Home

    /

    Blog

    /

    Project Management Blog

    /

    How to Succeed in Your First 90 Days as a Risk Manager

    How to Succeed in Your First 90 Days as a Risk Manager

    Published: Sep 16, 2026

    Author: Lucy Brown

    Share

    Stepping into your first Risk Manager role is a strange mix of confidence and uncertainty. You have the frameworks, the terminology and the methodologies from your certification, but the organization in front of you has its own history, its own priorities and its own way of handling risk. The gap between knowing risk management and practicing it inside a real business is exactly what your first 90 days are for. This guide gives you a structured 30-60-90 day roadmap to turn credential knowledge into visible, credible results, without overpromising what risk management can do.

    What should a Risk Manager do in the first 90 days? In the first 30 days, learn the business and its current risk framework. In days 31-60, run structured assessments, prioritize risks and assign owners. In days 61-90, implement responses, track key risk indicators and present a 90-day risk assessment to leadership.

    What Does a Risk Manager Do?

    Risk management roles are projected to grow 5% through 2033 (Bureau of Labor Statistics), driven by regulatory complexity and technology risk. A risk manager identifies, assesses and monitors threats and opportunities that could affect an organization's objectives, then communicates them in language leadership can act on.

    A Risk Manager helps an organization understand and manage uncertainty that could affect its objectives. The role is part analyst, part communicator and part facilitator. Core responsibilities usually include:

    • Identifying risks across operations, finance, strategy, projects, technology and compliance.

    • Assessing and analyzing risks by likelihood and impact.

    • Prioritizing risks so attention goes where it matters most.

    • Developing risk responses: mitigate, transfer, avoid or accept.

    • Monitoring risk exposure and tracking changes over time.

    • Maintaining the risk register as a living record.

    • Reporting risks to stakeholders in clear, decision-ready language.

    • Supporting risk-based decision-making and establishing controls.

    • Monitoring emerging risks and communicating across departments.

    • Aligning risk management with organizational objectives.

    These responsibilities vary by industry, organization size and how mature the risk function is. In a small company you may own the entire process; in a large enterprise you may coordinate a network of risk owners. Understanding your version of the role is the first task of your first 90 days. Professional bodies such as the Institute of Risk Management (IRM) set out these responsibilities and the competencies behind them. 

    If you are still weighing the move, our guide to the risk management career path sets out how the role typically develops.

    "Whatever your approach to risk management, it must be sustainable and integrated. If a risk manager designs a bespoke, non-standard risk management system and then leaves the organisation, the next risk manager is better able to build on the existing system if it is aligned to a traditional, recognised framework, rather than having to start all over again."

    Darren Mullan, Head of Project Risk, NEOM Core PMO · Saudi Arabia

    Why Risk Management Certification Matters in Your First 90 Days

    A certification will not, on its own, guarantee a job, a promotion, a salary rise or success in the role. What it does give a new Risk Manager is a structured foundation you can apply from day one:

    • Standardized terminology: So you and your stakeholders mean the same thing by "likelihood," "impact," "inherent," and "residual" risk.

    • Recognized frameworks and methodologies, such as ISO 31000 (risk management principles and guidelines) and the COSO ERM framework, that you can lean on instead of improvising.

    • A repeatable process for identifying, assessing, treating and monitoring risk.

    • Techniques for risk assessment, scoring and prioritization.

    • A shared language for risk appetite and tolerance, governance and compliance.

    • Credibility: A recognized credential signals professional commitment while you build a track record.

    PMI-RMP holders earn a 15-25% salary premium over non-certified risk professionals (rmpexam.com, 2026), underscoring the credential's market value.

    Think of certification as scaffolding. It gives your first 90 days a shape, but the building work, understanding the organization, its stakeholders and its real exposures, is done on the job. For a fuller view of what the credential covers, see the benefits of PMI-RMP certification.

    Key Risk Terms You Will Use from Day One

    These are the core terms your stakeholders will expect you to use precisely:

    • Risk register: the living record of identified risks, their assessment, owners, controls and responses.

    • Inherent vs residual risk: inherent risk is the exposure before controls; residual risk is what remains after controls are applied.

