Risk Management Framework — Systematic approach to identifying, assessing, and managing business risks through probability-impact assessment and mitigation strategies.

Risk Management Framework: The Cycle, Scoring and Treatment

Standardized by ISO, COSO and NIST COSO 2004; ISO 31000 from 2009 Med-High Complexity

Risk Management Framework is a structured cycle for identifying, assessing, evaluating, treating and monitoring risks, recording each one in a risk register with its probability, impact, owner and chosen response.

Before you start

Is this your framework?

Risk management answers one question, over and over: which of the things that could go wrong will we act on, and which are we carrying on purpose? The second half matters as much as the first. A framework that only lists risks gives you a longer list. One that works gives you decisions, including decisions to accept.

It also assumes the risks can be named. Some uncertainty has no precedent to estimate from. Scoring that on a five-point scale produces a number but no knowledge, and a different tool is needed.

Matching your actual problem to the right framework.
If your real problem is…You probably want
The important uncertainties have no precedent, so probabilities cannot be estimatedScenario Planning — several plausible futures, with no probabilities attached
Compare Risk Management and Scenario Planning
We need duration uncertainty on a project schedule, not a risk listPERT — three-point estimates producing a probability for the finish date
Compare Risk Management and PERT
We need to know which activities threaten the delivery dateCritical Path Method — float tells you which delays cost nothing
The exposure is external and we have not mapped what is out therePESTEL Analysis — the environmental sweep that feeds a risk identification session
We need a current internal and external picture, quicklySWOT Analysis — threats among other things, at a lower resolution
The concern is one process breaking rather than a portfolio of risksBusiness Process Management — controls built into how the work runs
We need a repeatable way to identify, score, treat and track what could go wrongRisk Management Framework — you are in the right place

What Is It?

Every organization carries risk whether or not it manages it. A risk management framework is the machinery that makes those exposures explicit: a repeating cycle that surfaces what could go wrong, judges how much it would matter, decides what to do, and keeps the answer current as conditions change.

The working artifact is the risk register — a list in which each risk has a description, an owner, a probability and impact score, a chosen treatment and a review date. The scoring usually runs through a probability-impact matrix, which multiplies the two judgments into a single number and sorts risks into bands.

What the framework produces is not safety. It is a set of deliberate positions. The purpose is not to eliminate risk but to decide which risks to carry, knowingly and with someone accountable, and to spend effort only on the ones where the exposure justifies it. An organization with no accepted risks has either misunderstood the exercise or is not doing anything interesting.

One point of order about the name. Risk Management Framework means several different things, and for some organizations the choice is not open: a US federal contractor must use NIST RMF, and a US public company will normally anchor on COSO. The which standard applies to you section sorts out who is obliged to use what.

Risk work pairs with Scenario Planning where uncertainties have no base rate, and with PESTEL Analysis for finding external exposures in the first place.

A five by five probability-impact matrix with scores from 1 to 25 in every cell, banded low, medium, high and critical according to the score
The band follows the score and nothing else, so the grid is symmetric: swapping probability and impact cannot change a rating. Matrices that color cells by feel rather than by score produce ratings that cannot be defended when someone disagrees

Quick Reference

Complexity
Med-High (6/10)
Time to Establish
4-8 weeks
Data Required
Medium-High
Team Size
3-8
Objectivity
Medium
Learning Curve
2-3 weeks

The method

The cycle, and the four treatments

Five steps that repeat. The third is the one organizations most often skip, and skipping it is what turns a risk process into a list.

The five steps, what each requires, and the test that it was done rather than documented.
StepWhat it requiresThe test
1. IdentifySurface what could go wrong, from people who would know: operations, front line, suppliers, past incidents. Describe each as a cause, an event and a consequence, not as a topic.Would someone outside the room recognize the risk from its wording?
2. AssessScore probability and impact, using defined scales rather than adjectives. Five bands per axis, with each band described in terms someone can apply consistently.Would two people score it the same?
3. EvaluateCompare the scores against what the organization is willing to carry. This is the step most often missing. Without a stated appetite, every risk looks worth treating and effort spreads evenly across all of them.Can you say which scores you will simply accept?
4. TreatChoose one of four responses — avoid, reduce, transfer or accept, each explained below the table — then name an owner and a date. A treatment with no owner is a wish, and a treatment with no date is an intention.Who owns it, and by when?
5. MonitorReview on a fixed cadence, retire risks that have passed, and watch indicators that would tell you a risk is materializing before it does.What has been removed from the register this quarter?

