How Do You Manage Risk

Photo of author
Written By Chris Ekai

How do you manage risk? Set the scope and appetite first, then identify what threatens your objectives, analyze likelihood and impact, rank the results, treat each priority risk by avoiding, reducing, transferring, or accepting it, and monitor the whole system with indicators. ISO 31000 formalizes this loop; discipline in running it turns a register into protection.

On December 18, 2023, the US Department of Transportation fined Southwest Airlines $140 million for the December 2022 meltdown that canceled 16,700 flights and stranded more than two million travelers. The penalty was thirty times larger than any in the agency’s history.

The storm was the trigger, but the cause sat in a risk register for years. Southwest’s pilots had warned publicly about the aging crew-scheduling software that buckled, and the company logged the meltdown’s cost at roughly $1.2 billion across two quarters. An identified risk, unfunded and untreated, behaves exactly like an unknown one.

How Do You Manage Risk: Key Takeaways
Managing risk is a six-step loop: set scope and appetite, identify, analyze, evaluate, treat, monitor. ISO 31000 and COSO ERM both reduce to this sequence.
Southwest’s December 2022 meltdown canceled 16,700 flights, cost roughly $1.2 billion, and drew a record $140 million DOT penalty; the failed system had been flagged for years.
Only 32 percent of US organizations rate their risk management oversight as mature, and just 30 percent tie risk exposure to capital allocation (AICPA and NC State, 2025).
Every treatment is one of four moves: avoid, reduce, transfer, or accept. Acceptance must be an active, signed decision inside a stated tolerance, never silent inaction.
Wire key risk indicators to named responses with thresholds; treat a repeat near miss as an unscheduled review of the risk it exposed.
Review the register and indicators quarterly, appetite and criteria annually, and everything immediately after a loss event or major change.

That gap between knowing and managing is where most programs fail. We run risk programs for a living, and the honest answer to how you manage risk is a loop, not a document: scope it, score it, treat it, watch it, and pay for the treatments that matter.

What It Takes to Manage Risk Well

Southwest is the extreme case of a universal pattern. Managing risk means running a governed process that converts uncertainty about your objectives into ranked, owned, and funded decisions, and ISO 31000 defines that process as scope, assessment, treatment, and monitoring wrapped in communication. A risk register alone is inventory, and inventory protects nothing.

The scale of the discipline gap is measured annually. The AICPA and NC State’s 2025 State of Risk Oversight report found 61 percent of US executives see rising risk complexity, while only 32 percent rate their own oversight as mature, and just 30 percent connect risk exposure to capital allocation.

How Do You Manage Risk

Figure 1. Complexity is rising in 61 percent of organizations; mature risk management oversight exists in 32 percent.

Risk category Typical sources A metric that tracks it
Strategic Competitive shifts, M&A, product bets Market share and pipeline trend
Operational Processes, people, systems, third parties Incident and near-miss counts
Financial Credit, liquidity, market movements Cash runway, exposure limits
Compliance Regulation, contracts, licensing Findings open past due date
Reputational Service failures, conduct, social media Complaint volume and sentiment

Categories matter only when each carries an owner with budget. We assign every register entry a named executive, a treatment, and a review date, consistent with the IIA’s Three Lines Model; that assignment, more than any framework choice, separates a filing exercise from a working risk management lifecycle.

Why Identified Risks Still Sink Companies

Ownership gaps explain why known risks keep detonating. Southwest’s scheduling system was a documented vulnerability with union warnings on the record, yet the airline deferred the upgrade spending year after year; the eventual bill ran to roughly $1.2 billion plus a $140 million consumer-protection penalty and a brand scar.

How Do You Manage Risk

Figure 2. Ten days in December 2022, priced: the meltdown that funded risk management would have prevented.

The pattern deserves a blunt name: risk appetite theater. Boards approve appetite statements, registers list the exposures, and then funding decisions ignore both; the NC State data shows only 11 percent of organizations get strategic advantage from their ERM process. Appetite means nothing until it prices treatments.

