- Risk Management
- 16th Aug 2026
- 1 min read
Risk Management Frameworks Compared: 7 Ways to Choose
- Written by
In Short...
- Most organisations layer frameworks rather than choosing one: ISO 31000 sits at the top as the enterprise umbrella, with domain frameworks like COBIT 2019, ISO 27005 and DORA operating beneath it.
- The right framework depends on your regulatory driver: DORA-regulated entities need COBIT 2019 and ISO 27005 as a mandatory overlay; SOX-exposed organisations need COSO ERM; ISO 27001 candidates need ISO 27005.
- Framework mapping matters more than framework choice: A single control can satisfy ISO 27001, DORA, NIS2 and COBIT 2019 at once, but only if it’s tested once and mapped explicitly across each one.
- DORA is a legal obligation with enforcement teeth: It has applied to in-scope EU/UK financial entities since 17 January 2025, and its ICT risk framework under Articles 5-16 requires board approval.
Seven frameworks cover almost every risk management programme in regulated UK and EU organisations: ISO 31000, COSO ERM, NIST RMF, COBIT 2019, ISO/IEC 27005, FAIR and DORA’s ICT risk framework. Most regulated organisations don’t pick one. They layer ISO 31000 as the enterprise umbrella, add COBIT 2019 or ISO 27005 for IT and information security governance, apply FAIR where financial quantification is needed, and treat DORA’s ICT framework as a mandatory overlay for financial services. This guide compares all seven against the dimensions that matter for a selection decision, then works through a decision path by team, regulatory driver and risk maturity.
Expert View
|
Matt Davies Chief Product Officer, SureCloud |
What our experts say about layering GRC frameworks without duplicate work
“Every team we talk to has the frameworks mapped on a slide somewhere. The real problem shows up in the evidence folder, when the same access control gets tested four times under four different names. Map the control once, and the reporting cycle stops eating the team’s capacity.” |
What Is a Risk Management Framework?
A risk management framework is the architecture that connects risk appetite at board level to risk activities on the ground. It sets out the principles, processes and guidelines an organisation uses to identify, assess, treat and monitor risk.
The distinction matters because frameworks are often confused with standards, which specify requirements, and methodologies, which prescribe specific techniques. A framework sets the overall structure; standards and methodologies sit within it.
A framework does more than a risk register on its own. It defines governance, setting out who is accountable, what gets escalated, and how risk appetite is set and communicated. It provides process architecture, the cycle of identification, assessment, treatment, monitoring and review. And it enables comparability, giving business units, geographies and risk domains a common language and scoring system so results can be aggregated and reported.
A risk register is the operational output of that framework, the record where identified risks, owners, controls and actions are tracked. The framework makes that register meaningful, and the sections below explain the seven frameworks GRC teams rely on and how they connect in practice.
Seven Risk Management Frameworks Explained
These are the frameworks GRC practitioners encounter most often in regulated UK and EU organisations, described by scope, structure and where each one fits in practice.
ISO 31000: The Enterprise Umbrella
ISO 31000:2018 is the international standard for risk management principles and guidelines. It applies to any organisation, any sector and any risk type, and sets out eight principles: integrated, structured and systematic, customised, inclusive, dynamic, based on best available information, attentive to human and cultural factors, and committed to continual improvement. It doesn’t prescribe a methodology. Instead, it guides organisations through a process built around establishing scope, context and criteria, risk assessment, risk treatment, and monitoring, review, recording and reporting, with communication and consultation running throughout.
ISO 31000 is the most widely adopted enterprise risk framework in the EU and UK. It provides the common language and governance structure that lets domain-specific frameworks, cyber, IT, operational, connect to the board-level risk picture, which is why most regulated organisations use it as the top-level architecture.
It stops short of specifying how to score risks, which controls to implement, or how to meet a specific regulatory requirement, by design. Organisations that need prescriptive guidance add a domain-specific framework beneath it, which is where COBIT 2019, ISO 27005 and DORA’s ICT framework come in.
COSO ERM: Governance and Financial Risk
The COSO Enterprise Risk Management framework (2017 edition) integrates risk management with strategy and performance. It’s built around five components and twenty principles, with a strong emphasis on board-level governance, risk culture, and the link between risk and business objectives.
