Skip to main content
Image coming soon

The Business Unit Risk Manager's Quarterly Reporting Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Business Unit Risk Manager's Quarterly Reporting Playbook

Build the BU risk report your business head reads, your second line signs off, and the audit committee cites without rewrites.

The quarterly BU risk report is the one artefact every senior stakeholder reads, and it is the artefact that gets rewritten the most. The business head wants the bottom line, the second line wants the methodology, internal audit wants the evidence, and the regulator wants the trend. Most BU risk managers ship a version that satisfies one of those readers and disappoints the other three.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

A Business Unit Risk Senior Manager inside a US broker-dealer and wealth-management firm sits at a difficult seat. The first line owns the risk. The second-line enterprise risk function owns the framework. The BU risk function is the translator between them, and the translation product is the quarterly risk report, the RCSA refresh, the issue and finding log, and the KRI dashboard. When those four artefacts agree with each other and tell a single story, the BU risk function is invisible in the good way. When they disagree, every senior reader notices, and the BU risk manager spends the next two weeks reconciling. This course is the reconciliation playbook. It treats the four artefacts as one connected reporting system. It walks through the taxonomy crosswalks between the BU's operational-risk categories and the enterprise framework. It teaches the residual-risk attribution math that survives second-line challenge. It teaches the issue triage that audit will not reopen. It teaches the executive narrative pattern that the divisional president actually reads instead of skimming. It is built for the seat, not for the framework.

What you walk away with

  • A BU-level operational-risk taxonomy that maps cleanly to the enterprise framework and to the regulator's expected categories.
  • A residual-risk attribution model that the second line accepts on the first review.
  • An issue and finding triage protocol that audit closes rather than reopens.
  • A KRI threshold-setting method that produces actionable signal at the BU level instead of green-amber noise.
  • A quarterly executive narrative pattern that the divisional president reads end to end.

The 12 modules

Module 1. The BU risk seat and the four reporting artefacts
Map the role honestly. The BU risk function exists to translate between the line of business and the enterprise framework. The translation product is four connected artefacts: the RCSA, the quarterly risk report, the issue and finding log, and the KRI dashboard. This module pins down what each artefact is actually for, who its primary reader is, and the failure mode when the four disagree. The rest of the course is the reconciliation method.
Module 2. BU taxonomy crosswalk to the enterprise framework
Most BU risk reports fail because the BU's natural risk categories do not map cleanly to the enterprise taxonomy or to the operational-risk categories the regulator expects. This module walks the crosswalk. Build a two-way mapping from the BU's working categories (client onboarding, trade processing, advisor supervision, custody, fee billing) to the enterprise framework and to the standard operational-risk event-type categories. Document the mapping once so every downstream artefact uses it.
Module 3. Inherent risk scoring that survives challenge
Inherent risk is the easiest score to overstate and the easiest to under-defend. Walk through a scoring rubric that names the drivers explicitly (transaction volume, dollar exposure, customer impact, regulatory sensitivity, change velocity), the evidence required for each driver score, and the calibration anchors that keep the BU's inherent ratings comparable to peer BUs. The output is a scoring sheet the second line accepts as evidence rather than as assertion.
Module 4. Control inventory and design effectiveness
Move from a control list to a control inventory with design assertions. For each material control, document the control owner, the control objective, the control type (preventive, detective, corrective), the frequency, and the design effectiveness rationale. This module gives the working format and the evidence standards. The output is the control inventory that the RCSA references and that internal audit walks during the next operational-risk audit.
Module 5. Residual risk attribution math
Residual risk is the number every senior reader looks at, and it is the number most BU risk managers cannot defend in detail. Walk the attribution math from inherent risk through control design effectiveness through control operating effectiveness to residual. Show the residual movement quarter over quarter and the specific control or exposure change that drove the movement. The output is a residual-risk worksheet that explains itself.
Module 6. Issue and finding triage that audit closes
Issues and findings pile up because triage is inconsistent. Walk through a triage protocol that classifies every open item by source (self-identified, internal audit, compliance testing, regulatory, second-line), by severity using a defined rubric, by remediation owner, and by target close date with named milestones. Show the closure evidence standard internal audit accepts. The output is an issue log that closes items at the rate they open instead of accumulating.
Module 7. KRI design and threshold setting at the BU level
Enterprise-level KRIs do not produce signal at the BU level. Walk through the design of BU-specific KRIs, the data sources behind them, the threshold-setting method that produces actionable amber and red zones, and the escalation path when a threshold is breached. Show the three to seven KRIs that actually matter for a wealth-management or broker-dealer BU and the calibration evidence that defends them under challenge.
Module 8. RCSA refresh execution
Run the quarterly or semi-annual RCSA refresh as a managed process rather than a workshop scramble. Walk the pre-refresh data pull, the workshop agenda that gets honest answers from process owners, the scoring reconciliation between participants, the second-line review cycle, and the documentation standard. The output is a refresh that closes inside two weeks with audit-ready evidence and accepted second-line sign-off.
Module 9. The executive narrative the divisional president reads
Senior business readers do not read the full report. They read the first page. Walk through a narrative pattern that opens with the residual-risk position, names the two or three concentrations that matter, explains the movement since last quarter, and closes with the specific decision being asked of the reader. The output is a one-page executive summary that the divisional president reads end to end and that the audit committee can cite without rewrites.
Module 10. Second-line challenge meetings and how to survive them
Second-line enterprise risk will challenge the BU risk report. The challenge is the point of the seat. Walk through how to prepare the challenge meeting, the evidence packet the second line expects, the questions they consistently ask (taxonomy mapping, residual attribution, issue ageing, KRI calibration), and the response patterns that close challenge rather than escalate it. The output is a challenge-meeting playbook that turns a defensive review into a productive one.
Module 11. Internal audit and regulator engagement
Internal audit and the BU's regulators (FINRA, SEC, OCC depending on the entity structure) read the same artefacts the BU risk function produces. Walk through how to position the RCSA, the issue log, and the KRI dashboard as evidence in an audit or regulatory exam. Show the document-request response pattern, the walkthrough preparation, and the trend-evidence presentation that satisfies the exam team without opening new findings.
Module 12. Quarter-close runbook and the next refresh cycle
Close the quarter with a runbook that produces the four artefacts in a single connected cycle: residual-risk position locked, issue log reconciled, KRI dashboard published, executive narrative written. Walk through the calendar, the responsible parties, the review gates, and the artefact dependencies. The output is a repeatable quarter-close process that the BU risk function owns end to end and that the second line can audit at any point.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Quarterly risk report needs to go upstairs and you do not want a third round of rewrites: modules 5, 9, 10 are the path.
RCSA refresh is on the calendar and last cycle ran two weeks late: modules 3, 4, 8 are the runbook.
Issue log is growing faster than it is closing: module 6 is the triage and module 11 is the audit engagement.
KRI dashboard is mostly green and nobody believes it: module 7 is the recalibration and module 2 is the taxonomy work behind it.

