Concept and mechanism
A risk and control self-assessment, often called RCSA, should explain how its conclusion was reached. Inherent risk describes exposure before controls are considered; residual risk considers the effect of relevant controls. Effectiveness is not demonstrated by document count. A dual-approval procedure may be well designed yet fail in practice if one person controls both accounts. Reviewing design, coverage, and observed operation distinguishes these situations. A sample or record should suit the control objective without presenting limited checking as complete assurance. When evidence is missing, record the gap and uncertainty rather than inventing a favorable result.
Guided application
Assessment depends on assumptions, horizon, and context. If volume will double, six months of history does not justify automatically retaining the previous rating. It also does not justify doubling a score without understanding the mechanism. NIST SP 800-30 Revision 1 explains limitations of qualitative and quantitative scales: a number may summarize judgment without representing euros of expected loss. Two equally scored risks can require different responses. Use impact examples, ranges where appropriate, and clear prioritization rules. Combining prevention, detection, and response supports assessment of what happens when a control fails. Duplicate blocking and later reconciliation serve complementary purposes.
Example: two accounts approve the same change but belong to one person. The control needs effective independence and residual assessment should reflect the gap.
Common pitfalls
Procedure treated as execution; score treated as euros; missing data treated as low risk; two controls treated as zero risk.
Related topics: Scope, governance, and accountability · Events, near misses, and response · Indicators, reporting, and acceptance
Explain exposure, evidence, assumptions, and conclusion limits.
Reference: Guide for Conducting Risk Assessments · DR operational risk professional assessment2026.10