EZ

Eduzan

Learning Hub

Eduzan
Eduzan / 01 Foundations of Risk Management

FRM 7: Principles for Effective Data Aggregation and Risk Reporting

Worked examples are fully visible. Check-yourself items are study aids you can reveal one at a time.

Every risk number a firm produces rests on data that somebody collected, stored and passed along, which is why data belongs on the list of assets a business genuinely owns. Some of it is generated inside the firm: a bank has its own transaction records, and a manufacturer knows what it paid for raw materials. The awkward question about internal data is not whether it exists, but whether anyone kept it in a shape that allows analysis. Other material comes from outside, and public sources cover only part of what risk teams want, which includes histories of inflation rates, movements in the money supply, major interest rates and exchange rates. Alternative data is the label for information gathered by third parties, including data scraped from the web and readings from mobile devices and sensors. Big data means volumes complex enough to defeat ordinary processing techniques, and unstructured data arrives with no predefined data model. Machine learning and artificial intelligence are now the standard tools for turning both into something a risk manager can use.

How the industry acquired a data problem

Financial firms spent decades collecting data department by department, or business activity by business activity, with very little coordination. Separate teams sourced the same feed twice and neither knew about the other. Plenty of data was neglected, and some was destroyed, since migration from one computer system to the next is exactly the moment at which records disappear. Through the 1960s and 1970s the medium was paper cards and computer tapes. Floppy disks and hard disk drives arrived afterwards, and neither could be read by the older generation of systems.

Within the Basel Committee on Banking Supervision, a special committee looked at how banks collected, stored and analysed data. It found problems throughout the industry and published a report on risk data management, concluding that quality was not adequate for aggregating exposures and reporting them at the level of the bank group, or for breaking them down by legal entity and by business line. In January 2013 the BCBS answered with fourteen principles, known ever since by the paper number: BCBS 239.

In the Committee’s own words, risk data aggregation is the work of defining, gathering and processing risk data so that it answers whatever risk reporting requirements the firm has set, which lets the bank judge its performance against the risk tolerance and risk appetite it has chosen. The principles reach risk management data and the models fed by it, and they fall into four groups that the rest of this lesson follows in order.

The 14 principles of BCBS 239, by group
GroupNumberShort name
Governance and infrastructure1Governance
Governance and infrastructure2Data architecture and IT infrastructure
Aggregation capability3Accuracy and integrity
Aggregation capability4Completeness
Aggregation capability5Timeliness
Aggregation capability6Adaptability
Reporting practices7Accuracy
Reporting practices8Comprehensiveness
Reporting practices9Clarity and usefulness
Reporting practices10Frequency
Reporting practices11Distribution
Supervisory expectations12Review
Supervisory expectations13Remedial actions and supervisory measures
Supervisory expectations14Home/host cooperation

Source: Basel Committee on Banking Supervision, BCBS 239, January 2013.

Check yourself
Which of the fourteen principles are addressed to supervisors rather than to banks, and what does that split imply about how compliance is judged?
Principles 12, 13 and 14 speak to supervisors: review, remedial action, and cooperation between home and host jurisdictions. So compliance is not a self-assessment. A supervisor rates the bank, can compel remediation, and coordinates with counterparts abroad.
End of lesson.