FRM Exam Part II · Risk Governance
Risk Reporting, Data and Internal Controls for FRM Part II
Updated 11 October 2026 · Fact-checked
Risk reporting turns risk data into management information that the board and committees can act on. It rests on accurate, complete, timely data (BCBS 239), clear escalation when limits or events breach thresholds, and internal controls (COSO) that make the data and decisions reliable. Solve questions by finding which link failed.
Understand Risk Reporting, Data and Internal Controls
Governance only works if the people in charge can see risk. The board sets risk appetite. Management runs the business within it. Between them sits a chain: data is captured, aggregated, turned into reports, reviewed by committees, and escalated when something goes wrong. If any link is weak, oversight fails even when the policies look good.
Risk data aggregation is the ability to collect and combine risk data across business lines, legal entities and risk types. The Basel Committee's BCBS 239 (Principles for effective risk data aggregation and risk reporting) was written after the 2007-09 crisis, when banks could not quickly see group-wide exposures. It applies first to global systemically important banks. Its principles cover four areas: overarching governance and infrastructure; risk data aggregation capabilities (accuracy and integrity, completeness, timeliness, adaptability); risk reporting practices (accuracy, comprehensiveness, clarity and usefulness, frequency, distribution); and supervisory review.
Good risk reports are accurate, reconciled to accounting and source data, and clear. They show exposures against limits and appetite, trends, concentrations, emerging risks and forward-looking views, not just numbers. The board needs a concise, decision-focused view. Operational risk reports typically show loss events, key risk indicators (KRIs), control failures, open audit issues and scenario results. Frequency should rise in stress, and on-demand reporting must be possible.
Escalation is the rule that tells staff who must be told, how fast, and what happens next when a threshold is crossed. Triggers include limit breaches, KRIs in red, a material loss event, a major control failure or a regulatory issue. Escalation should be defined in policy, move up the line to senior management, the risk committee and the board, and be recorded and tracked to closure. A culture where bad news is hidden defeats the framework.
Internal controls are the processes that give reasonable assurance about reliable reporting, effective operations and compliance. The COSO internal control framework has five components: control environment, risk assessment, control activities, information and communication, and monitoring activities. Controls can be preventive, detective or corrective. Under the three lines of defense, the first line owns and controls risk, the second line (risk and compliance) oversees and challenges, and the third line (internal audit) gives independent assurance to the board.
Key formulas to remember
- BCBS 239 data quality attributes
- Accuracy and integrity | Completeness | Timeliness | Adaptability
- These are the risk data aggregation capability principles. Match each failure in a case to one attribute.
- BCBS 239 reporting attributes
- Accuracy | Comprehensiveness | Clarity and usefulness | Frequency | Distribution
- These are the risk reporting practice principles. Distribution means the right reports reach the right people securely.
- COSO internal control components
- Control environment | Risk assessment | Control activities | Information and communication | Monitoring activities
- Five components. Tone at the top and integrity sit in the control environment.
- Three lines of defense
- 1st: business owns risk | 2nd: risk and compliance oversee | 3rd: internal audit assures
- Audit must stay independent of the first two lines and report to the board or its audit committee.
- Control types
- Preventive | Detective | Corrective
- Preventive stops the error (segregation of duties). Detective finds it (reconciliation). Corrective fixes it (remediation).
How to solve Risk Reporting, Data and Internal Controls questions
Most questions give a short case about a weak report, a data problem, a missed escalation or a control failure. Use the same path each time.
- 1Read the last line first to see what is asked: the cause, the principle breached, the best fix or the right escalation.
- 2Locate the failure in the chain: data capture, aggregation, report content, distribution, escalation or control.
- 3Name the precise concept: a BCBS 239 principle, a COSO component, or a line of defense.
- 4Check who should own the action. First line fixes and controls, second line challenges and reports, third line audits, board sets appetite and oversees.
- 5Judge timing and level. A breach of appetite or a material event must go up to senior management or the board, not stay with the desk.
- 6Eliminate options that weaken independence, rely on manual workarounds or give only backward-looking data.
- 7Pick the answer that fixes the root cause, not the symptom.
Quickest way: Failure-point shortcut
When to use it: Use it when time is short and the options look similar.
- Ask: was the data wrong, late, incomplete, or unreadable? Map to accuracy, timeliness, completeness or clarity.
- Ask: did the right person know in time? If not, it is an escalation or distribution failure.
- Ask: was there a control, and did it prevent, detect or correct? Missing monitoring points to the fifth COSO component.
- Choose the option that is systematic, independent and board-visible over ad hoc or manual fixes.
Common mistakes in Risk Reporting, Data and Internal Controls
Treating BCBS 239 as only an IT or data project.
The title mentions data aggregation, so students ignore governance.
Fix: Remember that the board and senior management own data quality and must sign off on capabilities. Governance is the first principle group.