COSO ERM is the framework of choice for publicly listed companies, financial institutions with SOX obligations, and organisations where the audit committee or board needs a structured approach to risk oversight. It aligns directly with financial reporting governance and is widely used in the US, with selective adoption in the UK and EU financial sector.
COSO ERM’s focus is enterprise and financial-reporting risk. It doesn’t go deep on cyber or IT risk, so organisations in regulated sectors usually pair it with ISO 27005 or COBIT 2019 to reach the depth DORA or NIS2 require in those domains.
NIST RMF: Prescriptive Cybersecurity Risk
The NIST Risk Management Framework (SP 800-37 Rev. 2) sets out a seven-step lifecycle for managing cybersecurity and privacy risk in information systems: Prepare, Categorise, Select, Implement, Assess, Authorise and Monitor. It’s prescriptive and sequential by design.
NIST RMF is the dominant framework for US federal agencies and organisations with US government contracts, and it’s also widely referenced by security teams in regulated industries globally, particularly where NIST CSF is already in use. For organisations running NIST CSF as their cybersecurity programme, NIST RMF provides the underlying system-level risk process.
Its origin is US federal guidance, so it doesn’t map directly to EU requirements such as DORA or NIS2. Its system-level focus makes it a complement to ISO 31000’s enterprise view, not a full replacement for it.
COBIT 2019: IT Governance and DORA Alignment
COBIT 2019, from ISACA, is an IT governance and management framework built around forty governance and management objectives across five domains: Evaluate, Direct and Monitor; Align, Plan and Organise; Build, Acquire and Implement; Deliver, Service and Support; and Monitor, Evaluate and Assess. It’s rapidly becoming the go-to framework for DORA-regulated financial entities, since its objectives map directly to DORA’s ICT risk management requirements under Articles 5 to 16 and provide the management structure needed to demonstrate board accountability for digital operational resilience.
COBIT 2019’s focus is IT governance and management, narrower than ISO 31000’s enterprise-wide scope, and it’s also relevant to the IT governance dimension of NIS2 compliance. Organisations usually run it alongside ISO 31000 for enterprise risk and ISO 27005 for information security risk processes.
FAIR: Quantitative Cyber Risk
Boards and CFOs increasingly ask one question that most heat-map risk scoring can’t answer: what is this risk actually worth? Factor Analysis of Information Risk (FAIR) is the only widely adopted quantitative framework built to answer it, decomposing risk into two factors, loss event frequency and loss magnitude, and expressing cyber risk in financial terms.
FAIR converts qualitative heat maps into financial figures, supporting investment decisions, insurance assessments and board-level risk reporting, and CISOs use it to justify security spend with the same rigour applied to financial risk. It needs data and analytical capability many organisations haven’t built yet, though, which makes it a supplementary layer, not a standalone system. Most organisations apply it selectively, to the handful of high-impact risks where financial quantification changes the decision.
ISO/IEC 27005: Information Security Risk
ISO/IEC 27005:2022 provides guidance on information security risk management, directly supporting the risk assessment requirements of ISO 27001 clause 6.1. It’s a methodology-level standard that sits beneath ISO 31000 and operationalises risk management for the information security domain.
ISO 27005 is the practical standard for any organisation pursuing ISO 27001 certification. It also aligns directly with NIS2 and DORA’s ICT risk process requirements, which makes it the default choice for EU-regulated organisations managing information security risk, and it’s widely adopted as the EU security baseline.
DORA: The Mandatory Operational Resilience Framework
DORA, the Digital Operational Resilience Act, is EU law that has applied since 17 January 2025, mandating a specific ICT risk management framework for financial entities and their critical ICT third-party providers.
