Joint Resolution No. 18: What Changes in the Quality of Information Reported to the Central Bank

Joint Resolution No. 18, issued by the Central Bank of Brazil (BCB) and the National Monetary Council (CMN) on November 28, 2025, establishes the mandatory adoption of an information quality policy governing the information submitted to the regulator. The regulation entered into force on January 1, 2026, and requires institutions to achieve full compliance by December 31, 2026. As of January 1, 2027, responsibility for the quality of such information will formally rest with a designated officer accountable to the BCB.
The regulation applies to all financial institutions and other entities authorized to operate by the Central Bank of Brazil. As a joint resolution issued by both the BCB and the CMN, its scope includes banks, credit unions, finance companies, payment institutions, consortium administrators and, subject to a specific compliance timeline, virtual asset service providers.
What the Regulation Requires
Joint Resolution No. 18 requires each institution to implement and maintain an information quality policy that is appropriate to its nature, size, complexity, risk profile, and business model. The information covered includes quantitative and qualitative data, documents, and reports, whether submitted to or otherwise made available within the scope of the Central Bank’s supervisory activities.
One significant aspect of the regulation is the change in the status of information quality. Previously addressed as part of internal control policies, information quality must now be governed by a dedicated policy, maintained as a single document and segregated from other institutional policies. The resolution also establishes that the responsibilities of the Board of Directors and executive management may not be delegated, and that the institution must formally designate an officer responsible for compliance with the regulation.
The Twelve Dimensions of Information Quality
The regulation defines information quality as the extent to which data complies with the requirements established by applicable laws, regulations, and demands from the Central Bank, and organizes this concept into twelve dimensions: accessibility, accuracy, adaptability, clarity, comparability, completeness, reliability, consistency, integrity, traceability, relevance, and timeliness.
These dimensions are aligned with international data quality standards. In practice, however, they are not addressed in the same manner. Dimensions such as accuracy, completeness, and consistency depend on testing and reconciliation against source systems. Traceability and clarity rely on artifacts such as data dictionaries and audit trails. Others, such as accessibility, concern the end user’s ability to access information, including accessibility for persons with disabilities, and therefore apply primarily to information made available to the public.
The regulation does not require institutions to assign a score to each dimension. Instead, institutions must describe the measures adopted to ensure that each dimension is appropriately addressed. This allows the twelve dimensions to be treated proportionately according to the nature and characteristics of the information concerned.
Reliability and the Impact of Restatements
Among the twelve dimensions, reliability deserves particular attention because the regulation provides it with a specific definition. Reliability is described as the absence of material deviations between revised data and the values initially reported. In practical terms, this means that the frequency and materiality of corrections or restatements become indicators of information quality, even when the final reported figure is ultimately correct.
The impact is tangible. An institution that frequently corrects previously submitted information may reduce the regulator’s confidence in its reporting processes, potentially resulting in increased requirements related to guarantees and retention. Reducing the need for restatements therefore ceases to be merely an operational concern and begins to directly affect the institution’s relationship with the Central Bank.
Governance, Testing, and Evidence
Article 3 of the resolution sets out the essential characteristics of the information quality policy. These include the establishment of a governance framework with clearly defined responsibilities; a data and technology architecture supported by prior validation mechanisms; documentation of the relevant processes through data dictionaries and auditable trails; and mechanisms for continuous monitoring.
Monitoring includes specific information quality tests performed before information is submitted, together with reviews and reconciliations between reported data and internal systems. It also includes the preparation of a semiannual report consolidating information quality processes, detailing identified irregularities, and describing both completed and ongoing remediation measures.
This report must be submitted to the Board of Directors, the Audit Committee where applicable, and internal, independent, and cooperative auditors, as applicable. It must also be provided to the Central Bank upon request.
The regulation further requires the documentation supporting the policy and the information quality report to be retained and made available to the Central Bank for a minimum period of five years. Without a structured approach to producing and retaining such evidence, sustaining ongoing compliance with the regulation becomes significantly more challenging.
From Policy to a Demonstrable Process
One aspect of Joint Resolution No. 18 that is often underestimated is that it does not merely require a formal policy document. It requires institutions to demonstrate an effective capability. An institution may have a well-drafted policy and still be non-compliant if it cannot provide evidence that the required tests were performed, that its data dictionary is up to date, and that an audit trail exists linking the information submitted to the system from which it originated.
This challenge is particularly common in operations where information from multiple sources must be consolidated before submission. When data originates from different systems, passes through external partners, and must ultimately be aggregated at the customer level, the consolidation stage often becomes a significant source of errors. Data may be omitted, overwritten, or aggregated incorrectly.
Automated validation, supported by reconciliation against source systems, enables institutions to identify such discrepancies before submission and significantly reduce the time spent on manual verification activities.
How to Structure the Compliance Process
Given the applicable deadline, the sequence in which actions are undertaken is important. A consistent approach begins with an assessment of the institution’s current level of maturity and the creation of a regulatory inventory identifying which information is subject to mandatory reporting and the systems through which it flows before submission. This assessment frequently reveals weaknesses that were not previously apparent.
Based on this assessment, the institution can select a report of greater materiality and address it end to end, incorporating validation and reconciliation controls before expanding the approach to other reports and regulatory submissions. This pilot initiative helps determine the actual level of effort required for each workstream and establishes standards that can accelerate subsequent implementations.
The final stage consolidates the information quality policy, the controls applicable to each dimension, and the semiannual report, establishing the foundation that the institution will need to maintain from 2027 onward.
Joint Resolution No. 18 formalizes a requirement that was already recognized as good practice within the financial services industry. What changes is that the quality of information submitted to the Central Bank is now subject to a defined compliance timeline, formal accountability by a designated officer, and an obligation to provide supporting evidence.
For institutions, the challenge therefore extends beyond producing accurate data. They must also be able to demonstrate, through an auditable process, that the information they provide is reliable.
Talk to our experts about compliance with Joint Resolution No. 18
*Your data is handled safely and in compliance with the LGPD.
For more information, see our Privacy Policy.
Contact Us
Doubts? Talk to us using the form below