What Is a Risk Management Program

Photo of author
Written By Chris Ekai

A risk management program is the permanent structure an organization uses to find, rate, treat, monitor, and report the risks that threaten its objectives. It combines governance, a documented process, a risk register with indicators, assigned owners across three lines, and controls spanning safety, cyber, insurance, and continuity, then reviews all of it on a fixed cycle.

At about 12:15 a.m. on April 7, 2026, an employee of the logistics contractor NFI Industries set fires in six places inside a 1.2 million square foot Kimberly-Clark distribution center in Ontario, California. ASIS International’s review of the FBI affidavit records that the simultaneous ignitions overwhelmed the sprinkler system’s water pressure within minutes.

About 20 employees evacuated on the alarm, 175 firefighters worked for nearly 12 hours, and the building was a total loss. Federal prosecutors put the property damage at $600 million against a building valued at $156 million, and Bloomberg Intelligence estimated the loss could affect 3 percent of Kimberly-Clark’s West Coast sales.

What Is a Risk Management Program: Key Takeaways

A risk management program is the standing set of governance, people, process, and tools an organization runs to identify, assess, treat, monitor, and report risk against its objectives; the plan, policy, and framework are documents inside it.

Seven components make a program work: governance and appetite, a risk process, a register with indicators, three lines of accountability, controls across safety, cyber, insurance, and continuity, reporting, and culture.

ISO 31000:2018, COSO ERM 2017, the IIA Three Lines Model, OSHA’s safety management practices, NIST CSF 2.0, and NFPA 1600 each cover one part of the program; no single standard covers all of it.

Only 32% of 273 US organizations rate their risk oversight mature and 64% say it gives no or minimal advantage (AICPA and NC State, 2025), so most programs exist on paper more than in practice.

Work injuries cost the US $181.4 billion in 2024 (NSC), a US data breach averages $10.22 million (IBM 2025), and one insider arson fire cost about $600 million in April 2026.

A credible program takes 18 to 36 months to build in four phases, and the first deliverable is a board-approved charter and appetite statement, not a software licence.

 

Two coworkers had noticed the suspect’s rhetoric change two weeks before the fire, and his own social media showed the motive. A risk management program is what connects those signals, the sprinkler design, the third-party contract, the insurance schedule, and the recovery plan into one system. What follows explains what a risk management program is and how to build one.

What Is a Risk Management Program?

Start with the distinction that trips up most searches. A program is the standing organizational capability; a plan, a policy, and a framework are documents that live inside it. ISO 31000:2018 describes the framework and the process, COSO ERM 2017 describes the components and principles, and neither uses the word program for the whole, so the term needs defining.

Term

What it is in the risk management program

Where it lives on this site

Risk management program

The standing structure: governance, people, process, register, controls, reporting, and review cycle

This guide

Risk management policy

The board-approved statement of intent, roles, and appetite that authorizes the program

Risk management policy guide

Risk management plan

The document that applies the program to one project, site, or initiative

How to create a risk management plan

Risk management framework

The design of principles, components, and process the program follows, usually ISO 31000 or COSO

ERM framework development guide

Risk assessment program

The recurring assessment cycle inside the wider program

Risk assessment program guide

EPA Risk Management Program (RMP)

A federal rule under Clean Air Act section 112(r) for facilities holding regulated hazardous substances

EPA RMP rule, separate from enterprise programs

The last row matters. The EPA’s Risk Management Program rule requires facilities that use extremely hazardous substances to file a risk management plan and resubmit it every five years. That is a chemical safety regulation, distinct from the enterprise program described here, although a chemical plant’s program must include it.

On this site the risk management policy authorizes the program, the risk management plan applies it to a single undertaking, and the ERM framework guide covers the design layer. What follows is the whole, which is where the Kimberly-Clark fire found the gaps.

Why the Program Matters More in 2026

The definition matters because most organizations have the documents and lack the program. The AICPA and NC State 2025 State of Risk Oversight surveyed 273 US organizations and found 32 percent rate their risk oversight mature, 45 percent have a chief risk officer, and 57 percent report top risks to the board.

The value verdict is worse. Only 11 percent of finance leaders say risk management gives them a competitive advantage, 64 percent say it provides no or minimal advantage, and 41 percent cite competing priorities and insufficient resources as the main barriers, per NC State’s summary by Mark Beasley, director of the ERM Initiative.

