What Is the First Step in the Risk Management Process?

Photo of author
Written By Chris Ekai

The first step in the risk management process is establishing scope, context and criteria: defining what you are assessing, the internal and external conditions that shape it, and the thresholds that separate acceptable exposure from unacceptable. ISO 31000:2018 places this at clause 6.3, ahead of risk identification at 6.4.2. Identification is the second step.

Hawaiian Electric wrote its first wildfire safety plan in 2019. On August 8, 2023, wind-driven flames destroyed Lahaina, killed 102 people, and led the utility and its co-defendants to a $4.037 billion global settlement announced in August 2024, with the company carrying roughly half the bill.

First Step in the Risk Management Process: Key Takeaways
The first step in the risk management process is establishing scope, context and criteria, which ISO 31000:2018 places at clause 6.3, ahead of risk identification at clause 6.4.2.
Four independent standards agree on the sequence: NIST SP 800-39 opens with Frame, COSO ERM 2017 opens with Governance and Culture, and PMI opens with Plan Risk Management.
Hawaiian Electric wrote a wildfire safety plan in 2019, yet its public safety power shutoff criteria did not take effect until July 2024, eleven months after the August 2023 Lahaina fire.
Risk criteria are the decision thresholds that convert a score into an action and an owner. Without them a five-by-five matrix produces colors nobody is accountable for.
The often quoted claim that 40 to 45 percent of businesses never reopen after a disaster has no traceable source study, and practitioners should stop citing it.
Budget two to four weeks for the first step in the risk management process on an enterprise scope. The outputs are a scope statement, a context register, a criteria table and a named decision owner per band.

The hazard had been identified years earlier. What had not been written down were the criteria: the wind speeds, fuel dryness and public safety thresholds that decide when to switch a circuit off. The utility’s Public Safety Power Shutoff program did not take effect until July 1, 2024.

That gap is the argument of this article. Identification is not where risk management starts, and treating it as the opening move is the most common structural error we find in the registers that reach us for a second opinion.

First step in the risk management process: the risk was named in 2019 but the criteria arrived in 2024

Figure 1. The risk was named in 2019. The risk criteria that would have governed a shutoff arrived in 2024. The first step in the risk management process exists to close exactly that gap.

Why the First Step in the Risk Management Process Is Not Identification

Ask ten risk teams where their process begins and most will answer identification. Every major standard says otherwise, and the difference is not academic. It decides whether the register you hand an auditor is defensible or merely long when someone asks why a line item sits there.

Read ISO 31000:2018 in clause order and the sequence is unambiguous. Clause 6.3 covers scope, context and criteria, the first step in the risk management process. Clause 6.4.2 covers risk identification, and it sits inside risk assessment, which the standard treats as the second stage of the process rather than the first.

The reason is practical. Identification without a defined scope produces a list with no boundary, so the team argues about whether a supplier’s supplier belongs on it. Identification without criteria produces scores nobody can act on, because no threshold says which score forces a decision.

We put it to clients this way: a risk register is an answer, and clause 6.3 is where you write the question. Skip the question and you get a document that reads like a brainstorm transcript, which is exactly what the risk management process is meant to replace.

Scope, Context and Criteria, Defined Without the Jargon

The three words in clause 6.3 do different jobs, and teams routinely collapse them into one workshop. Splitting them out is the single change that most improves a register’s quality, because each produces a distinct artifact that the next stage consumes.

Element The question it answers The artifact it produces
Scope (6.3.2) What exactly are we assessing, over what time horizon, and what is deliberately excluded? A one-page scope statement naming assets, processes, entities, period and exclusions
External context (6.3.3) What regulatory, market, climate and technology conditions do we not control? A context register of external drivers with a source and a review date
Internal context (6.3.3) What objectives, structures, capabilities and culture shape how we respond? A mapping of objectives to accountable owners and existing control capability
Risk criteria (6.3.4) At what point does exposure stop being tolerable, and who must be told? A criteria table with impact bands, likelihood scales and escalation owners

Scope is the boundary of the exercise. It names the entity, the processes, the assets and the period under assessment, and it records the exclusions explicitly so that a reviewer months later can see what was deliberately left out rather than what was merely forgotten in the room.

Context is the operating environment you inherit rather than choose. External context covers regulation, markets, climate and technology, while internal context covers objectives, structure, capability and culture. Both feed directly into the risk assessment methodology you will apply once identification finally opens.

