FRM Exam Part II · Risk Reporting
Risk Data Aggregation Capabilities and Data Governance
Updated 11 October 2026 · Fact-checked
Risk data aggregation is a bank's ability to collect, combine and report risk data accurately, completely and on time, including under stress. BCBS 239 requires strong governance, integrated data architecture and IT infrastructure. To solve questions, match the weakness described to the right principle: accuracy, completeness, timeliness or adaptability.
Understand Risk Data Aggregation Capabilities and Data Governance
Risk reports are only as good as the data behind them. In the 2007-2009 crisis, many global banks could not quickly see their total exposure to one counterparty or product. Data sat in separate systems, and reports were slow and inconsistent. The Basel Committee responded with BCBS 239, the Principles for effective risk data aggregation and risk reporting.
Risk data aggregation means defining, gathering and processing risk data so a bank can measure performance against its risk tolerance. It covers sorting, merging and breaking down data by legal entity, business line, asset type, industry, region and so on. BCBS 239 was aimed first at global systemically important banks (G-SIBs), and supervisors encourage other banks to apply it too.
The principles split into four groups. First, overarching governance and infrastructure: the board and senior management own data quality, and the bank needs data architecture and IT infrastructure that work in normal times and in stress or crisis. Second, risk data aggregation capabilities: accuracy and integrity, completeness, timeliness and adaptability. Third, risk reporting practices: accuracy, comprehensiveness, clarity and usefulness, frequency, and distribution. Fourth, supervisory review, tools and cooperation.
In plain terms: accuracy and integrity means data is reliable, with few manual workarounds and with reconciliation to accounting and source data. Completeness means all material risks and all relevant entities are captured. Timeliness means data is produced fast enough, with faster speed in stress. Adaptability means the bank can produce ad hoc reports for new requests, such as a sudden question on exposure to one country.
Governance ties this together. The board approves the framework and senior management makes sure resources are there. Data should have clear owners, a single data dictionary and consistent definitions across the group. Data governance also covers a risk data architecture that is largely automated, and independent validation of the aggregation process. A bank cannot use outsourcing or a weak legacy system as an excuse: responsibility stays with the bank.
Key formulas to remember
- BCBS 239 structure
- Governance and infrastructure + Aggregation capabilities + Reporting practices + Supervisory review
- The principles are grouped in four parts. Aggregation capabilities are accuracy and integrity, completeness, timeliness, adaptability.
- Aggregation capability test
- Accurate + Complete + Timely + Adaptable
- All four must hold, in normal times and in stress or crisis. Strength in three does not offset a failure in the fourth.
- Accountability rule
- Responsibility for data quality = board and senior management (not IT alone, not a vendor)
- Outsourcing a task does not outsource accountability.
- Reconciliation principle
- Risk data should reconcile with accounting data and other sources
- Used to evidence accuracy and integrity; manual intervention should be minimal and documented.
How to solve Risk Data Aggregation Capabilities and Data Governance questions
Most questions give a short bank scenario and ask which principle is breached or what the bank should do. Work in a fixed order.
- 1Read the scenario and underline the symptom: wrong numbers, missing entities, slow reports, or inability to answer new requests.
- 2Map the symptom to a capability: wrong numbers = accuracy and integrity; missing entities or risks = completeness; slow delivery = timeliness; cannot answer ad hoc = adaptability.
- 3Check whether the problem is at the governance level: unclear ownership, no board oversight or inconsistent definitions point to governance and architecture.
- 4Check the condition: does the failure happen only in stress or crisis? BCBS 239 expects capability in both normal and stressed conditions.
- 5Pick the remedy that fixes the root cause: integrated data model, single data dictionary, automation, reconciliation, independent validation.
- 6Eliminate options that shift accountability away from the board or that rely on more manual work.
- 7Confirm your answer names the exact principle and not a neighboring one.
Quickest way: Symptom-to-principle shortcut
When to use it: Use when you have about a minute per question and the options are close.
- Find the symptom word: wrong, missing, late, inflexible, unowned.
- Match to accuracy, completeness, timeliness, adaptability or governance.
- Prefer the answer that automates, integrates and assigns ownership.
- Reject answers that say manual processes are fine, that IT alone is accountable, or that the rules apply only in calm markets.
Common mistakes in Risk Data Aggregation Capabilities and Data Governance
Treating completeness and accuracy as the same thing.
Both sound like data quality, so they blur together.
Fix: Accuracy is about correct values and reliable data. Completeness is about covering all material risks and entities. Missing a subsidiary is completeness, not accuracy.
