Operational Risk Checklist
Risk Identification and Assessment
Walk through the risk register with operations, trading, advisory, and IT leads. Capture new risks introduced by custodian changes (e.g., Schwab/TDA conversion aftermath), new product approvals, vendor onboardings, and staff turnover. Cross-departmental gaps — wire fraud handoffs between ops and advisors are a perennial example — surface here.
Use the firm's heat-map scale (typically 1-5 on each axis). Inherent risk first, then residual after controls. Anything landing in the red zone needs an owner and a mitigation plan in this cycle.
Pull the standing letter of authorization (SLOA) inventory from the custodian. Verify each SLOA meets the SEC no-action conditions (Form ADV disclosure, third-party authorization on file, written confirmation from custodian) — failing any condition means the firm has custody and owes a surprise exam.
Control Testing and Mitigation
Sample at least 10 outgoing wires and ACH instruction changes from the quarter. Confirm verbal callback to a known number on file before processing. This is the single most common operational loss vector — email-spoofed wire fraud.
Pull the trade error log; confirm same-day reporting and resolution within the firm's 5-day SLA. Verify error account losses are absorbed by the firm, not the client, and that tax/cost-basis adjustments flowed through the custodian correctly.
Spot-audit personal device usage and confirm Smarsh/Global Relay archiving is capturing all approved channels. Texting through MyRepChat or Hearsay Relate must be enforced — the SEC has assessed over $2B in off-channel fines since 2022.
Walk advisors and CSAs through recent attempted-fraud examples — urgency cues, instruction changes from email-only, lookalike domains. Capture attendance for the compliance training log.
Each red-zone risk gets a named owner, target residual rating, and remediation due date. Carry-forward items from prior cycles get explicit re-justification — repeated open findings are an exam citation waiting to happen.
Monitoring and KRI Reporting
Update KRIs the firm tracks: NIGO rate on new accounts, ACATS rejection rate, trade error count and dollar impact, complaint volume, OFAC false-positive rate, fee-billing variance. Flag any KRI breaching its threshold.
Pull principal-review exceptions from ComplySci or MyComplianceOffice — outsized trades, concentration, unsuitable-on-face flags, advertising pre-approval gaps. Confirm each exception was cleared with documented rationale.
Three-way reconciliation: internal billing calculation in Orion/Black Diamond, custodian fee debit, client invoice. Variance over the firm's threshold (typically $25 or 5%) triggers a refund or correction memo.
Send the report to the management committee, CCO, and (if applicable) board risk committee. Include heat map, KRI dashboard, open findings, and incident summary. Archive the distributed PDF in NetDocuments under the books-and-records retention path.
Incident Management
Use the firm's RCA template (5-whys or fishbone). Distinguish process gaps, control failures, and human error. Note whether the same root cause has surfaced in prior cycles — repeat causes warrant escalation to the management committee.
For AML-flagged incidents, the SAR clock is 30 days from detection. For client-data incidents, check Reg S-P safeguards rule and state breach-notice statutes. Document the determination even if the conclusion is no filing required — exam staff will ask.
Every incident closes with a named owner, due date, and verification step. Track to completion in the firm's findings tracker; do not close on commitment alone.
Compliance and Regulatory Sign-Off
Capture SEC risk alerts, FINRA notices, state securities bulletins, and DOL guidance issued this quarter. Note which firm policies need amendment (Reg BI disclosures, ADV brochure, ITPP, AML program).
Spot-check CRM-driven Form CRS delivery at recommendation events, and confirm the annual ADV Part 2 delivery (within 120 days of fiscal year-end) ran clean for any clients onboarded mid-cycle.
Pull the LexisNexis Bridger / World-Check screening report. Verify rescreening fired on every beneficiary add, trustee change, and entity beneficial-owner update — not just at account opening.
