A risk management program is the permanent structure an organization uses to find, rate, treat, monitor, and report the risks that threaten its objectives. It combines governance, a documented process, a risk register with indicators, assigned owners across three lines, and controls spanning safety, cyber, insurance, and continuity, then reviews all of it on a fixed cycle.
At about 12:15 a.m. on April 7, 2026, an employee of the logistics contractor NFI Industries set fires in six places inside a 1.2 million square foot Kimberly-Clark distribution center in Ontario, California. ASIS International’s review of the FBI affidavit records that the simultaneous ignitions overwhelmed the sprinkler system’s water pressure within minutes.
About 20 employees evacuated on the alarm, 175 firefighters worked for nearly 12 hours, and the building was a total loss. Federal prosecutors put the property damage at $600 million against a building valued at $156 million, and Bloomberg Intelligence estimated the loss could affect 3 percent of Kimberly-Clark’s West Coast sales.
|
What Is a Risk Management Program: Key Takeaways |
|
A risk management program is the standing set of governance, people, process, and tools an organization runs to identify, assess, treat, monitor, and report risk against its objectives; the plan, policy, and framework are documents inside it. |
|
Seven components make a program work: governance and appetite, a risk process, a register with indicators, three lines of accountability, controls across safety, cyber, insurance, and continuity, reporting, and culture. |
|
ISO 31000:2018, COSO ERM 2017, the IIA Three Lines Model, OSHA’s safety management practices, NIST CSF 2.0, and NFPA 1600 each cover one part of the program; no single standard covers all of it. |
|
Only 32% of 273 US organizations rate their risk oversight mature and 64% say it gives no or minimal advantage (AICPA and NC State, 2025), so most programs exist on paper more than in practice. |
|
Work injuries cost the US $181.4 billion in 2024 (NSC), a US data breach averages $10.22 million (IBM 2025), and one insider arson fire cost about $600 million in April 2026. |
|
A credible program takes 18 to 36 months to build in four phases, and the first deliverable is a board-approved charter and appetite statement, not a software licence. |
Two coworkers had noticed the suspect’s rhetoric change two weeks before the fire, and his own social media showed the motive. A risk management program is what connects those signals, the sprinkler design, the third-party contract, the insurance schedule, and the recovery plan into one system. What follows explains what a risk management program is and how to build one.
What Is a Risk Management Program?
Start with the distinction that trips up most searches. A program is the standing organizational capability; a plan, a policy, and a framework are documents that live inside it. ISO 31000:2018 describes the framework and the process, COSO ERM 2017 describes the components and principles, and neither uses the word program for the whole, so the term needs defining.
|
Term |
What it is in the risk management program |
Where it lives on this site |
|
Risk management program |
The standing structure: governance, people, process, register, controls, reporting, and review cycle |
This guide |
|
Risk management policy |
The board-approved statement of intent, roles, and appetite that authorizes the program |
Risk management policy guide |
|
Risk management plan |
The document that applies the program to one project, site, or initiative |
How to create a risk management plan |
|
Risk management framework |
The design of principles, components, and process the program follows, usually ISO 31000 or COSO |
ERM framework development guide |
|
Risk assessment program |
The recurring assessment cycle inside the wider program |
Risk assessment program guide |
|
EPA Risk Management Program (RMP) |
A federal rule under Clean Air Act section 112(r) for facilities holding regulated hazardous substances |
EPA RMP rule, separate from enterprise programs |
The last row matters. The EPA’s Risk Management Program rule requires facilities that use extremely hazardous substances to file a risk management plan and resubmit it every five years. That is a chemical safety regulation, distinct from the enterprise program described here, although a chemical plant’s program must include it.
On this site the risk management policy authorizes the program, the risk management plan applies it to a single undertaking, and the ERM framework guide covers the design layer. What follows is the whole, which is where the Kimberly-Clark fire found the gaps.
Why the Program Matters More in 2026
The definition matters because most organizations have the documents and lack the program. The AICPA and NC State 2025 State of Risk Oversight surveyed 273 US organizations and found 32 percent rate their risk oversight mature, 45 percent have a chief risk officer, and 57 percent report top risks to the board.
The value verdict is worse. Only 11 percent of finance leaders say risk management gives them a competitive advantage, 64 percent say it provides no or minimal advantage, and 41 percent cite competing priorities and insufficient resources as the main barriers, per NC State’s summary by Mark Beasley, director of the ERM Initiative.

Figure 1. Most US organizations have a risk function; a third have a risk management program they would call mature.
