Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk Management Program · CoreTrack
1Risk, Treasury & Financial Control
iRisk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
iiEnterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
iiiRisk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
ivCredit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
vMarket Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
viLiquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
viiOperational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
viiiRisk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
ixTreasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
xFinancial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
xiOperational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

How to run a Risk and Control Self Assessment

Nine steps, in this order: fix the scope, name the people and the challenger, list the risks, list the controls and mark the key ones, rate design, rate operation against evidence, judge what is left, raise an issue for every control that failed, then sign it and hand it on. Each step out of order leaves a mark that can be read in the finished document.

The definition of a risk and control self assessment, and the reason what comes back is kinder than an independent measurement of the same controls, are covered separately. The runbook is the rest: what happens on the first morning, what happens next, and what each step has to hand the step after it. An assessment can be run end to end, in order, by somebody who has never watched anybody else do it.

Nine steps, numbered RC1 to RC9. The numbering is a working scheme rather than anything an authority publishes. How often an assessment is run, how much of an institution it covers, and what rating words or scale it uses are decided inside an institution and named by whoever supervises it. The order is most of the method.

In what order do the nine steps actually run?

In the order they are numbered. Each step decides what the next step is allowed to be, so reversing any pair produces a defect that can be read straight off the finished document months later.

Step outside banking for a moment. A residential society runs a safety walk once a year. Suppose the committee agrees on the way down the stairs that the building is basically fine, and only then walks around writing things in the report. They are now looking for confirmations rather than for problems, so every item they find will be one they already have an answer for. The walk happened. The report exists. The report contains nothing anybody did not already believe on the staircase.

A safety walk run in that order is a reversal, and reversals leave marks. The reversal leaves a report in which every risk has something written against it and nothing is left uncovered. Fixing the answers first and writing the questions backwards out of them produces exactly that shape. A genuine list contains items nobody has an answer for yet. A list without them went wrong somewhere in the order.

NINE STEPS, RUN IN THIS ORDER, AND EACH ONE HANDS THE NEXT ITS INPUTThe order is the method. Every reversal leaves a mark in the finished document.Step numbering RC1 to RC9 is this guide's own and is not any authority's scheme.1RC1 FIX THE SCOPEhands on: a written scope statement naming the processes, the controls and the period2RC2 NAME THE PARTICIPANTS AND THE CHALLENGERhands on: a named list, one of whom is there to disagree3RC3 LIST THE RISKShands on: a risk list drawn from three separate sources4RC4 LIST THE CONTROLS AND MARK THE KEY ONEShands on: a control list with the key ones flagged5RC5 RATE THE DESIGNhands on: a design rating against every key control6RC6 RATE THE OPERATION AGAINST EVIDENCEhands on: an operating rating, and the evidence each one rests on7RC7 JUDGE WHAT IS LEFThands on: a residual judgement, made after the two ratings8RC8 RAISE THE ISSUEShands on: an issue with a named owner, an agreed action and a date9RC9 SIGN IT AND HAND IT ONhands on: a signed result carrying the disagreements as well as the ratings
Nine steps down one spine, with eight arrowheads marking the eight handoffs between them: the line written under each step is the thing it produces, and that thing is what the next step works from, which is why beginning at a rating step means rating a list no earlier step ever produced.

Read the middle column above as inputs and the bottom line of each box as outputs. The sequence is made of nothing but those two things. RC1 hands RC2 a population. RC2 hands RC3 a room. RC3 hands RC4 a list of risks to hang controls on. RC4 hands RC5 and RC6 the set of things to be rated. RC5 and RC6 hand RC7 two ratings to judge against. RC7 hands RC8 the places that are not good enough. RC8 hands RC9 a set of issues with names and dates on them. And RC9 hands the whole thing to whoever looks at it next.

Here is the same sequence written out flat, with the one thing each step produces. If a step has produced nothing anybody can point at, that step has not happened, whatever the plan says.

