AI Regulation Tracker · Basel Committee · Framework

What does BCBS 239 say about AI in banking?

Published Jan 9, 2013 · Last reviewed Sep 10, 2026

BCBS 239, published by the Basel Committee on 9 January 2013, sets 14 principles for how banks govern, aggregate, and report risk data, covering governance and IT infrastructure, data accuracy, completeness, timeliness and adaptability, and supervisory review. G-SIBs had to comply by the beginning of 2016 and D-SIBs within three years of designation. It has become the data-governance foundation banks cite when supervisors ask how the data feeding AI and machine-learning models is controlled.

OFFICIAL TEXT: bis.org · IN FORCE · BASEL COMMITTEE

DocumentBCBS 239Principles for effective risk data aggregation and risk reporting
Issued byBasel Committee on Banking Supervision (BCBS)
TypeFramework
StatusIn force
PublishedJan 9, 2013
EffectiveJan 1, 2016
Applies toGlobal systemically important banks (G-SIBs) from the beginning of 2016; domestic systemically important banks (D-SIBs) three years after designation; widely applied by supervisors to other large banks
Official sourcebis.org
Use casesModel risk management · AI governance (general) · Data & privacy

What are the key points of BCBS 239?

  • 14 principles in four groups: overarching governance and infrastructure (Principles 1–2), risk data aggregation capabilities (3–6), risk reporting practices (7–11), and supervisory review, tools and cooperation (12–14).
  • Principle 1 makes the board and senior management accountable for risk data aggregation and reporting; Principle 2 requires IT and data architecture that supports the capabilities in normal times and in stress.
  • Principles 3–6 require risk data to be accurate and reliable, complete across business lines and legal entities, timely, and adaptable to ad-hoc requests including in crisis.
  • Compliance deadline: G-SIBs designated in November 2011 or 2012 by the beginning of 2016; D-SIBs three years after national designation.
  • Written after the 2007–09 crisis, when many banks could not aggregate exposures or identify concentrations 'fully, quickly and accurately'.
  • A 6 January 2026 Basel Committee newsletter (bcbs_nl36) reports data-driven culture, data lineage, and ad-hoc reporting still 'a work in progress' and notes that AI and advanced automation depend on the same high-quality data.

What did BCBS 239 change for banks?

BCBS 239 predates the current AI wave, but it is the standard examiners reach for when reviewing model inputs: data lineage, ownership, quality controls, and the ability to trace a number from a report back to source. Banks building AI governance programs typically map training-data and feature-pipeline controls onto BCBS 239 principles rather than inventing a new framework, and the ECB, PRA, and US agencies have all leaned on it in data-quality findings that increasingly concern AI/ML use.

What is BCBS 239 and what are its 14 principles?

BCBS 239 is the Basel Committee on Banking Supervision's January 2013 paper 'Principles for effective risk data aggregation and risk reporting' — the 239th Basel Committee publication, which is where the number comes from. It sets 14 principles in four groups: overarching governance and infrastructure (Principles 1–2), risk data aggregation capabilities (3–6), risk reporting practices (7–11), and supervisory review, tools and cooperation (12–14). It is not a regulation but a supervisory expectation: global systemically important banks had to meet it by the beginning of 2016, national supervisors are 'strongly suggested' to apply it to domestic systemically important banks three years after their designation, and supervisors enforce it through Pillar 2 measures. The official text is a 28-page PDF on bis.org, linked in the table below.

RuleAuthorityWhat it requiresApplies
Official text (PDF)Basel CommitteePrinciples for effective risk data aggregation and risk reporting, Basel Committee on Banking Supervision, 9 January 2013 — the primary source for everything below.Published Jan 2013
Principle 1 — GovernanceBasel CommitteeRisk data aggregation and risk reporting must sit under strong governance arrangements consistent with the Committee's other principles; the board and senior management own them.G-SIBs from 2016
Principle 2 — Data architecture and IT infrastructureBasel CommitteeDesign, build and maintain data architecture and IT infrastructure that fully supports aggregation and reporting in normal times and in stress or crisis.G-SIBs from 2016
Principle 3 — Accuracy and integrityBasel CommitteeGenerate accurate and reliable risk data; aggregate on a largely automated basis to minimise the probability of errors.G-SIBs from 2016
Principle 4 — CompletenessBasel CommitteeCapture and aggregate all material risk data across the group, available by business line, legal entity, asset type, industry, region and other relevant groupings.G-SIBs from 2016
Principle 5 — TimelinessBasel CommitteeGenerate aggregate, up-to-date risk data in a timely manner, with timing set by the volatility and criticality of the risk and by normal and stress reporting needs.G-SIBs from 2016
Principle 6 — AdaptabilityBasel CommitteeMeet a broad range of on-demand, ad hoc reporting requests, including in stress, for changing internal needs and for supervisory queries.G-SIBs from 2016
Principle 7 — Accuracy (reporting)Basel CommitteeRisk reports must accurately and precisely convey aggregated data and be reconciled and validated.G-SIBs from 2016
Principle 8 — ComprehensivenessBasel CommitteeReports cover all material risk areas, with depth and scope matching the bank's size, complexity and risk profile and the recipients' requirements.G-SIBs from 2016
Principle 9 — Clarity and usefulnessBasel CommitteeReports communicate clearly and concisely, balancing data, analysis, interpretation and qualitative explanation, tailored to the recipients.G-SIBs from 2016
Principle 10 — FrequencyBasel CommitteeThe board and senior management set report frequency to reflect recipients' needs and how fast the risk can change; frequency increases in stress or crisis.G-SIBs from 2016
Principle 11 — DistributionBasel CommitteeReports reach the relevant parties while confidentiality is maintained.G-SIBs from 2016
Principle 12 — ReviewBasel CommitteeSupervisors periodically review and evaluate a bank's compliance with Principles 1–11.Supervisors
Principle 13 — Remedial actions and supervisory measuresBasel CommitteeSupervisors have and use tools — including Pillar 2 — to require effective and timely remediation of deficiencies.Supervisors
Principle 14 — Home/host cooperationBasel CommitteeHome and host supervisors cooperate on the review of the principles and on any remedial action.Supervisors
Basel Committee newsletter on BCBS 239 implementationBasel CommitteeJanuary 2026 assessment: data-driven culture, data lineage and ad hoc reporting remain 'a work in progress'; AI and advanced automation depend on the same high-quality data.Jan 2026