Use this template in Manifestly
- Business Continuity Checklist
- KYC Checklist
- Employee Termination Checklist
- Accounts Receivable Checklist
- Employee Performance Review Checklist
- Quarterly Operations and Compliance QA Review
- Quarterly Financial Reporting Checklist
- RIA Acquisition Due Diligence Checklist
- Credit Risk Checklist
- Daily Operations Checklist
- Client Satisfaction Survey Checklist
- Know Your Customer (KYC) Checklist
- Anti-Money Laundering (AML) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- AML / BSA Compliance Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Practice Process Improvement Review
- Internal Audit Checklist
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Month-End Close Checklist
- Disaster Recovery Checklist
- Annual Risk Assessment Checklist
- Advisory Firm Operational Efficiency Review
- Data Security Review Checklist
- Client Risk Profile Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- Client Retention Checklist
- Vendor Management Checklist
- Sales Pipeline Checklist
- Campaign Performance Checklist
- Data Protection Checklist
- Investment Due Diligence Checklist
- Asset Allocation Checklist
- Portfolio Management Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- Advisor and Staff Onboarding Checklist
- Annual Budget Planning Checklist
- Business Continuity Plan Checklist
- Annual Risk Management Review Checklist
- Internal Controls Checklist
- Client Onboarding Checklist
- Client Communication Checklist
- Annual Client Review Checklist
- Market Risk Checklist
- Marketing Strategy Checklist
- Risk Management Checklist
- Regulatory Compliance Checklist
- Quarterly Internal Control Review Checklist
- Sales Tax Reporting Checklist
- Legal Entity Management Checklist
- Employee File Audit Checklist
- Anti-Money Laundering Compliance Checklist
- SOX Compliance Checklist
- GDPR Compliance Review Checklist
- IT Security Audit Checklist
- HR Compliance Checklist
- Payroll Processing Checklist
- Building Code Compliance Checklist
- Employee Records Management Checklist
- Legal Document Storage Checklist
- Security Audit Checklist
- Property Risk Assessment Checklist
- Property Safety Inspection Checklist
- Cybersecurity Protocol Checklist
- Fair Housing Compliance Checklist
- Legal Compliance Checklist for New Properties
- Lease Agreement Checklist
- Software Licensing Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Legal Compliance Checklist
- HIPAA Compliance Checklist
- MLS Listing Review Checklist
- Real Estate License Renewal Checklist
- GDPR Compliance Checklist
- Real Estate Contract Review Checklist
- Fair Housing Compliance Audit
- Listing Agreement Intake Checklist
- ISO/IEC 27001 Compliance Checklist
- HR Compliance Checklist
- Real Estate Ethics & Compliance Review
- Brokerage Trust Account Management Checklist
- Real Estate Professional Development Checklist
- Brokerage Technology Inventory Audit
- Real Estate Website Audit Checklist
- Continuing Education Checklist
- Employee Termination Checklist
- Employee Records File Audit
- Regulatory Compliance Checklist
- Brokerage HR Policy Compliance Checklist
- Employee Handbook Annual Review
- Employee Termination Checklist
- Data Privacy Compliance Checklist
- Risk Management Checklist
- Insurance Compliance Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Claims Auditing Checklist
- Quarterly Industry Standards Compliance Review
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Manufacturing Regulatory Compliance Checklist
- Training Needs Assessment Checklist
- Skills Development Checklist
- Audit Preparation Checklist
- Network Security Checklist
- Employee Offboarding Checklist
- IT Asset Inventory Management Checklist
- Regulatory Reporting Checklist
- Compliance Audit Checklist
- Insurance Program Initiation Checklist
- Insurance Program Launch Project Monitoring Checklist
- Training Materials Checklist
- Quarterly Risk Monitoring Checklist
- System Backup Checklist
- Employee Benefits Checklist
- Insurance Program Launch Execution Checklist
- Insurance Marketing Campaign Checklist
- Email Compliance Checklist
- Law Firm Compliance Checklist
- Anti-Money Laundering Compliance Checklist
- Law Firm Compliance Checklist
- Professional Responsibility Compliance Review
- Data Privacy Compliance Checklist
- Law Firm Risk Management Checklist
- HR Audit Checklist
- HR Compliance Checklist
- Email Deliverability Checklist
- Law Firm Ethics Compliance Review
- Document Retention Policy Checklist
- Employee File Audit Checklist
- Law Firm Risk Management Checklist
- Cloud Security Checklist
- User Access Review Checklist
- IT Regulatory Compliance Review
- Compliance Audit Checklist
- Security Audit Checklist
- Business Continuity Checklist
- Employee Termination Checklist
- Quarterly Operations and Compliance QA Review
- Expense Management Checklist
- Advisor and Employee Onboarding Checklist
- Client Satisfaction Survey Checklist
- Know Your Customer (KYC) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Intellectual Property Management Checklist
- Internal Audit Checklist
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Annual Risk Assessment Checklist
- Data Security Review Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- IT Policy Review Checklist
- Data Protection Checklist
- E-commerce Sales Tax Reporting Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Quarterly Compliance Monitoring Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- PCI DSS Compliance Checklist
- Advisor and Staff Onboarding Checklist
- Cybersecurity Incident Response Checklist
- E-commerce Risk Management Checklist
- CRM Data Entry Checklist
- Business Continuity Plan Checklist
- E-commerce Legal Compliance Checklist
- Vendor Contract Review Checklist
- Annual Risk Management Review Checklist
- Risk Assessment Checklist
- Agency Compliance and Risk Management Checklist
- Annual School Compliance Audit
- School First Aid and Emergency Medication Audit
- Motor Carrier TSA Security Compliance Checklist
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Permit and Licensing Renewal Checklist
- New Hire Paperwork Checklist
- Restaurant Policy Update Checklist
- Restaurant New Hire Checklist
- Annual Attorney Professional Conduct Review
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Restaurant Licensing Renewal Checklist
- Marketing Strategy Checklist
- Department of Transportation (DOT) Audit Checklist
- Retail Policy Update and Compliance Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
