Inside RMBOK: the detailed table of contents
By Julian Talbot

The printed edition of the Risk Management Body of Knowledge is 534 pages. Below is its detailed content structure, with page numbers removed so you can see the breadth of the book and find the topics that matter to you.
The first two levels include a brief explanation of what follows. The more detailed entries retain the contents headings and their hierarchy. Section numbers are kept to show how the topics fit together.
Explore the other RMBOK insights
How to use this book
Introduces the different ways to navigate RMBOK, beginning with a shared vocabulary and the six main sections.
Preface
Sets out the purpose and perspective behind the book as an integrated reference for risk professionals.
Authors
Introduces the three authors and the experience they bring to the body of knowledge.
Julian Talbot
Provides a short biography of Julian Talbot.
Miles Jakeman
Provides a short biography of Miles Jakeman.
Jason Brown
Provides a short biography of Jason Brown.
Acknowledgments
Recognises the people and organisations that contributed to the development of the book.
Peer Reviewers and Collaborating Practitioners
Acknowledges the reviewers and practitioners who contributed their expertise.
Professional Organizations
Acknowledges the professional organisations associated with the development of the work.
Global Access
Introduces the ambition to make risk knowledge more widely accessible through companion resources.
A Possible Companion Wiki
Outlines the possibility of a collaborative online companion to the published book.
Guides and Future Assistance
Introduces prospective guides and other support for applying and extending the material.
Introduction
Places RMBOK within the wider management literature and explains how to find your way through it.
The place of RMBOK
Shows how the risk management body of knowledge relates to other management disciplines.
Finding your way through the book
Explains how readers can use the structure to follow a learning path or locate a particular topic.
The History of Risk
Traces the development of ideas about risk and their influence on contemporary practice.
The Future of Risk
Considers how the changing environment may shape future risk management practice.
Terminology
Establishes the vocabulary and conceptual relationships used throughout the book.
A Shared Understanding
Explains why risk conversations depend on a shared understanding of key terms.
A Definition of Risk
Examines the meaning of risk as a starting point for the rest of the book.
Uncertainty
Explores the uncertainty that underlies risk and decisions about future outcomes.
Objectives
Explains the role of objectives in deciding which uncertainties and outcomes matter.
Industry Norms
Considers how established usage and sector conventions influence risk terminology.
Relationships of Key Terms
Connects the principal terms so they can be understood as parts of a coherent model.
RMBOK Risk Model
Introduces the relationships between the present, uncertainty and possible futures.
The Present
Uncertainty
The Future
Clarity and Ambiguity
Examines how precise language and ambiguous interpretations affect risk discussions.
Risk and Control
Explores the relationship between risk and the measures used to influence it.
An Evolving Definition
Recognises that the language and interpretation of risk continue to develop.
Management of Risk
Connects the terminology to the practical task of managing risk.
SECTION ONE: Risk Management Foundations
Brings together the concepts, models, human factors and quantitative methods that underpin risk practice.
1.1 Overview
Introduces the foundations and how their different elements support risk management.
1.2 Key Concepts
Explores recurring ideas about uncertainty, likelihood, consequences, resilience, opportunity and complex problems.
1.2.1 Positive and Negative Risk
1.2.2 The Law of Large Numbers
1.2.3 Adverse Selection
1.2.4 Managing Uncertainty
1.2.5 As Low As Reasonably Practicable
1.2.6 As High/Low As Reasonably Practicable
1.2.7 Likelihood
1.2.8 Likelihood vs. Consequence
1.2.9 Quadruple Constraints
1.2.10 Risk Dimensions
1.2.11 Risk Considerations
1.2.12 Resilience
1.2.13 Presilience
1.2.14 Antifragility
1.2.15 Elasticity
1.2.16 Resilience Engineering
1.2.17 Unsung Heroes
1.2.18 Unintended Consequences
1.2.19 Zero Harm
1.2.20 Risk Management Continuum
1.2.21 Opportunity Realization
1.2.22 Asynchronous Evolution
1.2.23 VUCA
1.2.24 Contingent Capital
1.2.25 Wicked Problems
1.3 Tools and Models
Surveys analytical tools and conceptual models, from root cause analysis and bow ties to controls, assurance and risk aggregation.
