Running risk and control assessment - whether you call it RCSA or fold it into operational risk routines - is less about the template and more about sequence and discipline. When the steps are clear, the first line knows what "done" looks like, and second line can review quality instead of reconstructing meaning from inconsistent spreadsheets.
Below is a practical flow for risk and control assessment / RCSA that works in regulated firms. Adapt the granularity to your size - but keep the logic: risks first, controls mapped with intent, assessments backed by evidence, gaps owned, and actions tracked to closure.
Step 1: Define the Risks (Scope and Materiality)
Start with scope: which processes, products, entities, or systems are in boundary for this cycle? Then identify inherent risks - what could go wrong before considering controls - using a consistent taxonomy (categories, causes, impacts).
Avoid the trap of listing hundreds of micro-risks. Prefer a smaller set of material risks that leaders recognise, with clear owners. If everything is high priority, nothing is.
- Align to risk appetite statements where they exist - so scoring maps to how the organisation actually tolerates loss or failure.
- Record likelihood and impact using agreed scales and worked examples - not gut feel hidden in a single cell.
Step 2: Map Controls to Risks (Deliberately)
For each material risk, map the key controls that meaningfully reduce likelihood or impact. Classify them (preventive, detective, corrective) so everyone understands the role each plays. If a control does not change the risk story, question whether it belongs in the core map.
Good mapping answers: if this control failed tomorrow, would risk materially increase? If the answer is no, it is probably secondary documentation - not a key control.