The paper was written for the world the 2007–09 crisis exposed: banks that could not aggregate their exposures to a single counterparty across legal entities, or could not produce a group-wide picture of a risk in days rather than weeks. The Committee's stated goal is that a bank's risk data is 'fully, quickly and accurately' available in stress, which is why the aggregation principles are written around stress and ad hoc requests rather than routine reporting. The four groups map onto four questions supervisors still ask: who owns the data (I), can you produce it (II), can you present it (III), and what happens if you can't (IV).

Scope is the bank's risk-management data — the data critical to enabling it to manage the risks it faces, including data for regulatory capital and liquidity reporting, and the Committee expects the principles to be applied to key internal risk-management models. Principles 3 and 4 together are the operational core: 'largely automated' aggregation and completeness by business line, legal entity, asset type, industry and region are what data lineage tooling, data dictionaries and control frameworks exist to prove. Principle 6, adaptability, is the one most often cited in supervisory findings, because ad hoc requests are where manual workarounds surface.

More than a decade on, no supervisor treats it as finished. The Committee's implementation newsletter of 6 January 2026 says data-driven culture, data lineage and ad hoc reporting are still 'a work in progress' at the banks it reviewed, and the ECB published its own Guide on effective risk data aggregation and risk reporting in May 2024 to turn the principles into concrete expectations for the banks it supervises. Where BCBS 239 meets AI is Principle 3: models — including machine-learning and generative systems — are only as controlled as the data pipelines feeding them, and the same lineage, ownership and quality controls that examiners assess under BCBS 239 are what they ask about when reviewing AI training data and feature stores.

WHAT THIS MEANS IN PRACTICE

  • The 14 principles are a checklist supervisors actually use: map every risk data flow feeding a model to an owner (Principle 1), a documented lineage (Principle 3) and an ad hoc extraction path (Principle 6) before an examiner asks.
  • BCBS 239 has no 'data quality rules' of its own — accuracy, completeness and timeliness are the dimensions; the thresholds are the bank's to set and evidence.
  • Treat AI training data as risk data: the January 2026 newsletter makes the link explicit, and the ECB's 2024 guide expects the same controls over model inputs.
  • For D-SIBs the clock starts at designation — three years — and national supervisors decide which other banks are assessed; ask your supervisor rather than assuming you are out of scope.

How does BCBS 239 apply to the data behind AI and machine-learning models?

BCBS 239 never mentions artificial intelligence, but it is the standard supervisors reach for when they ask how the data feeding a bank's AI and machine-learning models is governed. Its scope is the bank's risk-management data, including the data behind key internal models, and its first six principles map directly onto an AI data pipeline: a named owner and board accountability (Principle 1), architecture that works under stress (Principle 2), accuracy and integrity with documented lineage and 'largely automated' aggregation (Principle 3), completeness across entities and business lines (Principle 4), timeliness (Principle 5) and adaptability to ad hoc requests (Principle 6). The Basel Committee's January 2026 implementation newsletter made the link explicit, saying AI and advanced automation depend on high-quality data and make robust data management more important, and the 2026 US model-risk guidance, the EU AI Act's data-governance article and the ECB's internal-models guide each restate the same expectations for model inputs in their own terms.