1.3.1 Three Types of Risk
1.3.2 Four Paradigms of Risk
1.3.3 Swiss Cheese
1.3.4 Black Swans
1.3.5 Gray Rhinos
1.3.6 Stroud Matrix
1.3.7 The Titanic Effect
1.3.8 Causal Chains
1.3.9 Root Cause Analysis
1.3.10 Failure Mode and Effects Analysis
1.3.11 Analysis of Competing Hypotheses
1.3.12 BowTie
1.3.13 Fast and Frugal Trees
1.3.14 Hierarchy of Controls
1.3.15 All-Hazards Approach
1.3.16 PPRR
1.3.17 Consequence Calibration Matrix
1.3.18 Risk Matrices
1.3.19 Heat Maps
1.3.20 Ishikawa Diagrams
1.3.21 Delphi Technique
1.3.22 STAMP
1.3.23 Cynefin Framework
1.3.24 Safety Case
1.3.25 Auditing
1.3.26 Audit Findings
1.3.27 Audit Recommendations
1.3.28 Rock Pool Model
1.3.29 Three Lines Model
1.3.30 Combined Assurance Model
1.3.31 Risk Aggregation, Accumulation, and Compounding
1.4 Human Factors
Examines how cognition, behaviour, culture and perception influence decisions and organisational performance.
1.4.1 A Model of Human Factors
1.4.2 Human Factors Analysis and Classification System
1.4.3 Heuristics and Cognitive Biases
1.4.4 Sample Selection Bias
1.4.5 Bradley Curve
1.4.6 Icarus Paradox
1.4.7 Attention
1.4.8 Intuition
1.4.9 Survivorship Bias
1.4.10 Risk Homeostasis
1.4.11 Automaticity
1.4.12 High Reliability Organizations
1.4.13 Calibration Training
1.4.14 Behavioral Psychology
1.4.15 Culture
1.4.16 Prospect Theory
1.4.17 Sensemaking
1.4.18 Two System Model
1.4.19 Triune Brain
1.4.20 Risk Seeking
1.4.21 Risk Perception
1.4.22 Emotions Drive Decisions
1.5 Quantitative Methods
Introduces ways to analyse uncertainty numerically, compare choices and understand financial exposure and risk financing.
1.5.1 What Is Quantitative Analysis
1.5.2 Decision Analysis
1.5.3 Bayesian Analysis
1.5.4 Subjective Expected Utility
1.5.5 Probabilistic Risk Assessment
1.5.6 Actuarial Analysis
1.5.7 Mean Time Between Failures
1.5.8 The Flaw of Averages
1.5.9 Net Present Value
1.5.10 Probabilistic Forecasting
1.5.11 Three Point Estimation
1.5.12 Expected Monetary Value
1.5.13 Monte Carlo
1.5.14 Decision Trees
1.5.15 Sensitivity Analysis
1.5.16 Pareto Analysis
1.5.17 Portfolio Theory
1.5.18 Value at Risk
1.5.19 Capital Markets
1.5.20 Derivatives
1.5.21 Options
1.5.22 Options Greeks
1.5.23 Insurance
1.5.24 Risk Engineering
1.5.25 Alternative Risk Financing
1.5.26 Limitations of QRA
SECTION TWO: Risk Management Standards
Introduces widely used risk management standards and compares the approaches they provide.
2.1 Overview
Sets the context for understanding the role and application of risk management standards.
2.2 ISO 31000 Standard
Introduces the ISO 31000 approach to risk management.
2.3 COSO ERM vs ISO 31000
Compares COSO ERM and ISO 31000, including their terminology, editions and implications for choosing an approach.