The loss side is easy to quantify. The National Safety Council puts the cost of US work injuries in 2024 at $181.4 billion, or $48,000 per medically consulted injury and $1,540,000 per death. IBM’s 2025 Cost of a Data Breach report puts the average US breach at $10.22 million, a record, while the global average fell to $4.44 million.
|
Exposure a risk management program covers |
2024 to 2026 figure |
Source |
|
Work injuries and illnesses |
$181.4 billion total; $48,000 per injury |
National Safety Council, Injury Facts 2024 |
|
Injury count and rate |
2.5 million cases; 2.3 per 100 workers, a 20-year low |
BLS 2024 data via NSC, January 2026 |
|
Data breach |
$10.22 million average US cost |
IBM Cost of a Data Breach 2025 |
|
Single-site insider arson |
About $600 million property damage |
Federal prosecutors, Kimberly-Clark fire, April 2026 |
|
Commercial insurance pricing |
Global composite down 6% in Q2 2026; casualty up 2% |
Marsh Global Insurance Market Index |
|
Executive top risk |
Cyber threats first; 43% rank cyber as top investment |
Protiviti Top Risks 2026, 1,500+ executives |
Executives know where the exposure sits. Protiviti’s Top Risks 2026 survey of more than 1,500 board members and C-suite leaders ranks cyber threats first and third-party risk second, with 43 percent naming cybersecurity their leading investment area.
The Kimberly-Clark loss was both at once, inside one risk management program’s scope: a third-party employee inside a third-party-run building.
BLS data shows safety improving. Employers reported 2.5 million injuries in 2024, down 3.1 percent, and the rate fell to 2.3 cases per 100 workers, a 20-year low, per the National Safety Council’s analysis. Programs that measure and act on hazards drive that, and our post on why risk management is important sets out the wider case.
The Seven Components Every Program Needs
Having established why, here is what. We build client risk management programs from seven components, each mapping to a clause in ISO 31000 or a principle in COSO ERM, so an auditor can trace each to a standard. Remove one and the others stop working: a register without owners is a list, and controls without reporting are unverified.
|
Risk management program component |
What it contains |
Standard reference |
|
1. Governance and appetite |
Board charter, risk committee, named executive owner, risk appetite and tolerance statements |
ISO 31000 clause 5 leadership; COSO governance and culture |
|
2. Risk process |
Scope, identification, analysis, evaluation, treatment, recorded on a fixed cycle |
ISO 31000 clause 6; COSO performance |
|
3. Register and indicators |
Risk register with owners and ratings, key risk indicators with thresholds |
COSO information, communication, and reporting |
|
4. Three lines of accountability |
Line management owns risk, risk and compliance functions oversee, internal audit assures |
IIA Three Lines Model 2020 |
|
5. Controls across domains |
Safety management, cyber controls, insurance programme, continuity and emergency plans |
OSHA practices; NIST CSF 2.0; NFPA 1600 |
|
6. Reporting |
Quarterly board report, monthly dashboard, incident and near-miss reporting |
ISO 31000 clause 6.7; COSO principle 20 |
|
7. Culture and competence |
Training, incentives, speak-up channels, consequence management |
COSO principles 3 to 5; ISO 31000 clause 5.4 |
Governance comes first because it decides everything after it. The risk appetite statement tells line managers how much risk they may take without escalation, and the charter tells the board what it will see and when. Without both, the risk register fills with items nobody is authorized to accept or refuse.
The process component is the ISO 31000 loop most readers already know, and the five risk management steps and the risk management lifecycle posts cover it in detail. The program adds what the loop leaves out: who runs it, how often, and what happens when a rating crosses a threshold.
Accountability follows the IIA’s Three Lines Model, updated in July 2020 to drop the word defense. Management in the first line owns and treats risk, risk and compliance functions in the second line set method and challenge, and internal audit in the third line gives independent assurance. The model allows a 50-person company to blend the first two lines.
Culture is the component that failed at the Ontario warehouse, where coworkers noticed the change in the suspect’s behavior and had nowhere to take it. ASIS notes that workplace violence includes sabotage, and a program’s speak-up channel and insider threat assessment are the controls that convert unease into a security decision. Our risk culture guide covers that channel.
