Back to Frameworks

IRM/AIRMIC/ALARM A Risk Management Standard (2002)

International (IRM)
vA Risk Management Standard (AIRMIC, ALARM and IRM, 2002; IRM print of 2010 held)
7 domains
17 controls

The Institute of Risk Management's risk management framework is set out in A Risk Management Standard, written in 2002 by the IRM with AIRMIC and ALARM using the ISO/IEC Guide 73 vocabulary and still issued free by the IRM. It treats risk as having upside and downside, is deliberately non-prescriptive and not certifiable, and describes a process from the organisation's strategic objectives through risk assessment (identification, description, estimation, analysis techniques, risk profile, evaluation against criteria), internal and external reporting, treatment (control, avoidance, transfer, financing) and monitoring and review, together with the structure for administering it: the risk management policy and appetite and the roles of the board, business units, the risk management function and internal audit, with resourcing and embedding.

Verified

IRM/AIRMIC/ALARM A Risk Management Standard (2002) is a compliance framework from International (IRM) with 7 domains and 17 controls that map to 74 other frameworks. The largest domains are Structure and administration of risk management – IRM/AIRMIC/ALARM A Risk Management Standard (2002) (6 controls), Risk analysis – IRM/AIRMIC/ALARM A Risk Management Standard (2002) (5 controls), Risk reporting and communication – IRM/AIRMIC/ALARM A Risk Management Standard (2002) (2 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Monitoring and review – IRM/AIRMIC/ALARM A Risk Management Standard (2002)

1 controls
Controls in the Monitoring and review – IRM/AIRMIC/ALARM A Risk Management Standard (2002) domain of IRM/AIRMIC/ALARM A Risk Management Standard (2002) — 1 controls
CodeTitle
irm-enterprise-risk-management-framework-institute-of-risk-management::88 Monitoring and review of the risk management process

Risk analysis – IRM/AIRMIC/ALARM A Risk Management Standard (2002)

5 controls
Controls in the Risk analysis – IRM/AIRMIC/ALARM A Risk Management Standard (2002) domain of IRM/AIRMIC/ALARM A Risk Management Standard (2002) — 5 controls
CodeTitle
irm-enterprise-risk-management-framework-institute-of-risk-management::4.14.1 Risk identification
irm-enterprise-risk-management-framework-institute-of-risk-management::4.24.2 Risk description
irm-enterprise-risk-management-framework-institute-of-risk-management::4.34.3 Risk estimation
irm-enterprise-risk-management-framework-institute-of-risk-management::4.44.4 Risk analysis methods and techniques
irm-enterprise-risk-management-framework-institute-of-risk-management::4.54.5 Risk profile

Risk evaluation – IRM/AIRMIC/ALARM A Risk Management Standard (2002)

1 controls
Controls in the Risk evaluation – IRM/AIRMIC/ALARM A Risk Management Standard (2002) domain of IRM/AIRMIC/ALARM A Risk Management Standard (2002) — 1 controls
CodeTitle
irm-enterprise-risk-management-framework-institute-of-risk-management::55 Risk evaluation

Risk management and its process – IRM/AIRMIC/ALARM A Risk Management Standard (2002)

1 controls
Controls in the Risk management and its process – IRM/AIRMIC/ALARM A Risk Management Standard (2002) domain of IRM/AIRMIC/ALARM A Risk Management Standard (2002) — 1 controls
CodeTitle
irm-enterprise-risk-management-framework-institute-of-risk-management::22 Risk management

Risk reporting and communication – IRM/AIRMIC/ALARM A Risk Management Standard (2002)

2 controls
Controls in the Risk reporting and communication – IRM/AIRMIC/ALARM A Risk Management Standard (2002) domain of IRM/AIRMIC/ALARM A Risk Management Standard (2002) — 2 controls
CodeTitle
irm-enterprise-risk-management-framework-institute-of-risk-management::6.16.1 Internal reporting
irm-enterprise-risk-management-framework-institute-of-risk-management::6.26.2 External reporting

Risk treatment – IRM/AIRMIC/ALARM A Risk Management Standard (2002)

1 controls
Controls in the Risk treatment – IRM/AIRMIC/ALARM A Risk Management Standard (2002) domain of IRM/AIRMIC/ALARM A Risk Management Standard (2002) — 1 controls
CodeTitle
irm-enterprise-risk-management-framework-institute-of-risk-management::77 Risk treatment

