Skip to content

FRM Part II · FRM Exam Part II

Risk Reporting: formula sheet

Full chapter guide

Key formulas

Structure of BCBS 239
14 principles = 2 (governance and infrastructure) + 4 (aggregation) + 5 (reporting) + 3 (supervisory)
Use the counts to place a principle in its group quickly.
Aggregation principles (3-6)
Accuracy and integrity, Completeness, Timeliness, Adaptability
These concern data capability. Remember as ACTA.
Reporting principles (7-11)
Accuracy, Comprehensiveness, Clarity and usefulness, Frequency, Distribution
These concern the reports themselves and who receives them.
Aggregation vs reporting
Aggregation = data capability; Reporting = content and delivery
The most common classification test.
BCBS 239 structure
Governance and infrastructure + Aggregation capabilities + Reporting practices + Supervisory review
The principles are grouped in four parts. Aggregation capabilities are accuracy and integrity, completeness, timeliness, adaptability.
Aggregation capability test
Accurate + Complete + Timely + Adaptable
All four must hold, in normal times and in stress or crisis. Strength in three does not offset a failure in the fourth.
Accountability rule
Responsibility for data quality = board and senior management (not IT alone, not a vendor)
Outsourcing a task does not outsource accountability.
Reconciliation principle
Risk data should reconcile with accounting data and other sources
Used to evidence accuracy and integrity; manual intervention should be minimal and documented.
Limit utilisation
Utilisation (%) = Current exposure ÷ Approved limit × 100
Report it with a trend and flag breaches or amber zones. Utilisation above 100% is a breach.
Headroom
Headroom = Limit − Current exposure
Negative headroom means a limit excess that needs escalation.
Concentration share
Share of largest exposure (%) = Largest single exposure ÷ Total portfolio exposure × 100
A simple concentration indicator. Often shown for top 10 names, sectors or countries.
Core content checklist
Exposures + Limits/appetite + Concentrations + Forward-looking indicators + Stress results + Actions
Use as a rule to judge whether a report is complete. It is a checklist, not a numerical formula.
Audience rule
Higher audience level → more aggregation, less detail, more focus on decisions
A general principle, not an absolute rule. Material issues must still be escalated to the board.
Net loss
Net loss = Gross loss − Recoveries
Recoveries include insurance and other amounts recovered. Report gross, recovery and net amounts separately.
KRI threshold logic
Green: within appetite | Amber: approaching limit | Red: limit breached → escalate
Thresholds are set by the firm. The principle is that a breach triggers a defined escalation and action.
Impact tolerance test
Tested recovery time ≤ impact tolerance → within tolerance
If the tested recovery time is longer than the tolerance, the service is outside tolerance and remediation is needed.
Loss event date types
Date of occurrence ≤ Date of discovery ≤ Date of accounting
Basel loss data collection records all three. Use them to analyse detection lags.
Event reporting rate
Rate = Number of events ÷ Volume of activity
Normalising by volume (for example per 10,000 transactions) lets you compare periods and units fairly.
Frequency principle
Frequency ∝ speed of risk change × importance to decisions; increase in stress
This is a rule of thumb from the principle, not a numeric formula. No fixed number of days is prescribed for all reports.
Distribution principle
Right recipient + right time + confidentiality (need-to-know)
Both parts matter. Wide circulation without access control fails the principle.
Supervisory cycle
Review → identify weakness → require remedial action → follow up
Supervisors can use audit findings, thematic reviews and on-site work. Remediation must be monitored.
Cross-border rule
Home supervisor + host supervisors → cooperate and share information
Aim is consistent assessment of group-wide compliance.

Quick revision

  • BCBS 239 sets principles for effective risk data aggregation and risk reporting.
  • Governance and data architecture come first: the board and senior management own risk data quality.
  • Aggregation capabilities cover accuracy, integrity, completeness, timeliness and adaptability.
  • Risk data should be aggregated largely automatically, with manual workarounds kept to a minimum.
  • Reports must be accurate, comprehensive, clear, useful, and produced at the right frequency.
  • Good reports highlight exposures against limits and risk appetite, not just raw numbers.
  • Reports must be adaptable: the bank should be able to produce ad hoc reports in stress or crisis.
  • Distribution must reach the right people while keeping confidential information protected.
  • Reports should be reviewed and validated, and supervisors can assess compliance.
  • Operational risk reports use incidents, losses and key risk indicators to show trends and control weaknesses.
  • Resilience metrics test whether the bank can operate within its tolerance for disruption.
  • In a scenario, identify the specific weakness first, then choose the fix that targets it.

Common mistakes

  • Confusing aggregation accuracy (Principle 3) with reporting accuracy (Principle 7). Fix: Principle 3 is about data sources, controls and reconciliation. Principle 7 is about the reports being precise, reconciled and validated for the reader.
  • Treating BCBS 239 as only an IT project. Fix: Principle 1 puts responsibility on the board and senior management, and governance covers the whole framework, not just systems.
  • Treating completeness and accuracy as the same thing. Fix: Accuracy is about correct values and reliable data. Completeness is about covering all material risks and entities. Missing a subsidiary is completeness, not accuracy.
  • Thinking BCBS 239 only matters in normal conditions. Fix: The principles stress capability in stress and crisis, with faster and more flexible reporting when needed.
  • Assuming more detail is always better for the board. Fix: Remember the board needs aggregated, prioritised information. Detail goes in supporting appendices or lower-level reports.
  • Treating a report as only current exposures. Fix: Add limits, concentrations, forward-looking indicators and stress results. Reports must show where risk is heading, not just where it is.
  • Treating KRIs and KPIs as the same thing. Fix: Ask whether the metric measures performance toward a goal (KPI) or exposure to a risk that could cause a loss (KRI).
  • Calling loss data a leading indicator. Fix: Loss data is backward-looking. KRIs are the forward-looking signal. Loss data validates and calibrates KRIs.
  • Assuming one fixed reporting frequency for every risk report. Fix: Remember frequency is set by risk nature, speed of change and user needs, and rises in stress.
  • Thinking faster reporting justifies lower accuracy in a crisis. Fix: The principles require timely reports that still meet accuracy and integrity standards.

Exam tips

  • Memorise the principle numbers and group counts: 2, 4, 5 and 3.
  • Questions usually describe a symptom and ask which principle is breached. Match the keyword, then check the group.
  • Watch for the aggregation versus reporting distinction. It is the most common trap.
  • Remember that BCBS 239 was aimed first at G-SIBs and applies in both normal and stress periods.
  • Reject options that say the principles require full automation or real-time data for every risk.
  • Learn the four aggregation capabilities by name and by symptom. Most questions are symptom matching.
  • Watch for words like stress, crisis or ad hoc. They signal timeliness and adaptability.
  • Governance answers usually name the board and senior management, never IT alone.