BCBS 239 is entering a new phase. More than a decade after its introduction, supervisors now expect institutions to prove, with evidence, that their risk data is accurate, traceable, and trustworthy from source to report. The ECB's 2024 Guide on Risk Data Aggregation and Risk Reporting (RDARR) has raised the bar significantly, shifting the conversation from policy to proof.
Under the ECB's 2025–2027 supervisory priorities, remediating long-standing RDARR deficiencies ranks as the second highest priority for banks. Supervisors expect:
Clear governance and accountability across the three lines of defence
Complete, linked business and technical data lineage
Automated, continuously monitored data quality controls
Reporting that is timely, consistent, and explainable
This isn't simply about avoiding capital add-ons or intensified supervision. Institutions that treat this moment as a structural transformation gain something more durable: trusted, resilient data capabilities that support better decisions, forecasting, and risk management.
In our latest white paper, we break down what BCBS 239 excellence actually looks like in practice from governance and lineage to a structured four-phase approach for building sustainable RDARR maturity, illustrated with a real remediation case from a major Dutch bank.
👉 Curious how your organization can move from BCBS 239 compliance to competitive advantage?
Read the full insights in our whitepaper below:
Achieving BCBS 239 Excellence - from Compliance to Competitive Advantage