all material risk data across the banking group. Data should be available by business line, legal entity, asset type, industry, region and other groupings, as relevant for the risk in question, that permit identifying and reporting risk exposures, concentrations and emerging risks.

  • Aggregation capabilities should cover all material risk exposures, including off-balance-sheet commitments.
  • The bank is not required to express all forms of risk in a common metric, but each system should clearly set out the approach used to aggregate exposures, so that the board and senior management can properly assess the results.
  • Supervisors expect the data produced to be materially complete; any exceptions should be identified and explained.
Keyword: scope coverage · BCBS 239 §41-43
BCBS 239 requirementPrinciple 5Guide cross-refs: §3.6

A bank should be able to generate aggregate and up-to-date risk data in a timely manner while also meeting the principles relating to accuracy and integrity, completeness and adaptability. The precise timing will depend upon the nature and potential volatility of the risk being measured, its criticality to the overall risk profile of the bank, as well as the bank-specific frequency requirements for risk management reporting, under both normal and stress/crisis situations.

  • Different types of data should be capable of being produced at different speeds; some risk data may be needed faster in a crisis situation.
  • Banks should build their systems so as to be able to rapidly produce aggregated risk data during periods of stress for all critical risks.
  • Examples of critical risks cited: aggregated credit exposure to a large corporate borrower; counterparty credit risk exposures (derivatives in particular); trading exposures, positions, operating limits and market concentrations by sector and region; liquidity risk indicators (cash flows, funding); time-critical operational risk indicators (systems availability, unauthorised access).
Keyword: speed during a crisis · BCBS 239 §44-47
BCBS 239 requirementPrinciple 6

A bank should be able to generate aggregate risk data to meet a broad range of on-demand, ad hoc risk management reporting requests, including requests during stress/crisis situations, requests due to changing internal needs and requests to meet supervisory queries.

  • This requires flexible aggregation processes, enabling rapid assessment and decision-making.
  • Capabilities to customise to users' needs (dashboards, key takeaways, anomalies) and to drill down, in order to quickly produce summary reports.
  • The ability to incorporate changes in the organisation of the business and/or external factors that influence the risk profile.
  • The ability to incorporate changes in the regulatory framework.
  • Example given: the bank should be able to quickly aggregate its credit exposures by country as of a given date, from a list of countries, as well as its credit exposures by industry, across all business lines and geographic areas.
Keyword: ad hoc flexibility · BCBS 239 §48-50
III

Risk reporting practices

Accurate, complete and timely data is the foundation of effective risk management, but it is not enough on its own: the right information also needs to reach the right people at the right time. These five principles must not be met at the expense of one another.

BCBS 239 requirementPrinciple 7

Risk management reports should accurately and precisely convey aggregated risk data and reflect risk in an exact manner. Reports should be reconciled and validated.

  • To ensure accuracy, the bank should maintain, at a minimum: defined requirements and processes to reconcile reports with the underlying risk data; automated and manual consistency and reasonableness checks, with an inventory of the validation rules applied; integrated procedures to identify, report and explain data errors or integrity weaknesses through exception reports.
  • Approximations (model results, scenario analyses, stress tests) are an integral part of risk reporting and risk management; reliability requirements should nonetheless be established for these approximations.
  • Senior management should set accuracy and precision requirements for both normal and stress/crisis reporting, including for critical position and exposure information.
  • Supervisors expect banks to consider accuracy requirements analogous to the concept of accounting materiality: if an omission or misstatement could influence users' risk decisions, it may be considered material.
Keyword: reporting fidelity · BCBS 239 §52-56
BCBS 239 requirementPrinciple 8

Risk management reports should cover all material risk areas within the organisation. The depth and scope of these reports should be consistent with the size and complexity of the bank's operations and risk profile, as well as the requirements of the recipients.

  • Reports should include exposures and positions for all significant risk areas (credit, market, liquidity, operational) and their main components (single name, country, industry for credit risk, for example), as well as associated risk measures (regulatory and economic capital).
  • They should identify emerging risk concentrations, place the information in the context of limits and risk appetite, and propose recommendations for action where relevant.
  • They should indicate the status of measures decided by the board or senior management to reduce a risk or address a specific risk situation, including the ability to track emerging trends through forward-looking forecasts and stress tests.
  • Supervisors expect reports to provide a forward-looking assessment of risk, not just past or current data.
Keyword: risk coverage · BCBS 239 §57-60
BCBS 239 requirementPrinciple 9

Risk management reports should communicate information in a clear and concise manner. Reports should be easy to understand yet comprehensive enough to facilitate informed decision-making, and include meaningful information tailored to the needs of the recipients.