What Is a Risk Management Program

Figure 1. Most US organizations have a risk function; a third have a risk management program they would call mature.

The loss side is easy to quantify. The National Safety Council puts the cost of US work injuries in 2024 at $181.4 billion, or $48,000 per medically consulted injury and $1,540,000 per death. IBM’s 2025 Cost of a Data Breach report puts the average US breach at $10.22 million, a record, while the global average fell to $4.44 million.

Exposure a risk management program covers

2024 to 2026 figure

Source

Work injuries and illnesses

$181.4 billion total; $48,000 per injury

National Safety Council, Injury Facts 2024

Injury count and rate

2.5 million cases; 2.3 per 100 workers, a 20-year low

BLS 2024 data via NSC, January 2026

Data breach

$10.22 million average US cost

IBM Cost of a Data Breach 2025

Single-site insider arson

About $600 million property damage

Federal prosecutors, Kimberly-Clark fire, April 2026

Commercial insurance pricing

Global composite down 6% in Q2 2026; casualty up 2%

Marsh Global Insurance Market Index

Executive top risk

Cyber threats first; 43% rank cyber as top investment

Protiviti Top Risks 2026, 1,500+ executives

Executives know where the exposure sits. Protiviti’s Top Risks 2026 survey of more than 1,500 board members and C-suite leaders ranks cyber threats first and third-party risk second, with 43 percent naming cybersecurity their leading investment area.

The Kimberly-Clark loss was both at once, inside one risk management program’s scope: a third-party employee inside a third-party-run building.

BLS data shows safety improving. Employers reported 2.5 million injuries in 2024, down 3.1 percent, and the rate fell to 2.3 cases per 100 workers, a 20-year low, per the National Safety Council’s analysis. Programs that measure and act on hazards drive that, and our post on why risk management is important sets out the wider case.

The Seven Components Every Program Needs

Having established why, here is what. We build client risk management programs from seven components, each mapping to a clause in ISO 31000 or a principle in COSO ERM, so an auditor can trace each to a standard. Remove one and the others stop working: a register without owners is a list, and controls without reporting are unverified.

Risk management program component

What it contains

Standard reference

1. Governance and appetite

Board charter, risk committee, named executive owner, risk appetite and tolerance statements

ISO 31000 clause 5 leadership; COSO governance and culture

2. Risk process

Scope, identification, analysis, evaluation, treatment, recorded on a fixed cycle

ISO 31000 clause 6; COSO performance

3. Register and indicators

Risk register with owners and ratings, key risk indicators with thresholds

COSO information, communication, and reporting

4. Three lines of accountability

Line management owns risk, risk and compliance functions oversee, internal audit assures

IIA Three Lines Model 2020

5. Controls across domains

Safety management, cyber controls, insurance programme, continuity and emergency plans

OSHA practices; NIST CSF 2.0; NFPA 1600

6. Reporting

Quarterly board report, monthly dashboard, incident and near-miss reporting

ISO 31000 clause 6.7; COSO principle 20

7. Culture and competence

Training, incentives, speak-up channels, consequence management

COSO principles 3 to 5; ISO 31000 clause 5.4

Governance comes first because it decides everything after it. The risk appetite statement tells line managers how much risk they may take without escalation, and the charter tells the board what it will see and when. Without both, the risk register fills with items nobody is authorized to accept or refuse.

The process component is the ISO 31000 loop most readers already know, and the five risk management steps and the risk management lifecycle posts cover it in detail. The program adds what the loop leaves out: who runs it, how often, and what happens when a rating crosses a threshold.

Accountability follows the IIA’s Three Lines Model, updated in July 2020 to drop the word defense. Management in the first line owns and treats risk, risk and compliance functions in the second line set method and challenge, and internal audit in the third line gives independent assurance. The model allows a 50-person company to blend the first two lines.

Culture is the component that failed at the Ontario warehouse, where coworkers noticed the change in the suspect’s behavior and had nowhere to take it. ASIS notes that workplace violence includes sabotage, and a program’s speak-up channel and insider threat assessment are the controls that convert unease into a security decision. Our risk culture guide covers that channel.

Standards That Shape the Program

Components need a source of authority, and six standards supply it. None covers the whole program, which is why we map each to the component of the program it governs rather than picking one and forcing the rest to fit. The table shows the division of labor.

