
Risk Management Frameworks: 10 Options Compared and How to Choose
Emily Bonnie
Senior Content Marketing Manager
Rob Gutierrez
Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP
Risk keeps getting more complicated, and most organizations know their programs haven't kept pace. In the 2026 State of Risk Oversight study from NC State University's ERM Initiative and the AICPA, 69% of executives said the volume and complexity of risks facing their organizations has increased over the past five years. Only 30% described their risk oversight processes as mature or robust, and just 29% had formally defined their risk appetite as part of strategic planning.
A risk management framework gives your team a shared structure for finding, measuring, and acting on risk. The hard part is picking one. There are dozens of frameworks, many overlap, and several are built for very different audiences, from federal agencies to boards of directors to AI product teams.
This guide compares 10 of the most widely used risk management frameworks, explains what each one covers and who it fits, and walks through how to choose and implement the right one for your organization.
What is a risk management framework?
A risk management framework is a structured set of principles, processes, and roles an organization uses to identify, assess, treat, and monitor risk over time. It defines who owns risk decisions, how risks are evaluated, what happens after a risk is found, and how the program is reviewed and improved.
Frameworks are typically published by standards bodies, government agencies, or professional associations such as NIST, ISO, COSO, and ISACA. Some are voluntary guidance. A few, like ISO/IEC 27001, can be independently certified.
Frameworks, methodologies, and standards: What's the difference?
These terms get used interchangeably, which causes a lot of confusion when teams start building a program.
- A risk management framework defines the overall program: governance, roles, processes, and the cycle of review. NIST CSF 2.0 and COSO ERM are frameworks.
- A risk assessment methodology defines how you score a single risk, such as a qualitative high/medium/low matrix or a quantitative dollar estimate. Most frameworks let you choose your own methodology. Our risk assessment methodologies guide covers these in detail.
- A standard is a formally published document, often with requirements you can be audited against. ISO/IEC 27001 is both a standard and a framework for managing information security risk.
Most mature programs use all three: a framework to organize the program, a methodology to score risks consistently, and one or more standards that customers or regulators expect them to meet.
Recommended reading
Risk Assessment Methodologies Explained: Types, Examples, and How to Choose
The five activities every risk management framework shares
Different frameworks use different names, but nearly all of them organize risk management around the same five activities. Understanding these makes it much easier to compare frameworks, and to combine them later.
- Identify. Catalog what could go wrong: threats, vulnerabilities, and uncertain events that could affect your objectives, assets, customers, or obligations.
- Assess. Estimate how likely each risk is and how severe the impact would be, then compare the result against your risk criteria.
- Treat. Decide what to do about each risk: reduce it with controls, avoid the activity that creates it, share or transfer it through insurance or contracts, or accept it and document why.
- Monitor. Track risks and controls as conditions change, so assessments and treatment plans stay current.
- Govern. Assign ownership, set risk appetite, define who can accept risk, and report to leadership.
Here's how four common frameworks label those activities:
| Activity | NIST CSF 2.0 | ISO 31000:2018 | COSO ERM (2017) | NIST RMF |
|---|---|---|---|---|
| Identify | Identify | Risk identification | Performance | Categorize |
| Assess | Identify (risk assessment category) | Risk analysis and risk evaluation | Performance | Select, Assess |
| Treat | Protect, Detect, Respond, Recover | Risk treatment | Performance (risk response) | Implement |
| Monitor | Detect, Govern (oversight) | Monitoring and review | Review and Revision | Monitor |
| Govern | Govern | Leadership and commitment; recording and reporting | Governance and Culture; Strategy and Objective-Setting | Prepare, Authorize |
Popular risk management frameworks
The 10 frameworks below are among the most widely used by security, compliance, and risk teams today. They range from government standards like the NIST RMF to enterprise frameworks like COSO ERM and newer AI-focused standards like ISO/IEC 42001.
