On 2 June 2016, nine soldiers from the 3rd Battalion, 16th Field Artillery Regiment drowned at Fort Hood, Texas, when their light medium tactical vehicle was swept into roughly seven feet of floodwater at a low-water crossing during routine training. Twelve soldiers were aboard that morning. Three of them survived.
The crossing had already been closed that morning. The National Weather Service had issued a flash flood advisory, and Fort Hood range operations had suspended tactical low-water crossings, but the platoon did not know. That gap is what composite risk management existed to prevent.
| Composite Risk Management: Key Takeaways |
| The Army retired the term composite risk management in April 2014, when ATP 5-19 superseded FM 5-19 and renamed the process simply risk management. |
| The process has five steps, not the three or four that older composite risk management articles describe: identify, assess, develop controls, implement, supervise and evaluate. |
| DA Form 7566, the composite risk management worksheet, was rescinded. Units now use DD Form 2977, the Deliberate Risk Assessment Worksheet, dated September 2014. |
| Nine soldiers died at Fort Hood on 2 June 2016 after an LMTV entered a flooded low-water crossing that had already been closed, a documented breakdown in hazard communication. |
| GAO found 3,753 non-combat tactical vehicle accidents and 123 deaths across FY2010 to FY2019, citing supervision lapses and lack of training among the leading causes. |
| CRM is ambiguous: it also means crew resource management in aviation and customer relationship management in software. Check which one a source means. |
If you searched for composite risk management and landed on a tidy four-step definition, that definition is out of date. The US Army stopped using the term more than a decade ago. What replaced it, and why the change happened, matters more than the old label ever did.
What Composite Risk Management Was, and Why the Term Is Obsolete
Composite risk management was the US Army’s name for a five-step process used to identify hazards, judge the risk they carried, and control them before a mission began. The Army introduced the term in FM 5-19 in August 2006, deliberately pairing tactical threats and accidental safety hazards inside a single assessment.
The word composite carried that pairing: combat threats and everyday safety hazards were assessed together rather than tracked in two parallel systems. It was a sound idea that outlived its own name. The label did not survive contact with joint doctrine and the need for one shared vocabulary.

Figure 1. The composite risk management term was renamed in April 2014 and the worksheet rescinded five months later.
Why the Army Retired the Composite Risk Management Label
In April 2014, ATP 5-19 Risk Management superseded FM 5-19 and dropped composite from the name. The Army adopted the plain term risk management to align with joint terminology already in use across the other services, so that a single word meant the same thing everywhere.
The change served interoperability. The method itself was never in question. A joint task force cannot run four differently named hazard processes and still brief risk to one commander in a single language, which is the practical problem the rename solved.
The current edition of ATP 5-19 dates from November 2021, and it sits inside a wider body of safety regulation. AR 385-10 establishes risk management as the Army’s principal risk reduction methodology, while DA PAM 385-30 carries the detailed mishap risk management procedures.
The Five Steps That Replaced the Composite Risk Management Process
Most surviving composite risk management content gets this wrong. Older articles describe three steps, and sometimes four, often within the same page. Army doctrine has specified five steps throughout, and a wrong count usually means a step has been quietly dropped somewhere.

Figure 2. The five-step cycle. Steps 1 and 2 assess; steps 3 to 5 manage and verify.
| Step | Name | What it actually requires |
| 1 | Identify the hazards | List conditions that could cause injury, death, damage, or mission failure, working from the mission variables |
| 2 | Assess the hazards | Apply probability and severity to each hazard to produce a risk level from the standard matrix |
| 3 | Develop controls and make risk decisions | Design controls, then have the right level of command accept or reject the residual risk |
| 4 | Implement controls | Push controls into orders, briefings, rehearsals, and standard operating procedures so they exist in practice |
| 5 | Supervise and evaluate | Check that controls are in place and working, and adjust as conditions change during execution |
Step 3 is the one civilian programs most often skip. Developing a control is not the same as deciding who is authorized to accept the risk that remains, and our guide to the wider risk management process covers that accountability gap in more depth than any worksheet manages to.
How the Composite Risk Management Risk Assessment Matrix Works
The matrix is the part of composite risk management that survived the rename completely unchanged. It pairs a probability estimate against a severity estimate and returns one of four risk levels, giving leaders at every echelon a shared vocabulary for weighing a mission against its cost.

