Public libraries that have implemented information technology in their business processes have a great responsibility in service and management because the visiting users are the general public. In implementing information technology, maintaining the security of user data, members, resources, and library information is very important. Digital libraries must have consideration of the risks and threats that may occur. The risks and threats that can occur are as follows server damage, hardware damage, staff negligence, loss, and natural disasters. The purpose of this research is to analyze risk management by identifying risks and measuring the level of risk from one of the Riau Province Library and Archives Services which already uses a library automation system, namely INLISLite. The method used to identify and assess risk is the Failure Mode Effect and Analysis (FMEA) method. Risk assessment is based on calculating the value of the Risk Priority Number (RPN) resulting from multiplying the level parameters severity, occurrence, and detection. Risk assessment is carried out based on the category list of asset components that support the running of the system, namely, hardware, software, data, people, and network. From the calculations that have been carried out, there are six categories of RPN levels, namely 1 score at a very high level, 3 scores at a high level, 2 scores at a medium level, 16 scores at a low level, and 1 score at a very low level. From the results of the RPN value that needs to be given recommendations for action, namely the RPN value which is at very high and high levels