— Risk & Compliance

RCSA questionnaire → risk register

Runs a scored risk and control self-assessment questionnaire and calculates residual risk identically every time, producing a register comparable across teams and quarters.

  • Risk & Compliance
  • Deterministic scoring
  • Traceable reasoning
  • Runs anywhere
Preview methodology

2–3 days → ~5 minutes

For one document, brief or record at a time

No coding required

Input
Your risk taxonomy and control descriptions
Output
A risk register table: inherent score, key controls, residual score, action, owner
Runs in
Skillsize · ChatGPT · Claude · Copilot
Export
SKILL.md · MCP
Time saved
~2–3 days per run

— USE CASES

What people use RCSA questionnaire → risk register for

Quarterly RCSA cycles

Run the same scored questionnaire across business units so residual risk is comparable rather than a matter of local scoring habits.

First-line risk registers

Give process owners a structured self-assessment that outputs a register with owners and actions, not a free-text form.

Audit committee reporting

Produce a register where every inherent and residual score can be traced back to the answers that produced it.

What it works from

  • Your risk taxonomy and control descriptions
  • Likelihood, impact and control-effectiveness scales
  • The process or entity in scope

What you get back

  • A risk register table: inherent score, key controls, residual score, action, owner
  • Deterministic weighted scoring applied identically every run
  • A scored answer trail behind each risk

— HOW IT BEHAVES

How RCSA questionnaire → risk register produces its result

The mechanics behind this specific template — what it reads, what it calculates, and where a human stays in the loop.

Deterministic scoring per risk

Each risk is scored from a fixed scoring form rather than model judgement, which is what makes the risk universe in scope comparable across runs and reviewers.

Composed as work product

Findings on the risk universe in scope are written up as a document that reads like professional output, with each claim tied back to a risk.

Delivered as a working table

The risks land as a clean table you can sort, filter or drop straight into the deliverable.

Why this is expensive by hand

Risk and control self-assessments usually live in a spreadsheet that every assessor scores slightly differently. In practice it shows up as quarterly RCSA cycles: run the same scored questionnaire across business units so residual risk is comparable rather than a matter of local scoring habits. The value sits in the rigour, not the typing — yet the rigour is exactly what gets traded away when there is only 2–3 days of capacity for it.

How this Skill produces it

As a Skill, the work is already sequenced. You bring the evidence, and the run produces a risk register table: inherent score, key controls, residual score, action, owner plus deterministic weighted scoring applied identically every run. The judgement is built in — how items are broken up, what standard they are held to, and where the run stops for a human review. The practical effect: 2–3 days of manual work becomes a ~5 minutes run, held to an identical standard on the tenth engagement as on the first.

Who it's for

  • Internal audit and risk functions
  • Compliance and controls teams
  • Second-line functions reporting to committees
  • Risk consultants running assessments

Run it in Skillsize — or export it anywhere

RCSA questionnaire → risk register exports as a structured SKILL.md file and is MCP-ready, so the same method runs in ChatGPT, Claude, Copilot or your own AI products. Adapt it to your methodology, and the intelligence stays yours — not locked to one vendor.

ChatGPTClaudeCopilotAI Products (MCP)
Risk & Compliance

Data Subject Access Request (DSAR) Engine

Assesses a data subject access request end to end and returns a governed decision on whether to fulfil it, fulfil it in part, refuse it with reasons or extend the deadline, having verified identity, mapped the request to the systems that actually hold the data and held the outcome for a data protection sign-off before anything is disclosed.

Risk & Compliance

Findings consolidation

Fans multiple audit or review reports into individual findings, deduplicates repeats, and sorts them by severity into one consolidated register with sources retained.

Risk & Compliance

Audit evidence mapping

Pairs a full evidence set against every audit assertion or PBC item to produce a coverage matrix, naming the assertions nothing supports and the documents supporting nothing.

Risk & Compliance

Claims Coverage Triage Engine

Reads a submitted claim against the policy wording that governs it and returns a coverage assessment showing whether it appears covered, potentially excluded or in need of specialist review, mapped clause by clause and never issued without a handler's sign-off.

Risk & Compliance

Incident Severity & Response

Assesses a reported incident against your response playbook and policies, assigns the severity band the evidence supports, and returns the matching response plan with the notifications, owners and timelines that band requires.

Risk & Compliance

Privacy / Data-Transfer Approval

Assesses personal-data processing and cross-border transfers against privacy policy and jurisdiction rules, producing a documented approval outcome with conditions, policy evidence and grounds for referral.