Skip to content
RiskTemplates · The Daily Brief Sunday, October 4, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30
Template Updated September 2026

RCSA Template for Fintech Risk & Control Assessments

141 fintech risks with mapped controls, a 97-question self-assessment, control testing plan, challenge log and a one-page Board Summary.

Price

$69

One-time. No subscription. Use forever.

Buy & download — $69 →
◆ Secure checkout ◆ Emailed access ◆ Fully editable ◆ 30-day money-back

Delivered immediately after checkout — your template and guide links are emailed to you with your receipt.

Built for risk and compliance teams at financial-services organizations

◆ Quick buying summary

What you get and when you can use it

Good fit if
A bank partner or examiner asked for your RCSA and you do not have one
Format
Editable Excel workbook (9 tabs) plus a 25-page PDF implementation guide. Instant download after checkout.
Need the methodology first?
Read the RCSA Template Guide.
Time to value
Start reviewing, editing, and assigning owners the same day; customize to your organization before sharing outputs externally.
After purchase
After payment, download every file immediately from the confirmation page. RiskTemplates also emails a secure access link, and Stripe sends the payment receipt separately. No account required.

◆ What's included

  • ◆ 141 fintech risks with mapped controls across 21 categories
  • ◆ Inherent and residual ratings on one 4×4 scale, with automatic rating checks
  • ◆ 97-question self-assessment with “what good looks like” and evidence to request
  • ◆ Control testing plan: interval by residual rating, sample size by frequency
  • ◆ Second-line challenge log and sign-off by category
  • ◆ Dashboard with heat maps and a one-page Board Summary
  • ◆ All 152 KRIs from the KRI Library linked; risk IDs match the Risk Register
  • ◆ 25-page guide with workshop agenda, owner email and Board brief templates

Use rights: customize for internal business use and use outputs with your auditors, customers, bank partners, and regulators. Do not resell or redistribute the template files.

◆ Preview

See what the template covers.

RCSA Board Summary — headline numbers, top 5 residual risks, residual heat map, commentary and decisions for the Board

RCSA Board Summary — headline numbers, top 5 residual risks, residual heat map, commentary and decisions for the Board

RCSA Dashboard — headline metrics and results by risk category, with sign-off status

RCSA Dashboard — headline metrics and results by risk category, with sign-off status

Inherent and residual heat maps, control effectiveness mix and inherent-to-residual change

Inherent and residual heat maps, control effectiveness mix and inherent-to-residual change

● Case file

When control failures make the news

These public cases show why control design, evidence, testing and challenge matter. They are useful discussion scenarios for an RCSA, not proof that a template would have caught a particular failure.

October 2024

TD Bank — about $3.09 billion in total

DOJ called TD Bank the largest bank in US history to plead guilty to Bank Secrecy Act program failures, and the first US bank to plead guilty to conspiracy to commit money laundering. From January 2014 to October 2023 the bank's transaction monitoring left out all domestic ACH and most check activity.

Why it mattersA documented control is not an effective one. Monitoring existed, but its design excluded most of the volume. Rating design and operating effectiveness separately, and testing what the control actually covers, is how an RCSA surfaces gaps like this.

August 2020

Capital One — $80 million OCC penalty

The OCC cited “the bank's failure to establish effective risk assessment processes prior to migrating significant information technology operations to the public cloud environment and the bank's failure to correct the deficiencies in a timely manner.” The consent order pointed to network security controls, data loss prevention and the handling of alerts.

Why it mattersA new operating environment resets the control environment. The OCC found the bank had not established effective risk assessment processes before the migration; the guide's refresh triggers call for reassessing the affected risks and controls before a change like that goes live.

October 2020

Citibank — $400 million OCC penalty, then $135.6 million more

The OCC cited “deficiencies in enterprise-wide risk management, compliance risk management, data governance, and internal controls” and a “long-standing failure” to fix them. The consent order required OCC non-objection before significant new acquisitions.