StepWho does itWhat comes out of it
RC1 Fix the scopethe people accountable for the processes, with the risk function holding the methoda written scope statement: which processes, which controls count, over what period
RC2 Name the participants and the challengerthe risk function, agreed with whoever will signa named list, including one person there to disagree
RC3 List the risksthe participants, working from three sourcesa risk list for each process in scope
RC4 List the controls and mark the key onesthe participants, with the method holder testing the lista control list with the key ones flagged
RC5 Rate the designthe participants, control by controla design rating against every key control
RC6 Rate the operation against evidencethe participants, holding up what the process itself producedan operating rating, and the evidence each one rests on
RC7 Judge what is leftthe participants, after both ratings and never before thema residual judgement for each process
RC8 Raise the issueswhoever is accountable for the failing controlan issue with a named owner, an agreed action and a date
RC9 Sign it and hand it onthe person accountable for the process, by namea signed result carrying the disagreements as well as the ratings

The step numbering RC1 to RC9 is a working scheme, not a published one. The nine processes, the control count and every figure below belong to one invented bank.

Try it out

Why do the risks have to be listed before any control is rated?

Derivatives Foundation Bootcamp — Fin Maverick

What has to be settled before anybody is asked a single question?

RC1. Fix the scope

The first step is done by the people accountable for the processes being assessed, with the risk function holding the method. Its input is the list of processes the institution runs. Its output is one written paragraph, and that paragraph fixes three things and stops.

The three are these. Which processes are in. Which controls are counted, meaning which ones the institution says it relies on rather than everything anybody does that helps. And over what period, meaning the exact stretch of time the ratings will describe. The scopeThe processes, the controls and the period an assessment covers, settled in writing before any question is asked so that the population cannot be renegotiated once the answers are in. is written down before anybody is asked anything, and it is the only thing standing between a fixed population and one that can be renegotiated later.

At Vindhya Commercial Bank Limited, an invented bank carrying invented figures throughout, the paragraph fixed nine processes, numbered PR1 to PR9: account opening and customer onboarding, lending and disbursal, collateral management and valuation, payments and settlement, trade finance, treasury dealing and settlement, deposit servicing, financial reporting and close, and access management and information security. The paragraph fixed 214 key controls as the population. The period it fixed was the twelve months to month 12, all of it, with no months left out.

Notice what that paragraph does not do. Because this bank never published the split, the paragraph does not say how many of the 214 sit in any one process, and no number for it exists. A runbook step that cannot be completed from the record stops at the record, and the honest output here is a total with no breakdown behind it.

THE SCOPE STATEMENT, WRITTEN BEFORE ANYBODY IS ASKED ANYTHINGOne paragraph. Three things fixed. At one invented bank it read like this.WHICH PROCESSESnine, numbered PR1 to PR9, from account opening to access managementWHICH CONTROLS COUNTthe 214 the bank says it relies on, and nothing elseOVER WHAT PERIODthe twelve months to month 12, the whole of it, no sampling of monthsAND HERE IS WHAT APPEARS INSTEAD WHEN THE SCOPE WAS SETTLED AFTERWARDSNote added at final draft: trade finance has been excluded from thisassessment and will be covered in the next cycle.A sentence that only ever appears once the answers are already in.Every figure here belongs to one invented bank and none is a requirement from any authority.
Three things fixed in one paragraph before a single question is asked: which processes, which controls are counted and over how long, so that the awkward process cannot be quietly dropped later by a note that appears for the first time in a final draft.
Try it out

What three things does the scope paragraph have to fix, and why before rather than after?

Who is in the room, and who is there to disagree?

RC2. Name the participants and the challenger

The second step is done by the risk function, agreed with whoever will sign the result at the end. Its input is the scope paragraph from RC1. Its output is a named list of people, and one of those names is there for a different reason from all the others.

The participants are the people who know what actually happens: the ones who run the process day to day, the ones who supervise it, and the one who will write the ratings down. Then one more name. A challengerSomebody in the room whose job is to disagree, and who does not run the process or hold any rating in it. is somebody whose job in the session is to disagree, who does not run the process and holds no rating inside it. At this invented bank that name was never added.

Every other step produces a document and RC2 produces a person, and that is exactly why RC2 is the step that goes missing. Nobody decides to skip it. RC2 simply leaves nothing behind, so nothing in the finished pack marks its absence, and a pack assembled without a challenger is indistinguishable from a pack assembled with one until somebody measures the same controls a second time.

