Skip to main content
Image coming soon

The US Regional Bank Risk Specialist Evidence Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The US Regional Bank Risk Specialist Evidence Playbook

Turn the OCC Heightened Standards risk-id artefacts your line manager keeps redlining into clean first-line submissions auditors sign off without follow-up.

The residual rating, the control adequacy note, and the issue write-up keep coming back with red ink. Second line and QA ask the same three challenge questions every cycle. The course rebuilds those three artefacts so they pass first time.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Risk Specialists at large US banks live inside an evidence economy. The OCC Heightened Standards taxonomy sits behind every risk-ID memo. The CCAR and DFAST cycles pull on the operational and credit risk inventories. The Federal Reserve SR 11-7 and SR 21-3 governance memos sit behind every model risk submission. The internal three-lines-of-defence playbook stamps QA challenge questions on every issue. The artefacts that decide year-end review are not the dashboards, they are the small stack of memos and self-assessments that survive challenge without rework. This course is built around exactly those artefacts: the residual rating narrative, the control adequacy note, the issue write-up with root cause and target date, the quarterly RCSA refresh, the heightened-standards self-assessment, and the BSA/AML risk inventory update. Twelve modules, each anchored to one artefact, each ending in a worked example you can drop straight into your work papers.

What you walk away with

  • Write a residual rating narrative that survives second-line challenge first pass.
  • Map every control adequacy note to the OCC Heightened Standards twelve categories without ambiguity.
  • Draft issues with root cause, control gap, and target date that QA accepts without rework.
  • Refresh the RCSA inventory inside the quarterly window without rolling over stale ratings.
  • Produce a heightened-standards self-assessment narrative the board pack uses verbatim.

The 12 modules

Module 1. The residual rating narrative that survives QA
Walks through the three challenge questions QA asks every cycle: is the inherent rating supported by loss data or scenario evidence, is the control rating supported by testing results, and does the residual rating arithmetic match the heightened-standards rubric. The worked example is a credit concentration residual rating for a commercial real-estate book, with the second-line redlines that did not survive and the rewrite that closed them.
Module 2. Control adequacy notes mapped to the OCC twelve categories
Builds a single-page control adequacy note that names the OCC category, the control objective, the control activity, the testing population, the testing exception rate, and the adequacy conclusion. Includes a side-by-side of three notes that QA returned and the three rewrites that passed. The template is structured so the second-line reviewer can complete challenge in under fifteen minutes.
Module 3. Issue write-ups with root cause and target date that hold
The issue write-up is where most rework happens. Root cause gets written as a symptom, target dates slip without governance, and the linkage to the control universe is missing. This module teaches the five-why root cause format the second line accepts, the target-date governance template that survives steering committees, and the issue-to-control linkage that lets QA close the loop without a follow-up email.
Module 4. The quarterly RCSA refresh without stale ratings
Risk and Control Self-Assessment refreshes go wrong when the inventory rolls over without challenge. This module gives the quarterly script: which risks must be re-rated based on loss events, which controls must be re-tested based on operating effectiveness changes, and which issues must be re-aged. Includes the spreadsheet template, the second-line review checklist, and the change-log format the audit committee asks for.
Module 5. The heightened-standards self-assessment narrative
Once a year the holding company writes a self-assessment against the OCC Heightened Standards. The narrative is what the board reads and what the OCC examiner tests. This module walks through the twelve-category narrative template, the supporting evidence pack the examiner expects, and the gaps-and-remediation section that turns honest weakness into credible commitment. Includes a worked example for the credit risk pillar.
Module 6. BSA/AML risk inventory update aligned to the FFIEC manual
The BSA/AML risk inventory has its own taxonomy from the FFIEC examination manual. The module maps the bank's products, services, customers, and geographies into the inventory, walks the risk-rating logic from inherent through control to residual, and produces the documentation pack the next FFIEC exam will request. The worked example covers correspondent banking and trade finance, where most exam findings concentrate.
Module 7. Operational risk loss event capture and classification
The operational risk loss database drives capital under the standardised approach and is the input to scenario analysis. The module teaches the seven Basel event-type categories, the timing rules for capture, the threshold logic for material events, and the boundary calls between operational and credit losses. Includes the loss event template, the classification decision tree, and the case studies from internal fraud, external fraud, and execution and delivery.
Module 8. Third-party risk: inherent risk tiering and ongoing monitoring
The OCC and Federal Reserve interagency guidance on third-party relationships sets the expectations. The module covers the inherent risk tiering questionnaire, the due diligence requirements per tier, the contract clauses examiners look for, the ongoing monitoring cadence, and the exit and concentration risk reporting. Includes the tiering template, the due diligence checklist, and the quarterly monitoring report format.
Module 9. Model risk submission against SR 11-7 and SR 21-3
For first-line risk specialists touching model inputs and outputs, the SR 11-7 model inventory submission and the SR 21-3 governance memo are the gatekeepers. The module covers the model inventory entry, the conceptual soundness write-up, the ongoing monitoring report template, and the governance memo that gets the model into production. Includes a worked example for a deposit attrition model and the validation comments that closed approval.
Module 10. Information security risk and the FFIEC CAT
The FFIEC Cybersecurity Assessment Tool is the diagnostic the regulator expects against the inherent risk and the cybersecurity maturity. The module walks the inherent risk profile by technology, delivery channel, online product, organisational characteristic, and external threat. It then walks the maturity assessment across the five domains. Includes the worked CAT for a regional bank and the board reporting summary.
Module 11. Audit committee and risk committee evidence packs
The quarterly risk committee pack and the audit committee pack are the artefacts the board sees. The module covers the residual risk heat map, the top-issues page, the emerging risk section, the regulatory exam tracker, and the management response to internal audit findings. Includes the template the committee secretary uses, the slide format the chair prefers, and the speaking notes the CRO uses to walk the page.
Module 12. Preparing for an OCC continuous monitoring meeting
OCC supervisors run continuous monitoring meetings monthly or quarterly. The agenda is predictable: portfolio composition, top emerging risks, control environment changes, recent issues, and management actions. The module walks through the meeting prep pack, the talking points the line of business head will use, the questions the supervisor will ask, and the follow-up letter format the OCC sends. Includes a worked example for a commercial banking line of business.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Residual rating returned by QA, line manager asking for a stronger evidence link.
Heightened-standards self-assessment narrative needs the credit risk pillar rewritten before board pack lockdown.
Third-party risk tiering questionnaire is out for the next vendor refresh and the contract clauses must be in place.
Risk committee pack drafting cycle is open and the top-issues page needs an update with current target dates.