Each framework takes a different approach to the same core activities. Some focus on enterprise strategy, others on cybersecurity controls or AI governance, and a few can be independently certified. For each one, we cover how it's structured, who it fits best, and which frameworks it pairs well with, so you can narrow the list to the options that match your risks and obligations.
| Framework | Published by | What it covers | Certification? | Best fit |
|---|---|---|---|---|
| NIST RMF (SP 800-37 Rev. 2) | NIST | Security and privacy risk across the system lifecycle | No. Federal systems receive an authorization to operate (ATO) | Federal agencies and organizations operating systems on their behalf |
| NIST CSF 2.0 | NIST | Cybersecurity risk outcomes organized into six functions | No | Any organization that wants a common cybersecurity baseline and vocabulary |
| ISO 31000:2018 | ISO | Any type of risk, enterprise-wide | No (guidelines only) | Organizations that want one risk process across every business unit |
| ISO/IEC 27001:2022 | ISO/IEC | Information security management system (ISMS) | Yes, through an accredited certification body | Companies that need to prove security to enterprise or international customers |
| COSO ERM (2017) | COSO | Enterprise risk tied to strategy and performance | No | Public companies, boards, internal audit, and finance-led programs |
| COBIT 2019 | ISACA | Governance and management of enterprise IT | No (individual credentials exist) | IT-heavy organizations and teams supporting IT audit |
| CIS Controls v8.1 | Center for Internet Security | Prioritized technical safeguards | No | Lean teams that need a clear, prioritized starting point |
| FAIR | FAIR Institute; standardized as Open FAIR by The Open Group | Quantifying cyber and operational risk in financial terms | No (individual certification exists) | Teams reporting risk in dollars to executives and boards |
| NIST AI RMF 1.0 | NIST | Risks from designing, developing, and using AI systems | No | Organizations building or deploying AI |
| ISO/IEC 42001:2023 | ISO/IEC | AI management system (AIMS) | Yes | AI providers that need certifiable proof of AI governance |
1. The NIST Risk Management Framework (NIST RMF)
The NIST Risk Management Framework (RMF) is a comprehensive, flexible, and repeatable process developed by the National Institute of Standards and Technology (NIST). It’s designed to integrate security and risk management into every phase of an organization’s system development lifecycle.
The RMF ensures that security and privacy aren’t afterthoughts, but are woven into the fabric of how systems are developed, operated, and maintained. It's about making risk management an ongoing, methodical process that aligns with an organization's broader mission and business objectives.
The framework consists of seven steps.
- Prepare: Involves understanding the organization’s risk context, defining risk tolerance, and identifying the resources needed for effective risk management.
- Categorize: Involves classifying information systems based on the potential impact a security breach could have on operations, assets, or individuals.
- Select: Organizations choose security controls tailored to the risk levels identified during categorization.
- Implement: Controls are deployed within the system and thoroughly documented.
- Assess: Ensures the controls are functioning as intended and effectively reducing risk.
- Authorize: Requires decision-makers to evaluate the overall risk and determine if the system should be approved for operation.
- Monitor: Involves ongoing assessment and adjustment of security controls to ensure they remain effective over time.
Use the NIST RMF if you need a structured, detailed approach to managing security and privacy risks, especially for systems that process sensitive data. It's mandatory for U.S. federal agencies but is also a strong choice for state, local, and tribal governments, as well as private sector organizations that want to align with federal standards or manage high-risk environments. The RMF is particularly useful if you want a repeatable, lifecycle-based process to integrate security and privacy into every phase of your system development and operations.

Recommended reading
Understanding the NIST Risk Management Framework: A Comprehensive Guide
2. NIST Cybersecurity Framework (CSF) 2.0
NIST released CSF 2.0 in February 2024. It organizes cybersecurity risk management into six functions, adding Govern to the five functions from version 1.1:
- Govern: Set and monitor cybersecurity strategy, expectations, roles, and policy, including supply chain risk management.
- Identify: Understand your assets, suppliers, and current cybersecurity risks.
- Protect: Use safeguards such as access control, training, and data security to manage those risks.
- Detect: Find and analyze possible attacks and compromises.
- Respond: Take action on detected incidents.
- Recover: Restore assets and operations affected by an incident.
