The bank designs, builds and maintains data architecture and IT infrastructure that fully support aggregation and reporting in normal times and in stress or crisis while still meeting the other Principles. Aggregation and reporting are considered directly in business continuity planning and covered by a business impact analysis. The bank has integrated data taxonomies and architecture across the group, with metadata and single identifiers or unified naming conventions for legal entities, counterparties, customers and accounts (one data model is not required, but where several are used there must be robust automated reconciliation). Roles and responsibilities for ownership and quality of risk data are set for business and IT owners, who with risk managers keep adequate controls over the data lifecycle and the technology; the business owner ensures data is entered correctly by the front office, kept current and aligned with definitions. The 2013 paper adds that aggregation capabilities must be strong enough that reports reflect risk reliably and that the Principles are met together, not one at the expense of another.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.