BLOG
The Top Five Risk Management Frameworks and When Each Earns Its Place
Published 31 August 2026 · By P Larner
Frameworks & Standards#ISO 27005#FAIR#risk frameworks#ISO 31000#NIST CSF#COSO ERM
The Top Five Risk Management Frameworks and When Each Earns Its Place
Illustration for: The Top Five Risk Management Frameworks and When Each Earns Its Place
Every organisation that told me it had no risk management framework turned out to have three. One in the information security team, inherited from an old certification push. One in finance, buried in the audit committee papers. One in the project office, where somebody had drawn a five by five grid in a spreadsheet and nobody had questioned it since. None of them talked to each other, and the board saw whichever one shouted loudest that quarter.
Choosing a framework deliberately is not an act of bureaucracy. It is the decision about what your organisation means by the word risk, and who gets to say a number is too high. Here are the five that matter, what each one is genuinely good at, and where each one is the wrong tool.
What a framework actually buys you
A framework does not find your risks. People find risks, and they will find them whether or not you have bought a standard. What a framework gives you is a shared structure for arguing about them, which means consistent language, a defensible method, and a record that shows how a decision was reached rather than merely what it was.
The test is whether it survives contact with a real decision
If your framework produces a rating that nobody uses to spend money, defer a release, or accept a supplier, it is decoration. Every framework below is judged here on that basis.
ISO 31000 gives you the vocabulary
ISO 31000 is the closest thing risk management has to a constitution. It defines risk as the effect of uncertainty on objectives, sets out principles, and separates the framework, meaning how risk management is governed, from the process, meaning how a single risk is assessed and treated.
It is not certifiable and that is the point
There is no ISO 31000 badge to hang in reception. It is guidance, deliberately generic, and it applies to safety, finance, supply chain and cyber without modification. If your organisation cannot agree on what appetite, tolerance and likelihood mean, this is where you start, and an earlier post in this series on getting those terms straight leans heavily on it.
Where ISO 31000 falls short
It will not tell you which controls to implement, how to score anything, or what good looks like in a technical environment. Organisations that adopt ISO 31000 alone tend to produce beautifully worded policies and empty risk registers.
NIST CSF 2.0 gives you the conversation with the board
The Cyber Security Framework organises cyber risk into six functions, Govern, Identify, Protect, Detect, Respond and Recover, and expresses maturity through tiers and profiles rather than pass or fail. Version 2.0 added Govern, which was overdue, because most failures I have investigated were governance failures wearing a technical costume.
Its real strength is communication
A current profile against a target profile is the single most effective board slide in the discipline, because it shows a gap, a direction and a cost without requiring anyone to understand a control identifier. It also maps cleanly onto other control sets, which makes it useful as a translation layer when you are running ISO 27001 and answering American customer questionnaires at the same time.
Where NIST CSF 2.0 falls short
It is voluntary, American in origin, and cyber only. It says nothing about your fraud exposure, your obsolescent plant or your single supplier in a flood plain.
ISO 27005 gives you a repeatable method
ISO 27005 is the information security risk management companion to ISO 27001. It is the only entry on this list that answers the question most people actually ask, which is how do I do this, step by step, in a way an auditor will accept.
It works because it is boring
Establish context, identify risks against assets or scenarios, analyse, evaluate against criteria, treat, accept, communicate, monitor. The 2022 revision sensibly allows both asset-based and event-based identification, which matters because asset-based analysis on a large estate collapses under its own weight.
Where ISO 27005 falls short
It assumes you already have an information security management system, and its output is qualitative by default, which puts you back in the world of high, medium and low that an earlier post on risk matrices treats with some suspicion.
COSO ERM keeps risk in the language of the business
COSO ERM is the framework your audit committee already knows, even if your security team has never heard of it. Its 2017 revision ties risk to strategy and performance across five components and twenty principles, and it treats risk as something that affects whether the organisation achieves what it set out to achieve, not as a catalogue of bad things.
