You can download a risk management plan template in about thirty seconds. It will be formatted, it will have all the right headings, and it will belong to no industry in particular. It gets filled in, approved at the next governance meeting, and filed alongside the policies nobody reads. Six months later the register is running on different assumptions from the plan, the risk owners do not know what the plan requires of them, and the document is ticked as complete without having changed how risk is actually managed.
The problem is not the template format. A structured starting point is genuinely useful, and the sections that matter are broadly consistent across organisations. The problem is that most templates present structure without explaining why each element exists and what it needs to do in practice. A section labelled Risk Appetite that gets populated with a generic line about balanced risk-taking is worse than no appetite statement at all, because it creates the appearance of governance without the substance of it.
This post sets out what a risk management plan template actually needs to contain, why each section matters, and how the core structure adapts across the sectors where risk management tends to be most consequential: construction, government, healthcare, infrastructure, mining and resources, and transport.
What should a risk management plan template include?
A complete risk management plan template includes eight sections: purpose and scope, a risk appetite statement, a risk identification and assessment methodology, risk categories, roles and responsibilities, risk treatment and controls, monitoring and review, and reporting. Together these define what the plan covers, how much risk the organisation will accept, how risks are rated and managed, who is accountable, and how the board stays informed. The structure is consistent across organisations. What changes is the content you put inside it.
A risk management plan should be a working document, not a policy artefact. It serves two purposes: it tells the organisation how risk will be managed, and it gives the risk function a clear mandate to carry that out. Every section should connect to one of those purposes. If a section is there because it looks complete rather than because it does something, it probably should not be there. For the full method behind building one, see our guide on how to write a risk management plan.
The 8 sections of a risk management plan template
1. Purpose and scope
State what the plan covers and what it does not. Is this an enterprise-level plan governing risk across the whole organisation, or a project-level plan for a defined programme of work? Does it extend to third-party and supply chain risk, or focus on internal operations? Does it cover all risk categories, or is it complemented by separate safety or clinical governance frameworks? This section is short, a paragraph or two, but it prevents a great deal of confusion later. Scope ambiguity is one of the most common reasons risk frameworks fail to take hold, because people default to the interpretation that suits them and the function loses the consistency it depends on.
2. Risk appetite statement
This is the section most templates either omit or fill with language that commits to nothing. A risk appetite statement is the organisation’s explicit position on how much uncertainty it is willing to accept in pursuit of its objectives, and where that tolerance is higher or lower. A useful one is specific enough to guide real decisions. Saying you have low appetite for risks that could compromise the safety of your workforce, the public, or the communities you operate in is more useful than saying you take a balanced approach to risk. Name the categories the organisation is most sensitive to, distinguish them from areas where higher uncertainty is accepted, and give decision-makers a reference point when weighing a course of action. For regulated sectors, acknowledge the non-negotiable floors set by regulation, the risks where appetite is effectively zero because the regulator has already decided it must be.
3. Risk identification and assessment methodology
Describe the scales and process used to identify and rate risks: the likelihood and consequence scales applied, how inherent and residual risk are defined, and how ratings are reviewed and challenged over time. The critical function here is consistency. If different parts of the organisation rate a similar risk differently because there is no shared methodology, the register cannot be used as a comparative tool and the board cannot rely on it to tell high from moderate exposure. Include the risk matrix, or a clear reference to it. If consequence is assessed across several dimensions such as safety, operational, reputational, or regulatory, document those dimensions and how they are applied, so ratings across the register reflect the same underlying logic.
4. Risk categories
List the categories of risk the organisation recognises and manages. These become the taxonomy for the risk register and the assurance plan, and they shape how risks are identified, reported, and assigned. Common categories include strategic, operational, people and capability, technology and data, regulatory and compliance, and safety risk, but the right categories are the ones that reflect how the organisation actually thinks about its exposure. Resist the temptation to create a category for everything. A long list nobody can remember from one committee meeting to the next is worse than a short, precise list that genuinely organises thinking and makes ownership clear.
5. Roles and responsibilities
Who identifies risks? Who owns them once identified? Who assesses control effectiveness, and at what level of management? Who escalates, to whom, and when? This is the section where risk management either connects to how the organisation actually operates or floats above it as an aspiration. If risk ownership is assigned to roles with no practical authority over the controls that manage the risk, the ownership is nominal. The section needs to be specific, grounded, and agreed with the people named in it before the plan is finalised. At minimum, document the risk function’s responsibilities, the responsibilities of risk owners in the business, the role of the executive team in reviewing and acting on risk information, and the board’s oversight responsibilities.
