top of page

Inside RMBOK: the detailed table of contents

2d
8 min read

By Julian Talbot

Rows of books on shelves in a bright library.

The printed edition of the Risk Management Body of Knowledge is 534 pages. Below is its detailed content structure, with page numbers removed so you can see the breadth of the book and find the topics that matter to you.

The first two levels include a brief explanation of what follows. The more detailed entries retain the contents headings and their hierarchy. Section numbers are kept to show how the topics fit together.

Explore the other RMBOK insights

How to use this book

Introduces the different ways to navigate RMBOK, beginning with a shared vocabulary and the six main sections.

Preface

Sets out the purpose and perspective behind the book as an integrated reference for risk professionals.

Authors

Introduces the three authors and the experience they bring to the body of knowledge.

Julian Talbot

Provides a short biography of Julian Talbot.

Miles Jakeman

Provides a short biography of Miles Jakeman.

Jason Brown

Provides a short biography of Jason Brown.

Acknowledgments

Recognises the people and organisations that contributed to the development of the book.

Peer Reviewers and Collaborating Practitioners

Acknowledges the reviewers and practitioners who contributed their expertise.

Professional Organizations

Acknowledges the professional organisations associated with the development of the work.

Global Access

Introduces the ambition to make risk knowledge more widely accessible through companion resources.

A Possible Companion Wiki

Outlines the possibility of a collaborative online companion to the published book.

Guides and Future Assistance

Introduces prospective guides and other support for applying and extending the material.

Introduction

Places RMBOK within the wider management literature and explains how to find your way through it.

The place of RMBOK

Shows how the risk management body of knowledge relates to other management disciplines.

Finding your way through the book

Explains how readers can use the structure to follow a learning path or locate a particular topic.

The History of Risk

Traces the development of ideas about risk and their influence on contemporary practice.

The Future of Risk

Considers how the changing environment may shape future risk management practice.

Terminology

Establishes the vocabulary and conceptual relationships used throughout the book.

A Shared Understanding

Explains why risk conversations depend on a shared understanding of key terms.

A Definition of Risk

Examines the meaning of risk as a starting point for the rest of the book.

Uncertainty

Explores the uncertainty that underlies risk and decisions about future outcomes.

Objectives

Explains the role of objectives in deciding which uncertainties and outcomes matter.

Industry Norms

Considers how established usage and sector conventions influence risk terminology.

Relationships of Key Terms

Connects the principal terms so they can be understood as parts of a coherent model.

RMBOK Risk Model

Introduces the relationships between the present, uncertainty and possible futures.

  • The Present

  • Uncertainty

  • The Future

Clarity and Ambiguity

Examines how precise language and ambiguous interpretations affect risk discussions.

Risk and Control

Explores the relationship between risk and the measures used to influence it.

An Evolving Definition

Recognises that the language and interpretation of risk continue to develop.

Management of Risk

Connects the terminology to the practical task of managing risk.

SECTION ONE: Risk Management Foundations

Brings together the concepts, models, human factors and quantitative methods that underpin risk practice.

1.1 Overview

Introduces the foundations and how their different elements support risk management.

1.2 Key Concepts

Explores recurring ideas about uncertainty, likelihood, consequences, resilience, opportunity and complex problems.

  • 1.2.1 Positive and Negative Risk

  • 1.2.2 The Law of Large Numbers

  • 1.2.3 Adverse Selection

  • 1.2.4 Managing Uncertainty

  • 1.2.5 As Low As Reasonably Practicable

  • 1.2.6 As High/Low As Reasonably Practicable

  • 1.2.7 Likelihood

  • 1.2.8 Likelihood vs. Consequence

  • 1.2.9 Quadruple Constraints

  • 1.2.10 Risk Dimensions

  • 1.2.11 Risk Considerations

  • 1.2.12 Resilience

  • 1.2.13 Presilience

  • 1.2.14 Antifragility

  • 1.2.15 Elasticity

  • 1.2.16 Resilience Engineering

  • 1.2.17 Unsung Heroes

  • 1.2.18 Unintended Consequences

  • 1.2.19 Zero Harm

  • 1.2.20 Risk Management Continuum

  • 1.2.21 Opportunity Realization

  • 1.2.22 Asynchronous Evolution

  • 1.2.23 VUCA

  • 1.2.24 Contingent Capital

  • 1.2.25 Wicked Problems

1.3 Tools and Models

Surveys analytical tools and conceptual models, from root cause analysis and bow ties to controls, assurance and risk aggregation.

