Skip to main content
Image coming soon

The Operational Risk Officer's Issues-and-Events Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Operational Risk Officer's Issues-and-Events Playbook

Run RCSA, issues, events, KRIs and third-party reviews as one closed loop that holds up to OCC, Fed and internal audit scrutiny.

An operational risk event that keeps re-opening, a KRI that nobody recalibrated after the last loss, and an RCSA that no longer reflects the control changes second line forced through. The pieces are all there, the loop between them is not.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Operational risk officers at a large US bank inherit a control inventory built across two decades of mergers, an issues backlog the prior CRO restructured, an ORC packet expected to land monthly, and an OCC heightened standards file the examiner expects to see updated after every material event. Loss events get logged, root cause gets written, an action plan gets owned by the line, second line validates closure, and six months later the same event re-opens because the underlying control was never re-rated in the RCSA and the KRI threshold was never recalibrated. The internal audit team writes the same finding twice. The examiner asks for the evidence trail and the team produces three artefacts from three systems with no canonical link between them. The work is not absent. The closed loop between event, control change, KRI and RCSA is.

What you walk away with

  • A canonical loss-event-to-control-to-KRI-to-RCSA link table that survives a regulator request without three days of reconciliation.
  • RCSA re-rating logic that fires automatically after a material event closes, instead of waiting for the annual refresh.
  • KRI threshold recalibration procedure tied to event severity, so a breach actually signals something second line did not already know.
  • Issues-management evidence pack template that satisfies internal audit and the OCC examiner from the same source artefacts.
  • Third-party operational risk review cadence aligned with the same control inventory the RCSA uses, ending the dual-inventory problem.

The 12 modules

Module 1. The Closed Loop: Events, Issues, Controls, KRIs, RCSA
The five artefacts every operational risk function maintains, why they typically drift apart, and the canonical link table that ties them. You will map each artefact your team currently maintains to its place in the loop, identify the missing joins, and draft the data-model change that turns five disconnected inventories into one queryable graph the CRO can interrogate in a single sitting.
Module 2. Loss Event Taxonomy: Basel, ORX, and Your Internal Map
Basel II event-type categories, ORX Reference Taxonomy, and the internal taxonomy your bank actually uses. You will reconcile the three, document the cross-walk in a single sheet, and resolve the handful of internal categories that map to two Basel buckets or none. Output is a taxonomy your loss-data team can defend to ORX peer-bank reviewers and to an OCC examiner asking why a fraud event landed in execution.
Module 3. Root Cause That Drives Control Change
Most root-cause statements end at people, process, or system. None of those three drive a control change. You will rewrite a real root cause from your own inventory into a statement that names the failed control, the design weakness, and the specific control attribute that needs to change. The output is a root-cause template that forces a control-change action plan rather than a training reminder.
Module 4. RCSA Re-rating After a Material Event
The annual RCSA refresh is too slow for the events that matter. You will design a trigger-based re-rating procedure: which event types force a re-rating, which control owners are required to attend, what evidence has to be on the table, and how the re-rated inherent and residual scores propagate into the business-line risk profile that lands on the next ORC packet.
Module 5. KRI Threshold Recalibration
Most KRI breaches surprise no one and trigger no action. You will rebuild a KRI inventory for one business line, calibrate thresholds against the prior twelve months of internal and ORX loss data, and document a recalibration cadence tied to event severity. The output is a KRI pack where every breach forces a specific second-line conversation rather than a routine acknowledgement.
Module 6. Issues Management: Audit, Regulatory, Self-identified
Three streams of issues hit the same backlog and the closure standard for each one differs. You will document a single issues-management procedure that handles internal audit findings, OCC and Federal Reserve matters requiring attention, and self-identified issues, with closure criteria, validation owner, and evidence requirements explicit for each stream. The output is a procedure the examiner can read in twenty minutes.
Module 7. Third-Party Operational Risk Reviews
Your third-party reviews almost certainly maintain a separate control inventory from the RCSA, which is why the same vendor control gets rated twice with two different scores. You will redesign the third-party review template to draw from the same control inventory the RCSA uses, document the shared-control concept, and produce a vendor risk pack that no longer contradicts the enterprise RCSA.
Module 8. The Monthly ORC Packet
The Operational Risk Committee packet is the artefact most CROs read first and the artefact most operational risk teams put together last. You will redesign yours: the top-of-pack one-page event summary, the trend slide that ties loss events to control posture, the KRI heatmap with recalibrated thresholds, the issues aging slide that distinguishes audit from regulatory from self-identified, and the third-party page. Output is a packet template the CRO can stand behind in a board risk committee.
Module 9. OCC Heightened Standards: Evidence on Demand
The heightened standards file is what the OCC examiner asks for first and what most banks reconstruct under pressure. You will document the standing evidence the file needs to contain, the cadence at which each piece refreshes, and the source-system query that produces each artefact. Output is a procedure that lets the team produce the file in a day rather than a week, and a sample file mapped to the relevant OCC standards.
Module 10. Internal Audit Coordination Without Duplicate Testing
Internal audit and second-line operational risk both test controls and both write findings. Without a coordination model, the line gets tested twice on the same control and the bank pays for two opinions that disagree. You will draft a coordination protocol that names the shared control universe, the test-plan reconciliation cadence, and the rule for who writes the finding when both functions see the same issue.
Module 11. The Closure Validation Pack
Second-line validation of issue closure is the single artefact that examiners most often find missing or thin. You will build a validation pack template: what the action plan promised, what the line actually changed, what control evidence demonstrates the change is operating, and what KRI or RCSA score shifted as a result. The output is a pack the examiner can read once and accept, instead of asking three follow-up questions.
Module 12. Scenario Analysis and the Capital Conversation
Operational risk capital, whether under the standardised approach or an internal model, draws on scenario analysis your team is expected to lead. You will run one scenario end to end: the business-line and event-type combination, the severity distribution, the control-environment overlay, and the documentation pack that defends the resulting capital input to the model risk team and to the regulator. Output is a scenario template plus a sample scenario your team can reuse.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

