The five risk management steps are: identify the risks that threaten your objectives, analyze their likelihood and impact, evaluate them against your risk appetite, treat the priorities by avoiding, reducing, transferring, or accepting each one, and monitor results with indicators and reviews. ISO 31000:2018 frames the loop; discipline in repeating it does the protecting.
Late on Friday, September 19, 2025, ransomware hit MUSE, the check-in and boarding software Collins Aerospace runs for airports across Europe. By Saturday morning, staff at Heathrow, Brussels, and Berlin Brandenburg were writing boarding passes by hand while hundreds of flights slipped or died on the boards.
The EU cyber agency ENISA confirmed ransomware that Monday, as Brussels cancelled roughly 60 of 550 departures in a single day. None of the three airports had been breached; their shared vendor had, and no plan on any shelf covered that dependency.
| Risk Management Steps: Key Takeaways |
| Five verbs run the loop: identify, analyze, evaluate, treat, monitor. These risk management steps repeat under ISO 31000:2018, with communication threaded through every stage. |
| The September 2025 Collins Aerospace ransomware attack pushed Heathrow, Brussels, and Berlin to pen-and-paper check-in; Brussels cancelled about 60 of 550 departures the following Monday. |
| Allianz’s 2026 Risk Barometer, drawn from 3,338 experts in almost 100 countries, puts cyber first at a record 42%, with AI second at 32% after jumping from tenth place. |
| Each step has one deliverable: a live register, scored exposures, a prioritized list against appetite, funded treatment actions with owners, and KRIs with escalation triggers. |
| Treatment follows the profile: avoid high-likelihood high-impact exposures, reduce frequent small ones, transfer rare severe ones through insurance and contracts, accept the rest in writing. |
| The SEC’s cybersecurity disclosure rule gives US registrants four business days to report a material incident, which makes step five a regulatory clock, and untested monitoring a filing risk. |
Every one of the five risk management steps failed somewhere in that chain: an unidentified single point of failure, an unanalyzed concentration, an untreated dependency, unmonitored vendor controls. This guide works through each step the way practitioners actually run them, with the deliverable that proves each one happened.
What the Five Risk Management Steps Cover
Identify, analyze, evaluate, treat, monitor: the five risk management steps convert uncertainty into a sequence of decisions. ISO 31000:2018 formalizes them as one process, with scope-setting up front and communication running through every stage. The loop repeats; a register that never changes is a museum piece.

Figure 1. Five steps, one loop: communication and review thread through every stage.
Two clarifications save endless confusion. The first three steps together form the risk assessment, which is one stage inside risk management, never a substitute for it. And the steps apply at every altitude, from a single project to the enterprise-wide program a board oversees.
Each step earns its place by producing something a reviewer can hold in their hands. Skip a deliverable and the step did not happen, whatever the meeting minutes claim. The table below is the working contract we use with clients on every engagement.
| Stage | Core question | Deliverable that proves it |
| 1. Identify | What could stop us meeting our objectives? | Live risk register with causes and owners |
| 2. Analyze | How likely is each risk, and how big? | Scored exposures with stated criteria |
| 3. Evaluate | Which exposures breach our appetite? | Prioritized list ranked against tolerance |
| 4. Treat | Avoid, reduce, transfer, or accept? | Funded actions with owners and dates |
| 5. Monitor | Is it working, and what has changed? | KRIs, escalation triggers, review minutes |
Why One Vendor Grounded Three Airports
The Collins incident deserves a closer look, because it maps a failure onto every one of the five steps in turn. The Everest ransomware group claimed the attack, and recovery stretched across days while airports processed passengers on iPads, laptops, and paper.

Figure 2. One vendor outage, three grounded hubs: the cost of an unidentified dependency.
Now run it backwards through the risk management process. Identification should have flagged one vendor serving check-in at three hubs as a concentration risk. Analysis should have scored the outage scenario; evaluation should have found it far outside appetite; treatment should have funded a tested manual fallback. If you need the case for running the process at all, see why risk management is important before starting step one.
The airports that recovered fastest were the ones whose continuity plans had been exercised, a point the NCSC board toolkit keeps making about testable questions. Plans that exist only as documents fail exactly when the disciplined version of the process would have paid for itself.
Step One: Identify What Can Hurt You
Identification opens the risk management steps as a hunt for causes, not a brainstorm of headlines. Risk identification works from your objectives outward: for each one, list what could derail it, who owns that exposure, and what evidence would show it forming. Interviews, loss data, and process walkthroughs all feed the register.