Structure and administration of risk management – IRM/AIRMIC/ALARM A Risk Management Standard (2002)

6 controls
Controls in the Structure and administration of risk management – IRM/AIRMIC/ALARM A Risk Management Standard (2002) domain of IRM/AIRMIC/ALARM A Risk Management Standard (2002) — 6 controls
CodeTitle
irm-enterprise-risk-management-framework-institute-of-risk-management::9.19.1 Risk management policy
irm-enterprise-risk-management-framework-institute-of-risk-management::9.29.2 Role of the board
irm-enterprise-risk-management-framework-institute-of-risk-management::9.39.3 Role of the business units
irm-enterprise-risk-management-framework-institute-of-risk-management::9.49.4 Role of the risk management function
irm-enterprise-risk-management-framework-institute-of-risk-management::9.59.5 Role of internal audit
irm-enterprise-risk-management-framework-institute-of-risk-management::9.69.6 Resources and implementation

Your Compliance Coverage

If you comply with IRM/AIRMIC/ALARM A Risk Management Standard (2002), you already cover:

Maps to 74 other frameworks

24 total controls
NIST Privacy Framework
2 source controls mapped|2 target controls covered
8%
Vietnam Law on Cybersecurity (No. 116/2025/QH15)
2 source controls mapped|1 target controls covered
8%
Vermont Data Privacy and Online Surveillance Act
2 source controls mapped|1 target controls covered
8%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
2 source controls mapped|2 target controls covered
8%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
2 source controls mapped|1 target controls covered
8%
Protective Security Policy Framework (PSPF) Release 2026
2 source controls mapped|2 target controls covered
8%
Privacy Act 1988 (Australia)
2 source controls mapped|1 target controls covered
8%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
2 source controls mapped|3 target controls covered
8%
Nevada Gaming Control Board Cybersecurity Requirements
2 source controls mapped|3 target controls covered
8%
Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP)
2 source controls mapped|1 target controls covered
8%
Law No. 172-13 on the Protection of Personal Data
2 source controls mapped|1 target controls covered
8%
South Korea PIPA
2 source controls mapped|1 target controls covered
8%
APRA CPS 230 Operational Risk Management
2 source controls mapped|6 target controls covered
8%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
2 source controls mapped|7 target controls covered
8%
FFIEC Cybersecurity Assessment Tool (CAT)
2 source controls mapped|3 target controls covered
8%
FFIEC IT Examination Handbook
2 source controls mapped|6 target controls covered
8%
APRA CPS 234
2 source controls mapped|4 target controls covered
8%
IEC 62443
2 source controls mapped|5 target controls covered
8%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
2 source controls mapped|5 target controls covered
8%
BS 65000:2014 - Guidance on Organizational Resilience
2 source controls mapped|3 target controls covered
8%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
2 source controls mapped|3 target controls covered
8%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
2 source controls mapped|2 target controls covered
8%
AS9100D - Aerospace Quality Management System
2 source controls mapped|2 target controls covered
8%
API 1164
2 source controls mapped|5 target controls covered
8%
AML/CTF Act 2006 (Australia)
2 source controls mapped|2 target controls covered
8%
ICH Q10 - Pharmaceutical Quality System
2 source controls mapped|2 target controls covered
8%
FBI CJIS Security Policy
2 source controls mapped|2 target controls covered
8%
Barbados Data Protection Act 2019
2 source controls mapped|1 target controls covered
8%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
2 source controls mapped|2 target controls covered
8%
BSI IT-Grundschutz
2 source controls mapped|3 target controls covered
8%
ISO/IEC 27031:2011
2 source controls mapped|3 target controls covered
8%
ISO/IEC 29134:2023
2 source controls mapped|3 target controls covered
8%
GDPR
2 source controls mapped|1 target controls covered
8%
ISO/IEC 29147:2018
2 source controls mapped|1 target controls covered
8%
ASIS SPC.1-2009 - Organizational Resilience Standard
2 source controls mapped|4 target controls covered
8%
Bahrain PDPL
2 source controls mapped|1 target controls covered
8%
8%
ICAO Annex 17 - Aviation Security (AVSEC)
2 source controls mapped|2 target controls covered
8%
German Supply Chain Due Diligence Act (LkSG)
2 source controls mapped|3 target controls covered
8%
French Sapin II Law (Law No. 2016-1691)
2 source controls mapped|2 target controls covered
8%
SQF Code Edition 9 - Safe Quality Food
2 source controls mapped|2 target controls covered
8%
Annex 11 to EU GMP - Computerised Systems
2 source controls mapped|2 target controls covered
8%
US Consumer Product Safety Act (CPSC) Manufacturer and Importer Duties
2 source controls mapped|1 target controls covered
8%
OCC Heightened Standards (12 CFR Part 30, Appendix D)
1 source controls mapped|2 target controls covered
4%
IAIS Insurance Core Principles (ICPs)
1 source controls mapped|2 target controls covered
4%
IEC 60601-1 - Medical Electrical Equipment Safety
1 source controls mapped|3 target controls covered
4%
IEC 62304:2015 Medical Device Software Lifecycle Processes
1 source controls mapped|3 target controls covered
4%
Singapore AI Governance Framework
1 source controls mapped|1 target controls covered
4%
Aged Care Quality Standards 2019 (repealed edition)
1 source controls mapped|1 target controls covered
4%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|1 target controls covered
4%
South Korea Cloud Security Assurance Program (CSAP)
1 source controls mapped|1 target controls covered
4%
OWASP Top 10:2025
1 source controls mapped|1 target controls covered
4%
OWASP DevSecOps Maturity Model (DSOMM)
1 source controls mapped|2 target controls covered
4%
ISO/IEC 27010:2015
1 source controls mapped|1 target controls covered
4%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|1 target controls covered
4%
Space ISAC (Information Sharing and Analysis Center) - Threat Framework
1 source controls mapped|1 target controls covered
4%
Automotive SPICE (ASPICE) v4.1 - Process Assessment Model
1 source controls mapped|1 target controls covered
4%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
1 source controls mapped|2 target controls covered
4%
4%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|2 target controls covered
4%
ISO/IEC 27011:2024
1 source controls mapped|1 target controls covered
4%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|1 target controls covered
4%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|2 target controls covered
4%
Science Based Targets Initiative (SBTi) - Net-Zero Standard
1 source controls mapped|1 target controls covered
4%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|1 target controls covered
4%
COBIT 2019
1 source controls mapped|1 target controls covered
4%
ISO/IEC 27007:2020
1 source controls mapped|1 target controls covered
4%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|1 target controls covered
4%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|2 target controls covered
4%