DORA’s ICT risk framework under Articles 5 to 16 requires financial institutions to run a board-approved framework covering identification, protection, detection, response and recovery from ICT risks, across five pillars:
|
Pillar |
Articles |
What it requires |
|
ICT Risk Management |
Articles 5-16 |
Board-approved framework, documented and integrated with overall risk management |
|
Incident Management and Reporting |
Articles 17-23 |
Classification and notification within 4 hours (initial), 72 hours (intermediate), one month (final) |
|
Digital Operational Resilience Testing |
Articles 24-27 |
Annual testing programme; significant entities run threat-led penetration testing at least every three years |
|
ICT Third-Party Risk Management |
Articles 28-44 |
Register of Information submitted annually; mandatory contractual provisions for all ICT providers |
|
Information Sharing |
Articles 45-49 |
Voluntary intelligence sharing on cyber threats |
Regulators in 2026 have moved from reviewing paperwork to demanding real-time evidence of resilience. DORA delegates the setting of fines to individual member states under Article 50, so the exact cap varies by jurisdiction. There’s no single EU-wide figure. Penalties for individuals responsible for a breach range from around €100,000 in Finland to €5 million in Germany, while penalties for the financial entity itself run higher still, from roughly €2 million in the Czech Republic to €20 million, or 10% of annual turnover, in Italy.
But the direction of travel across member states points the same way, toward penalties with real financial weight. For any UK or EU financial services organisation, DORA’s ICT risk framework carries the force of law and sets the baseline every other control has to meet.
Our DORA Compliance Roadmap covers the board-approval steps in practice, and our guide to preparing for a DORA audit sets out what supervisors expect to see in a review.
Risk Management Frameworks Compared, Side by Side
The table below compares the seven frameworks across the dimensions that matter most for a framework selection decision.
|
Framework |
Scope |
Approach |
Primary users |
EU/UK alignment |
|
ISO 31000 |
All risk types, enterprise-wide |
Principles-based, flexible |
Boards, CROs, risk functions |
Very high, standard umbrella |
|
COSO ERM |
Enterprise and financial reporting risk |
Governance-focused, 5 components, 20 principles |
Boards, audit committees, listed companies |
Selective, financial and listed entities |
|
NIST RMF |
Information systems and cybersecurity |
Prescriptive, 7-step lifecycle |
IT/security teams, US-connected organisations |
Moderate, widely used with US exposure |
|
COBIT 2019 |
IT governance and management |
Objectives-based, 40 objectives |
IT governance, DORA-regulated financial entities |
Growing rapidly in financial services |
|
ISO/IEC 27005 |
Information security risk |
Methodology, supports ISO 27001 |
ISO 27001 implementers, security teams |
Very high, EU security baseline |
|
FAIR |
Cyber and operational risk (quantitative) |
Data-driven, financial modelling |
CISOs, risk analysts, insurers |
Niche but growing |
|
DORA ICT RMF |
ICT risk, operational resilience |
Mandatory, prescriptive, board-approved |
Financial entities, critical ICT providers |
Mandatory for EU/UK financial services |
Three Framework Families
The seven frameworks fall into three natural families.
- Enterprise and principles-based: ISO 31000 and COSO ERM define governance, culture and the overall risk management architecture, and sit at the top of any multi-framework stack.
- IT, information security and operational resilience: NIST RMF, ISO 27005, COBIT 2019 and DORA operationalise risk management for specific domains, and sit beneath the enterprise umbrella.
- Quantitative: FAIR applies a supplementary analytical layer to high-priority risks selectively.
Most regulated organisations in the UK and EU run a layered approach: ISO 31000 as the enterprise structure, COBIT 2019 and ISO 27005 for IT and information security governance, and DORA’s ICT framework as a mandatory overlay for financial entities, with FAIR added where cyber risk needs a financial figure attached.
How to Choose: Decision Table by Team and Risk Domain
The right framework depends on three factors: your team’s primary focus, your regulatory obligations, and your organisation’s risk maturity. The table below maps each combination to a recommended framework stack.
|
Team / role |
Primary focus |
Recommended framework(s) |
Regulatory driver |
|
CRO / Enterprise Risk |
Enterprise-wide risk governance |
ISO 31000 + COSO ERM (if listed) |
General; SOX if applicable |
|
CISO / Cyber Risk |
Cybersecurity risk management |
ISO 27005 + NIST RMF (if US-connected) + FAIR |
NIS2, DORA, ISO 27001 |
|
Compliance Lead |
Regulatory and standards compliance |
ISO 27005 + COBIT 2019 |
DORA, NIS2, ISO 27001, SOC 2 |
|
Third-Party / Vendor Risk |
Supplier and ICT third-party risk |
ISO 31000 + DORA Articles 28-44 |
DORA, NIS2, ISO 27001 Annex A |
|
Operational Risk |
Operational resilience and continuity |
ISO 31000 + DORA + COBIT 2019 |
DORA, ISO 22301, NIS2 |
|
IT Governance |
IT management and control |
COBIT 2019 |
DORA, SOX IT controls |
|
Internal Audit |
Assurance over risk and controls |
ISO 31000 + COSO ERM |
Regulatory and governance requirements |
Decision Logic: Three Questions
If the table above doesn’t immediately resolve your choice, work through these three questions.
