You are on page 1of 9

RISK CONTROL SELF ASSESSMENT

(RCSA)
PRESENTATION BY – KUMAR NATARAJAN

4th Annual Operational Risk


Management Forum
Dubai, 2012

© Kumar Natarajan 2012. Contact: kumar_natarajan@hotmail.com


Agenda for this session

• How to identify risks for which RCSA may


be deployed?
• Why RCSA?

• Types of RCSA?

• Reporting RCSA Results

• How to make the process effective?

© Kumar Natarajan 2012. Contact: kumar_natarajan@hotmail.com


Which risks to deploy RCSA?

• All Risks

• At an appropriate level of granularity

• Risks defined in the language of the risk


owner
• Risks duly mapped to source and

• Controls

© Kumar Natarajan 2012. Contact: kumar_natarajan@hotmail.com


Why Risk Control Self
Assessment (RCSA)?
• Survey?

• Risk owners opinion or expert opinion?

• An opportunity to communicate views on


risks
• Biggest benefit – Culture building…..

© Kumar Natarajan 2012. Contact: kumar_natarajan@hotmail.com


Types of RCSA

• Whatever works…

• Multiple choice RCSA..

• Probability and Impact scale based RCSA

• Voting and aggregation (workshop scenario)

© Kumar Natarajan 2012. Contact: kumar_natarajan@hotmail.com


Reporting RCSA Results

• A top down view for senior management

• Heat map – several types available

• Need to define reporting parameters.. For e.g. if


based on a scale of 1-5 what is one and what is 5? If
based on good….bad. What is good what is bad?
• Scope to drill down till the risk mapping.

• Multiple slice and dice views, risk/product/etc.

© Kumar Natarajan 2012. Contact: kumar_natarajan@hotmail.com


Sample Heat Maps

Risk 1

5 Risk 2

Risk 3

Risk 4

0 Risk1
5
Risk2

© Kumar Natarajan 2012. Contact: kumar_natarajan@hotmail.com


How to make the process
effective?

• Million dollar question…

• Consistency in assessment cycle and methodology

• Regular discussion of assessment results with stake


holders
• Regular reporting and commentary by Operational
risk on the assessments to top management.

© Kumar Natarajan 2012. Contact: kumar_natarajan@hotmail.com


Thank You
Kumar Natarajan
Practicing Operational Risk Professional

Email : kumar_natarajan@hotmail.com
LinkedIn Profile :http://ae.linkedin.com/in/kumar1

© Kumar Natarajan 2012. Contact: kumar_natarajan@hotmail.com

You might also like