We present a risk management framework which allows to reason about and manage risk for role based access control systems. The framework expresses essential characteristics of risk management in dynamic environments, and can be used for assessing risk and decision making; it is flexible, and able to handle different access control requirements. This framework provides a basis for designing and implementation of access control systems.