4 Examples of a Risk Management Plan

 , January 11, 2020
A risk management plan is a plan to treat identified risks. This is a type of action plan that is the output of risk identification and analysis. The following are illustrative examples.


The basic elements of a risk management plan are a description of each risk, an estimate of their impact and probability and an overview of the steps that are taken to treat each risk.

Risk Exposure

Risk exposure is a numerical estimate of the probable cost of a risk. This is calculated as impact × probability. For example, if there is a 10% chance that a million dollar house will burn down your risk exposure is $1,000,000 × 0.1 = $100,000. A more sophisticated analysis will also include the risk of partial losses such as a fire that only damages your kitchen.

Residual Risk

Residual risk is the risk that remains after risk treatment. This implies that you have accepted a certain amount of risk as part of risk management. In practice, most risks can't be reduced to zero and this would seldom be desirable as you tend to get decreasing returns if you overmanage risk.

Secondary Risk

A secondary risk is a risk that is created by risk treatments themselves. Risk management can go too far and cause more problems than it prevents. As such, measuring and communicating secondary risk has value in preventing overzealous risk management steps.

Other Fields

The following fields can additionally be added to the columns of a risk management plan:
A named individual who is responsible for implementing risk treatments and risk monitoring.
A named individual who is accountable for the risk.
A target date for the completion of each risk treatment.
Risk Monitoring
Details of how each risk will be monitored.
Risk Response
Details of what you will do if each risk actually occurs.

