A Texas judge ordered CPS Energy, San Antonio’s city-owned utility, to pay nearly $400M in July 2026 after ruling it broke natural-gas contracts signed during Winter Storm Uri. The utility had spent roughly $850M on emergency fuel during the February 2021 freeze, and its customers are still repaying storm costs through a monthly surcharge.

That ruling is what risk management for public power utilities looks like in practice: a five-year-old weather event turning into a nine-figure court judgment. Public power utilities, the more than 2,000 community-owned electric utilities that serve 55 million Americans, carry financial, operational, legal, and physical risks that investor-owned peers manage differently because they answer to ratepayers and bondholders, not shareholders.

Risk Management for Public Power Utilities: Key Takeaways
A Texas court ordered CPS Energy, San Antonio’s public power utility, to pay nearly $400M in July 2026 over Winter Storm Uri gas contracts from 2021.
Public power utility risk management now has to price wildfire liability: LADWP faces lawsuits over water-system failures in the January 2025 Palisades Fire.
Only 32% of US organizations rate their risk oversight as mature, and just 11% see ERM as a strategic advantage, per the 2025 State of Risk Oversight report.
Three NERC CIP deadlines land between September 2025 and July 2026, adding internal network monitoring and vendor remote-access governance.
The SEC’s March 2025 withdrawal from defending its climate disclosure rule does not remove state PUC, bond covenant, or physical climate exposure.
COSO’s 2017 ERM framework and ISO 31000:2018 both fit public power utilities; the right choice depends on whether the board wants a controls lens or a principles lens.

This guide sets out how public power utility risk management actually works in 2026: the risk categories a program has to cover, two live case studies with real dollar figures, the framework choice between COSO and ISO 31000, and the cyber and climate rules reshaping the job.

Table of Contents

What Risk Management for Public Power Utilities Actually Means

Enterprise risk management for public power utilities means one coordinated view of every risk that could stop the utility from keeping the lights on, keeping rates affordable, and keeping its bond rating intact. COSO first published its ERM framework in 2004 and rebuilt it in 2017 around strategy and performance, not just controls.

A public power utility risk management program is not a compliance checklist bolted onto operations. It is how a utility decides which risks to accept, which to transfer through insurance or hedging, and which are severe enough to change capital spending, drawing directly on our enterprise risk management framework guide for the underlying mechanics.

Risk Management for Public Power Utilities: The 2026 Playbook

Figure 1. The public power sector that risk management for public power utilities exists to protect. Source: APPA, 2026.

Why Public Power Utility Risk Management Differs From Investor-Owned Utilities

Investor-owned utilities answer to shareholders and state public utility commissions that set rates through formal proceedings. Public power utility risk management answers to a city council, a municipal board, or a rural electric cooperative’s member-elected directors instead, which changes how risk appetite gets set.

Credit rating agencies treat that difference as material. S&P Global’s 2024 rating actions for municipal electric utilities weigh board tolerance for financial risk directly, because a public power utility cannot raise equity capital the way an investor-owned peer can when a loss hits.

That capital constraint is why public power utility risk management leans harder on reserve funds, rate covenants, and conservative debt structuring than on risk transfer through capital markets. When CPS Energy lost its Uri case in July 2026, the cost did not hit a shareholder’s dividend; it hit a rate surcharge that will run for roughly 21 years.

The Six Risk Categories a Public Power Utility Risk Management Program Must Track

Public power utility risk management programs organize exposure into six recurring categories, echoing how Moody’s and S&P Global score municipal utility credit risk. Skipping any one of them is how a program ends up surprised, because these categories interact rather than sit in isolation from one another.

Risk Management for Public Power Utilities: The 2026 Playbook

Figure 2. The six categories a public power utility risk management program has to monitor together, not in isolation.

Category What it covers in public power Primary owner
Credit risk Bond rating, reserve adequacy, and access to capital markets CFO / Treasury
Market risk Fuel and wholesale power price volatility, hedging positions Power supply / trading desk
Operational risk Outages, equipment failure, workforce and grid strain Operations leadership
Legal and regulatory FERC reliability standards, state PUC rules, statute changes General counsel
Physical and climate Wildfire, storm, and extreme-weather exposure to assets Risk management / engineering
Cyber risk NERC CIP compliance and nation-state threat activity CISO / IT security

Case Study: How Winter Storm Uri Broke Public Power Utility Risk Management in Texas

Winter Storm Uri hit Texas across February 8-20, 2021, triggering the loss of 61,800 megawatts of generation and the largest manually controlled blackout in US history. CPS Energy, San Antonio’s municipally owned utility, spent about $850M buying emergency natural gas at storm-spiked prices to keep the lights on.

Five years later, that decision became a legal liability. A Bexar County judge ruled in July 2026 that CPS Energy owed Energy Transfer subsidiaries nearly $400M: $264M in unpaid contract costs, $119M in pre-judgment interest, and $9.3M in attorney fees.

Risk Management for Public Power Utilities: The 2026 Playbook

Figure 3. What weak public power utility risk management around fuel procurement cost one Texas utility, five years later.

