In the digital era, the rapid advancement of information technology (IT) has become a critical element in supporting business operations. However, the use of IT also introduces risks such as operational disruptions, data security threats, and system failures. This study aims to evaluate the implementation of IT risk management at CV XYZ, a mineral water distribution company in Sumatra, using the COBIT 5 framework in the APO12 (Manage Risk) domain. The research employs a qualitative case study approach, including literature review, problem identification, data collection through interviews with company executives, and descriptive data analysis. The findings reveal that CV XYZ operates at Capability Level 2 (Managed Process) for the data collection and risk analysis subdomains, and Level 3 (Established Process) for the risk profile maintenance and mitigation action determination subdomains. However, the company requires further optimization to achieve Level 5 (Optimizing Process). Strategic recommendations include strengthening risk policies, enhancing human resource skills, maintaining IT infrastructure, and improving disaster recovery systems to support sustainable business operations