InternationalModel riskIssued 2013, fully applicable to G-SIBs
BCBS 239

Principles for effective risk data aggregation and risk reporting

The baseline for data governance and risk reporting capability — directly applicable to AI systems in risk models and aggregation pipelines.

Depth of coverage

What we know in this framework.

The specific clauses, articles, appendices and supervisory expectations we work against — anchored to primary source and maintained as the regime evolves.

01Data architecture
02Data lineage
03Risk reporting capability
04Governance of risk data
How we cover it

How the firm carries BCBS 239 into client work.

BCBS 239 is read against the services below. Each one draws on the same compliance intelligence layer — indexed to primary source, versioned alongside the regulator, and carried into the engagement.

Related playbooks

Playbooks that ship against BCBS 239.

Each playbook walks from discovery through artifact — phases, controls, evidence. Agents assist the mechanical steps; specialists own the sign-off.

No standalone playbook is published for this framework yet. Our cross-framework control mapping still covers it — speak with a partner for a scoped plan.

Map your posture against BCBS 239.

Bring us your current documentation, controls and inventory. We will map them clause by clause against BCBS 239 — and against every other regime your portfolio touches — and produce the evidence artifact your supervisor will read.