What you get with this course

  • Twelve worked submissions across the OCC Heightened Standards risk categories, each with the QA challenge questions and the wording that closes them.
  • Editable templates for residual rating narratives, control adequacy notes, issue write-ups, RCSA refresh sheets, and self-assessment pages.
  • A hand-built implementation playbook tailored to the recipient's portfolio of risks and the second-line review patterns at their bank.
  • Side-by-side redlines showing what QA returned and what passed first time.
  • A 30-day money-back position if the submissions in the recipient's actual cycle do not pass first-line review.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

Modules one through four cover the artefacts most likely to be on your desk this cycle: residual ratings, control adequacy notes, issue write-ups, and the RCSA refresh.

Modules five through eight cover the cross-pillar artefacts: heightened-standards self-assessment, BSA/AML inventory, operational loss capture, and third-party risk tiering.

Modules nine through twelve cover the higher-stakes artefacts: model risk submissions, FFIEC CAT, board pack pages, and OCC continuous monitoring prep.

Before and after

Before

Risk-ID memos and self-assessment narratives that come back with red ink, two or three rounds of rework per cycle, and a year-end review that flags evidence quality as a development area.

After

Submissions that pass first-line and second-line review on the first pass, a self-assessment narrative the board pack uses verbatim, and a year-end review that flags evidence quality as a strength.

What happens if you do not address this

Risk specialists who keep getting work returned by QA absorb the rework cost personally. The team capacity goes into rewrites instead of into the next cycle's risk-ID work. The OCC examiner sees thin evidence files and writes a finding. The line of business head loses confidence in the risk function's submissions.

Who it is for

A Risk Specialist or Risk Analyst in the first or second line of defence at a US bank with consolidated assets above 50 billion USD, sitting under a Chief Risk Officer org with separate operational, credit, third-party, BSA/AML, model and information security risk pillars, accountable for the artefacts that go into the OCC Heightened Standards and the holding-company self-assessments.

Who this is NOT for. Not for risk leaders at community banks under 10 billion in assets, where the heightened-standards regime does not apply. Not for pure quantitative model developers whose work is governed by SR 11-7 validation rather than first-line risk identification. Not for second-line policy writers whose output is the policy itself rather than evidence against the policy.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Six to ten hours across the twelve modules, completed at the cadence your cycle dictates. Most specialists complete a module the evening before the artefact is due and use the template the next morning.

Why $199 is the right number

Internal training tends to walk the policy without producing the artefact. External GARP or PRMIA reading is theory without the submission template. Big four advisory work produces a deck, not the residual rating narrative your line manager will sign. This course produces the submission.

FAQ

Will this be specific to my bank's templates?
The implementation playbook is hand-built to your bank's templates and second-line review patterns once you purchase. The course modules use the regulator-canonical templates so the principles transfer.
Does this cover model risk validation?
Module nine covers the first-line model risk submission and governance memo. Validation work itself is the second-line model risk function and is out of scope here.
How current is the heightened-standards material?
The OCC Heightened Standards twelve categories are stable. The course uses the current FFIEC examination manual and the active interagency third-party guidance for the supporting material.
Is the implementation playbook reusable cycle to cycle?
Yes. The playbook is built around your portfolio of risks so the templates carry through quarter to quarter. Updates are your work to fold in.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.