IRM/AIRMIC/ALARM A Risk Management Standard (2002)
The Institute of Risk Management's risk management framework is set out in A Risk Management Standard, written in 2002 by the IRM with AIRMIC and ALARM using the ISO/IEC Guide 73 vocabulary and still issued free by the IRM. It treats risk as having upside and downside, is deliberately non-prescriptive and not certifiable, and describes a process from the organisation's strategic objectives through risk assessment (identification, description, estimation, analysis techniques, risk profile, evaluation against criteria), internal and external reporting, treatment (control, avoidance, transfer, financing) and monitoring and review, together with the structure for administering it: the risk management policy and appetite and the roles of the board, business units, the risk management function and internal audit, with resourcing and embedding.
IRM/AIRMIC/ALARM A Risk Management Standard (2002) is a compliance framework from International (IRM) with 7 domains and 17 controls that map to 74 other frameworks. The largest domains are Structure and administration of risk management – IRM/AIRMIC/ALARM A Risk Management Standard (2002) (6 controls), Risk analysis – IRM/AIRMIC/ALARM A Risk Management Standard (2002) (5 controls), Risk reporting and communication – IRM/AIRMIC/ALARM A Risk Management Standard (2002) (2 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Monitoring and review – IRM/AIRMIC/ALARM A Risk Management Standard (2002)
| Code | Title |
|---|---|
| irm-enterprise-risk-management-framework-institute-of-risk-management::8 | 8 Monitoring and review of the risk management process |
Risk analysis – IRM/AIRMIC/ALARM A Risk Management Standard (2002)
| Code | Title |
|---|---|
| irm-enterprise-risk-management-framework-institute-of-risk-management::4.1 | 4.1 Risk identification |
| irm-enterprise-risk-management-framework-institute-of-risk-management::4.2 | 4.2 Risk description |
| irm-enterprise-risk-management-framework-institute-of-risk-management::4.3 | 4.3 Risk estimation |
| irm-enterprise-risk-management-framework-institute-of-risk-management::4.4 | 4.4 Risk analysis methods and techniques |
| irm-enterprise-risk-management-framework-institute-of-risk-management::4.5 | 4.5 Risk profile |
Risk evaluation – IRM/AIRMIC/ALARM A Risk Management Standard (2002)
| Code | Title |
|---|---|
| irm-enterprise-risk-management-framework-institute-of-risk-management::5 | 5 Risk evaluation |
Risk management and its process – IRM/AIRMIC/ALARM A Risk Management Standard (2002)
| Code | Title |
|---|---|
| irm-enterprise-risk-management-framework-institute-of-risk-management::2 | 2 Risk management |
Risk reporting and communication – IRM/AIRMIC/ALARM A Risk Management Standard (2002)
| Code | Title |
|---|---|
| irm-enterprise-risk-management-framework-institute-of-risk-management::6.1 | 6.1 Internal reporting |
| irm-enterprise-risk-management-framework-institute-of-risk-management::6.2 | 6.2 External reporting |
Risk treatment – IRM/AIRMIC/ALARM A Risk Management Standard (2002)
| Code | Title |
|---|---|
| irm-enterprise-risk-management-framework-institute-of-risk-management::7 | 7 Risk treatment |
Structure and administration of risk management – IRM/AIRMIC/ALARM A Risk Management Standard (2002)
| Code | Title |
|---|---|
| irm-enterprise-risk-management-framework-institute-of-risk-management::9.1 | 9.1 Risk management policy |
| irm-enterprise-risk-management-framework-institute-of-risk-management::9.2 | 9.2 Role of the board |
| irm-enterprise-risk-management-framework-institute-of-risk-management::9.3 | 9.3 Role of the business units |
| irm-enterprise-risk-management-framework-institute-of-risk-management::9.4 | 9.4 Role of the risk management function |
| irm-enterprise-risk-management-framework-institute-of-risk-management::9.5 | 9.5 Role of internal audit |
| irm-enterprise-risk-management-framework-institute-of-risk-management::9.6 | 9.6 Resources and implementation |
Your Compliance Coverage
If you comply with IRM/AIRMIC/ALARM A Risk Management Standard (2002), you already cover:
NIST Privacy Framework
8%
2 controls mapped
Compare →Vietnam Law on Cybersecurity (No. 116/2025/QH15)
8%
2 controls mapped
Compare →Vermont Data Privacy and Online Surveillance Act
8%
2 controls mapped
Compare →+ 71 more: US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule (8%), UK Defence Standard 05-138 - Cyber Security for Defence Suppliers (8%)
See all 74 mapped frameworks ↓Maps to 74 other frameworks
Coverage is not the same as your position
This page shows what IRM/AIRMIC/ALARM A Risk Management Standard (2002) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is IRM/AIRMIC/ALARM A Risk Management Standard (2002) and who does it apply to?
IRM/AIRMIC/ALARM A Risk Management Standard (2002) is a compliance framework from International (IRM) with 7 domains and 17 controls. The Institute of Risk Management's risk management framework is set out in A Risk Management Standard, written in 2002 by the IRM with AIRMIC and ALARM using the ISO/IEC Guide 73 vocabulary and still issued free by the IRM. It treats risk as having upside and downside, is deliberately non-prescriptive and not certifiable, and describes a process from the organisation's strategic objectives through risk assessment (identification, description, estimation, analysis techniques, risk profile, evaluation against criteria), internal and external reporting, treatment (control, avoidance, transfer, financing) and monitoring and review, together with the structure for administering it: the risk management policy and appetite and the roles of the board, business units, the risk management function and internal audit, with resourcing and embedding. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does IRM/AIRMIC/ALARM A Risk Management Standard (2002) actually require?
IRM/AIRMIC/ALARM A Risk Management Standard (2002) has 17 controls organised across 7 domains. The largest domains are Structure and administration of risk management – IRM/AIRMIC/ALARM A Risk Management Standard (2002) (6 controls), Risk analysis – IRM/AIRMIC/ALARM A Risk Management Standard (2002) (5 controls), Risk reporting and communication – IRM/AIRMIC/ALARM A Risk Management Standard (2002) (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of IRM/AIRMIC/ALARM A Risk Management Standard (2002) do I already cover?
IRM/AIRMIC/ALARM A Risk Management Standard (2002) maps to 74 other compliance frameworks. The top mapping partners are NIST Privacy Framework (8% coverage), Vietnam Law on Cybersecurity (No. 116/2025/QH15) (8% coverage), Vermont Data Privacy and Online Surveillance Act (8% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement IRM/AIRMIC/ALARM A Risk Management Standard (2002)?
Start your IRM/AIRMIC/ALARM A Risk Management Standard (2002) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about IRM/AIRMIC/ALARM A Risk Management Standard (2002) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 17 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.
Get Started Free →Free forever — no credit card required