A risk management policy is the short, board-approved document that states why and how an organization manages risk: its objectives, risk appetite, roles and responsibilities, process reference, escalation rules, and review cycle. ISO 31000 expects top management to issue one. The template below supplies model wording for all eight standard sections, ready to adapt.
In October 2020, the OCC fined Citibank $400 million and ordered its board to adopt an effective risk governance framework, citing longstanding deficiencies in risk management, data governance, and internal controls. Citi had policies; the consent order found the practice beneath them missing.
Four years later the bill arrived again: on July 10, 2024, the OCC assessed another $75 million and the Federal Reserve $60.6 million, $135.6 million total, for insufficient remediation progress, as Citi’s own 8-K filing details. A risk management policy is where that chain of accountability starts, which is why the document deserves more care than most give it.
What a Risk Management Policy Is (and Is Not)
ISO 31000:2018 places the obligation under leadership and commitment: top management issues a statement or policy that establishes the risk management approach, plan, or course of action. The risk management policy is that statement in document form, board-approved, short, and stable.
It is not the enterprise risk management framework, which holds the methodology, criteria, and tools, and it is not a procedure manual or a register. The policy authorizes those layers and assigns their owners; each layer beneath it carries detail the policy deliberately leaves out.

Figure 1. The document stack: the risk management policy is short and durable, while the records beneath it change daily.
|
Document |
What it contains |
Who owns it |
|
Risk management policy |
Objectives, appetite summary, roles, escalation, review cycle; 3-6 pages |
Board approves; CEO sponsors |
|
ERM framework |
Methodology, criteria, appetite metrics, tools, templates |
CRO or risk manager |
|
Procedures and register |
Process detail, scoring scales, treatment governance |
Line management |
|
Working records |
Assessments, KRIs, treatment plans, committee packs |
Risk owners and staff |
Why a Short Document Carries Board-Level Weight
Regulators treat the policy as the anchor of accountability. The OCC’s heightened standards at 12 CFR Part 30 require large banks to maintain a written risk governance framework approved by the board, and the Citi orders show what enforcement looks like when the paper and the practice diverge.