6. Risk treatment and controls
Describe how the organisation decides what to do about identified risks. This covers the four standard treatment options, which are avoid, reduce, transfer, and accept, and the criteria for choosing between them in this organisation’s context. It also covers how controls are documented, who is accountable for their effectiveness, and how control failures or degradations are identified and escalated. A plan that describes treatment without connecting it to controls has a structural gap. Controls are where risk management intersects with operations. They are the mechanisms the organisation actually relies on to keep exposure within appetite, so the plan should establish that controls are not just catalogued but actively assessed for effectiveness, with accountability sitting with someone specific.
7. Monitoring and review
How often is the risk register reviewed, and by whom? What triggers an out-of-cycle review? What are the escalation thresholds, the ratings, events, or control failures that prompt immediate reporting rather than waiting for the next scheduled cycle? This section should also address how risk management connects to performance reporting. In many organisations risk and performance are reviewed in separate processes by separate teams, which means the links between strategic performance and risk exposure are rarely made explicit. The plan is an opportunity to commit to an integration that the reporting cycle then has to deliver.
8. Reporting
Document what gets reported, to whom, and on what cycle. The board risk report is not the only reporting that matters. The executive team, risk owners, and the audit and risk committee each need information calibrated to their role and their decision-making authority. Good risk reporting is not comprehensive, it is prioritised. This section should commit the function to reporting that focuses on what has changed, where confidence is weakest relative to exposure that matters, and what decisions or interventions are needed, rather than reporting that describes every risk in full detail and leaves the reader to work out what to do with it.
"A section populated to look complete, rather than to do something, is worse than no section at all. It creates the appearance of governance without the substance."
How to customise the template by industry
The core structure above applies across sectors. What changes is the content within it: the risk categories that carry most weight, the regulatory environment that shapes appetite, and the operational contexts that generate the risks the organisation actually faces.
Construction
Construction risk management operates at two levels at once: enterprise risk for the organisation overall, and project risk for individual programmes of work. A construction plan needs to accommodate both, with clear guidance on how project-level risks escalate to enterprise level and how enterprise appetite applies to project decisions. That relationship is where construction organisations most commonly have gaps. The categories that warrant most attention typically include safety and environment, commercial and contract risk, supply chain and subcontractor risk, programme and delivery risk, and design and regulatory approval risk. The appetite statement needs to be specific about the relationship between programme risk and commercial risk, particularly when schedule pressure is acceptable, when it triggers escalation, and when it affects decisions about scope or methodology.
Government
In government, risk management operates within a statutory and accountability framework that shapes almost every other aspect of the plan. The appetite statement needs to reflect the political and public accountability dimensions of government risk, which extend well beyond financial exposure. Reputational risk, service continuity risk, and risks to public trust are often the most material consequences of poor risk management in government, and they are rarely well captured by standard consequence scales built around financial impact. Government plans also need to be explicit about the interface between risk management and internal audit, the requirements of parliamentary or ministerial accountability, and any applicable public sector or whole-of-government frameworks.
Healthcare
Healthcare risk management is defined by its safety and regulatory environment above all else. The appetite statement must make explicit that appetite for patient safety risk is at or near zero, and that all other categories are evaluated in the context of that primary commitment. That hierarchy needs to be built into the methodology, not just stated in the appetite section. Beyond safety, the categories that tend to require most attention include workforce and capability risk, clinical governance risk, information and data risk, regulatory compliance risk, and financial sustainability risk. The plan needs to establish clearly how clinical risk governance and enterprise risk management connect, because in many healthcare organisations they operate as separate systems, which creates blind spots at the boundaries between them.
Infrastructure
Infrastructure risk management covers assets and services that operate over long timeframes, often under regulatory frameworks that specify service reliability obligations. The plan needs to address both the asset management dimension, covering ageing assets, maintenance regimes, and service continuity, and the capital programme dimension, since infrastructure organisations typically carry significant delivery programmes alongside their operational responsibilities. Appetite in infrastructure often needs to distinguish explicitly between risk to existing service levels, where appetite is typically very low, and risk associated with new capital programmes, where a different tolerance may apply. The plan should also address how risk management connects to asset management planning cycles and long-term investment decisions.