A two person tailoring shop makes the difficulty plain. One of them cuts and the other stitches, and asked whether the measurements get checked before cutting, both will say yes, and both will be describing the same shared habit rather than checking each other. The moment a third person walks in and asks to see the last ten jobs, the question changes from what usually happens to what happened. The third person is not cleverer than the two. The third person simply has nothing riding on the answer.

WHO IS IN THE ROOM, AND WHO IS THERE TO DISAGREEFour seats produce a document. The fifth produces nothing, which is why it goes missing.THE WORKSHOPRUNS THE PROCESSknows what happens at 4pmand is rated on itseat 1SUPERVISES ITsigns the ratings offand is rated on itseat 2RECORDS ITwrites the ratings downand reports the totalseat 3SETS THE METHODruns the sessionand holds the recordseat 4CHALLENGES ITthere to disagree, and holds no ratingof any control in the roomSEAT NOT FILLED AT THIS INVENTED BANKTHE FOUR SEATS ABOVE EACH LEAVE SOMETHING BEHIND:a rating, a signature, a record, a method note.THE FIFTH SEAT LEAVES NOTHING BEHIND AT ALL,so nothing in the finished pack marks its absence.
Four of the five seats leave a document behind and the fifth leaves nothing at all, so a pack with no challenger looks exactly like a pack with one, and the absence is the only omission in the whole method that nothing in the finished paperwork records.
Try it out

Of the nine steps, RC2 is the one most often skipped. Why that one?

Risk Management Program Bootcamp — Fin Maverick

How is a risk list built so that it is not just a list of last year?

RC3. List the risks

The third step is done by the participants named in RC2. Its input is the scope paragraph and three separate sources. Its output is a risk list for each process that is in scope.

The first source is the institution's standing list of categories, the one that says what can go wrong anywhere in a bank of this kind. The standing list supplies completeness. The second source is the record of what has actually gone wrong here, meaning the losses booked and the near misses caught. The loss record supplies specificity. The third source is the people in the room, and what they know has nearly gone wrong and reached neither of the first two. Only the third source can put a risk on the list that has not yet cost anybody anything.

The invented bank's record carries thirteen operational risk incidents for the year, numbered I1 to I13, costing Rs 43.8 crore net of recoveries, and five near misses, numbered N1 to N5. Take one pairing the bank itself records. In month 6 the collateral valuation feed went stale for two working days and a data quality check caught it, which is near miss N3. In month 10 the same feed went stale for eleven working days and 340 loans were wrongly marked, which is incident I10, at Rs 1.4 crore net. Both of those are in the second source, and a risk list built from the second source alone would have carried the feed only after month 6 and never before it.

The pairing shows the shape of the problem with the second source, and the shape is not a criticism of the record. A record can only hold what has happened. Everything it contains arrived by costing something or by very nearly costing something. So a risk list assembled only from it is a careful, accurate, well evidenced description of the year that has just finished.

THREE SOURCES FOR THE RISK LIST, AND ONLY ONE OF THEM LOOKS FORWARDBuilt from the middle column alone, the list is a record of last year.SOURCE ONETHE CATEGORIESthe standing list of what cango wrong anywhere in a banksupplies: completenessmisses: anything specific tothis process on this dayCAN IT PRODUCE A RISK THAT HASNOT YET COST ANYBODY ANYTHING?NOSOURCE TWOTHE RECORDED EVENTSthe losses and the near missesthis bank actually bookedsupplies: what has happenedmisses: everything that hasnot happened yetCAN IT PRODUCE A RISK THAT HASNOT YET COST ANYBODY ANYTHING?NOSOURCE THREETHE PEOPLE IN THE ROOMwhat they know has nearly gonewrong and reached neither recordsupplies: what is not writtendown anywhere at allmisses: nothing systematicCAN IT PRODUCE A RISK THAT HASNOT YET COST ANYBODY ANYTHING?YESThe three sources are named in the order they are worked through, and the third is the one a workshop exists for.
Two of the three sources can only describe things that have already gone wrong somewhere, so a list built from them alone cannot contain a single item that has not yet cost anybody anything, and the room is the only place the third kind comes from.
Try it out

A risk list built only from the loss record and the near miss record. What has that produced?