Standard

What it governs

Use in the risk management program

ISO 31000:2018

Principles, framework, and process for managing any risk

The backbone: process design, review cycle, integration with decisions

COSO ERM 2017

Five components and 20 principles linking risk to strategy and performance

Governance, culture, and reporting design; audit-committee language

IIA Three Lines Model 2020

Roles of management, oversight functions, and internal audit

Accountability map and assurance plan

OSHA Recommended Practices

Seven core elements of a safety and health program

Safety component, hazard identification, worker participation

NIST CSF 2.0

Six functions: govern, identify, protect, detect, respond, recover

Cyber component and board cyber reporting

NFPA 1600 and Ready.gov

Continuity, emergency, and crisis management program requirements

Continuity and emergency component; tabletop exercises

COSO’s five components, governance and culture, strategy and objective-setting, performance, review and revision, and information, communication and reporting, are the ones boards recognize, and our COSO ERM guide walks through all 20 principles. ISO 31000 is shorter and process-led, and the two combine well: COSO for the governance layer, ISO for the operating loop.

The domain standards plug into component five. OSHA’s recommended practices list management leadership, worker participation, hazard identification, hazard prevention, training, program evaluation, and multi-employer coordination. NIST CSF 2.0 added a Govern function in 2024 so that cyber risk reports in the same language as the rest of the ERM framework.

Continuity has its own standard. NFPA 1600 sets the requirements for continuity, emergency, and crisis management programs, and Ready.gov’s business guidance gives a free implementation path for small firms. The multi-employer clause in OSHA’s list is the one the Kimberly-Clark case makes concrete: the building owner, the brand, and the operator each held part of the program.

Insurance, Safety, Cyber, and Continuity as One Control Set

Component five of the program is where money changes hands, so it gets its own section. Insurance transfers the financial part of a risk, safety and cyber controls reduce likelihood, and continuity plans reduce impact. A program that runs the four separately buys cover for risks it could have controlled and controls risks it should have insured.

What Is a Risk Management Program

Figure 2. Marsh’s Q2 2026 index: buyers with a documented risk management program are renewing property and cyber cover at lower rates; casualty is the exception.

The insurance market is rewarding documented programs. Marsh’s Global Insurance Market Index for Q2 2026 shows global composite rates down 6 percent, the eighth consecutive quarterly decline, with property down 12 percent and cyber down 4 percent.

John Donnelly, Marsh’s president of global placement, noted insurers competing on broader coverage and lower deductibles as well as price.

Casualty is the exception at plus 2 percent, and US composite rates fell only 2 percent, per Insurance Journal’s coverage. That divergence is the program’s cue: liability exposure needs control evidence at renewal, while property and cyber buyers should be trading rate reductions for higher limits or lower retentions.

Domain

Primary control set

Financial backstop

Risk management program evidence at renewal

Workplace safety

OSHA seven-element safety program; hazard register; training records

Workers’ compensation; employers’ liability

Incident rate trend, DART cases, inspection closure

Cyber

NIST CSF 2.0 controls; MFA; backups; incident response plan

Cyber liability with business interruption

Control attestation, tabletop dates, patch metrics

Property and fire

Fire risk assessment; sprinkler design to fuel load; hot-work permits

Property all risks; business interruption

Fire risk assessment date, sprinkler test records, storage plan

Third parties

Contract clauses; access control; contractor vetting

Contractual indemnity; contingent BI cover

Vendor scorecards, site access logs, insurance certificates

Continuity

BIA, recovery strategies, alternate sites, crisis communications

Business interruption; contingent BI

Exercise reports, recovery time objectives met in tests

Safety is the largest cost line. NSC’s $181.4 billion splits into $64.5 billion of administrative expense, $54.9 billion of wage and productivity loss, $36.8 billion of medical cost, and $15.5 billion of employers’ uninsured cost, with fire losses at $3.8 billion. A program tracks its own share of each through the KPI dashboard and the KRI set.

What Is a Risk Management Program

Figure 3. Administrative and productivity costs outweigh medical costs in the NSC’s 2024 work injury total.

Fire protection needs a note after Ontario. ASIS found the paper-goods fuel load and six simultaneous ignitions defeated a sprinkler design built for one accidental fire. A fire risk assessment that considers deliberate ignition, and a business impact analysis that values a single distribution center at 3 percent of regional sales, would have changed the design brief and insurance limits.

