BCBS 239: the principles for risk data aggregation and risk reporting

BCBS 239 is the Basel Committee's standard on how banks collect, aggregate and report their risk data. It asks a simple question with an expensive answer: can the bank tell its management, quickly and correctly, how much risk it carries, also in a crisis?

Why the principles exist

The Basel Committee published the principles on January 9, 2013. The crisis that began in 2007 had shown that many large banks were unable to aggregate their risk exposures and spot concentrations fully, quickly and accurately. The principles address global systemically important banks, and national supervisors may apply them to domestic systemically important banks as well.

Risk data aggregation means defining, gathering and processing risk data according to the bank's reporting needs, so it can measure its performance against its risk appetite. According to Wikipedia, banks designated as global systemically important by November 2012 had to comply from January 1, 2016.

The 14 principles in four groups

The standard has 14 principles. Two cover overarching governance and infrastructure: the board and senior management own the data framework, and the data architecture and IT infrastructure must support aggregation in normal times and under stress. Four cover aggregation capabilities: accuracy and integrity, completeness, timeliness and adaptability. Five cover risk reporting: accuracy, comprehensiveness, clarity and usefulness, frequency, and distribution. Three are addressed to supervisors, on review, remedial action and cooperation.

The principles do not prescribe a technology. They describe outcomes, so two banks can comply with very different architectures, as long as each can show the outcome when a supervisor tests it.

The ECB guide and German supervision

The European Central Bank consulted on a guide on effective risk data aggregation and risk reporting from July to October 2023. It names seven areas: the responsibility of the management body, the scope of the data governance framework, roles and responsibilities for data governance, a group-wide integrated data architecture, effective data quality controls, timely internal risk reporting, and implementation programs. The ECB wrote that adequate capabilities in this area were still the exception, after a 2016 review of 25 significant banks had found serious weaknesses.

Deloitte reports high-severity findings in inspections and notes that risk data aggregation sits among the ECB's supervisory priorities. For banks that BaFin supervises, MaRisk asks in AT 7.2 for effective processes that secure data quality for the material risk types, and in AT 4.4.1 for unrestricted access of the risk control function to all risk data it needs.

Upcoming events on risk and compliance

What are the 14 principles of BCBS 239?

Governance (1) and data architecture and IT infrastructure (2); accuracy and integrity (3), completeness (4), timeliness (5) and adaptability (6) of aggregation; accuracy (7), comprehensiveness (8), clarity and usefulness (9), frequency (10) and distribution (11) of reports; and supervisory review (12), remedial actions (13) and home and host cooperation (14).

Does BCBS 239 apply to smaller banks in Germany?

Not as such. The principles target systemically important banks, and the ECB applies its guide to the significant institutions it supervises. Smaller German banks meet the same questions in a lighter form through MaRisk, whose rules on data quality and risk reporting apply to every institution.

What is data lineage in BCBS 239?

Lineage is the documented path of a number from its source system through every transformation to the risk report. Without it a bank cannot show that a figure is accurate and complete, which is why supervisors ask for it when they test the aggregation principles. It is also the part where data engineering and risk management have to work on the same model.

BCBS 239 and Finance Loop

Finance Loop connects the finance, IT and AI communities, and BCBS 239 is a project where risk managers and data engineers have to agree on one data model. Finance Loop co-organized the Frankfurt Quantum Finance Forum at Frankfurt School with the Deutsche Bundesbank and IBM, where risk modeling was on the agenda, and holds events in Frankfurt, Munich, Berlin and Hamburg.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.