Topic Operational Risk
The operational risk program, built one template at a time.
ERMF, RCSA, KRIs, issues management, loss tracking, third-party risk — the operational risk stack practitioners actually use. Aligned with COSO ERM, ISO 31000, FFIEC IT, and FRB SR 21-3.
◆ COSO ERM · ISO 31000 · FFIEC IT · FRB SR 21-3 · Basel
◆ What you'll find here
The core risk program — without the consulting markup.
◆ 01
ERMF, RCSA, KRIs
The three core building blocks of every operational risk program. Inventory the risks, self-assess the controls, monitor the indicators. Mapped to COSO ERM and FRB SR 21-3.
◆ 02
Issues & loss tracking
Track MRAs, audit findings, and operational losses with severity scoring, owners, and remediation timelines. Built for teams that need to show progress to regulators and bank partners.
◆ 03
Third-party & vendor risk
TPRM intake, due diligence, ongoing monitoring, and the evidence regulators expect when a critical vendor goes down. Aligned with FFIEC and OCC third-party guidance.
◆ Operational risk templates
Tools for the operational risk team.
Excel-native templates with editable workbooks and PDF guides. Buy once, tailor to your program, deploy in days.
Enterprise Risk Management Framework (ERMF)
Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.
RCSA (Risk & Control Self-Assessment)
141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
Loss Monitoring & Event Tracking Kit
Basel-aligned operational loss event tracking and root cause analysis for financial services.
Financial Risk Management Kit
Credit risk, liquidity, concentration, and capital adequacy templates built for fintechs.
Contingency Funding Plan — Banks
Examiner-ready contingency funding plan for chartered banks built to the 2023 Interagency Addendum.
Contingency Funding Plan — Fintechs
Contingency funding plan for sponsor-bank fintechs — FBO reconciliation, runway-based triggers, post-Synapse stress scenarios.
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
Fintech Customer AUP Kit
Acceptable Use Policy framework for fintech compliance teams evaluating high-risk customers and merchants.
216+
Operational risk articles
10
Templates · Excel + PDF
US
COSO · ISO 31000 · FFIEC · Basel
◆ Latest analysis
From the journal.
Operational Risk
$3 Billion in BEC Losses. 58% Recovery Rate. A Pending Federal Appeal That Could Change What Banks Pay Back.
The FBI IC3 2025 report shows $3.04 billion in business email compromise losses, with 86% moving by wire or ACH. A 2025 Fourth Circuit ruling narrowed bank liability under UCC Article 4A. The Second Circuit is now poised to decide whether the Electronic Fund Transfer Act gives consumers stronger recourse — a ruling that will reshape who absorbs the loss when a fraudulent wire clears.
Compliance Strategy
Five Statutes Generated 75% of All FDIC Compliance Violations in 2025. Here's What They Are.
The FDIC's 2026 Consumer Compliance Supervisory Highlights identified 1,155 violations in 2025 exams. Five statutes — TILA, EFTA, the Flood Act, TISA, and HMDA — drove three-quarters of them. Here is what examiners actually cited and what your compliance program needs to test.
Compliance Strategy
CFPB and CFTC Self-Reporting Policies: A 2026 Decision Guide
Compare the CFPB and CFTC self-reporting policies, penalty-credit rules, and evidence needed for a defensible disclosure decision.
Third-Party Risk
DORA Register of Information: Turn the 2024 Dry-Run Results Into a Data-Quality Control
Only 6.5% of 947 integrated DORA dry-run registers passed all 116 checks. Here is a repeatable remediation and evidence process.
Compliance Strategy
FTC Debanking Warning Letters: What PayPal and Stripe Were—and Were Not—Told
The FTC Chair sent warning letters to PayPal, Stripe, Visa, and Mastercard. They flag potential Section 5 risk but do not adjudicate a violation.
Third-Party Risk
UK Critical Third Parties: What the 2026 Cloud Designations Mean for TPRM
Four UK critical-third-party designations took effect July 13, 2026. Separate provider duties, firm duties, PS26/2, and existing U.S. authority.