3.4 The Risk Management Plan and Framework Documentation Architecture

Key Takeaways

  • The risk management policy states intent and commitment; the risk management plan states how, by whom, with what, and by when.
  • A risk management plan specifies objectives and scope, roles and accountabilities, methodology, risk criteria, resources, schedule, reporting cadence, and review triggers.
  • A risk treatment plan is narrower than a risk management plan: it governs the actions for specific evaluated risks.
  • ISO 31000 Clause 5.4.3 requires the framework design to allocate resources including people, skills, tools, information systems, and documented processes.
  • Documentation architecture should be a hierarchy - policy, plan, procedure, register, report - with each level owned and version-controlled.
Last updated: July 2026

3.4 The Risk Management Plan and Framework Documentation Architecture

A named Domain 2 knowledge statement is knowledge of the main components of a risk management plan. Candidates who have only studied the risk management policy lose these marks, because PECB tests the distinction between four separate documents that all contain the words "risk" and "plan".


Four Documents, Four Jobs

DocumentQuestion it answersApproved byTypical horizon
Risk management policyWhy do we manage risk, and what is leadership committed to?Top management / governing bodyReviewed annually, changes rarely
Framework implementation planHow do we roll the framework out across the organization?Top managementOne-off programme, 6-24 months
Risk management planHow is risk managed day to day — by whom, with what method, on what cadence?Top management, maintained by the risk functionStanding, reviewed annually
Risk treatment planWhat specific actions will modify these specific evaluated risks?Risk owner, endorsed at the authority level matching the exposurePer risk, tracked to completion

Exam Trap: A distractor that describes "the actions, owners, and deadlines for reducing a specific evaluated risk" is describing a risk treatment plan, not a risk management plan. A distractor describing "top management's declared commitment and intent" is describing the policy.


Main Components of a Risk Management Plan

A complete risk management plan under ISO 31000 specifies:

  1. Objectives and intended outcomes — what the risk management activity is meant to achieve, expressed against organizational objectives, not as generic aspiration.
  2. Scope and boundaries — the entities, locations, processes, projects, assets, and time period covered, plus explicit exclusions.
  3. Roles, responsibilities, authorities, and accountabilities — often expressed as a RACI matrix covering risk owners, action owners, the risk function, assurance providers, and the governing body. Authority limits for accepting residual risk are stated here.
  4. Risk management methodology — the process steps to be followed, the assessment techniques permitted for each step, and the conditions under which qualitative, semi-quantitative, or quantitative approaches apply.
  5. Risk criteria — the consequence and likelihood scales, the risk matrix or scoring model, tolerance thresholds, and the escalation triggers derived from risk appetite.
  6. Resources — budget, headcount, specialist skills, training programmes, information systems (GRC tooling), and external expertise, consistent with Clause 5.4.3.
  7. Schedule and cadence — the frequency of risk assessments, register reviews, control testing, and management reporting, plus event-driven triggers.
  8. Communication and consultation arrangements — which stakeholders are engaged, when, by what method, and how their input is recorded and fed back.
  9. Recording and reporting arrangements — the register format, retention periods, report templates, distribution lists, and reporting tiers.
  10. Monitoring, review, and improvement provisions — the performance indicators for the plan itself and the triggers that force it to be revised.

Resource Allocation under Clause 5.4.3

ISO 31000 Clause 5.4.3 requires the organization to allocate appropriate resources when designing the framework. The standard's own list is broader than budget alone:

  • People — with defined skills, experience, and competence.
  • Organizational processes, methods, and tools for managing risk.
  • Documented processes and procedures.
  • Information and knowledge management systems.
  • Professional development and training needs.

A plan that names a budget but no competence requirement or training programme is incomplete against this clause, and "we bought GRC software" is never a sufficient answer to a resource-allocation question.


The Documentation Hierarchy

Risk Management Policy          (intent, commitment, appetite direction)
        |
Risk Management Plan            (method, roles, criteria, cadence, resources)
        |
Procedures & Work Instructions  (how to run an assessment, how to score, how to escalate)
        |
Risk Register(s)                (the live record of identified risks and treatments)
        |
Risk Reports                    (tiered outputs to operational, executive, and board audiences)

Each level should have a named owner, a version number, an approval record, and a defined review interval. This hierarchy is what makes the framework auditable under Clause 6.7 (recording and reporting) and what an evaluator examines under Clause 5.6 when judging framework effectiveness.


Real-World Example: A Utility's Plan Refresh

A regional water utility held a two-page risk management policy signed by the CEO and a 400-line risk register, but nothing between them. Assessments were run inconsistently — one business unit used a 3x3 matrix, another a 5x5, and a third scored in monetary terms only. Aggregation across the units was meaningless.

The risk manager authored a single risk management plan that fixed one 5x5 criteria set with defined monetary, safety, environmental, and regulatory consequence bands; assigned risk owners at director level with a documented residual-risk acceptance authority ladder; mandated quarterly register review with event-driven triggers for major incidents and regulatory change; and set a three-tier reporting cadence. Within two cycles the utility could produce a defensible enterprise risk profile, and the regulator's next inspection closed a long-standing finding on inconsistent risk methodology.

Test Your Knowledge

Which document specifies the methodology, risk criteria, roles and accountabilities, resources, and review cadence by which risk will be managed on an ongoing basis?

A
B
C
D
Test Your Knowledge

A risk manager claims resource allocation for the framework is complete because a GRC software licence has been purchased. Against ISO 31000 Clause 5.4.3, why is this insufficient?

A
B
C
D
Test Your Knowledge

During an audit, a reviewer finds that three business units score risks on different consequence scales and that no document defines which scale applies. Which framework artifact is missing?

A
B
C
D