RCSAs: Industry study reveals a move towards drastic reduction in the number of entries
Fig 1, Best Practice Operational Risk Forum, September 2024

RCSAs: Industry study reveals a move towards drastic reduction in the number of entries

Best Practice Operational Risk Forum conducted a deep dive into the topic of Risk and Control Self-Assessments (RCSAs).

Despite being the core forward-looking tool of the Operational risk framework, RCSAs typically generate a mixed response, with multiple industry studies reflecting the view that they are time consuming, not delivering enough value, perceived as a tick-box exercise.

One of the key challenges has always been the level of granularity at which risks and controls are described. If the approach is too granular, RCSAs may end up with thousands of entries – emphasizing quantity over quality and quickly leading to organizational fatigue. After all, no firm will be actively managing 500+ risks.

The poll conducted by Best Practice Forum members reflected the latest trend towards significant reduction in the number of entries. All participants - from smaller institutions comprised of less than 1,000 staff to sizable firms with over 200K employees - noted the total number of risks not exceeding 500 (see Fig 1). Many practitioners described how they embarked on a recent program with business units to revisit lengthy RCSAs and achieve drastic decrease in the number of risks, bringing the number down from thousands to less than 500 records.


Fig 2, Best Practice Operational Risk Forum, September 2024

As a result of the programs, 50% of respondents were satisfied that they have reached the right level of granularity, eliminating the disproportionate effort of continuously maintaining and updating an overly detailed risk register (see Fig 2). Not all risks require to be recorded; the focus must be on material items, enabling to actively manage, mitigate or accept the risks to answer the crucial ‘so what?’ question. This is even more important in the current testing environment, when demands are continuing to increase while budgets and resources (at best) remain at the same level. There is less room for risk administration and more impetus for value-added risk management.

Despite the overall improvement, 41% of respondents saw further optimization opportunities.


Fig 3, Best Practice Operational Risk Forum, September 2024

Have we mastered RCSAs or are we still on a journey? Majority of Best Practice Forum members were looking for further improvements (see Fig 3). Apart from granularity, the right methodology, correct risk and control formulation to achieve meaningful results, better use of (better) technology, links to risk appetite and capital assessment were all on the list of enhancements.

Re-injecting the energy with expert facilitation, re-engaging the stakeholders into meaningful discussions, and deriving value by making the results actionable will keep the momentum going.

Alex Irvin

Experienced Financial Services Operational and Conduct Risk Leader

5 个月

Great to see and I’ve been pushing this for a number of years in a few roles. RCSA is a great tool for managing key risks, and reporting risk profiles and control effectiveness to senior management and board. However it’s only worthwhile if led by risk SMEs who really understand how to maximise its impact and value to support strategic decision making.

Dr Jimi M.V. Hinchliffe

Former UK banking regulator, Risk and Compliance professional. Operational Risk, Operational Resilience, TPRM and Regulatory Affairs Consultant and Trainer. Former Chairman IOR England & Wales

6 个月

Do you think this trend is driven by efforts to improve the quality and value of RCSA as a tool (focusing on key risks) or due to limited resources in 1st and 2nd lines, so something forced rather than chosen as a way to improve ORM?

要查看或添加评论,请登录

Elena Pykhova的更多文章

  • GenAI in Operational Risk Management: Use Cases

    GenAI in Operational Risk Management: Use Cases

    The Best Practice Operational Risk Forum members had a round table discussion to review the progress in adoption of…

    5 条评论
  • No more D in 3LOD

    No more D in 3LOD

    The three lines of defense (3LOD) model, which has its origins in military planning and sports management, is now…

    36 条评论
  • Top Operational Risk Priorities 2024

    Top Operational Risk Priorities 2024

    What is on your agenda this year? Best Practice Operational risk Forum members discussed and ranked top Operational…

    10 条评论
  • Top Operational Risks 2024

    Top Operational Risks 2024

    This year’s view of the risk landscape from Best Practice Operational Risk Forum; members ranked top Operational risks…

    12 条评论
  • 2023 Operational Risk Priorities

    2023 Operational Risk Priorities

    What’s on your agenda for 2023? Best Practice Operational Risk forum comprised of risk executives from 50 international…

    6 条评论
  • Top Operational Risks 2023

    Top Operational Risks 2023

    As always, new year brings a set of challenges, some new and others very familiar. This year’s view of the risk…

    30 条评论
  • 1st Line Risk Champions: Is there a magic number?

    1st Line Risk Champions: Is there a magic number?

    It is a common practice within the financial services firms to appoint 1st Line Operational Risk coordinators, or risk…

    9 条评论
  • Operational Risk Priorities 2022

    Operational Risk Priorities 2022

    What’s on your agenda for 2022? Best practice Operational Risk forum comprised of practitioners from over 50…

    5 条评论
  • Operational risk management: Importance of Celebrating Success

    Operational risk management: Importance of Celebrating Success

    Consciously pausing to acknowledge achievements and celebrate success of Operational risk management is the practice…

    2 条评论
  • Top 10 Operational Risks in 2022

    Top 10 Operational Risks in 2022

    Hot off the press: Best Practice Operational Risk Forum, comprised of professionals from over 50 national and…

    55 条评论

社区洞察

其他会员也浏览了