What makes a control a key control, and who decides?

RC4. List the controls and mark the key ones

The fourth step is done by the participants, with the risk function testing the list they produce. Its input is the risk list from RC3. Its output is a control list with a flag against the ones that will actually be rated.

Almost everything in a working process reduces risk a little. Somebody double checks a figure out of habit. A screen happens to sort in an order that makes an error obvious. A colleague notices things. None of that is nothing, and because there is no moment at which it either happened or did not, none of it can be rated. A key controlA control an institution has decided it relies on, as distinct from everything in a process that reduces risk a little. is one the institution has decided it relies on, and the deciding is the step.

Being a key control is a status somebody grants and records, not a property the control has by itself. The list can therefore change without a single thing in the process changing. The participants propose, the risk function tests what has been proposed against the risk list, and whoever will sign accepts the result. At this invented bank that produced 214 key controls across the nine processes PR1 to PR9, and that 214 is the number every later figure in this guide sits on.

WHAT MAKES A CONTROL A KEY CONTROLThe narrowing is a decision somebody makes and records, not a property a control has on its own.EVERYTHING IN THE PROCESS THAT REDUCES RISK AT ALLno count of this exists in the record, and none is stated hereTHE INSTITUTION DECIDES WHICH ONES IT RELIES ONthe people who run the process propose, the method holder tests the listand the accountable owner accepts it214 KEY CONTROLSthe population every later figure sits onThis invented bank locks the total and publishes no split, so no count is given for any one of the nine processes.
The narrowing from everything that helps a little down to the set an institution says it leans on is a decision somebody takes and records, which is why a key control can be added or removed by agreement while the risk it sits against cannot.

How are design and operation rated, and on what evidence?

RC5. Rate the design

The fifth step is done by the participants, one key control at a time. Its input is the control list from RC4. Its output is a design ratingA judgement about whether a control would achieve its objective if it happened every single time. against every key control on it.

The question the step asks is fixed and narrow: would this control achieve what it is there for, if it happened every single time? Nothing about whether it did happen. The material that answers it is the procedure, the system setting, the description of what is supposed to occur. All of that can be read on a quiet afternoon with nobody else in the room.

RC6. Rate the operation against evidence

The sixth step is done by the same participants, holding up something the process itself produced. Its input is the control list, the design ratings, and whatever the period actually threw off. Its output is an operating ratingA judgement about whether a control did in fact happen every time over the period, which needs a different kind of material from a design judgement. for each key control, together with the material each rating rests on.

The RC6 question is a different one: did the control in fact happen every time, across the period fixed back at RC1? The word evidenceSomething that would exist whether or not anybody had asked, as distinct from a description of what normally happens. is doing one specific job in this step, and the job is to insist on something that would exist whether or not anybody had ever asked. A count of the occasions a check did not run, produced by the system that runs it, exists on its own. A description of what normally happens does not; it comes into being because somebody asked for it, and it answers the RC5 question rather than this one.

RC6 is where most sessions run thin, and the reason is practical rather than moral. The material that answers RC5 is easy to bring to a room. The material that answers RC6 has to be pulled out of a system by somebody, in advance, for every control being rated. If nobody did that before the session, the room can still answer RC5 honestly and cannot answer RC6 at all, and what usually happens next is that the RC5 answer gets written into the RC6 box.

TWO RATINGS, TWO QUESTIONS, AND TWO DIFFERENT KINDS OF ANSWERBoth are asked about the same control, one after the other, and they can land differently.RC5 THE DESIGN RATINGTHE QUESTIONwould this control achieve its objectiveif it happened every single time?WHAT ANSWERS ITthe procedure, the system setting,the description of what is meant to happenWOULD THAT ANSWER EXISTIF NOBODY HAD ASKED?NOT NECESSARILYRC6 THE OPERATING RATINGTHE QUESTIONdid it in fact happen every timeover the period in scope?WHAT ANSWERS ITa count of the occasions it did not,thrown off by the process itselfWOULD THAT ANSWER EXISTIF NOBODY HAD ASKED?YES, AND THAT IS THE TESTOnly the right hand answer is something that would exist whether or not anybody had ever asked.That is the whole of what the word evidence is doing in step RC6.
The left hand question is answered by reading what is meant to happen and the right hand one by counting the occasions it did not, and only the second kind of answer is something the process would have thrown off whether or not a workshop was ever held.
Try it out

A control is described in the session as something the team does at the end of every day. Which rating does that description answer, and which does it not?