The four treatment options are worth stating precisely, because two of them are routinely confused. Avoid means not doing the thing. Reduce means lowering probability, impact, or both. Transfer moves the financial consequence to somebody else, usually through insurance or a contract clause — it does not move the operational consequence, and your customers will still be affected. Accept means carrying the risk deliberately, which only counts as a treatment if it is written down and someone has agreed to it.

Why scoring is a judgment, not a measurement

A probability-impact score looks quantitative and is not. Both numbers are estimates, and the estimate for probability is usually anchored on what has already happened. That systematically under-rates anything without history, which is precisely the category that causes serious losses. A matrix is excellent at sorting familiar risks and blind to unfamiliar ones.

Scoring is also political. The person best placed to judge a risk usually owns the area it sits in, and rating your own area critical invites scrutiny. Registers therefore drift toward the middle bands. Two cheap correctives: have risks scored by someone who does not own them, and write the probability scale in concrete terms — once a year, once a decade — rather than as likely and unlikely.

Obligation, not preference

Which standard applies to you

The phrase risk management framework covers four quite different things. For many organizations the choice is settled by regulation rather than judgment, so the first question is whether anything is required of you.

What each covers, who it is for, and whether you have a choice about it.
FrameworkStructureWho it is forObligatory?
The generic cycleIdentify, assess, evaluate, treat, monitor, with a register and a matrixProjects, programs and businesses with no external requirementNo. Sufficient for most work, and what the rest of this page describes.
ISO 31000:2018Principles, framework and process. Deliberately general and not prescriptive about controls.Any organization, any sector, wanting a recognized structureNo, and it is guidance rather than a certifiable standard.
COSO ERM
2017 edition
Five components and twenty principles, tying risk to strategy and performanceCorporate governance, boards, financial servicesEffectively, for US public companies under Sarbanes-Oxley reporting.
NIST RMF
SP 800-37 Rev. 2
Seven steps applied to each information system: Prepare, Categorize, Select, Implement, Assess, Authorize, MonitorInformation systems, security and privacyYes for US federal systems, and in practice for federal contractors and anyone pursuing FedRAMP or CMMC.

The practical consequence

These are not interchangeable, and substituting one for another has real costs. A federal contractor that runs a sensible generic risk process instead of NIST RMF will fail an audit, because what is required is not good risk management but a specific seven-step process with defined inputs, outputs and traceability for each system. Conversely, a mid-size manufacturer that adopts COSO ERM because it sounds authoritative has taken on a governance apparatus built for listed companies.

Two further distinctions are worth holding. NIST RMF is not the NIST Cybersecurity Framework: the CSF is voluntary and strategic, the RMF is a mandatory implementation process for federal systems, and organizations often run both. And ISO 31000 is guidance, so nobody can certify you against it — if a supplier claims ISO 31000 certification, that is worth a question.

Core Features

  • A repeating cycle: identify, assess, evaluate, treat, monitor
  • The risk register: description, owner, scores, treatment, review date
  • Probability and impact: two judgments combined into one score
  • Risk appetite: the stated line between treat and accept
  • Four treatments: avoid, reduce, transfer, accept
  • Indicators: measures that move before a risk materializes

Worked example

A mobile money operator, and the risk that was not on the register

An illustrative composite. A mobile money operator in Nairobi, Kenya, running about KES 90 billion in annual transaction value through a network of some 12,000 agents. It had a mature-looking risk framework: a register, quarterly reviews, a scored matrix and a board risk report.

What the review of the risk process found.
Where they lookedWhat they found
The registerOne hundred and eighty open risks. The top ten had barely changed in two years, which had been read as stability. It was more likely a sign that nothing was being re-scored.
The scoresOne hundred and forty of the 180 sat in the medium band. Risks were scored by the managers who owned them, and a critical rating brought attention nobody wanted. The matrix was sorting almost nothing.
The lossThe material loss that year came from agent float fraud through a settlement timing gap. It appeared nowhere on the register, because probability had been judged from history and this had no history.
The appetiteNo stated appetite existed, so nothing was ever formally accepted. Every risk stayed open with a treatment plan, which is why 180 of them had accumulated.
What changedProbability scales rewritten in frequencies rather than adjectives. Scoring moved to a panel that did not own the areas. An appetite statement let 60 risks be formally accepted and closed. Nine were given indicators that would move before a loss.

