Risk isn’t what it used to be. Five years ago, a risk register update once a quarter felt sufficient. Today, with AI adoption accelerating, supply chains shifting overnight, and hybrid delivery models becoming the norm, organisations need risk management that’s built into everyday decisions — not bolted on after the fact.

That’s exactly the gap MoR® 4 (Management of Risk) was designed to close. And at the heart of the framework sit its principles — the non-negotiable ground rules that shape how good risk management actually works.
At SkillMetrix, we’ve been fielding a lot of questions about MoR® 4 lately, so we thought 2026 was a good moment to break down what these principles actually mean and why they matter more than ever.
A quick note on the “4”
If you’re coming from MoR®’s earlier editions, here’s something worth flagging upfront: the 4 in MoR® 4 refers to the edition, not the number of principles. The 3rd edition had four principles. MoR® 4 expanded that set to eight, reflecting how much more central risk management has become to organisational strategy, culture, and value creation.
The Eight MoR® 4 Principles
1. Aligns with objectives: Risk management only makes sense in the context of what an organisation is trying to achieve. Every risk activity should trace back to a strategic, portfolio, programme, project, product, or operational objective.
2. Fits the context: There’s no one-size-fits-all approach. MoR® 4 pushes organisations to tailor their risk practices to their own size, sector, culture, and maturity level.
3. Engages stakeholders: Risk isn’t owned by a single team. This principle emphasises transparent communication and active involvement from everyone who has a stake in the outcome.
4. Provides clear guidance. Ambiguity is the enemy of good risk management. Roles, responsibilities, and escalation paths need to be spelled out clearly enough that people can actually act on them.
5. Informs decision-making. Risk data is only useful if it changes what leaders decide. This principle ties risk management directly to real decisions, not just reporting for its own sake.
6. Facilitates continual improvement. Risk practices should evolve. What worked last year may not hold up against new threats — or new opportunities — this year.
7. Creates a supportive culture. This is one of the more significant additions in MoR® 4. It recognises that people won’t raise risks honestly unless the culture around them makes it safe to do so.
8. Achieves measurable value. Ultimately, risk management has to earn its keep. This principle keeps the framework anchored to tangible outcomes — protecting value and creating it.
Why These Principles Matter Right Now
Two of these principles — creating a supportive culture and achieving measurable value — didn’t really exist in earlier editions in this form. That’s not an accident. Organisations navigating AI governance, distributed teams, and near-constant change need risk frameworks that account for human behaviour and demonstrate ROI, not just checklists.
For professionals working across ITSM, project and programme management, DevOps, or senior leadership, understanding these principles isn’t just exam prep — it’s a genuinely useful lens for spotting where an organisation’s risk practices are falling short.
Where SkillMetrix Comes In
At SkillMetrix, we’ve built our MoR® 4 training around exactly this shift — helping professionals not just memorise the eight principles, but apply them in real organisational contexts. Whether you’re a Project Manager, PMO lead, Risk Analyst, or moving into a broader governance role, our courses are designed to make the framework practical, not theoretical.
As a training and certification partner working across ITSM, project and programme management, and agile domains, SkillMetrix has seen firsthand how frameworks like MoR® 4 help teams move from reactive firefighting to proactive, value-focused risk management.
If 2026 is the year you’re planning to add MoR® 4 to your credentials — or upskill your team — SkillMetrix is a great place to start.