Cyber and continuity share an incident plan. The incident response plan template covers the first 72 hours, the business continuity management program covers recovery, and the cybersecurity risk management post maps controls to NIST. The program’s job is to keep the three on one calendar with one owner.

How to Build a Risk Management Program in 36 Months

The components and standards above are the design; this section is the sequence. Ncontracts’ build guide for financial institutions proposes four phases over 18 to 36 months, and we use the same shape for clients outside banking because the dependencies are the same: governance before infrastructure, infrastructure before operations, operations before analytics.

What Is a Risk Management Program

Figure 4. The four build phases. Most risk management programs that fail skipped the first three months and bought software in month one.

Phase

Risk management program deliverables

Exit test

Months 1 to 3: Governance

Board-approved charter, risk appetite statement, risk committee terms of reference, named program owner, first enterprise risk assessment

Board minutes record approval; appetite statement has numeric tolerances

Months 4 to 9: Infrastructure

Risk management policy, risk register, KRI set with thresholds, reporting template, tool selection

First quarterly report delivered to the board on time

Months 10 to 18: Operations

Business-unit assessments, control documentation, incident and near-miss reporting, staff training, control testing

Every top-10 risk has a tested control and an owner

Months 19 to 36: Maturity

Scenario and stress testing, analytics, integration with strategy and budgeting, external assurance

Risk input recorded in at least one strategic decision

Phase one produces paper, and that is correct. The charter and appetite statement are the only two documents the rest of the program cannot function without, and they take a board cycle to approve. Use the risk matrix template to agree rating scales in the same meeting, because every later assessment inherits them.

Phase two is where most programs buy software too early. A register in a spreadsheet with 30 well-owned risks beats a platform with 300 unowned ones, and the complete risk assessment guide shows how to populate it. Select a tool once the register, KRIs, and report format have survived two quarterly cycles on paper.

Phase three is the operational test, and it is where the risk management program stops being a set of documents and starts producing records. The deliverables that prove the program is running, and that an auditor will ask for, are short enough to list:

  • A quarterly board risk report with the top 10 risks, trend, appetite breaches, and actions
  • A control register showing owner, test date, and result for every top-10 risk
  • An incident and near-miss log with root cause and closure dates
  • Training records for every risk owner and first-line manager
  • Evidence of one tabletop exercise covering a cyber, a fire, and a supplier scenario

Phase four connects the program to money. Stress tests, operational risk scenarios, and compliance risk analysis feed the budget and the strategy cycle, which is the point at which the 11 percent who report a competitive advantage separate from the 64 percent who do not. The integrated risk management approach post explains that integration step.

Measuring Whether the Program Works

A risk management program needs a scoreboard. The measures below are the ones we put in front of audit committees, and each has a source in the program’s own records rather than in opinion. Report them quarterly, trend them for eight quarters, and treat any measure that has not moved as evidence the component behind it is not operating.

Measure

How to calculate it

What a healthy risk management program shows

Risk ownership

Top-20 risks with a named owner who reviewed the rating this quarter / 20

100% for four consecutive quarters

Control effectiveness

Controls tested and passed / controls due for test

Above 90%, with failures re-tested within 60 days

Appetite breaches

KRIs outside tolerance at quarter end, and days to return

Falling count; every breach with a decision recorded

Incident learning

Root causes closed within 90 days / incidents logged

Above 80%; repeat causes below 10%

Assurance coverage

Top-10 risks with third-line assurance in the last 24 months / 10

At least 8 of 10

Decision influence

Strategic or capital decisions with recorded risk input / total decisions

Rising each year; the 11% versus 64% test

Two measures matter more than the rest of the program’s scoreboard. Ownership, because the AICPA data shows 41 percent of organizations blame competing priorities, meaning nobody owns the risk. Decision influence, because it is the only measure that separates a program that protects value from one that only reports it, as the risk management value guide argues.

Treatment quality inside the program also needs a measure. Each top-10 risk should carry a chosen response from the four available, and the risk mitigation guide and risk management techniques posts cover the options. Record the response, the control measure that delivers it, and the residual rating; a register that records only the inherent rating has skipped the step that costs money.

Questions Boards and Executives Keep Asking About a Risk Management Program

What is a risk management program in simple terms?

A risk management program is the permanent system an organization runs to find risks to its objectives, rate them, decide what to do about each, check that the decision worked, and report the results. It includes the people who own risks, the process they follow, the register they keep, and the controls, insurance, and plans that respond to each risk.