Figure 3. Probability runs A to E, severity runs I to IV. The intersection sets the risk level.
Probability is assessed as frequent when a harmful occurrence is known to happen continuously, regularly, or inevitably given the exposure involved. Severity is rated catastrophic when the expected consequences include death, unacceptable loss or damage, mission failure, or the loss of unit readiness.
Frequent probability against catastrophic severity, written IA, is the first combination assessed as extremely high risk. Civilian teams running a risk matrix template or a risk heat map are applying the same logic under different labels, usually with a five by five grid instead.
The Composite Risk Management Worksheet Was Rescinded Too
Search results still surface DA Form 7566, the Composite Risk Management Worksheet, and dozens of template aggregator sites still host it for download. The form was rescinded years ago. Units across the Department of Defense now use DD Form 2977, the Deliberate Risk Assessment Worksheet, dated September 2014.
This has practical consequences. A soldier or safety officer who downloads DA Form 7566 from a template aggregator is filling in a form their unit cannot accept, and the last edition of that form dates all the way back to April 2005.
Fort Hood 2016: What a Composite Risk Management Failure Looks Like
The Fort Hood investigation remains the clearest case study in why the composite risk management steps exist. Warnings had been issued and the crossing had been closed, yet none of that information reached the vehicle commander in time to change the decision that followed.
Investigators also found the forward support company had no formal driver training program consistent with Army regulations, and none specific to that company’s vehicles or to the particular hazards of Fort Hood itself. Step 4, implementing controls, never happened in any documented form.
Nine soldiers died in an accident that hazard identification had already anticipated. The hazard was known and the control existed on paper in the form of a closed crossing. The step that should have carried that decision to the crew never worked.
What Mishap Data Says About Composite Risk Management’s Successor
Fort Hood was not an isolated failure, and the federal audit record shows why. The Government Accountability Office reviewed Army and Marine Corps tactical vehicle accidents across fiscal years 2010 to 2019, and found exactly the pattern that risk management is designed to interrupt.

Figure 4. GAO-21-361 counted 3,753 non-combat accidents and 123 deaths over ten fiscal years.
GAO named driver inattentiveness, lapses in supervision, and lack of training among the most common causes, and issued nine recommendations to the Department of Defense in response. Every one of those three causes maps directly onto a step in the five-step process.

Figure 5. FY2024 saw the highest Class A aviation mishap rate since 2007. Source: US Army Combat Readiness Center.
Army aviation recorded 17 Class A mishaps in FY2024, a rate of 1.9 per 100,000 flight hours and the highest such rate recorded since 2007, roughly four times the FY2022 figure. The Army went on to lose 98 soldiers and 2 civilian employees to mishaps of all kinds in FY2025, down 2 percent on the previous year.
Three Different Disciplines Abbreviate to CRM, Not Just Composite Risk Management
Part of the confusion around composite risk management comes from the acronym itself. Three unrelated disciplines share the letters CRM, and search engines blend all three into a single set of results for anyone researching the term for the first time.

