Old but gold? Mastering the RCSA despite Covid-19

Jonas Hampl and Johanna Sax





Introduction to Part I: The origins of non-financial risk management


The complete history of operational risk regulation (abridged)


Financial institutions and non-financial risk: Learning from the corporate approach


The painful financial side of NFR


“Risk management is about managing risk” and “It’s all about people”: Psychology might be more important than models


The confusion of Babel: What’s in the name NFR – taxonomy

Introduction to Part II: Governance of non-financial risk management


“It’s the culture, stupid”: Risk culture as the key building block of NFR management – and why some banks have come through the Covid-19 pandemic better than others


Do you know who is who? Three lines of defence in the context of NFR


Herding cats? NFR divisions as truly diverse units


“Just do it!”: Partially self-organising governance structures for NFR frameworks

Introduction to Part III: Tools and instruments for non-financial risk management


A risk by any other name: Identification, classification and agendas


Old but gold? Mastering the RCSA despite Covid-19


Biases in scenario analyses and how to mitigate them


When scenarios are not severe enough: Stress testing for non-financial risk


Ending NFR in NFR: From Excel sheets to professional IT systems for NFR management


Breaking up with risk management: Using the power of controls for good not the prevention of evil

Introduction to Part IV: Focus areas of non-financial risk management


It won’t be over after Covid-19: Pandemics and operational resilience


Dealing with IT complexity and innovation: Delivering business resilience and customer outcomes


Protecting the new gold: Information security


Conduct risk and the impact of Covid-19


From lawsuits to models: Compliance risk and financial crime


Others are doing it cheaper: But can they really? Opportunities and risks in outsourcing


Managing reputation and stakeholders

Introduction to Part V: The future of non-financial risk management


ESG risk as a new (and very important) trigger for NFR


Looking into the crystal ball: What will NFR management look like in 2030?


This time will be different: An alternative future of NFR management


Right time, right place: The drive for change in operational and non-financial risk

“Risks? We don’t have any risks!” is a response probably every risk professional hears occasionally; in particular, while explaining that a risk and control self-assessment (RCSA) is imminent. Despite involving a certain degree of irony, this statement often marks the beginning of a rather tedious exercise for the risk professional with a counterpart that is profoundly uninspired to think about the risks of our daily work.

The reluctance to fully accept an exposure to risks is not uncommon. In fact, powerful cognitive forces, known to science for centuries, are at play. For instance, people tend to overestimate their control over uncertain events. This misjudgement is called “illusion of control” and is maybe best exemplified by the belief of study subjects to have higher chances of winning the lottery if they pick the numbers themselves (Langer, 1975). In addition, people tend to overestimate the probability of positive life events happening to them while underestimating the likelihood of falling victim to negative ones, which is known as optimism bias. For instance, we find it disproportionately likely that our children will turn out exceptionally gifted and will somehow be

Sorry, our subscription options are not loading right now

Please try again later. Get in touch with our customer services team if this issue persists.

New to Risk.net? View our subscription options

Want to know what’s included in our free membership? Click here

You need to sign in to use this feature. If you don’t have a Risk.net account, please register for a trial.

Sign in
You are currently on corporate access.

To use this feature you will need an individual account. If you have one already please sign in.

Sign in.

Alternatively you can request an individual account here