A register documents the risks you can imagine

The loss that happened was not a failure of the process; it was a property of it. Scoring probability from experience means anything without precedent scores low and drops below the line. That is not fixable by a better matrix, because the matrix is doing exactly what it was designed to do. It needs a different practice alongside — a pre-mortem, or a scenario exercise that assigns no probabilities at all — aimed specifically at the risks with no base rate.

The other finding was structural too. A register with no appetite statement cannot close anything, so it only grows, and a register that only grows eventually stops being read. Being able to accept a risk formally is what keeps the list short enough to matter. Closing 60 risks made the remaining ones visible for the first time in three years.

When to Use

  • The organization carries exposures nobody has written down
  • A regulator, insurer, client or board requires a documented process
  • Projects keep being surprised by things somebody already knew about
  • Decisions about what to protect are being made informally
  • Operations, safety, finance or information security at any scale
  • You need a defensible record of what was known and when

When NOT to Use

  • The important uncertainties have no precedent to estimate from
  • Nobody has authority to accept a risk, so nothing can ever be closed
  • The purpose would be to produce a document for an auditor and nothing else
  • The organization is small enough to hold every exposure in one conversation
  • The specific obligation is NIST RMF or COSO, which the generic cycle will not satisfy

In practice

How risk frameworks go wrong

Almost every failure here produces a register that looks healthier than the organization is.

The recurring failure modes and their remedies.
Failure modeWhat it looks likeWhat to do instead
Everything scores mediumMost of the register in the middle band, because owners score their own areasScore risks with a panel that does not own them, and define scales in frequencies.
No stated appetiteNothing is ever accepted, so the register only grows and eventually goes unreadWrite the appetite down, then formally accept and close everything beneath it.
Novel risks score lowAnything without history rated unlikely, which is the category that causes real lossesRun a separate practice for risks with no base rate. A matrix cannot help there.
Topics instead of risksEntries reading cyber or supply chain, which cannot be scored, owned or treatedWrite cause, event and consequence. If it cannot be scored, it is not yet a risk.
Transfer mistaken for removalInsurance bought and the risk closed, while the operational consequence is unchangedTransfer moves money, not outcomes. Customers still notice the outage.
Treatments without ownersMitigation plans naming a department and no date, so nothing is anybody’s jobOne named person and one date per treatment. Review both on the cadence.

Sourced

Evidence, and how to cite it

There is no single risk management framework, and no single body behind it.

Three formal frameworks share the name and were published separately. COSO issued its enterprise risk management framework in 2004 and revised it in 2017 as Integrating with Strategy and Performance, with five components and twenty principles. ISO published ISO 31000 in 2009, revising it in 2018 into principles, framework and process. NIST published SP 800-37 for federal information systems, whose second revision in 2018 raised the process from six steps to seven by adding Prepare. The generic identify-assess-treat cycle predates all three and belongs to nobody.

ISO 31000:2018 Risk management — Guidelines; COSO (2017) Enterprise Risk Management — Integrating with Strategy and Performance; NIST (2018) SP 800-37 Rev. 2.

A probability-impact score is a judgment wearing the clothes of a measurement.

Both inputs are estimates, and multiplying two estimates produces a number with a false air of precision. The deeper problem is where the probability estimate comes from: people judge likelihood by how readily examples come to mind, so risks with recent precedent score high and risks without any score low. A matrix is therefore reliable for sorting the familiar and structurally unreliable for anything new, which is why serious losses so often turn out to have been absent from the register rather than mis-scored on it.

A long-standing critique in the risk literature; see discussions of scoring limitations accompanying ISO 31000 and in the risk assessment methodology literature.

NIST RMF and the NIST Cybersecurity Framework are different instruments.

The Cybersecurity Framework sets out high-level outcomes, is voluntary, and is generally used for strategic and board-level conversations. The Risk Management Framework in SP 800-37 is a mandatory process for authorizing federal information systems, applied system by system alongside the control catalog in SP 800-53. Many organizations run both, using the CSF to set priorities and the RMF to implement and certify controls. Treating them as alternatives is a common and expensive confusion.

NIST (2018) SP 800-37 Rev. 2; NIST Cybersecurity Framework; NIST SP 800-53 control catalog.

How to cite it.