Figure 2. Citi paid twice for the same gap: $400 million in 2020, then $135.6 million in 2024 when remediation lagged.
Adoption data says most organizations still lack the machinery a policy authorizes. The 2025 State of Risk Oversight report found only 35 percent of 273 U.S. organizations with complete ERM processes in place, and just 32 percent rating their oversight at the top two maturity levels.
Disclosure keeps raising the stakes for the unprepared majority. The SEC’s cybersecurity rule makes public companies describe their risk processes in filings, and only 11 percent of finance leaders currently call those processes a competitive advantage; a signed policy is the cheapest first step toward the other column.
The Eight Sections Every Risk Management Policy Covers
Eight sections recur across well-drafted policies in every sector, and each earns its place by answering one governance question. Write them in order, keep each tight, and resist importing framework detail; a policy that quotes scoring scales will need board re-approval every time a scale changes.
|
# |
Section |
The governance question it answers |
|
1 |
Purpose and objectives |
Why does this organization manage risk, and what does it protect? |
|
2 |
Scope and application |
Who and what does the policy bind: entities, people, risk categories? |
|
3 |
Definitions |
What do risk, appetite, and residual risk mean here, per ISO 31000? |
|
4 |
Risk appetite statement |
How much of which risks will the board pursue, tolerate, or refuse? |
|
5 |
Roles and responsibilities |
Who approves, who owns, who reports, who assures? |
|
6 |
Process reference |
Which framework and process govern day-to-day risk work? |
|
7 |
Reporting and escalation |
What gets reported to whom, how often, and what triggers escalation? |
|
8 |
Review and version control |
When is the policy re-approved, and who keeps the record? |
Two sections do the heavy lifting. The risk appetite statement is the board’s single most consequential sentence set, and roles are where the Three Lines Model gets written into obligations: management owns risk, the risk function supports, and internal audit assures independently.
Free Risk Management Policy Template
Copy the model wording below, replace every bracketed item, and delete anything that does not apply. The language is deliberately plain: a policy read only by its authors protects nobody, and the Citi orders show regulators reading these documents against observed practice, line by line.
|
Section |
Model wording (adapt bracketed text) |
|
1. Purpose and objectives |
This policy establishes [Company]’s approach to managing risk in pursuit of its objectives. It exists to protect our people, assets, reputation, and service delivery, and to support informed risk-taking rather than eliminate risk. |
|
2. Scope and application |
This policy applies to all [Company] operations, employees, contractors, and third parties acting on our behalf, across all risk categories: strategic, operational, financial, compliance, and technology. |
|
3. Definitions |
Risk: the effect of uncertainty on objectives (ISO 31000:2018). Risk appetite: the amount and type of risk [Company] is willing to pursue or retain. Residual risk: the risk remaining after treatment. |
|
4. Risk appetite statement |
[Company] accepts measured strategic risk in pursuit of growth, maintains low appetite for operational disruption and data loss, and has no appetite for breaches of safety, law, or ethics. Detailed appetite metrics are maintained in the ERM framework. |
Sections five through eight assign the machinery: who runs the process, how findings travel upward, and when the document itself gets re-approved. These are the clauses examiners test first, because they are the easiest to falsify against meeting minutes and committee packs.
|
Section |
Model wording (adapt bracketed text) |
|
5. Roles and responsibilities |
The Board approves this policy and the risk appetite. The [CEO] is accountable for the risk environment. The [Risk Manager/CRO] maintains the framework and reports [quarterly]. Line managers own and treat risks in their areas. Internal audit provides independent assurance. |
|
6. Process reference |
Risks are identified, analyzed, evaluated, and treated under the [Company] ERM framework, which follows ISO 31000:2018. Every risk evaluated outside appetite receives a named owner, a funded treatment plan, and a review date. |
|
7. Reporting and escalation |
The risk register is reviewed [quarterly] by the [Risk Committee]. Risks rated [High or above] or breaching a KRI threshold are escalated to the [Board Audit and Risk Committee] within [five] business days. |
|
8. Review and version control |
This policy is reviewed [annually] by the [Risk Committee], re-approved by the Board after any material organizational change, and version history is maintained by [the Company Secretary]. |
Pair the finished template with its three working companions: a risk matrix for the scoring scales the framework will define, the five-step process the process-reference section points to, and the business continuity policy template if resilience sits in a sibling document.
Adapting the Template to Your Organization
Size changes the signatures, never the sections. A 60-person firm merges the CRO role into the CFO or COO and reviews the register at the leadership meeting instead of a committee; the federal government’s own OPM ERM policy shows the same eight-part skeleton scaled to an agency of thousands.
Work one adaptation end to end. A mid-size manufacturer names the COO as risk sponsor, sets appetite lines for supply disruption and safety, points the process reference at its risk assessment procedure, and sets escalation at any risk scoring 15 or above on its 5×5 matrix.
Regulated industries add sector obligations on top. Banks map the policy to 12 CFR 30 Appendix D heightened standards, health systems cite HIPAA’s risk analysis specification, and firms leaning on NIST’s Cybersecurity Framework or SP 800-39 reference them in the process section. Four adaptation checks before the board sees it:
- Every bracketed placeholder replaced, and every named role actually exists on the org chart
- Appetite lines match the risk appetite statements the board has already debated, not aspirations
- Escalation thresholds trace to the scoring scales in the framework and risk matrix
- Sector regulators’ expectations cited by name: OCC, SEC, HHS, or state equivalents
Approval, Socialization, and the Annual Review
Board approval is the start of the policy’s life, never the finish line. Socialize it through induction, annual attestation, and the operational risk training calendar, because an unread policy fails exactly the way Citi’s did: paper compliance over practiced control.