Debt Capital Markets Bootcamp — Fin Maverick

What is left over, and when is that judged?

RC7. Judge what is left

The seventh step is done by the participants once both ratings exist and never before. Its input is the design ratings from RC5 and the operating ratings from RC6. Its output is a residualWhat remains once the controls and their ratings have been taken into account, which is the third judgement and the one that comes last. judgement for each process in scope.

The step is no larger than that, and its position in the sequence is doing more work than anything inside it. The three judgements an assessment makes, and how they relate to each other, are set out separately under the same subject. The runbook settles only where the third judgement goes, and it goes seventh.

Put RC7 first and the two ratings above it stop being measurements and become supporting material for a conclusion that has already been reached. The mark that reversal leaves is a uniformity that is very easy to spot afterwards: a process carrying a comfortable residual judgement in which every single control also came out effective, with nothing awkward anywhere in it. Real processes are not that tidy. A process with one broken control and a low residual is a much more believable document than a process with none.

Try it out

A process is judged to carry a low residual and every control inside it has come out effective, with nothing awkward anywhere. What does that pattern suggest?

What comes out at the end, and who is it handed to?

RC8. Raise the issues

The eighth step is done by whoever is accountable for each control that did not pass. Its input is every rating from RC5 and RC6 that came out short. Its output is an issue, and an issue here means three things together: a named owner, an agreed action, and a date.

All three or none. A weakness written down with no name against it belongs to nobody. A name with no action is a person carrying a label. An action with no date closes whenever somebody remembers. The step is not finished when the weakness has been described; it is finished when a person, a thing to do and a day are attached to it. Tracking that issue afterwards, and how long it takes to close, is a separate subject under the same material, and RC8 stops at raising it.

RC9. Sign it and hand it on

The ninth step is done by the person accountable for the process, by name. Its input is everything the eight steps above produced. Its output is a signed result, and the result carries two things rather than one.

The first is the answer: the ratings, control by control, the period they cover and the population they sit on. The second is the recorded disagreementA note of where participants in the session rated the same control differently, which is the output most often left out of the finished document., meaning a note of every control on which the people in the room did not land in the same place. A control two participants rated differently is a live question about what actually happens, and a control everybody agreed on is a closed one, so a result recording only the agreed rating has kept the closed questions and thrown away the open ones.

A sign-offThe point at which somebody accountable accepts the result, which is a decision that can be asked about later rather than an administrative step. is a decision and not a formality. A sign-off converts a document that exists into a statement somebody made. Where the signed result goes next, meaning which committee receives it and what an institution does with it after that, sits with the governance material. The runbook says only that the handing on is a step, that it has an output, and that the output is bigger than the ratings.

WHAT A SIGN-OFF CARRIES, AND WHAT IT USUALLY DROPSThe shape of the document, not this bank's record. What was said in any room here is not recorded.SIGN-OFF SHEETRC9the ratings, control by controlthe period covered and the population it sits onthe name and the date of whoever accepts itwhere two participants rated one control differentlywhich ratings rested on description and not evidencewhat the challenger did not acceptTHE THREE EMPTY BOXESA control two people in the roomrated differently is a live questionabout what actually happens.A control everybody agreed on isa closed one.A sheet that records only the agreedrating has kept the closed questionsand thrown away the open ones.The six fields are the shape of the artefact this method asks for, not a count of anything at this bank.
A signature carries the agreed answer and drops the three fields that were harder to fill in, and one of those three is the only record of the questions the room had not settled, which is the part a later reader would most want back.
Try it out

The signed result records the agreed rating for every control and nothing else. What has been lost?