Criteria are the decision rules, and they are the element teams skip most often under schedule pressure. Criteria state what counts as minor, moderate or severe in money, downtime, injury or reputation, and they name the person who must be told at each band.

Four Standards, One Starting Point

This is not a quirk of one standard. Four frameworks written by different bodies for different audiences converge on the same first step in the risk management process, which is strong evidence that the sequence reflects something real about how risk work succeeds or fails.

ISO 31000, NIST, COSO and PMI vocabulary for the first step in the risk management process

Figure 2. ISO 31000, NIST, COSO and PMI use different vocabulary for the same first step in the risk management process.

Standard What it calls step one Where it sits What step one must produce
ISO 31000:2018 Scope, context and criteria Clause 6.3 Scope statement, context register, risk criteria
NIST SP 800-39 Frame risk Chapter 2, first component A documented risk management strategy
COSO ERM 2017 Governance and culture Component one, principles 1 to 5 Board oversight, operating structures, defined culture
PMI project risk Plan risk management First of the risk processes A risk management plan with categories and definitions
NIST CSF 2.0 Govern Function added in February 2024 Risk management strategy, roles, policy and oversight

NIST SP 800-39 is the clearest of the four. It requires organizations to frame risk before they assess it, and it defines framing as establishing the context for risk-based decisions and producing a risk management strategy that says how the organization will assess, respond and monitor.

The pattern repeats one layer down, inside the assessment itself. NIST SP 800-30 Revision 1 splits a risk assessment into prepare, conduct and maintain, and the preparation step covers purpose, scope, assumptions and constraints before a single threat gets listed.

Governance frameworks land in the same place from a different direction. COSO ERM 2017 opens with governance and culture, and its first five principles cover board oversight, operating structures and desired culture. Our ISO 31000 and COSO ERM comparison maps the overlap in detail.

Even cybersecurity has now followed the same path. When NIST published Cybersecurity Framework 2.0 in February 2024 it added a sixth function, Govern, and placed it at the center of the other five. Running a NIST CSF risk assessment therefore now starts with organizational context and risk strategy.

What Breaks When Teams Open the Register on Day One

Bridging from theory to the symptoms we actually see: the cost of skipping clause 6.3 is rarely a missing risk. It is a register that exists, looks complete, and cannot drive a decision, which is far harder to spot in a board pack than an empty page. The failure modes are consistent enough to list:

  • Scope drift, where the register swells past 300 lines because nobody agreed what sits inside the boundary
  • Color without consequence, where every risk lands amber because there is no criteria table to force a split
  • Orphaned risks, where a line item has a score but no owner because escalation bands were never defined
  • Duplicate registers, where operations, IT and finance each maintain a list built on incompatible impact scales
  • Dead reviews, where the quarterly meeting restates scores because no threshold triggers an action
  • Audit findings, where the tester asks how severe was defined and the answer is a shrug

The AICPA and NC State State of Risk Oversight report has tracked this gap for sixteen editions, and the share of US organizations describing their risk processes as mature has stayed stubbornly low across that run. Volume of risk work is not the constraint.

There is a related discipline problem worth naming. The claim that 40 to 45 percent of businesses never reopen after a disaster, attributed to FEMA in thousands of articles including the earlier version of this page, has no traceable source study.

Researchers who chased the number to its origin found a trail that runs cold in mid-century survey work. If you want defensible US disaster data, the Federal Reserve’s Small Business Credit Survey reports actual losses among firms in FEMA-designated disaster areas.

How to Run the First Step in the Risk Management Process

Here is the sequence we use on engagements, sized for an enterprise scope. Budget two to four weeks. A single department or project can compress it to a few days, but the artifacts stay the same because the next stage consumes all four.

Clause 6.3, the first step in the risk management process, feeds every later stage

Figure 3. Clause 6.3, the first step in the risk management process, feeds every later stage, including monitoring and reporting.

Step Action Who is involved What lands in the file
1 Fix the assessment boundary and the time horizon in writing Process owner and risk lead Signed scope statement with explicit exclusions
2 Map objectives the scope is meant to protect Executive sponsor Objective-to-owner mapping
3 Capture external drivers with named sources Risk lead and subject experts Context register with review dates
4 Capture internal capability and known control gaps Second line and internal audit Capability baseline
5 Draft impact bands in money, time, safety and reputation Finance and risk committee Draft criteria table
6 Calibrate likelihood scales against real frequency data Risk lead and data owner Defined likelihood scale
7 Assign an escalation owner to each band and get sign-off Risk committee or board Approved criteria with named owners

Step one, the first step in the risk management process, is where most of the argument happens, and that is healthy. If two executives disagree about whether contractor safety sits inside the scope, better to settle it now than to discover the gap after an incident when the register is evidence.

