Skip to content
RiskTemplates · The Daily Brief Sunday, October 4, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Template Guide Operational Risk Template Guide

RCSA Template Guide

A practical guide to building an RCSA template: risk statements, controls, testing evidence, ratings, owners, issues, and reporting outputs.

◆ Built for financial services risk teams ◆ Practitioner methodology ◆ Updated September 2026

◆ Quick answer

An RCSA template should include a risk ID and risk statement, risk category, a control ID linked to that risk, the control description, type, owner and frequency, inherent risk on a defined scale, design and operating effectiveness, the last test date and result, residual risk with a written rationale, second-line challenge, linked key risk indicators (KRIs), remediation or issue links, and sign-off by both lines.

Guide vs. template

This guide explains what belongs in the template. The paid template gives you the editable working files so you're not rebuilding from a blank page.

Paid template includes

  • ◆ 141 fintech risks with mapped controls across 21 categories
  • ◆ Inherent and residual ratings on one 4×4 scale, with automatic rating checks
  • ◆ 97-question self-assessment with “what good looks like” and evidence to request
  • ◆ Control testing plan: interval by residual rating, sample size by frequency

What is this template for?

An RCSA template is the spreadsheet or workflow risk teams use to identify business-process risks, map controls to those risks, assess control design and operating effectiveness, and document residual risk. The point is not to create a pretty risk inventory. The point is to prove which controls are working, which risks remain too high, and which issues need remediation.

◆ Audience

Who needs this.

  • ◆ Your organization has risks and controls listed in different places and no clean owner-by-owner view.
  • ◆ A bank partner, internal audit or an examiner asked how business units self-assess controls and how second line challenges them.
  • ◆ You need a repeatable way to compare inherent risk, control effectiveness, and residual risk across teams.
  • ◆ You are building an operational risk program without a full GRC platform.

◆ Required fields

What every row needs.

The fields that make this template defensible to an auditor, bank partner, or examiner — and what goes in each.

Field Why it matters Example
Risk ID and risk statement Ties the RCSA to your risk register and keeps each risk distinct from its neighbors. FR-003: customers tricked into authorizing payments to fraudsters
Risk category Supports aggregation, sign-off by category and board reporting. Fraud, compliance, technology, third-party, model, people
Control ID, description and type A control-level ID lets one risk carry several controls, each tested on its own. CTRL-FR-003: scam warnings, first-payment friction, mule detection; Preventive
Control owner and frequency Prevents accountability gaps and sets the test sample. Head of Fraud; continuous (25 items per test)
Inherent risk rating Shows exposure before controls, on the same scale as residual. Likelihood 4 × impact 4 = 16, Critical
Design and operating effectiveness Separates a good-looking control from a working one. Each rated Effective, Needs Improvement or Ineffective; combined into Effective, Adequate or Weak
Last test date and result Evidence that the control actually ran; the operating rating should match it. July 12, 2026; 1 exception in 25; Partial Pass
Residual risk and rating rationale Records why the controls reduce the risk by as much as you say. High (3 × 3 = 9): warnings exist but most customers override them
Second-line challenge Shows the ratings were questioned, not just collected. First line proposed Effective; second line changed operating to Needs Improvement
Linked KRIs Tells you between cycles whether the risk is moving. Scam intervention success rate; APP fraud loss rate
Remediation / issue link Turns the RCSA into action with an owner and a date. An issue ID in your tracker (e.g., ISS-2026-014), due December 15, 2026
Sign-off Records that the business owns the result and second line reviewed it. Head of Fraud signed September 15, 2026; second-line sign-off (Head of Operational Risk) still pending in the sample

◆ Worked example

Example RCSA row (from the sample cycle)

Risk ID / control ID FR-003 / CTRL-FR-003 — the control ID carries the risk ID, and a risk can have more than one control.
Risk statement Customers are tricked into authorizing payments to fraudsters through romance, investment or impersonation scams (authorized push payment, or APP, fraud).
Control activity Preventive, continuous: scam warnings at payment initiation for high-risk recipients, extra friction on first payments to new payees, and mule-account detection. Owner: Head of Fraud.
Inherent risk Critical — likelihood 4 × impact 4 = 16 on a 4×4 scale (Critical 12–16, High 8–9, Medium 3–6, Low 1–2).
Design / operating Needs Improvement / Needs Improvement, so overall Weak: the warnings are live, but 75% of customers override them.
Latest test July 12, 2026: 25 payments sampled, 1 exception, Partial Pass. Next test due January 12, 2027.
Residual risk High — 3 × 3 = 9. One band below inherent, the most a Weak control should reduce it.
Challenge and issue First line proposed operating Effective; second line changed it to Needs Improvement. Remediation (redesign warnings, add a first-time payee delay, launch mule detection) due December 15, 2026, tracked in your issues log (illustrative ID: ISS-2026-014).

◆ Implementation roadmap

How to roll this out.

01

Pick 5–10 critical processes first

Owner · Operational risk lead

Output · Initial RCSA scope and business owner list

02

Write risk statements and map controls with IDs

Owner · Risk lead + process owner

Output · Risk and control inventory with owners, types and frequencies

03

Rate inherent risk, controls and residual risk

Owner · Business owner

Output · Ratings on one 4×4 scale with a written rationale

04

Challenge the ratings and test the highest-risk controls

Owner · Second line (risk and compliance)

Output · Challenge log and first test results

05

Open issues for Weak controls and sign off by category

Owner · Issue owner + both lines

Output · Tracked issues (e.g., ISS-2026-###) and dated sign-offs

◆ Ready to use it?

Download the RCSA (Risk & Control Self-Assessment).

Use the guide to understand the structure, or buy the editable template to move faster.

◆ FAQ

Frequently asked questions.

What is the difference between an RCSA and a risk register? ⌄

A risk register inventories and scores risks. An RCSA goes one layer deeper by mapping controls to those risks and assessing whether the controls are designed well and operating effectively.

How often should an RCSA be updated? ⌄

Most teams refresh high-risk processes at least annually, with interim updates when a process, product, vendor, system, regulation, or control changes materially.

Who owns RCSA completion? ⌄

The business or process owner should own the content. Risk or compliance should provide the methodology, challenge ratings, and ensure weak controls become tracked issues.

What rating scale should an RCSA use? ⌄

One scale for inherent and residual risk. A 4×4 likelihood-by-impact scale is enough for most fintechs: Critical 12–16, High 8–9, Medium 3–6, Low 1–2. Rate control design and operating effectiveness separately, then combine them into Effective, Adequate or Weak.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.