Why it mattersRegulators judge whether remediation actually happens. An RCSA that tracks remediation owners and dates, and reports overdue actions to the Board, keeps a known weakness from becoming a repeat finding.

If you are trying to make sure your control environment does not become someone else's case study, this is what the kit helps you do:

◆ Good fit if any of these sound familiar

When teams reach for this template.

Your bank partner asked for your RCSA, and all you have is a Risk Register.

A Risk Register lists risks; an RCSA shows whether the controls work. The inventory uses the same 141 risk IDs as our Risk Register and adds the control, its ratings, test results and remediation.

An exam or partner review said your risk assessment process is not effective.

Reviewers want evidence that you assessed controls, challenged the ratings and fixed what was weak. The challenge log, testing plan and remediation columns produce that record, and the guide shows how to start when documentation is thin.

Business owners are supposed to self-assess, but the forms come back blank or all “Effective.”

The questionnaire tells them what good looks like and what evidence to attach, and the Rating Check column flags ratings that do not add up before second line sees them.

◆ Why now

Reviewers are testing whether controls work, not whether they exist

Recent enforcement actions turn on the gap between a documented control and one that operates — and on whether known weaknesses were actually fixed. This kit supports evidence-based ratings, second-line challenge, risk-based testing and tracked remediation. It does not guarantee examiner or bank-partner acceptance; tailor it to your organization and the request.

◆ Where this fits

Where this fits in your risk program

  • ◆ If you have a Risk Register but cannot answer “are your controls effective?” — the inventory uses the same risk IDs, so the RCSA picks up where the register stops.
  • ◆ If you are starting from scratch — delete the risks that do not apply, replace the controls with what you actually do, and use the 30-day plan.
  • ◆ If you are preparing for an exam or partner review — the challenge log, test results and Board Summary are the evidence reviewers ask for.
  • ◆ If your current process is a form nobody fills in — replace it with the questionnaire and the Joint workshop approach for complex areas.

◆ What this isn't

Setting expectations.

  • × Not a replacement for a risk function — it is the toolkit your risk team uses, not a substitute for its judgment.
  • × Not software — an Excel workbook and a PDF guide, not a GRC platform.
  • × Not a Risk Register — the register lists risks; the RCSA evaluates whether controls work against them. The Risk Register is a free download.
  • × Not theoretical — every tab is filled in with a worked sample cycle you can follow and then replace.

◆ 30-day rollout plan

A sample 30-day rollout

Use this four-week sequence as a starting point and adjust it for scope, owner availability, evidence and governance review.

  1. Week 1

    Scope and set up

    Set the as-of date and lists, delete risks that do not apply, name first-line owners and second-line reviewers, and choose who leads each area: the first line of defense (1LOD), the second line (2LOD) or both jointly. Output: a scoped inventory with owners.

  2. Week 2

    Self-assessment

    Business owners answer the questionnaire with evidence and rate design and operating effectiveness on the inventory. Run workshops for the areas with the most Critical inherent risks. Output: first-line ratings and evidence.

  3. Week 3

    Challenge and test

    Second line reviews every rating, logs challenges and tests controls on High and Critical residual risks first. Output: challenge log and first test results.

  4. Week 4

    Finalize and report

    Clear Rating Check flags, agree remediation owners and dates, record sign-offs and take the Board Summary to the risk committee or Board. Output: a signed-off baseline and Board report.

◆ Full playbook in the PDF guide

The 25-page guide includes a 90-minute workshop agenda, an email to business owners and a Board brief outline you can copy.

