My bookmarksSign up free

Commission Delegated Regulation (EU) 2022/439 CHAPTER 12 — ASSESSMENT METHODOLOGY FOR DATA MAINTENANCE

Article 72–Article 75 · 4 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

General

Article 72

1.   When assessing compliance with the requirements on data maintenance laid down in Article 144(1)(d) and Article 176 of Regulation (EU) No 575/2013, competent authorities shall evaluate all of the following: (a) the quality of the internal, external or pooled data, including the data quality management process, in accordance with Article 73; (b) the data documentation and reporting, in accordance with Article 74; (c) the relevant IT infrastructure, in accordance with Article 75. 2.   For the purpose of the assessment under paragraph 1, competent authorities shall apply all of the following methods: (a) review the data quality management policies, methods and procedures relevant to the data used in the IRB Approach; (b) review the relevant data quality reports, as well as their conclusions, findings and recommendations; (c) review the IT infrastructure policies and IT systems management procedures, including the contingency planning policies, relevant for the IT systems used for the purpose of the IRB Approach; (d) review the relevant minutes of the institution’s internal bodies, including management body, or committees; (e) review the relevant findings of the internal audit or of other control functions of the institution; (f) review the progress reports on the efforts made by the institution to correct shortcomings and mitigate risks detected during relevant audits; (g) obtain written statements from or interview the relevant staff and senior management of the institution. 3.   For the purpose of the assessment under paragraph 1, competent authorities may also apply any of the following additional methods: (a) perform own tests on the data of the institution or request the institution to perform tests proposed by the competent authorities; (b) review other relevant documents of the institution.

Data quality

Article 73

1.   When assessing the quality of internal, external or pooled data necessary to effectively support credit risk measurement and management process in accordance with Article 144(1)(d) and Article 176 of Regulation (EU) No 575/2013, competent authorities shall verify: (a) the completeness of values in the attributes that require them; (b) the accuracy of data ensuring that the data is substantively error-free; (c) the consistency of data ensuring that a given set of data can be matched across different data sources of the institution; (d) the timeliness of data values ensuring that the values are up-to-date; (e) the uniqueness of data ensuring that the aggregate data is free from any duplication given by filters or other transformations of source data; (f) the validity of data ensuring that the data is founded on an adequate system of classification, rigorous enough to compel acceptance; (g) the traceability of data ensuring that the history, processing and location of data under consideration can be easily traced. 2.   When assessing the data quality management process, competent authorities shall verify that: (a) all of the following are in place: (i) adequate data quality standards that set the objectives and the overall scope of the data quality management process; (ii) adequate policies, standards and procedures for data collection, storage, migration, actualisation and use; (iii) a practice of continuously updating and improving of the data quality management process; (iv) a set of criteria and procedures for determining conformity with the data quality standards, and in particular the general criteria and process of data reconciliation across and within systems including among accounting and internal ratings-based data; (v) adequate processes for internally assessing and constantly improving data quality, including the process of issuing internal recommendations to address problems in areas which need improvement and the process of implementing these recommendations with a priority based on their materiality and in particular the process for addressing material discrepancies arising during the data reconciliation process; (b) there is a sufficient degree of independence of the data collection process from the data quality management process, including a separation of the organizational structure and staff, where appropriate.

Data documentation and reporting

Article 74

1.   When assessing the documentation of data necessary to effectively support credit risk measurement and management process in accordance with Articles 144(1)(d) and 176 of Regulation (EU) No 575/2013 competent authorities shall evaluate all of the following: (a) the specification of the set of databases and in particular: (i) the global map of databases involved in the calculation systems used for the purpose of the IRB Approach; (ii) the relevant sources of data; (iii) the relevant processes of data extraction and transformation and criteria used in this regard; (iv) the relevant functional specification of databases, including their size, date of construction, data dictionaries specifying the content of the fields and of the different values inserted in the fields with clear definitions of data items; (v) the relevant technical specification of databases, including the type of database, tables, database management system and database architecture, and data models given in any standard data modelling notation; (vi) the relevant work-flows and procedures relating to data collection and data storage; (b) the data management policy and allocation of responsibilities, including users’ profiles and data owners; (c) the transparency, accessibility and consistency of the controls implemented in the data management framework. 2.   When assessing data reporting, competent authorities shall verify, in particular, that data reporting: (a) specifies the scope of reports or reviews, the findings and, where applicable, the recommendations to address weaknesses or shortcomings detected; (b) is communicated to the senior management and management body of the institution with an adequate frequency and that the level of the recipient of the data reporting is consistent with the institution's organizational structure, and the type and significance of the information; (c) is performed regularly and where appropriate, also on an ad hoc basis; (d) provides adequate evidence that the recommendations are sufficiently addressed and properly implemented by the institution.

IT infrastructure

Article 75

1.   When assessing the architecture of the IT systems, of relevance to the institution’s rating systems and to the application of the IRB Approach in accordance with Article 144 of Regulation (EU) No 575/2013, competent authorities shall evaluate all of the following: (a) the IT systems architecture including all applications, their interfaces and interactions; (b) a data flow diagram showing a map of the key applications, databases and IT components involved in the application of the IRB Approach and relating to rating systems; (c) the assignment of IT systems owners; (d) the capacity, scalability and efficiency of IT systems; (e) the manuals of the IT systems and databases. 2.   When assessing the soundness, safety and security of the IT infrastructure that is of relevance to the institution’s rating systems and to the application of the IRB Approach, competent authorities shall verify that: (a) the IT infrastructure can support the ordinary and extraordinary processes of an institution in a timely, automatic and flexible manner; (b) the risk of suspension of the abilities of the IT infrastructure (‘failures’), the risk of loss of data and the risk of incorrect evaluations (‘faults’) are appropriately addressed; (c) the IT infrastructure is adequately protected against theft, fraud, manipulation or sabotage of data or systems by malicious insiders or outsiders. 3.   When assessing the robustness of the IT infrastructure that is of relevance to the institution’s rating systems and to the application of the IRB Approach, competent authorities shall verify that: (a) the procedures to back up the IT systems, data and documentation are implemented and tested on a periodic basis; (b) continuity action plans are implemented for critical IT systems; (c) the recovery procedures of IT systems in case of failure are defined and tested on a periodic basis; (d) the management of IT systems users is compliant with the institution’s relevant policies and procedures; (e) audit trails are implemented for critical IT systems; (f) the management of changes of IT systems is adequate and the monitoring of changes covers all IT systems. 4.   When assessing whether the IT infrastructure that is of relevance to the institution’s rating systems and to the application of the IRB Approach is reviewed both regularly and on an ad hoc basis, competent authorities shall verify that: (a) regular monitoring and ad hoc reviews result in recommendations to address weaknesses or shortcomings, where detected; (b) the findings and the recommendations referred to in point (a) are communicated to the senior management and management body of the institution; (c) there is adequate evidence that the recommendations are properly addressed and implemented by the institution.

Back to Commission Delegated Regulation (EU) 2022/439 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next