Mining and resources
Mining and resources risk management operates within some of the most demanding safety, environmental, and regulatory environments of any sector. The appetite statement must be specific about the non-negotiable safety and environmental thresholds that apply, and must connect those thresholds to the escalation, reporting, and notification requirements that flow from them under applicable legislation. The categories that typically require most attention include geotechnical risk, operational continuity risk, community and social licence risk, environmental and regulatory risk, and major project delivery risk. Plans for mining operations often need to address the distinct risk profiles of different operational phases, covering exploration, development, production, and eventual closure, and establish how the plan and associated registers adapt as the operation moves through them.
Transport
Transport risk management covers both the safety-critical dimension of moving people and freight, and the operational and commercial dimensions of running network infrastructure and services. Safety risk management in transport typically operates within a regulatory framework that prescribes specific requirements for how safety risks are identified, assessed, and controlled. The enterprise plan needs to reflect those requirements and establish clearly how safety risk management connects to enterprise risk management rather than operating as an entirely separate discipline. The categories that warrant most attention typically include safety and operational risk, network and asset resilience risk, demand and capacity risk, regulatory compliance risk, and major project delivery risk.
Getting the template to work
A template is a starting point, not a destination. The sections above give you the right structure. What makes the plan useful is the specificity and honesty with which you fill it in, and the degree to which the people named in it have actually been engaged in its development.
The most important test for any risk management plan is whether it can be read by someone with no background in risk management and leave them with a clear understanding of how risk is managed in this organisation and what their role in it is. If it cannot pass that test, it is probably written for governance compliance rather than operational usefulness. The audience for a risk management plan is not the risk function. It is the whole organisation.
The second test is whether the plan connects to the risk register and the assurance programme in practice, not just in theory. If the methodology in the plan is not the methodology being used in the register, one of them is wrong. If the risk appetite in the plan is not visible in the ratings in the register, the appetite statement is decorative. The plan sets the standard. The register, and the reporting that flows from it, are how you know whether that standard is being met.
The test that matters
If the risk appetite in your plan is not visible in the ratings in your register, the appetite statement is decorative.
Frequently asked questions
What should a risk management plan template include?
A risk management plan template should include eight sections: purpose and scope, a risk appetite statement, a risk identification and assessment methodology, risk categories, roles and responsibilities, risk treatment and controls, monitoring and review, and reporting. Each section should do a job rather than simply look complete. The structure is consistent across organisations, but the content within each section should reflect how your organisation actually manages risk.
Is a free risk management plan template enough on its own?
A template gives you the headings, a sensible order, and a reminder of what not to forget, which is a fair way to avoid a blank page. What it cannot give you is the thinking. The hard parts, your appetite, your real risks, and an honest view of your controls, are the parts no template fills in. Treat it as scaffolding, not the building. The headings take an afternoon; the judgement is the work, and it is the judgement that makes the plan worth keeping.
How do you customise a risk management plan for your industry?
Keep the eight-section structure and change the content within it. Adjust the risk categories that carry most weight, reflect the regulatory environment that shapes your appetite, and ground the plan in the operational contexts that generate your real risks. A construction plan must reconcile project and enterprise risk; a healthcare plan must put patient safety at or near zero appetite; a mining plan must name non-negotiable safety and environmental thresholds. The skeleton is shared; the substance is sector-specific.
What is the difference between a risk management plan and a risk register?
The plan is the governing document that sets out your approach, scope, appetite, methodology, and accountability. The register is the live record of identified risks within that structure, including current ratings, controls, and actions. The plan sets the rules; the register is where they are applied. You need both, and they should be traceable to each other so any risk in the register links back to the objective the plan exists to protect.
From template to working system
Clew links the risk management plan’s framework directly to the operational reality of the register, the Golden Thread that runs from strategic objectives to the controls that manage them and the exposure that remains. Instead of a template filled in once and filed, the plan and the register live in one platform, on one cycle. Risk and assurance teams in construction, government, healthcare, infrastructure, mining, and transport use Clew to make the plan a working system rather than a document. See how Clew turns the plan into a working system →
Clew is built around exactly this connection, the Golden Thread that runs from strategic objectives to material risks, to the critical controls managing them, to the actions in train where gaps exist. The plan's framework and the register's operational reality live in the same platform, not in separate documents on separate cycles. Risk and assurance teams in construction, government, healthcare, infrastructure, mining, and transport use Clew to make that connection real.
Explore Clew's risk management software →
