Topic Operational Risk
The operational risk program, built one template at a time.
ERMF, RCSA, KRIs, issues management, loss tracking, third-party risk — the operational risk stack practitioners actually use. Aligned with COSO ERM, ISO 31000, FFIEC IT, and FRB SR 21-3.
◆ COSO ERM · ISO 31000 · FFIEC IT · FRB SR 21-3 · Basel
◆ What you'll find here
The core risk program — without the consulting markup.
◆ 01
ERMF, RCSA, KRIs
The three core building blocks of every operational risk program. Inventory the risks, self-assess the controls, monitor the indicators. Mapped to COSO ERM and FRB SR 21-3.
◆ 02
Issues & loss tracking
Track MRAs, audit findings, and operational losses with severity scoring, owners, and remediation timelines. Built for teams that need to show progress to regulators and bank partners.
◆ 03
Third-party & vendor risk
TPRM intake, due diligence, ongoing monitoring, and the evidence regulators expect when a critical vendor goes down. Aligned with FFIEC and OCC third-party guidance.
◆ Operational risk templates
Tools for the operational risk team.
Excel-native templates with editable workbooks and PDF guides. Buy once, tailor to your program, deploy in days.
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
RCSA (Risk & Control Self-Assessment)
141 fintech risks with mapped controls, a 97-question self-assessment, control testing plan, challenge log and a one-page Board Summary.
KRI Library (152 Key Risk Indicators)
152 KRIs — including 20 emerging-risk KRIs for AI-enabled fraud, scams and AI governance — with thresholds, owners and a calculating dashboard.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
Loss Monitoring & Event Tracking Kit
Operational loss and near-miss tracking for fintechs — with automatic escalation tiers, bank-partner notice flags and a dashboard that calculates itself.
Financial Risk Management Kit
Credit, liquidity, customer funds, payments losses, capital, interest rate and concentration risk for fintechs — with stress scenarios and a board-ready risk appetite statement.
Contingency Funding Plan — Banks
Examiner-ready contingency funding plan for chartered banks built to the 2023 Interagency Addendum.
Contingency Funding Plan — Fintechs
Contingency funding plan for sponsor-bank fintechs — FBO reconciliation, runway-based triggers, post-Synapse stress scenarios.
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
Fintech Customer AUP Kit
Acceptable Use Policy framework for fintech compliance teams evaluating high-risk customers and merchants.
280+
Operational risk articles
10
Templates · Excel + PDF
US
COSO · ISO 31000 · FFIEC · Basel
◆ Latest analysis
From the journal.
Operational Risk
Two Employees Falsified Compliance Records. 160 SARs Went Unfiled. FinCEN's $80 Million Fine Against Canaccord Genuity Shows Exactly How an AML Program Collapses.
On March 6, 2026, FinCEN, the SEC, and FINRA imposed an $80 million penalty on broker-dealer Canaccord Genuity for willful Bank Secrecy Act violations — including surveillance reports that went unreviewed for four years, falsified compliance records, and 160+ unfiled SARs tied to OTC securities fraud. Here's what the consent order reveals about AML program failure.
Third-Party Risk
Federal Regulators Just Listed the Specific Contract Terms in Your Core System Agreement That Will Draw Examiner Scrutiny. Here's What to Check.
On September 11, 2026, the OCC, Federal Reserve, and FDIC issued a joint statement naming four specific contract practices used by core service providers that regulators intend to scrutinize directly. Deconversion fees, back-billing windows, opaque pricing, and integration restrictions are now on the examiner checklist. Here's how to review your core provider agreement before they do.
Compliance Strategy
16 Days, 30 Days, 44 Days: The Q4 2026 Compliance Deadline Stack Every Financial Institution Needs to Clear
October 19, November 2, November 16: three separate compliance deadlines land in the next six weeks. One is a comment period for guidance that will define how examiners evaluate your vendor program. One is the effective date of the new MRA standard. One is the comment period for GENIUS Act implementing rules that will freeze your options if you miss it. Here's what each requires.
Operational Risk
40 States Just Made Credit Acceptance Corporation Pay $700 Million for Loans It Knew Borrowers Couldn't Repay. Here's What Consumer Lenders Need to Lock In Now.
On September 17, 2026, a 40-state coalition secured a $700 million settlement against Credit Acceptance Corporation for predatory subprime auto loans—including $634M in debt relief for 55,000 consumers. The smoking gun was CAC's own internal predictive model showing expected defaults. Here's what every consumer lender needs to do before November.
Compliance Strategy
New York City's Click-to-Cancel Rule Is Now in Effect. What Financial Services Subscription Products Need to Show Before the First Enforcement Wave.
On October 1, 2026, New York City became the first US municipality to require click-to-cancel for subscription products. Civil penalties start at $525 per violation. For financial services companies with premium account tiers, advisory subscriptions, credit monitoring, and cash-advance membership models, this is a three-layer compliance obligation most haven't fully mapped.
Operational Risk
The Fed's 2026 Risk Officer Survey Is Out. No Major Fraud Category Is Getting Better. Here's What Your Controls Are Flagging Late.
The Federal Reserve's 2026 Risk Officer Survey of 400+ financial institutions shows fraud rising or persisting in every payment channel. Debit card fraud is near-universal. Money mule accounts are discovered after funds disappear. Synthetic identities are defeating KYC. Here's the diagnostic checklist your program needs.