Banking
BCBS 239: the unfinished work of risk data
The 2008 crisis revealed that many banks could not tell regulators (or themselves) what their total exposures were quickly enough. The Basel Committee on Banking Supervision responded with BCBS 239, fourteen principles requiring banks to govern their risk data properly, build systems that can aggregate it quickly, and report reliably even when markets are under stress.
A credit committee convenes at short notice during a period of market volatility. The head of risk requests a consolidated view of exposures across counterparties, geographies, and legal entities by the following morning. What arrives is a patchwork: some figures drawn directly from the core banking system, others manually compiled from spreadsheets of uncertain vintage, a third set still pending from an overseas subsidiary running on a separate platform. The numbers are reconciled overnight by a team of analysts. By the time the committee reconvenes, the market has moved and the consolidated figure is already outdated.
BCBS
BCBS 239: Principles for effective risk data aggregation and risk reporting, Paragraphs 14 and 15
View source ↗The Basel Committee on Banking Supervision (BCBS) documented exactly this pattern in the aftermath of the 2008 financial crisis. Its review of major banks found that many could not produce accurate, timely, consolidated risk data when it mattered most. Boards and senior management lacked the information needed to make sound decisions while supervisors lacked the visibility to assess true exposures. In January 2013, the Committee published BCBS 239, formally titled Principles for effective risk data aggregation and risk reporting, setting out 14 principles intended to address this.1
BCBS 239 became binding for global systemically important banks (G-SIBs) on 1 January 2016. The 2013 text also reached domestic systemically important banks (D-SIBs) from the start. Paragraph 15 “strongly suggested” that national supervisors apply the Principles to D-SIBs three years after designation, which is a recommendation to supervisors rather than a rule binding the banks.1
ECB Banking Supervision
Sound risk data reporting, key to better decision-making and resilience
View source ↗PRA
Thematic review of private equity related financing activities, Paragraphs 10 and 13
View source ↗The standard is still in effect and has not been replaced. What has shifted is how supervisors apply it. In Europe, the European Central Bank (ECB) launched a supervisory programme in 2022, written up as its May 2024 guide on risk data aggregation and reporting.2 It has since linked poor risk data aggregation directly to worse Supervisory Review and Evaluation Process (SREP) outcomes. The SREP overall score runs from 1, the lowest risk, to 4, the highest, so weak aggregation pushes a bank’s score up rather than down.3 In the UK, the Prudential Regulation Authority (PRA) has pressed the same point through thematic supervision rather than a dedicated data standard.4
What are the fourteen BCBS 239 principles?
BCBS 239 organises its 14 principles into four categories:
- Governance and infrastructure: the board and senior management must review and approve the firm’s risk data framework and ensure adequate resources are deployed to it. IT systems must be able to pull together all risk data at any time, including during periods of stress, not just at quarter-end.
- Risk data aggregation capabilities: data must be accurate, complete, timely, and adaptable. These requirements apply across the whole group and each legal entity.
- Risk reporting practices: reports must be accurate, thorough, and clear, and delivered at a frequency that matches the risk involved.
- Supervisory review: regulators assess G-SIB compliance as part of routine supervision and feed the results into their Pillar 2 (firm-specific capital) reviews.
Governance and infrastructure underpins all the other principles. A bank must establish integrated data taxonomies and a group-wide architecture, down to single identifiers for legal entities, counterparties and accounts, and a dictionary of the concepts used so that a term means the same thing across the group.
The common failure point under BCBS 239 is completeness under stress. A bank may achieve accuracy for data sourced from its core system while relying on manual processes for exposures held in overseas branches, the end user computing estate our companion piece examines.5
The reporting principles compound the completeness gap under stress. Reports must enable the board to form a view on whether the firm’s overall risk profile is within its appetite. A fancy presentation built on unreliable data does not satisfy BCBS 239. The standard is about the data infrastructure, not the dashboard that sits on top of it.
How banks have responded
BCBS
BCBS d559: Progress in adopting the Principles for effective risk data aggregation and risk reporting
View source ↗The BCBS’s November 2023 progress report on adoption of the principles found that of the 31 G-SIBs assessed, only two were fully compliant with all 14 principles. That assessment used data as of June 2022, six years after the expected date of compliance.6
The Basel Committee’s November 2023 progress report is blunter still on how little had changed: “there is not a single Principle that has been fully implemented across all banks”.6 The Committee attributes that to “lack of prioritisation, insufficient ownership by the board and senior management”, and to programmes that were “often underfunded, limited in scope”, which is a governance failure rather than a technical one.
In the UK
The PRA treats BCBS 239 as a live standard, not a legacy one. Its thematic review of private equity related financing, published on 23 April 2024, found that “a number of banks were unable to uniquely identify and systematically measure their combined credit and counterparty exposures linked to the PE sector within their overall risk data”, more than a decade after the principles were issued.4 The cause it identifies is organisational: exposures sit across many business lines, and a siloed approach to oversight does not add them up.4
The same infrastructure-first logic runs through the PRA’s model risk management expectations, Supervisory Statement SS1/23, effective 17 May 2024 and updated on 16 April 2026: a model is only as reliable as the data feeding it, so data suitability sits inside model development rather than beside it.7,
What good looks like under pressure
The value of sound data aggregation becomes clearest when conditions deteriorate rapidly. During the COVID-19 pandemic, the ECB reports that banks with mature aggregation capabilities could monitor how payment moratoria were phasing out and refine their risk appetite indicators accordingly. During the Russia-Ukraine conflict, the same banks adapted their country risk exposure assessments rapidly.3 In both cases, the ECB reports, the advantage was speed: new risk indicators, recalibrated limits and more frequent reporting, put in place while the stress was still developing.3
The regulatory expectation now is that data aggregation is a question of accountability, not architecture. What reviewers look for is a gap analysis, a remediation plan, and visible progress against it. Firms that have built that habit, not just the architecture, are the ones ready when the market moves again.
