Risk and Control Self-Assessment for Operational Loss Prevention Training Course
| Course code | SD-RM-036 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Risk Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Operational losses frequently arise from known process weaknesses: unclear ownership, undocumented manual workarounds, ineffective reconciliations, poorly designed access controls, or risk assessments that are completed as an annual compliance exercise rather than used to drive remediation. Risk and Control Self-Assessment (RCSA) gives operational risk teams and business managers a structured method for identifying these exposures before they become loss events, audit findings, customer harm, or regulatory breaches. This course focuses on building RCSAs that management can use to make defensible control and investment decisions.
Participants learn to scope an RCSA around a process, legal entity, product, or risk theme; map process steps and hand-offs; identify operational risk events, causes, and impacts; assess inherent and residual risk; evaluate control design and operating effectiveness; and document treatment actions. The course addresses risk and control taxonomies, assessment scales, control libraries, loss-event data, key risk indicators (KRIs), scenario analysis, challenge sessions, and reporting for risk committees. Participants practise distinguishing a control from a procedure, an issue from a risk, and a risk indicator from a performance metric.
Instruction combines worked examples, facilitated calibration discussions, control-testing scenarios, and a running operational-loss case study. Participants build an RCSA pack for a realistic business process, including a process-and-risk map, control assessment, scoring rationale, KRI set, issue log, remediation plan, and committee-ready risk summary. The final day includes an application workshop in which each participant adapts the method to a live or anticipated RCSA in their own organisation.
The course is suited to experienced risk, control, audit, compliance, finance, and operations professionals who need to improve the quality, consistency, and decision value of operational risk assessments.
Course objectives
By the end of this course, participants will be able to:
- Scope an RCSA using a defined process boundary, risk taxonomy, and accountable ownership model
- Map end-to-end business processes to identify failure points, hand-offs, systems, and manual interventions
- Formulate operational risk statements that separate event, cause, impact, and affected stakeholder
- Assess inherent and residual risk using calibrated likelihood, impact, velocity, and control-effectiveness criteria
- Evaluate control design and operating effectiveness using a control objective and evidence-based testing approach
- Develop KRIs with thresholds, escalation triggers, data owners, and linkage to identified risks
- Produce a prioritised remediation plan with actions, owners, due dates, dependency analysis, and validation criteria
- Present an RCSA results pack containing risk heat maps, control gaps, loss-data insights, and management recommendations
Benefits of attending
For you
- Gain a repeatable method for facilitating credible RCSA workshops with process owners and senior managers
- Build the judgement to challenge weak risk statements, unsupported scores, and ineffective controls
- Create committee-ready risk packs that demonstrate clear links between risks, controls, indicators, and actions
- Strengthen credibility for operational risk, controls assurance, internal audit, and second-line risk roles
- Develop practical evidence for leading an RCSA refresh, control rationalisation, or operational-loss reduction initiative
For your organisation
- Improve consistency of risk and control assessments across functions, products, and legal entities
- Identify control gaps and manual-process weaknesses before they result in operational loss events or audit findings
- Produce clearer risk-based priorities for remediation funding, control automation, and management attention
- Create stronger evidence trails for risk committees, internal audit reviews, and regulatory examinations
- Link incident data, KRIs, control assessments, and action plans into a more useful operational risk profile
Target competencies
Who should attend
- Operational Risk Managers — who design, coordinate, or challenge RCSA programmes across business units
- Risk and Control Officers — who maintain risk registers, control libraries, and remediation tracking
- Internal Auditors — who assess management control frameworks and need stronger risk-assessment evidence
- Business Process Owners — who are accountable for operational processes and control performance
- Compliance Managers — who need to connect regulatory obligations to operational risks and controls
- Finance Control and Assurance Professionals — who oversee reconciliations, reporting controls, and loss prevention
Requirements and prerequisites
Participants should have practical exposure to operational processes, internal controls, audit, compliance, finance operations, or enterprise risk management. They should understand basic concepts such as risk appetite, risk registers, control ownership, incidents, issues, and corrective actions. Familiarity with spreadsheets is assumed, as participants work with assessment templates, scoring matrices, and KRI data in Microsoft Excel. Prior experience of running an RCSA is helpful but not essential. Statistical modelling, coding, specialist GRC-system administration, and prior certification in ISO 31000 or COSO are not required.