Each function breaks down into categories and subcategories that describe outcomes, and organizations use Profiles to compare their current state to a target state.
Use NIST CSF 2.0 if you want a flexible, widely recognized cybersecurity baseline that works for organizations of any size or sector. Its outcome-based structure gives security teams and leadership a common language for discussing risk, and its Profiles help you measure progress from your current state to a target state. Because CSF describes outcomes and doesn't prescribe specific controls, most teams pair it with a control catalog like the CIS Controls or NIST SP 800-53, and add ISO/IEC 27001 when they need a certification.
Recommended reading
The NIST Cybersecurity Framework 2.0: What It Is & How to Comply [+ Checklist]
3. ISO 31000:2018
ISO 31000 provides guidelines for managing any type of risk, in any organization, at any level. It's intentionally general, which makes it a common foundation for enterprise risk programs and for more specific standards like ISO/IEC 27005.
The ISO 31000 process involves several key principles:
- Integration ensures risk management is part of organizational decision-making at every level.
- Customization allows organizations to tailor the framework based on their specific risk profile and operational context.
- Structured and Comprehensive processes ensure a consistent and thorough approach.
- Dynamic principles recognize that risks evolve and require responsive management.
- Inclusivity encourages engaging stakeholders in the risk identification and management process.
If you're looking for a flexible, all-purpose framework that can apply to any type of risk, ISO 31000 is a great choice. It's especially useful for organizations that value adaptability and need a framework that can evolve with their business.
Use ISO 31000 if you want a single, consistent risk process that applies across finance, operations, security, and strategy. Its principles-based approach adapts to any organization and any type of risk, which makes it a common foundation for enterprise risk programs. ISO 31000 is guidance, so you can't be certified against it, and it leaves most implementation decisions to you. Many organizations pair it with ISO/IEC 27001 and ISO/IEC 27005 for information security, and with COSO ERM for board-level governance.
Recommended reading

Cyber Risk Quantification: How It Can Help Protect Your Digital Assets
 4. ISO/IEC 27001:2022
ISO/IEC 27001 is the international standard for an information security management system (ISMS). Risk sits at its center: clause 6.1.2 requires a defined, repeatable information security risk assessment process, and clause 6.1.3 requires a risk treatment process, including a Statement of Applicability that explains which Annex A controls apply and why.
The 2022 version organizes its 93 Annex A controls into four themes: organizational, people, physical, and technological. Organizations are audited by an accredited certification body, and certification is maintained through surveillance audits and recertification.
Use ISO/IEC 27001 if you sell to enterprises or international customers who expect independent proof that you protect their data. Certification gives prospects, partners, and regulators a recognized credential, and the standard's risk assessment and treatment requirements give your security program a repeatable structure. Certification takes time and budget, and the ISMS has to be maintained year-round through surveillance audits and recertification. Many organizations use ISO/IEC 27005 to guide their risk assessments and pursue SOC 2 alongside ISO 27001 to meet U.S. customer expectations.
Recommended reading
The ISO 27001 Compliance Hub
5. COSO Enterprise Risk Management (ERM)
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) published its current ERM framework, Enterprise Risk Management: Integrating with Strategy and Performance, in 2017. It replaced the 2004 "COSO cube" with five interrelated components and 20 principles:
- Governance and Culture: Board oversight, operating structures, and the culture that shapes risk decisions.
- Strategy and Objective-Setting: Risk appetite and how risk factors into strategy and business objectives.
- Performance: Identifying, assessing, prioritizing, and responding to risks that affect objectives.
- Review and Revision: Evaluating how well risk management is working and adjusting as the business changes.
- Information, Communication, and Reporting: Getting the right risk information to the right people.Each function is supported by categories and subcategories that provide additional guidance on achieving specific cybersecurity outcomes.
Use COSO ERM if you want risk management tied directly to strategy, performance, and board oversight. It's a natural fit for public companies, internal audit teams, and finance-led programs, where leadership needs to see how risk affects business objectives. Because COSO ERM operates at the enterprise level, security teams usually need a more detailed framework underneath it. Pair it with ISO 31000 for a structured risk process and NIST CSF or ISO/IEC 27001 for cybersecurity.
