Composite risk management (CRM) means managing the combined risks from all relevant sources through a continuous five-step process: identify hazards, assess hazards, develop controls and make risk decisions, implement controls, then supervise and evaluate. The term comes from U.S. Army doctrine; current Army guidance normally calls the method simply “risk management”.
CRM is not merely a form to complete or a separate international business standard. It is a practical process for balancing risk against the expected benefit of an activity or mission.
What does composite risk management mean?
The word composite refers to the combined risk picture. Rather than separating operational, accidental and human hazards, the method considers how they interact within one activity. A U.S. Army Corps of Engineers document describes this as a holistic approach focused on risks from all sources (U.S. Army Corps of Engineers). The purpose is to distinguish necessary from avoidable risk, choose proportionate controls and identify who may accept the residual risk.
Where did the term composite risk management come from?
Composite risk management is principally associated with the U.S. Army. The 2006 field manual FM 5-19 was titled Composite Risk Management. Current Army safety guidance refers instead to ATP 5-19, Risk Management, but retains the five-step process and its continuous, integrated character (U.S. Army Combat Readiness Center).
The phrase remains useful when researching the Army method, but readers should recognise the terminology change. A business may adapt CRM as an operational technique, but should not present it as a certification, regulation or replacement for an organisation-wide framework.

What are the five steps of composite risk management?
The five steps move from understanding the hazard to confirming that the response remains effective. The U.S. Army Combat Readiness Center states that the process should be embedded in operations and warns that completing only a worksheet does not constitute risk management (Army Safety).
| Step | Key question | Practical output |
|---|---|---|
| 1. Identify the hazards | What could cause harm, loss, delay or mission failure? | A specific list of hazards linked to the activity and its conditions |
| 2. Assess the hazards | How likely is each outcome, and how severe could it be? | Prioritised initial risks and the assumptions behind the rating |
| 3. Develop controls and make risk decisions | What can eliminate or reduce the risk, and who may accept what remains? | Selected controls, residual-risk judgement and approval at the appropriate level |
| 4. Implement controls | Who will do what, by when and with which resources? | Assigned owners, communicated instructions, resources and evidence that controls are in place |
| 5. Supervise and evaluate | Are the controls working, and has the situation changed? | Monitoring, corrective action, lessons learned and a return to step one when needed |
1. Identify the hazards
Review the task, environment, people, equipment and timing. Describe each hazard specifically—for example, fatigue causing a driving error during an overnight journey.
2. Assess the hazards
Estimate probability and severity using consistent criteria, recording important assumptions and existing controls. The aim is prioritisation, not false precision.

3. Develop controls and make risk decisions
Choose controls that address the cause, removing the hazard where possible. Assess the residual risk and send the decision to someone with the correct authority and information.
4. Implement controls
Assign each control an owner, deadline, resources and communication method. Confirm that affected people understand it and can apply it in real conditions.
5. Supervise and evaluate
Check whether each control was applied, reduced the intended risk or created another hazard. Reassess when conditions change; this step makes CRM a cycle rather than a one-time assessment.
What are the four principles of Army risk management?
Current Army safety guidance lists four principles that give the five steps their decision-making context:
- Integrate risk management into every phase of missions and operations.
- Make risk decisions at the appropriate level.
- Accept no unnecessary risk.
- Apply risk management cyclically and continuously.
CRM is therefore not the same as risk avoidance. Its role is to expose the trade-off, remove unnecessary exposure and ensure the remaining risk is consciously accepted. The Army’s 2024 guidance emphasises balancing the cost of risk with mission benefit.
Composite risk management example
Consider a technical team inspecting equipment at an operating industrial site. This is an illustrative business adaptation, not an Army case study.
- Identify: Record travel fatigue, moving machinery, heat, emergency procedures and incomplete equipment data.
- Assess: Rate each hazard using agreed probability and severity criteria; prioritise travel and machinery risks.
- Control and decide: Change the travel schedule, require an induction and escort, confirm isolation rules, and have an authorised manager approve the residual risk.
- Implement: Assign owners and timings; confirm site access, isolation and briefing arrangements.
- Supervise and evaluate: Check conditions on arrival. If isolation is unavailable, stop and reassess; record lessons after the visit.
The value lies in linking assessment to action, ownership and review.
CRM vs risk assessment vs enterprise risk management
| Approach | Main purpose | Typical scope | Important distinction |
|---|---|---|---|
| Composite risk management | Manage combined hazards through a continuous five-step decision process | A mission, task, activity or operation | Originates in U.S. Army doctrine and includes implementation and supervision |
| Risk assessment | Identify and analyse risk to support a decision | A task, process, project or decision | Assessment alone does not ensure controls are implemented or reviewed |
| Enterprise risk management (ERM) | Integrate risk with organisational strategy, performance and governance | The whole organisation and its portfolio of objectives | Broader than CRM and normally overseen through governance structures |
For organisations, ISO 31000 provides risk-management principles and guidance, while COSO’s ERM framework connects risk with strategy and performance. CRM can complement those approaches as an operational cycle; it is not equivalent to them.
When is a CRM-style process useful outside the military?
The process suits operational decisions that must be revisited as conditions change, including project site work, maintenance, logistics, emergency response and business travel. An organisation should map the terminology, risk scales, approval levels and records to its laws, policies and governance, including clear authority for accepting residual risk.
Professionals seeking an organisation-wide perspective can review EPW’s Strategic Risk Management for Public and Private Sectors Course. Project leaders may prefer the Project Risk Management and Mitigation Strategies Course.
Common composite risk management mistakes
- Treating the worksheet as the entire process.
- Copying generic hazards without checking the current task and environment.
- Using inconsistent probability or severity criteria.
- Selecting controls without owners, resources or deadlines.
- Failing to identify who may accept residual risk.
- Assuming a control is effective without observing or testing it.
- Completing the first three steps but neglecting implementation and evaluation.
- Calling CRM a universal corporate standard without explaining its Army origin.
For a broader comparison of manager-level learning options, see EPW’s guide to risk management training choices. Readers building governance structures may also find What Is GRC? Governance, Risk and Compliance useful.
Frequently asked questions
What is composite risk management in one sentence?
It is a continuous five-step method for identifying hazards, assessing risk, applying controls, making informed decisions and evaluating results.
Why is it called composite risk management?
“Composite” reflects the treatment of risks from different sources within the same activity rather than as isolated categories.
Is composite risk management the same as ERM?
No. CRM is an Army-originated operational process. ERM connects risk with strategy, performance and governance across an organisation. A CRM-style cycle may operate within ERM.
What is the most commonly missed CRM step?
Implementation and evaluation are often neglected. Army guidance warns that documented controls have little value unless they are implemented and assessed for effectiveness.
Final takeaway
The clearest composite risk management meaning is continuous, integrated risk-based decision-making. The method moves a team from hazards to controls, ownership and review. Used accurately, CRM is a practical operational method with U.S. Army roots—not a substitute for legal duties or wider risk governance.
To build broader skills in identifying, evaluating and treating organisational risk, review EPW’s Strategic Risk Management for Public and Private Sectors Course.
Sources and references
- U.S. Army Combat Readiness Center, Risk Management, 20 September 2024.
- U.S. Army Safety, Publications: FM 5-19 Composite Risk Management.
- U.S. Army Corps of Engineers, Appendix C: Flood Risk Management.
- International Organization for Standardization, ISO 31000:2018 — Risk Management Guidelines.
- Committee of Sponsoring Organizations of the Treadway Commission, Enterprise Risk Management.