Figure 6. Three disciplines, one acronym. Only the first is the Army hazard process.
Crew resource management is the aviation human-factors discipline covering communication, workload distribution, and the cockpit authority gradients that let a junior officer challenge a captain. It grew directly out of airline accident investigation, and is now taught across business aviation as well.
Customer relationship management is sales and marketing software with no connection to risk management, despite dominating the search results. When a source says CRM without qualifying it, check which of the three disciplines it belongs to before citing it in a safety document.
Translating Composite Risk Management for Civilian Risk Programs
The Army process maps cleanly onto civilian standards, which is why composite risk management still gets taught well outside the military. The vocabulary changes at every border. The underlying sequence of identify, assess, control, and verify does not change at any of them.
| Army step | ISO 31000 equivalent | COSO ERM equivalent | Workplace safety equivalent |
| Identify the hazards | Risk identification | Identifies risk | Hazard identification |
| Assess the hazards | Risk analysis and evaluation | Assesses and prioritizes risk | Risk assessment |
| Develop controls, decide | Risk treatment | Implements risk responses | Hierarchy of controls |
| Implement controls | Recording and reporting | Deploys the response | Control implementation |
| Supervise and evaluate | Monitoring and review | Reviews and revises | Monitoring and audit |
One difference deserves attention. Army control development ranks options by how much each one removes human decision-making from the failure path, the same principle behind the NIOSH hierarchy of controls, where elimination beats substitution and both beat protective equipment on its own.
If you are building a civilian program from this foundation, ISO 31000 and the COSO ERM framework are the two standards to compare before you commit. Our ISO 31000 versus COSO breakdown sets out where each one fits and which suits a hazard-heavy operation.
Practitioners moving from military to corporate risk work usually find the closest match in operational risk management, where hazard thinking and control design transfer almost directly. The distinction from enterprise risk is the part that takes longer to internalize, because the change is one of scope.
Frequently Asked Questions About Composite Risk Management
Is composite risk management still current Army doctrine?
No. ATP 5-19 superseded FM 5-19 in April 2014 and renamed the process risk management, dropping composite from the title. The current edition dates from November 2021, so any source presenting composite risk management as current Army practice is over a decade out of date.
How many steps does the composite risk management process have?
Five. Identify the hazards, assess the hazards, develop controls and make risk decisions, implement controls, then supervise and evaluate. Articles describing three or four steps have usually collapsed the control development and risk decision step, which is the one that assigns accountability.
What replaced the DA Form 7566 composite risk management worksheet?
DD Form 2977, the Deliberate Risk Assessment Worksheet, dated September 2014, replaced it across the Department of Defense. DA Form 7566 was rescinded and its last edition dates from April 2005, so downloading it from a template site produces a document your unit cannot accept.
Does composite risk management mean the same thing as crew resource management?
No, though both abbreviate to CRM and are often conflated. Composite risk management was the Army’s hazard assessment process, while crew resource management is an aviation human-factors discipline covering communication and authority gradients in the cockpit. The two have entirely separate origins.
What is the composite risk management risk assessment matrix?
It pairs probability, graded frequent through unlikely, against severity, graded catastrophic through negligible. The intersection of the two returns a risk level of low, moderate, high, or extremely high. Frequent probability against catastrophic severity is the first combination rated extremely high.
How does composite risk management compare with ISO 31000?
The sequences align closely. Identify and assess map to ISO 31000 risk identification, analysis, and evaluation, while develop and implement controls map to risk treatment. ISO 31000 adds explicit stakeholder consultation, which Army doctrine handles through the chain of command instead.
Can civilian organizations still use composite risk management?
Yes, and many safety programs do. The five-step structure and the matrix remain sound tools regardless of what the Army calls them, but cite ATP 5-19 rather than the retired composite risk management terminology so readers can find the current source.
Where Composite Risk Management Practice Breaks Down
| Pitfall | Root cause | Remedy |
| Teaching a three or four step process | Copying older composite risk management summaries that dropped a step | Use the five steps in ATP 5-19 and keep the risk decision step separate from control design |
| Using rescinded DA Form 7566 | Template aggregators still rank for the old worksheet | Download DD Form 2977 from the official Washington Headquarters Services forms library |
| Assessment written but never briefed | Step 4 treated as filing rather than communication | Require controls to appear in the operations order and the pre-execution brief, as Fort Hood showed |
| Risk accepted at the wrong level | No mapping of risk level to approving authority | Publish an approval matrix so extremely high risk cannot be signed off locally |
| Controls never re-checked in execution | Step 5 dropped once the mission starts | Assign a named individual to verify controls during execution, not just before it |
The last two are where civilian programs fail most often. A risk appetite statement that names who may accept which level of exposure does the same work as the Army’s approval authority table, and key risk indicators give you the execution-phase check that step 5 demands.
Monitoring earns its keep only when it produces evidence. Teams that build a KRI library and pair it with risk management KPIs convert supervision from an intention into something measurable, which is what measuring risk management performance demands of them in practice.
Applying Composite Risk Management Thinking Beyond the Motor Pool
Hazard-based thinking travels further than most corporate risk functions assume it does. A physical security risk assessment and a workplace safety risk program both run the same identify, assess, control, and verify loop, under different names and different reporting lines.
The same structure underpins hazard identification practice, control self-assessment through RCSA, and project-level work such as risk mitigation in project management, where the sequence is identical. The discipline stays portable even where the doctrine that produced it does not apply.
Where it stops transferring is enterprise scope. An enterprise risk management framework has to handle strategic, financial, and reputational exposure that no hazard worksheet was ever built to capture, which is why the COSO five components exist alongside hazard analysis, not in place of it.
What Practitioners Should Take From Composite Risk Management
Terminology ages faster than method. The Army renamed composite risk management in 2014, rescinded its worksheet months later, and refreshed the governing publication again in 2021. The five steps and the matrix have held their shape throughout all of that churn.
For anyone studying this for a risk management course or building a civilian program, cite the current publication and use the current form. Getting the label right is how you avoid teaching a decade-old process to people who will be assessed against the present one.
The deeper lesson from Fort Hood is that steps 4 and 5 carry most of the weight. Identification and assessment produce a document, but implementation and supervision are what actually put a control between a hazard and the people exposed to it that morning.
Strengthen Your Composite Risk Management Practice With Risk Publishing
Safety leads translating military hazard process into a corporate risk register usually need the bridge built once, properly. Our advisory services map five-step hazard work onto enterprise risk and continuity programs, and you can reach the team to start with a control-design review.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.