Coverage is not the same as your position

This page shows what IRM/AIRMIC/ALARM A Risk Management Standard (2002) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is IRM/AIRMIC/ALARM A Risk Management Standard (2002) and who does it apply to?

IRM/AIRMIC/ALARM A Risk Management Standard (2002) is a compliance framework from International (IRM) with 7 domains and 17 controls. The Institute of Risk Management's risk management framework is set out in A Risk Management Standard, written in 2002 by the IRM with AIRMIC and ALARM using the ISO/IEC Guide 73 vocabulary and still issued free by the IRM. It treats risk as having upside and downside, is deliberately non-prescriptive and not certifiable, and describes a process from the organisation's strategic objectives through risk assessment (identification, description, estimation, analysis techniques, risk profile, evaluation against criteria), internal and external reporting, treatment (control, avoidance, transfer, financing) and monitoring and review, together with the structure for administering it: the risk management policy and appetite and the roles of the board, business units, the risk management function and internal audit, with resourcing and embedding. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does IRM/AIRMIC/ALARM A Risk Management Standard (2002) actually require?

IRM/AIRMIC/ALARM A Risk Management Standard (2002) has 17 controls organised across 7 domains. The largest domains are Structure and administration of risk management – IRM/AIRMIC/ALARM A Risk Management Standard (2002) (6 controls), Risk analysis – IRM/AIRMIC/ALARM A Risk Management Standard (2002) (5 controls), Risk reporting and communication – IRM/AIRMIC/ALARM A Risk Management Standard (2002) (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of IRM/AIRMIC/ALARM A Risk Management Standard (2002) do I already cover?

IRM/AIRMIC/ALARM A Risk Management Standard (2002) maps to 74 other compliance frameworks. The top mapping partners are NIST Privacy Framework (8% coverage), Vietnam Law on Cybersecurity (No. 116/2025/QH15) (8% coverage), Vermont Data Privacy and Online Surveillance Act (8% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement IRM/AIRMIC/ALARM A Risk Management Standard (2002)?

Start your IRM/AIRMIC/ALARM A Risk Management Standard (2002) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about IRM/AIRMIC/ALARM A Risk Management Standard (2002) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 17 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.

Get Started Free →

Free forever — no credit card required