Skip to content

FRM Part I · FRM Exam Part I · Principles for Effective Data Aggregation and Risk Reporting

A bank's board approves a risk appetite statement, but the risk data used to monitor it comes from several legacy systems that have never been independently validated. Which BCBS 239 governance expectation is most directly breached?

The breached expectation is that risk data aggregation and reporting be under strong governance and independent validation. Principle 1 requires a review of the capabilities by skilled, independent staff. It does not require the board to produce reports, internal audit to aggregate data, or a single system.

  1. ASenior management must ensure the bank's risk data aggregation capabilities and reporting practices are subject to strong governance and are independently validatedCorrect
  2. BThe board must personally prepare each daily risk report
  3. CRisk data aggregation must be handled only by the internal audit function
  4. DThe bank must use one single legacy system for all risk data

Explanation

Principle 1 requires strong governance over risk data aggregation and reporting, with independent validation by staff with appropriate skills. The board need not prepare reports, internal audit does not own aggregation, and a single system is not mandated.

Did you get it right without looking?

One question tells you little. A timed set on Principles for Effective Data Aggregation and Risk Reporting shows your real accuracy, how long you take and where you lose marks.

More Principles for Effective Data Aggregation and Risk Reporting questions