Standards That Shape the Program
Components need a source of authority, and six standards supply it. None covers the whole program, which is why we map each to the component of the program it governs rather than picking one and forcing the rest to fit. The table shows the division of labor.
|
Standard |
What it governs |
Use in the risk management program |
|
ISO 31000:2018 |
Principles, framework, and process for managing any risk |
The backbone: process design, review cycle, integration with decisions |
|
COSO ERM 2017 |
Five components and 20 principles linking risk to strategy and performance |
Governance, culture, and reporting design; audit-committee language |
|
IIA Three Lines Model 2020 |
Roles of management, oversight functions, and internal audit |
Accountability map and assurance plan |
|
OSHA Recommended Practices |
Seven core elements of a safety and health program |
Safety component, hazard identification, worker participation |
|
NIST CSF 2.0 |
Six functions: govern, identify, protect, detect, respond, recover |
Cyber component and board cyber reporting |
|
NFPA 1600 and Ready.gov |
Continuity, emergency, and crisis management program requirements |
Continuity and emergency component; tabletop exercises |
COSO’s five components, governance and culture, strategy and objective-setting, performance, review and revision, and information, communication and reporting, are the ones boards recognize, and our COSO ERM guide walks through all 20 principles. ISO 31000 is shorter and process-led, and the two combine well: COSO for the governance layer, ISO for the operating loop.
The domain standards plug into component five. OSHA’s recommended practices list management leadership, worker participation, hazard identification, hazard prevention, training, program evaluation, and multi-employer coordination. NIST CSF 2.0 added a Govern function in 2024 so that cyber risk reports in the same language as the rest of the ERM framework.
Continuity has its own standard. NFPA 1600 sets the requirements for continuity, emergency, and crisis management programs, and Ready.gov’s business guidance gives a free implementation path for small firms. The multi-employer clause in OSHA’s list is the one the Kimberly-Clark case makes concrete: the building owner, the brand, and the operator each held part of the program.
Insurance, Safety, Cyber, and Continuity as One Control Set
Component five of the program is where money changes hands, so it gets its own section. Insurance transfers the financial part of a risk, safety and cyber controls reduce likelihood, and continuity plans reduce impact. A program that runs the four separately buys cover for risks it could have controlled and controls risks it should have insured.

Figure 2. Marsh’s Q2 2026 index: buyers with a documented risk management program are renewing property and cyber cover at lower rates; casualty is the exception.
The insurance market is rewarding documented programs. Marsh’s Global Insurance Market Index for Q2 2026 shows global composite rates down 6 percent, the eighth consecutive quarterly decline, with property down 12 percent and cyber down 4 percent.
John Donnelly, Marsh’s president of global placement, noted insurers competing on broader coverage and lower deductibles as well as price.
Casualty is the exception at plus 2 percent, and US composite rates fell only 2 percent, per Insurance Journal’s coverage. That divergence is the program’s cue: liability exposure needs control evidence at renewal, while property and cyber buyers should be trading rate reductions for higher limits or lower retentions.
|
Domain |
Primary control set |
Financial backstop |
Risk management program evidence at renewal |
|
Workplace safety |
OSHA seven-element safety program; hazard register; training records |
Workers’ compensation; employers’ liability |
Incident rate trend, DART cases, inspection closure |
|
Cyber |
NIST CSF 2.0 controls; MFA; backups; incident response plan |
Cyber liability with business interruption |
Control attestation, tabletop dates, patch metrics |
|
Property and fire |
Fire risk assessment; sprinkler design to fuel load; hot-work permits |
Property all risks; business interruption |
Fire risk assessment date, sprinkler test records, storage plan |
|
Third parties |
Contract clauses; access control; contractor vetting |
Contractual indemnity; contingent BI cover |
Vendor scorecards, site access logs, insurance certificates |
|
Continuity |
BIA, recovery strategies, alternate sites, crisis communications |
Business interruption; contingent BI |
Exercise reports, recovery time objectives met in tests |
Safety is the largest cost line. NSC’s $181.4 billion splits into $64.5 billion of administrative expense, $54.9 billion of wage and productivity loss, $36.8 billion of medical cost, and $15.5 billion of employers’ uninsured cost, with fire losses at $3.8 billion. A program tracks its own share of each through the KPI dashboard and the KRI set.

Figure 3. Administrative and productivity costs outweigh medical costs in the NSC’s 2024 work injury total.
Fire protection needs a note after Ontario. ASIS found the paper-goods fuel load and six simultaneous ignitions defeated a sprinkler design built for one accidental fire. A fire risk assessment that considers deliberate ignition, and a business impact analysis that values a single distribution center at 3 percent of regional sales, would have changed the design brief and insurance limits.