  • 1.3.1 Three Types of Risk

  • 1.3.2 Four Paradigms of Risk

  • 1.3.3 Swiss Cheese

  • 1.3.4 Black Swans

  • 1.3.5 Gray Rhinos

  • 1.3.6 Stroud Matrix

  • 1.3.7 The Titanic Effect

  • 1.3.8 Causal Chains

  • 1.3.9 Root Cause Analysis

  • 1.3.10 Failure Mode and Effects Analysis

  • 1.3.11 Analysis of Competing Hypotheses

  • 1.3.12 BowTie

  • 1.3.13 Fast and Frugal Trees

  • 1.3.14 Hierarchy of Controls

  • 1.3.15 All-Hazards Approach

  • 1.3.16 PPRR

  • 1.3.17 Consequence Calibration Matrix

  • 1.3.18 Risk Matrices

  • 1.3.19 Heat Maps

  • 1.3.20 Ishikawa Diagrams

  • 1.3.21 Delphi Technique

  • 1.3.22 STAMP

  • 1.3.23 Cynefin Framework

  • 1.3.24 Safety Case

  • 1.3.25 Auditing

  • 1.3.26 Audit Findings

  • 1.3.27 Audit Recommendations

  • 1.3.28 Rock Pool Model

  • 1.3.29 Three Lines Model

  • 1.3.30 Combined Assurance Model

  • 1.3.31 Risk Aggregation, Accumulation, and Compounding

1.4 Human Factors

Examines how cognition, behaviour, culture and perception influence decisions and organisational performance.

  • 1.4.1 A Model of Human Factors

  • 1.4.2 Human Factors Analysis and Classification System

  • 1.4.3 Heuristics and Cognitive Biases

  • 1.4.4 Sample Selection Bias

  • 1.4.5 Bradley Curve

  • 1.4.6 Icarus Paradox

  • 1.4.7 Attention

  • 1.4.8 Intuition

  • 1.4.9 Survivorship Bias

  • 1.4.10 Risk Homeostasis

  • 1.4.11 Automaticity

  • 1.4.12 High Reliability Organizations

  • 1.4.13 Calibration Training

  • 1.4.14 Behavioral Psychology

  • 1.4.15 Culture

  • 1.4.16 Prospect Theory

  • 1.4.17 Sensemaking

  • 1.4.18 Two System Model

  • 1.4.19 Triune Brain

  • 1.4.20 Risk Seeking

  • 1.4.21 Risk Perception

  • 1.4.22 Emotions Drive Decisions

1.5 Quantitative Methods

Introduces ways to analyse uncertainty numerically, compare choices and understand financial exposure and risk financing.

  • 1.5.1 What Is Quantitative Analysis

  • 1.5.2 Decision Analysis

  • 1.5.3 Bayesian Analysis

  • 1.5.4 Subjective Expected Utility

  • 1.5.5 Probabilistic Risk Assessment

  • 1.5.6 Actuarial Analysis

  • 1.5.7 Mean Time Between Failures

  • 1.5.8 The Flaw of Averages

  • 1.5.9 Net Present Value

  • 1.5.10 Probabilistic Forecasting

  • 1.5.11 Three Point Estimation

  • 1.5.12 Expected Monetary Value

  • 1.5.13 Monte Carlo

  • 1.5.14 Decision Trees

  • 1.5.15 Sensitivity Analysis

  • 1.5.16 Pareto Analysis

  • 1.5.17 Portfolio Theory

  • 1.5.18 Value at Risk

  • 1.5.19 Capital Markets

  • 1.5.20 Derivatives

  • 1.5.21 Options

  • 1.5.22 Options Greeks

  • 1.5.23 Insurance

  • 1.5.24 Risk Engineering

  • 1.5.25 Alternative Risk Financing

  • 1.5.26 Limitations of QRA

SECTION TWO: Risk Management Standards

Introduces widely used risk management standards and compares the approaches they provide.

2.1 Overview

Sets the context for understanding the role and application of risk management standards.

2.2 ISO 31000 Standard

Introduces the ISO 31000 approach to risk management.

2.3 COSO ERM vs ISO 31000

Compares COSO ERM and ISO 31000, including their terminology, editions and implications for choosing an approach.

  • Definitions and Editions

  • Choosing an Approach

SECTION THREE: Risk Management Principles

Brings together principles from established approaches and presents the RMBOK principles for guiding practice.

3.1 Overview

Introduces principles as a basis for judgement across different risk management settings.

3.2 Core Risk Principles

Reviews principles from ISO, COSO, high reliability organisations, government guidance and general risk practice.