Mixing up data aggregation principles with reporting principles.
Accuracy appears in both lists.
Fix: Aggregation covers the data itself. Reporting covers the output: content, frequency and distribution. Decide which stage the case describes.
Assigning internal audit to build or run controls.
Audit sounds like control work.
Fix: The third line gives independent assurance only. Owning controls is the first line's job. Challenge belongs to the second line.
Assuming more detail always makes a better board report.
Students equate volume with completeness.
Fix: Board reports must be clear and useful, with key risks, trends, limit breaches and decisions needed. Detail sits in supporting committee packs.
Thinking escalation is optional below a large loss.
Students focus on loss size.
Fix: Escalation is triggered by pre-set thresholds, including limit breaches, KRI breaches and control failures, even with no loss yet.
Listing COSO as risk identification steps or as an operational risk model.
COSO also publishes an enterprise risk management framework.
Fix: The internal control framework has five components. Link them to reliable reporting, effective operations and compliance.
Worked examples
Example 1
A global bank takes three days to produce a group-wide credit exposure report after a market shock. Business units use different counterparty identifiers, and the report needs manual spreadsheets. Which BCBS 239 data aggregation attributes are most clearly weak, and what is the best remedy? (A) Adaptability only; add more staff (B) Timeliness and accuracy/integrity; build common identifiers and automated aggregation under senior management sponsorship (C) Clarity only; redesign the report layout (D) Distribution only; send the report to more people
Show the solution
- Identify the symptoms. Three days is slow, so timeliness is weak.
- Different identifiers and manual spreadsheets raise error risk, so accuracy and integrity are weak.
- A fix must address root causes: common data standards and automated aggregation.
- BCBS 239 puts responsibility on the board and senior management, so sponsorship matters.
- Options A, C and D address single or unrelated attributes and leave the root cause.
Answer: B. Timeliness and accuracy/integrity are weak, and the remedy is common identifiers plus automated aggregation with senior management ownership.
Example 2
A trading desk breaches a key operational risk indicator threshold for failed settlements for two weeks. The desk head fixes it informally and tells no one. What went wrong and what should have happened? (A) Nothing; no loss occurred (B) Internal audit should have corrected it (C) The escalation process failed; the breach should have been reported to the second line and senior management per policy and tracked to closure (D) The board should have approved the fix
Show the solution
- The KRI crossed a pre-set threshold, which is an escalation trigger. No loss is needed.
- The desk is the first line. It may act, but policy requires reporting the breach upward.
- The second line should challenge and monitor, and senior management and the risk committee should be informed per policy.
- Internal audit is independent and does not correct issues.
- The board sets appetite and oversees. It does not approve routine fixes.
Answer: C. The escalation process failed. The breach should have been reported through the defined channels and tracked until resolved.
Exam tips
- Match each failure in a case to a named principle or component. Examiners reward precise terms such as timeliness or monitoring activities.
- Watch the line of defense in every option. Wrong ownership is a favourite distractor.
- Prefer answers that are systematic, documented and independent over manual or informal fixes.
- Remember BCBS 239 begins with governance. A pure technology answer is often incomplete.
- In reporting questions, favour forward-looking, decision-useful content that ties exposures to risk appetite.
Practice questions from Risk Governance
- At a mid-sized bank, the head of the trading desk's business unit appoints a risk coordinator who identifies operational risk events, mainta…
- A bank is reviewing a loss event in which a settlement control failed for several months. Findings: (1) the operations team knew the control…
- A bank's operational risk function reports to the head of the retail banking division, who also sets its budget and evaluates its staff. The…
- A firm distinguishes between risk appetite and risk tolerance. Which of the following best illustrates risk tolerance rather than risk appet…
- Which of the following is a responsibility the Basel principles assign to senior management, rather than to the board, regarding operational…
Risk Reporting, Data and Internal Controls in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Risk Reporting, Data and Internal Controls: frequently asked questions
What is BCBS 239 in simple terms?
It is the Basel Committee's set of principles for risk data aggregation and risk reporting. It aims to let banks produce accurate and timely group-wide risk information, especially in stress. It was issued after the 2007-09 crisis exposed weak data.
How should operational risk issues be escalated?
Follow a defined policy with thresholds for limits, KRIs, loss events and control failures. Issues go from the first line to the second line and senior management, and to the risk committee or board when material. Each issue is logged and tracked until closed.
What are the five components of the COSO internal control framework?
They are control environment, risk assessment, control activities, information and communication, and monitoring activities. They work together to support reliable reporting, effective operations and compliance.
What should an operational risk report to the board contain?
It should show key loss events, KRIs against thresholds, major control weaknesses, open audit findings, scenario results and emerging risks, linked to risk appetite. It should be concise, clear and focused on decisions needed.