    • Risk appetite vs tolerance: appetite is the amount of risk an organization is willing to pursue toward its objectives; tolerance is the acceptable variation around that level for a specific risk.

    • Key risk indicator (KRI): a metric that gives early warning that a risk's likelihood or impact is changing.

    • Likelihood and impact: the two dimensions used to score a risk, usually combined in a probability-impact matrix.

    Your First 30 Days: Understand, Observe, and Assess

    Resist the urge to "fix" anything in month one. Your job now is to build an accurate picture of the organization and how it currently handles risk.

    Key Objectives for Days 1-30

    • Understand the business model, objectives and strategic priorities.

    • Learn the existing risk management framework, policies and procedures.

    • Meet key stakeholders, leadership, department heads, project managers, compliance, and audit.

    • Map your key stakeholders early: who owns risk decisions, who has informal influence, and who holds institutional knowledge about past incidents. These relationships will shape every phase that follows.

    • Review existing risk registers and previous risk assessments.

    • Understand the organization's risk appetite and tolerance.

    • Identify major business processes and existing controls.

    • Identify regulatory and compliance requirements.

    • Review historical incidents and lessons learned.

    • Understand current risk reporting practices and cadence.

    How to Apply Your Certification in the First 30 Days

    This is where certification knowledge becomes practical:

    • Risk identification: use the categories from your training (operational, financial, strategic, project, technology, compliance) as a checklist to structure conversations and spot gaps in the existing register.

    • Risk assessment & scoring: learn how the organization currently scores likelihood and impact, and compare it with the assessment techniques you studied.

    • Risk categorization: map existing risks to a consistent taxonomy so nothing is double-counted or lost.

    • Risk appetite: ask leadership how much risk they are willing to accept, and translate vague answers into the appetite/tolerance language from your certification.

    Example: Reviewing the current register, you notice it lists ten IT risks but nothing about supplier dependency. Using the risk categories from your training, you flag a gap in third-party/operational risk, an early, credible contribution that costs nothing but structured thinking.

    Look for one early, visible win: a gap in the register, a missing owner, a reporting improvement. One contribution that demonstrates the value of structured risk thinking builds credibility before you propose larger changes.

    Days 31-60: Analyze, Prioritize, and Build

    With context in hand, month two is about turning observation into a validated, prioritized view of risk.

    • Conduct structured risk assessments and validate existing risks.

    • Identify missing risks and retire ones no longer relevant.

    • Prioritize risks by exposure against the organization's appetite.

    • Evaluate existing controls and perform gap analysis.

    • Define and confirm risk owners for each significant risk.

    • Develop risk response strategies for priority risks.

    • Establish key risk indicators (KRIs) for early warning.

    • Improve risk reporting and engage business stakeholders.

    • Scan for emerging risks (technology, regulatory, market).

    • Evaluate the organization's risk tools and reporting systems; understand where data lives and where manual workarounds mask gaps in your GRC capability.

    Applying Certification Knowledge in Days 31-60

    Month two is the certification lifecycle in action:

    Risk Identification → Risk Assessment → Risk Analysis → Risk Evaluation → Risk Treatment → Risk Monitoring

    Month two is also where you choose the right risk-assessment techniques for the job. For identification, structured methods such as SWOT, PESTLE, checklists and root-cause analysis help surface risks systematically. For analysis, distinguish between:

    • Qualitative analysis: scoring likelihood and impact on a scale and plotting them on a probability-impact matrix to rank risks quickly. Use this for most risks.

    • Quantitative analysis: assigning numeric values to model exposure, using techniques such as Monte Carlo simulation, sensitivity analysis, decision-tree analysis or expected monetary value. Reserve this for high-stakes risks where the extra effort is justified.

    A bow-tie diagram is useful when you need to show causes, controls and consequences for a single major risk. Remember that risk is not only about threats: where relevant, treat opportunities (positive risks) the same way, identify, assess and plan to exploit or enhance them, not just avoid downside.

    Figure 3. Scoring likelihood against impact to prioritize risks.

    Example: A recurring problem is late supplier deliveries affecting a flagship project. You identify it as a supplier/operational risk, assess likelihood and impact with the project manager, analyze exposure against the project deadline, evaluate it against risk appetite, and propose treatment, a secondary supplier plus contractual milestones, with the procurement lead as risk owner and a KRI tracking on-time delivery rate. That is certification theory delivering a concrete, owned outcome.