External scanning keeps the register honest. The Allianz Risk Barometer 2026, compiled from 3,338 risk experts in almost 100 countries, puts cyber incidents first at a record 42%, with artificial intelligence second at 32% after jumping from tenth place a year earlier.

Figure 3. Cyber holds first place for a fifth year, and AI is the fastest riser: calibrate your register accordingly.
Write each risk as cause, event, consequence. A register entry reading ‘cyber risk’ invites a shrug; one reading ‘phished vendor credential leads to check-in outage across all hubs, causing mass cancellations’ invites a plan. Worked register examples show the difference.
Step Two: Analyze Likelihood and Impact
Analysis, second of the risk management steps, attaches numbers, or at least defensible scales, to what identification found. Qualitative scoring rates likelihood and impact on anchored one-to-five scales; quantitative work models financial outcomes where the exposure justifies the effort. IEC 31010 catalogues more than thirty techniques, from bow-tie diagrams to Monte Carlo simulation.
Choose depth by decision, and let the assessment methodology say so in writing. A supplier-concentration exposure that could ground operations justifies scenario modelling; a minor compliance gap needs a score and an owner. Uniform depth across the register wastes analyst hours where they buy nothing.
Anchor the scales before anyone scores. When ‘likely’ means above 60% in one department and ‘happens most years’ in another, aggregation produces nonsense, and software platforms cannot fix definitions nobody agreed. Publish the anchors and challenge outlier scores in review.
Step Three: Evaluate Against Appetite
Evaluation, third of the risk management steps, is where analysis meets governance. Each scored exposure gets compared with the risk appetite the board approved, and lands in one of three buckets: fine as is, treat where cost-effective, or outside tolerance and demanding action. Without a stated appetite, evaluation collapses into whoever argues loudest.
Ranking is the visible output, and it must survive challenge. A prioritized list tells management where the next dollar of mitigation goes and why, which is precisely what Protiviti’s 2026 top-risks survey shows boards now asking for. Tie each priority to the objective it protects.
Watch for the quiet failure at this step: everything scoring medium. Force-rank the register when scores cluster, and record the rationale for every rank. The full risk management lifecycle depends on evaluation actually separating the urgent from the merely present.
Step Four: Treat the Priorities
Treatment, step four of the risk management process, turns the ranked list into funded work. Four responses cover the territory: avoid the activity, reduce likelihood or impact through controls, transfer through insurance or contract terms, or accept in writing with a named approver. The matrix below maps response to profile.

Figure 4. Match the treatment to the profile, then fund it, own it, and date it.
Every treatment needs an owner, a budget line, and a completion date, or it is a wish wearing a control’s name. Deciding what happens for each scored risk is the step that turns a register into funded work. Build all three into the risk management plan and track closure monthly. Project-level mitigation follows the same grammar at smaller scale.
Positive risk deserves a sentence of its own. Where uncertainty could break your way, treatment means enlarging the opportunity: committing earlier, scaling faster, or contracting for upside. Registers that only ever record threats teach leadership that risk work is the department of no.
Step Five: Monitor, Report, Adjust
Monitoring closes the loop and restarts it. Key risk indicators with green, amber, and red thresholds catch drift between reviews, and each breach needs a documented response inside an agreed window. Reporting carries the signal to people who can act on it.
Regulators have quietly turned this step into a clock with penalties attached, and the timestamps are auditable. The SEC’s cybersecurity disclosure rule gives US registrants four business days to report a material incident once materiality is determined, which quietly assumes monitoring that can spot the incident, judge its materiality, and escalate it fast enough for counsel to file.
When a monitored risk crystallizes, it stops being a risk and becomes an issue: move it to the issue log, trigger the response plan, and record what the register missed. That record is the raw material for the next identification pass, which is why the risk management process never finishes.
Where the Steps Sit in ISO 31000, COSO, and NIST
The five steps are not one framework’s property; the major standards tell the same story in different accents. Knowing the mapping saves teams from running parallel processes when an auditor or customer names a different framework. Assessing your own process against any of them starts with this table.
| Step | ISO 31000:2018 | COSO ERM (2017) | NIST RMF (SP 800-37) |
| Identify | Risk identification (6.4.2) | Identifies risk to strategy | Categorize systems |
| Analyze | Risk analysis (6.4.3) | Assesses severity of risk | Select and assess controls |
| Evaluate | Risk evaluation (6.4.4) | Prioritizes risks | Authorize operation |
| Treat | Risk treatment (6.5) | Implements risk responses | Implement controls |
| Monitor | Monitoring and review (6.6) | Reviews and revises | Continuous monitoring |
COSO’s ERM framework speaks the board’s language of strategy and performance, while NIST SP 800-37 and the Cybersecurity Framework go deepest on technology risk. Pick the spine your regulator expects, then map the others to it inside one enterprise framework.
