Moment A
The program was never really built
A risk function exists on the org chart. The RCSA is a spreadsheet inherited from someone who left. There is no defensible link between the risks named, the controls tested, and the losses actually taken.
Risk & Data Advisory · For Financial Institutions
Most operational risk programs fail the same way: the register is stale, the assessment is an annual ritual nobody acts on, and the reporting cannot survive a regulator's follow-up question. Enderassey builds risk programs that hold up under scrutiny because they were designed by someone who has sat on the receiving end of the examination.
Who calls us
Moment A
A risk function exists on the org chart. The RCSA is a spreadsheet inherited from someone who left. There is no defensible link between the risks named, the controls tested, and the losses actually taken.
Moment B
The finding is already written in your head. You need the risk register, the control documentation, and the governance reporting to say the same thing, and you need it to be true before it is presented.
Moment C
A merger, a platform replacement, or a system migration is moving your risk and control data. Nobody independent is challenging whether it arrives intact.
A short, examiner-led assessment of the risk program you already have. We trace a sample of your risks from the register through the controls, the testing evidence, and the reporting, and we tell you where the chain breaks.
Designed for the executive who already suspects the answer but needs evidence, priorities, and a defensible plan before committing budget or headcount.
A traceability test from risk to control to evidence to reported conclusion. An assessment of your RCSA methodology, risk register, issue management, and KRIs against what an examiner will actually ask for. A prioritized 90-day remediation plan.
If a full program build is warranted, you leave with its scope and its price. If it is not, we say so.
A COSO-aligned operational risk management program, designed and stood up end to end: risk identification, risk and control self-assessment, the risk register, issue and action management, and the governance reporting that carries it to the board.
This is the program that was built once already, at a top-tier annuity carrier, from nothing. Assessment cycle time came down 50% through Lean process redesign, because a risk program nobody can complete on time is a risk program nobody completes.
A risk taxonomy your business actually recognizes. An RCSA methodology with rating scales, challenge criteria, and evidence standards. A working risk register with named owners and live issues. Key risk indicators tied to something that moves. A reporting pack your executives can defend without a translator.
The deliverable is a running cycle, not a framework document. We run the first assessment with your team and hand it over.
Data is where operational risk actually lives now. This engagement establishes what data you depend on, who owns it, where it breaks, and what happens to your controls when it does.
Grounded in data risk management work at MUFG Union Bank, performing independent review and challenge across seven enterprise GRC system conversions through the US Bank acquisition.
A data risk framework mapped to your existing operational risk taxonomy, so it is one program rather than two. Critical data element identification. Data ownership and stewardship assignments that name people, not departments. Quality controls at the points where a failure becomes a loss. An independent review and challenge function that has teeth.
Independent review and challenge through a GRC implementation, migration, or merger. Somebody has to ask whether the risks, controls, and issues that went in are the ones that came out, and it should not be the team being measured on the go-live date.
RSA Archer, IBM OpenPages, and ServiceNow. Practitioner experience, not vendor certification.
Requirements written from the risk program outward rather than the platform inward. Data migration review and reconciliation. Configuration challenge before it is locked. Post-conversion validation that the program still functions as designed.
Conversions are where risk programs quietly die. This is the engagement that notices.
Fractional risk leadership is available on an annual agreement for operations that need the judgment without the headcount. It pairs naturally with the fractional fraud officer engagement.
How we price
Every Enderassey engagement is scoped and priced in writing before work begins. No discovery surprises, no meter running. If the scope changes, the fee conversation happens before the work does.
The principal does the work. No leverage model, no junior staff learning on your engagement.
Next step
Thirty minutes, confidential, no obligation. Describe your program and your exposure, and you will leave with a straight answer about what will hold and what will not.