What did this invented bank's assessment actually produce?

Run end to end, the nine steps at Vindhya Commercial Bank Limited produced one rated list. Of the 214 key controls in scope, 196 came out effective. As a rate that is 91.6 per cent, and as a body of work it is eighteen named things somebody has to fix.

Some time later the same 214 controls were measured independently, and that measurement reached 172. On the same population that is 80.4 per cent. Put the two on the same 214 and the difference is 11.2 percentage points, which is exactly 24 controls. Both figures have to sit on the full population to be compared at all, and the reason a different pairing of these numbers is wrong, along with the whole account of why the business's answer runs high, is covered separately. The like for like reading is taken as settled here.

Hold on to what 24 is and what it is not. The 24 is a measured distance between two finished exercises: what one described and what the other found, on the same controls, in the same period. The 24 is not a price anybody paid, and because the method was only run once, nothing in this bank's record measures what would have happened if it had been run differently.

What does running the steps out of order actually look like?

Five ways the sequence breaks, and the mark each one leaves

Every reversal in this method leaves a signature in the finished document, and once the five signatures are known the order can be read off a pack nobody has seen before.

Rating before listing, meaning RC5 or RC6 run before RC3. The mark is a risk list in which every single risk has a control against it and nothing is left uncovered. Writing the controls down first and working the risks backwards out of them produces exactly that mark. A list built the right way round contains items nobody has a control for, and those items are the most useful thing on it.

Residual before operation, meaning RC7 before RC6. The mark is uniformity: processes carrying a comfortable residual in which every control also came out effective. Ratings taken after a conclusion tend to agree with it.

Scope after the fact, meaning RC1 settled once the answers are already in. The mark is a scope note that appears for the first time in a final draft, explaining why one process has been left for the next cycle. A scope fixed at the start reads like a definition; a scope fixed at the end reads like an explanation.

RC2 skipped, meaning no challenger named. The skipped step leaves no mark at all, and the missing mark is the whole problem. Nothing in the pack is missing, nothing looks odd, and the only way to see it is to measure the same controls a second time and find out how far apart the two answers are. At this invented bank that distance was 24 controls and 11.2 percentage points.

RC9 done as a signature, meaning the result handed on with the agreed ratings and nothing else. The mark is a document that looks unanimous. Sessions are not unanimous. A pack with no disagreement recorded anywhere in it either had none, which is unlikely across 214 controls, or had some and did not keep them.

Breaking Into Quants Bootcamp — Fin Maverick Hypothesis Testing — free micro-course from Fin Maverick

How much independent challenge is the right amount?

RC2 is the step with no output document, so the honest way to ask what it is worth is to put a dial on it and turn it. Call the dial q: the share of the 196 ratings the business called effective that a challenger reviews before the result is signed. At this invented bank q was nil.

Turning the dial at all requires an assumption, and the assumption is nowhere in the record. One such assumption is that challenge lands on wrong ratings at the same rate the independent measurement later did. On that assumption the ratings withdrawn are 24 times q, settled to whole controls because a rating cannot be part withdrawn, and what stands is 196 less that number, out of 214 throughout. The independent result is held still at 172.

q, per cent challengedRatings reviewedRatings withdrawnRatings standingReported, per centGap, points
00019691.611.2
2549619088.88.4
50981218486.05.6
751471817883.22.8
1001962417280.40.0

Every figure belongs to one invented bank. The left hand row is what happened; the other four evaluate one assumption at four settings, and none of them is a measurement.

Challenge over a quarter of the ratings recovers 6 of the 24 controls of distance, over a half recovers 12, over three quarters recovers 18, and only complete challenge recovers all 24. The last of those four settings matters more than it looks. The whole 24 arrives at exactly one setting of the dial, and it is the setting this guide refuses.