The Mistakes That Break the Process
Most process failures are predictable, and internal audit sees them repeatedly. Risk in Focus 2026 reads as a catalogue of organizations that ran the risk management steps on paper while the exposures ran ahead of them. Five patterns account for most of the damage.
| Mistake | Why it happens | Fix |
| Register built once, never revisited | Steps treated as a project with an end date | Standing review cadence plus event triggers |
| Vendor dependencies never reach the register | The contract gets mistaken for a control | Map concentrations; test fallbacks yearly |
| Scores without anchored criteria | Each team invents its own scale | Published anchors; challenge sessions |
| Treatment lists with no budget | Actions agreed but never funded | No action enters the plan without a cost line |
| Monitoring without escalation | KRIs reported but nobody must respond | Every threshold breach gets a named responder |
The annual cycle is a floor, and certain events should never wait for the scheduled date to come around. Re-run all five steps early, at minimum for the objectives the event touches, the moment any one of these five triggers fires:
- Objectives shift under you: a merger closes, a business unit is sold, strategy pivots.
- Something new becomes critical: a vendor, a platform, a market you now depend on.
- An incident lands close to home, in your organization or at a direct peer.
- A regulator issues new expectations that touch your sector.
- Growth outruns the controls that were sized for a smaller firm.
Self-review has predictable blind spots, so buy independence at intervals. A periodic independent audit of the process catches what self-review politely ignores, and a structured program-level review tells the board which of the five steps is actually the weak one. Fund that answer before funding more controls.
Risk Management Steps: Your Questions Answered
What are the 5 risk management steps?
The five risk management steps are risk identification, risk analysis, risk evaluation, risk treatment, and monitoring with review. ISO 31000:2018 defines them as one continuous process with communication running throughout. Identification through evaluation together form the risk assessment; treatment and monitoring turn its findings into protection.
What is the first step in the risk management process?
Establishing scope and context comes first, then risk identification. You define the objectives at stake, the criteria for scoring, and the appetite boundaries, because a risk only means something relative to an objective. Teams that skip context produce registers full of generic threats no one owns.
Where do risk analysis and risk evaluation differ in the risk management steps?
Analysis measures; evaluation judges. Analysis estimates each risk’s likelihood and impact using anchored scales or financial models, producing a score. Evaluation compares that score against the organization’s stated appetite and decides whether the exposure is acceptable, worth treating, or intolerable, producing a ranked priority list.
How often should the risk management steps be repeated?
Run the full loop at least annually, with quarterly register reviews and continuous KRI monitoring between passes. Pull the cycle forward after a merger, a new critical vendor, a material incident, or a regulatory change. High-velocity risks like cyber justify monthly indicator reviews rather than annual ones.
Which standards define the risk management process steps?
ISO 31000:2018 is the international benchmark, supported by IEC 31010 for assessment techniques. COSO ERM 2017 frames the same steps for boards through a strategy lens, and NIST SP 800-37 applies them to federal and technology systems. Most organizations choose a single spine and translate the other frameworks into its language.
Who should own each of the risk management steps?
Risk owners in the business own identification, treatment, and the exposures themselves; the risk function owns the method, the scales, and the consolidated register; boards own appetite and evaluation thresholds. Monitoring splits: owners track their indicators while the risk team watches the portfolio and escalates breaches.
What to Remember
The loop is entering a faster gear. AI risk moved from tenth to second in the Allianz Barometer in a single year, disclosure clocks like the SEC’s four-day rule keep shrinking response windows, and vendor concentration keeps producing Collins-scale surprises.
Expect two changes in how the steps get run through 2027. Monitoring will absorb most of the new budget, since regulators now grade speed of detection as harshly as quality of prevention. And third-party mapping will move from step-one afterthought to a standing register section with its own tested fallbacks.
Our position after years of running these loops: the organizations that win are rarely the ones with the most elaborate registers. They are the ones where all five steps produce their deliverable every cycle, on a simple set of tools everyone actually uses.
If your register has not moved since last year, or your board cannot name its top five exposures with owners and dates, our advisory services rebuild the loop step by step. Reach out and leave the first working session with a register your team can defend.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.