◆ Regulatory alignment

Grounded in the expectations reviewers apply

The guide cites these sources where they apply, checked against the primary text in September 2026:

  • ◆ OCC Heightened Standards (12 CFR Part 30, Appendix D) — front line units assess their material risks on an ongoing basis
  • ◆ Interagency Guidance on Third-Party Relationships: Risk Management (June 2023; OCC Bulletin 2023-17) — how bank partners oversee fintech programs
  • ◆ OCC news release 2025-21 (March 20, 2025) — reputation risk removed from OCC examinations
  • ◆ Federal Reserve SR 13-13 and the FDIC Risk Management Manual — how examination findings (MRAs, MRIAs, Matters Requiring Board Attention) reach the Board

Built for risk, compliance and operations leads at fintechs and small banks, and the business owners who assess their own risks. Acceptance depends on your own evidence, review and applicable requirements.

Last updated: September 30, 2026

◆ Template guide

RCSA Template Guide

A practical guide to building an RCSA template: risk statements, controls, testing evidence, ratings, owners, issues, and reporting outputs.

Read guide →

◆ FAQ

Frequently asked questions.

How are the 141 risks organized?

By the same 21 categories and risk IDs as our free Risk Register (PR-001, FR-003 and so on), so the two line up row for row. Each risk has a mapped control, linked KRIs where the KRI Library has them (all 152 KRIs, across 100 risks), inherent and residual scores, design and operating ratings, and a written rationale.

What scale does it use?

One 4×4 scale everywhere: likelihood 1–4 times impact 1–4. Critical is 12–16, High 8–9, Medium 3–6, Low 1–2. Design and operating effectiveness are rated separately and combined into Effective, Adequate or Weak. The Risk Rating Methodology tab has the definitions and five guardrails that the Rating Check column applies automatically.

Can business owners without a risk background fill it in?

That is what the questionnaire is for. Each of the 97 questions says what good looks like and which evidence to ask for, and the answer scale is plain: Yes, Partial, No or N/A. Every Partial or No needs a risk level, action, owner and date, and the sheet flags any that are missing.

Do I need existing controls documentation?

No. The guide has a chapter on starting from nothing: using the RCSA interviews to document controls as you find them, using KRIs, incidents and audit findings as indirect evidence, and a two- to three-day documentation sprint.

What does the Board see?

The Board Summary tab: risks assessed, Critical and High residual risks, Weak controls, percent tested, overdue actions, the top 5 residual risks with owners and dates, a residual heat map, your commentary and the decisions you need. Every number is a formula; it prints on one landscape page.

How long does the first cycle take?

The guide lays out a 30-day plan: set-up and scoping, business-owner self-assessment, second-line challenge and testing, then finalizing and reporting. Actual timing depends on your scope, owner availability and how much evidence already exists.

Can I share completed outputs externally?

Yes. You can use completed outputs with auditors, customers, bank partners, regulators, and internal stakeholders. Customize the template for internal business use — just don't resell or redistribute the source template files.

How do I receive the files?

Checkout is handled through Stripe. After payment, download every file immediately from the confirmation page. RiskTemplates also emails a secure access link, and Stripe sends the payment receipt separately. No account is required.

What if it's not a fit?

Email within 30 days for a full refund, no questions asked. The guarantee is meant to remove purchase risk while you evaluate whether the template fits your use case.

● First-time buyer offer

Get 20% off your first template.

Drop your email and we'll send the code.

◆ Not ready to buy?

Start with the free Risk Register.

141 pre-populated fintech risks across 21 categories. ISO 31000 structure.

Download free Risk Register →

◆ Related templates

Pairs well with.

Template
$79

Enterprise Risk Management Framework (ERMF)

Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.

Template
$49

KRI Library (152 Key Risk Indicators)

152 KRIs — including 20 emerging-risk KRIs for AI-enabled fraud, scams and AI governance — with thresholds, owners and a calculating dashboard.

★ Free
Free

Risk Register — Fintech Edition (Free)

141 pre-populated fintech risks across 21 categories. ISO 31000 structure. Ready to use in a week.

◆ Ready when you are

Get the RCSA (Risk & Control Self-Assessment).

Start building a defensible risk program today.

Buy & download — $69 →
◆ Secure checkout ◆ Emailed access ◆ Fully editable ◆ 30-day money-back

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.