Use it when you need the finance director on side
COSO speaks in objectives, portfolio view and performance variance. That is the native language of the people who approve budgets, and a cyber risk expressed in it will be understood in a way that a CVSS score never will.
Where COSO ERM falls short
It is heavy, it was born in internal control and financial reporting, and it offers almost nothing operationally useful to an engineer trying to decide whether an unpatched historian is acceptable this quarter.
FAIR gives you numbers you can defend
Factor Analysis of Information Risk decomposes a risk into loss event frequency and loss magnitude, then decomposes those again until you reach quantities a knowledgeable person can estimate as a range. Feed the ranges through a simulation and you get a loss distribution rather than a colour.
It changes the conversation from ranking to spending
Once a risk is expressed as a range of annual loss, comparing it against the cost of a control becomes arithmetic rather than rhetoric. An earlier post in this series on running a Monte Carlo assessment walks through the mechanics.
Where FAIR falls short
It is demanding. It needs calibrated estimators, decent incident data and a sponsor with patience, and applied badly it produces false precision that is more dangerous than an honest amber. Use it on your top ten risks, not your top two hundred.
Horizontal ladder of five framework roles from vocabulary through to numbers
The five sit at different depths rather than in competition. Language is ISO 31000, outcomes is NIST CSF 2.0, method is ISO 27005, money is the boardroom framing of COSO ERM and numbers is the quantified loss of FAIR.
Framework | What it governs | Who tends to mandate it | Effort to adopt |
|---|---|---|---|
ISO 31000 | Principles and governance of risk, any domain | Nobody, adopted voluntarily | Low |
NIST CSF 2.0 | Cyber outcomes and maturity | US federal supply chain, many customers | Medium |
ISO 27005 | Information security risk method | Implied by ISO 27001 certification | Medium |
COSO ERM | Enterprise risk tied to strategy | Audit committees, listed company governance | High |
FAIR | Quantified loss exposure | Nobody, adopted by choice | High |
How to choose without starting a war
- Ask what you are contractually or legally obliged to hold. Certification and customer requirements narrow the field before preference does.
- Ask who has to act on the output. If it is engineers, you need method. If it is a board, you need outcomes or money.
- Ask what data you actually have. FAIR without incident history is guesswork with a spreadsheet attached.
- Ask what already exists elsewhere in the organisation, because adopting finance’s framework badly is usually better than running a rival one well.
The honest counterarguments
The case for using none of them
A twenty person company does not need COSO. It needs a list of the ten things that would end the business, an owner for each, and a review date. Framework adoption at that size consumes the very attention it is supposed to direct, and I would defend the list over the standard in any audit.
The case for using several
Layering is legitimate and common. ISO 31000 for language, ISO 27005 for method and FAIR for the top few risks is a coherent stack, not a contradiction. What is not legitimate is three parallel registers with three sets of criteria, because then the organisation has no view of anything, only opinions with different formatting.
The case against frameworks generally
Every one of these can be performed rather than practised. A register with two hundred entries, all amber, all owned by the head of information security, all reviewed on the same day each year, is compliant with everything and useful for nothing.
Common mistakes
Adopting the method without the criteria
ISO 27005 will happily produce ratings against thresholds nobody has agreed. Set the evaluation criteria first, in writing, approved by someone who can sign for the consequences.
Confusing a control set with a risk framework
ISO 27001 Annex A and NIST SP 800-53 are catalogues of controls. They tell you what you could do, not what you should worry about, and an earlier post in this series compares them on that basis.
Letting the tool choose
Plenty of organisations run whatever risk model their software shipped with. That is a vendor making your governance decision, which is the same category of mistake as letting a hosting choice decide where your compliance data lives.
Go and look for the three registers. They are there, in the security team, in finance, and in a spreadsheet somebody built in a hurry. Pick which one is the real one, name the framework it follows, write down why, and retire the others. The framework you choose matters less than the fact that you chose it on purpose and can say so in a sentence.
Run your GRC programme in your own network.
RaptorGRC Community Edition is free: every module, offline licence activation, nothing phones home.
Register / Download Contact us