Start a free trial
Menu

ARAMP-01

ARAMP-1 risk management guide for NATO acquisition programmes

NATO acquisition programme offices, and the acquirers and suppliers running risk management on a NATO programme

A NATO guide to planning, running and monitoring risk management across an acquisition programme's life cycle, from risk register to response strategy.

Edition
1
Published
2012-02

What it is

ARAMP-1, NATO's Allied Risk Assessment Management Publication, is a guide to running risk management (RM) on an acquisition programme or project within NATO's System Life Cycle Management (SLCM) framework. It covers programmes of any kind and product class run under NATO or a NATO nation's acquisition policy, from a Risk Management Plan and a maintained risk register through to how risk is shared with a contractor across the life of a contract.

A guide, not an obligation

Clause 1.2 of the document is explicit: "This document is not mandatory for use but is principally focused toward NATO Nations." It is offered to "any NATO Nation or organization as well as industrial bodies, in their role as acquirer or supplier," and it is carried by STANREC 4739, a NATO Standardization Recommendation. A STANREC invites rather than commits, so ARAMP-1 has no force of its own; a supplier meets it only because a specific contract, RFP, or a national implementation of NATO's SLCM policy asks for a Risk Management Plan and risk register built along these lines.

The five-step risk management process

The document's core is a five-step process, each step described with a common structure of inputs, tasks, outputs and toolbox:

  • Risk Management Planning sets the tone: who is involved, which tools and techniques apply, and how RM integrates with project management. Its output is the Risk Management Plan (RMP), a standalone document for a large project or programme, or a chapter of the Project Management Plan for a small one.
  • Risk Identification produces risk statements, an event, an impact, and often a cause, written in a risk-impact format, "As a result of (X), (Y) may occur which would/could/may lead to (Z)", using top-down and bottom-up techniques, the Delphi technique, checklists, and historical data from earlier programmes.
  • Risk Analysis always runs qualitative analysis first, ranking risks by probability and impact against a matrix, before any quantitative work, such as Monte Carlo simulation, on a selected, interdependent subset of risks.
  • Risk Response Planning chooses a strategy per risk: avoidance, mitigation or transfer for a threat; exploit, enhance or share for an opportunity; active or passive acceptance for either. Every chosen response is checked for the residual and secondary risks it creates.
  • Risk Monitoring and Control keeps the RMP and risk register current through regular risk review meetings and periodic risk audits, ideally run by auditors not immediately involved in the project.

Fitting into NATO's life cycle

The document maps this process onto NATO's system life cycle stages (AAP-48) and the programme/project management process (AAP-20). Stage transitions are controlled by decision gates at programme level; a project moves through milestones within a stage. At each decision gate, the authority responsible has to confirm that risks for the next stage are identified, that risks and actions carried over from the previous stage are accepted, and that the risk situation itself permits entering or leaving the stage.

Chapter 5 adds two NATO-specific concerns. It sets out a collaborative, rather than a purely risk-transferring, relationship between a NATO contracting authority and its contractor: a shared risk register, common definitions, and joint risk reviews across pre-contract-award, RFP development, source selection and post-contract-award phases. It also treats accelerated or rapid fielding as a distinct risk driver: reduced documentation, a compressed life cycle, and reliance on commercial or government off-the-shelf products all carry named risks, with concrete alternatives suggested rather than a blanket refusal.

What an auditor or contracting authority actually looks at

Nobody certifies against ARAMP-1; it is guidance, and the document sets up no accreditation scheme. What does happen: internal risk audits check the RM process and response plans, and on a NATO contract, a source-selection evaluation team assesses an offeror's proposal risk and performance risk, with risk management sometimes used as a selection discriminator. After award, an Integrated Baseline Review checks the pre-award risk plans against what was actually contracted.

What it does not cover

ARAMP-1 does not tell a reader whether it applies to their programme; that is set by the contract and the customer's quality clause, not by this guide or by us. It does not certify anything or anyone. And it is not a technical specification for a product: the risk register, RMP template and toolbox in its annexes are process tools, not requirements on what is being acquired.

How we help

ARAMP-1 describes a process run by people: risk workshops, a maintained risk register, RMP reviews, and periodic risk audits. That work happens in programme meetings and contractor reviews, not inside a piece of software, and ComplyTrain makes no claim of a built-in ARAMP-1 mapping, because there is none.

What ComplyTrain does for this kind of work in general: it holds the Risk Management Plan as a controlled, versioned document rather than a file that quietly diverges between the programme office and the contractor; it keeps training records for whoever is assigned to run risk management on a programme; and it logs the outcome of risk reviews and risk audits as dated, auditable records instead of meeting notes that get lost. That is the same document-control, training-record and corrective-action trail ComplyTrain provides for any process an organisation has to evidence, applied here to risk management rather than built specifically for it.

Which tier of NATO risk management practice a given programme has to meet, and which other Allied Publications sit alongside ARAMP-1, is set by the contract and the customer's quality clause. Use the standards explorer to see what else applies to your programme, and talk to us about how ComplyTrain holds the evidence for whichever of those a contract asks for.

Standards it references

Questions

Is ARAMP-1 mandatory?

No. Clause 1.2 of the document states plainly that it is not mandatory for use. It is carried by STANREC 4739, a NATO recommendation rather than a ratified STANAG, so it becomes relevant to a supplier only when a specific contract or RFP calls for a Risk Management Plan and risk register built to it.

Is there an ARAMP-1 certification?

No. ARAMP-1 is a process guide, and the document sets up no accreditation or certification scheme against it. What happens instead is internal risk audits and, on a NATO contract, a source-selection evaluation of an offeror's proposal and performance risk.

How does ARAMP-1 relate to AQAP-2070?

ARAMP-1's risk register template includes a field for linking a risk to a Mutual Government Quality Assurance reference, which is what AQAP-2070 governs. The two documents inform each other; ARAMP-1 does not require AQAP-2070 or vice versa.

Does ARAMP-1 cover opportunities as well as threats?

Yes. The document treats risk as any uncertain event with a positive or negative effect on a project's objectives, and runs both threats and opportunities through the same five-step process, with separate response strategies: avoidance, mitigation and transfer for threats, exploit, enhance and share for opportunities.

What is STANREC 4739?

STANREC 4739 is the NATO Standardization Recommendation that carries ARAMP-1: the cover document under which nations are invited, not required, to use this risk management guide.