Step six deserves more rigour than it usually gets. Likelihood scales built on adjectives like rare or possible collapse under challenge, so anchor each band to a frequency, and our guide to likelihood in risk assessment sets out the calibration methods.

Step seven is the one that converts paperwork into actual governance. An approved criteria table carrying named owners is what lets a risk register escalate on its own logic, instead of waiting for someone senior to happen to notice a red cell in a quarterly pack.

Two related documents usually get drafted alongside this work. A risk management plan records the method and cadence, and on delivery work a project risk management plan does the same job inside a defined lifecycle. Both depend on criteria already existing.

Writing Risk Criteria That Survive an Audit

Risk criteria carry more weight than any other output of the first step in the risk management process, so they deserve their own section. A tester will ask one question about your matrix: who decided that this score means this action, and on what basis. Adjectives will not answer it.

Risk criteria turn a risk score into a named person with a decision to make

Figure 4. Risk criteria, the output of the first step in the risk management process, turn a risk score into a named person with a decision to make.

Good criteria share four properties in our experience. They are quantified wherever quantification is possible, expressed in units the business already reports to its board, tied to a named decision owner, and approved at a level senior enough to bind the whole organization.

Criterion type Weak version we see often Version that holds up
Financial impact High, medium, low Severe is any single loss above $10m or 5 percent of EBITDA
Operational disruption Significant downtime Major is loss of a tier-one process beyond the four-hour recovery time objective
Safety Serious injury Severe is any fatality or permanent disability, reportable within 24 hours
Regulatory Compliance breach Major is any breach carrying enforcement exposure above $1m or licence conditions
Likelihood Possible Possible is expected once every three to ten years on observed frequency

Notice how each strong version borrows a threshold the organization already uses elsewhere. Recovery time objectives come out of business impact analysis work inside the business continuity program, and materiality comes from finance, so the criteria inherit an audit trail instead of inventing one.

Criteria and appetite are related but distinct. Appetite states how much risk the organization is willing to accept in pursuit of objectives, while criteria operationalise that into thresholds. Our risk appetite statement examples and the sector-specific versions show both layers written out.

Keep the scale count honest. A five-by-five grid is the default because it fits a page, but nothing in ISO 31000 requires five bands, and a three-band scale with sharp thresholds beats a five-band scale where three bands mean the same thing in practice.

Where Risk Identification Actually Belongs

None of this diminishes identification. It remains the stage of the risk management process that populates the register, closing with the final step in the risk identification process, and it is far more productive once the boundary and thresholds exist, because the team knows what to look for and how much detail each finding warrants.

With scope fixed, identification techniques can be selected rather than defaulted to. Structured interviews suit regulatory exposure, failure analysis suits process risk, and scenario work suits low-frequency events. Our guide to risk identification tools and techniques matches method to context.

The stages that follow inherit the same benefit. Analysis has a scale, evaluation has thresholds, and treatment has an owner already named, which is the sequence set out in the five steps of the risk management process and the risk management lifecycle stages. Here is how to test whether your first step in the risk management process is finished:

  • Can a newcomer read the scope statement and say what is excluded, without asking anyone?
  • Does every impact band carry a number, a unit and a named escalation owner?
  • Is each likelihood band anchored to an observed or modelled frequency rather than an adjective?
  • Has the criteria table been approved by a body that can bind the organization?
  • Do the thresholds reconcile with finance materiality and recovery time objectives already in use?

If all five answers are yes, open the register. If any answer is no, the gap will surface later as an argument about scoring, and by then the register will have enough lines that reworking the scale is a project of its own. Our complete risk assessment guide covers what comes next.

Frequently Asked Questions About the First Step in the Risk Management Process

What is the first step in the risk management process according to ISO 31000?

Establishing scope, context and criteria is the first step in the risk management process, set out at clause 6.3 of ISO 31000:2018. The standard places it before risk assessment at clause 6.4, which contains identification, analysis and evaluation. Its purpose is to customize the process so assessment and treatment are appropriate to the organization.