Cyber and continuity share an incident plan. The incident response plan template covers the first 72 hours, the business continuity management program covers recovery, and the cybersecurity risk management post maps controls to NIST. The program’s job is to keep the three on one calendar with one owner.
How to Build a Risk Management Program in 36 Months
The components and standards above are the design; this section is the sequence. Ncontracts’ build guide for financial institutions proposes four phases over 18 to 36 months, and we use the same shape for clients outside banking because the dependencies are the same: governance before infrastructure, infrastructure before operations, operations before analytics.

Figure 4. The four build phases. Most risk management programs that fail skipped the first three months and bought software in month one.
|
Phase |
Risk management program deliverables |
Exit test |
|
Months 1 to 3: Governance |
Board-approved charter, risk appetite statement, risk committee terms of reference, named program owner, first enterprise risk assessment |
Board minutes record approval; appetite statement has numeric tolerances |
|
Months 4 to 9: Infrastructure |
Risk management policy, risk register, KRI set with thresholds, reporting template, tool selection |
First quarterly report delivered to the board on time |
|
Months 10 to 18: Operations |
Business-unit assessments, control documentation, incident and near-miss reporting, staff training, control testing |
Every top-10 risk has a tested control and an owner |
|
Months 19 to 36: Maturity |
Scenario and stress testing, analytics, integration with strategy and budgeting, external assurance |
Risk input recorded in at least one strategic decision |
Phase one produces paper, and that is correct. The charter and appetite statement are the only two documents the rest of the program cannot function without, and they take a board cycle to approve. Use the risk matrix template to agree rating scales in the same meeting, because every later assessment inherits them.
Phase two is where most programs buy software too early. A register in a spreadsheet with 30 well-owned risks beats a platform with 300 unowned ones, and the complete risk assessment guide shows how to populate it. Select a tool once the register, KRIs, and report format have survived two quarterly cycles on paper.
Phase three is the operational test, and it is where the risk management program stops being a set of documents and starts producing records. The deliverables that prove the program is running, and that an auditor will ask for, are short enough to list:
- A quarterly board risk report with the top 10 risks, trend, appetite breaches, and actions
- A control register showing owner, test date, and result for every top-10 risk
- An incident and near-miss log with root cause and closure dates
- Training records for every risk owner and first-line manager
- Evidence of one tabletop exercise covering a cyber, a fire, and a supplier scenario
Phase four connects the program to money. Stress tests, operational risk scenarios, and compliance risk analysis feed the budget and the strategy cycle, which is the point at which the 11 percent who report a competitive advantage separate from the 64 percent who do not. The integrated risk management approach post explains that integration step.
Measuring Whether the Program Works
A risk management program needs a scoreboard. The measures below are the ones we put in front of audit committees, and each has a source in the program’s own records rather than in opinion. Report them quarterly, trend them for eight quarters, and treat any measure that has not moved as evidence the component behind it is not operating.
|
Measure |
How to calculate it |
What a healthy risk management program shows |
|
Risk ownership |
Top-20 risks with a named owner who reviewed the rating this quarter / 20 |
100% for four consecutive quarters |
|
Control effectiveness |
Controls tested and passed / controls due for test |
Above 90%, with failures re-tested within 60 days |
|
Appetite breaches |
KRIs outside tolerance at quarter end, and days to return |
Falling count; every breach with a decision recorded |
|
Incident learning |
Root causes closed within 90 days / incidents logged |
Above 80%; repeat causes below 10% |
|
Assurance coverage |
Top-10 risks with third-line assurance in the last 24 months / 10 |
At least 8 of 10 |
|
Decision influence |
Strategic or capital decisions with recorded risk input / total decisions |
Rising each year; the 11% versus 64% test |
Two measures matter more than the rest of the program’s scoreboard. Ownership, because the AICPA data shows 41 percent of organizations blame competing priorities, meaning nobody owns the risk. Decision influence, because it is the only measure that separates a program that protects value from one that only reports it, as the risk management value guide argues.
Treatment quality inside the program also needs a measure. Each top-10 risk should carry a chosen response from the four available, and the risk mitigation guide and risk management techniques posts cover the options. Record the response, the control measure that delivers it, and the residual rating; a register that records only the inherent rating has skipped the step that costs money.
Questions Boards and Executives Keep Asking About a Risk Management Program
What is a risk management program in simple terms?
A risk management program is the permanent system an organization runs to find risks to its objectives, rate them, decide what to do about each, check that the decision worked, and report the results. It includes the people who own risks, the process they follow, the register they keep, and the controls, insurance, and plans that respond to each risk.
