Drafting the RDARR Guide

The ECB's 2023 consultation: from draft Guide to final Guide

Before publishing its Guide on effective risk data aggregation and risk reporting (May 2024), the ECB submitted its draft to an 11-week public consultation in the summer of 2023. 308 comments were received, presented in the feedback statement as 186 blocks, each followed by the ECB's response and its decision on whether to amend the Guide. This page summarises the process and, theme by theme, what the ECB took away from it.

24 July 2023
Public consultation launched

Announced duration: 11 weeks. The European Parliament is informed.

15 September 2023
Stakeholder meeting

More than 300 online participants engage with the ECB; their questions are covered in the feedback statement.

6 October 2023
Consultation closes

308 comments received, covering the seven sections of Chapter 3 of the draft Guide.

May 2024
Publication of the Guide and the feedback statement

The final Guide and the feedback statement (186 comment blocks, with the ECB's response) are published together.

308
Comments received
186
Blocks analysed
70
Amendments to the Guide · ≈38%
11
Weeks of consultation

The comments came from financial institutions, European banking associations (EBF, ESBG, EACB, AFME, German Banking Industry Committee…), advisory firms and non-governmental organisations. Each block in the feedback statement indicates the respondent(s) concerned.

Scope of applicationDoes the Guide go beyond risk data? Financial reports, models, indicators.
Management body responsibilitiesWho is responsible, how to delegate, individual or collective responsibility.
Data governanceRoles of data owners, the central governance function and validation.
Data lineageWhat granularity of traceability, for which data, at what level of detail.
Data qualityDimensions, indicators, external sources, spreadsheets (EUC/EUDA), existing controls.
Timeliness of reportingThe 20-business-day rule and timely response.
Consistency with BCBS 239Does the Guide create new requirements, or does it merely clarify?
ImplementationRemediation programmes, resources, terminology and glossary.

A selection of the most significant exchanges, organised by theme. The numbers refer to the May 2024 feedback statement ("Feedback statement on responses to the public consultation"). Of the 186 blocks, 70 led to an amendment of the Guide (≈38%).

Scope of application
Table 3 · No. 18Guide amended
The request. Does the scope of section 3.2 deliberately go beyond risk data? Should data used for financial and supervisory reporting be included?
The ECB's response. Yes: BCBS 239 considers that other processes (financial, supervisory) can benefit from applying the principles. The scope is threefold — risk, financial and supervisory reports, key internal models, and risk indicators — defined proportionately by each institution. The term "management information system" is removed from the final Guide to avoid too broad a reading.
Table 3 · No. 17Guide amended
The request. Given the breadth of the scope, can a bank internally define reasonable consistency checkpoints and limit the extent of data lineage?
The ECB's response. It is up to institutions to define the scope proportionately, on a case-by-case basis; complete end-to-end data lineage is expected for risk indicators and their critical data elements within scope. A paragraph on proportionality is added to the final Guide.
Management body responsibilities
Table 2 · No. 1 and 4Guide amended
The request. Who is the "management body"? Is a designated individual responsibility realistic?
The ECB's response. The "management body" is defined in accordance with the CRD and the EBA guidelines on internal governance. Responsibility is exercised by one or two individuals (e.g. the CRO, or the CRO and the CFO); where no suitable member is available, a senior manager may be designated provided they have a direct reporting line to the management body. Delegation does not relieve the body of its collective responsibility.
Table 2 · No. 21Position maintained
The request. Replace "confirming" (the scope of reports) with "monitoring" in paragraph 3.1.6.
The ECB's response. No: "confirming" is consistent with paragraph 69 of BCBS 239 Principle 9. Not changed.
Data governance and validation
Table 4 · No. 39 and 40Guide amended
The request. Should the independent validation function be split into two separate units?
The ECB's response. No: validation is expected as the second line of defence, but it is not expected to be split into two functions. The relevant paragraph is amended in the final Guide.
Table 4 · No. 9Position maintained
The request. Is a single data owner responsible for the entire chain, from the transaction to the VaR calculation?
The ECB's response. No: the data owner is the function responsible for capture; for derived data, the calculating function owns the new information but not the underlying data. Different data owners, each focused on part of the chain, share the responsibilities; service-level agreements between data owners are essential.
Data lineage
Table 5 · No. 17Clarified
The request. Complete, up-to-date data lineage for all data is impossible to achieve and maintain at large banks.
The ECB's response. Data lineage can be achieved through a layered approach (an overview of the data landscape, documentation of systems, interfaces and mapping tables). End-to-end lineage is not expected for all data, but for the risk indicators and their critical data elements referred to in paragraph 3.2.3; creating lineage on demand is not sufficient, particularly during periods of stress.
Data quality
Table 6 · No. 8Guide amended
The request. Is "adaptability" a measurable dimension of data quality?
The ECB's response. No: adaptability is an overall capability of the aggregation function, not an observable data quality dimension like completeness. The dimension is removed from the final Guide.
Table 6 · No. 21Guide amended
The request. Incorporate root cause analysis and proof of resolution into the data quality issue remediation process.
The ECB's response. Yes: root cause analysis and evidence of resolution are seen as an integral part of remediation and are now explicitly mentioned in the final Guide.
Table 6 · No. 27Guide amended
The request. Must new quality controls be created when existing control frameworks already cover the scope?
The ECB's response. No: institutions may reuse their existing control frameworks (e.g. accounting, SOX controls) where they serve BCBS 239's objectives, without duplicating them. A reference to integrating existing controls is added to the Guide.
Timeliness of reporting
Table 7 · No. 4 and 5Position maintained
The request. A 20-business-day limit for all regular reports is inappropriate and unworkable (including for the ICAAP); production should balance speed and comprehensiveness.
The ECB's response. The ECB maintains its expectation: a risk report that takes more than 20 business days to produce no longer allows management to react in a timely manner. The rule applies to internal reporting (not to the submission of ICAAP results at end-March); flash reports should be regularly reconciled with final figures, with measures taken in the event of material discrepancies.
Implementation and consistency with BCBS 239
Table 8 · No. 2Guide amended
The request. The Guide should include a uniform data glossary defining key concepts (risk data, data owner, data steward, end-user computing, data lineage).
The ECB's response. No glossary (to avoid duplicating terminology from other sources), but footnotes are added throughout the Guide to clarify certain definitions.
Table 1 · No. 12Position maintained
The request. Will the Guide lead to an update of BCBS 239?
The ECB's response. No: the Guide neither replaces nor updates the BCBS 239 principles; it complements them and clarifies their implementation from a banking supervision perspective.
Table 1 · No. 1Partially accepted
The request. The Guide should require the collection and aggregation of climate data (high-impact sectors).
The ECB's response. References to the ECB's publications on climate and environmental risks are added to the final Guide, but no mandatory climate requirement is introduced: the Guide does not address RDARR practices for any particular type of risk.

A methodological note. The 186 blocks in the feedback statement cover far more than this selection: terminology detail, the roles of senior management and report owners, metadata granularity, sample-based controls, the integration of spreadsheets (EUC/EUDA), data quality risk in the ICAAP/ILAAP, examples of external data, and much more. The full responses are available in the ECB's consultation feedback statement (May 2024), linked on the Resources page.