    Days 61-90: Implement, Communicate, and Demonstrate Value

    Month three is about execution, governance and showing value in the organization's own terms.

    • Implement risk response plans and strengthen priority controls.

    • Establish monitoring mechanisms and track KRIs.

    • Create management dashboards and improve reporting.

    • Conduct stakeholder reviews and escalate critical risks appropriately.

    • Measure risk-treatment effectiveness and document lessons learned.

    • Establish ongoing risk governance, ownership, escalation, and cadence.

    • Present a 90-day risk assessment to leadership with clear next steps.

    Demonstrating value does not mean claiming you have eliminated risk, you cannot, and credible risk managers never say so. It means showing that the organization now has a clearer, prioritized, owned and monitored view of its most important risks than it did 90 days ago, and a plan to keep improving. That is the outcome leadership actually wants.

    The 90-Day Risk Manager Roadmap

    Figure 1. The 30-60-90 day roadmap for a new Risk Manager.

    How to Apply Risk Certification Knowledge at Work

    This map connects the concepts you studied to what you actually do in the role:

    Figure 2. The risk management process, always tied to your objectives.

    Certification concept

    Workplace application

    Risk Identification

    Identify operational, financial, strategic, project, technology or compliance risks

    Risk Assessment

    Evaluate likelihood and impact using a consistent scale

    Risk Analysis

    Determine risk exposure and relative priority

    Risk Treatment

    Develop mitigation, transfer, avoidance or acceptance strategies where appropriate

    Risk Appetite

    Compare risk exposure with the organization's tolerance

    Risk Monitoring

    Track KRIs and changes in exposure over time

    Risk Communication

    Present relevant risk information to the right stakeholders

    Risk Governance

    Establish ownership, escalation, reporting and accountability

    Practical Examples: Applying Certification Knowledge

    Example 1: Project Risk

    A flagship project faces schedule pressure and a single-supplier dependency.

    • Identify: Two risks, schedule slippage and supplier concentration.

    • Assess: With the project manager, score likelihood and impact; supplier failure is medium-likelihood, high-impact.

    • Analyze: Map exposure against the go-live date on a probability-impact matrix; supplier risk sits in the "high" quadrant.

    • Evaluate: Compare against the project's risk tolerance, it exceeds it.

    • Treat: Mitigate with a qualified backup supplier and contractual delivery milestones; add schedule buffer.

    • Monitor: The procurement lead owns the risk; a KRI tracks supplier on-time-delivery rate weekly.

    The vague worry is now a managed, owned, monitored item, the structured process in action.

    Example 2: Cyber / Technology Risk

    The organisation depends on one critical legacy system.

    • Identify: A single point of failure in a business-critical application.

    • Assess: Estimate likelihood of failure and business impact (downtime, data loss).

    • Analyze controls: Review backups, patching cadence and access management; estimate the residual risk that remains after those controls.

    • Evaluate: Residual risk still exceeds appetite for a critical system.

    • Treat: Present response options, invest in resilience/migration, transfer via a support contract, or a documented, time-boxed acceptance decision.

    • Monitor: You inform the decision with clear analysis; leadership owns the choice, and a KRI tracks system incidents.

    Example 3: Operational Risk

    A recurring process failure keeps causing rework.

    • Identify & analyze: Apply root-cause analysis (and a bow-tie view) to see whether a control is missing or failing.

    • Assess controls: Test whether the existing control is designed correctly and operating as intended.

    • Treat: Recommend a proportionate control improvement, not an overengineered fix, with a clear owner.

    • Monitor: Define a metric (e.g., rework rate) to confirm the control actually works.

    Example 4: Compliance Risk

    A new regulation creates fresh exposure.

    • Identify: Pin down the specific obligation and where it applies.

    • Assess the gap: Compare current practice against the requirement.

    • Assign ownership: Give the risk to the accountable function (e.g., legal, operations).

    • Treat: Implement the controls needed to meet the obligation.

    • Monitor: Set up evidence and reporting so compliance is demonstrable, not assumed.