CPS Energy customers are already repaying storm fuel costs through a $1.26 monthly surcharge that is expected to run for roughly 21 more years. That is the real lesson for public power utility risk management: a single emergency procurement decision, made under duress, can outlive the crisis by two decades.

Case Study: LADWP and the Wildfire Risk Now Central to Public Power Utility Risk Management

The Los Angeles Department of Water and Power, the country’s largest public power utility, is being sued over water-system failures during the January 2025 Palisades Fire. Plaintiffs allege the Santa Ynez Reservoir, a 117-million-gallon storage complex, sat empty for cost-saving reasons when the fire broke out.

LADWP said extreme firefighting demand, not the empty reservoir, caused the pressure loss that affected 20% of hydrants in the fire zone. Either explanation lands in the same place for public power utility risk management: a maintenance or capacity decision became a wildfire-liability lawsuit.

Risk Management for Public Power Utilities: The 2026 Playbook

Figure 4. One wildfire drove over half of 2025’s US disaster losses. Source: Climate Central.

The January 2025 Los Angeles wildfires caused more than $61 billion in damage, out of $115 billion across all US billion-dollar weather disasters that year. For a public power utility risk management program in a wildfire-exposed service territory, that concentration is the risk to model, not the annual average.

Choosing a Framework for Public Power Utility Risk Management: COSO or ISO 31000

Most public power utility risk management programs standardize on either COSO’s 2017 ERM framework or ISO 31000:2018. COSO gives boards a controls-and-performance lens with five components and 20 principles; ISO 31000 gives a shorter, principles-based structure that many international utilities already use.

Neither framework is inherently better for public power; the choice usually tracks what a utility’s auditors or bond counsel already expect. Our COSO versus ISO 31000 comparison walks through the practical differences board members actually ask about before committing budget to either one.

A public power utility risk management program built on either standard still needs a working risk register, a documented risk appetite, and a board-ready dashboard that turns both into a monthly decision tool rather than an annual compliance filing that nobody reopens until the next audit cycle.

Setting Risk Appetite in a Public Power Utility Risk Management Program

Risk appetite is where public power utility risk management gets political as much as technical. A board that will not tolerate a rate increase is implicitly setting a low appetite for operational risk, whether or not anyone writes that down.

Writing it down matters anyway. A documented risk appetite statement gives management and the board a shared reference point before a crisis, not during one, and our guide on drafting a board-ready risk appetite statement shows the structure that holds up under scrutiny.

Public power utility risk management appetite statements should name specific thresholds: maximum unhedged fuel exposure, minimum reserve days, acceptable outage minutes per customer. Vague language like “prudent risk-taking” gives a board nothing to hold management accountable to when a decision goes wrong.

Where Public Power Utility Risk Management Sits on the Org Chart

A dedicated Chief Risk Officer role remains rare among smaller public power utilities, but the largest members of the Large Public Power Council increasingly staff one. Without a CRO, public power utility risk management typically reports through the CFO or general counsel.

RIMS’ Carol Fox put the governance problem plainly: “The evidence shows that risk management has evolved from a promising but somewhat perfunctory exercise into a strategic management competency.” That evolution has not reached every public power board yet.

Effective public power utility risk management governance follows a bottom-up and top-down mix: an executive risk committee aggregates risk from operating functions, and the board’s audit or risk committee sets appetite and reviews the register at least quarterly, not just when a crisis forces the conversation.

Cybersecurity Is the Fastest-Growing Line in Public Power Utility Risk Management

CISA’s February 2024 Volt Typhoon advisory disclosed that a Chinese state-sponsored group had maintained access to US energy, water, and communications infrastructure for at least five years, positioned to disrupt services during a geopolitical crisis rather than for immediate financial gain.

Public power utility risk management now has to plan around nation-state threats, not just ransomware. The energy sector’s average breach cost reached $4.83M in 2025, above the $4.44M global average, reflecting how costly critical-infrastructure incidents have become once regulators and litigation get involved.

Risk Management for Public Power Utilities: The 2026 Playbook

Figure 5. Three NERC CIP deadlines every public power utility risk management program has to plan around.

Three NERC CIP deadlines land in close succession: CIP-015-1 phases in internal network security monitoring from September 2025, CIP-003-9 expands vendor remote-access governance from April 2026, and CIP-012-2 strengthens control-center data protection from July 2026, each with its own compliance calendar.

Public power utility risk management teams that treat NERC CIP as a once-a-year audit exercise miss how fast the standard is moving. Our cyber security risk management framework hub maps how CIP fits alongside NIST CSF 2.0 for utilities running both frameworks at once.

Climate and Regulatory Risk in Public Power Utility Risk Management After the SEC’s Retreat

The SEC voted in March 2025 to stop defending its climate disclosure rule, and by May 2026 it had proposed rescinding the rule entirely, arguing it exceeded the agency’s statutory authority. Litigation over the rule remains stayed while the commission works through notice-and-comment rulemaking.

That retreat does not remove climate risk from public power utility risk management; it just moves the pressure elsewhere. State public utility commissions, bond rating agencies, and physical exposure to wildfire and extreme weather all still demand climate risk analysis regardless of what the SEC requires.