If the same loss event in your inventory has re-opened, work modules 3, 4, and 11 in order; that triplet rebuilds the loop that lets a closure actually stick.
If the OCC heightened standards file is what your team most fears producing on demand, modules 9 and 6 are the spine; the rest are supporting evidence.
If your KRI pack is read as routine and breaches surprise no one, modules 5 and 8 are the priority; module 2 will surface the taxonomy mismatches feeding bad thresholds.
If third-party reviews and the RCSA disagree about the same vendor control, module 7 plus module 1 fix the dual-inventory problem at the data-model level.

What you get with this course

  • Twelve written modules in the Art of Service learning environment, each with worked examples drawn from US regional-bank operational risk practice.
  • Downloadable templates for the closed-loop link table, the root-cause-to-control-change form, the RCSA trigger-based re-rating procedure, the KRI recalibration sheet, the issues-management procedure, the third-party review template, the ORC packet, the OCC heightened standards evidence file, the internal audit coordination protocol, the closure validation pack, and the scenario analysis pack.
  • A hand-built implementation playbook tailored to your event-type mix, business-line scope, and regulator footprint, delivered alongside course access.

What you will have in hand by Day 1, Week 1, Month 1

Within a day of purchase: account in the Art of Service learning environment is provisioned, all twelve modules and every template are accessible, and the hand-built implementation playbook lands alongside it tailored to your event-type mix and regulator footprint.

Weeks one to four: complete modules one through six and apply the closed-loop link table, root-cause template, RCSA trigger-based re-rating procedure, and issues-management procedure to one business line.

Weeks five to eight: complete modules seven through twelve and roll the templates to a second business line, including the third-party review redesign and the ORC packet rebuild.

Week nine onward: the templates become the standing operating model for the function; ongoing access remains for refresh as regulation and taxonomy evolve.

Before and after

Before

Loss events log, root causes get written, action plans get owned by the line, second line validates closure, and a quarter later the same event re-opens because the RCSA never re-rated and the KRI threshold never moved. The ORC packet shows activity but not posture, and the OCC heightened standards file gets rebuilt every time the examiner asks for it.

After

Every material event closes through a documented re-rating of the affected control, a recalibrated KRI threshold, an updated RCSA score, and a validation pack the examiner can read once and accept. The ORC packet reads as posture rather than activity, the heightened standards file is standing rather than reconstructed, and internal audit findings stop repeating.

What happens if you do not address this

An OCC heightened standards review that reopens findings the bank thought were closed, a Federal Reserve horizontal review that ranks your operational risk function below peers, a CRO who has to defend a packet that reads as activity instead of posture, and a quiet drift toward an MRA on second-line effectiveness that takes two cycles to clear.

Who it is for

You are a senior Operational Risk Officer at a large US regional or super-regional bank. You own the second-line view of operational risk events, the RCSA refresh cycle for at least one business line, the KRI inventory tied to that line, the issues backlog from internal audit and from regulators, and the third-party operational risk review function. You report into a Head of Operational Risk who reports into the CRO. The OCC and the Federal Reserve are your primary regulators. ORX is your loss-data consortium. You sit in the second line, but the first line treats you as the de-facto owner of every artefact that names the word risk.

Who this is NOT for. First-line business managers, internal audit testers without second-line responsibility, enterprise risk generalists at firms below regional-bank scale, and consultants pitching a SaaS platform. The playbook assumes you already operate inside a defined three-lines model with a real RCSA, real KRIs, and a real issues backlog, and that you are accountable for the loop between them rather than for any single artefact.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Roughly six to eight hours per week for eight weeks, weighted toward the modules covering the loop you most need to repair. Most officers complete the course in parallel with the regular ORC cycle rather than in addition to it.

Why $199 is the right number

A consulting firm will rebuild the loop for you for low six figures and leave when the engagement ends. An internal task force will spend a quarter scoping the work and rarely produce a procedure the examiner can read in twenty minutes. A GRC platform vendor will sell you a tool that needs the same procedure written before it can be configured. The playbook is the procedure, the templates, and a tailored implementation pack for 199 USD.

FAQ

Is this aligned to the OCC heightened standards specifically?
Yes. Module nine maps the standing evidence file to the relevant OCC standards, and the issues-management and closure-validation modules are written to the standard the OCC examiner expects in a heightened standards review.
Does it cover ORX taxonomy?
Yes. Module two reconciles the Basel II event-type categories, the ORX Reference Taxonomy, and the internal taxonomy your bank uses, with a cross-walk template you can defend to ORX peer-bank reviewers.
How is the implementation playbook tailored?
After purchase your event-type mix, business-line scope, and regulator footprint are used to produce a playbook that names the specific re-rating triggers, KRI thresholds, and issues categories your function should adopt. The course modules remain general; the playbook is yours.
Will this conflict with the work an internal audit consulting firm has already started?
No. Module ten is the coordination protocol with internal audit, written so the second-line procedure complements rather than overlaps audit testing. Many officers run the course in parallel with an active audit engagement.
What if my function is smaller than a super-regional bank?
The procedures scale down cleanly. The closed-loop link table, the root-cause template, and the issues-management procedure work at any scale; the ORC packet and heightened standards file modules assume a regulator relationship and a board risk committee, which apply broadly across regional banks.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.