    For governance-heavy environments, credentials such as those in our IT governance certification courses complement a risk role.

    These examples are illustrative. Do not present hypothetical figures as industry statistics, always cite a credible source for any real number you publish.

    Common Mistakes New Risk Managers Make in the First 90 Days

    The most common mistake is trying to document every risk at once instead of focusing on the risks that matter most to the organization's objectives.

    • Trying to identify every possible risk at once. Prioritize; a focused register beats an exhaustive one.

    • Focusing only on documentation. A tidy register nobody uses is not risk management.

    • Ignoring business objectives. Risk only matters in relation to what the organization is trying to achieve.

    • Working without stakeholders. Risk owned only by you is risk that will not be managed.

    • Treating the register as static. It is a living record, reviewed on a cadence.

    • Failing to establish ownership. Every significant risk needs a named owner.

    • Confusing identification with management. Listing a risk is the start, not the finish.

    • Ignoring opportunities. Where relevant, risk management addresses upside, not just threats.

    • Overcomplicating reporting. Leaders need clarity and decisions, not a data dump.

    • Ignoring emerging and residual risk. Watch what is coming and what remains after controls.

    • Treating certification as a substitute for context. Frameworks guide judgment; they do not replace it.

    Skills to Build Alongside Certification

    Certification gives you the method; these skills make you effective with it:

    • Business acumen: Connect risk to strategy and money.

    • Communication and stakeholder management: The core of the role.

    • Analytical thinking and critical thinking: Separate signal from noise.

    • Data interpretation and scenario analysis: Reason about uncertainty.

    • Decision-making and negotiation: Influence without authority.

    • Problem-solving: Get to root causes and workable responses.

    • Leadership, reporting and presentation: Make risk actionable.

    Certification and workplace experience complement each other, one supplies structure, the other supplies context. Sharpen the broader capability set with our overview of project management skills, which overlap heavily with the risk role, many risk professionals also hold a broader credential such as the PMP certification.

    How to Measure Your First 90 Days

    Useful, honest measures of progress include:

    • Number and quality of risks identified (not volume for its own sake).

    • Risk register completeness and risk-ownership coverage.

    • Risk and control assessments completed.

    • Risk-treatment progress and KRIs implemented.

    • Reporting improvements and stakeholder engagement.

    • Reduction of specific priority exposures where appropriate.

    A caution: fewer risks on the register does not automatically mean better risk management, it may mean risks are being missed. Effective risk management is about understanding, managing and communicating risk in relation to organizational objectives, not minimizing a count.

    How PMI-RMP Certification Can Support Your First 90 Days

    The average risk manager salary in the United States is $119,760 per year (Indeed, September 2026, based on 3,000 reported salaries). For professionals moving into risk-focused roles, especially in project-driven organizations, the risk management certification covered here is the PMI Risk Management Professional (PMI-RMP)®. The following details are drawn from the official PMI-RMP certification training page and PMI; verify current specifics there before relying on them.

    • Certification & body: PMI-RMP is offered by the Project Management Institute (PMI). The provider delivers the training as a PMI Authorized Training Partner (ATP 4177), aligned to PMI's latest PMI-RMP Exam Content Outline.

    • Who it is for: Project managers, risk practitioners and professionals who identify and manage risk in project environments.

    • What it covers: The risk process end to end, risk strategy and planning, identification, analysis, response, and monitoring.

    • Eligibility (per PMI): Qualifying risk-management experience plus 30 contact hours of formal risk education (which PMI-authorized training provides). Experience requirements vary by your education level, see the PMI-RMP eligibility guide. Confirm the current requirements with PMI before applying.

    • Course support (per Invensis): Digital courseware, scenario-based mock tests, expert-led interactive sessions, exam-application support, flashcards and chapter-wise quizzes, plus a Flexi Pass retake option. Confirm current inclusions on the course page.

    Mapping PMI-RMP Knowledge to Your 90 Days

    Phase

    PMI-RMP knowledge applied

    Days 1-30

    Risk strategy & planning and risk identification, structure how you learn the existing framework and map current risks.

    Days 31-60

    Risk analysis (qualitative and quantitative) and response planning, prioritise risks and design treatments with owners.

