Building a scalable data foundation for BCBS239/RDARR at a Belgian Bank

Introduction

A Belgian bank and insurance company operating in a highly regulated environment where reliable, well-governed risk data underpins both regulatory compliance and sound decision-making. DTA has supported the institution since 2021, progressively strengthening its data quality and governance capabilities.

Client

Belgian Bank

Client since

2021

Technologies

No items found.
No items found.

The problem

The institution already had data governance and quality practices in place. As ECB regulatory requirements tightened, the bank decided to mature those capabilities rather than patch them. This means building a stronger, more reusable governance foundation on top of a central Data Catalog, integrated with its cloud data platform. The challenge was bringing governance, lineage, data quality, ownership, and management oversight together into one structured program that could be applied consistently across all critical risk data and reports.

DTA didn't start from scratch. The institution had existing strengths. DTA's role was to connect and mature those capabilities into a coherent, regulation-ready program. One that could scale across critical reports and Critical Data Concepts without fragmenting into siloed workstreams.

How we solved it

Build a central governance foundation for critical metadata

DTA supported the institution in implementing a central Data Catalog as the common governance layer. The underlying metamodel was aligned with ECB requirements and designed to describe both business and technical lineage. Critical reports and Critical Data Concepts are now documented, owned, and governed in one controlled environment with consistent definitions, roles, responsibilities, and classifications across business, technology, and governance teams.

Connect business and technical lineage

BCBS 239 requires banks to demonstrate where risk data comes from and how it is transformed. DTA mapped business lineage and technical lineage, then connected both. Critical Data Concepts and reports are linked to the technical assets that produce them, creating end-to-end traceability. Business and technology teams now work from the same view of critical data, which strengthens transparency and makes impact analysis actionable.

Make data quality maturity measurable

DTA governed data quality controls, both business and technical, and linked them to the relevant Critical Data Concepts. A dedicated scoring model assesses governance and data quality maturity across the program scope. That makes progress visible, supports prioritisation, and gives the institution a structured way to manage a broad BCBS 239/RDARR perimeter without losing focus.

Set up integrated governance and quality reporting

DTA built reporting that brings together maturity scores, lineage status, control results, and delivery progress into a single view for governance and management teams. Open actions, control performance, and key attention points are tracked consistently — giving the institution the oversight it needs to manage the program over time.

The results

Maturing an existing governance foundation into a full BCBS 239/RDARR program takes discipline and a clear structure. This is what the institution gained from getting it right.

An integrated BCBS 239/RDARR program built on a reusable foundation

Critical risk data is governed through a central model. Business and technical lineage are connected. Maturity is measured consistently. The institution has moved from established-but-fragmented practices to a structured program that can scale.

End-to-end traceability across critical risk data

Critical Data Concepts can be traced from business definition to the technical assets and transformations that produce them. This gives both business and technology teams a shared, reliable view, and gives regulators the transparency BCBS 239 requires.

Maturity that can be measured, tracked, and reported

The scoring model and governance reporting make progress visible to management. Planned objectives, completed activities, open actions, and control performance are all tracked in one place, removing ambiguity about where the program stands and what needs attention.

Key Learnings

BCBS 239/RDARR is a long game. These are the principles that made the difference on this engagement.

Foundation

A shared foundation scales. When governance, lineage, and data quality are managed as connected capabilities from the start, not bolted together later, the program becomes easier to extend and harder to break.

Connected

Connected lineage only works when business and technology teams own it together. Technical traceability without business context answers the wrong questions. Building both views simultaneously, and linking them, is what makes the lineage meaningful for BCBS 239.

Measurable maturity

Making maturity measurable changes the conversation. A scoring model shifts program governance from subjective progress updates to evidence-based prioritisation, which matters when the scope spans multiple critical reports and data concepts.

Degroof Petercam

From fragmented controls to scalable regulatory data quality

Degroof Petercam is a Belgian investment house and private bank with deep roots in wealth management. Since 2024, it operates as part of Indosuez Wealth Management, the global wealth arm of Crédit Agricole Group. That integration created an immediate compliance pressure: the group needed a unified, scalable data quality framework across multiple entities... and fast.

Mega

Managing GDPR compliance across a complex stakeholder landscape

Mega is an internationally active energy-sector company with a complex supplier network spanning both the EU and non-EEA countries. Alongside external vendors, Mega relies on intra-group relationships with holding and sister organisations, each carrying its own data transfer risk profile.

LM Oost-Vlaanderen

From regulatory scrutiny to demonstrated compliance

LM Oost-Vlaanderen is a Belgian social security mutuality serving members across the province of East Flanders. As a social security organisation, it operates under strict sector-specific regulations and handles some of the most sensitive personal data categories that exist: health records, financial entitlements, and member identity.