2017年-普华永道全球_BCBS_239_-_Raising_the_standard_18页_880kb
报告摘要
BCBS 239 – Raising the standard Summary
Core Content
BCBS 239, or the Basel Committee on Banking Supervision Principles for effective risk data aggregation and risk reporting, was introduced in January 2013. It has since become a de facto standard across the banking industry, with many national supervisors requiring compliance from both G-SIBs (Global Systemically Important Banks) and D-SIBs (Domestic Systemically Important Banks). Despite the three-year deadline, only one institution was deemed fully compliant by March 2017.
The principles are not only relevant to the banking sector but also influence other industries such as insurance, where IFRS17 has emerged as a similar benchmark. Implementation of BCBS 239 involves significant changes in data collection, storage, analysis, and reporting, necessitating enhanced data governance, systems, and processes.
Main Challenges and Delays
The delays in achieving compliance with BCBS 239 stem from several challenges:
- High-level and subjective nature of the principles – Lacking clear regulatory guidance and emphasis.
- Complexity and effort – Overhauling data, systems, and architecture requires substantial investment and effort.
- Management fatigue – Regulatory-driven programs have led to burnout and reduced focus.
- Overconfidence in current capabilities – Some banks believe they already meet the standards.
- Competing priorities – Budget constraints have led to spreading costs over multiple years.
- Alignment and momentum – Maintaining consistency across the banking group is difficult due to varying ambitions and supervisory regimes.
Key Focus Areas for G-SIBs
For G-SIBs not yet fully compliant, the key focus areas include:
- Implementation of a Data Management Strategy – Many have appointed Chief Data Officers and are rolling out foundational policies.
- Technology and Architecture Programs – Most rely on existing programs, but challenges remain due to interdependencies and complexity.
- Addressing End-to-End Control Weaknesses – Banks struggle with data quality, EUC (End User Computing) applications, and reconciliation controls.
Compliance Phases
Banks have adopted a three-phase approach to BCBS 239 compliance:
- Definition Phase – Understanding and interpreting the principles, defining compliance, and agreeing on an execution plan.
- Execution Phase – Implementing programs to address gaps and enhance capabilities in data management, risk reporting, governance, and technology.
- Continuous Improvement Phase – Embedding BCBS 239 disciplines into business-as-usual models and measuring ROI.
4 Pillar Capability Framework
The capability model is divided into four key pillars:
- Data Management – Enterprise-wide standards, golden sources, and consistent data models.
- Risk Standards and Processes – Documentation, standardisation of risk information, and integration of exception reporting.
- Governance and Control – Policies, independent validation, and escalation channels.
- Technology Infrastructure and Architecture – Group-wide IT strategy, automation, and flexible reporting capabilities.
Regulatory Perspectives
Supervisors have been evolving in their approach to BCBS 239 compliance:
- EU ECB – Active in enforcing compliance, conducting thematic reviews, and expecting progress on systems and data architecture.
- UK PRA – Conducting rolling 3-year assessments and requiring detailed compliance reviews.
- US Fed and OCC – The Fed has taken a hands-off approach, while the OCC has introduced heightened standards for large banks.
- Asia CBRC and JFSA – CBRC has issued guidelines similar to BCBS 239, while JFSA has been hands-on with frequent follow-ups.
- Singapore MAS – Still light in supervision, but planning to tighten reviews by 2019.
- Switzerland FINMA – Requires external audits and applies a strict interpretation of the principles.
Compliance Terminology and Challenges
There is inconsistency in the interpretation of compliance terms across institutions and supervisors:
- Largely Complied With – Often associated with a '3' rating, indicating minor actions are needed for full compliance.
- Material Compliance – Typically used interchangeably with 'Largely Complied With', but applied to a prioritised subset.
- Fully Complied With – A '4' rating, indicating full achievement of the principle's objectives, though debated due to the lack of a common benchmark.
- Compliance – Some banks have shifted to using this term to avoid the pressure of 'full compliance'.
- Continuous Improvement – An emerging interpretation where compliance is seen as ongoing and not a one-time event.
Key Takeaways for Banks
- Define Full Compliance Thresholds – Clear definitions and tangible measures are essential for compliance success.
- Start Early for D-SIBs and Smaller Banks – Early implementation helps avoid surprises and aligns with the de facto standard.
- Clarify Compliance Scope and Rationale – Formal scoping documents with detailed rationale are necessary for effective compliance.
- Develop a Strategic Risk Architecture – A robust architecture is crucial for achieving full compliance.
- Improve Data Quality and Controls – Data governance and quality are foundational to compliance.
- Enhance Governance and Validation – Independent validation and clear governance structures are required.
- Align with Supervisory Expectations – Supervisors are increasingly focusing on material entities and non-financial risks.
- Prepare for Continuous Improvement – Compliance is a continuous process, not a final destination.
Conclusion
BCBS 239 has had a significant impact on the banking industry, driving changes in data management, risk reporting, and technology infrastructure. While the principles are becoming more widely adopted, the lack of clear regulatory guidance and varying interpretations across jurisdictions have led to delays and inconsistencies. PwC recommends that banks adopt a capability-based approach, define clear compliance thresholds, and engage in continuous improvement to ensure resilience and alignment with regulatory expectations.
试读结束,高清完整版pdf/doc/ppt,请点下载