    Days 61-90

    Risk monitoring and reporting, implement responses, track indicators and communicate to stakeholders.

    Certification vs Practical Experience: How They Work Together

    Certification provides

    Workplace experience provides

    Frameworks and terminology

    Organisational context

    Structured methods and approaches

    Stakeholder relationships

    Professional development

    Business priorities and practical constraints

    A repeatable process

    Judgement in applying theory to real decisions

    Use certification as your foundation and strengthen it through application. Neither is sufficient alone; together they make a capable Risk Manager.

    90-Day Checklist for a New Risk Manager

    Use this operational risk checklist to track your progress through each phase of your first quarter.

    First 30 Days

    • ☐ Meet key stakeholders

    • ☐ Understand business objectives

    • ☐ Review risk policies

    • ☐ Review existing risk register

    • ☐ Understand risk appetite

    • ☐ Review existing controls

    • ☐ Identify major risk categories

    Days 31-60

    • ☐ Validate risk assessments

    • ☐ Prioritize risks

    • ☐ Review controls

    • ☐ Identify gaps

    • ☐ Assign risk owners

    • ☐ Develop treatment strategies

    • ☐ Define KRIs

    Days 61-90

    • ☐ Implement risk responses

    • ☐ Monitor KRIs

    • ☐ Improve reporting

    • ☐ Conduct stakeholder reviews

    • ☐ Escalate critical risks

    • ☐ Measure treatment effectiveness

    • ☐ Present 90-day findings

    • ☐ Develop the ongoing risk roadmap

    Conclusion

    Your first 90 days follow a clear progression: Learn → Understand → Assess → Prioritize → Apply → Monitor → Communicate → Improve. Certification gives you the structured foundation, the frameworks, terminology and process, but the results come from applying that foundation to your organization's real objectives, stakeholders, risks and controls. Focus on the risks that matter, involve the people who own them, communicate clearly, and show that the organisation understands and manages its risk better at day 90 than it did on day one.

    If you are preparing for a risk role or want to formalise your knowledge, explore Invensis Learning's PMI-RMP certification training, and browse related project management certification courses to build the surrounding skill set.

    Frequently Asked Questions

    What should a Risk Manager do in the first 90 days?

    Spend the first 30 days understanding the business, its objectives, existing risk framework and stakeholders. Use days 31-60 to run structured risk assessments, prioritize risks, evaluate controls and assign owners. In days 61-90, implement responses, set KRIs, improve reporting and present a 90-day risk assessment to leadership.

    Is risk management certification useful for a new Risk Manager?

    Yes, it provides standardized terminology, recognized frameworks and a repeatable process you can apply from day one, and it signals professional commitment. It does not, on its own, guarantee a job, promotion or results; workplace success depends on experience and organizational context.

    What skills does a new Risk Manager need?

    Alongside certification knowledge: business acumen, communication, stakeholder management, analytical and critical thinking, data interpretation, decision-making, negotiation, leadership and presentation skills.

    What risk management tools should a new Risk Manager learn?

    Core tools include the risk register, risk assessment matrices (likelihood/impact), risk scoring, control assessments, key risk indicators (KRIs) and management dashboards, plus your organization's chosen GRC or reporting tools.

    Is certification enough to become an effective Risk Manager?

    No. Certification provides a strong structured foundation, but effectiveness comes from applying it within a specific organization, understanding its objectives, stakeholders, risk environment and controls. Certification and experience work together.

    Author Profile

    Lucy Brown

    Lucy Brown has many years of experience in the project management domain and has helped many organizations across the Asia Pacific region. Her excellent coordinating capabilities, both inside and outside the organization, ensures that all projects are completed on time, adhering to clients' requirements. She possesses extensive expertise in developing project scope, objectives, and coordinating efforts with other teams in completing a project. As a project management practitioner, she also possesses domain proficiency in Project Management best practices in PMP and Change Management. Lucy is involved in creating a robust project plan and keep tabs on the project throughout its lifecycle. She provides unmatched value and customized services to clients and has helped them to achieve tremendous ROI.

    Elevate Your Corporate Training Strategy

    Join thousands of organizations transforming their workforce through Invensis Learning.