Risk Management Lifecycle

The risk management lifecycle is the loop every framework describes in slightly different words: identify, assess, treat, monitor, report, and then start again because the exposure has already changed. ISO 31000 and NIST CSF 2.0 disagree on vocabulary and emphasis, not on shape.

The stage most organisations get wrong is the last one. Identification and assessment attract attention and budget; monitoring quietly decays until the register describes a business that no longer exists. A lifecycle that runs once a year during audit season is a document, not a process.

This section walks the stages in general terms and then in specific contexts, including IT and cyber risk under NIST CSF 2.0, financial crime, the spiral SDLC model, and security risk management. It links to risk assessment for the analytical core of the loop, key risk indicators for the monitoring stage that usually fails first, and enterprise risk management for the governance that decides who owns each stage.

Receive the latest articles in your inbox