Every reconciliation of a regulatory return produces a percentage, and every percentage is computed over whatever happened to flow through the systems during the window it was measured. Two banks can both report “99% reconciled” and be in completely different places — because the number is silent on what it was computed over.

Supervisors on three continents expect the reconciliation. None of them, so far, expects the denominator. That gap is where regulatory reporting systems actually fail, and it is worth writing down before it is written down for us.

The expectation, in each supervisor’s own words

AuthorityInstrumentThe expectation
🇬🇧 PRA“Thematic findings on the reliability of regulatory reporting”, Dear CEO letter, 10 Sep 2021“Reconciliations are an essential element of generating reliable regulatory returns” — and the PRA observed “unsatisfactory reconciliation disciplines across a number of firms.”
🌐 Basel CommitteeBCBS 239, Principles 3 and 7 (2013)Risk data should be “reconciled with bank’s sources, including accounting data where appropriate” (P3); reports should be “reconciled and validated” (P7).
🇨🇦 OSFINCCF Reporting Manual (in force)“Discrepancies with the balance sheet balances should be within reason and explainable.”
🇨🇦 OSFIDraft ILAAP guideline, ¶29 — draft, consultation closes 19 Aug 2026“Institutions should be able to demonstrate reconciliation to regulatory returns, such as the LAR.”

Different instruments with different weights: the Dear CEO letter is UK supervisory expectation backed by the statutory s166 skilled-person power; BCBS 239 is a Basel standard implemented nationally — which is how the duty reaches institutions supervised by OSFI, the Fed and FINMA; the NCCF manual is in force in Canada today; the ILAAP text is a draft and labelled as one. But the direction is unanimous: reconcile the return, validate the report.

And the cost of failing is not hypothetical. In December 2021 the PRA fined Metro Bank £5,376,000 for failings in its regulatory reporting governance and controls — a fine for the reporting apparatus itself, not for the underlying risk.

The vacuum in the American row

There is a row missing from that table, and its absence is the most instructive fact in this piece.

The Federal Reserve’s FR 2052a — the liquidity return that large US-regulated banks file, daily in some cases — has instructions that are purely a data-element specification. They contain no accuracy, validation, certification or attestation language at all. I verified this the direct way: extracted the full text of the instructions and searched for “certif”, “attest”, “valida”, “quality” and “control”. Zero hits, across the entire document.

That cuts in both directions, and both matter:

  • Nobody can honestly tell you the Fed requires you to validate your 2052a. Anyone claiming it is selling something that is not in the text.
  • The vacuum is real. A US bank’s 2052a validation discipline is entirely self-imposed — which means the self-imposed discipline is the only control there is. When there is no external floor, the internal one is the floor.

The jurisdictions with the loudest reconciliation expectations and the jurisdiction with none arrive at the same practical conclusion from opposite ends: the quality of the reconciliation is the institution’s own responsibility. Which makes it worth asking what the reconciliation actually proves.

Where the number gets made

The reconciliation percentage matters most at exactly the moment it is least trustworthy: when a reporting system is replaced.

The customary evidence for a platform migration is a parallel run — old system and new system side by side for a period, outputs reconciled, a percentage produced, a go-live decision made on it. The percentage is computed on whatever the bank’s business happened to generate during the parallel window.

Now list what a window does not contain. Product types that didn’t trade that month. Currencies that were quiet. Counterparty classes that didn’t move. Intercompany flows that didn’t occur. Contingent outflows that never triggered — because contingencies mostly don’t, until they do. Every one of these is a behaviour the new system has never once processed at the moment it becomes the system of record.

The reconciliation can be excellent and the migration can still be unsound, because the reconciliation and the risk live in different places: the percentage lives in what flowed; the risk lives in what didn’t. This is how migrations pass validation and fail in production — not on the populations that were compared, but on the populations that were never exercised.

The PRA’s 2021 letter contains a warning that is really about this, though it never uses the word migration. It found that firms’ interpretations of reporting rules had been “hard coded into firms’ systems”, and told firms it expects them to “i) identify the key interpretations; ii) validate these; iii) correct them where appropriate.” A hard-coded interpretation is precisely the kind of thing a parallel run misses when the behaviour it governs doesn’t occur in the window — it sits in a branch of the code the comparison never reached.

Completeness is already a requirement — the denominator is how you evidence it

Here is the part I find genuinely odd about the current state of the texts.

BCBS 239 Principle 4 requires banks to “capture and aggregate all material risk data across the banking group”. Completeness is a named principle with the same standing as accuracy. The reconciliation expectations in the table above all sit next to it.

And yet the reconciliation, as universally practised and universally expected, reports a percentage with no statement of the population it covers. The one number that would connect the reconciliation (Principle 3, Principle 7) to completeness (Principle 4) — reconciled over which behaviours, and which behaviours were never exercised — is not asked for by any instrument in the table.

A percentage without a denominator is not a lie. It is just an answer to a smaller question than the one the reader thinks was asked.

What no instrument says — and what I am reading into them

The citations stop here, so let me label the synthesis as mine, the same way the six-regulators piece labels its own inference section.

No supervisory instrument requires population coverage to be reported alongside a reconciliation percentage. Not BCBS 239, not the PRA letter, not OSFI’s NCCF manual, not the draft ILAAP. If someone tells you “the regulator requires coverage reporting,” they are overreaching in exactly the way that loses a compliance reader’s trust in the first meeting.

What I am arguing is narrower: that the expectations which do exist — reconcile the return, validate the report, capture all material risk data, identify and validate hard-coded interpretations — are jointly impossible to evidence without the denominator. You cannot show a reconciliation supports completeness without saying what it covered. You cannot claim a validated migration while behaviours the new system has never processed carry no flag. The requirement for the number exists; the requirement for the number’s meaning does not, yet. That is a gap in the drafting, not in the logic.

It is also, in my reading, a gap that is starting to close. OSFI’s draft ILAAP expects institutions to “demonstrate reconciliation” — demonstrate, not merely perform — and its consultation is open until 19 August 2026. Whether the final text asks for the denominator will say a great deal about whether the gap survives this round of guidance.

The question this leaves open

If your institution replaced a liquidity reporting platform tomorrow, the go-live pack would contain a reconciliation percentage. Sit with the narrower question: would anything in that pack state what the percentage was computed over — and name the behaviours the new system has never processed?

If the answer is no, then the number that authorized the cutover answered a smaller question than the one it was taken to answer. Finding that out at drafting time costs a paragraph. Finding it out in production costs what Metro Bank paid, plus the remediation, plus the conversation with the supervisor.

I work with risk and technology leaders on exactly this question — what a reconciliation actually proved, what it didn’t, and what the evidence should say about both. curiochat.ai/consulting

I put a version of this argument to OSFI directly, in a comment letter on the draft ILAAP guideline: Four Comments on OSFI’s Draft ILAAP Guideline.


Every quotation above was read at the cited location in the primary source on 3 August 2026. The OSFI ILAAP guideline is a draft under consultation and is labelled as such wherever it appears. Nothing here is legal advice; it is an engineer’s reading of published supervisory texts, and your counsel’s reading is the one that counts.