Is risk identification the first step in the risk management process?

No. The first step in the risk management process is establishing scope, context and criteria; identification is the second step and the first stage within risk assessment, at ISO 31000 clause 6.4.2. The confusion is widespread because many summaries begin their list at identification, quietly dropping the scoping stage that makes identification meaningful.

What are the five steps that follow the first step in the risk management process?

Identification, analysis, evaluation and treatment, with monitoring and review running alongside recording and reporting throughout. ISO 31000 groups the middle three of those as risk assessment. We set the full sequence out in the risk management lifecycle, together with the outputs each stage is expected to produce.

Who owns the first step in the risk management process?

Scope and context are usually drafted by the risk function with the process owner, but criteria must be approved by a body that can bind the organization, typically a risk committee or the board. Ownership of the first step in the risk management process is therefore shared: the risk function drafts, the board approves. The Three Lines Model published by the IIA sets out the accountability split.

How long should the first step in the risk management process take?

The first step in the risk management process takes two to four weeks for an enterprise scope, and a few days for a single department or project. Most of the elapsed time goes into agreeing impact thresholds with finance and securing sign-off, rather than into drafting the documents themselves.

What documents prove you completed the first step in the risk management process?

Four artifacts: a signed scope statement with explicit exclusions, a context register with sources and review dates, an approved criteria table with escalation owners, and a likelihood scale anchored to frequency. Auditors ask for the criteria table first, so keep its approval date visible.

Does the first step in the risk management process differ by sector?

The sequence holds, but the criteria change. A hospital anchors severity to patient harm, a bank to capital and operational risk loss data, and a manufacturer to downtime and safety. Cybersecurity programs increasingly anchor to disclosure thresholds under the SEC cyber rules.

Where Programs Stall, and How to Unstick Them

Six failure patterns account for most of the stalled first-step work we get asked to rescue. Each of them has a cheap remedy if it is caught before the register grows past a hundred lines, and a painful one once scoring is already underway.

Pitfall Root cause Remedy
Scope written as a topic, not a boundary The workshop opened with a subject line rather than an asset list Rewrite scope to name entities, processes, period and exclusions on one page
Criteria copied from a template Bands lifted from another organization’s materiality Rebuild thresholds from your own finance materiality and recovery time objectives
Likelihood defined with adjectives No frequency data was consulted at calibration Anchor each band to an observed or modelled frequency range
Context captured once and frozen No review date was attached to external drivers Add a review date and owner to every context entry
Criteria approved at the wrong level Sign-off taken from the drafting team Take approval to the risk committee or board and record the date
Identification started in parallel Schedule pressure to show a populated register Pause identification until the criteria table is approved, then score once

The parallel-start pitfall in the last row is the costliest. Scoring a 300-line register against draft criteria means rescoring the whole thing when the criteria change, which is how risk management techniques get blamed for what is really a sequencing failure.

Where an existing register is already built on weak criteria, we do not recommend a full rebuild. Fix the criteria table, then rescore only the lines above the moderate band, since those are the ones where a threshold change alters who has to act.

What Changes Between Now and 2028

Three shifts are already visible in how the first step in the risk management process gets treated across the programs we review, and each pushes in the same direction. Scoping is becoming an evidenced, dated, approved artifact rather than a workshop memory that lives in one person’s notebook.

Regulators keep raising the evidentiary bar. The SEC’s cybersecurity disclosure rules require registrants to judge materiality on a four-business-day clock, which is impossible without pre-agreed thresholds, and that same pressure is now spreading out of cyber into operational and climate reporting.

Governance-first framing is now the default in new standards rather than a bolted-on addition. NIST’s decision to add Govern to the Cybersecurity Framework in 2024 followed the lead COSO set back in 2017, and continuity standards including ISO 22301 already require organizational context before any planning begins.

Expect tooling to catch up next. Risk platforms have long opened on an empty register grid, and the ones worth buying by 2028 will refuse to accept a risk entry until a criteria set exists, the same way accounting systems refuse an unbalanced journal. Build the enterprise risk management framework for that.

If your register is long and your board still asks what any of it means, the problem is upstream of identification. We rebuild the first step in the risk management process, scope, context and criteria, against ISO 31000 clause 6.3 and rescore only what the new thresholds actually move. Getting the first step in the risk management process right is most of the work. Read our services, then get in touch and bring the criteria table you have.