Figure 3. Only 35 percent of U.S. organizations run complete ERM processes; a signed risk management policy is the entry ticket, not the finish.
Prove the policy operates by wiring its clauses to evidence. The escalation section should match the KRI thresholds the risk team actually monitors, the treatment clause should trace to funded mitigation plans, and committee minutes should show the quarterly review the reporting section promises.
Review annually and after material change: acquisition, new regulator, new business line, or a loss event that exposed a gap. Track version history the way ISO 22301 expects for continuity documents, with dates, approvers, and a one-line summary of what changed and why.
FAQ: Risk Management Policy Questions
What should a risk management policy include?
Eight sections: purpose and objectives, scope, definitions, a risk appetite statement, roles and responsibilities, a process reference, reporting and escalation rules, and a review cycle with version control. Keep methodology detail out; that belongs in the ERM framework the policy authorizes, not in the board-approved document itself.
How long should a risk management policy be?
Three to six pages. A policy is a durable statement of intent and accountability, and every page of methodology you add drags board re-approval into routine framework changes. OPM’s federal ERM policy and most bank policies under OCC heightened standards land in exactly this range.
Who approves the risk management policy in an organization?
The board, or its audit and risk committee acting under delegated authority, approves the policy and the appetite statement inside it. Management drafts and maintains it, typically through the CRO or risk manager, and internal audit periodically verifies that practice matches the approved text.
Is a risk management policy required by ISO 31000 or U.S. regulators?
ISO 31000:2018 expects top management to demonstrate leadership by issuing a policy or statement establishing the risk management approach. U.S. regulators require it in substance for many sectors: OCC heightened standards demand a board-approved risk governance framework for large banks, and the SEC’s cyber rule makes risk processes a disclosed fact.
What is the difference between a risk management policy and a risk management plan?
The policy is the stable, board-approved statement of intent, appetite, and roles. A plan is time-bound and operational: it schedules the assessments, treatments, and reviews for a period or project. The policy authorizes; plans execute, and they change far more often than the policy should.
How often should a risk management policy be reviewed and updated?
Annually at minimum, with re-approval after any material change: a merger, a new regulator, a new business line, or a loss that exposed a governance gap. Keep formal version history with dates and approvers; examiners and auditors read the change log as evidence the document is alive.
Where Policy Documents Go Wrong
Six failure patterns show up in most policy reviews I run, and each is checkable in under an hour against the org chart, the minutes, and the register. The first one is the Citi pattern, and it is the one regulators now hunt for deliberately.
|
Pitfall |
Root cause |
Remedy |
|
Paper policy, absent practice |
Document written for auditors, never operationalized |
Wire each clause to evidence: KRIs, minutes, funded treatments |
|
Forty-page policy nobody reads |
Framework and procedure detail imported into the policy |
Cut to 3-6 pages; push methodology down a document level |
|
Appetite section without numbers |
Board comfortable with adjectives, not thresholds |
Anchor appetite lines to metrics kept in the framework |
|
Roles named for people who left |
Policy written once, org chart moved on |
Use role titles, and check them at every annual review |
|
Escalation thresholds nobody triggers |
Thresholds set high enough to stay quiet |
Test them: if nothing escalated all year, they are wrong |
|
No version history |
Review cycle skipped once, then abandoned |
Version table with dates, approvers, and one-line change notes |
Looking Ahead: Policy Expectations Through 2027
Regulators keep converting policy from a formality into testable evidence. The Citi amendment now requires a resource review plan proving money follows the remediation promises, and that practice-over-paper posture is spreading through examinations well beyond banking, into the sectors the SEC and HHS supervise.
AI risk is the next clause your policy will need. Boards are extending appetite statements to model use and automated decisions, and the scope section increasingly names AI systems alongside the traditional categories; the risk management techniques for treating model risk are the same twelve, but the policy must claim jurisdiction first.
The winning documents will stay short while their evidence gets richer. Live dashboards, automated KRIs, and continuous control monitoring let a three-page policy prove itself daily, and the case for the whole discipline increasingly rests on exactly that proof; knowing where assessment ends and management begins keeps the policy pointed at decisions.
Infographic: The Policy Document Stack

Figure 4. The risk management policy stack: four ownership levels, plus the eight sections every policy covers.
Riskpublishing drafts and pressure-tests risk management policies for U.S. mid-market boards, from the appetite wording down through the framework beneath it. Our services include policy reviews against regulator expectations; contact us if your current policy would not survive the Citi test.
risk-management-policy-template-word-download

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.