Your Risk Report Is Only as Good as the Data Beneath It

Risk reporting can look increasingly sophisticated at the top of an organisation. Board packs bring together key risk indicators, limits, trends, incidents and control information in formats designed to make complex exposures easier to understand.

Yet beneath that apparent clarity, supervisors are still finding problems that are much less polished.

Risk data aggregation and risk reporting (RDARR) remains an explicit European Central Bank supervisory priority for 2026–28. The ECB says progress in addressing structural deficiencies remains slow, with the 2025 Supervisory Review and Evaluation Process showing no improvement in the relevant average sub-score. Its supervisory work continues to identify weaknesses in data governance, management-body involvement, IT and data architecture, and data accuracy and integrity.

That creates an important tension for boards and senior management. A report may be concise, coherent and apparently authoritative while the data used to produce it has travelled through fragmented systems, inconsistent definitions, manual adjustments and repeated reconciliation.

The quality of the presentation cannot resolve weaknesses in the information underneath it.

Where risk information loses its integrity

Most large financial institutions do not have one clean source of risk data.

Information is generated across products, legal entities, business units and jurisdictions. Operational events may sit in one system, controls in another and key indicators somewhere else. Legacy platforms, acquisitions and local requirements add further complexity, which can make even a seemingly simple question surprisingly difficult to answer.

That does not automatically make the resulting information unreliable, though. The difficulty comes when an organisation cannot aggregate those sources consistently or explain what has happened to the data as it moves between them.

The Basel Committee highlighted this again in its 2026 work on BCBS 239, pointing to persistent challenges around data lineage, decentralised data environments and legacy systems. It also noted the difficulty internationally active banks can face when trying to align practices across subsidiaries and local entities before aggregating information at group level.

Definitions matter just as much as systems. Two business units can both report an operational event while applying different thresholds for what constitutes one. A control described as “effective” may be assessed against different criteria. Risk categories that appear comparable may contain materially different exposures.

Aggregation under those conditions can create precision without comparability.

Common taxonomies therefore have a practical governance purpose. Uniform definitions and consistent classifications help information retain its meaning as it moves across systems and organisational boundaries. Without them, firms can aggregate numbers without necessarily aggregating the same thing.

Manual intervention presents a similar problem. Reconciliations and spreadsheets may be necessary where legacy architecture cannot yet support a cleaner process, but repeated corrections downstream can disguise weaknesses at source.

ECB supervisory work has identified inadequate data lineage, weakly controlled manual workarounds, insufficient taxonomies and inappropriate allocation of data ownership among the recurring deficiencies in firms’ arrangements.

A reconciliation process can fix a number before it reaches the board. It does not necessarily fix the underlying reason the number was wrong.

A report can be accurate and still fail the decision

Data quality is sometimes treated as synonymous with accuracy. For risk management, that is too narrow.

BCBS 239 also requires completeness, timeliness and adaptability. Banks should be able to aggregate material risk data across the organisation and respond to ad hoc requests, including during periods of stress.

Timeliness deserves particular attention.

A figure may be technically accurate when it reaches senior management but still arrive too late to influence the decision for which it was needed. That becomes more important when conditions are changing quickly and management needs a consolidated view outside the normal reporting timetable.

Consider a sudden market event that prompts senior management to ask for the organisation’s total exposure to a particular sector. Producing the answer may require data from several legal entities, different systems and locally maintained classifications. If teams must extract files, translate definitions and reconcile discrepancies manually before management can see the overall exposure, the weakness has moved beyond operational inconvenience.

It has affected the organisation’s ability to make a risk decision.

This is why the Basel Committee continues to emphasise the ability to produce ad hoc risk information and to test that capability in normal conditions. Discovering during a crisis that important exposures cannot be aggregated quickly enough is a serious indication that the information architecture is not working as it should.

Decision-grade risk information therefore involves more than arriving at the correct final number. Management also needs to understand its scope, its age, any material limitations and the assumptions involved in producing it.

Data governance reaches the board

Persistent RDARR weaknesses are often described as a technology problem because legacy architecture is frequently involved.

But decisions about definitions, ownership, remediation, quality standards and acceptable manual intervention are governance decisions.

The ECB places explicit responsibility on management bodies for overseeing risk data aggregation and reporting. Its 2026–28 priorities continue that focus, with supervisory attention extending from management-body accountability into data-quality management and IT and data architecture. The ECB has also indicated that supervisory efforts will intensify where weaknesses remain severe or difficult to remediate.

Boards do not need to understand every transformation at field level, but they do need confidence that the organisation can explain where material risk information came from and how it was produced.

If a significant exposure appears in a board paper, somebody should be able to trace it back through the information chain: which entities and systems contributed to it, which definitions were applied, whether data was adjusted or reconciled, and where material limitations remain.

That is a more demanding test than whether the final report looks coherent.

Better risk data starts with consistency: common definitions, clear ownership and the ability to trace important information from source to report. Technology matters, but so does fixing data-quality problems at source rather than repeatedly correcting them downstream.

The same principle applies across GRAC information. Risks, controls, processes, causes, events and indicators become more useful when organisations can classify and relate them consistently. Their value increases when management can understand not only each data point in isolation, but also how it connects to the wider risk picture.

For boards, this changes the standard by which a risk report should be judged. The question is not simply whether the pack contains the right metrics or whether management received it on schedule. Confidence must extend down through the information chain.

As supervisory attention continues through 2026–28, firms that still treat RDARR as a reporting remediation exercise may miss the broader governance issue. The stronger test will come when circumstances demand an answer that was not anticipated by the normal reporting cycle.

At that point, the quality of the dashboard matters far less than whether the organisation can assemble the underlying risk information quickly, consistently and with enough traceability for management to act on it – which makes weak data foundations a very real governance problem.

Stay up to date with the latest news and views from the world of governance, risk, audit and compliance >>>

Facebook
Twitter
LinkedIn