6. COBIT 2019
COBIT is ISACA's framework for the governance and management of enterprise information and technology. COBIT 2019 is built on six governance system principles:
- Provide stakeholder value
- Holistic approach
- Dynamic governance system
- Governance distinct from management
- Tailored to enterprise needs
- End-to-end governance system
It defines 40 governance and management objectives across five domains: Evaluate, Direct and Monitor; Align, Plan and Organize; Build, Acquire and Implement; Deliver, Service and Support; and Monitor, Evaluate and Assess.
Use COBIT 2019 if your organization runs complex IT environments and needs a structured approach to IT governance, especially where IT supports financial reporting and audit. Its governance and management objectives give IT leaders and auditors a shared reference point for aligning technology with business goals. COBIT is broad and detailed, so it usually takes experienced practitioners to tailor it well. Many organizations pair it with COSO for internal control and ISO/IEC 27001 or NIST CSF for security.
7. CIS Critical Security Controls v8.1
The CIS Controls are a prioritized set of 18 controls broken into 153 Safeguards. Version 8.1 aligned its security function mappings to NIST CSF 2.0, including the new Govern function.
Safeguards are grouped into three Implementation Groups:
- IG1: Essential cyber hygiene for organizations with limited IT and security expertise.
- IG2: Adds Safeguards for organizations with more complex environments and dedicated IT staff.
- IG3: Adds Safeguards for organizations with security experts and exposure to sophisticated attacks.
Use the CIS Controls if you need a practical, prioritized starting point for technical security work. The Implementation Groups show smaller and leaner teams exactly where to begin, which makes CIS a strong fit for organizations new to formal risk management or those that need to strengthen security quickly. As a control set, CIS doesn't cover governance, risk appetite, or non-technical risk on its own, so most teams use NIST CSF 2.0 as the program structure around it.
Recommended reading
CIS Controls: How to Implement v8.1 to Set CMMC Level 2 Foundation [+ Checklist]
8. FAIR (Factor Analysis of Information Risk)
FAIR is a model for quantifying cyber and operational risk in financial terms. It breaks risk into two main factors: loss event frequency (how often a loss is likely to happen) and loss magnitude (how much it's likely to cost). Each factor is broken down further, and analysts typically use ranges and Monte Carlo simulation to produce a distribution of likely losses.
FAIR is promoted by the FAIR Institute and standardized by The Open Group as Open FAIR.
Use FAIR if you need to justify security investments, compare remediation options, or report risk to executives and boards in financial terms. Expressing risk as likely dollar loss makes it easier for leadership to weigh security spending against other business priorities.
FAIR takes training, reliable data, and time, so most teams apply it to their top risks and use a simpler scoring method for the rest of the register. Because FAIR is closer to an assessment model than a full program framework, it pairs well with any of the frameworks above. Our risk assessment methodologies guide covers quantitative assessment in more depth.
9. NIST AI Risk Management Framework (AI RMF 1.0)
NIST released the AI RMF 1.0 in January 2023 to help organizations manage risks from designing, developing, deploying, and using AI systems. It's organized into four functions:
- Govern: Build a culture, policies, and accountability structures for AI risk.
- Map: Understand each AI system's context, purpose, and potential impacts.
- Measure: Analyze, assess, and track AI risks and system trustworthiness.
- Manage: Prioritize and act on AI risks based on their projected impact.
NIST has since published companion profiles, including one focused on generative AI (NIST AI 600-1).
Use the NIST AI RMF if your organization builds AI products or uses AI to support consequential decisions. Its four functions give teams a structured way to identify and manage risks like bias, security weaknesses, and lack of transparency across the AI lifecycle. The framework is voluntary and can't be certified, so organizations that need third-party proof of responsible AI governance usually pair it with ISO/IEC 42001.
