Since the release of the “Principles for effective risk data aggregation and risk reporting” regulation (commonly known as BCBS 239) in January 2013 by the Basel Committee on Banking Supervision (BCBS), the regulation evolved significantly, transitioning from a regulatory requirement into a strategic framework for improving risk data aggregation and reporting across the banking sector.
Initially, the regulation targeted Global Systemically Important Banks (G-SIBs), with a compliance deadline set for January 2016. The goal was to address the data and reporting deficiencies exposed during the 2007 – 2009 financial crisis. The High-Level Group of Financial Supervision in the EU, found that amongst other factors, a key driver was that critical risk information remained siloed within specific departments and never reached the decision-makers who could have taken preventive action. With the best intentions and drive by regulators, early implementation of BCBS239 revealed significant challenges, including outdated IT systems, data silos and weak data governance structures.
Recognising these challenges, regulators globally extended the principles to Domestic Systemically Important Banks (D-SIBs) with a compliance deadline set for January 2019, allowing for more flexible, risk-based implementation. Locally, the South African Reserve Bank (SARB), released Directive D2/2015: Effective risk data aggregation and risk reporting and D5/2016: Compliance with principles for effective risk data aggregation and risk reporting with the purpose to drive robust risk management practices within the South African banking sector.
Over time, BCBS 239 became integrated into broader regulatory and digital transformation agendas, aligning with Basel III reforms, stress testing, and emerging standards for data governance and cyber resilience. The COVID-19 pandemic further accelerated the evolution of BCBS 239, highlighting the need for real-time, high-quality risk data. Banks responded by accelerating their adopting of cloud technologies, automating reporting processes, and exploring AI and machine learning for risk analytics.
To help close some of the remaining gaps in the implementation, the European Central Bank (ECB) released its “Guide on Effective Risk Data Aggregation and Risk Reporting” in May 2024. This initiative aligns with the Single Supervisory Mechanism (SSM) priorities for 2025–2027, placing a strong focus on risk data aggregation and reporting. The guide was designed to strengthen governance and ensure that banks have effective systems in place to identify, monitor, and report risks in line with BCBS 239. In addition, it also emphasised the importance of using high-quality data not only for regulatory compliance but also to support strategic and operational decision-making and unlock its broader economic value.
Going forward, the focus has shifted toward embedding data governance into Bank’s organisational culture, enhancing operational resilience, and integrating ESG and cyber risk data into reporting frameworks. Supervisory reviews continue to assess compliance maturity, emphasising not just technical capabilities but also data ethics, explainability and strategic alignment.
Objectives set out in 2013
The primary objective of the BCBS 239 regulations was to enhance banks’ ability to manage risk effectively by improving the quality, accuracy, and timeliness of risk data aggregation and reporting.
By ensuring that banks can quickly and accurately consolidate risk data across their business lines and geographies, BCBS 239 aimed to support better strategic and operational decision-making, especially during periods of financial stress or crisis. To achieve this, the Basel Committee outlined 14 principles grouped into four categories.
Four categories of BCBS 239 principles:
- Governance and infrastructure
- Risk data aggregation
- Risk reporting practices
- Supervisory review
These principles emphasise the importance of strong…
![]() |
|
|
Alec Slabbert | Associate Director | Financial Risk Management (FRM) Credit & Capital Risk | mail me | |
Maria van der Valk | Partner | Financial Risk Management (FRM) Credit & Capital Risk | mail me | |
The full article is reserved for our subscribers!
Read the full article by Alec Slabbert, Associate Director and Maria van der Valk, Partner, KPMG Southern Africa, as well as a host of other topical management articles written by professionals, consultants and academics in the August/September 2025 edition of BusinessBrief.
admin@bbrief.co.za | +27 (0)11 788 0880 |




























