ICT systems, risk data aggregation and risk reporting
Competent authorities should assess whether the institution’s ICT systems are reliable, resilient and adequate to measure, assess and report on the size, composition and quality of exposures across all the institution’s risk types, products and counterparties and fully support risk data aggregation capabilities at normal times and times of stress.
Competent authorities should verify whether the institution develops and maintains appropriate risk data aggregation and risk reporting capabilities commensurate with its risk profile and systemic importance. When reviewing the institution’s risk data aggregation and risk reporting capabilities, competent authorities should take into account the BCBS 239 principles for effective risk data aggregation and risk reporting(34) for supervised institutions that fall under the scope of those principles. In particular, competent authorities should assess whether the institution is able to generate accurate, consistent, complete and reliable risk data and reporting for the entire institution, capturing all material risks, and appropriately reflecting the institution’s risk profile and capital and liquidity needs, and whether these can be aggregated and made available in a timely and flexible manner to the management body and senior management. Where applicable, competent authorities should assess whether the institution has established an effective group-wide management information and reporting system applicable to all business units and legal entities, and this information is available to the management body of the institution’s parent undertaking on a timely basis.
Competent authorities should determine whether the management body of the institution approves the institution’s risk data aggregation and risk reporting framework and oversees its effective implementation, including deployment of adequate resources to support these efforts. Competent authorities should also assess whether the institution’s risk data aggregation capabilities and risk reporting practices are independently validated in accordance with the institution’s internal control framework.