Risk manager: role, responsibilities and tools
Responsibilities, place in the organisation, how the role differs from the CISO, the ISO 31000 method, skills, pay and tools: the risk manager role explained simply.
The risk manager helps management understand and control all the risks the company faces. They identify them with business units, assess them, build the risk map, monitor treatment plans and report to the audit or risk committee. Cyber risk is one of them, and has become one of the most closely watched.
The role varies widely with company size and sector. This guide describes its core, the method it relies on, how it works with the CISO, and what public sources say about pay in France.
Risk manager: definition of the role
The risk manager leads enterprise risk management: everything an organisation does to spot what could stop it reaching its objectives, decide what it accepts and organise the reduction of the rest. The scope is cross-functional: strategic, financial, operational, legal, reputational, environmental and digital risks.
The job profile published by Apec, the French executive employment agency, lists several titles for the role: enterprise risk manager, risk and insurance manager, risk and compliance manager, chief risk officer in large groups. In banking and insurance, the role has a strong regulatory and financial flavour (credit, market and liquidity risk); this guide focuses on the role in companies and public organisations.
What a risk manager does
According to Apec, the role covers six groups of responsibilities:
- Identifying and ranking risks, and opportunities, through workshops with business units and process analysis.
- Assessing risks and building the risk map, often shown as a likelihood and impact matrix.
- Building and monitoring the control plan and the risk register, with owners and deadlines.
- Preparing for continuity: business continuity plans and emergency plans.
- Spreading a risk culture through a network of correspondents, and tracking legal and regulatory changes.
- Reporting to the audit or risk committee and managing relations with regulators.
In many companies the risk manager also runs the insurance programme: transferring part of the risk to an insurer is one of the treatment options, including for cyber risk.
Enterprise risk management: the ISO 31000 framework
The international reference is ISO 31000:2018, which provides guidelines for managing risk in any organisation. It is not certifiable: it is a good-practice framework. It has three parts: principles (risk management that is integrated, structured, customised, inclusive, dynamic…), a framework driven by leadership commitment, and a process, which the diagram below follows on an example.
Animated diagram of the ISO 31000 process: set the scope, context and criteria, then risk assessment chains identification, analysis and evaluation, before treatment. Communication and consultation on one side, monitoring and review on the other, accompany every step, and everything is recorded and reported.
Specialised methods follow the same process. ISO 27005 applies it to information security, and ANSSI's EBIOS Risk Manager method adapts it to digital risk. The other major reference in the field is COSO ERM, published by COSO, the body behind the internal control framework of the same name. Either way, the key is the same: common criteria (impact scales, risk appetite) set by management so that very different risks can be compared.
Risk manager and CISO: who does what?
Both roles deal with risk, but not at the same level. The CISO is the information security expert: they carry out cyber risk analyses and lead protective measures. The risk manager places that risk among all the others and helps management arbitrate.
| Criterion | Risk manager | CISO |
|---|---|---|
| Scope | All of the company's risks | Information and IT security |
| Key question | Which risks could compromise our objectives, and which do we accept? | Are we protected in line with the threats? |
| Frameworks | ISO 31000, COSO ERM | ISO 27001, ISO 27005, EBIOS RM, NIS 2 |
| Deliverables | Risk map, control plan, audit committee report | Security policy, risk analyses, security plan, security dashboard |
| Counterparts | Senior management, finance, audit, insurers | IT, business units, suppliers, cyber authorities |
French authorities encourage the two to work together. In 2019, ANSSI and AMRAE (the French risk managers' association) jointly published the guide "Controlling the digital risk: the trust advantage", aimed at executives and risk managers. Its message, as ANSSI's press release puts it: digital risk is a strategic risk to be handled at the highest level, through a progressive fifteen-step approach. The NIS 2 Directive points the same way: its Article 21 requires risk management measures based on an "all-hazards" approach.
In practice, three rules avoid misunderstandings: cyber risk appears on the company risk map with the same impact scales as other risks; major cyber scenarios are built with the CISO; and cyber indicators presented to management go through a shared dashboard.