  • ISO 31000 Principles

  • COSO Internal Control Principles

    • Control Environment

    • Risk Assessment

    • Control Activities

    • Information and Communication

    • Monitoring Activities

  • High Reliability Organizations

  • UK Government Risk Management Principles

  • General Risk Management Principles

    • Risk Is Ubiquitous

    • Avoid Unnecessary Risk

    • Benefits Should Outweigh Costs

    • The Precautionary Principle

    • As High/Low As Reasonably Practicable

    • Risk Efficiency Principle

    • Manage Risk at the Point at Which It Occurs

    • Integrate Risk Management into Operations

    • All-Hazards Approach

    • All Opportunities Approach

    • Serendipity

    • Systems Trump Solutions

    • Strategy Trumps Tactics

    • Culture Eats Strategy for Breakfast

    • Fast Decisions Can Be Good Decisions

    • People Breach Procedures

    • Clear Decision Authority

3.3 RMBOK Principles

Presents the RMBOK principles and the supporting ideas that help translate them into practice.

  • Create and Protect Value

    • Strategy-Driven

    • Preoccupation with Failure

    • Avoid Unnecessary Risk

    • Precautionary

    • Benefits Outweigh Costs

  • Integrated

    • Ubiquitous

    • Integrated at All Levels

    • Systems-Focused

    • Deployed through Management Systems

  • Structured and Comprehensive

    • Oversight and Structure

    • Accountability and Responsibility

    • Commitment to Competence

  • Customized

    • Objectives-Based

    • Custom Criteria and Controls

  • Inclusive

    • Manage Risk Where It Occurs

    • Communicate Internally and Externally

  • Dynamic

    • Reluctance to Simplify Interpretations

    • Sensitivity to Operations

    • Identify, Analyze, and Manage Risk

    • Ongoing Monitoring, Reporting, and Evaluation

  • Based on the Best Available Information

    • Appropriate and Relevant Information

    • Appropriate Decision Speed

  • Includes Human and Cultural Factors

    • Values-Based

    • Deference to Expertise

    • Managed Environment

  • Continual Improvement

    • Evaluate and Communicate Deficiencies

    • Commitment to Resilience

    • All-Hazards Approach

    • All Opportunities Approach

  • Applying the RMBOK Risk Management Principles

SECTION FOUR: Risk Management Frameworks

Explores how risk management is organised, integrated and supported within management systems.

4.1 Overview

Surveys a range of frameworks and approaches, highlighting their different purposes and contexts.

  • Comparison and Contrast

  • ISO 31000 Framework

  • COSO ERM

  • Gartner IRM

  • MITRE ATT&CK Framework

  • The Orange Book

  • FERMA

  • NIST Risk Management Framework

  • US GAO ERM

  • Factor Analysis for Information Risk (FAIR)

  • Open Group’s Risk Taxonomy Standard (O-RT)

  • Open Group’s Risk Analysis Standard (O-RA)

  • COBIT

  • OCTAVE

  • UK Government Portfolio Risk Management Guidance (Historical)

4.2 Risk Management Integration

Examines how risk management can become part of organisational activity and decision-making.

4.3 Practical Application

Follows the integration, design, implementation, evaluation and improvement of a risk management framework.

  • Integration

  • Design

  • Implementation

  • Evaluation

  • Improvement

4.4 Risk Professionals

Considers professional roles, responsibilities, information flows and development within an organisation.

  • Roles and Responsibilities

  • Personal Risk Management

  • Information Flow

  • Hierarchy and Progression

4.5 Framework vs. System

Distinguishes a risk management framework from the system that puts it into operation, including the Plan–Do–Check–Act cycle.

  • Risk Management Framework

  • Risk Management System

  • Interplay Between Framework and System

  • Plan, Do, Check, Act

    • RMS Planning (the ‘Plan’ in PDCA)

    • RMS Implementation (the ‘Do’ in PDCA)

    • RMS Evaluation (the ‘Check’ in PDCA)

    • RMS Improvement (the ‘Act’ in PDCA)

4.6 RMBOK Integration Framework

Connects objectives and outcomes through knowledge, competency and controls, supported by disciplines and enablers.

  • Objectives

  • Disciplines

  • Enablers

  • Knowledge

  • Competency

  • Controls

  • Outcomes

SECTION FIVE: Risk Management Processes

Explores risk management activities at strategic, operational, tactical and background levels, including assessment and treatment.

5.1 Overview

Introduces the different levels of risk management activity and how they relate to one another.

  • Strategic

  • Operational

  • Tactical

  • Background

5.2 Operational Risk Management Processes

Compares operational process models and explains how their activities and risk estimates can be interpreted.

