Governance. Risk. Compliance. Cybersecurity.
guide

Risk Management Frameworks: A Practitioner's Guide

How NIST RMF, ISO 27005, FAIR, COSO ERM and OCTAVE compare in practice — with guidance on which to pick for cyber, enterprise and AI risk.

23 June 2026Risk ManagementGuide

Why pick a framework at all

A framework gives you a defensible vocabulary, a repeatable process, and the ability to roll risk up to the board without re-inventing the methodology every quarter. The right choice depends on your sector, regulator and the type of risk you need to quantify.

The five frameworks compared

NIST RMF (SP 800-37 Rev 2)

  • Best for: US-aligned organisations, federal supply chains, defence
  • Strengths: Tight integration with NIST 800-53 controls, continuous-monitoring built-in
  • Watch-outs: Heavy documentation; needs tailoring outside the US public sector

ISO/IEC 27005:2022

  • Best for: ISMS-driven organisations, ISO 27001 certification, GCC regulators
  • Strengths: Vendor-neutral, integrates cleanly with ISO 27001 risk requirements
  • Watch-outs: Methodology-agnostic — you still need to pick qualitative or quantitative scoring

FAIR (Factor Analysis of Information Risk)

  • Best for: Quantifying cyber risk in financial terms for boards and insurers
  • Strengths: Defensible loss-event maths, executive-friendly outputs
  • Watch-outs: Requires data — loss tables, threat-event frequency, vulnerability data

COSO ERM (2017)

  • Best for: Enterprise risk reporting, audit-committee oversight
  • Strengths: Aligns with internal-controls reporting, integrates with SOX
  • Watch-outs: Not cyber-specific — pair with NIST CSF or ISO 27005

OCTAVE Allegro

  • Best for: Asset-centric workshops in mid-sized organisations
  • Strengths: Quick to run, business-owner friendly
  • Watch-outs: Less rigorous than FAIR for board-level loss quantification

A decision tree

  1. Is your primary driver a certification (ISO 27001, SOC 2, ADHICS, CBUAE)? → ISO 27005
  2. Do you report to a US federal customer? → NIST RMF
  3. Does the board want cyber risk in dollars? → FAIR
  4. Are you consolidating financial, operational and cyber risk? → COSO ERM as the umbrella with FAIR or ISO 27005 underneath
  5. Do you need a 6-week pilot? → OCTAVE Allegro

What about AI risk?

ISO/IEC 23894:2023 and NIST AI RMF 1.0 extend the same lifecycle to AI systems. Use them alongside — not instead of — your existing cyber risk framework.

Common implementation mistakes

  • Switching frameworks before completing one full annual cycle
  • Treating the risk register as a spreadsheet rather than a workflow
  • Skipping the risk-appetite statement
  • Letting risk owners be IT, not the business

Next step

MAST runs framework-selection workshops as a one-day engagement. Book a workshop to walk your top 20 risks through three methodologies side-by-side.

Related resources