# BCBS 239 explained for banks in Luxembourg: risk data aggregation, the ECB guide and the CSSF

> BCBS 239 sets 14 principles for aggregating and reporting risk data; for Luxembourg banks the ECB's May 2024 guide and CSSF Circular 12/552 make them concrete.

Published: 2026-09-12 · Dataplaz editorial team · https://dataplaz.lu/en/bcbs-239-risk-data-aggregation-luxembourg-banks/

## Key takeaways
- BCBS 239, published by the Basel Committee in January 2013, contains 14 principles on risk data aggregation and risk reporting, grouped in four areas.
- In its report of 28 November 2023, the Basel Committee found that only two of 31 global systemically important banks fully complied with all principles.
- The ECB published its Guide on effective risk data aggregation and risk reporting on 3 May 2024, setting out seven areas, from management body responsibility to implementation programmes.
- In its supervisory priorities for 2026-28, the ECB noted no improvement in the average RDARR sub-score in the 2025 SREP and announced targeted on-site inspections.
- For less significant institutions, the CSSF's Circular 12/552 refers to BCBS 239 when describing the risk overview the risk management function must give to management.

BCBS 239 is the Basel Committee's set of 14 principles, published in January 2013, on how banks should aggregate risk data and report risks to management, accurately, completely and fast enough to act on. For banks in Luxembourg it matters in two ways: significant institutions are assessed against the ECB's Guide on effective risk data aggregation and risk reporting of 3 May 2024, and the CSSF's Circular 12/552 refers to BCBS 239 for the risk reporting of the credit institutions it supervises directly.

## Where BCBS 239 comes from

The Basel Committee wrote the principles after the 2007-2009 crisis, when, in its own words, many banks "were unable to aggregate risk exposures and identify concentrations fully, quickly and accurately". Global systemically important banks (G-SIBs) designated by November 2012 were expected to comply from 1 January 2016; banks designated later have three years from designation, and supervisors were recommended to apply the principles to domestic systemically important banks three years after their designation.

Compliance has lagged ever since. The ECB's thematic review of 25 significant institutions, published in May 2018, found that none had fully implemented the principles. In its [progress report of 28 November 2023](https://www.bis.org/bcbs/publ/d559.htm), the Basel Committee found that only two of 31 G-SIBs were fully compliant with all principles.

## The 14 principles, grouped

| Area | Principles |
|---|---|
| I. Overarching governance and infrastructure | 1 Governance · 2 Data architecture and IT infrastructure |
| II. Risk data aggregation capabilities | 3 Accuracy and integrity · 4 Completeness · 5 Timeliness · 6 Adaptability |
| III. Risk reporting practices | 7 Accuracy · 8 Comprehensiveness · 9 Clarity and usefulness · 10 Frequency · 11 Distribution |
| IV. Supervisory review, tools and cooperation | 12 Review · 13 Remedial actions and supervisory measures · 14 Home/host cooperation |

Principles 1 to 11 are addressed to banks, principles 12 to 14 to supervisors. The logic runs in one direction: without governance and an integrated data architecture (I), data cannot be aggregated reliably (II), and without reliable aggregation, reports to the board cannot be accurate or timely (III).

## The ECB's 2024 guide on RDARR

The ECB uses the term RDARR, risk data aggregation and risk reporting. Its [guide of May 2024](https://www.bankingsupervision.europa.eu/ecb/pub/pdf/ssm.supervisory_guides240503_riskreporting.en.pdf) does not create new rules; it sets out "minimum supervisory expectations", compiled with the national competent authorities, on how existing law based on the Capital Requirements Directive is applied. The ECB uses BCBS 239 as its benchmark of best practice and applies proportionality.

The guide is blunt about the starting point. RDARR was the worst-rated sub-category of internal governance in the 2023 SREP cycle, and the ECB had observed monthly risk reports that took 40 or more working days to produce. It sets out seven areas:

| # | Area | What the ECB expects, in short |
|---|---|---|
| 1 | Responsibilities of the management body | Board-level ownership of data governance and of the implementation timeline |
| 2 | Sufficient scope of application | All material legal entities, risks, business lines, and financial and supervisory reporting, across the full data lifecycle |
| 3 | Effective data governance framework | Data owners for key risk indicators, a central data governance function, an independent validation function and internal audit |
| 4 | Integrated data architecture | A group-level architecture with a data dictionary, metadata and complete data lineage |
| 5 | Group-wide data quality management | Data quality standards, controls and remediation across the group |
| 6 | Timeliness of internal risk reporting | Generally no more than 20 working days for a monthly or quarterly risk report in normal times; ad hoc capability in stress |
| 7 | Effective implementation programmes | Funded programmes with milestones, owners and progress reporting |

## Supervisory focus in 2025 and 2026

The pressure has not eased. In its [supervisory priorities for 2026-28](https://www.bankingsupervision.europa.eu/framework/priorities/html/ssm.supervisory_priorities202511.en.html), published in November 2025, the ECB states that the 2025 SREP showed persistent RDARR deficiencies, "with no improvement in the relevant average sub-score". The weaknesses it names are data governance (including board involvement), data infrastructure and IT architecture, and data accuracy and integrity. Planned activities include system-wide monitoring, targeted on-site inspections and follow-up of severe findings.