  • The Generic Risk Management Concept

  • FERMA Risk Management Process

  • NIST SP 800-39 Risk Management Process

  • Safe Work Australia Risk Management Process

  • ISO 31000:2018 Risk Management Process

  • A Practical Interpretation of the ISO 31000 Process

  • Interpreting Activities and Risk Estimates

    • Activities and Estimates

    • Context and Inherent Risk

    • Continuing Activities

5.3 Scope, Context, Criteria

Explains how the boundaries, circumstances and decision criteria establish the basis for risk management.

  • 5.3.1 Scope

  • 5.3.2 Context

  • 5.3.3 Criteria

5.4 Risk Assessment

Covers risk identification, analysis and evaluation, including techniques, modelling, control assessment and estimation.

  • 5.4.1 General

  • 5.4.2 Risk Identification

    • 5.4.2.1 Overview

    • 5.4.2.2 Techniques for Identifying Risks

    • 5.4.2.3 Sources of Risk

    • 5.4.2.4 Describing Risks

  • 5.4.3 Risk Analysis

    • 5.4.3.1 Overview

    • 5.4.3.2 Risk Analysis Techniques

    • 5.4.3.3 Risk Analysis Methodologies

    • 5.4.3.4 Categorization

    • 5.4.3.5 Risk Analysis Considerations

    • 5.4.3.6 Quantitative Analysis

    • 5.4.3.7 Building a Risk Analysis Model

    • 5.4.3.8 Control Assessment

    • 5.4.3.9 Risk Estimation

  • 5.4.4 Risk Evaluation

    • 5.4.4.1 Overview

    • 5.4.4.2 Techniques

    • 5.4.4.3 Risk Matrices

5.5 Risk Treatment

Examines treatment strategies, their costs and the planning and resources needed to put them into practice.

  • 5.5.1 Risk Treatment Strategies

  • 5.5.2 Writing Risk Treatments

  • 5.5.3 Risk Treatment Costs

  • 5.5.4 Treatment Plans

  • 5.5.5 Designing Treatment Plans

  • 5.5.6 Resource Estimation

  • 5.5.7 Treating Complex Risks

5.6 Communication and Consultation

Explores understanding, perception, communication barriers and stakeholder participation in managing risk.

  • Communication

    • Comprehension of Risk

    • Perception of Risk

    • Barriers to Communication

    • Communication Challenges

  • Consultation

    • Stakeholder Engagement

    • Stakeholder Categories

    • Stakeholder Groups

    • RACI Model

    • RACI Definitions and Responsibilities

  • Conclusion

5.7 Monitoring and Review

Examines how organisations track risks and treatments, review their systems and assess risk management maturity.

  • Risk Registers

  • Treatment Plans

  • Limitations of Standardized Tools

  • Environmental Scanning

  • Data Analytics

  • Risk Management Framework and System Review

  • Benchmarking

  • Risk Maturity Models

  • RMBOK Maturity Model

    • Level 1—Initial

    • Level 2—Basic

    • Level 3—Repeatable

    • Level 4—Optimizing

5.8 Recording and Reporting

Considers how risk information is recorded and communicated through reporting.

  • Reporting

  • Record Keeping

SECTION SIX: Risk Management Definitions

Provides a reference vocabulary through a glossary and a list of abbreviations.

6.1 Glossary

Collects risk management terms with explanations to support a shared understanding.

6.2 Abbreviations

Provides a reference for abbreviations used across the subject and the book.

Thematic Guides

Introduces companion guides organised around particular themes or applications.

Notes

Collects supporting notes and source references for the text.

Selected Bibliography

Provides a selected reading list for exploring the sources and wider literature.

Other books

Lists related books for readers who want to explore further.

Index

Provides an alphabetical route to subjects and terms across the book.

Companion resources

Points readers towards resources that complement the printed edition.

Continue exploring RMBOK

Browse the book and its companion resources at rmbok.com.


The Risk Management Body of Knowledge ("RMBOK") refers to the book of the same name and the professional body of knowledge related to risk management.

 PMBOK™ is a trademark of the Project Management Institute, Inc. (“PMI”). PMI, the PMBOK® Guide (A Guide to the Project Management Body of Knowledge), and the trademarked term PMBOK™ are not associated with the Risk Management Body of Knowledge or with RMBOK Pty Ltd and should not be conflated with the abbreviation "RMBOK," which is an abbreviation for the book The Risk Management Body of Knowledge.

Contact | Book updates | Disclaimer

© 2024–2026 RMBOK Pty Ltd

bottom of page