RuleAuthorityWhat it requiresApplies
BCBS 239, Principles 1–6Basel CommitteeOwnership and board accountability, supporting architecture, accuracy with lineage and largely automated aggregation, completeness, timeliness and adaptability for all risk-management data, including the data behind key internal models.G-SIBs from 2016; D-SIBs 3 years after designation
BCBS 239 implementation newsletterBasel CommitteeData lineage and ad hoc reporting still 'a work in progress'; AI and advanced automation depend on high-quality data, so robust data management matters more, not less.Published Jan 6, 2026
SR 26-2 / OCC Bulletin 2026-13Federal ReserveUS model risk management retains the expectation that input data be assessed for quality and relevance as part of sound development and conceptual-soundness review, scaled to materiality.In force from Apr 17, 2026
EU AI Act, Article 10 (data and data governance)EU AI ActHigh-risk systems, including credit scoring of natural persons, need training, validation and testing data subject to documented governance: design choices, provenance, preparation, bias examination, gaps and their remedies.Stand-alone Annex III obligations from Dec 2, 2027
ECB Guide to internal models, ML sectionECBML capital models must be adequately explainable and their complexity justified; the data behind them sits inside the ECB's internal-model data-quality expectations.In force from Jul 28, 2025
EBA Guidelines on loan origination and monitoringEBAAutomated creditworthiness models need governance of their design and data, proportionate model-risk management, and staff able to interpret and override outputs.In force from Jun 30, 2021
NIST AI RMF 1.0, Map and Measure functionsNISTVoluntary framework whose Map and Measure outcomes cover data provenance, representativeness and quality for AI systems.Voluntary

The reason BCBS 239 travels so well into AI is that it was written about a failure of data rather than a failure of models. In 2007–09 banks could not aggregate exposures to a counterparty across legal entities or produce a group-wide view of a risk in days. The Committee's remedy was to make risk data a governed asset: owned, architected, traceable from report to source, complete, timely and available for questions nobody planned for. A training dataset, a feature store and a retrieval corpus are risk data in exactly that sense, and an examiner reviewing an AI model's inputs asks the BCBS 239 questions whether or not the paper is cited: who owns this data, where did it come from, how do you know it is complete and current, and could you re-run it tomorrow with a different cut?

Three principles carry most of the weight for AI. Principle 3, accuracy and integrity, is where lineage lives, and lineage is what makes a model's output defensible when a supervisor, an auditor or a declined customer asks how a number was produced; the Committee's 2026 newsletter singles out lineage as the capability legacy systems still frustrate. Principle 4, completeness, is the control against models trained on a subset that silently excludes a business line, a legal entity or a population. Principle 6, adaptability, is the ad hoc test: a bank that cannot reproduce or re-cut the data behind a model on request has a model it cannot explain in a crisis.

Newer rules restate the same expectations in their own vocabulary. The 2026 US model-risk guidance keeps data quality and relevance inside conceptual-soundness review. The EU AI Act's Article 10 turns data governance into a legal duty for high-risk systems such as consumer credit scoring, with provenance, preparation, bias examination and gap analysis to be documented, from December 2, 2027 for stand-alone Annex III systems after the Digital Omnibus deferral. The ECB's internal-models guide asks whether an ML model's complexity is justified by performance, a question that cannot be answered without controlled data. A bank that has genuinely implemented BCBS 239 for its risk data has most of the evidence these regimes ask for; the gap is usually that AI datasets were assembled outside the governed perimeter.

WHAT THIS MEANS IN PRACTICE

  • Classify training, validation and inference datasets for material AI models as risk data under the BCBS 239 framework, with a named owner, a lineage record and a data-quality threshold for each.
  • Make lineage the first artefact a model validation asks for: source systems, transformations, feature definitions and the date of the cut, reproducible on demand (Principles 3 and 6).
  • Test completeness explicitly: which entities, products, periods and populations are absent from the training set, and what that does to the model's outputs (Principle 4).
  • For EU credit scoring, map the BCBS 239 evidence onto Article 10 of the AI Act now; the December 2, 2027 date is a deadline for documentation that takes years to assemble.
  • Expect the question from the board: the Committee's 2026 newsletter says boards must oversee risk data aggregation, and AI has made data the board-level risk it was always meant to be.

Does BCBS 239 apply to AI training data?

Not explicitly, but its principles on accuracy, completeness, lineage, and governance apply to any risk data, and supervisors expect banks to demonstrate the same controls over data used to train and run AI/ML models. The Committee's January 2026 newsletter says AI and advanced automation make robust data management more important, not less.

Which banks must comply with BCBS 239?

G-SIBs from the beginning of 2016 and D-SIBs three years after designation, with national supervisors free to apply it more widely. In practice most large internationally active banks are assessed against it.

DateDocumentStatus
Jun 2, 2026BCBS ICT Risk Management Report (June 2026)Information and communication technology risk management: range of practicesFinal
Jan 6, 2026BCBS 239 Implementation Newsletter (Jan 2026)Implementation of the Principles for effective risk data aggregation and risk reporting (BCBS 239 Principles)Final
Dec 10, 2025BCBS Third-Party Risk Principles (Dec 2025)Principles for the sound management of third-party riskIn force
Feb 4, 2025BCBS Work Programme 2025–26Basel Committee work programme and strategic priorities for 2025/26In force
May 16, 2024BCBS Digitalisation of finance report (May 2024)Digitalisation of financeFinal
Mar 16, 2022BCBS AI/ML Newsletter (March 2022)Newsletter on artificial intelligence and machine learningFinal

Which banks' AI programmes does BCBS 239 reach?

6 of the 100 largest US banks profiled on this site cite BCBS 239 among the documents their AI work answers to.

Follow every document these regulators publish

the daily brief · six sourced stories · in your inbox by 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning