Outsourcing Risk Assessment
Assess an outsourcing arrangement across eleven risk dimensions under CSSF Circular 22/806, points 66–70, with the points 83–87/101 contractual-safeguards check and a reperformance note. A max-driven residual tier feeds straight into the Criticality Assessment's point 20 screen. Browser-only; nothing is stored or sent.
The Outsourcing Risk Assessment rates the risks of an outsourcing arrangement across the dimensions CSSF Circular 22/806 names at points 66–70 — eleven of them — capturing sub-point answers and driving an overall residual tier from the highest individual rating rather than an average. Alongside the risk view it runs the contractual-safeguards check of points 83–87 and 101, recording the status of each safeguard as an input to the risk picture rather than a substitute for the full contract review. The circular names the risks but prescribes no scale, weighting or review cycle, so the 1–4 scale, the max-driven tier and the cycle defaults are flagged throughout as a practitioner overlay — not circular text — with a reperformance note so a reviewer can follow the reasoning. The residual tier is designed to feed straight into the Criticality Assessment's point 20 screen. It runs entirely in the browser — nothing is stored or sent — and exports to Excel, a printable memo and a JSON working file, with values you can paste into your register or the IddiLabs Outsourcing Register.
- Eleven risk dimensions under points 66–70, with lettered sub-point answers
- A max-driven residual tier — the overall rating follows the highest risk, not an average
- The points 83–87 / 101 contractual-safeguards check, recorded as risk inputs
- Overlay rules (scale, tiering, cycles) flagged as practitioner convention, with a reperformance note
- A residual tier that plugs into the Criticality Assessment's point 20 screen
- Excel, printable memo and JSON export — plus a save/resume working file
- Fully browser-based — nothing is stored or sent
CSSF Circular 22/806 requires a risk assessment of outsourcing arrangements and names the risks to consider at points 66–70, but it stops there: no scale, no weighting, no rating rule, no review cycle. Every team invents its own, and the result is assessments that vary by author and are hard to reperform — exactly what internal audit tests under point 52. The mitigating contractual safeguards (points 83–87, 101) usually live in a separate review and never get linked back to the risks they address. This tool gives the assessment a consistent, disclosed structure: eleven dimensions, a max-driven residual tier, the safeguards check folded in as risk inputs, and every overlay rule labelled as practitioner convention rather than circular text. It sits in the middle of the outsourcing tool chain — its residual tier feeds the Criticality Assessment, and it hands off to the Due Diligence and the Contract Clause Gap Checker.
Status
LiveRegulation
CSSF 22/806Format
This tool runs entirely in your browser. Don't take my word for it — open it, switch your device to airplane mode, and keep working. If it still works offline, nothing is being sent anywhere.
You can also inspect what the server sends back. The response headers are public; scan them yourself.
Scan iddi-labs.comNo account, no upload, no server-side storage of your data.