Risk Assessment Templates
Six editable Excel templates for the risk assessments regulators expect to see documented at community banks and credit unions. Free, no account, no registration, direct download. Right sized for small and mid size institutions and built from real exam experience, so your time goes into your institution's specifics instead of a blank page.
What is inside each file
Every workbook is built the same way, so once you have worked through one the rest are familiar. Each is a single Excel file with two tabs.
Tab 1: Start Here
The nine step how-to, the scoring benchmarks, and a placeholder glossary listing every bracketed field in that workbook so you can find and replace them in one pass.
Tab 2: The assessment
The grid itself. Threat areas grouped by category, regulatory citations, five scoring columns, controls, remediation, and an overall inherent risk score that calculates automatically.
The benchmarks are the part worth reading. Each of the five scoring dimensions has defined 1, 2, and 3 thresholds, so two people scoring the same risk land on the same number. Financial impact is anchored to a percentage of net worth rather than fixed dollar amounts, which means the scale works whether you are a $30 million shop or a $2 billion one. Control effectiveness and residual risk are defined the same way, and both use dropdowns with colour coding driven by the cell value.
Placeholder names are shared across all six workbooks, so an institution using several of them keeps one consistent audit trail. [Online Banking Vendor] means the same thing in the Fraud assessment as it does in the Online Banking one.
Why use these
A defensible starting point
An assessment in progress beats no documentation. These give you a structured foundation with the citations already attached, before your next exam.
Structure, not a blank page
Pre-built with the risk areas and categories examiners look for, so your effort goes into your controls and your ratings rather than into deciding what belongs in the document.
Built for community institutions
Not enterprise templates padded with complexity you do not need, and not so thin they fail to show diligence. The scoring scales to your size rather than assuming it.
Consistent scoring
Defined thresholds for every rating, so the numbers hold up when an examiner asks why a risk was scored the way it was, and when a different person scores it next year.
How to use them
The six assessments
Fraud Risk Assessment
The largest of the six. External fraud covering account takeover, check and card fraud, wire and business email compromise, and ransomware; internal fraud; vendor and third party fraud; and fraud governance and response. Includes synthetic identity fraud and elder financial exploitation.
DownloadOnline and Mobile Banking Risk Assessment
System and vendor security, member authentication including MFA coverage and credential compromise, monitoring and incident response, member awareness, and administration and system change risk. Covers P2P payment risk and credential stuffing.
DownloadSocial Media Risk Assessment
Content and compliance risk, account security and access, social engineering exposure against both staff and members, and operational oversight. Includes an AI generated content risk area for institutions using AI tools to draft posts.
DownloadFair Lending Risk Assessment
Underwriting consistency, indirect lending dealer pricing discretion, marketing and outreach including redlining exposure, HMDA and data integrity, adverse action and appraisal bias, and complaint oversight. Built around ECOA, Regulation B and the Fair Housing Act.
DownloadExecutive Order and Non-Work-Authorized Borrower Lending
Credit and underwriting risk, fair lending exposure including national origin proxy risk, BSA/AML and member identification, and collateral and regulatory volatility risk, with decision triggers for when to reassess.
Guidance in this area is still moving. The citations in this file reflect a point in time. Confirm current requirements before you rely on it.
DownloadDDoS Risk Assessment
Denial of service against online banking, your informational website, and corporate internet connectivity, plus the account takeover risk that often runs alongside a DDoS event as a diversion. Mapped to FFIEC Cybersecurity guidance and NCUA 748 Appendix B.
DownloadImportant legal & exam disclaimers
These templates are provided free of charge, as-is, with no warranty and no support. They are a starting point, not a finished assessment, and they do not constitute legal, regulatory, or compliance advice.
No guarantee of regulatory acceptance
Expectations differ by charter, regulator, examiner, asset size, and geography, and may be supplemented by state law. No guarantee of regulatory acceptance, examiner approval, or legal sufficiency is expressed or implied.
Customization is required for compliance
The sample ratings, controls, and remediation steps in each file describe a hypothetical institution. They are not findings about yours and not recommendations for it. Designed as a flexible framework, you must review and rewrite every row to match what your institution actually does to ensure a successful exam.
Counsel review recommended
Review by qualified counsel or a compliance professional is strongly recommended before you rely on a completed assessment. Full terms are on the Terms of Use page and in each download.
Free to use, adapt, and share. Use these inside your institution, adopt your customized versions as your own, give them to your examiners and auditors, and pass a copy to a peer institution if it would help them. What you may not do is sell them or repackage them into something you sell. The full Terms of Use are short and are included in every download.
No support comes with these. No consulting, no customization, and no review of your completed assessment. If you find an error or a broken file, info@mycurisk.com will read it, though no response time is promised.
If one of these saved your institution a weekend, a voluntary contribution is welcome and entirely optional. Nothing is withheld without it.

