About a-team Marketing Services
The knowledge platform for the financial technology industry

A-Team Insight Blogs

Tata Consultancy Services Details a Strategic Approach to BCBS 239 Compliance

Subscribe to our newsletter

As the January 2016 deadline for compliance with BCBS 239 approaches, banks are making substantial data management changes in order to meet the regulation’s requirement for on-demand enterprise-wide risk data aggregation and reporting. The task is not easy and includes data management challenges posed by data silos, legacy systems and poor data governance practices, but emerging data architectures and governance regimes that identify and manage risk can support not only compliance, but also more adaptable and scalable business.


Tata Consultancy Services (TCS) identifies where current data aggregation frameworks are failing and recommends an approach to BCBS 239 that will enable an automated on-demand view of a bank’s risk profile in ‘A Point of View’ paper authored by information architecture specialists Maryann Houglet and Lilian Penna, and entitled BCBS 239: An Urgent Call to Overhaul Risk Data Management.

The paper notes shortcomings in banks’ governance, risk and compliance programmes, and ongoing problems presented by silod IT operations for business functions, and states: “BCBS 239 could be the game changer. The regulation explicitly and directly tackles banks’ data architecture and the governance regime needed to identify and manage risks.”

While globally, systematically important banks will be first to face BCBS 239 compliance in January 2016, the regulation does not stop here, with numerous national regulatory bodies also requiring domestic systemically important banks to comply. Many are taking a tactical approach to compliance, but TCS argues that banks need strategic solutions and sets out a step-by-step approach to improving risk data management through the establishment of a risk data strategy, an architectural framework and a roadmap to BCBS 239 compliance.

The consultancy acknowledges that banks differ in their risk tolerance, profile and data management maturity, and must therefore drive their own approaches to aligning information and data architecture with a risk management framework, but warns: “Moving forward without a plan that incorporates parallel businesses, data and governance programmes can distract from achieving a bank’s compliance goal, introduce risks and increase the time and cost required for compliance.” On a wider scale, it concludes: “The urgency of achieving risk data clarity and transparency through data management principles mandated by BCBS 239 cannot be overemphasised.”

Subscribe to our newsletter

Related content

WEBINAR

Recorded Webinar: The ROI of Data Trust: Quantifying the Business Value of Data Observability

Data is the fuel that keeps modern financial institutions’ motors running but if that data can’t be trusted then the decisions made based upon it, or the uses to which its put, will be compromised. That’s especially important for data that’s fed into artificial intelligence models. If the data isn’t clean, accurate and complete, then...

BLOG

smartKYC QnA: Accelerating Due Diligence at Scale

Hugo Chamberlain is the chief commercial officer of UK-based smartKYC, which has been automating the KYC process since 2014. Data Management Insight spoke to Hugo to find out how the company is helping financial institutions streamline their onboarding processes. Data Management Insight: Hello Hugo. When was smartKYC created and how does it serve financial institutions?...

EVENT

Data Management Summit New York City

Now in its 15th year the Data Management Summit NYC brings together the North American data management community to explore how data strategy is evolving to drive business outcomes and speed to market in changing times.

GUIDE

Regulatory Data Handbook 2026 – Fourteenth Edition

Welcome to the fourteenth edition of A-Team Group’s Regulatory Data Handbook. Supervisors increasingly expect firms to demonstrate which rules apply, which data supports each obligation, who owns the control and how exceptions are identified and resolved. Policies and implementation programmes must now be supported by records that can withstand regulatory scrutiny. This edition examines material...