What is the difference between a risk management program and a risk management plan?

The risk management program is the standing capability that runs across the whole organization every year; the plan is a document that applies the program to one project, site, or initiative for a defined period. A company has one risk management program and many risk management plans, and the program’s policy sets the rules every plan follows.

What are the key components of a risk management program?

A risk management program has seven components: governance with a charter and risk appetite, a documented risk process, a register with key risk indicators, three lines of accountability, controls across safety, cyber, insurance, and continuity, regular reporting, and a culture with training and speak-up channels. Each component maps to a clause in ISO 31000 or a principle in COSO ERM.

Which standard should a risk management program follow?

Use ISO 31000:2018 for the process and COSO ERM 2017 for the governance and reporting layer, then plug in domain standards where the risk lives: OSHA’s recommended practices for safety, NIST CSF 2.0 for cyber, and NFPA 1600 for continuity. A risk management program that follows one standard alone leaves either the board layer or the operating layer undefined.

How long does it take to build a risk management program?

Plan for 18 to 36 months in four phases: governance in months 1 to 3, infrastructure in months 4 to 9, operations in months 10 to 18, and maturity from month 19. A risk management program can produce its first board report within nine months, but decision influence and external assurance take two to three years to become routine.

Is a risk management program required by law?

No general law requires a risk management program, but many rules require its parts. OSHA requires hazard control and recordkeeping, the SEC requires cyber incident disclosure and risk oversight disclosure for public companies, the EPA’s Risk Management Program rule applies to facilities with regulated hazardous substances, and bank regulators expect enterprise risk management at supervised institutions.

How much does a risk management program cost?

The cost of a risk management program is mostly people: a program owner, part of each risk owner’s time, and internal audit hours. Software ranges from a spreadsheet to six-figure platforms; spend nothing on tools until the register has run on paper for two quarters. Measure it against the exposure: work injuries alone cost US employers $1,120 per worker in 2024.

Lessons from Programs That Failed

The failures below come from risk management programs we have reviewed and from the public record, and each pairs with the cheapest fix that would have prevented it. The pattern is consistent: the documents existed and the component behind them did not operate.

Failure

What it looked like

Fix

Software before governance

A platform full of risks with no appetite statement to rate them against

Charter and appetite approved before any tool is selected

Register without owners

Hundreds of risks, reviewed by the risk team, changed by nobody

Cap the register at what named owners will review quarterly

Third-party blind spot

Operator staff inside a leased building, outside the insider-threat program

Extend vetting, access control, and speak-up channels to contractors

Controls designed for one scenario

Sprinklers sized for accidental fire, defeated by six ignitions

Fire risk assessment includes deliberate ignition and fuel load

Insurance treated as the program

Cover bought annually with no control evidence, renewed at rising rates

Control evidence pack at every renewal; trade rate for limit

Reports without decisions

Quarterly pack presented and filed; no recorded action

Every board report ends with decisions requested and taken

No exercise

Continuity plan written in 2022, never tested

One tabletop a year across cyber, fire, and supplier loss

Emerging Threats Your Program Is Not Ready For

Ideologically motivated insider sabotage is the threat the Ontario fire put on the register. ASIS notes the suspect framed the arson as part of an anti-corporate narrative and that coworkers saw the shift two weeks earlier. A risk management program built around theft and negligence will need behavioral indicators, contractor coverage, and a reporting channel that staff trust.

AI governance is the second gap. IBM’s 2025 report found 63 percent of breached organizations had no AI governance policy and 97 percent of those with an AI-related incident lacked AI access controls. By 2027, expect audit committees to ask where AI risk sits in the program’s register and which line owns it.

Insurance conditions will not stay soft. Eight quarters of falling rates have given buyers with documented programs the chance to raise limits cheaply, and casualty is already rising. Use the current cycle to lock in cover that matches the business impact analysis, because the next hard market will price control evidence again.

Organizations that want a risk management program designed, benchmarked against ISO 31000 and COSO, or rebuilt from a stalled register can send us the current policy and register. We return the charter, appetite statement, component gap analysis, and a 36-month build plan with owners and exit tests.

The engagement options are listed on our services page, and a short message through the contact page gets a scoped proposal within five working days. The program that would have connected two worried coworkers to a security decision costs less than one night of fire.