FRM Part II · FRM Exam Part II
Risk Reporting: formula sheet
Key formulas
- Structure of BCBS 239
- 14 principles = 2 (governance and infrastructure) + 4 (aggregation) + 5 (reporting) + 3 (supervisory)
- Use the counts to place a principle in its group quickly.
- Aggregation principles (3-6)
- Accuracy and integrity, Completeness, Timeliness, Adaptability
- These concern data capability. Remember as ACTA.
- Reporting principles (7-11)
- Accuracy, Comprehensiveness, Clarity and usefulness, Frequency, Distribution
- These concern the reports themselves and who receives them.
- Aggregation vs reporting
- Aggregation = data capability; Reporting = content and delivery
- The most common classification test.
- BCBS 239 structure
- Governance and infrastructure + Aggregation capabilities + Reporting practices + Supervisory review
- The principles are grouped in four parts. Aggregation capabilities are accuracy and integrity, completeness, timeliness, adaptability.
- Aggregation capability test
- Accurate + Complete + Timely + Adaptable
- All four must hold, in normal times and in stress or crisis. Strength in three does not offset a failure in the fourth.
- Accountability rule
- Responsibility for data quality = board and senior management (not IT alone, not a vendor)
- Outsourcing a task does not outsource accountability.
- Reconciliation principle
- Risk data should reconcile with accounting data and other sources
- Used to evidence accuracy and integrity; manual intervention should be minimal and documented.
- Limit utilisation
- Utilisation (%) = Current exposure ÷ Approved limit × 100
- Report it with a trend and flag breaches or amber zones. Utilisation above 100% is a breach.
- Headroom
- Headroom = Limit − Current exposure
- Negative headroom means a limit excess that needs escalation.
- Concentration share
- Share of largest exposure (%) = Largest single exposure ÷ Total portfolio exposure × 100
- A simple concentration indicator. Often shown for top 10 names, sectors or countries.
- Core content checklist
- Exposures + Limits/appetite + Concentrations + Forward-looking indicators + Stress results + Actions
- Use as a rule to judge whether a report is complete. It is a checklist, not a numerical formula.
- Audience rule
- Higher audience level → more aggregation, less detail, more focus on decisions
- A general principle, not an absolute rule. Material issues must still be escalated to the board.
- Net loss
- Net loss = Gross loss − Recoveries
- Recoveries include insurance and other amounts recovered. Report gross, recovery and net amounts separately.
- KRI threshold logic
- Green: within appetite | Amber: approaching limit | Red: limit breached → escalate
- Thresholds are set by the firm. The principle is that a breach triggers a defined escalation and action.
- Impact tolerance test
- Tested recovery time ≤ impact tolerance → within tolerance
- If the tested recovery time is longer than the tolerance, the service is outside tolerance and remediation is needed.
- Loss event date types
- Date of occurrence ≤ Date of discovery ≤ Date of accounting
- Basel loss data collection records all three. Use them to analyse detection lags.
- Event reporting rate
- Rate = Number of events ÷ Volume of activity
- Normalising by volume (for example per 10,000 transactions) lets you compare periods and units fairly.
- Frequency principle
- Frequency ∝ speed of risk change × importance to decisions; increase in stress
- This is a rule of thumb from the principle, not a numeric formula. No fixed number of days is prescribed for all reports.
- Distribution principle
- Right recipient + right time + confidentiality (need-to-know)
- Both parts matter. Wide circulation without access control fails the principle.
- Supervisory cycle
- Review → identify weakness → require remedial action → follow up
- Supervisors can use audit findings, thematic reviews and on-site work. Remediation must be monitored.
- Cross-border rule
- Home supervisor + host supervisors → cooperate and share information
- Aim is consistent assessment of group-wide compliance.
Quick revision
- BCBS 239 sets principles for effective risk data aggregation and risk reporting.
- Governance and data architecture come first: the board and senior management own risk data quality.
- Aggregation capabilities cover accuracy, integrity, completeness, timeliness and adaptability.
- Risk data should be aggregated largely automatically, with manual workarounds kept to a minimum.
- Reports must be accurate, comprehensive, clear, useful, and produced at the right frequency.
- Good reports highlight exposures against limits and risk appetite, not just raw numbers.
- Reports must be adaptable: the bank should be able to produce ad hoc reports in stress or crisis.
- Distribution must reach the right people while keeping confidential information protected.
- Reports should be reviewed and validated, and supervisors can assess compliance.
- Operational risk reports use incidents, losses and key risk indicators to show trends and control weaknesses.
- Resilience metrics test whether the bank can operate within its tolerance for disruption.
- In a scenario, identify the specific weakness first, then choose the fix that targets it.
Common mistakes
- Confusing aggregation accuracy (Principle 3) with reporting accuracy (Principle 7). Fix: Principle 3 is about data sources, controls and reconciliation. Principle 7 is about the reports being precise, reconciled and validated for the reader.
- Treating BCBS 239 as only an IT project. Fix: Principle 1 puts responsibility on the board and senior management, and governance covers the whole framework, not just systems.
- Treating completeness and accuracy as the same thing. Fix: Accuracy is about correct values and reliable data. Completeness is about covering all material risks and entities. Missing a subsidiary is completeness, not accuracy.
- Thinking BCBS 239 only matters in normal conditions. Fix: The principles stress capability in stress and crisis, with faster and more flexible reporting when needed.
- Assuming more detail is always better for the board. Fix: Remember the board needs aggregated, prioritised information. Detail goes in supporting appendices or lower-level reports.
- Treating a report as only current exposures. Fix: Add limits, concentrations, forward-looking indicators and stress results. Reports must show where risk is heading, not just where it is.
- Treating KRIs and KPIs as the same thing. Fix: Ask whether the metric measures performance toward a goal (KPI) or exposure to a risk that could cause a loss (KRI).
- Calling loss data a leading indicator. Fix: Loss data is backward-looking. KRIs are the forward-looking signal. Loss data validates and calibrates KRIs.
- Assuming one fixed reporting frequency for every risk report. Fix: Remember frequency is set by risk nature, speed of change and user needs, and rises in stress.
- Thinking faster reporting justifies lower accuracy in a crisis. Fix: The principles require timely reports that still meet accuracy and integrity standards.
Exam tips
- Memorise the principle numbers and group counts: 2, 4, 5 and 3.
- Questions usually describe a symptom and ask which principle is breached. Match the keyword, then check the group.
- Watch for the aggregation versus reporting distinction. It is the most common trap.
- Remember that BCBS 239 was aimed first at G-SIBs and applies in both normal and stress periods.
- Reject options that say the principles require full automation or real-time data for every risk.
- Learn the four aggregation capabilities by name and by symptom. Most questions are symptom matching.
- Watch for words like stress, crisis or ad hoc. They signal timeliness and adaptability.
- Governance answers usually name the board and senior management, never IT alone.