Skip to main content
Category: Risk Reporting and Indicators

Risk Aggregation Reporting

Also known as: Risk Data Aggregation and Risk Reporting, RDARR
Simply put

Risk aggregation reporting is the practice of combining many individual risks into a single, overall view so that decision-makers can understand an organization's total risk exposure rather than looking at each risk in isolation. It also covers how that combined information is gathered, processed, and communicated to those who need it. In banking, this practice is closely associated with supervisory expectations for how risk data is collected and reported.

Formal definition

Risk aggregation reporting refers to the combination of several individual risks into a consolidated measure of overall risk exposure to support a more complete understanding of an organization's risk profile, together with the processes for defining, gathering, processing, and communicating the underlying risk data. Risk data aggregation, in this sense, means defining, gathering, and processing risk data according to an organization's risk reporting requirements. In the banking sector, these activities are commonly framed under Risk Data Aggregation and Risk Reporting (RDARR), described as the practical implementation of the principles set out by the Basel Committee on Banking Supervision in BCBS 239, whose stated objectives include strengthening risk management and improving decision-making. This entry addresses the concept of aggregation and reporting; it does not cover specific aggregation methodologies, correlation modeling techniques, tooling, or the detailed provisions of any particular regulation, and the applicability of RDARR expectations varies by jurisdiction, sector, and institution.

Why it matters

Individual risks viewed in isolation can understate an organization's true exposure. A single business unit may operate within its own limits while similar exposures accumulate across the enterprise, producing concentrations that only become visible when data is combined. Risk aggregation reporting exists to give boards and senior management a consolidated view of overall risk, supporting a more complete understanding of the risk profile than fragmented, siloed reporting allows. In many frameworks this consolidated view is treated as a precondition for informed decision-making and effective risk oversight.

In the banking sector, aggregation and reporting expectations are commonly framed under Risk Data Aggregation and Risk Reporting (RDARR), described as the practical implementation of the principles set out by the Basel Committee on Banking Supervision in BCBS 239. The stated objectives of these principles include strengthening risk management and improving decision-making. The emphasis on aggregation capability reflects a supervisory concern that institutions be able to produce accurate, timely, and complete risk information, particularly under stress, when the demand for reliable aggregated data is greatest.

The applicability of these expectations varies by jurisdiction, sector, and institution. RDARR expectations are specific to banking supervision and should not be presented as universal obligations across all organizations. Outside that context, aggregation reporting remains a general risk management practice rather than a mandated regime, and the rigor applied typically scales with the size and complexity of the organization.

Who it's relevant to

Risk managers
Risk managers use aggregation reporting to move beyond individual risk assessments toward a consolidated view of overall exposure, helping them identify concentrations and understand the organization's risk profile as a whole. They are typically responsible for defining the risk reporting requirements against which data is gathered and processed.
Boards and senior management
Boards and senior executives rely on aggregated risk reporting to support informed oversight and decision-making, as strengthening risk management and improving decision-making are among the stated objectives of the principles underlying RDARR in banking. Consolidated reporting is intended to give them a complete rather than fragmented picture of exposure.
Banking compliance and regulatory reporting teams
In banks, teams responsible for supervisory expectations engage with RDARR as the practical implementation of the principles set out by the Basel Committee on Banking Supervision in BCBS 239. The relevance and detailed requirements vary by jurisdiction, sector, and institution, so these teams should confirm the specific expectations that apply to their organization.
Data and reporting functions
Functions responsible for defining, gathering, and processing risk data support aggregation reporting by ensuring that underlying inputs align with the organization's risk reporting requirements, since the reliability of any consolidated view depends on the quality of the data feeding it.

Inside Risk Aggregation Reporting

Aggregated Risk Position
A consolidated view that combines individual risk exposures across business units, categories, or entities into a summary of the organization's overall risk position. The method of combination (for example, simple summation, correlation-adjusted aggregation, or scenario-based rollup) affects the result and should be stated.
Data Sourcing and Taxonomy
The underlying risk data drawn from risk registers, control assessments, loss events, and key risk indicators, organized under a common risk taxonomy. Consistent definitions and classifications across sources are needed for meaningful aggregation.
Aggregation Methodology
The documented approach used to combine exposures, including assumptions about correlation, diversification, and dependencies between risks. Different methodologies can produce materially different aggregate figures, so the basis is typically disclosed alongside results.
Reporting Dimensions
The axes along which aggregated risk is presented, such as risk category, business line, legal entity, geography, or time period. These dimensions allow recipients to view concentrations and trends.
Comparison to Appetite and Tolerance
Presentation of aggregated exposures relative to defined risk appetite and, where set, risk tolerance thresholds. Risk appetite expresses the amount of risk an organization is willing to pursue in aggregate, while tolerance typically refers to acceptable variation at a more granular level; the report should keep these distinct.
Governance and Audience
The intended recipients, commonly the board, board risk committee, or senior management, and the cadence of reporting. The report supports oversight and decision rights rather than performing risk treatment itself.
Data Quality and Limitations Disclosure
Statements on completeness, timeliness, and known limitations of the aggregation, including assumptions and areas of estimation. This supports informed interpretation by recipients.