Run this test against your own register before the next renewal cycle, because auditors and insurers increasingly do the same. A risk is listed rather than managed when any of these five signals shows up anywhere in the current record:

  • No named owner, or an owner who left the company two reorganizations ago
  • A treatment described as “monitor” with no indicator or threshold attached
  • No budget line connected to the mitigation
  • The same score carried forward unchanged through three review cycles
  • Union, auditor, or frontline warnings noted in minutes without a logged response

How Do You Manage Risk in Six Steps

The fix is procedural, and it fits in six steps. Our sequence tracks ISO 31000 and COSO ERM and starts where the first step in the risk management process genuinely sits: scoping and criteria, before any risk is named. Each step below produces a record an auditor can test.

Step What you do What goes on file
1 Set scope, objectives at stake, scoring criteria, and appetite by category Signed scope and criteria memo
2 Identify risks through workshops, loss data, and external scans Register entries with causes and consequences
3 Analyze likelihood and impact on anchored scales; model the biggest exposures Scored register with written rationale
4 Evaluate against appetite; rank and flag exposures beyond tolerance Prioritized treatment list
5 Treat: avoid, reduce, transfer, or accept, each with an owner and budget Treatment plans with dates and funding
6 Monitor with indicators, trend reviews, and defined reopening triggers Dashboard and review minutes

 

How Do You Manage Risk

Figure 3. The loop repeats: monitoring findings feed the next scoping pass, per ISO 31000 clause 6.

Steps one and four are the two most organizations skip. Without written criteria, scoring becomes a mood survey; without evaluation against a stated appetite, every risk fights every other risk for attention and the loudest owner wins. The five-step process article walks the assessment core in more depth.

A 5×5 matrix and quantified loss modeling both work when the scales carry written anchors and concrete examples, so two assessors land on the same number. NIST’s risk management guidance and our risk assessment pillar cover the anchoring method; the tool choice is secondary to the anchoring.

Identification deserves one warning of its own. Workshops recycle last year’s list unless you force fresh inputs, so rotate risk identification tools each cycle: loss data one year, external scans and pre-mortems the next, frontline interviews after that. New method, new blind spots caught.

Choosing a Treatment: The Four Ts and Their Price Tags

Step five is where money enters, so it gets its own section. Every treatment is one of four moves, and each carries a cost profile the decision must price; insurance moves severity to a carrier’s balance sheet and leaves the operational disruption with you, a distinction Southwest’s $1.2 billion quarter makes vivid.

Treatment When it fits What it costs you
Avoid Exposure exceeds any tolerable appetite; exit the activity or market Lost upside and revenue
Reduce Controls cut likelihood or impact at a cost below the exposure Capital plus ongoing control operation
Transfer Severity beyond the balance sheet; insurable or contractible Premiums, deductibles, residual disruption
Accept Inside appetite; treatment would cost more than the exposure Retained losses when they land

Acceptance is the most abused move of the four. Done properly it is an active, signed decision inside a board-approved tolerance, the standard the Financial Stability Board’s appetite framework principles set for banks and one worth borrowing everywhere. Silent acceptance by inaction, Southwest-style, is not a treatment; our sector-by-sector appetite examples show what usable tolerances look like.

Reduction takes most of the budget, so sequence it by cost per unit of risk removed, the discipline McKinsey’s risk practice keeps documenting in resilience work. We rank controls by expected loss avoided against implementation cost, fund down the list until marginal benefit flips, and log the rest as acceptances; a risk mitigation plan template makes that ranking repeatable.

Two companion pieces carry the detail. How to mitigate risk works through reduction design, and the twelve risk management techniques catalog covers the standard moves with their known failure modes, so treatments get chosen by fit rather than inherited by habit. When a treatment changes how people work day to day, the change manager roles and responsibilities guide covers the adoption half of the job.

Monitoring That Catches Drift Before Losses

Treatments decay, which is why step six exists. Controls rot as processes change, and a monitoring layer of key risk indicators with thresholds tells you a treatment is failing while the fix is still cheap. Southwest even had the warning shot: more than 1,800 cancellations across an October 2021 weekend, fourteen months before the meltdown.

Indicator Threshold example What a breach triggers
Control failure rate Over 2% of tested controls fail Re-test and treatment review
Near-miss trend Three-month rising trend Root-cause review with the risk owner
Risk score drift Any score rising two cycles running Full re-assessment of the entry
Treatment milestones Any milestone 30+ days late Escalation to the risk committee
Appetite utilization Over 80% of a category limit Pre-emptive board notification

Escalation rules make the dashboard mean something. We wire each indicator to a named response inside the risk management KPI dashboard, and every quarterly review asks one question first: which treatments did the data just falsify? A dashboard nobody must answer to is scenery.