Definitions and Editions
Choosing an Approach
SECTION THREE: Risk Management Principles
Brings together principles from established approaches and presents the RMBOK principles for guiding practice.
3.1 Overview
Introduces principles as a basis for judgement across different risk management settings.
3.2 Core Risk Principles
Reviews principles from ISO, COSO, high reliability organisations, government guidance and general risk practice.
ISO 31000 Principles
COSO Internal Control Principles
Control Environment
Risk Assessment
Control Activities
Information and Communication
Monitoring Activities
High Reliability Organizations
UK Government Risk Management Principles
General Risk Management Principles
Risk Is Ubiquitous
Avoid Unnecessary Risk
Benefits Should Outweigh Costs
The Precautionary Principle
As High/Low As Reasonably Practicable
Risk Efficiency Principle
Manage Risk at the Point at Which It Occurs
Integrate Risk Management into Operations
All-Hazards Approach
All Opportunities Approach
Serendipity
Systems Trump Solutions
Strategy Trumps Tactics
Culture Eats Strategy for Breakfast
Fast Decisions Can Be Good Decisions
People Breach Procedures
Clear Decision Authority
3.3 RMBOK Principles
Presents the RMBOK principles and the supporting ideas that help translate them into practice.
Create and Protect Value
Strategy-Driven
Preoccupation with Failure
Avoid Unnecessary Risk
Precautionary
Benefits Outweigh Costs
Integrated
Ubiquitous
Integrated at All Levels
Systems-Focused
Deployed through Management Systems
Structured and Comprehensive
Oversight and Structure
Accountability and Responsibility
Commitment to Competence
Customized
Objectives-Based
Custom Criteria and Controls
Inclusive
Manage Risk Where It Occurs
Communicate Internally and Externally
Dynamic
Reluctance to Simplify Interpretations
Sensitivity to Operations
Identify, Analyze, and Manage Risk
Ongoing Monitoring, Reporting, and Evaluation
Based on the Best Available Information
Appropriate and Relevant Information
Appropriate Decision Speed
Includes Human and Cultural Factors
Values-Based
Deference to Expertise
Managed Environment
Continual Improvement
Evaluate and Communicate Deficiencies
Commitment to Resilience
All-Hazards Approach
All Opportunities Approach
Applying the RMBOK Risk Management Principles
SECTION FOUR: Risk Management Frameworks
Explores how risk management is organised, integrated and supported within management systems.
4.1 Overview
Surveys a range of frameworks and approaches, highlighting their different purposes and contexts.
Comparison and Contrast
ISO 31000 Framework
COSO ERM
Gartner IRM
MITRE ATT&CK Framework
The Orange Book
FERMA
NIST Risk Management Framework
US GAO ERM
Factor Analysis for Information Risk (FAIR)
Open Group’s Risk Taxonomy Standard (O-RT)
Open Group’s Risk Analysis Standard (O-RA)
COBIT
OCTAVE
UK Government Portfolio Risk Management Guidance (Historical)
4.2 Risk Management Integration
Examines how risk management can become part of organisational activity and decision-making.
4.3 Practical Application
Follows the integration, design, implementation, evaluation and improvement of a risk management framework.
Integration
Design
Implementation
Evaluation
Improvement
4.4 Risk Professionals
Considers professional roles, responsibilities, information flows and development within an organisation.
Roles and Responsibilities
Personal Risk Management
Information Flow
Hierarchy and Progression
4.5 Framework vs. System
Distinguishes a risk management framework from the system that puts it into operation, including the Plan–Do–Check–Act cycle.
Risk Management Framework
Risk Management System
Interplay Between Framework and System
Plan, Do, Check, Act
RMS Planning (the ‘Plan’ in PDCA)
RMS Implementation (the ‘Do’ in PDCA)
RMS Evaluation (the ‘Check’ in PDCA)
RMS Improvement (the ‘Act’ in PDCA)
4.6 RMBOK Integration Framework
Connects objectives and outcomes through knowledge, competency and controls, supported by disciplines and enablers.