Frequently asked questions
What is BCBS 239?
BCBS 239 is the Basel Committee's standard on risk data, published in January 2013 and formally titled Principles for effective risk data aggregation and risk reporting. It sets out 14 principles requiring banks to govern their risk data, build systems that can aggregate it quickly, and report reliably even when markets are under stress.
Why was BCBS 239 written?
Because the 2008 crisis showed that many banks could not tell their supervisors, or themselves, what their total exposures were quickly enough. The Basel Committee's review of major banks after the crisis found that they could not produce accurate, timely, consolidated risk data when it mattered most. Boards and senior management lacked the information to make sound decisions, and supervisors lacked the visibility to assess true exposures.
Which banks does BCBS 239 apply to?
It became binding for global systemically important banks on 1 January 2016. Its scope also asks national supervisors to apply equivalent requirements to domestic systemically important banks within three years of designation, so the reach extends well beyond the G-SIB population.
What are the four groups of BCBS 239 principles?
Four categories organise the 14 principles. Governance and infrastructure puts the firm's risk data framework in front of the board for review and approval, with adequate resources behind it, and requires IT systems able to pull together all risk data at any time, including during stress, not only at quarter-end. Risk data aggregation capabilities require data to be accurate, complete, timely and adaptable, across the whole group and each legal entity. Risk reporting practices require reports to be accurate, thorough and clear, and delivered at a frequency matching the risk involved. Supervisory review covers how regulators assess compliance and feed the result into firm-specific capital decisions.
What does the governance and infrastructure group require?
It underpins everything else, which is why a firm that treats it as background rarely satisfies the rest. A bank must establish integrated data taxonomies and a group-wide architecture, down to single identifiers for legal entities, counterparties and accounts, and a dictionary of the concepts used. Ownership of risk data sits with the business and IT functions, in partnership with risk managers, while the board and senior management review and approve the framework and answer for the resources behind it. The requirement that systems can aggregate risk data at any time, including under stress, is what rules out an architecture that only works to a reporting calendar.
Where do banks most often fail BCBS 239?
On completeness under stress. A bank may achieve accuracy for data drawn from its core system while relying on manual processes for exposures held in overseas branches, and the gap only shows when a consolidated view is needed at short notice. The reporting principles compound it, because reports must enable the board to form a view on whether the firm's overall risk profile sits within its appetite. A polished presentation built on unreliable data does not satisfy the standard: BCBS 239 is about the data infrastructure, not the dashboard on top of it.
How compliant are banks with BCBS 239?
Not very, on the Basel Committee's own assessment. Its November 2023 progress report, BCBS d559, found that of the 31 G-SIBs assessed, only two were fully compliant with all 14 principles, using data as of June 2022. That is six years after the compliance date for that population. The Committee's recommendations in response centred on board ownership of data governance, more intrusive supervisory measures, and capital add-ons.
Is BCBS 239 still a live standard?
Yes. It has not been replaced, and what has changed is how supervisors apply it. The European Central Bank has run a supervisory programme on risk data aggregation since 2022 and feeds weaknesses into its Supervisory Review and Evaluation Process outcomes. In the UK, the PRA's UK Deposit Takers Supervision letter of 15 January 2026 names data risk as a supervisory priority and points firms to BCBS 239 as a base for managing it.
Why does risk data aggregation matter outside a compliance review?
Because its value shows when conditions deteriorate quickly. Strong aggregation capability let banks refine risk appetite indicators and monitor payment moratorium phasing through the COVID-19 pandemic, and adapt country risk exposure assessment rapidly following the invasion of Ukraine. In both cases the advantage was speed: they could add risk indicators, recalibrate limits and report more often while the stress was still developing.
What do supervisors look for now?
Accountability rather than architecture alone. What reviewers ask for is a gap analysis, a remediation plan, and visible progress against it. The firms that are ready when the market moves are the ones that built the habit of maintaining those three, not only the systems underneath them.
Sources
- 1 BCBS. BCBS 239: Principles for effective risk data aggregation and risk reporting, Paragraphs 14 and 15 View source ↗
- 2 ECB Banking Supervision. Guide on effective risk data aggregation and risk reporting View source ↗
- 3 ECB Banking Supervision. Sound risk data reporting, key to better decision-making and resilience View source ↗
- 4 PRA. Thematic review of private equity related financing activities, Paragraphs 10 and 13 View source ↗
- 5 Gini. End user computing in banking: why three regulators now watch the same estate View source ↗
- 6 BCBS. BCBS d559: Progress in adopting the Principles for effective risk data aggregation and risk reporting View source ↗
- 7 PRA. SS1/23: Model risk management principles for banks, Principle 3 View source ↗