rcsa

Generate RCSA reports with risk scores and remediation actions.

2|Updated Mar 6, 2026
One-click install
npx skills add https://github.com/Vaibhavkkm/vkkm-aegis-plugin --skill rcsa
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: rcsa
Source: https://github.com/Vaibhavkkm/vkkm-aegis-plugin/tree/main/skills/rcsa
Command: npx skills add https://github.com/Vaibhavkkm/vkkm-aegis-plugin --skill rcsa

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill automates the generation of structured Risk and Control Self-Assessments (RCSA), a critical tool for identifying, assessing, and controlling operational risks in business processes, particularly within regulated financial institutions.

Core Features & Use Cases

  • Structured Risk Assessment: Guides users through identifying risks, scoring inherent and residual risk, and rating control effectiveness based on industry standards (ISO 31000, Basel II).
  • Control Gap Identification: Automatically flags areas where controls are weak or missing, requiring remediation.
  • Automated Reporting: Generates a comprehensive RCSA report including a summary, prioritized remediation actions, and a risk snapshot.
  • Use Case: A compliance officer needs to conduct an RCSA for the 'Customer Onboarding' process. This Skill will prompt for process details, identify potential risks (people, process, systems, external), help score them, and output a formatted report with actionable insights.

Quick Start

Use the rcsa skill to generate a risk and control self-assessment for the 'Customer Onboarding' process, owned by the 'Compliance' department, with 500 monthly volume and subject to 'KYC/AML' regulations.

Frequently Asked Questions about rcsa

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a Risk and Control Self-Assessment report for operational risk?

To generate a Risk and Control Self-Assessment (RCSA) report, you input process details like department, systems, volume, and regulatory requirements. The system then identifies operational risks and outputs a structured assessment with inherent and residual risk scores.

What is an RCSA report in the context of ISO 31000 and Basel II frameworks?

An RCSA report under ISO 31000 and Basel II is a structured assessment identifying and scoring operational risks across people, process, systems, and external event categories. It rates control effectiveness and outlines prioritized remediation actions for compliance.

How do I identify control gaps and score residual risk in business processes?

You identify control gaps by evaluating inherent risks against existing controls to calculate residual risk scores. This process flags areas with weak or missing controls and generates prioritized remediation actions within the RCSA framework.

Can I use this RCSA process for regulated financial institutions with high transaction volumes?

Yes, you can use this RCSA process for regulated financial institutions by providing specific inputs like monthly transaction volume and regulatory requirements such as KYC/AML. It assesses operational risks and control effectiveness tailored to your process scale.

What input data do I need to conduct an operational risk assessment for customer onboarding?

To conduct an operational risk assessment for customer onboarding, you need the process name, owning department, process description, utilized systems, monthly volume, and applicable regulatory requirements to accurately score inherent and residual risks.

What's the best way to document remediation actions for operational risk management?

The best way to document remediation actions is through an automated RCSA report that prioritizes identified control gaps. It generates a risk snapshot and actionable remediation plan based on ISO 31000 and Basel II operational risk frameworks.