Question 1: What Is Your Primary Regulatory Obligation?
- DORA (financial entity or critical ICT provider): COBIT 2019 + ISO 27005, with DORA’s ICT framework as the mandatory overlay.
- NIS2 (essential or important entity): ISO 27005 + ISO 31000, aligned to the ENISA interoperable framework.
- ISO 27001 certification: ISO 27005.
- SOX or financial governance: COSO ERM.
- Multiple EU regulations: ISO 31000 as the umbrella, plus COBIT 2019 and ISO 27005.
Question 2: What Is Your Risk Scope?
- Information security only: ISO 27005 or NIST RMF.
- IT governance and management: COBIT 2019.
- Enterprise-wide, all risk types: ISO 31000 or COSO ERM.
- Financial quantification of cyber risk: Add FAIR to whichever framework you’re running.
Question 3: What Is Your Risk Maturity?
- Starting out: ISO 27005 provides the most structured, practical starting point for ISO 27001 and NIS2.
- Intermediate: ISO 31000 as the umbrella, with domain-specific additions, COBIT for IT governance, ISO 27005 for information security.
- Advanced: A multi-framework approach with COBIT 2019 at governance level, ISO 27005 for risk processes, and FAIR for quantitative analysis of high-priority risks.
There’s no universal answer here, and the most common mistake is adopting a single framework and expecting it to cover every domain. Mature GRC programmes connect their frameworks into a single mapped stack once they’re chosen. Everyone else ends up with separate registers nobody reconciles.
How Frameworks Connect in Practice
Choosing the right frameworks solves half the problem. The harder part is making them work together inside a single GRC programme without creating siloed registers, duplicate controls and inconsistent reporting.
Most organisations running multi-framework programmes hit the same failure point: each team owns its own register, scores risk differently, and reports upward in isolation. The enterprise risk picture becomes an aggregation exercise rather than a real-time view, and by the time the board sees it, the data is weeks old.
The Layered Framework Architecture
- Governance layer: ISO 31000, or COSO ERM for listed entities, defines risk appetite, governance structure and the overall risk management cycle.
- Domain layer: COBIT 2019 for IT governance, ISO 27005 for information security risk processes, and DORA’s ICT framework for financial entities.
- Quantification layer: FAIR applied selectively to high-priority cyber and operational risks where financial figures are needed.
- Control testing layer: ISO 27001, NIST CSF, PCI DSS, SOC 2 and other standards that specify controls, tested once across multiple frameworks through a unified controls library.
The critical design principle is framework mapping at the control level. A single control, access management for example, can satisfy requirements under ISO 27001 Annex A, DORA Article 9, NIS2 and COBIT 2019 at the same time. Without explicit mapping, teams test and evidence the same control multiple times under different labels, creating effort that doesn’t add assurance.
What Good Framework Mapping Looks Like
|
GRC capability |
What it enables |
|
Unified risk register |
All enterprise, cyber, operational and third-party risks in one place, scored consistently against a common taxonomy |
|
Cross-framework control mapping |
A single control evidenced once, mapped to multiple frameworks, eliminating duplicate testing |
|
Framework-aligned risk scoring |
Risk ratings that reflect the specific appetite and tolerance defined under each framework |
|
Real-time regulatory reporting |
DORA Register of Information, NIS2 incident notifications and board risk reports generated from the same data source |
|
Third-party risk integration |
Supplier assessments linked to ICT third-party risk registers under DORA Articles 28-44 |
Forty-nine per cent of enterprises report managing five or more major regulatory obligations simultaneously. Without a platform that maps frameworks to controls and risks in a single data model, the manual overhead of running multiple frameworks at once becomes unsustainable at scale.
SureCloud’s Risk Management product is built for exactly this problem: a unified risk register that connects enterprise, cyber, operational and third-party risks in one place, with consistent scoring, named owners and real-time status. Risks link directly to controls, incidents, third-party assessments and key risk indicators, so the register reflects the current state of the programme, not a snapshot from the last quarterly review.