TWENTY FOUR CONTROLS OF DISTANCE, AND FIVE STOPS ALONG ITThe distance is measured. How much of it any real challenge recovers is an assumption, and it is the reader's own.196 RATED EFFECTIVEwhat the business stood behind172 FOUND EFFECTIVEwhat an independent measurement reachedTHE DISTANCE: 24 CONTROLS, BEING 11.2 PERCENTAGE POINTSTHE STOP THIS GUIDE REFUSESq = 00 recovered196 stand91.6 per centq = 256 recovered190 stand88.8 per centq = 5012 recovered184 stand86.0 per centq = 7518 recovered178 stand83.2 per centq = 10024 recovered172 stand80.4 per centThis invented bank challenged none of its ratings before sign-off, so it sits at the left hand stop.Nothing in this guide measures what a challenger would have found, because no challenge was run.
The span is measured and the stops along it are not: the record fixes both ends because both exercises were completed, while every position in between rests on an assumption about how often a challenger would land on a rating that was wrong.

Look at the far right of that picture and say what is actually happening there. Every one of the 196 ratings has been reviewed by somebody who did not make it. A full review is no longer a challenge to a self assessment. A full review is a second measurement of the same controls by somebody independent, and that is precisely what the independent measurement already was. The gap closes because one of the two exercises has stopped existing.

Which leaves the trade in plain view. The value of the process is that the people who run the work describe and rate it, because nobody else can describe it at all. The cost of the process is that the people who run the work describe and rate it. RC2 is where an institution picks its position between those two sentences, and the far end of the dial is not the answer to the problem. The far end solves the problem by removing the process that had it.

Try it out

Before the control below is touched. A challenger reviews half the effective ratings before sign-off. What does the reported figure become, and how much of the 24 controls of distance has that recovered?

Play with it

Turn the challenge dial and watch the reported figure walk down to meet the other one

One control: q, the share of the 196 ratings this business called effective that a challenger reviews before sign-off, from nil to all of them. Ratings withdrawn are 24 times q, settled to whole controls, and the independent result is held at 172 of 214, being 80.4 per cent, throughout. The solved points are these. At q of nil, no ratings are reviewed, none is withdrawn, 196 stand, the bank reports 91.6 per cent and the gap is 11.2 percentage points, and that is what this invented bank actually did. At q of 25 per cent, 49 reviewed, 6 withdrawn, 190 stand, 88.8 per cent, gap 8.4 points. At q of 50 per cent, 98 reviewed, 12 withdrawn, 184 stand, 86.0 per cent, gap 5.6 points. At q of 75 per cent, 147 reviewed, 18 withdrawn, 178 stand, 83.2 per cent, gap 2.8 points. At q of 100 per cent, all 196 reviewed, 24 withdrawn, 172 stand, 80.4 per cent and no gap at all. The setting at 100 per cent is a warning and not a target: at complete challenge the assessment has become a second testing programme and has stopped being a self assessment. The control starts at q of nil, reproducing this bank exactly.

NIL, WHAT THIS BANK DIDq = 0 PER CENT CHALLENGEDALL OF THEM, AND THE WARNING
80848892REPORTED EFFECTIVENESS, PER CENTINDEPENDENT MEASUREMENT HELD AT 172 OF 214, 80.4 PER CENTWHAT THIS INVENTED BANK DIDno challenge before sign-off, 196 of 214 standingAND HERE THE GAP CLOSESbecause every rating has been challenged, which isa second testing programme rather than a self assessment0255075100SHARE OF THE 196 EFFECTIVE RATINGS CHALLENGED BEFORE SIGN-OFF, PER CENTCONTROLS THE CHALLENGE HAS WITHDRAWN, OUT OF THE 24 OF DISTANCE0 of the 24 withdrawn, and 196 of the 214 still standingAT THIS SETTING THE ASSESSMENT HAS STOPPED BEING A SELF ASSESSMENT
Ratings withdrawn
0
Reported effectiveness
91.6%
Gap, percentage points
11.2

With nil per cent of its ratings challenged before sign-off, this bank reports 91.6 per cent and the gap against the independent 80.4 per cent stands at 11.2 percentage points.

Educational illustration. Challenge is assumed to find wrong ratings at the same rate the independent measurement did, and the assumption is not a finding: a challenge aimed at the processes carrying the year's incidents would find more, and one aimed where the business is already confident would find fewer. The independent result is held at 172 of 214 throughout, and ratings withdrawn are settled to whole controls, on which basis all five solved points above reproduce exactly. Every figure belongs to one invented bank and none of it is a requirement from any authority. Vindhya Commercial Bank ran no challenge before sign-off, so no setting of this control other than nil is a measurement of anything.