What is the difference between a risk management program and a risk management plan?
The risk management program is the standing capability that runs across the whole organization every year; the plan is a document that applies the program to one project, site, or initiative for a defined period. A company has one risk management program and many risk management plans, and the program’s policy sets the rules every plan follows.
What are the key components of a risk management program?
A risk management program has seven components: governance with a charter and risk appetite, a documented risk process, a register with key risk indicators, three lines of accountability, controls across safety, cyber, insurance, and continuity, regular reporting, and a culture with training and speak-up channels. Each component maps to a clause in ISO 31000 or a principle in COSO ERM.
Which standard should a risk management program follow?
Use ISO 31000:2018 for the process and COSO ERM 2017 for the governance and reporting layer, then plug in domain standards where the risk lives: OSHA’s recommended practices for safety, NIST CSF 2.0 for cyber, and NFPA 1600 for continuity. A risk management program that follows one standard alone leaves either the board layer or the operating layer undefined.
How long does it take to build a risk management program?
Plan for 18 to 36 months in four phases: governance in months 1 to 3, infrastructure in months 4 to 9, operations in months 10 to 18, and maturity from month 19. A risk management program can produce its first board report within nine months, but decision influence and external assurance take two to three years to become routine.
Is a risk management program required by law?
No general law requires a risk management program, but many rules require its parts. OSHA requires hazard control and recordkeeping, the SEC requires cyber incident disclosure and risk oversight disclosure for public companies, the EPA’s Risk Management Program rule applies to facilities with regulated hazardous substances, and bank regulators expect enterprise risk management at supervised institutions.
How much does a risk management program cost?
The cost of a risk management program is mostly people: a program owner, part of each risk owner’s time, and internal audit hours. Software ranges from a spreadsheet to six-figure platforms; spend nothing on tools until the register has run on paper for two quarters. Measure it against the exposure: work injuries alone cost US employers $1,120 per worker in 2024.
Lessons from Programs That Failed
The failures below come from risk management programs we have reviewed and from the public record, and each pairs with the cheapest fix that would have prevented it. The pattern is consistent: the documents existed and the component behind them did not operate.
|
Failure |
What it looked like |
Fix |
|
Software before governance |
A platform full of risks with no appetite statement to rate them against |
Charter and appetite approved before any tool is selected |
|
Register without owners |
Hundreds of risks, reviewed by the risk team, changed by nobody |
Cap the register at what named owners will review quarterly |
|
Third-party blind spot |
Operator staff inside a leased building, outside the insider-threat program |
Extend vetting, access control, and speak-up channels to contractors |
|
Controls designed for one scenario |
Sprinklers sized for accidental fire, defeated by six ignitions |
Fire risk assessment includes deliberate ignition and fuel load |
|
Insurance treated as the program |
Cover bought annually with no control evidence, renewed at rising rates |
Control evidence pack at every renewal; trade rate for limit |
|
Reports without decisions |
Quarterly pack presented and filed; no recorded action |
Every board report ends with decisions requested and taken |
|
No exercise |
Continuity plan written in 2022, never tested |
One tabletop a year across cyber, fire, and supplier loss |
Emerging Threats Your Program Is Not Ready For
Ideologically motivated insider sabotage is the threat the Ontario fire put on the register. ASIS notes the suspect framed the arson as part of an anti-corporate narrative and that coworkers saw the shift two weeks earlier. A risk management program built around theft and negligence will need behavioral indicators, contractor coverage, and a reporting channel that staff trust.
AI governance is the second gap. IBM’s 2025 report found 63 percent of breached organizations had no AI governance policy and 97 percent of those with an AI-related incident lacked AI access controls. By 2027, expect audit committees to ask where AI risk sits in the program’s register and which line owns it.
Insurance conditions will not stay soft. Eight quarters of falling rates have given buyers with documented programs the chance to raise limits cheaply, and casualty is already rising. Use the current cycle to lock in cover that matches the business impact analysis, because the next hard market will price control evidence again.
Organizations that want a risk management program designed, benchmarked against ISO 31000 and COSO, or rebuilt from a stalled register can send us the current policy and register. We return the charter, appetite statement, component gap analysis, and a 36-month build plan with owners and exit tests.
The engagement options are listed on our services page, and a short message through the contact page gets a scoped proposal within five working days. The program that would have connected two worried coworkers to a security decision costs less than one night of fire.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.