Published on June 22, 2026
Last updated on June 25, 2026
Risk identification, evaluation, and management are vital parts of any business operations. Knowing when to use individual approaches or a more comprehensive composite model can help to establish good practices, improve efficiencies, and build a good foundation of risk management throughout an organisation.
Composite risk management (often abbreviated as CRM) is a strategy that can be used to create a holistic and systematic process that manages all risk in one specific area. In doing so, teams can manage the risks ahead of them comprehensively and continuously.
Composite risk management is strongly associated with US Army doctrine, where it was used as a structured decision-making process for identifying hazards and controlling risk across missions, operations and activities. It is used to identify and assess potential hazards and risks that could arise, and then strategies can be developed to mitigate or eliminate what has been identified. This helps teams to make balanced and informed decisions that ensure risks are identified and addressed before they can cause serious issues.
The types of risk identified in the CRM process may include:
For maximum operational success, teams should undertake the same CRM process every time. This helps to standardise practices. Regardless of the nature of the event or set of risks being tackled, the following framework should be observed.
Teams first need to identify the risks that they could face as a result of the proposed activity. If it can impact safety or operations, no matter how great or small and whether an emerging threat or already established, it should be included.
With the risks identified, they then need to be evaluated for severity, probability, and potential impact. Using risk matrices like the ones below can help with this evaluation:

With risks categorised, prioritised and evaluated, attention and resources can be focused where they are needed the most.
Control measures are the actions that help us to limit or even eliminate the risk at hand. Teams will have to decide what can be changed, added, removed, or monitored so the activity can continue with risk reduced to an acceptable level.
Active risk management is where teams implement controls. These could include the introduction of personal protective measures, systems and checks, or even the elimination or replacement of an action that could lead to an extremely severe outcome.
Risk management is not something to be completed once and then never revisited. For a true proactive approach, all controls and actions should be monitored and reviewed on a regular basis. If a gap is identified, changes and updates need to be made. Whether introducing new safety procedures to meet compliance needs or responding to fresh and developing cyber threats, monitoring and reviewing keep an organisation at the forefront of risk management.
When should risk professionals use CRM over other techniques? This framework is best chosen when the following factors are present and need to be considered:
When multiple, serious risks are present, such as those listed above, a composite risk management process can account for all of them in ways that a single-channel approach may not. A composite risk assessment by its very nature will include and cover all of them.
If these risks could lead to failures with major repercussions – personnel safety, business continuity, compliance or governance violations, or reputational harm, to name a few – CRM allows risk teams to gain a greater oversight of the situation to create paths that avoid them.
Using any framework supplies operational teams with a blueprint and paper trail of evidence that can be used in support of decisions made under pressure, as can be required in high-pressure environments or during live events.
For the best and most effective risk management practices, organisations need to shift from reactive problem-solving to proactive risk prevention. Rather than leap from one crisis to the next, teams can identify risks most likely to affect them and put concrete plans in place to help mitigate their effects.
Mastering composite risk management should give an organisation a complete overview of the full lifecycle of a given activity. From planning and initial ideation through to final execution and evaluation, a full and comprehensive risk strategy should be put in place.
Most risk officers might be more used to single-risk approaches that tackle specific risks one at a time. Though these can be incredibly comprehensive and detailed, they might not be able to handle the scope of many risks all present in one situation. This is when we should be more comfortable with a CRM approach:
Situation | Single-risk management | Composite risk management |
Risk complexity | The risk is simple and isolated | Several risks interact or overlap |
Operating environment | Conditions are stable and predictable | Conditions change, or are uncertain and high pressure |
Stakeholder involvement | One person or team owns the risk | Multiple teams, roles, or departments are involved |
Impact level | The potential impact is limited or low severity | Failure could affect safety, continuity, compliance, or reputation |
Control measures | One clear control or action is enough | Several controls are needed across people, process, systems, or environments |
Monitoring needs | Risk can be assessed once and managed through a fixed process | Risk needs to be reviewed as the situation changes |
Type of activity | The activity is routine, repeatable, and well understood | The activity is complex, mission-critical, or non-routine |
As with any other process, challenges can arise. Risk officers need to be fully aware of these challenges and how to avoid them so they themselves do not become a risk. Common issues that can arise in this style of risk management include:
As mentioned above, the best approach to risk management is a proactive one. Treating exercises like CRM as tick-box exercises reduces their overall impact and allows for issues to slip through. Frameworks like CRM need to be used to guide real decisions throughout the organisation, not merely used for completing paperwork and meeting standards.
As comprehensive as any risk management approach might be, there is always a chance that important issues and hazards can be missed. Involve different teams or roles to ensure a full cross-section of the task can be examined. All risks need to be identified and addressed.
Especially in the modern world surrounded by technology, it can be easy to forget simple human error, but it can cause a massive impact if left unaddressed. Account for fatigue, skills gaps, communication issues, pressure and decision-making errors. If a knowledge gap emerges, ensure training is in place to fill it.
Overcompensating for a risk and choosing the wrong control to address it can still cause issues. Staff need to be well-educated in the controls available to them so they can make the right decisions the first time. Each control needs to be practical, clearly owned, and capable of reducing risk.
CRM needs to be treated as a live process. Risks should be reassessed during planning, delivery, and after major changes, and this needs to happen as many times as necessary. Only by making this a living part of your operational resilience strategy will you be able to leverage a strong level of protection.
Composite risk management needs to be a living, supported part of your organisation's risk and operational resilience practices. Since by its very nature it is complex and requires many moving parts, all risk procedures and controls must be correctly documented and stored.
C2's Meridian is designed to provide this centralised and comprehensive platform for risk management. Risk officers can be as granular as they need or can undertake a full overview of an activity to measure every risk that it may face. Take correct action, assign key responders, and create reports as needed.
Book a demo to find out more about how Meridian can transform your approach to composite risk management.
Resilience Manager at Continuity2
With an Honours degree in Risk Management from Glasgow Caledonian University and 6+ years in Business Risk and Resilience, Aimee looks after the design and implementation of Business Continuity Management Systems (BCMS) across all clients. From carrying out successful software deployments to achieving ISO 22301, Aimee helps make companies more resilient and their lives easier in the long run.
Resilience Manager at Continuity2
With an Honours degree in Risk Management from Glasgow Caledonian University and 6+ years in Business Risk and Resilience, Aimee looks after the design and implementation of Business Continuity Management Systems (BCMS) across all clients. From carrying out successful software deployments to achieving ISO 22301, Aimee helps make companies more resilient and their lives easier in the long run.