Continuing our RCSA blog series, we explore how advancements in technology can enhance RCSAs. In this segment, we focus on integrating GRC tools, leveraging automation, incorporating external loss data, and utilising AI to support and improve the RCSA process.
This blog is a three part series. Read the first of the series, Top tips for effective and dynamic RCSA: Process and the third Top tips for making your RCSAs more effective and dynamic: Culture and People.Technology
1. Integrate GRC tools into the RCSA process
Details of a discussion on GRC tool selection, integration and maintenance by the Operational Resilience Working Group can be found here.
2. Leverage automation solutions throughout the RCSA exercise
There are many opportunities for automating RCSAs from automating the entire workflow, to just automating specific stages:
- Data collection, aggregation, and monitoring
- Data reporting e.g. the delivery to the 1LoD
- Generation of action plans
3. Incorporate external loss data into the RCSA exercise
By including external loss data, like that provided by ORX News or the ORX loss databases, into RCSAs, financial institutions can:
- Raise awareness
- Identify additional risks
- Horizon scanning
- Benchmarking purposes
- Stress testing
- Inform operational risk scenarios
- Support operational risk capital calculations
ORX News subscribers have access to an API to integrate external loss event data from the ORX News service into their systems which can support the RCSA process.
4. Explore use cases of Artificial Intelligence (AI)
Some ORX members have started to leverage AI to automate the generation of control descriptions and to ensure their consistency and quality. Running '5 Whys’ exercises could be simplified and sped up by using AI.
AI could also be used to write test plans for controls as part of wider GRC tool integration.
Related resources
For more details and a full panel discussion on this topic, listen to our podcast: Top tips for making your RCSAs more effective and dynamic (process, technology, and people).
Resources for ORX members
- Read our short report on Three key areas to improve your RCSAs published earlier this year. This includes further details on how aligning RCSAs and business strategy can unlock additional value
- Read our blog, Enhancing RCSAs – A guide to three key areas, related to the report above
- Read our blog on the Top discussion points from our recent regional forums, which took place over Q1 2024
- Read the RCSA Practice Benchmark
- Discover more from our Risk Management Working Group and Community For summary notes of the RCSA-focused discussions, see the RMWG webpage
Stay tuned for the upcoming third part of the blog series focusing on culture and people.
Next steps
If you would like to learn more about this blog or get in touch about the Risk Management Working group, please visit the website, or contact Matthew Glinister (matthew.glinister@orx.org) or Natasha Smith-Craig (natasha.smith-craig@orx.org).