Monitoring also faces outward, because the risk environment resets faster than annual reviews. The World Economic Forum’s Global Risks Report 2026 found half of surveyed leaders expect a stormy or turbulent world over the next two years, up 14 points in a year, with geoeconomic confrontation ranked the top near-term risk.

How Do You Manage Risk

Figure 4. Nine in ten leaders expect an unsettled world or worse through 2028; annual risk management reviews lag that pace.

How Do You Manage Risk: Your Questions Answered

These are the questions that follow the six steps in practice, phrased the way owners and executives ask them in reviews. Each answer front-loads the decision, so take what your situation needs and follow the links where the full method lives.

What is the first step when you manage risk in a small business?

Scope before listing: to manage risk in a small business, write down the objectives at stake, the loss you can absorb, and simple scoring anchors. A small firm can do this in a two-hour session and immediately outperform larger rivals that skipped criteria; our step-by-step guide shows the full sequence at small-company scale.

What works when you manage risk without a dedicated team?

Assign ownership to line managers and keep the machinery light: one register, one quarterly review, one page of appetite statements. The risk management process scales down cleanly; what cannot be delegated is executive ownership of the ranking and the funding decisions that follow from it.

Can you manage risk that insurance will not cover?

Uninsurable exposures leave three moves: avoid the activity, reduce the exposure with controls, or accept it formally within tolerance. Reputation and strategic risks live here, which is why scenario-based assessment and early-warning indicators matter more for them than any policy document.

How often should you review how you manage risk?

Quarterly for the register and indicators, annually for appetite and criteria, and immediately after any loss event, near miss, or major change. How often to run assessments depends on volatility; the Southwest lesson is that a repeat near miss is an unscheduled review demanding attention now.

Which framework should you use to manage risk: ISO 31000 or COSO ERM?

ISO 31000 is leaner and works across any organization; COSO ERM speaks the language of US boards and integrates with strategy setting. Most risk management programs borrow from both, and our comparison breaks down where they genuinely differ; the six steps here satisfy either.

How do you measure whether you manage risk effectively?

Track losses against appetite, treatment completion rates, indicator breaches caught before impact, and near-miss learning speed. The advantages of formal risk management show up in loss volatility over time; if three review cycles change nothing in funding or behavior, you are measuring theater.

Lessons from Programs That Failed

Risk management failure modes repeat across industries with impressive fidelity. The table condenses what we see in remediation engagements and what the public record, from Southwest to the banks, keeps confirming; each trap pairs with the correction that reliably works in practice.

Trap Why it happens Correction
Register grows, budget does not Risk process runs disconnected from the planning cycle Time the risk review to precede budget season
Every risk scored medium No written anchors; committee compromise Anchored scales plus force-ranking
“Monitor” listed as a treatment Watching mistaken for acting Require a real treatment or a signed acceptance
Appetite statement no one can apply Written for the annual report, not for decisions Rewrite as numeric limits per category
Near misses closed without learning Incident process ends at service restoration Feed every near miss back into the scores
Risk review as compliance ritual No executive consequences attached Tie treatment milestones to owner scorecards

One more distinction saves real money in a bad week: risk management prevents and prepares, while crisis management responds. Programs that conflate them staff neither properly, and the gap shows exactly when 16,700 flights are falling out of the schedule.

Where the Profession Is Heading

Expect regulators to keep converting risk management from voluntary practice into enforced duty. The SEC’s cybersecurity disclosure rules already require registrants to describe their risk processes in Item 106 filings, and boards are learning that a described process must exist in testable form.

The toolset is shifting toward continuous assessment. Risk teams are wiring indicators to live operational data instead of quarterly self-reports, and the WEF’s turbulence numbers argue for exactly that cadence; a register refreshed annually now ages faster than the environment it describes. The refresh cycle also needs a check of its own: assess whether your risk management actually works before trusting what the register says.

Southwest, for its part, publicly committed to a sweeping technology overhaul after the meltdown, rebuilding the crew-recovery systems it had deferred for years. The same fix was available earlier at a fraction of the eventual bill; managing risk well simply means buying at the early price.

If your register has grown while your treatment budget has not, that is the signal to act on. We build and repair risk programs for boards and operating teams; our services explain the engagement shapes, and a short note through our contact page is enough to start the conversation.