What you get with this course

  • Twelve written modules with worked examples drawn from US broker-dealer and wealth-management BU risk functions.
  • Downloadable templates: RCSA workbook, residual-risk attribution worksheet, issue and finding log, KRI dashboard, executive summary template.
  • The hand-built implementation playbook tuned to the recipient's BU structure and entity perimeter.
  • Access in the Art of Service learning environment, single seat, lifetime access to the materials.
  • Thirty-day satisfaction window.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours of purchase, the learning-environment account is provisioned and the tailored implementation playbook is delivered alongside it.

All twelve modules are available on first login.

The implementation playbook is hand-built to the recipient's BU structure (broker-dealer entity, wealth-management entity, dual-registrant, or banking BU) and uses the recipient's stated reporting cycle.

Before and after

Before

The quarterly report goes through three rounds of rewrites between the BU risk team, the divisional president's chief of staff, the second-line enterprise risk function, and the audit committee secretariat. The residual-risk number is questioned. The issue log is questioned. The KRI thresholds are questioned. The cycle closes a week late and the next refresh is already behind.

After

The four artefacts agree with each other and tell one story. The residual-risk position is defended by the attribution worksheet. The issue log closes items at the rate they open. The KRI dashboard produces actionable signal. The executive summary is read end to end and the audit committee cites it without rewrites. The cycle closes on calendar and the next refresh starts on time.

What happens if you do not address this

The BU risk function gets defined by the artefacts it ships. A report that gets rewritten three times defines a function that does not own its own product. Over enough quarters, the second line stops trusting the BU's residual-risk position, the divisional president stops reading past the first page, and the next operational-risk audit opens findings the BU did not see coming. The cost is not a single quarter, it is the cumulative loss of standing.

Who it is for

A Senior Manager or Manager of Business Unit Risk inside a US broker-dealer, wealth-management, or asset-management firm. Sits inside a line of business (advisor services, retail brokerage, institutional services, banking, asset management) and reports through a BU risk leader who reports to a divisional president and dotted-line to the enterprise CRO. Owns the RCSA refresh for the BU, the quarterly risk report, the issue and finding log, and a defined set of KRIs. Works alongside compliance, internal audit, and second-line enterprise risk. Has three to ten years in operational risk, financial-services risk, or audit.

Who this is NOT for. Not for second-line enterprise risk staff who own the framework rather than apply it inside a line of business. Not for internal auditors. Not for credit-risk or market-risk specialists. Not for risk staff at firms that have not yet stood up a formal RCSA process.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. About eight to twelve hours to work through all twelve modules. The templates are designed to be picked up and used inside the next quarter-close cycle rather than completed sequentially.

Why $199 is the right number

An enterprise risk management training course teaches the framework. A CFA or PRM certification teaches the discipline. Neither produces a working BU-level reporting product. Free industry papers describe the concepts at a level too generic to apply to a wealth-management or broker-dealer BU. This course is the working product: templates, worked examples, and a hand-built playbook tuned to the recipient's seat.

FAQ

Is this aligned to a specific framework?
It uses the standard operational-risk event-type categories and is mapped to the COSO ERM and ISO 31000 vocabularies, but the focus is the working artefacts at the BU level rather than the framework itself.
Does it cover broker-dealer specifics?
Yes. Worked examples cover advisor supervision, trade processing, custody, fee billing, and client onboarding. The implementation playbook is tuned to the recipient's entity perimeter.
Will the templates work in our GRC tool?
The templates are spreadsheet and document formats designed to be the source of truth that feeds whichever GRC platform the firm uses (Archer, ServiceNow GRC, OpenPages, MetricStream). The course explains the data model so the templates map cleanly into any of them.
What if I already run an RCSA?
Most BU risk teams already run one. The course addresses the parts that consistently struggle: residual-risk attribution, second-line challenge, issue closure rate, KRI threshold calibration, and the executive narrative.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.