The platform’s Continuous Controls Monitoring capability maps a single control to multiple standards at once, ISO 27001:2022, NIST CSF v2.0, DORA, NIS2, SOC 2, PCI DSS and more, testing it once to satisfy all of them. For DORA-regulated entities specifically, SureCloud supports the board-approval workflow for ICT risk frameworks, the Register of Information for third-party arrangements, and the incident classification and reporting timelines required under Articles 17 to 23.
Running a multi-framework programme by hand is where most GRC teams hit their capacity ceiling. Gracie AI Agents with Personas and Skills gives risk and compliance teams a virtual GRC team that performs framework-aligned activities at scale: updating risk registers, surfacing emerging risks, generating board-ready reports and testing controls across frameworks, each with a full audit trail and human oversight. SureCloud customers report a 50-65% reduction in manual evidence collection and 40% faster risk-based decision-making, cutting board report preparation from two weeks to two days.
That’s the real payoff: GRC teams spending their working hours on judgment calls, with consolidation, chasing and manual reporting off their plate.
Found this useful?
Choose SureCloud as a preferred source in Google and you will see more of our GRC guidance in Top Stories, AI Overviews and AI Mode. It takes one click and you can undo it at any time.
See Every Framework Mapped to One Controls Library
FAQ’s
What is a risk management framework?
A risk management framework is a structured set of principles, processes and guidelines that defines how an organisation identifies, assesses, treats, monitors and reports risk. It differs from a risk register, which records individual risks, and a risk methodology, which prescribes specific scoring techniques. A framework provides the governance architecture that connects risk appetite at board level to risk activities on the ground.
What are the main risk management frameworks used in the UK and EU?
The seven most widely used frameworks in regulated UK and EU organisations are ISO 31000:2018 for enterprise-wide risk principles and guidelines, COSO ERM (2017) for enterprise risk integrated with strategy and financial governance, NIST RMF (SP 800-37 Rev. 2) for prescriptive cybersecurity risk, COBIT 2019 for IT governance with strong DORA alignment, ISO/IEC 27005:2022 for information security risk methodology, FAIR for quantitative cyber and operational risk, and DORA’s ICT Risk Management Framework, mandatory for EU/UK financial entities since January 2025.
Do I need to choose just one framework?
No. Most regulated organisations run a layered stack, not a single framework. The typical architecture is ISO 31000 as the enterprise umbrella, COBIT 2019 or ISO 27005 for IT and information security governance, and DORA’s ICT framework as a mandatory overlay for financial entities, with FAIR added selectively where financial quantification is needed. Choosing a single framework and expecting it to cover every domain is the most common implementation mistake.
What is the difference between ISO 31000 and ISO 27005?
ISO 31000 is a high-level, principles-based standard that applies to all risk types across the entire organisation, defining governance structure, risk culture and the overall risk management cycle. ISO/IEC 27005 is a methodology-level standard scoped specifically to information security risk, operationalising the risk assessment requirements of ISO 27001 clause 6.1. Most organisations use ISO 31000 as the umbrella and ISO 27005 as the information security process layer beneath it.
Is DORA a risk management framework?
DORA, the Digital Operational Resilience Act, is EU law that mandates a specific ICT risk management framework for financial entities and their critical ICT third-party providers. Articles 5-16 require a board-approved ICT risk framework covering identification, protection, detection, response and recovery, and enforcement began on 17 January 2025. For in-scope organisations, DORA carries the force of law and enforcement consequences for non-compliance.
How do risk management frameworks connect to a risk register?
A risk register is the operational output of a framework: the record where identified risks, owners, controls and actions are tracked against that structure. The framework defines governance, who owns risk and how appetite is set, and the process cycle of identification, assessment, treatment, monitoring and review. A register without a framework becomes a list of worries; a framework without a register has no operational record, so the two work together.
Platform +
Frameworks +
Products +
Industries +
Resources +
Company +
London Office
1 Sherwood Street, London, W1F 7BL, United Kingdom
US Headquarters
6010 W. Spring Creek Pkwy., Plano, TX 75024, United States of America
© SureCloud 2026. All rights reserved.