Recommended reading
Understanding the NIST AI RMF: What It Is and How to Put It Into Practice
10. ISO/IEC 42001:2023
Published in December 2023, ISO/IEC 42001 is the first international standard for an AI management system (AIMS). Its structure mirrors ISO/IEC 27001, so teams that already run an ISMS will recognize the clauses, the risk assessment and treatment requirements, and the Annex A control approach. It also requires AI system impact assessments.
Use ISO/IEC 42001 if you develop or provide AI systems and your customers, partners, or regulators are asking for independent proof of responsible AI governance. Teams that already run an ISO/IEC 27001 ISMS can reuse much of their existing management system structure, which reduces duplicated effort. Like ISO 27001, certification requires ongoing investment in documentation and audits. Pair it with the NIST AI RMF for detailed AI risk work and ISO/IEC 27001 for shared management system processes.
A note on maturity models: RIMS RMM
You may also see the RIMS Risk Maturity Model on lists of risk frameworks. RIMS RMM measures how mature an existing ERM program is across seven attributes, including ERM process management, risk appetite management, and root cause discipline. It's most useful once you've adopted a framework and want to benchmark progress and build an improvement roadmap.
How to choose a risk management framework
Start with the decisions that narrow the field fastest.
1. What kind of risk are you trying to manage?
- Enterprise and strategic risk: COSO ERM or ISO 31000
- Cybersecurity risk: NIST CSF 2.0, ISO/IEC 27001, or CIS Controls
- IT governance: COBIT 2019
- AI risk: NIST AI RMF and ISO/IEC 42001
- Financial quantification of cyber risk: FAIR
2. Do customers, regulators, or contracts require a specific approach?
Requirements usually decide the framework for you. Enterprise customers often ask for ISO/IEC 27001 certification or a SOC 2 report. Federal agencies follow NIST RMF. Publicly traded companies often lean on COSO for internal control and enterprise risk. Start with what you're obligated to meet, then fill gaps with voluntary frameworks.
3. Do you need a certification or attestation?
If you need independent proof, focus on certifiable standards (ISO/IEC 27001, ISO/IEC 42001) or attestation reports (SOC 2). Voluntary frameworks like NIST CSF and ISO 31000 can structure your program, but they won't produce a certificate.
4. How mature is your program today?
If you're building your first formal program, CIS Controls IG1 and NIST CSF 2.0 give you a clear, manageable starting point. If you already have a program, a maturity model like RIMS RMM or a CSF Profile can show you where to invest next.
5. Who needs to understand the output?
Boards and CFOs tend to respond to COSO language and financial estimates from FAIR. Engineering and IT teams work better with control-level frameworks like CIS and NIST SP 800-53. Pick a framework your decision-makers will use.
Common framework combinations
Most organizations end up using more than one framework, each at a different level. A few combinations we see often:
| Situation | Common combination |
|---|---|
| Growth-stage SaaS company selling to enterprises | NIST CSF 2.0 to structure the program, ISO/IEC 27001 and/or SOC 2 for customer assurance |
| Public company or board-driven program | COSO ERM at the enterprise level, NIST CSF 2.0 or ISO/IEC 27001 for cybersecurity |
| Small team building its first program | CIS Controls IG1 for technical priorities, NIST CSF 2.0 for structure |
| Company building or selling AI | NIST AI RMF for risk work, ISO/IEC 42001 for certification, ISO/IEC 27001 for security |
| Security team defending budget to the board | Any program framework, with FAIR used for the top risks |
The more frameworks you adopt, the more cross-mapping matters. A single control, such as multi-factor authentication, can satisfy requirements in ISO/IEC 27001, SOC 2, NIST CSF, and CIS all at once. Mapping controls to every framework they support lets you test and evidence each control once instead of repeating the work.

Risk Management Resources Kit
Assessing your organization’s risk profile can be complicated — especially when you’re strapped for time and resources. This free risk management resources kit simplifies the process with essential tools you’ll need to identify, prioritize, and mitigate risk, including policy templates, worksheets, and more.
Using GRC automation to enhance your risk program
Frameworks tell you what to do. Keeping a risk program current across spreadsheets, email threads, and quarterly reviews is where most teams fall behind. A GRC platform keeps risks, controls, owners, and evidence connected in one place.
