Skip to content

FRM Part I · FRM Exam Part I · Principles for Effective Data Aggregation and Risk Reporting

A bank's internal audit reviews BCBS 239 compliance. Findings: (I) the board has not assessed whether risk reporting meets its needs; (II) a third-party vendor supplies risk data aggregation but the bank has no oversight of it; (III) the framework was validated only by the team that built it. According to BCBS 239 governance expectations, which statement is correct?

All three findings are weaknesses. Under BCBS 239 governance, the board and senior management are responsible for risk reporting adequacy, remain accountable for outsourced data aggregation, and the framework should be independently validated rather than checked only by its builders.

  1. AAll three findings indicate weaknesses, since the board and senior management remain responsible even for outsourced arrangements and the framework should be independently validatedCorrect
  2. BOnly finding I is a weakness, because vendor use and validation are management matters outside the principles
  3. COnly findings I and II are weaknesses, because validation by the builders is sufficient
  4. DNone are weaknesses, as BCBS 239 applies only to reports delivered to supervisors

Explanation

BCBS 239 states that a bank's board and senior management are responsible for the framework, including when aggregation is outsourced, and that the framework should be independently validated. All three findings therefore breach governance expectations; the other options wrongly limit scope or accept self-validation.

Did you get it right without looking?

One question tells you little. A timed set on Principles for Effective Data Aggregation and Risk Reporting shows your real accuracy, how long you take and where you lose marks.

More Principles for Effective Data Aggregation and Risk Reporting questions