FRM Part II · FRM Exam Part II · Risk Reporting
A bank's new data governance framework assigns responsibilities after a supervisory review of its BCBS 239 compliance. Which arrangement best aligns with the principles on governance and infrastructure?
The best arrangement has senior management accountable for data quality, business data owners, independent validation of aggregation capabilities, and board oversight that includes acquisitions and new initiatives. Sole IT ownership, exempting acquired entities, or having internal audit design the architecture conflict with BCBS 239 governance expectations.
- AThe IT department alone owns risk data quality, with business lines consulted annually
- BRisk data aggregation is covered by the bank's own policies, but newly acquired entities are exempted for the first five years
- CSenior management is responsible for data quality, with data owners in the business and an independent validation of aggregation capabilities, and the board oversees compliance including in acquisitions and new initiativesCorrect
- DInternal audit designs the data architecture to ensure independence, and the board is informed only of failures
Explanation
BCBS 239 places responsibility on the board and senior management, requires clear data ownership, independent validation of risk data aggregation capabilities, and consideration of the effect on aggregation of mergers, acquisitions and new products. IT-only ownership, blanket exemptions and audit designing the architecture each contradict these principles.
Did you get it right without looking?
One question tells you little. A timed set on Risk Reporting shows your real accuracy, how long you take and where you lose marks.
More Risk Reporting questions
- A bank's operational risk team receives loss event data from three subsidiaries. One subsidiary records losses net of insurance recoveries, …
- During a review of its risk reports, a bank finds that the key risk indicator (KRI) section shows only current-month values with no threshol…
- A bank wants its operational risk reports to support an assessment of resilience for critical operations. Which metric is most directly usef…
- A bank's operational risk function is redesigning its quarterly report for the board risk committee. Which design choice best supports the c…
- A payments firm has defined an impact tolerance for its payment processing service of a maximum disruption of 4 hours. During a scenario tes…
- During a stress event, a G-SIB's chief risk officer asks for an ad hoc report on exposures to a specific counterparty group, but the bank ca…