Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Topic Operational Risk

The operational risk program, built one template at a time.

ERMF, RCSA, KRIs, issues management, loss tracking, third-party risk — the operational risk stack practitioners actually use. Aligned with COSO ERM, ISO 31000, FFIEC IT, and FRB SR 21-3.

◆ COSO ERM · ISO 31000 · FFIEC IT · FRB SR 21-3 · Basel

◆ What you'll find here

The core risk program — without the consulting markup.

◆ 01

ERMF, RCSA, KRIs

The three core building blocks of every operational risk program. Inventory the risks, self-assess the controls, monitor the indicators. Mapped to COSO ERM and FRB SR 21-3.

◆ 02

Issues & loss tracking

Track MRAs, audit findings, and operational losses with severity scoring, owners, and remediation timelines. Built for teams that need to show progress to regulators and bank partners.

◆ 03

Third-party & vendor risk

TPRM intake, due diligence, ongoing monitoring, and the evidence regulators expect when a critical vendor goes down. Aligned with FFIEC and OCC third-party guidance.

◆ Operational risk templates

Tools for the operational risk team.

Excel-native templates with editable workbooks and PDF guides. Buy once, tailor to your program, deploy in days.

Template
$79

Enterprise Risk Management Framework (ERMF)

Complete ERM documentation: risk appetite, 3 Lines of Defense, committee charter, and board reporting.

Template
$69

RCSA (Risk & Control Self-Assessment)

141 pre-populated fintech risks with control assessments, questionnaire framework, and testing calendar.

Template
$49

KRI Library (132 Key Risk Indicators)

132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.

Template
$49

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Template
$59

Loss Monitoring & Event Tracking Kit

Basel-aligned operational loss event tracking and root cause analysis for financial services.

Template
$59

Financial Risk Management Kit

Credit risk, liquidity, concentration, and capital adequacy templates built for fintechs.

Template
$79

Contingency Funding Plan — Banks

Examiner-ready contingency funding plan for chartered banks built to the 2023 Interagency Addendum.

Template
$79

Contingency Funding Plan — Fintechs

Contingency funding plan for sponsor-bank fintechs — FBO reconciliation, runway-based triggers, post-Synapse stress scenarios.

Template
$69

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Template
$79

Fintech Customer AUP Kit

Acceptable Use Policy framework for fintech compliance teams evaluating high-risk customers and merchants.

249+

Operational risk articles

10

Templates · Excel + PDF

US

COSO · ISO 31000 · FFIEC · Basel

◆ Latest analysis

From the journal.

Third-Party Risk

OCC's 2026 Third-Party Risk Guidance Rewrite: What Banks Should Change Now

The 2026 third-party risk guidance proposal rewrites vendor tiering and gives community banks leverage with core providers.

· 11 min read

Third-Party Risk

Everest Ransomware Hit Citizens Bank and Frost Bank Through a Vendor Nobody Will Name. Six Class Actions Later, Here's What Your TPRM Program Needs.

In April 2026, the Everest ransomware group claimed 3.65 million records from Citizens Bank and Frost Bank via a shared third-party vendor. Neither bank has named the vendor. Six class actions were filed against the banks. Here is what this means for your TPRM program.

· 12 min read

Compliance Strategy

DORA Is in Active Enforcement and 44% of Financial Institutions Still Have Gaps. Here's What Supervisors Are Finding — and What Your Program Needs to Fix Before They Get to You.

The Digital Operational Resilience Act entered active enforcement in January 2026. Fourteen months in, supervisory reviews are surfacing the same structural gaps at institution after institution: incomplete Registers of Information, empty exit strategy fields, and concentration risk documentation that looks complete but doesn't hold up. Here's what EU-exposed fintechs need to fix before the first wave of formal enforcement actions land in H2 2026.

· 9 min read

Operational Risk

FinCEN Hit UBS With a Record $125 Million 'Willful' BSA Fine — and FINRA Added $20 Million More. What the Double-Barrel Enforcement Action Means for Your AML Program.

FinCEN's $125 million penalty against UBS Financial Services — the largest BSA fine ever imposed on a broker-dealer — combined with FINRA's simultaneous $20 million fine creates a $145 million enforcement landmark. Both actions trace back to the same root cause: UBS knew its transaction monitoring had gaps, promised to fix them after a 2018 settlement, and didn't. Here's what 'reasonably designed' AML monitoring actually requires.

· 10 min read

Operational Risk

FinCEN's Southwest Border GTO Just Expired. Here's What MSBs in Four States Need to Know Now.

FinCEN's expanded Southwest Border Geographic Targeting Order expired September 2, 2026, ending enhanced $1,000 CTR requirements for MSBs in border counties of AZ, CA, NM, and TX. The enforcement operation behind it hasn't stopped. Here's what MSBs should do now and what to expect next.

· 9 min read

Third-Party Risk

NYDFS Said It in October. Examiners Are Checking in 2026. What Your Vendor Program Needs to Reflect the Part 500 Third-Party Guidance.

NYDFS's October 2025 industry letter on third-party cybersecurity risk established that covered entities cannot delegate Part 500 compliance to vendors. With MFA, asset inventory, and annual certification requirements now fully active, examiners are reviewing whether vendor programs actually reflect the guidance — not just acknowledge it. Here's what your TPRM program needs.

· 10 min read

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.