Cite the specific standard, since the generic cycle has no source. Harvard: International Organization for Standardization (2018) ISO 31000:2018 Risk management — Guidelines. Geneva: ISO.
APA: International Organization for Standardization. (2018). ISO 31000:2018 Risk management — Guidelines.
For NIST, cite National Institute of Standards and Technology (2018) SP 800-37 Rev. 2. For COSO, cite COSO (2017) Enterprise Risk Management.

Key Strengths

  • Makes exposures explicit: written down, owned and dated rather than assumed
  • Forces decisions: including the decision to accept something deliberately
  • Directs effort: scoring concentrates work where exposure justifies it
  • Creates a record: defensible evidence of what was known and when
  • Scales: the same cycle runs on one project or a whole enterprise

Key Weaknesses

  • Blind to the unprecedented: no history means a low probability score
  • False precision: two estimates multiplied still produce an estimate
  • Scoring is political: owners rate their own areas toward the middle
  • Registers grow without appetite: nothing closes, so nothing gets read
  • Compliance capture: the process survives as paperwork after the thinking stops

Sequencing

What to run before and after

A risk cycle needs raw material going in and an owner for what comes out. Neither is part of the framework itself.

Before

Find the exposures worth registering

Identification is only as good as the sweep behind it. Scanning the external environment and the project structure surfaces risks that a workshop of insiders will not think of on its own.

During

Handle the uncertainties a matrix cannot score

Structural uncertainty has no base rate, so scoring it produces a number and no knowledge. Run a method that refuses probabilities for those, and keep the register for the risks with history.

After

Give treatments owners, and put controls into the work

A treatment plan becomes real when a named person owns it and the control lives inside a process rather than in a document. Then track the indicators on the same cadence as everything else.

Common questions

Risk management: quick answers

What is a risk management framework?

A repeatable cycle for handling uncertainty: identify what could go wrong, judge how likely and how damaging each one is, decide which to act on, treat them, and keep watching. The output is a risk register and a set of decisions about which risks the organization is accepting on purpose.

What are the five steps of risk management?

Identify, assess, evaluate, treat and monitor. Identify surfaces what could go wrong. Assess scores probability and impact. Evaluate compares those scores against what the organization is willing to carry. Treat chooses a response. Monitor keeps the register current and watches for triggers. The cycle repeats rather than finishing.

What are the four risk treatment options?

Avoid, reduce, transfer and accept. Avoid means not doing the thing that carries the risk. Reduce means lowering the probability, the impact, or both. Transfer means moving the financial consequence elsewhere, usually by insurance or contract, which does not move the operational consequence. Accept means carrying it deliberately, which only counts if someone has said so in writing.

How does a probability-impact matrix work?

Each risk is scored on how likely it is and how much damage it would do, usually on a scale of one to five. Multiplying the two gives a score from 1 to 25, and bands on that score sort risks into low, medium, high and critical. The matrix is a sorting aid, not a calculation: the scores are judgments, and two people will produce different ones.

Do I need NIST RMF, ISO 31000 or COSO ERM?

It depends on obligation rather than preference. NIST RMF is required for US federal information systems and is effectively required for federal contractors and anyone pursuing FedRAMP or CMMC. COSO ERM is what US public companies subject to Sarbanes-Oxley normally anchor on. ISO 31000 is general guidance for any organization in any sector, and is not certifiable. If none of those apply, the generic cycle is enough.

How many steps are in the NIST risk management framework?

Seven: Prepare, Categorize, Select, Implement, Assess, Authorize and Monitor. The earlier revision of NIST SP 800-37 described six; revision 2 added Prepare at the front. It applies to individual information systems and is used alongside the control catalog in SP 800-53, which is why it is much narrower and much deeper than ISO 31000 or COSO ERM.

What is a risk register?

The list of identified risks with, for each one, a description, an owner, probability and impact scores, the chosen treatment and a review date. It is the working artifact of the whole cycle. Its characteristic failure is growing until nobody reads it, at which point the register documents risk management rather than performing it.

How do I cite a risk management framework?

Cite the specific standard, since there is no single source. Harvard style: International Organization for Standardization (2018) ISO 31000:2018 Risk management - Guidelines. Geneva: ISO. APA style: International Organization for Standardization. (2018). ISO 31000:2018 Risk management - Guidelines. For NIST cite National Institute of Standards and Technology (2018) SP 800-37 Rev. 2. For COSO cite COSO (2017) Enterprise Risk Management - Integrating with Strategy and Performance.

Deep Resources