Objectives
Disciplines
Enablers
Knowledge
Competency
Controls
Outcomes
SECTION FIVE: Risk Management Processes
Explores risk management activities at strategic, operational, tactical and background levels, including assessment and treatment.
5.1 Overview
Introduces the different levels of risk management activity and how they relate to one another.
Strategic
Operational
Tactical
Background
5.2 Operational Risk Management Processes
Compares operational process models and explains how their activities and risk estimates can be interpreted.
The Generic Risk Management Concept
FERMA Risk Management Process
NIST SP 800-39 Risk Management Process
Safe Work Australia Risk Management Process
ISO 31000:2018 Risk Management Process
A Practical Interpretation of the ISO 31000 Process
Interpreting Activities and Risk Estimates
Activities and Estimates
Context and Inherent Risk
Continuing Activities
5.3 Scope, Context, Criteria
Explains how the boundaries, circumstances and decision criteria establish the basis for risk management.
5.3.1 Scope
5.3.2 Context
5.3.3 Criteria
5.4 Risk Assessment
Covers risk identification, analysis and evaluation, including techniques, modelling, control assessment and estimation.
5.4.1 General
5.4.2 Risk Identification
5.4.2.1 Overview
5.4.2.2 Techniques for Identifying Risks
5.4.2.3 Sources of Risk
5.4.2.4 Describing Risks
5.4.3 Risk Analysis
5.4.3.1 Overview
5.4.3.2 Risk Analysis Techniques
5.4.3.3 Risk Analysis Methodologies
5.4.3.4 Categorization
5.4.3.5 Risk Analysis Considerations
5.4.3.6 Quantitative Analysis
5.4.3.7 Building a Risk Analysis Model
5.4.3.8 Control Assessment
5.4.3.9 Risk Estimation
5.4.4 Risk Evaluation
5.4.4.1 Overview
5.4.4.2 Techniques
5.4.4.3 Risk Matrices
5.5 Risk Treatment
Examines treatment strategies, their costs and the planning and resources needed to put them into practice.
5.5.1 Risk Treatment Strategies
5.5.2 Writing Risk Treatments
5.5.3 Risk Treatment Costs
5.5.4 Treatment Plans
5.5.5 Designing Treatment Plans
5.5.6 Resource Estimation
5.5.7 Treating Complex Risks
5.6 Communication and Consultation
Explores understanding, perception, communication barriers and stakeholder participation in managing risk.
Communication
Comprehension of Risk
Perception of Risk
Barriers to Communication
Communication Challenges
Consultation
Stakeholder Engagement
Stakeholder Categories
Stakeholder Groups
RACI Model
RACI Definitions and Responsibilities
Conclusion
5.7 Monitoring and Review
Examines how organisations track risks and treatments, review their systems and assess risk management maturity.
Risk Registers
Treatment Plans
Limitations of Standardized Tools
Environmental Scanning
Data Analytics
Risk Management Framework and System Review
Benchmarking
Risk Maturity Models
RMBOK Maturity Model
Level 1—Initial
Level 2—Basic
Level 3—Repeatable
Level 4—Optimizing
5.8 Recording and Reporting
Considers how risk information is recorded and communicated through reporting.
Reporting
Record Keeping
SECTION SIX: Risk Management Definitions
Provides a reference vocabulary through a glossary and a list of abbreviations.
6.1 Glossary
Collects risk management terms with explanations to support a shared understanding.
6.2 Abbreviations
Provides a reference for abbreviations used across the subject and the book.
Thematic Guides
Introduces companion guides organised around particular themes or applications.
Notes
Collects supporting notes and source references for the text.
Selected Bibliography
Provides a selected reading list for exploring the sources and wider literature.
Other books
Lists related books for readers who want to explore further.
Index
Provides an alphabetical route to subjects and terms across the book.
Companion resources
Points readers towards resources that complement the printed edition.
Continue exploring RMBOK
Browse the book and its companion resources at rmbok.com.