  • Reports should present an appropriate balance between risk data, analysis, interpretation and qualitative explanations; the higher up the organisation, the greater the degree of aggregation — and therefore of qualitative interpretation — required.
  • Reporting policies and procedures should recognise the differing information needs of the board, senior management and other levels of the organisation (risk committees in particular).
  • The board, as a key recipient, is responsible for determining its own reporting requirements and should ensure it receives information that allows it to fulfil its governance mandate; it should alert senior management if reports do not meet its requirements.
  • Senior management is also responsible for determining its own reporting requirements in order to fulfil its management mandate.
  • The bank should develop an inventory and classification of risk data items, including a reference to the concepts used to prepare the reports.
  • Supervisors expect the bank to periodically confirm with recipients that the information aggregated and reported is relevant and appropriate, in both amount and quality.
Keyword: decision-ready readability · BCBS 239 §61-69
BCBS 239 requirementPrinciple 10Guide cross-refs: §3.6

The board and senior management (or other recipients as appropriate) should set the frequency of risk management report production and distribution. These requirements should reflect the needs of the recipients, the nature of the risk reported and the speed at which it can change, as well as the importance of reports for sound risk management and effective decision-making. Report frequency should increase during times of stress/crisis.

  • Report frequency varies according to the type of risk, the purpose pursued and the recipients.
  • The bank should periodically assess the purpose of each report and set production-time requirements, in both normal and stress/crisis situations.
  • It should regularly test its ability to produce accurate reports within established timeframes, particularly in stress/crisis situations.
  • Supervisors expect that, during periods of stress/crisis, all critical credit, market and liquidity position/exposure reports be available within a very short period to allow for an effective response; some information may need to be available immediately (intraday).
Keyword: fit-for-purpose cadence · BCBS 239 §70-71
BCBS 239 requirementPrinciple 11

Risk management reports should be distributed to the relevant parties while ensuring confidentiality is maintained.

  • Procedures should allow for the rapid collection and analysis of risk data, as well as timely distribution of reports to all appropriate recipients, balancing that speed against confidentiality requirements.
  • Supervisors expect the bank to periodically confirm that the relevant recipients actually receive their reports on time.
Keyword: right hands, right level · BCBS 239 §72-73
IV

Supervisory review, tools and cooperation

Supervisors play an essential role in monitoring and providing incentives for banks' implementation of the principles, as well as in assessing their overall effectiveness.

BCBS 239 requirementPrinciple 12

Supervisors should periodically review and evaluate a bank's compliance with the eleven Principles above.

  • Reviews should be incorporated into the regular programme of supervisory review and may be supplemented by thematic reviews covering multiple banks on a given topic.
  • Supervisors may test compliance through occasional short-deadline requests for information on selected risk issues, in order to assess the bank's ability to rapidly aggregate data and produce reports.
  • Supervisors should draw on reviews conducted by internal or external auditors to inform their compliance assessment, and may require work to be carried out by the bank's internal audit function or by independent experts.
  • They should test aggregation and report-production capabilities both in stress/crisis situations and in steady-state conditions, including in the event of a sudden sharp increase in business volumes.
Actor: national supervisors · BCBS 239 §75-77
BCBS 239 requirementPrinciple 13

Supervisors should have and use the appropriate tools and resources to require effective and timely remedial action by a bank to address deficiencies in its risk data aggregation capabilities and risk reporting practices. Supervisors should have the ability to use a range of tools, including Pillar 2.

  • Available tools include, among others: requiring remedial action; increasing the intensity of supervision; requiring an independent review by a third party such as an external auditor; and the possible use of Pillar 2 capital add-ons, both as a risk mitigant and as an incentive.
  • Supervisors should be able to set limits on a bank's risks or on the growth of its activities where aggregation and reporting deficiencies are assessed as causing significant weaknesses in risk management.
  • For new initiatives, supervisors may require that a bank's implementation plans ensure robust aggregation before allowing a new business venture or acquisition to proceed.
  • When a supervisor requires remedial action, it should set a timetable for completion and have escalation procedures in place to require more stringent or accelerated action if the bank does not adequately address the identified deficiencies.
Actor: supervisors — sanctions & deadlines · BCBS 239 §78-82
BCBS 239 requirementPrinciple 14

Supervisors should cooperate with relevant supervisors in other jurisdictions regarding the supervision and review of the Principles, and the implementation of any remedial action if necessary.

  • Effective cooperation and appropriate information-sharing between home and host authorities should contribute to the robustness of a bank's risk management practices across its operations in multiple jurisdictions.
  • This cooperation can take the form of information-sharing within the limits of applicable law, as well as bilateral or multilateral discussions, in particular through supervisory colleges, regular meetings, calls and email exchanges.
  • Supervisors should exchange views on the quality of aggregation capabilities across different parts of the group, including any cross-border obstacles, in order to quickly identify significant concerns and respond to them effectively.
Actor: home/host cooperation · BCBS 239 §83-85