Skip to content

FRM Part II · FRM Exam Part II · Risk Reporting

A bank's new data governance framework assigns responsibilities after a supervisory review of its BCBS 239 compliance. Which arrangement best aligns with the principles on governance and infrastructure?

The best arrangement has senior management accountable for data quality, business data owners, independent validation of aggregation capabilities, and board oversight that includes acquisitions and new initiatives. Sole IT ownership, exempting acquired entities, or having internal audit design the architecture conflict with BCBS 239 governance expectations.

  1. AThe IT department alone owns risk data quality, with business lines consulted annually
  2. BRisk data aggregation is covered by the bank's own policies, but newly acquired entities are exempted for the first five years
  3. CSenior management is responsible for data quality, with data owners in the business and an independent validation of aggregation capabilities, and the board oversees compliance including in acquisitions and new initiativesCorrect
  4. DInternal audit designs the data architecture to ensure independence, and the board is informed only of failures

Explanation

BCBS 239 places responsibility on the board and senior management, requires clear data ownership, independent validation of risk data aggregation capabilities, and consideration of the effect on aggregation of mergers, acquisitions and new products. IT-only ownership, blanket exemptions and audit designing the architecture each contradict these principles.

Did you get it right without looking?

One question tells you little. A timed set on Risk Reporting shows your real accuracy, how long you take and where you lose marks.

More Risk Reporting questions