With Secureframe's risk management capabilities, you can:
- Assess risks with a guided workflow based on the ISO 27005 methodology, with scoring scales, score groups, and tags you can customize to match your risk criteria.
- Start from a risk library of pre-built risks based on NIST risk scenarios, then add custom risks for your business.
- Speed up assessments with Comply AI for Risk, which drafts likelihood, impact, treatment plans, and residual risk from a risk description and your company information.
- Link risks to controls across frameworks to see residual risk and close gaps.
- Show progress over time with snapshots of your risk register from any past date for auditors and executives.
By using a GRC platform, organizations can save time, improve accuracy, and ensure that risk management processes are continuously updated and aligned with evolving business needs and aligned compliance requirements.
Use trust to accelerate growth
FAQs
What are the most common risk management frameworks?
The most widely used risk management frameworks include NIST CSF 2.0, the NIST RMF, ISO 31000, ISO/IEC 27001, COSO ERM, COBIT 2019, and the CIS Controls. NIST AI RMF and ISO/IEC 42001 are increasingly common for AI risk.
What are the five components of a risk management framework?
Most frameworks share five core activities: identifying risks, assessing them, treating them, monitoring them over time, and governing the program through ownership, risk appetite, and reporting. Individual frameworks name and group these differently.
What's the difference between NIST RMF and NIST CSF?
The NIST RMF is a seven-step process for managing security and privacy risk in individual information systems, and it's mandatory for federal agencies. NIST CSF 2.0 is a voluntary framework that describes cybersecurity outcomes for an entire organization. Many organizations use CSF for their program and the RMF only for federal systems.
What's the difference between a risk management framework and a risk assessment methodology?
A framework structures your whole program, including governance, roles, and review cycles. A methodology is the method you use to score individual risks, such as a qualitative matrix or a quantitative dollar estimate.
Can you use more than one risk management framework?
Yes, and many organizations do. A common approach is an enterprise-level framework like COSO ERM or ISO 31000, a cybersecurity framework like NIST CSF 2.0 or ISO/IEC 27001, and a control set like CIS underneath. Cross-mapping controls keeps you from duplicating work.
Which risk management frameworks can you get certified against?
ISO/IEC 27001 and ISO/IEC 42001 are certifiable through accredited certification bodies. NIST CSF, ISO 31000, COSO ERM, CIS Controls, and NIST AI RMF are voluntary frameworks with no organizational certification. SOC 2 produces an attestation report from a CPA firm, not a certification.
Do SOC 2 and ISO 27001 require a specific risk management framework?
No. ISO/IEC 27001 requires a defined and repeatable risk assessment and treatment process, but lets you choose the methodology. SOC 2's Trust Services Criteria include risk assessment criteria (the CC3 series) without prescribing a framework. Many organizations use ISO/IEC 27005 or NIST SP 800-30 to structure the assessment.
What is the best risk management framework for a small business?
Small businesses often start with CIS Controls IG1 for prioritized technical safeguards and NIST CSF 2.0 for overall structure. Both are free to access. If customers require proof of security, add SOC 2 or ISO/IEC 27001.

Emily Bonnie
Senior Content Marketing Manager
Emily Bonnie is a seasoned digital marketing strategist with over ten years of experience creating content that attracts, engages, and converts for leading SaaS companies. At Secureframe, she helps demystify complex governance, risk, and compliance (GRC) topics, turning technical frameworks and regulations into accessible, actionable guidance. Her work aims to empower organizations of all sizes to strengthen their security posture, streamline compliance, and build lasting trust with customers.

Rob Gutierrez
Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP
Rob Gutierrez is an information security leader with nearly a decade of experience in GRC, IT audit, cybersecurity, FedRAMP, cloud, and supply chain assessments. As a former auditor and security consultant, Rob performed and managed CMMC, FedRAMP, FISMA, and other security and regulatory audits. At Secureframe, he’s helped hundreds of customers achieve compliance with federal and commercial frameworks, including NIST 800-171, NIST 800-53, FedRAMP, CMMC, SOC 2, and ISO 27001.