Thinking BCBS 239 only matters in normal conditions.
Candidates focus on routine reporting.
Fix: The principles stress capability in stress and crisis, with faster and more flexible reporting when needed.
Assigning data quality to the IT department.
Data and systems feel like a technology topic.
Fix: The board and senior management are responsible. IT supports, but business and risk own the data.
Assuming heavy manual processes are acceptable if people are skilled.
Experienced staff can make reports look right.
Fix: Manual workarounds raise error risk and slow the process. The principles favor automation and documented, controlled exceptions.
Confusing aggregation capabilities with reporting practices.
Both groups use words like accuracy and timeliness.
Fix: Aggregation is how data is gathered and processed. Reporting is how reports are built, presented and distributed. Ask which stage failed.
Believing BCBS 239 applies only to G-SIBs forever.
The initial deadline applied to G-SIBs.
Fix: It targeted G-SIBs first, but supervisors encourage domestic banks to follow the principles too.
Worked examples
Example 1
A global bank's risk team needs two weeks to compute total exposure to one corporate group because loans sit in separate regional systems with different client identifiers. Which capability is most clearly weak, and what is the best fix?
A. Accuracy, by increasing manual checks
B. Timeliness and adaptability, by integrating data with a common client identifier
C. Reporting frequency, by sending reports less often
D. Supervisory review, by asking for more audits
Show the solution
- Symptom: two weeks to get a group-wide exposure, and it is a new ad hoc question.
- Slow delivery points to timeliness. Difficulty answering a new request points to adaptability.
- Root cause: fragmented systems and inconsistent client identifiers, which is a data architecture problem.
- Best remedy: an integrated data model with a common identifier and automated aggregation.
- Option A adds manual work and does not address speed. C and D do not fix the aggregation process.
Answer: B
Example 2
After a review, a bank finds that its risk reports use figures that differ from the general ledger, and staff fix this each month by spreadsheet adjustments. Explain which principle is breached and what the bank should do.
Show the solution
- Symptom: risk numbers do not match accounting data.
- This is an accuracy and integrity issue. Reconciliation to accounting and other sources is expected.
- Monthly spreadsheet fixes are manual workarounds. They add error risk and slow reporting.
- Remedy: automate reconciliation between risk and finance data, document and limit manual adjustments, and assign clear data ownership.
- Add independent validation of the aggregation process, and have senior management oversee the remediation.
Answer: Accuracy and integrity is breached. The bank should automate reconciliation to accounting data, minimize and document manual adjustments, set clear data ownership, and have independent validation, with senior management accountable.
Exam tips
- Learn the four aggregation capabilities by name and by symptom. Most questions are symptom matching.
- Watch for words like stress, crisis or ad hoc. They signal timeliness and adaptability.
- Governance answers usually name the board and senior management, never IT alone.
- Prefer answers that integrate and automate over answers that add manual checks.
- Separate aggregation capabilities from reporting practices before choosing.
Practice questions from Risk Reporting
- A global bank's board reviews a monthly risk report. The Chief Risk Officer notes that the report ties exposures to the general ledger and i…
- Under BCBS 239, who holds responsibility for ensuring that the bank's risk data aggregation capabilities and risk reporting practices are su…
- A bank sets a key risk indicator for failed trade settlements with amber at 2.0% of trades and red at 3.0%. Over four months, 50,000 trades …
- A bank's risk reports rely heavily on manual reconciliations and end-user spreadsheets to aggregate credit exposures. Which control is most …
- An internal audit review of a bank's operational risk reports finds that the format has not changed in six years, several metrics are no lon…
Risk Data Aggregation Capabilities and Data Governance in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Risk Data Aggregation Capabilities and Data Governance: frequently asked questions
What does BCBS 239 require for risk data aggregation?
It requires banks to aggregate risk data in a way that is accurate, complete, timely and adaptable. This must work in normal times and in stress. It also needs strong governance and integrated data architecture and IT infrastructure.
How can a bank improve data quality in risk reporting?
Set clear data ownership and a single data dictionary, integrate systems, automate data flows and reconcile risk data to accounting data. Add independent validation and board oversight. Reduce manual workarounds.
What is the difference between completeness and accuracy?
Accuracy and integrity concern whether the data values are correct and reliable. Completeness concerns whether all material risks, entities and exposures are captured. A report can be accurate for what it covers and still be incomplete.
Who is responsible for risk data governance?
The board and senior management are responsible. They approve the framework and make sure resources and ownership exist. Using a third party or IT team does not remove that accountability.