RDARR Guide — ECB, May 2024
This European Central Bank guide complements the 14 BCBS 239 principles: it is not a fifth pillar, but a separate document detailing the ECB's minimum supervisory expectations for institutions under its direct supervision.
The ECB's RDARR Guide — May 2024
In 2016, the ECB carried out a thematic review of 25 significant institutions, based on the BCBS 239 principles. The 2018 report found that none of them, including globally systemically important institutions, fully complied with these principles. After sending a letter to all significant institutions in 2019 demanding progress, the ECB published a guide in May 2024 detailing seven minimum supervisory expectations, which clarify implementation of the Basel Committee's principles — without replacing them.
↗ See the full timeline: from the 2007-2008 crisis to the 2024 Guide · The 2023 consultation and its 308 comments
The management body should take full responsibility for risk data quality and governance, make RDARR a priority with sufficient resources, oversee remediation programmes, designate one or two of its members as responsible for the data governance framework, and ensure that its members and the heads of internal control functions have sufficient knowledge of data management, IT and the associated risks.
Ref. ECB Guide, section 3.1 · CRD art. 88(1)The data governance framework should cover all significant legal entities, all risks and business lines, and the entire data lifecycle. At a minimum, it should encompass internal risk reports, published financial reports, supervisory reports (FINREP/COREP, stress tests, Pillar 3), key internal models and key risk indicators.
Ref. ECB Guide, section 3.2Each institution should define data owners responsible for key risk indicators, a central data governance function, an independent validation function as the second line of defence, and an internal audit function as the third line of defence carrying out periodic independent reviews.
Ref. ECB Guide, section 3.3 — three lines of defenceAn integrated, documented data architecture should be implemented group-wide, including data taxonomies (dictionary, metadata repository), validation rules, and complete, up-to-date data lineage at the level of each data attribute, from capture through to reporting.
Ref. ECB Guide, section 3.4Data quality policies should cover at least accuracy, integrity, completeness and timeliness, with automated controls, quality indicators, an issues log with root cause analysis, the integration of end-user-developed tools, and the inclusion of data quality risks in the ICAAP.
Ref. ECB Guide, section 3.5The frequency and production time of reports should allow for a timely response. The ECB considers that a monthly or quarterly report taking more than 20 business days to produce generally does not allow for an adequate response; some institutions observed needed 40 business days or more.
Ref. ECB Guide, section 3.6 — benchmark: 20 business daysInstitutions not yet following BCBS 239 good practices should put in place remediation programmes with adequate project governance, including clearly defined remedial actions, targets, milestones, roles and responsibilities, under the oversight of one or two members of the management body.
Ref. ECB Guide, section 3.7