Training methodology
The course uses short instructor-led method sessions followed by structured application to a running payments-operations loss case. Participants work in groups to map a process, draft risk statements, rate inherent and residual exposure, challenge control evidence, and design KRIs and action plans. The instructor demonstrates practical Excel-based RCSA templates and examples from GRC platforms, while peer calibration exercises expose differences in scoring judgement. Each day closes with a reviewed working-paper output, culminating in an individual application plan for a current RCSA cycle or control issue.
Course outline
Day 1: RCSA foundations and assessment scope
- Operational loss event categories and causal analysis
- RCSA purpose within the three-lines model
- Process, entity, product, and thematic RCSA scoping
- Risk appetite, tolerance, and escalation boundaries
- Risk taxonomy design and risk-register architecture
- Roles of process owners, control owners, facilitators, and challengers
- RCSA governance calendar, approval routes, and evidence standards
Workshop: Participants define the scope, stakeholders, risk taxonomy references, and governance plan for an RCSA of a payments-operations process.
Day 2: Process mapping and risk identification
- SIPOC and swimlane process-mapping techniques
- Identifying hand-offs, manual workarounds, and system dependencies
- Risk-event, cause, impact, and consequence statement structure
- Using internal loss-event data to identify recurring exposures
- Near misses, customer complaints, audit findings, and issue data
- Root-cause techniques using five whys and causal factor analysis
- Risk-and-control matrix construction
Workshop: Participants produce a swimlane process map and a risk-and-control matrix identifying failure modes in the case-study payment workflow.
Day 3: Control assessment and residual risk scoring
- Control objectives, control activities, and control ownership
- Preventive, detective, corrective, and compensating controls
- Control design-effectiveness assessment criteria
- Operating-effectiveness evidence and sample-based testing
- Inherent risk scoring using likelihood and impact scales
- Residual risk calculation and score-calibration workshops
- Control gaps, control rationalisation, and residual-risk acceptance
Workshop: Participants assess five controls, document supporting evidence, score inherent and residual risk, and prepare a calibration rationale.
Day 4: KRIs, scenarios, and treatment actions
- KRI selection criteria and causal linkage to risk events
- Thresholds, limits, triggers, and traffic-light status design
- Distinguishing KRIs from KPIs and key control indicators
- Scenario analysis for low-frequency, high-impact losses
- Risk treatment options: mitigate, transfer, avoid, and accept
- Issue prioritisation using impact, urgency, dependency, and cost
- Remediation action plans and closure-validation evidence
Workshop: Participants design a KRI dashboard and prioritised remediation plan for the highest residual risks in the case study.
Day 5: Challenge, reporting, and implementation
- First-line self-assessment and second-line challenge protocols
- Quality assurance checks for RCSA completeness and consistency
- Risk heat maps, control-gap reporting, and risk narratives
- Management information for operational risk committees
- Linking RCSA outputs to internal audit plans and assurance testing
- Using Microsoft Excel, ServiceNow GRC, and RSA Archer RCSA workflows
- Annual refresh cycles, event-driven reassessments, and continuous monitoring
Workshop: Participants present a committee-ready RCSA pack and complete an implementation plan for applying the method to their own business area.
Tools & standards covered
Microsoft Excel, ServiceNow GRC, RSA Archer, ISO 31000
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Risk Management
Corporate Treasury Risk Management for Treasury Managers Training Course
Treasury managers are expected to protect liquidity, funding capacity and financial results while markets, counterparties and operating cash…
Three Lines Model for Financial Risk Accountability Training Course
Finance and accounting teams are often expected to own, challenge, report and assure risk at the same time. The result can be unclear contro…
Bloomberg Portfolio Risk Analytics for Investment Professionals Training Course
Portfolio managers and risk teams need to explain not only how a portfolio performed, but how its exposures could behave under changing rate…
COSO ERM Financial Risk Governance Training Course
Finance and accounting teams are expected to identify material risks early, explain their financial implications, and show that controls, li…