Try it out

At full challenge the reported figure and the independent one are the same. Is that the setting to aim for?

Hypothesis Testing teaches you to run a test, say what it can and cannot support, and recognise a manufactured result.

A finished assessment has just been handed over. What gets read first?

Most people meet this process from the other end. A pack lands on the desk, a hundred printed sides of ratings for a process somebody else runs, with a question attached about whether it can be relied on. The workshop cannot be re-run. Checking whether the nine steps happened in order can still be done, and the pack will show that to anyone who knows where to look.

Read the scope paragraph first, and read it for its date rather than its content. A scope written before the sessions is a definition of the population. A scope written after them is an account of what got left out, and it reads differently: it explains rather than states. Then check whether it names a population at all. A pack that reports a percentage and never says what it is a percentage of has hidden the only number that turns a rate back into a list of work.

Then look for a name against the challenger role, and if there is none, assume the whole distance is still there. The challenger name is the single fastest read in the pack. Nothing else in a set of ratings gives as much for as little effort. Asking for that name is the same move a household makes when somebody says the accounts are fine and one person asks to see the bank statement: the request does not change the fact, it changes the ground the fact is resting on.

After that, three quick tests. Does any control anywhere carry a recorded disagreement? A pack with none across a population this size has either had an unusually quiet year or has dropped the field. Does every issue raised carry all three of an owner, an action and a date? A count of issues with only two of the three is a count of intentions. And does any risk on the list have no control against it? If not one does, RC3 and RC4 probably ran in the wrong order, and the risk list in hand was assembled out of the control list.

India

Who requires any of this, and where is that written down?

The method itself is not bound to any country. Fixing a scope, naming a challenger, listing before rating and rating operation separately from design work the same way anywhere. The difference is who requires an institution to do it, of whom, how often and in what form, and those bodies are named below.

The operational risk framework this process sits inside originates with the Basel Committee on Banking Supervision at the Bank for International Settlements, bis.org. The Committee is a standard setting body and not an Indian supervisor. Naming only the global standard is the confident and common error here, because what actually binds a bank in India is what the Reserve Bank of India requires, published at rbi.org.in, and that is where a reader is sent for the text on operational risk management and internal control. Where the institution is a company rather than a bank, the duty around internal financial controls sits in the Companies Act, whose text, applicability and form of reporting come from the Ministry of Corporate Affairs at mca.gov.in, with the assurance standards and guidance from the Institute of Chartered Accountants of India at icai.org.

Coverage rules, frequency, rating scales, rating bands, thresholds, requirements and effective dates are set inside an institution and by whoever supervises it, and the step numbering RC1 to RC9 is a working scheme rather than anybody's published method.

The definition of a risk and control self assessment, why what it produces runs kinder than an independent measurement, and the trap in comparing two figures that sit on different populations, are all covered separately and are used here as understood. Control design and control testing as techniques, the comparison between a self assessment and an independent measurement as a subject in its own right, the map of who assures what, the structure of an audit finding, the scale a deficiency is rated on and how remediation runs, all belong to the material on financial controls and assurance, which comes later and checks what this method designs: the runbook stops at RC9, handing the result on, and what happens to the result afterwards is covered separately. Issue tracking and how long a weakness stays open is a separate subject under the same material, and RC8 stops at raising one. The standing list of risk categories and the register behind it belong to the foundations material and are named at RC3 as a source. Which committee receives the signed result belongs to the governance material.

Sources

SourceDocumentSite
Bank for International SettlementsThe Basel Committee on Banking Supervision publications setting out the operational risk framework this process sits insidebis.org
Reserve Bank of IndiaWhat an Indian bank is actually required to do about operational risk management and internal controlrbi.org.in
Ministry of Corporate AffairsThe Companies Act duty on internal financial controls, its applicability and the form of the reportmca.gov.in
Institute of Chartered Accountants of IndiaThe assurance standards and guidance behind reporting on internal financial controlsicai.org

Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.