Risk and Control Self-Assessment
A Risk and Control Self-Assessment (RCSA) is a structured process an organization uses to identify the operational risks it faces and to check whether the controls it has in place are adequate to manage those risks. It is a self-assessment, meaning the people who own and run the business processes assess their own risks and controls rather than relying solely on an external review. The goal is to help the organization understand its risk exposure and decide where controls may need strengthening.
An RCSA is a systematic, typically first-line process for identifying, evaluating, and prioritizing operational risks and the controls intended to mitigate them, and for determining whether existing controls are adequate relative to assessed risk exposure. It emphasizes self-assessment by process or risk owners, who identify inherent risks, evaluate control design and effectiveness, and assess residual risk, generally to support proactive risk identification, mitigation, and prioritization at the operational level. As a risk management methodology it is a tool to detect, assess, and manage risk rather than a guarantee that risks are eliminated; specific structures, scoring approaches, and governance expectations vary by organization and by applicable regulatory or supervisory framework, which should be confirmed against the relevant requirements.
Why it matters
For AML and financial crime compliance programs, the RCSA is a foundational mechanism for translating a firm's stated risk appetite into an operational understanding of where its exposures actually sit. Because it is generally a first-line process, it places responsibility for identifying operational risks and evaluating control adequacy on the people who own and run the business processes themselves, rather than deferring entirely to independent review. This helps surface risks proactively at the point where they originate, and it supports prioritization decisions about where controls may need strengthening. In an AML context, the outputs of an RCSA can inform how limited compliance resources are directed and how residual risk is understood after controls are applied.
The RCSA also serves an important governance function. It provides a documented, systematic record of how an organization identifies its operational risks, evaluates the design and effectiveness of its controls, and assesses residual exposure. That record can support internal escalation, board and senior management oversight, and conversations with auditors and supervisors about the state of the control environment. Because supervisory and regulatory expectations for risk assessment vary by jurisdiction and framework, the specific role an RCSA plays in demonstrating compliance should be confirmed against the applicable requirements.
It is important to be clear about what an RCSA is not. It is a tool to detect, assess, and manage operational risk, not a guarantee that risks have been eliminated or that controls will always operate as intended. Its value depends heavily on the honesty and rigor of the self-assessment, the quality of the scoring approach, and the governance around challenge and validation. A well-executed RCSA can improve an organization's understanding of its risk exposure and control gaps, but it does not by itself prove that a firm is compliant or that no residual risk remains.
Who it's relevant to
Inside RCSA
Common questions
Answers to the questions practitioners most commonly ask about RCSA.