Common questions

Answers to the questions practitioners most commonly ask about Risk Aggregation Reporting.

Does aggregating individual risks simply mean adding up their scores or values to get a total risk figure?
No. Risk aggregation is not a straightforward summation of individual risk scores or values. Simple addition typically overstates or misstates exposure because it ignores correlations, dependencies, diversification effects, and offsetting relationships between risks. In many frameworks, aggregation seeks to represent combined exposure in a way that reflects how risks interact, which may mean that the aggregate is less than, equal to, or in some cases greater than the arithmetic sum of components. The appropriate approach depends on the nature of the risks, the measurement basis, and the assumptions applied, which should be stated transparently in the reporting.
Is risk aggregation reporting an assurance activity performed by internal audit?
Not typically. Risk aggregation reporting is generally a management activity, commonly owned by a risk management function within the second line, that consolidates and communicates risk information to support decision-making and oversight. Internal audit, as a third line function, may independently evaluate the design and reliability of the aggregation process, the underlying data, and the reporting itself, but performing the aggregation would generally compromise the independence and objectivity expected of an assurance function. The distinction between producing the report and providing assurance over it should be kept clear.
At what organizational level should risks be aggregated for reporting?
The appropriate level depends on the intended audience and purpose of the report. Aggregation may occur at the level of a business unit, a risk category, a legal entity, a geography, or the enterprise as a whole. Reporting to a board or a risk committee commonly emphasizes higher, more consolidated views, while operational management may require more granular breakdowns. Many organizations define a hierarchy that allows risks to be rolled up and drilled down, so that the same underlying data can support different levels of reporting. The chosen levels should align with governance structures and decision rights.
How should we handle risks that are measured on different scales or in different units when aggregating?
Combining risks expressed in inconsistent scales or units, for example qualitative ratings alongside monetary estimates, is a common practical challenge. Approaches may include translating risks to a common basis where feasible, grouping risks that share a measurement method before consolidating, or presenting them side by side without forcing a single figure. Where a common quantitative basis is used, the conversion assumptions should be documented and their limitations disclosed. Forcing dissimilar measures into a single number can obscure meaning, so the reporting should make the basis of aggregation explicit.
What data quality considerations affect the reliability of aggregated risk reporting?
The reliability of an aggregate report depends heavily on the quality, consistency, and timeliness of the underlying inputs. Common considerations include consistent risk taxonomy and definitions across contributing areas, comparable assessment methods, clear ownership and source of data, controls over data entry and transformation, and version control. Inconsistent definitions or assessment scales across contributors can undermine comparability once risks are combined. Documenting data lineage and known limitations helps recipients interpret the report appropriately rather than treating aggregated figures as more precise than the inputs support.
How frequently should risk aggregation reporting be produced and refreshed?
Reporting frequency commonly reflects the volatility of the risks, the needs of the governance bodies receiving the report, and any applicable regulatory expectations, which may vary by jurisdiction and sector. Some organizations produce periodic reports aligned to committee or board cycles, while rapidly changing exposures may warrant more frequent or event-driven updates. Establishing a defined cadence, alongside triggers for interim reporting when material changes occur, helps ensure that decision-makers work from current information. The appropriate frequency should be set in the context of the organization's risk profile and oversight arrangements.

Common misconceptions

Aggregate risk is simply the sum of individual risks.
Combining exposures often involves assumptions about correlation and diversification. Simple summation may overstate exposure where risks are not perfectly correlated, or understate it where dependencies amplify losses. The chosen methodology, not arithmetic addition alone, drives the result.
Risk aggregation reporting is an assurance or audit activity.
Preparing and presenting aggregated risk information is typically a management or second-line activity supporting oversight and decision-making. It is distinct from independent assurance over the reporting process, which would generally be performed by internal audit or an equivalent third-line function to preserve objectivity.
A single aggregate number captures the organization's risk position.
A single figure can obscure concentrations, correlations, and the assumptions behind it. Useful reporting commonly presents multiple dimensions, thresholds relative to appetite, and disclosed limitations rather than relying on one summary metric.

Best practices

Apply a consistent risk taxonomy and common definitions across all data sources so that exposures being combined are genuinely comparable.
Document the aggregation methodology explicitly, including assumptions about correlation, diversification, and dependencies, and present results against that stated basis.
Report aggregated exposures relative to defined risk appetite and, where applicable, tolerance thresholds, keeping the two concepts clearly distinguished.
Disclose data quality issues, estimation, and known limitations alongside the figures so that recipients can interpret them appropriately.
Present multiple reporting dimensions, such as category, business line, and entity, to reveal concentrations that a single aggregate figure would mask.
Maintain a clear separation between management's preparation of the report and any independent assurance over the aggregation process to preserve objectivity.
Promotional banner for the Penetration Report Template Kit