Risk manager skills and training
Apec describes a master's-level profile (university, engineering or business school) in finance, statistics, risk control or a related field, and notes that at least five years of risk management experience is often required. Expected skills combine:
- a technical base: economic and financial analysis, statistical models, knowledge of regulation, project and change management;
- interpersonal skills: teaching, persuasion, writing, a view that is both strategic and operational;
- digital literacy, increasingly essential to discuss cyber scenarios with the CISO and IT.
AMRAE leads the professional community in France and offers specialised training.
How much does a risk manager earn in France?
Figures published online vary widely and rarely explain their method. The most solid source is Apec's job profile, based on published job ads: 80% of salaries offered fall between €36,000 and €65,000 gross per year, variable pay included, with an average of €50,000.
These figures describe risk manager roles; chief risk officer positions in large groups or banks follow different scales. As for the CISO, company size, sector and regulatory exposure weigh heavily.
The risk manager's toolkit
A risk manager's tools serve three purposes: recording (risk register, risk map), tracking (control plans, owners, deadlines, indicators) and reporting (reports for the audit committee, management and insurers). Many start with a spreadsheet, which quickly becomes hard to maintain as contributors multiply and the history of decisions must be kept.
For cyber, the challenge is linking the CISO's analyses to the overall risk map without re-keying. A shared governance, risk and compliance approach tracks risks, controls, action plans and supplier risks in one place.
Going further: Phinasoft's risk analysis module supports cyber risk analyses (ANSSI-certified EBIOS RM, ISO 27005 or your own method) and action plan tracking.
Summary
A view of all risks
The risk manager maps financial, operational, legal, reputational and cyber risks, and helps management decide which ones to accept.
A partner for the CISO
The CISO brings cyber expertise and scenarios; the risk manager puts them alongside the other risks and translates them into business stakes.
A shared method
ISO 31000 provides the frame: context and criteria, assessment, treatment, monitoring and communication, recorded and reported to management.
Frequently asked questions about the risk manager
What does a risk manager do?
They identify, assess and prioritise the risks that could stop the company from reaching its objectives, build the risk map with business units, monitor treatment plans and report to management and the audit or risk committee. They often handle insurance and business continuity as well.
What is the difference between a risk manager and a CISO?
The CISO is an information security specialist who analyses cyber risks and leads protective measures. The risk manager has a cross-functional view of all the company's risks, including cyber, and helps management arbitrate between them. The two must work together so cyber risk is assessed on the same scales as other risks.
How much does a risk manager earn in France?
According to Apec, the French executive employment agency, 80% of salaries offered in risk manager job ads fall between €36,000 and €65,000 gross per year, fixed and variable pay included, with an average of €50,000. Chief risk officer roles in large groups pay more.
What training does a risk manager need?
Apec cites a master's-level degree (university, engineering or business school) in finance, statistics, risk control or a related field, and at least five years of risk management experience is often required. Specialised training exists, including from AMRAE, the French risk management association.
What is ISO 31000?
ISO 31000 provides guidelines for managing risk that apply to any organisation. It describes principles, a framework and a process (context and criteria, assessment, treatment, monitoring, communication). It is not certifiable.
Who does the risk manager report to?
Most often to the CEO, the general secretary or the CFO. They may also sit in a risk department, internal audit or legal. They report regularly to the audit committee or risk committee.
Sources (8)
- Apec — Fiche métier risk manager
- ISO — ISO 31000:2018, Management du risque — Lignes directrices
- ANSSI et AMRAE — Maîtrise du risque numérique : l'atout confiance (2019)
- ANSSI — Communiqué de presse du guide ANSSI / AMRAE (18 novembre 2019)
- AMRAE — Association pour le management des risques et des assurances de l'entreprise
- COSO — Enterprise Risk Management
- EUR-Lex — Directive (UE) 2022/2555 (NIS 2), article 21
- ANSSI — La méthode EBIOS Risk Manager
A platform and service that adapt to you
Our platform is designed for fine-tuned configuration and broad adaptability to your needs.