A focused course, tailored for you
The LOB Risk Lead's First-Line RCSA and Issue-Closure Playbook
Run a first-line risk function at a large US bank where the RCSA is the source of truth and issue closure stops being the bottleneck.
The LOB Risk Lead role at a large US bank is judged on three artefacts: the RCSA that second-line and audit accept, the issue log that closes on time with evidence audit accepts without rework, and the LOB risk committee pack that tells the head of the business what to decide. When any of those drift, every other accountability of the role drifts with it.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
First-line LOB risk leads at large US banks live in a specific squeeze. The second-line risk function wants the RCSA mapped to its enterprise taxonomy, the issues coded to its issue framework, and the residual ratings reconciled to its risk appetite. Internal audit wants control descriptions that match the test plan, evidence that proves design and operating effectiveness, and a clear line from issue to root cause to remediation. The OCC and the Federal Reserve want the first-line to own its own risk, not delegate it to the second-line. The head of the LOB wants a risk committee pack that supports the next product decision, not a recap of last quarter's findings. The role becomes a translation layer between four audiences who each want the same data in a different shape. The RCSA refresh stretches from a six-week exercise to a four-month exercise. Issue closure piles up. The KRI thresholds were set by the prior risk lead and nobody has reconciled them to actual loss experience. Third-party risk attestations sit in a separate workflow that the LOB has no operational ownership of. The risk committee deck gets rewritten by the LOB head's chief of staff the night before the meeting because the version the risk function shipped did not answer the business question. This course rebuilds the operating model so the first-line LOB risk function produces one set of artefacts the second-line, audit, the regulators and the LOB head all read off.
What you walk away with
- Produce an RCSA refresh the second-line signs off the first pass, with control descriptions and residual ratings that reconcile to the issue log.
- Close issues on the date the issue log says, with evidence packs audit accepts without rework.
- Run KRI thresholds tied to actual loss data and recent near-miss events, not values inherited from a prior risk lead.
- Walk into the LOB risk committee with a pack that gives the head of the business one or two decisions to make, not a recap.
- Own the third-party risk attestations for the vendors your LOB depends on inside the LOB risk operating model, not in a separate workflow.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- Twelve written modules in the Art of Service learning environment, each with downloadable templates and worked examples drawn from large US bank first-line LOB risk functions.
- The RCSA refresh kit: risk taxonomy mapping worksheet, preventive-vs-detective classification rules, residual rating calibration worksheet, second-line challenge tracking log.
- The issue closure evidence pack template, with separate sections for control-design evidence, operating-effectiveness evidence and the sustainability test.
- The KRI recalibration worksheet that ties thresholds to historical loss data and leading-indicator events.
- Two worked LOB risk committee decks, one for a growth decision and one for a remediation decision.
- The federal examination preparation file structure and the MRA response template.
- A hand-built implementation plan for your specific line of business, written after purchase against the LOB context you supply at intake.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.
Module 1 and module 2 read together cover the first week of work on the operating model and the RCSA refresh.
Modules 3 to 5 build out the issue log, KRI methodology and third-party integration over the next two to three weeks.
Modules 6 to 9 cover model risk, the LOB risk committee, second-line working agreement and audit liaison.
Modules 10 to 12 close the loop on examination preparation, event capture and the 90-day operating cadence.
Before and after
The RCSA refresh runs four months because the second-line keeps reopening control descriptions and residual ratings. The issue log carries half the open issues past their target closure date. The KRI thresholds were set by the prior risk lead and nobody knows the methodology. The LOB risk committee pack gets rewritten by the LOB head's chief of staff. Third-party risk lives in a separate workflow the LOB cannot see into.
The RCSA refresh runs six weeks with second-line sign-off on the first pass. Issues close on the date the log says, with evidence packs audit accepts. KRI thresholds are tied to actual loss data with a documented methodology the second-line accepts. The LOB risk committee pack opens with the one or two decisions on the table and the LOB head reads it ahead of the meeting. Third-party risk attestations are part of the LOB operating model and show up in the same risk picture the committee sees.
What happens if you do not address this
If the RCSA, the issue log, the KRI dashboard and the risk committee pack continue to read as four separate artefacts in four different shapes, the function stays in translation mode. The federal examiners will eventually issue a matter-requiring-attention on first-line risk ownership. The LOB head will route around the risk function for product decisions. The role becomes reactive and the people in it leave.
Who it is for
You lead first-line risk for a specific line of business at a large US commercial or retail bank. You own the RCSA refresh, the issue log, the KRI dashboard, the third-party risk attestations for vendors your LOB depends on, the LOB risk committee deck, and the relationship with the second-line risk partner assigned to your LOB. You report into the LOB Chief Risk Officer or directly into the head of the business. You sit between the second-line enterprise risk function, internal audit, the regulators who examine your LOB, and the head of the business who wants to grow it. You have between three and twelve direct reports, a mix of risk officers, control testers and a risk reporting analyst.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Around twenty to thirty hours of reading and template work across the twelve modules. Most learners run the operating-model change inside their function over a single quarter while working through the modules in parallel.
Why $199 is the right number
Most first-line risk leads either run with whatever operating model they inherited from the prior lead, bring in a consulting firm at a six-figure engagement to rebuild the function, or hire a head of risk transformation into the LOB. The course is the operating model written down with the templates the role actually uses, at a price the role can authorise without a procurement cycle.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.