Our SEC climate disclosure implications guide covers what changed federally, while a climate transition risk assessment and scenario analysis using NGFS pathways give public power utility risk management teams a way to keep assessing exposure without waiting on federal rulemaking.

Third-Party and Vendor Risk in Public Power Utility Risk Management

Public power utilities increasingly depend on third-party software, grid-monitoring vendors, and outside fuel suppliers, the same dependency chain CPS Energy’s Uri contracts sat inside. A third-party risk management framework gives public power utility risk management a way to score vendor exposure before signing, not after a storm forces an emergency purchase.

Concentration is the underappreciated risk here. When one supplier handles fuel procurement, metering data, and grid software simultaneously, a single vendor failure cascades across operational, cyber, and market risk at once, which our concentration risk in third-party relationships guide walks through in more detail.

Is Your Public Power Utility Risk Management Program Actually Working?

Most programs are not, by their own leaders’ admission. The 2025 State of Risk Oversight report found only 32% of US organizations rate their risk oversight as mature, and just 35% report having a fully built-out ERM process in place at all.

Risk Management for Public Power Utilities: The 2026 Playbook

Figure 6. Public power utility risk management is not exempt from the maturity gap the rest of US business reports.

Only 11% of surveyed leaders said ERM offers a strategic advantage, even as 61% report rising risk complexity. RIMS research separately found organizations with mature risk management practices realize a valuation premium of up to 25%, which is the business case public power utility risk management programs can take to a skeptical board.

A working public power utility risk management program shows up in specific, checkable places: a risk register updated within the last quarter, key risk indicators pulled from our KRI library reviewed monthly, and a board that can name its top five risks without looking at a slide.

Frequently Asked Questions About Risk Management for Public Power Utilities

What makes risk management for public power utilities different from investor-owned utilities?

Public power utility risk management answers to a city council, municipal board, or cooperative membership instead of shareholders. That changes how risk appetite gets set and removes access to equity capital markets that investor-owned utilities use to absorb losses, leaving reserves and rate covenants as the main cushion.

Which framework should a public power utility risk management program use, COSO or ISO 31000?

Either fits. COSO’s 2017 framework suits utilities whose auditors already expect a controls-and-performance structure, while ISO 31000:2018 suits utilities that want a shorter, principles-based standard. The choice usually follows what bond counsel or external auditors already reference in existing engagement letters.

How does Winter Storm Uri still affect public power utility risk management in 2026?

CPS Energy’s July 2026 court judgment, nearly $400M over unpaid 2021 gas contracts, shows fuel-procurement decisions made during a crisis can generate liability years later. Public power utility risk management programs now model multi-year litigation exposure from emergency purchases, not just the immediate storm cost.

What NERC CIP deadlines should a public power utility risk management team track in 2026?

CIP-015-1 phases in internal network security monitoring starting September 2025, CIP-003-9 expands vendor remote-access governance from April 2026, and CIP-012-2 strengthens control-center data protection from July 2026. All three add work to existing cyber risk programs, none of them replace it.

Does the SEC’s climate rule retreat remove climate risk from public power utility risk management?

No. The SEC’s proposed rescission removes a federal disclosure mandate, but state utility commissions, bond rating agencies, and physical exposure to wildfire and extreme weather still require climate risk analysis independent of SEC rules, and that exposure has not gone anywhere.

How mature is the average public power utility risk management program?

Likely below where its board assumes. Nationally, only 32% of organizations rate their risk oversight as mature, and just 11% see ERM as a strategic advantage, per the 2025 State of Risk Oversight report. Public power utilities have not been shown to outperform that baseline.

Who owns risk management for public power utilities without a dedicated CRO?

At most smaller public power utilities, risk management for public power utilities reports through the CFO or general counsel rather than a standalone Chief Risk Officer. Only the largest utilities in the Large Public Power Council commonly staff a dedicated CRO role.

Where Public Power Utility Risk Management Programs Stall

Pitfall Root cause Remedy
Fuel procurement treated as operations, not risk No risk sign-off on emergency purchasing during extreme weather Route crisis fuel contracts through the same appetite thresholds as routine ones
Risk register reviewed annually, not monthly Program built for an audit cycle, not for decisions Pair the register with a monthly dashboard tied to named KRIs
Climate risk dropped after the SEC rule stalled Confusing a federal disclosure mandate with the underlying exposure Keep physical and transition climate analysis independent of SEC rulemaking status
NERC CIP treated as a once-a-year audit Standards updated faster than the compliance calendar reflects Assign an owner to track CIP revision dates on a rolling basis
No documented risk appetite before a crisis hits Appetite exists informally in board culture, never written down Draft explicit thresholds for fuel exposure, reserves, and outage minutes now

 

Build Stronger Risk Management for Public Power Utilities With Risk Publishing

A CFO or risk officer at a mid-size public power utility does not need another generic ERM template; they need a program that prices wildfire, Uri-style fuel exposure, and NERC CIP together. Our advisory services build public power utility risk management programs around exactly that mix, and you can get in touch to start with a risk register review.