The ECB's [annual report for 2025](https://www.bankingsupervision.europa.eu/press/other-publications/annual-report/html/ssm.ar2025~6ee989dc7e.en.html) adds that, where initial measures did not bring timely results, the ECB used binding supervisory measures under Article 16 of the SSM Regulation.

## What it means in Luxembourg

| Institution type | Supervisor | Reference point for risk data |
|---|---|---|
| Significant institutions (SIs) | ECB, with the CSSF in the joint supervisory teams | ECB RDARR guide of May 2024, BCBS 239, SREP findings |
| Less significant institutions (LSIs) | CSSF, under ECB oversight | Circular CSSF 12/552, which refers to BCBS 239 |

For LSIs, the main Luxembourg text is [Circular CSSF 12/552](https://www.cssf.lu/wp-content/uploads/cssf12_552eng.pdf) on central administration, internal governance and risk management, last amended by Circular CSSF 24/860 in the consolidated version consulted. Its point 132 requires the head of the risk management function to give management and the supervisory body "an independent, comprehensive, objective and relevant overview" of the risks, with a footnote stating that this is in line with BCBS 239. The ECB guide's annex lists this same point, together with point 30 of Circular CSSF 11/506 on stress testing, as Luxembourg's transposition of the relevant CRD provisions.

The ECB guide is formally addressed to significant institutions. For an LSI, it is not a CSSF requirement, but it is the most detailed public description of what European supervisors regard as adequate RDARR, and it was drawn up together with national authorities.

## What to do now

1. **Run a gap assessment** against the 14 principles and the seven ECB areas, and record it at board level.
2. **Define the scope**: list the material legal entities, risks and reports covered, including supervisory and financial reporting.
3. **Name data owners** for critical risk data elements and give them authority over definitions and quality thresholds.
4. **Document data lineage** for the key risk indicators, from source system to board report, and count the manual adjustments along the way.
5. **Measure production times** of monthly and quarterly risk reports against the ECB's 20-working-day reference.
6. **Set up an implementation programme** with budget, milestones and progress reporting to the management body, rather than a series of separate fixes.

## Questions & answers
**What is BCBS 239?**
It is the Basel Committee on Banking Supervision's standard number 239, "Principles for effective risk data aggregation and risk reporting", published in January 2013. Its 14 principles cover governance, data architecture, aggregation capabilities, risk reporting and supervisory review.

**Does BCBS 239 apply to banks in Luxembourg?**
BCBS 239 is not EU law, but supervisors use it as the benchmark. The ECB applies it to significant institutions through its May 2024 guide, and the CSSF's Circular 12/552 refers to it for the risk reporting of credit institutions it supervises.

**What is RDARR?**
RDARR stands for risk data aggregation and risk reporting, the term the ECB uses for the capabilities described in BCBS 239.

**What does the ECB consider too slow for internal risk reporting?**
The ECB guide states that, in normal situations, institutions will generally not be able to react in time if a monthly or quarterly risk report needs more than 20 working days to produce.

**Is the ECB's RDARR guide binding?**
The guide itself does not impose new requirements; it sets out how the ECB interprets existing CRD-based national law. The ECB has, however, used binding supervisory measures under Article 16 of the SSM Regulation where banks did not remediate in time.

## Sources
1. [Principles for effective risk data aggregation and risk reporting (BCBS 239)](https://www.bis.org/publ/bcbs239.htm) · Bank for International Settlements
2. [Progress in adopting the Principles for effective risk data aggregation and risk reporting (28 November 2023)](https://www.bis.org/bcbs/publ/d559.htm) · Bank for International Settlements
3. [Guide on effective risk data aggregation and risk reporting (May 2024)](https://www.bankingsupervision.europa.eu/ecb/pub/pdf/ssm.supervisory_guides240503_riskreporting.en.pdf) · ECB Banking Supervision
4. [Report on the Thematic Review on effective risk data aggregation and risk reporting (May 2018)](https://www.bankingsupervision.europa.eu/ecb/pub/pdf/ssm.BCBS_239_report_201805.pdf) · ECB Banking Supervision
5. [ECB Banking Supervision: supervisory priorities 2026-28](https://www.bankingsupervision.europa.eu/framework/priorities/html/ssm.supervisory_priorities202511.en.html) · ECB Banking Supervision
6. [ECB Annual Report on supervisory activities 2025](https://www.bankingsupervision.europa.eu/press/other-publications/annual-report/html/ssm.ar2025~6ee989dc7e.en.html) · ECB Banking Supervision
7. [Circular CSSF 12/552 on central administration, internal governance and risk management (as amended)](https://www.cssf.lu/wp-content/uploads/cssf12_552eng.pdf) · CSSF
8. [Single Supervisory Mechanism (SSM)](https://www.cssf.lu/en/single-supervisory-mechanism/) · CSSF
9. [Basel Committee report on implementing principles for effective risk data aggregation and reporting](https://www.regulationtomorrow.com/2023/11/basel-committee-report-on-implementing-principles-for-effective-risk-data-aggregation-and-reporting-shows-progress-made-but-significant-work-remains/) · Regulation Tomorrow (Norton Rose Fulbright)
10. [BCBS 239](https://en.wikipedia.org/wiki/BCBS_239) · Wikipedia
